[{"data":1,"prerenderedAt":844},["ShallowReactive",2],{"blog-post-zammad-mcp-server-vergleich-en":3},{"id":4,"title":5,"body":6,"date":833,"description":834,"draft":835,"extension":836,"meta":837,"navigation":839,"path":840,"seo":841,"stem":842,"__hash__":843},"blogEn\u002Fblog\u002Fzammad-mcp-server-vergleich.md","The Best Zammad MCP Server? basher83 vs. Softoft-Orga in a Hard Test",{"type":7,"value":8,"toc":815},"minimark",[9,13,26,42,45,50,55,58,94,98,101,123,125,129,287,289,293,297,300,436,440,443,467,471,474,494,498,518,520,524,531,535,677,681,780,782,786,789,803,811],[10,11,5],"h1",{"id":12},"the-best-zammad-mcp-server-basher83-vs-softoft-orga-in-a-hard-test",[14,15,16,17,21,22,25],"p",{},"The ",[18,19,20],"strong",{},"Model Context Protocol (MCP)",", initiated by Anthropic, has rapidly established itself as the industry standard for connecting AI assistants (such as Claude Desktop, Cursor, or Copilot) with external data sources and APIs. For the popular open-source ticketing system ",[18,23,24],{},"Zammad",", two outstanding MCP server implementations now exist, enabling AI models to interact directly with tickets, users, and organizations via natural language.",[14,27,28,29,32,33,36,37,41],{},"Since these integrations focus on different priorities, taking a close look at their architectures, licenses, and security features is worthwhile. In this post, we compare the community-driven server from ",[18,30,31],{},"basher83"," with the production-oriented solution from ",[18,34,35],{},"Softoft-Orga"," (",[38,39,40],"code",{},"zammad-mcp-server",").",[43,44],"hr",{},[46,47,49],"h2",{"id":48},"the-candidates-at-a-glance","The Candidates at a Glance",[51,52,54],"h3",{"id":53},"_1-zammad-mcp-by-basher83","1. Zammad MCP by basher83",[14,56,57],{},"This project is an established, highly interactive community solution. It features a wide range of functions tailored especially to power users and developers who want to access Zammad directly from their local LLM runtime environments.",[59,60,61,75,88],"ul",{},[62,63,64,67,68],"li",{},[18,65,66],{},"GitHub Repository:"," ",[69,70,74],"a",{"href":71,"rel":72},"https:\u002F\u002Fgithub.com\u002Fbasher83\u002FZammad-MCP",[73],"nofollow","basher83\u002FZammad-MCP",[62,76,77,67,80,83,84,87],{},[18,78,79],{},"PyPI Package:",[38,81,82],{},"iflow-mcp-basher83-zammad"," (registered on our hub under ",[69,85,86],{"href":86},"\u002Fpackages\u002Fiflow-mcpbasher83-zammad",")",[62,89,90,93],{},[18,91,92],{},"License:"," AGPL-3.0-or-later (closely aligned with the open-source licensing of the Zammad core project)",[51,95,97],{"id":96},"_2-zammad-mcp-server-by-softoft-orga","2. Zammad MCP Server by Softoft-Orga",[14,99,100],{},"This server is targeted at production-ready enterprise deployments. The focus lies on a fine-grained permission concept, flexible provisioning (SSE transport for distributed architectures), and modular connection to larger automation setups.",[59,102,103,112,118],{},[62,104,105,67,107],{},[18,106,66],{},[69,108,111],{"href":109,"rel":110},"https:\u002F\u002Fgithub.com\u002FSoftoft-Orga\u002Fzammad-mcp-server",[73],"Softoft-Orga\u002Fzammad-mcp-server",[62,113,114,67,116],{},[18,115,79],{},[38,117,40],{},[62,119,120,122],{},[18,121,92],{}," MIT (extremely permissive license, ideal for commercial integrations and