zscaler-mcp-server
OfficialServer Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| ZSCALER_CLOUD | No | Cloud override (e.g., beta, zscalertwo); omit for production | |
| ZSCALER_CLIENT_ID | Yes | OneAPI client ID from the ZIdentity console | |
| ZSCALER_CUSTOMER_ID | No | Zscaler customer/tenant ID (required for ZPA tools) | |
| ZSCALER_PRIVATE_KEY | No | PEM-encoded private key for JWT-based OneAPI auth, used in place of ZSCALER_CLIENT_SECRET | |
| ZSCALER_CLIENT_SECRET | No | OneAPI client secret | |
| ZSCALER_VANITY_DOMAIN | Yes | Your organization's vanity domain (e.g., acme) |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| logging | {} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| extensions | {
"io.modelcontextprotocol/ui": {}
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| zeasm_list_findingsA | List EASM findings for an organization. Read-only. Returns one triage row per finding (id, category, type, status,
risk level/score, impacted asset, first/last seen) rather than the raw SDK
record. Use the returned |
| zeasm_get_finding_detailsA | Get the full detail for one EASM finding. Read-only. Adds description, country, CISA/EPSS exploitation-likelihood signals, and scan provenance on top of the triage fields. |
| zeasm_get_finding_evidenceA | Get the scan evidence attributed to one EASM finding. Read-only. Returns the evidence |
| zeasm_get_finding_scan_outputA | Get the complete scan output for one EASM finding. Read-only. Returns the full scan |
| zeasm_list_lookalike_domainsA | List EASM lookalike domains for an organization. Read-only. Returns one triage row per detected lookalike/impersonation
domain (the lookalike, the domain it impersonates, risk, registration
state, deception methods). Use the returned |
| zeasm_get_lookalike_domainA | Get full detail for one EASM lookalike domain. Read-only. Adds description, registrar/registrant + lifecycle dates, and
remediation guidance on top of the triage fields. Look the domain up by its
|
| zeasm_list_organizationsA | List ZEASM organizations. Read-only. Returns one row per organization configured in the EASM Admin
Portal, carrying just the |
| zcc_get_device_otpA | Get the OTP bundle for a ZCC device (logout / exit / uninstall / disable OTPs). Read-only (GET, no tenant mutation) but the returned values ARE sensitive
short-lived credentials — treat them like passwords. Requires the device's
|
| zcc_list_devicesA | List ZCC enrolled devices (read-only). Each row is the full device record — identity, OS, agent version,
registration state, assigned |
| zcc_list_forwarding_profilesB | List ZCC forwarding profiles (by company). Read-only. |
| zcc_list_trusted_networksB | List ZCC trusted networks (by company). Read-only. |
| zcell_list_anomaly_policiesB | List Zscaler Cellular anomaly policies. Read-only. Returns one row per policy (id, name, type, enabled state, run
status, applied SIM location groups, violation count) over a |
| zcell_list_anomaly_policy_logsA | List the activity log for one Zscaler Cellular anomaly policy. Read-only. Returns the enable/disable/run history (status + message +
timestamp) for the given |
| zcell_list_anomaly_policy_violationsA | List the ICCIDs that violated a Zscaler Cellular anomaly policy. Read-only. Returns the policy rows carrying violation data over a |
| zcell_list_iccid_violationsA | List the anomaly-policy violation events for one ICCID. Read-only. Returns the individual violation events (event type, zone,
timestamp) attributed to |
| zcell_list_audit_customers_searchA | Search Zscaler Cellular audit-log entries over a lookback window. Read-only. Returns curated audit rows (who changed what, when, and the
operation) over a |
| zcell_list_audit_metadataA | List the Zscaler Cellular audit filter vocabulary. Read-only. Returns the valid operation types and object types you can pass
to |
| zcell_get_customer_data_handlingA | Get the logged-in Zscaler Cellular customer's profile and SIM totals. Read-only. Returns the customer record: identity, activation state, platform, configured regions, SIM counts, current usage, and the linked ZIA/ZPA cloud and SIM-provider metadata. Scoped by ZCELL_CUSTOMER_ID. |
| zcell_list_regionsB | List the Zscaler Cellular regions available/configured for the customer. Read-only. Returns each region and whether it is configured. |
| zcell_list_region_operational_statusA | List Zscaler Cellular configured regions with their operational status. Read-only. Returns each configured region plus the broker-cluster (BC) and app-connector (AC) status blocks and the MAP A-C / B-C link statuses. |
| zcell_list_network_eventsA | Search Zscaler Cellular network/session events over a lookback window. Read-only. Returns curated event rows (timestamp, event, outcome, SIM/ICCID,
