Skip to main content
Glama
zscaler

zscaler-mcp-server

Official
by zscaler

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
ZSCALER_CLOUDNoCloud override (e.g., beta, zscalertwo); omit for production
ZSCALER_CLIENT_IDYesOneAPI client ID from the ZIdentity console
ZSCALER_CUSTOMER_IDNoZscaler customer/tenant ID (required for ZPA tools)
ZSCALER_PRIVATE_KEYNoPEM-encoded private key for JWT-based OneAPI auth, used in place of ZSCALER_CLIENT_SECRET
ZSCALER_CLIENT_SECRETNoOneAPI client secret
ZSCALER_VANITY_DOMAINYesYour organization's vanity domain (e.g., acme)

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}
logging
{}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
extensions
{
  "io.modelcontextprotocol/ui": {}
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
zeasm_list_findingsA

List EASM findings for an organization.

Read-only. Returns one triage row per finding (id, category, type, status, risk level/score, impacted asset, first/last seen) rather than the raw SDK record. Use the returned id with zeasm_get_finding_details, zeasm_get_finding_evidence, or zeasm_get_finding_scan_output.

zeasm_get_finding_detailsA

Get the full detail for one EASM finding.

Read-only. Adds description, country, CISA/EPSS exploitation-likelihood signals, and scan provenance on top of the triage fields.

zeasm_get_finding_evidenceA

Get the scan evidence attributed to one EASM finding.

Read-only. Returns the evidence content (the subset of scan output attributable to this finding) and its source_type. The content can be large free-form scanner text and is preserved verbatim.

zeasm_get_finding_scan_outputA

Get the complete scan output for one EASM finding.

Read-only. Returns the full scan content and its source_type. The content can be large free-form scanner text and is preserved verbatim.

zeasm_list_lookalike_domainsA

List EASM lookalike domains for an organization.

Read-only. Returns one triage row per detected lookalike/impersonation domain (the lookalike, the domain it impersonates, risk, registration state, deception methods). Use the returned lookalike_raw with zeasm_get_lookalike_domain for full detail.

zeasm_get_lookalike_domainA

Get full detail for one EASM lookalike domain.

Read-only. Adds description, registrar/registrant + lifecycle dates, and remediation guidance on top of the triage fields. Look the domain up by its lookalike_raw name (from zeasm_list_lookalike_domains).

zeasm_list_organizationsA

List ZEASM organizations.

Read-only. Returns one row per organization configured in the EASM Admin Portal, carrying just the id + name. Use the returned id as the org_id argument for zeasm_list_findings, zeasm_list_lookalike_domains, and the other EASM tools.

zcc_get_device_otpA

Get the OTP bundle for a ZCC device (logout / exit / uninstall / disable OTPs).

Read-only (GET, no tenant mutation) but the returned values ARE sensitive short-lived credentials — treat them like passwords. Requires the device's udid (from zcc_list_devices).

zcc_list_devicesA

List ZCC enrolled devices (read-only).

Each row is the full device record — identity, OS, agent version, registration state, assigned policy_name, ownership, hardware, VPN/tunnel state, and the enrollment / keep-alive timestamps. Use the returned udid with zcc_get_device_otp.

zcc_list_forwarding_profilesB

List ZCC forwarding profiles (by company). Read-only.

zcc_list_trusted_networksB

List ZCC trusted networks (by company). Read-only.

zcell_list_anomaly_policiesB

List Zscaler Cellular anomaly policies.

Read-only. Returns one row per policy (id, name, type, enabled state, run status, applied SIM location groups, violation count) over a days lookback window. Use the returned id with the anomaly-policy logs and violations tools.

zcell_list_anomaly_policy_logsA

List the activity log for one Zscaler Cellular anomaly policy.

Read-only. Returns the enable/disable/run history (status + message + timestamp) for the given policy_id.

zcell_list_anomaly_policy_violationsA

List the ICCIDs that violated a Zscaler Cellular anomaly policy.

