Ext Ops Panel
Open dashboard

What it can do: Zscaler Zero Trust Exchange

MCP server · zscaler

What Zscaler Zero Trust Exchange declares, asks for and runs, according to the marketplaces we read. Runs on your machine: the AI tool starts this PyPI package locally: zscaler-mcp. Tools it declares: 302. Environment variables it asks for: 10, secrets among them: 5. As of our marketplace pass on 2026-10-11.

This is not a security audit. We list what the marketplaces publish about this plugin: what it declares, what it asks for and what it runs. We do not run or inspect its code, and a verified mark is the marketplace's statement, not ours.

Where it runs

  • Runs on your machine: the AI tool starts this PyPI package locally: zscaler-mcpAs declared on: Official MCP Registry.
  • Its MCP server runs on your machine: the AI tool starts this PyPI package locally: ${claude-plugin-root}/-envAs declared on: Claude Code: claude-plugins-official.
  • Runs on your machine, in a container started from this image: mcp/zscaler-mcp-serverAs declared on: Docker MCP Catalog.

What it declares

Tools it declares: 302. As declared on: Docker MCP Catalog.

  • get_zia_dlp_dictionaries
  • get_zia_dlp_engines
  • get_zia_user_departments
  • get_zia_user_groups
  • get_zia_users
  • get_zpa_app_protection_profile
  • get_zpa_app_segments_by_type
  • get_zpa_enrollment_certificate
  • get_zpa_isolation_profile
  • get_zpa_posture_profile
  • get_zpa_saml_attribute
  • get_zpa_scim_attribute
Show the remaining 188
  • get_zpa_scim_group
  • get_zpa_trusted_network
  • zcc_list_devices
  • zcc_list_forwarding_profiles
  • zcc_list_trusted_networks
  • zdx_delete_analysis
  • zdx_delete_deeptrace
  • zdx_get_alert
  • zdx_get_analysis
  • zdx_get_application
  • zdx_get_application_metric
  • zdx_get_application_score_trend
  • zdx_get_application_user
  • zdx_get_deeptrace_cloudpath
  • zdx_get_deeptrace_cloudpath_metrics
  • zdx_get_deeptrace_events
  • zdx_get_deeptrace_health_metrics
  • zdx_get_deeptrace_webprobe_metrics
  • zdx_get_device
  • zdx_get_device_deep_trace
  • zdx_get_software_details
  • zdx_get_web_probes
  • zdx_list_alert_affected_devices
  • zdx_list_alerts
  • zdx_list_application_users
  • zdx_list_applications
  • zdx_list_cloudpath_probes
  • zdx_list_deeptrace_top_processes
  • zdx_list_departments
  • zdx_list_device_deep_traces
  • zdx_list_devices
  • zdx_list_historical_alerts
  • zdx_list_locations
  • zdx_list_software
  • zdx_start_analysis
  • zdx_start_deeptrace
  • zeasm_get_finding_details
  • zeasm_get_finding_evidence
  • zeasm_get_finding_scan_output
  • zeasm_get_lookalike_domain
  • zeasm_list_findings
  • zeasm_list_lookalike_domains
  • zeasm_list_organizations
  • zia_activate_configuration
  • zia_add_atp_malicious_urls
  • zia_add_auth_exempt_urls
  • zia_add_urls_to_category
  • zia_bulk_update_cloud_applications
  • zia_create_cloud_firewall_rule
  • zia_create_gre_tunnel
  • zia_create_ip_destination_group
  • zia_create_ip_source_group
  • zia_create_location
  • zia_create_network_app_group
  • zia_create_network_service
  • zia_create_network_svc_group
  • zia_create_rule_label
  • zia_create_ssl_inspection_rule
  • zia_create_static_ip
  • zia_create_url_category
  • zia_create_url_filtering_rule
  • zia_create_vpn_credential
  • zia_create_web_dlp_rule
  • zia_delete_atp_malicious_urls
  • zia_delete_auth_exempt_urls
  • zia_delete_cloud_firewall_rule
  • zia_delete_gre_tunnel
  • zia_delete_ip_destination_group
  • zia_delete_ip_source_group
  • zia_delete_location
  • zia_delete_network_app_group
  • zia_delete_network_service
  • zia_delete_network_svc_group
  • zia_delete_rule_label
  • zia_delete_ssl_inspection_rule
  • zia_delete_static_ip
  • zia_delete_url_category
  • zia_delete_url_filtering_rule
  • zia_delete_vpn_credential
  • zia_delete_web_dlp_rule
  • zia_geo_search
  • zia_get_activation_status
  • zia_get_cloud_firewall_rule
  • zia_get_gre_tunnel
  • zia_get_ip_destination_group
  • zia_get_ip_source_group
  • zia_get_location
  • zia_get_network_app
  • zia_get_network_app_group
  • zia_get_network_service
  • zia_get_network_svc_group
  • zia_get_rule_label
  • zia_get_sandbox_behavioral_analysis
  • zia_get_sandbox_file_hash_count
  • zia_get_sandbox_quota
  • zia_get_sandbox_report
  • zia_get_ssl_inspection_rule
  • zia_get_static_ip
  • zia_get_url_category
  • zia_get_url_filtering_rule
  • zia_get_vpn_credential
  • zia_get_web_dlp_rule
  • zia_list_atp_malicious_urls
  • zia_list_auth_exempt_urls
  • zia_list_cloud_app_control_actions
  • zia_list_cloud_application_custom_tags
  • zia_list_cloud_applications
  • zia_list_cloud_firewall_rules
  • zia_list_device_groups
  • zia_list_devices
  • zia_list_devices_lite
  • zia_list_gre_ranges
  • zia_list_gre_tunnels
  • zia_list_ip_destination_groups
  • zia_list_ip_source_groups
  • zia_list_locations
  • zia_list_network_app_groups
  • zia_list_network_apps
  • zia_list_network_services
  • zia_list_network_svc_groups
  • zia_list_rule_labels
  • zia_list_ssl_inspection_rules
  • zia_list_static_ips
  • zia_list_url_categories
  • zia_list_url_filtering_rules
  • zia_list_vpn_credentials
  • zia_list_web_dlp_rules
  • zia_list_web_dlp_rules_lite
  • zia_remove_urls_from_category
  • zia_update_cloud_firewall_rule
  • zia_update_ip_destination_group
  • zia_update_ip_source_group
  • zia_update_location
  • zia_update_network_app_group
  • zia_update_network_service
  • zia_update_network_svc_group
  • zia_update_rule_label
  • zia_update_ssl_inspection_rule
  • zia_update_static_ip
  • zia_update_url_category
  • zia_update_url_filtering_rule
  • zia_update_vpn_credential
  • zia_update_web_dlp_rule
  • zia_url_lookup
  • zid_get_group
  • zid_get_group_users
  • zid_get_group_users_by_name
  • zid_get_user
  • zid_get_user_groups
  • zid_get_user_groups_by_name
  • zid_list_groups
  • zid_list_users
  • zid_search_groups
  • zid_search_users
  • zins_get_casb_app_report
  • zins_get_cyber_incidents
  • zins_get_cyber_incidents_by_location
  • zins_get_cyber_incidents_by_threat_and_app
  • zins_get_cyber_incidents_daily
  • zins_get_firewall_by_action
  • zins_get_firewall_by_location
  • zins_get_firewall_network_services
  • zins_get_iot_device_stats
  • zins_get_shadow_it_apps
  • zins_get_shadow_it_summary
  • zins_get_threat_class
  • zins_get_threat_super_categories
  • zins_get_web_protocols
  • zins_get_web_traffic_by_location
  • zins_get_web_traffic_no_grouping
  • zms_get_agent_connection_status_statistics
  • zms_get_agent_group_totp_secrets
  • zms_get_agent_version_statistics
  • zms_get_metadata
  • zms_get_nonce
  • zms_get_resource_group_members
  • zms_get_resource_group_protection_status
  • zms_get_resource_protection_status
  • zms_list_agent_groups
  • zms_list_agents
  • zms_list_app_catalog
  • zms_list_app_zones
  • zms_list_default_policy_rules
  • zms_list_nonces
  • zms_list_policy_rules
  • zms_list_resource_groups
  • zms_list_resources
  • zms_list_tag_keys

