{
 "categories": [
  "identity",
  "enterprise",
  "devsecops"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-09-25",
   "fact": "homepage",
   "note": "The Zscaler organization README is the public entry point opened for the MCP server that operates the Zero Trust Exchange.",
   "source": "https://github.com/zscaler/zscaler-mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-25",
   "fact": "license",
   "note": "The MCP repository license is MIT. The Zero Trust Exchange product itself is a commercial Zscaler service, which is the license recorded here.",
   "source": "https://api.github.com/repos/zscaler/zscaler-mcp-server",
   "tier": "scraped"
  },
  {
   "date": "2026-09-25",
   "fact": "deployment",
   "note": "The README authenticates to Zscaler cloud products through OneAPI and a vanity domain, which is a hosted control plane.",
   "source": "https://github.com/zscaler/zscaler-mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-25",
   "fact": "platforms",
   "note": "API clients are created in the ZIdentity platform, a web console linked from the README.",
   "source": "https://github.com/zscaler/zscaler-mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-25",
   "fact": "modalities.api.exists",
   "note": "The README says the server uses OneAPI authentication exclusively and points to Understanding OneAPI.",
   "source": "https://github.com/zscaler/zscaler-mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-25",
   "fact": "modalities.api.auth[0]",
   "note": "OneAPI credentials are an OAuth client id and client secret, or a private key, created as an API client in ZIdentity.",
   "source": "https://github.com/zscaler/zscaler-mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-25",
   "fact": "modalities.api.coverage",
   "note": "The Understanding OneAPI page did not return article text without JavaScript, so API coverage stays unknown.",
   "source": "https://help.zscaler.com/oneapi/understanding-oneapi",
   "tier": "declared"
  },
  {
   "date": "2026-09-25",
   "fact": "modalities.api.docs",
   "note": "The README links this page as the OneAPI explanation. The page shell loaded and the article body did not.",
   "source": "https://help.zscaler.com/oneapi/understanding-oneapi",
   "tier": "declared"
  },
  {
   "date": "2026-09-25",
   "fact": "modalities.mcp.first_party",
   "note": "The zscaler GitHub organization publishes zscaler-mcp-server and describes it as the MCP server for the Zero Trust Exchange.",
   "source": "https://github.com/zscaler/zscaler-mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-25",
   "fact": "modalities.mcp.verdict",
   "note": "The README is the vendor repository and marks the project as a public preview, so the verdict is official.",
   "source": "https://github.com/zscaler/zscaler-mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-25",
   "fact": "verdict.scores.mcp",
   "note": "Official MCP server with a large tool catalog, read-only by default, and an explicit public-preview warning against production use. Score 6.",
   "source": "https://github.com/zscaler/zscaler-mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-25",
   "fact": "freshness.watch[0].url",
   "note": "Opened the README. GitHub API reported the repository unarchived, MIT, and pushed at 2026-09-21T06:17:37Z.",
   "source": "https://github.com/zscaler/zscaler-mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-25",
   "fact": "freshness.watch[1].url",
   "note": "Opened the OneAPI page linked from the README. The article body did not render.",
   "source": "https://help.zscaler.com/oneapi/understanding-oneapi",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-09-25",
  "volatility": "high",
  "watch": [
   {
    "type": "repo",
    "url": "https://github.com/zscaler/zscaler-mcp-server"
   },
   {
    "type": "docs",
    "url": "https://help.zscaler.com/oneapi/understanding-oneapi"
   }
  ]
 },
 "homepage": "https://github.com/zscaler/zscaler-mcp-server",
 "id": "zscaler",
 "license": "commercial",
 "modalities": {
  "agent_docs": {
   "llms_txt": "unknown"
  },
  "api": {
   "auth": [
    "oauth2"
   ],
   "coverage": "unknown",
   "docs": "https://help.zscaler.com/oneapi/understanding-oneapi",
   "exists": true,
   "kinds": []
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [],
   "import": []
  },
  "extensibility": {
   "scripting": [],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. Zscaler documents a first-party MCP server that calls OneAPI. The OneAPI reference page did not render without JavaScript on this pass.\n",
   "ui_stack": [],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "Zscaler Zero Trust Exchange",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "cloudflare",
   "okta",
   "crowdstrike-falcon"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Zscaler",
 "verdict": {
  "best_path": "mcp",
  "scores": {
   "api": null,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": 6,
   "overall": 6,
   "rpa": null
  },
  "summary": "Zscaler Zero Trust Exchange is automatable today through the vendor MCP server, with a public-preview limit. This record is the Zero Trust Exchange surface that server exposes. It is not Cloudflare, Okta, or CrowdStrike Falcon. The Zscaler GitHub organization publishes zscaler-mcp-server. The README says the project is a public preview and asks operators to avoid production deployments before 1.0. The server uses OneAPI credentials only. Those credentials are a ZIdentity API client id and client secret, or a private key, plus customer id and vanity domain. The README says one credential set is used for ZIA, ZPA, ZCC, ZDX, Zscaler Cellular, ZTW, ZIdentity, ZMS, Z-Insights, and EASM. The default mode is read-only. Write tools require both an enable flag and an explicit allowlist. The README describes 402 tools grouped into toolsets. The package is installed as zscaler-mcp and can run from the command line. The OneAPI understanding page at help.zscaler.com did not return article text without JavaScript, so API coverage, protocol, and SDK support stay unknown. Connector catalogs were not opened. Computer-use viability is unassessed. MCP scores 6 because the server is an official, maintained, broad client that Zscaler still marks as a public preview. The API path is not scored. The zscaler-mcp command starts that server; it was not treated as a separate product CLI.\n"
 }
}