customizations)",[43,124],{},[46,126,128],{"id":127},"direct-feature-comparison","Direct Feature Comparison",[130,131,132,149],"table",{},[133,134,135],"thead",{},[136,137,138,143,146],"tr",{},[139,140,142],"th",{"align":141},"left","Feature \u002F Property",[139,144,145],{"align":141},"basher83 (iflow-mcp-basher83-zammad)",[139,147,148],{"align":141},"Softoft-Orga (zammad-mcp-server)",[150,151,152,166,185,198,228,244,261,274],"tbody",{},[136,153,154,160,163],{},[155,156,157],"td",{"align":141},[18,158,159],{},"License",[155,161,162],{"align":141},"AGPL-3.0 (Copyleft)",[155,164,165],{"align":141},"MIT (Permissive)",[136,167,168,173,179],{},[155,169,170],{"align":141},[18,171,172],{},"Tool Naming",[155,174,175,176,87],{"align":141},"Prefixed (e.g., ",[38,177,178],{},"zammad_search_tickets",[155,180,181,182,87],{"align":141},"Flat\u002FClear (e.g., ",[38,183,184],{},"search_tickets",[136,186,187,192,195],{},[155,188,189],{"align":141},[18,190,191],{},"Number of Tools",[155,193,194],{"align":141},"~20 standard operations",[155,196,197],{"align":141},"30+ tools (full API coverage)",[136,199,200,205,211],{},[155,201,202],{"align":141},[18,203,204],{},"Access Control (ACL)",[155,206,207,208],{"align":141},"Simple blacklist via ",[38,209,210],{},"MCP_DENIED_TOOLS",[155,212,213,214,217,218,217,221,217,224,227],{"align":141},"Fine-grained tiers (",[38,215,216],{},"DENIED",", ",[38,219,220],{},"READ_ONLY",[38,222,223],{},"WRITE",[38,225,226],{},"ADMIN","), category and group restrictions",[136,229,230,235,238],{},[155,231,232],{"align":141},[18,233,234],{},"SSE Transport (Remote)",[155,236,237],{"align":141},"Requires additional wrapper \u002F SSE proxy",[155,239,240,241,87],{"align":141},"Built-in natively (",[38,242,243],{},"--transport sse --port 8000",[136,245,246,251,258],{},[155,247,248],{"align":141},[18,249,250],{},"Resources & Prompts",[155,252,253,254,257],{"align":141},"Comprehensive resources (",[38,255,256],{},"zammad:\u002F\u002Fticket\u002F{id}",") & prompt templates",[155,259,260],{"align":141},"Focus on core APIs and programmatic integration",[136,262,263,268,271],{},[155,264,265],{"align":141},[18,266,267],{},"Caching",[155,269,270],{"align":141},"Caching for groups, priorities, and ticket states",[155,272,273],{"align":141},"Intelligent caching of static system metadata",[136,275,276,281,284],{},[155,277,278],{"align":141},[18,279,280],{},"Interface Coverage",[155,282,283],{"align":141},"Tickets, articles, attachments (Base64), tags, users, orgs, groups, states, stats",[155,285,286],{"align":141},"Tickets, articles, users, orgs, groups, caching, system health checks",[43,288],{},[46,290,292],{"id":291},"detailed-analysis-of-differences","Detailed Analysis of Differences",[51,294,296],{"id":295},"_1-permissions-and-security-access-control","1. Permissions and Security (Access Control)",[14,298,299],{},"Companies granting AI models access to their internal ticketing system must enforce strict security guidelines. This is where both servers differ most significantly:",[59,301,302,310],{},[62,303,304,306,307,309],{},[18,305,31],{}," offers robust yet simple protection: Using the environment variable ",[38,308,210],{},", specific tools (such as deletion or update functions) can be disabled completely.",[62,311,312,314,315,318,319],{},[18,313,35],{}," implements a ",[18,316,317],{},"fine-grained