country, carrier, RAT, IP) over a |
| zcell_list_sim_analytics_mapA | List Zscaler Cellular SIM map points (dashboard lat/lng summary). Read-only. Returns SIM location points with their ICCIDs, IMSIs, and tags — the data that backs the fleet map. Optionally scope to specific ICCIDs. |
| zcell_list_sim_analytics_summaryA | List the Zscaler Cellular SIM status summary (total/used/active/inactive). Read-only. Returns the SIM-count breakdown for the tenant. |
| zcell_list_sim_usage_by_countryB | List Zscaler Cellular data usage grouped by country (top countries). Read-only. Returns the top countries by data usage over a |
| zcell_list_sim_usage_by_dayA | List Zscaler Cellular data usage per day over the window. Read-only. Returns one usage bucket per day over a |
| zcell_list_sim_usage_by_simA | List Zscaler Cellular data usage grouped by SIM (top SIMs). Read-only. Returns the top SIMs by data usage over a |
| zcell_get_sim_detailsA | Get the full Zscaler Cellular record for one SIM by ICCID. Read-only. Returns the identifying, status, and device fields for the SIM (ICCID, IMSI/IMEI, status, network status, APN, IP, device, tags, usage). |
| zcell_list_simsA | Search the Zscaler Cellular SIM inventory with filters and pagination. Read-only (browses the inventory). Returns a page of curated SIM records plus the aggregate usage/pagination envelope. Filter by ICCID, status, network status, country, tag, device attributes, or IMEI lock status. |
| zcell_list_sim_location_groupsA | List Zscaler Cellular SIM location groups. Read-only. Returns one row per group (id, name, tracked ICCIDs). Use the
returned |
| zcell_get_sim_location_groupA | Get one Zscaler Cellular SIM location group. Read-only. Adds the geo-fence definition, linked anomaly policies, and the inside/outside ICCID membership buckets on top of the summary fields. |
| zcell_list_tagsA | List the Zscaler Cellular SIM tags defined for the customer. Read-only. Returns one row per tag (id, name, provenance). Use the returned
tag |
| zdx_list_devicesA | List active ZDX devices. Read-only. Returns one identifying row per device (id, hostname, owning
user). Filter by email, user ID, MAC/IP, location/department/geo, and the
|
| zdx_get_deviceA | Get one active ZDX device. Read-only. The ZDX SDK returns a single-element list; the device record is unwrapped and shaped to the identifying fields. |
| zdx_list_departmentsA | List ZDX departments as curated id/name rows. Read-only. Use a returned |
| zdx_list_locationsA | List ZDX locations as curated id/name rows. Read-only. Use a returned |
| zdx_get_analysisA | Get the status/result of a ZDX score analysis (full record). Read-only. Returns whether the analysis is still running or its results if
complete. Start one with |
| zdx_get_deeptrace_cloudpathB | Get the cloud-path (hop-by-hop network path) captured during a ZDX deep trace (curated, nested JSON). Read-only. |
| zdx_get_deeptrace_cloudpath_metricsA | Get cloud-path metrics captured during a ZDX deep trace (curated, nested time-series JSON). Read-only. |
| zdx_get_deeptrace_eventsC | Get the events captured during a ZDX deep trace (curated, nested JSON with ISO timestamps). Read-only. |
| zdx_get_deeptrace_health_metricsC | Get device health metrics captured during a ZDX deep trace (curated, nested time-series JSON). Read-only. |
| zdx_list_deeptrace_top_processesA | List the top processes captured during a ZDX deep trace (full records). Read-only. Returns the process groups captured during the session — useful for spotting resource-intensive processes impacting performance. |
| zdx_get_deeptrace_webprobe_metricsC | Get web-probe metrics captured during a ZDX deep trace (curated, nested time-series JSON). Read-only. |
| zdx_list_cloudpath_probesA | List cloud-path probes for an app on a ZDX device (full records). Read-only. Call this BEFORE |
| zdx_get_web_probesA | List web probes for an app on a ZDX device (full records). Read-only. Call this BEFORE |
| zdx_get_application_metricA | Get ZDX performance metrics for one application (time-series). Read-only. Returns one series per metric (Page Fetch Time, DNS Time,
availability), each with its datapoints over the |
| zdx_get_applicationA | Get the ZDX score for one application, with its most-impacted regions. Read-only. Returns the headline ZDX score plus the per-region impact
breakdown for the |
| zdx_get_application_score_trendA | Get the ZDX score trend (over time) for one application. Read-only. Returns the score-over-time datapoints for the |
| zdx_list_application_usersA | List users/devices that accessed a ZDX application, as curated rows. Read-only. Returns one triage row per user (id, name, email, ZDX score).