We keep the first 200 names of a list.

Prompts and resources: the marketplaces we read do not publish them.

What it asks for

Environment variables it asks for: 4, secrets among them: 2. As declared on: Official MCP Registry.

  • ZSCALER_CLIENT_ID secret required
  • ZSCALER_CLIENT_SECRET secret required
  • ZSCALER_CUSTOMER_ID required
  • ZSCALER_VANITY_DOMAIN required

Environment variables it asks for: 10, secrets among them: 5. As declared on: Docker MCP Catalog.

  • ZSCALER_CLIENT_ID secret required
  • ZSCALER_CLIENT_SECRET secret required
  • ZSCALER_CLOUD secret required
  • ZSCALER_CUSTOMER_ID secret required
  • ZSCALER_MCP_DISABLED_SERVICES
  • ZSCALER_MCP_DISABLED_TOOLS
  • ZSCALER_MCP_SKIP_CONFIRMATIONS
  • ZSCALER_MCP_WRITE_ENABLED
  • ZSCALER_MCP_WRITE_TOOLS
  • ZSCALER_VANITY_DOMAIN secret required

Names only: we keep no values, examples or descriptions of these variables. OAuth scopes and install-time settings are not published by the marketplaces we read.

What it runs besides MCP

Commands: 20 As declared on: Claude Code: claude-plugins-official.

  • app-health
  • audit-software
  • audit-ssl
  • check-access
  • compare-locations
  • create-access-rule
  • create-forwarding-rule
  • create-server-group
  • create-timeout-rule
  • diagnose-deeptrace
  • investigate-alerts
  • investigate-incident
Show the remaining 8
  • investigate-sandbox
  • investigate-url
  • onboard-app
  • onboard-location
  • review-attack-surface
  • troubleshoot-connector
  • troubleshoot-experience
  • troubleshoot-user

Rules: 7 As declared on: Claude Code: claude-plugins-official.

  • cross-service-overlap
  • write-operation-safety
  • zdx-read-only
  • zia-activation-required
  • zms-graphql-conventions
  • zpa-dependency-chain
  • zscaler-tool-conventions

Who answers for it

zscaler

  • No marketplace we read marks it or its publisher as verified.
  • License: MIT.
  • The repository github.com/zscaler/zscaler-mcp-server belongs to the account the publisher is listed under on Official MCP Registry.

How it has changed

Its tools, settings, hooks and composition have not changed since we started watching it.

In context

  • Median number of secrets an MCP server asks for on the marketplaces we read: 0.0. This one asks for: 5.
  • Share of MCP servers that run on a remote server: 63%.

Where it is published and how its figures have moved

Data comes from the Official MCP Registry (registry.modelcontextprotocol.io), CC0 1.0. Data comes from the public marketplace file https://github.com/anthropics/claude-plugins-official/blob/HEAD/.claude-plugin/marketplace.json. Data comes from the Docker MCP Catalog (desktop.docker.com/mcp/catalog) and Docker Hub. Figures come from our own regular passes over the marketplaces, last read on . We publish no contact details for plugin publishers.

Where the data comes from: how the catalog is built