permission concept",". Beyond a tool blacklist, access rights can be restricted at the category level (e.g., tickets read-only, users blocked) or even at the Zammad group level (e.g., granting access only to tickets in the \"Support\" and \"Sales\" groups). Furthermore, security policies can be adjusted declaratively in Python code:\n",[320,321,326],"pre",{"className":322,"code":323,"language":324,"meta":325,"style":325},"language-python shiki shiki-themes one-dark-pro","policy = AccessPolicy(\n    default_permission=Permission.READ_ONLY,\n    category_permissions={\n        ToolCategory.TICKETS: Permission.WRITE,\n        ToolCategory.ADMIN: Permission.DENIED,\n    },\n    denied_tools={\"delete_ticket\"},\n)\n","python","",[38,327,328,348,366,377,393,406,412,430],{"__ignoreMap":325},[329,330,333,337,341,345],"span",{"class":331,"line":332},"line",1,[329,334,336],{"class":335},"sn6KH","policy ",[329,338,340],{"class":339},"sjrmR","=",[329,342,344],{"class":343},"sVbv2"," AccessPolicy",[329,346,347],{"class":335},"(\n",[329,349,351,355,357,360,363],{"class":331,"line":350},2,[329,352,354],{"class":353},"s_ZVi","    default_permission",[329,356,340],{"class":339},[329,358,359],{"class":335},"Permission.",[329,361,220],{"class":362},"sVC51",[329,364,365],{"class":335},",\n",[329,367,369,372,374],{"class":331,"line":368},3,[329,370,371],{"class":353},"    category_permissions",[329,373,340],{"class":339},[329,375,376],{"class":335},"{\n",[329,378,380,383,386,389,391],{"class":331,"line":379},4,[329,381,382],{"class":335},"        ToolCategory.",[329,384,385],{"class":362},"TICKETS",[329,387,388],{"class":335},": Permission.",[329,390,223],{"class":362},[329,392,365],{"class":335},[329,394,396,398,400,402,404],{"class":331,"line":395},5,[329,397,382],{"class":335},[329,399,226],{"class":362},[329,401,388],{"class":335},[329,403,216],{"class":362},[329,405,365],{"class":335},[329,407,409],{"class":331,"line":408},6,[329,410,411],{"class":335},"    },\n",[329,413,415,418,420,423,427],{"class":331,"line":414},7,[329,416,417],{"class":353},"    denied_tools",[329,419,340],{"class":339},[329,421,422],{"class":335},"{",[329,424,426],{"class":425},"subq3","\"delete_ticket\"",[329,428,429],{"class":335},"},\n",[329,431,433],{"class":331,"line":432},8,[329,434,435],{"class":335},")\n",[51,437,439],{"id":438},"_2-naming-conventions-and-tool-collisions","2. Naming Conventions and Tool Collisions",[14,441,442],{},"Running multiple MCP servers simultaneously in your AI client (e.g., Claude Desktop) can lead to tool name collisions:",[59,444,445,458],{},[62,446,447,449,450,453,454,457],{},[18,448,31],{}," uses the ",[38,451,452],{},"zammad_"," prefix for all offered tools (e.g., ",[38,455,456],{},"zammad_get_ticket","). This reliably prevents naming conflicts in the AI context.",[62,459,460,462,463,466],{},[18,461,35],{}," relies on short, direct method names (e.g., ",[38,464,465],{},"get_ticket","). This is easier for dedicated, specialized AI agents to read, but requires attention when other MCP servers with similar generic tools run in parallel.",[51,468,470],{"id":469},"_3-network-and-deployment-architecture","3. Network and Deployment Architecture",[14,472,473],{},"How is the MCP server started and connected?",[59,475,476,485],{},[62,477,478,480,481,484],{},[18,479,31],{}," is optimized for classic stdio