Filter by |
| zdx_get_application_userA | Get one user's ZDX detail for an application (per-device breakdown). Read-only. Returns the user's score plus the nested per-device metrics for
the |
| zdx_list_alertsA | List ongoing ZDX alerts. Read-only. Returns one triage row per ongoing alert (id, rule, severity,
type, start time, impacted-device count). Filter by location/department/geo
and the |
| zdx_get_alertA | Get one ZDX alert as a curated, agent-facing detail view. Read-only. Adds the impacted department / location / geolocation scope to the summary fields. |
| zdx_list_alert_affected_devicesA | List devices affected by a ZDX alert. Read-only. Returns one identifying row per affected device. Filter by
location/department/geo, location groups, and the |
| zdx_list_applicationsA | List active ZDX applications. Read-only. Returns one row per application (id, name, ZDX score, impact
signals). Filter by location/department/geo and the |
| zdx_list_device_deep_tracesA | List deep-trace sessions for a ZDX device (full records). Read-only. Returns one row per trace (id, status, session name, app, ISO
timestamps). Use a returned |
| zdx_get_device_deep_traceA | Get one ZDX deep-trace session. Read-only. The SDK returns a single-element list; the trace record is unwrapped, timestamps ISO-normalized, and shaped to the identity fields. |
| zdx_list_historical_alertsA | List historical (ended) ZDX alerts. Read-only. Like |
| zdx_list_softwareA | List the ZDX software inventory. Read-only. Returns one row per software title (key, name, vendor, version,
install/user counts). Filter by location/department/geo/user/device. Use a
returned |
| zdx_get_software_detailsB | Expand one ZDX software key into its per-user/device install rows. Read-only. Returns the users and devices that have the given |
| zia_get_activation_statusA | Get the current ZIA configuration activation status. |
| zia_get_advanced_settingsA | Get the ZIA tenant-wide Advanced Settings object. |
| zia_get_atp_malware_policyA | Get the ZIA malware policy (file-handling toggles). |
| zia_get_atp_malware_inspectionB | Get the ZIA malware inspection (traffic-direction toggles). |
| zia_get_atp_malware_protocolsB | Get the ZIA malware protocol toggles (HTTP/FTP). |
| zia_get_malware_settingsA | Get the ZIA 16-field malware threat-class settings block. |
| zia_get_atp_settingsA | Get the ZIA tenant-wide ATP policy block. |
| zia_get_atp_security_exceptionsA | Get the ZIA ATP security-exception bypass URL allowlist. |
| zia_list_atp_malicious_urlsA | List the ZIA ATP malicious-URL denylist. |
| zia_list_auth_exempt_urlsA | List the ZIA cookie-auth exempt URL list. |
| zia_list_cloud_app_control_actionsA | List the available CAC actions for a category (and optional cloud apps). |
| zia_list_cloud_app_control_rulesC | List ZIA Cloud App Control rules for a category. |
| zia_get_cloud_app_control_ruleA | Get a single ZIA Cloud App Control rule by category + ID. |
| zia_list_cloud_app_policyB | List the ZIA policy-engine cloud-application catalog (Cloud App Control). |
| zia_list_cloud_app_ssl_policyC | List the ZIA policy-engine cloud-application catalog (SSL Inspection). |
| zia_list_cloud_firewall_dns_rulesC | List ZIA Cloud Firewall DNS rules. |
| zia_get_cloud_firewall_dns_ruleA | Get a single ZIA Cloud Firewall DNS rule by ID with member references. |
| zia_list_cloud_firewall_ips_rulesC | List ZIA Cloud Firewall IPS rules. |
| zia_get_cloud_firewall_ips_ruleB | Get a single ZIA Cloud Firewall IPS rule by ID with member references. |
| zia_list_cloud_firewall_rulesC | List ZIA Cloud Firewall rules. |
| zia_get_cloud_firewall_ruleA | Get a single ZIA Cloud Firewall rule by ID with member references. |
| zia_list_device_groupsC | List ZIA device groups. |
| zia_list_devicesC | List ZIA devices. |
