Can AI agents automate Zscaler Zero Trust Exchange?
Zscaler · saas · identityenterprisedevsecops
Zscaler Zero Trust Exchange is automatable today through the vendor MCP server, with a public-preview limit. This record is the Zero Trust Exchange surface that server exposes. It is not Cloudflare, Okta, or CrowdStrike Falcon. The Zscaler GitHub organization publishes zscaler-mcp-server. The README says the project is a public preview and asks operators to avoid production deployments before 1.0. The server uses OneAPI credentials only. Those credentials are a ZIdentity API client id and client secret, or a private key, plus customer id and vanity domain. The README says one credential set is used for ZIA, ZPA, ZCC, ZDX, Zscaler Cellular, ZTW, ZIdentity, ZMS, Z-Insights, and EASM. The default mode is read-only. Write tools require both an enable flag and an explicit allowlist. The README describes 402 tools grouped into toolsets. The package is installed as zscaler-mcp and can run from the command line. The OneAPI understanding page at help.zscaler.com did not return article text without JavaScript, so API coverage, protocol, and SDK support stay unknown. Connector catalogs were not opened. Computer-use viability is unassessed. MCP scores 6 because the server is an official, maintained, broad client that Zscaler still marks as a public preview. The API path is not scored. The zscaler-mcp command starts that server; it was not treated as a separate product CLI.
Best path today: mcp · Overall automatability: 6/10
Modalities
| Modality | Status | Detail |
|---|---|---|
| API | yes | oauth2 coverage: unknown · docs |
| SDK | unknown | official: unknown |
| MCP | yes | verdict: official |
| Integrations | unknown | |
| CLI | unknown | |
| Extensibility | unknown | webhooks: unknown |
| Data access | export: unknown · import: unknown | |
| RPA / UI automation | unknown | No repeatable UI probe was run. Zscaler documents a first-party MCP server that calls OneAPI. The OneAPI reference page did not render without JavaScript on this pass.
|
| Computer use | unknown | measured verdicts only — "unknown" means not yet probed by us |
Scores
| api | mcp | integrations | cli | rpa | computer use | overall |
|---|---|---|---|---|---|---|
| — | 6 | — | — | — | — | 6 |
Evidence
| Fact | Tier | Source | Date |
|---|---|---|---|
homepage | declared | source | 2026-09-25 |
license | scraped | source | 2026-09-25 |
deployment | declared | source | 2026-09-25 |
platforms | declared | source | 2026-09-25 |
modalities.api.exists | declared | source | 2026-09-25 |
modalities.api.auth[0] | declared | source | 2026-09-25 |
modalities.api.coverage | declared | source | 2026-09-25 |
modalities.api.docs | declared | source | 2026-09-25 |
modalities.mcp.first_party | declared | source | 2026-09-25 |
modalities.mcp.verdict | declared | source | 2026-09-25 |
verdict.scores.mcp | declared | source | 2026-09-25 |
freshness.watch[0].url | declared | source | 2026-09-25 |
freshness.watch[1].url | declared | source | 2026-09-25 |
Related tools
Other products in this database that share a category with Zscaler Zero Trust Exchange.
Last verified 2026-09-25 · volatility high · JSON record