Read-only. Returns the policy rows carrying violation data over a days lookback window. Use zcell_list_iccid_violations to drill into the per-event detail for a specific ICCID.

zcell_list_iccid_violationsA

List the anomaly-policy violation events for one ICCID.

Read-only. Returns the individual violation events (event type, zone, timestamp) attributed to iccid under policy_id, over a days lookback window.

zcell_list_audit_customers_searchA

Search Zscaler Cellular audit-log entries over a lookback window.

Read-only. Returns curated audit rows (who changed what, when, and the operation) over a days window, with optional operation/object/visibility filters. The before/after data blobs are omitted from the row.

zcell_list_audit_metadataA

List the Zscaler Cellular audit filter vocabulary.

Read-only. Returns the valid operation types and object types you can pass to zcell_list_audit_customers_search.

zcell_get_customer_data_handlingA

Get the logged-in Zscaler Cellular customer's profile and SIM totals.

Read-only. Returns the customer record: identity, activation state, platform, configured regions, SIM counts, current usage, and the linked ZIA/ZPA cloud and SIM-provider metadata. Scoped by ZCELL_CUSTOMER_ID.

zcell_list_regionsB

List the Zscaler Cellular regions available/configured for the customer.

Read-only. Returns each region and whether it is configured.

zcell_list_region_operational_statusA

List Zscaler Cellular configured regions with their operational status.

Read-only. Returns each configured region plus the broker-cluster (BC) and app-connector (AC) status blocks and the MAP A-C / B-C link statuses.

zcell_list_network_eventsA

Search Zscaler Cellular network/session events over a lookback window.

Read-only. Returns curated event rows (timestamp, event, outcome, SIM/ICCID, country, carrier, RAT, IP) over a days window, with optional filter_by conditions, sort_by, and pagination.

zcell_list_sim_analytics_mapA

List Zscaler Cellular SIM map points (dashboard lat/lng summary).

Read-only. Returns SIM location points with their ICCIDs, IMSIs, and tags — the data that backs the fleet map. Optionally scope to specific ICCIDs.

zcell_list_sim_analytics_summaryA

List the Zscaler Cellular SIM status summary (total/used/active/inactive).

Read-only. Returns the SIM-count breakdown for the tenant.

zcell_list_sim_usage_by_countryB

List Zscaler Cellular data usage grouped by country (top countries).

Read-only. Returns the top countries by data usage over a days lookback window.

zcell_list_sim_usage_by_dayA

List Zscaler Cellular data usage per day over the window.

Read-only. Returns one usage bucket per day over a days lookback window, optionally scoped to a single ICCID.

zcell_list_sim_usage_by_simA

List Zscaler Cellular data usage grouped by SIM (top SIMs).

Read-only. Returns the top SIMs by data usage over a days lookback window.

zcell_get_sim_detailsA

Get the full Zscaler Cellular record for one SIM by ICCID.

Read-only. Returns the identifying, status, and device fields for the SIM (ICCID, IMSI/IMEI, status, network status, APN, IP, device, tags, usage).

zcell_list_simsA

Search the Zscaler Cellular SIM inventory with filters and pagination.

Read-only (browses the inventory). Returns a page of curated SIM records plus the aggregate usage/pagination envelope. Filter by ICCID, status, network status, country, tag, device attributes, or IMEI lock status.

zcell_list_sim_location_groupsA

List Zscaler Cellular SIM location groups.

Read-only. Returns one row per group (id, name, tracked ICCIDs). Use the returned id with zcell_get_sim_location_group for the geo-fence and linked-policy detail.

zcell_get_sim_location_groupA

Get one Zscaler Cellular SIM location group.

Read-only. Adds the geo-fence definition, linked anomaly policies, and the inside/outside ICCID membership buckets on top of the summary fields.

zcell_list_tagsA

List the Zscaler Cellular SIM tags defined for the customer.