| zia_list_devices_liteA | List ZIA devices via the lighter endpoint (id/name only). |
| zia_list_file_type_control_rulesC | List ZIA File Type Control rules. |
| zia_list_file_type_categoriesB | List ZIA file-type categories usable in File Type Control rules. |
| zia_get_file_type_control_ruleA | Get a single ZIA File Type Control rule by ID with member references. |
| zia_geo_searchB | Resolve ZIA geo data by coordinates, by IP, or by city prefix (read-only). |
| zia_get_sandbox_quotaA | Get the ZIA Sandbox API submission quota. |
| zia_get_sandbox_behavioral_analysisA | Get the ZIA Sandbox behavioral-analysis configuration. |
| zia_get_sandbox_file_hash_countA | Get the ZIA Sandbox custom file-hash blocklist usage/quota. |
| zia_get_sandbox_reportB | Get the ZIA Sandbox detonation report for a file MD5 hash. |
| zia_list_gre_rangesB | List available ZIA GRE internal-IP ranges. |
| zia_list_gre_tunnelsB | List ZIA GRE tunnels. |
| zia_get_gre_tunnelB | Get a single ZIA GRE tunnel by ID. |
| zia_list_ip_destination_groupsC | List ZIA IP destination groups. |
| zia_get_ip_destination_groupB | Get a single ZIA IP destination group by ID with full members. |
| zia_list_ip_source_groupsC | List ZIA IP source groups. |
| zia_get_ip_source_groupA | Get a single ZIA IP source group by ID with its full member list. |
| zia_list_ips_signature_rulesC | List ZIA custom IPS signature rules. |
| zia_get_ips_signature_ruleB | Get a single ZIA custom IPS signature rule by ID with its body. |
| get_zia_dlp_dictionariesA | Read ZIA DLP dictionaries: list all/lite, or fetch one by ID (read-only). |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| zcell_audit_data_usage | Audit Zscaler Cellular data usage across the fleet: tenant status summary, usage by country / day / SIM, and data-cap events — to surface top consumers, roaming spend, and trends over a window. Args: since_days: Lookback window in DAYS for the usage analytics (the ZCell ``days`` parameter). Defaults to 30. country: Optional country to focus the audit on (e.g. "US", "GB"). Leave empty to audit the whole fleet and rank countries. |
| zcell_investigate_sim | Investigate one Zscaler Cellular SIM by ICCID: inventory record, recent network/session events, and any anomaly-policy (geofence) violations, to diagnose why a SIM is offline, roaming, data-capped, or flagged. Args: iccid: The ICCID of the SIM to investigate (passed as a string). since_days: Lookback window in DAYS for the event/violation history (the ZCell ``days`` parameter). Defaults to 7. |
| zcell_review_anomaly_policies | Review Zscaler Cellular anomaly/geofence policies: their run state, the location groups they watch, and the violations (and offending SIMs) they have generated over a window — a posture check on cellular anomaly detection. Args: since_days: Lookback window in DAYS for violations/logs (the ZCell ``days`` parameter). Defaults to 30. policy_type: Optional policy type to focus on (e.g. "GEOFENCING"). Leave empty to review all anomaly policy types. |
| zdx_troubleshoot_user_experience | Troubleshoot a user's ZDX digital experience: device health, application score trend, network-path metrics, and active alerts, to localize whether a slowdown is on the device, the network, or the application server. Args: user_or_device: The user's name/email or the device hostname to investigate (used as the ``search`` term for ``zdx_list_devices``). application: Optional application name to focus on (e.g. "Microsoft 365", "Salesforce"). Leave empty to triage across all monitored apps. since_hours: Lookback window in HOURS for ZDX queries (the ``since`` parameter). Defaults to 24. |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/zscaler/zscaler-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server