Read-only. Returns one row per tag (id, name, provenance). Use the returned tag id when assigning tags to SIMs.

zdx_list_devicesA

List active ZDX devices.

Read-only. Returns one identifying row per device (id, hostname, owning user). Filter by email, user ID, MAC/IP, location/department/geo, and the since HOURS window. Use a returned device id with zdx_get_device or the deep-trace / probe tools.

zdx_get_deviceA

Get one active ZDX device.

Read-only. The ZDX SDK returns a single-element list; the device record is unwrapped and shaped to the identifying fields.

zdx_list_departmentsA

List ZDX departments as curated id/name rows.

Read-only. Use a returned id as the department_id scope filter on other ZDX tools. since is in HOURS (default 2h).

zdx_list_locationsA

List ZDX locations as curated id/name rows.

Read-only. Use a returned id as the location_id scope filter on other ZDX tools. since is in HOURS (default 2h).

zdx_get_analysisA

Get the status/result of a ZDX score analysis (full record).

Read-only. Returns whether the analysis is still running or its results if complete. Start one with zdx_start_analysis.

zdx_get_deeptrace_cloudpathB

Get the cloud-path (hop-by-hop network path) captured during a ZDX deep trace (curated, nested JSON). Read-only.

zdx_get_deeptrace_cloudpath_metricsA

Get cloud-path metrics captured during a ZDX deep trace (curated, nested time-series JSON). Read-only.

zdx_get_deeptrace_eventsC

Get the events captured during a ZDX deep trace (curated, nested JSON with ISO timestamps). Read-only.

zdx_get_deeptrace_health_metricsC

Get device health metrics captured during a ZDX deep trace (curated, nested time-series JSON). Read-only.

zdx_list_deeptrace_top_processesA

List the top processes captured during a ZDX deep trace (full records).

Read-only. Returns the process groups captured during the session — useful for spotting resource-intensive processes impacting performance.

zdx_get_deeptrace_webprobe_metricsC

Get web-probe metrics captured during a ZDX deep trace (curated, nested time-series JSON). Read-only.

zdx_list_cloudpath_probesA

List cloud-path probes for an app on a ZDX device (full records).

Read-only. Call this BEFORE zdx_start_deeptrace to obtain the cloudpath_probe_id the deep-trace payload needs.

zdx_get_web_probesA

List web probes for an app on a ZDX device (full records).

Read-only. Call this BEFORE zdx_start_deeptrace to obtain the web_probe_id the deep-trace payload needs.

zdx_get_application_metricA

Get ZDX performance metrics for one application (time-series).

Read-only. Returns one series per metric (Page Fetch Time, DNS Time, availability), each with its datapoints over the since HOURS window (default 2h). Pass metric_name to narrow to a single metric. Use app_id from zdx_list_applications.

zdx_get_applicationA

Get the ZDX score for one application, with its most-impacted regions.

Read-only. Returns the headline ZDX score plus the per-region impact breakdown for the since HOURS window (default 2h). Use app_id from zdx_list_applications.

zdx_get_application_score_trendA

Get the ZDX score trend (over time) for one application.

Read-only. Returns the score-over-time datapoints for the since HOURS window (default 2h) so the agent can reason about whether an app's experience is improving or degrading. Use app_id from zdx_list_applications.

zdx_list_application_usersA

List users/devices that accessed a ZDX application, as curated rows.

Read-only. Returns one triage row per user (id, name, email, ZDX score). Filter by score_bucket (poor/okay/good), location/department/geo, and the since HOURS window (default 2h). Use a returned id with zdx_get_application_user.

zdx_get_application_userA

Get one user's ZDX detail for an application (per-device breakdown).

Read-only. Returns the user's score plus the nested per-device metrics for the since HOURS window (default 2h). Use app_id from zdx_list_applications and user_id from zdx_list_application_users.

zdx_list_alertsA

List ongoing ZDX alerts.

Read-only. Returns one triage row per ongoing alert (id, rule, severity, type, start time, impacted-device count). Filter by location/department/geo and the since HOURS window (max 336h). Use a returned alert id with zdx_get_alert or zdx_list_alert_affected_devices.

zdx_get_alertA

Get one ZDX alert as a curated, agent-facing detail view.

Read-only. Adds the impacted department / location / geolocation scope to the summary fields.

zdx_list_alert_affected_devicesA

List devices affected by a ZDX alert.

Read-only. Returns one identifying row per affected device. Filter by location/department/geo, location groups, and the since HOURS window.

zdx_list_applicationsA

List active ZDX applications.

Read-only. Returns one row per application (id, name, ZDX score, impact signals). Filter by location/department/geo and the since HOURS window. Use a returned id with zdx_get_application, zdx_get_application_metric, or zdx_list_application_users.

zdx_list_device_deep_tracesA

List deep-trace sessions for a ZDX device (full records).

Read-only. Returns one row per trace (id, status, session name, app, ISO timestamps). Use a returned trace_id with the deep-trace metric/event tools or zdx_get_device_deep_trace.

zdx_get_device_deep_traceA

Get one ZDX deep-trace session.

Read-only. The SDK returns a single-element list; the trace record is unwrapped, timestamps ISO-normalized, and shaped to the identity fields.

zdx_list_historical_alertsA

List historical (ended) ZDX alerts.

Read-only. Like zdx_list_alerts but for alert rules that have an Ended On date. since is in HOURS (default 2h, max 14 days = 336h).

zdx_list_softwareA

List the ZDX software inventory.

Read-only. Returns one row per software title (key, name, vendor, version, install/user counts). Filter by location/department/geo/user/device. Use a returned software_key with zdx_get_software_details to see who has it.

zdx_get_software_detailsB

Expand one ZDX software key into its per-user/device install rows.

Read-only. Returns the users and devices that have the given software_key installed. Obtain the key from zdx_list_software.

zia_get_activation_statusA

Get the current ZIA configuration activation status.

zia_get_advanced_settingsA

Get the ZIA tenant-wide Advanced Settings object.

zia_get_atp_malware_policyA

Get the ZIA malware policy (file-handling toggles).

zia_get_atp_malware_inspectionB

Get the ZIA malware inspection (traffic-direction toggles).

zia_get_atp_malware_protocolsB

Get the ZIA malware protocol toggles (HTTP/FTP).

zia_get_malware_settingsA

Get the ZIA 16-field malware threat-class settings block.

zia_get_atp_settingsA

Get the ZIA tenant-wide ATP policy block.

zia_get_atp_security_exceptionsA

Get the ZIA ATP security-exception bypass URL allowlist.

zia_list_atp_malicious_urlsA

List the ZIA ATP malicious-URL denylist.

zia_list_auth_exempt_urlsA

List the ZIA cookie-auth exempt URL list.

zia_list_cloud_app_control_actionsA

List the available CAC actions for a category (and optional cloud apps).

zia_list_cloud_app_control_rulesC

List ZIA Cloud App Control rules for a category.

zia_get_cloud_app_control_ruleA

Get a single ZIA Cloud App Control rule by category + ID.

zia_list_cloud_app_policyB

List the ZIA policy-engine cloud-application catalog (Cloud App Control).

zia_list_cloud_app_ssl_policyC

List the ZIA policy-engine cloud-application catalog (SSL Inspection).

zia_list_cloud_firewall_dns_rulesC

List ZIA Cloud Firewall DNS rules.

zia_get_cloud_firewall_dns_ruleA

Get a single ZIA Cloud Firewall DNS rule by ID with member references.

zia_list_cloud_firewall_ips_rulesC

List ZIA Cloud Firewall IPS rules.

zia_get_cloud_firewall_ips_ruleB

Get a single ZIA Cloud Firewall IPS rule by ID with member references.

zia_list_cloud_firewall_rulesC

List ZIA Cloud Firewall rules.

zia_get_cloud_firewall_ruleA

Get a single ZIA Cloud Firewall rule by ID with member references.

zia_list_device_groupsC

List ZIA device groups.

zia_list_devicesC

List ZIA devices.

zia_list_devices_liteA

List ZIA devices via the lighter endpoint (id/name only).

zia_list_file_type_control_rulesC

List ZIA File Type Control rules.

zia_list_file_type_categoriesB

List ZIA file-type categories usable in File Type Control rules.

zia_get_file_type_control_ruleA

Get a single ZIA File Type Control rule by ID with member references.

zia_geo_searchB

Resolve ZIA geo data by coordinates, by IP, or by city prefix (read-only).

zia_get_sandbox_quotaA

Get the ZIA Sandbox API submission quota.

zia_get_sandbox_behavioral_analysisA

Get the ZIA Sandbox behavioral-analysis configuration.

zia_get_sandbox_file_hash_countA

Get the ZIA Sandbox custom file-hash blocklist usage/quota.

zia_get_sandbox_reportB

Get the ZIA Sandbox detonation report for a file MD5 hash.

zia_list_gre_rangesB

List available ZIA GRE internal-IP ranges.

zia_list_gre_tunnelsB

List ZIA GRE tunnels.

zia_get_gre_tunnelB

Get a single ZIA GRE tunnel by ID.

zia_list_ip_destination_groupsC

List ZIA IP destination groups.

zia_get_ip_destination_groupB

Get a single ZIA IP destination group by ID with full members.

zia_list_ip_source_groupsC

List ZIA IP source groups.

zia_get_ip_source_groupA

Get a single ZIA IP source group by ID with its full member list.

zia_list_ips_signature_rulesC

List ZIA custom IPS signature rules.

zia_get_ips_signature_ruleB

Get a single ZIA custom IPS signature rule by ID with its body.

get_zia_dlp_dictionariesA

Read ZIA DLP dictionaries: list all/lite, or fetch one by ID (read-only).

Prompts

Interactive templates invoked by user choice

NameDescription
zcell_audit_data_usageAudit Zscaler Cellular data usage across the fleet: tenant status summary, usage by country / day / SIM, and data-cap events — to surface top consumers, roaming spend, and trends over a window. Args: since_days: Lookback window in DAYS for the usage analytics (the ZCell ``days`` parameter). Defaults to 30. country: Optional country to focus the audit on (e.g. "US", "GB"). Leave empty to audit the whole fleet and rank countries.
zcell_investigate_simInvestigate one Zscaler Cellular SIM by ICCID: inventory record, recent network/session events, and any anomaly-policy (geofence) violations, to diagnose why a SIM is offline, roaming, data-capped, or flagged. Args: iccid: The ICCID of the SIM to investigate (passed as a string). since_days: Lookback window in DAYS for the event/violation history (the ZCell ``days`` parameter). Defaults to 7.
zcell_review_anomaly_policiesReview Zscaler Cellular anomaly/geofence policies: their run state, the location groups they watch, and the violations (and offending SIMs) they have generated over a window — a posture check on cellular anomaly detection. Args: since_days: Lookback window in DAYS for violations/logs (the ZCell ``days`` parameter). Defaults to 30. policy_type: Optional policy type to focus on (e.g. "GEOFENCING"). Leave empty to review all anomaly policy types.
zdx_troubleshoot_user_experienceTroubleshoot a user's ZDX digital experience: device health, application score trend, network-path metrics, and active alerts, to localize whether a slowdown is on the device, the network, or the application server. Args: user_or_device: The user's name/email or the device hostname to investigate (used as the ``search`` term for ``zdx_list_devices``). application: Optional application name to focus on (e.g. "Microsoft 365", "Salesforce"). Leave empty to triage across all monitored apps. since_hours: Lookback window in HOURS for ZDX queries (the ``since`` parameter). Defaults to 24.

Resources

Contextual data attached and managed by the client

NameDescription

No resources

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/zscaler/zscaler-mcp-server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server