scenarios (called directly via ",[38,482,483],{},"uvx"," or Docker on the same machine running the client). It sets up exceptionally well as a local assistant.",[62,486,487,489,490,493],{},[18,488,35],{}," offers ",[18,491,492],{},"native SSE support"," (Server-Sent Events). This allows the server to run as a standalone web service within the corporate network. External clients or centralized agent platforms can connect via HTTP\u002FSSE instead of requiring the process to run locally on the desktop.",[51,495,497],{"id":496},"_4-integration-into-ai-infrastructure","4. Integration into AI Infrastructure",[59,499,500,513],{},[62,501,16,502,504,505,508,509,512],{},[18,503,31],{}," server brings its own MCP prompts (such as ",[38,506,507],{},"analyze_ticket"," or ",[38,510,511],{},"draft_response",") and resource URIs directly. This enables the AI assistant to instantly know how to structure typical workflows.",[62,514,16,515,517],{},[18,516,35],{}," server is designed as a modular building block and suits deployments in larger automation pipelines—such as classifying and answering tickets via on-premise models while agents make ad-hoc queries via MCP.",[43,519],{},[46,521,523],{"id":522},"configuration-examples","Configuration Examples",[14,525,526,527,530],{},"To test both servers directly, you can find the corresponding configurations for your ",[38,528,529],{},"claude_desktop_config.json"," or Cursor MCP settings below.",[51,532,534],{"id":533},"configuration-for-basher83-via-pypiuvx","Configuration for basher83 (via PyPI\u002Fuvx)",[320,536,540],{"className":537,"code":538,"language":539,"meta":325,"style":325},"language-json shiki shiki-themes one-dark-pro","{\n  \"mcpServers\": {\n    \"zammad-community\": {\n      \"command\": \"uvx\",\n      \"args\": [\n        \"--from\",\n        \"git+https:\u002F\u002Fgithub.com\u002Fbasher83\u002Fzammad-mcp.git\",\n        \"mcp-zammad\"\n      ],\n      \"env\": {\n        \"ZAMMAD_URL\": \"https:\u002F\u002Fyour-instance.zammad.com\u002Fapi\u002Fv1\",\n        \"ZAMMAD_HTTP_TOKEN\": \"your_api_token\",\n        \"MCP_DENIED_TOOLS\": \"zammad_delete_attachment\"\n      }\n    }\n  }\n}\n","json",[38,541,542,546,555,562,575,583,590,597,602,608,616,629,642,653,659,665,671],{"__ignoreMap":325},[329,543,544],{"class":331,"line":332},[329,545,376],{"class":335},[329,547,548,552],{"class":331,"line":350},[329,549,551],{"class":550},"sVyAn","  \"mcpServers\"",[329,553,554],{"class":335},": {\n",[329,556,557,560],{"class":331,"line":368},[329,558,559],{"class":550},"    \"zammad-community\"",[329,561,554],{"class":335},[329,563,564,567,570,573],{"class":331,"line":379},[329,565,566],{"class":550},"      \"command\"",[329,568,569],{"class":335},": ",[329,571,572],{"class":425},"\"uvx\"",[329,574,365],{"class":335},[329,576,577,580],{"class":331,"line":395},[329,578,579],{"class":550},"      \"args\"",[329,581,582],{"class":335},": [\n",[329,584,585,588],{"class":331,"line":408},[329,586,587],{"class":425},"        \"--from\"",[329,589,365],{"class":335},[329,591,592,595],{"class":331,"line":414},[329,593,594],{"class":425},"        \"git+https:\u002F\u002Fgithub.com\u002Fbasher83\u002Fzammad-mcp.git\"",[329,596,365],{"class":335},[329,598,599],{"class":331,"line":432},[329,600,601],{"class":425},"        \"mcp-zammad\"\n",[329,603,605],{"class":331,"line":604},9,[329,606,607],{"class":335},"      ],\n",[329,609,611,614],{"class":331,"line":610},10,[329,612,613],{"class":550},"      \"env\"",[329,615,554],{"class":335},[329,617,619,622,624,627],{"class":331,"line":618},11,[329,620,621],{"class":550},"        \"ZAMMAD_URL\"",[329,623,569],{"class":335},[329,625,626],{"class":425},"\"https:\u002F\u002Fyour-instance.zammad.com\u002Fapi\u002Fv1\"",[329,628,365],{"class":335},[329,630,632,635,637,640],{"class":331,"line":631},12,[329,633,634],{"class":550},"        \"ZAMMAD_HTTP_TOKEN\"",[329,636,569],{"class":335},[329,638,639],{"class":425},"\"your_api_token\"",[329,641,365],{"class":335},[329,643,645,648,650],{"class":331,"line":644},13,[329,646,647],{"class":550},"        \"MCP_DENIED_TOOLS\"",[329,649,569],{"class":335},[329,651,652],{"class":425},"\"zammad_delete_attachment\"\n",[329,654,656],{"class":331,"line":655},14,[329,657,658],{"class":335},"      }\n",[329,660,662],{"class":331,"line":661},15,[329,663,664],{"class":335},"    }\n",[329,666,668],{"class":331,"line":667},16,[329,669,670],{"class":335},"  }\n",[329,672,674],{"class":331,"line":673},17,[329,675,676],{"class":335},"}\n",[51,678,680],{"id":679},"configuration-for-softoft-orga-via-pypiuvx","Configuration for Softoft-Orga (via PyPI\u002Fuvx)",[320,682,684],{"className":537,"code":683,"language":539,"meta":325,"style":325},"{\n  \"mcpServers\": {\n    \"zammad-enterprise\": {\n      \"command\": \"uvx\",\n      \"args\": [\n        \"zammad-mcp-server\"\n      ],\n      \"env\": {\n        \"ZAMMAD_URL\": \"https:\u002F\u002Fyour-instance.zammad.com\",\n        \"ZAMMAD_HTTP_TOKEN\": \"your_api_token\",\n        \"MCP_DENIED_TOOLS\": \"delete_ticket,delete_user,delete_organization\"\n      }\n    }\n  }\n}\n",[38,685,686,690,696,703,713,719,724,728,734,745,755,764,768,772,776],{"__ignoreMap":325},[329,687,688],{"class":331,"line":332},[329,689,376],{"class":335},[329,691,692,694],{"class":331,"line":350},[329,693,551],{"class":550},[329,695,554],{"class":335},[329,697,698,701],{"class":331,"line":368},[329,699,700],{"class":550},"    \"zammad-enterprise\"",[329,702,554],{"class":335},[329,704,705,707,709,711],{"class":331,"line":379},[329,706,566],{"class":550},[329,708,569],{"class":335},[329,710,572],{"class":425},[329,712,365],{"class":335},[329,714,715,717],{"class":331,"line":395},[329,716,579],{"class":550},[329,718,582],{"class":335},[329,720,721],{"class":331,"line":408},[329,722,723],{"class":425},"        \"zammad-mcp-server\"\n",[329,725,726],{"class":331,"line":414},[329,727,607],{"class":335},[329,729,730,732],{"class":331,"line":432},[329,731,613],{"class":550},[329,733,554],{"class":335},[329,735,736,738,740,743],{"class":331,"line":604},[329,737,621],{"class":550},[329,739,569],{"class":335},[329,741,742],{"class":425},"\"https:\u002F\u002Fyour-instance.zammad.com\"",[329,744,365],{"class":335},[329,746,747,749,751,753],{"class":331,"line":610},[329,748,634],{"class":550},[329,750,569],{"class":335},[329,752,639],{"class":425},[329,754,365],{"class":335},[329,756,757,759,761],{"class":331,"line":618},[329,758,647],{"class":550},[329,760,569],{"class":335},[329,762,763],{"class":425},"\"delete_ticket,delete_user,delete_organization\"\n",[329,765,766],{"class":331,"line":631},[329,767,658],{"class":335},[329,769,770],{"class":331,"line":644},[329,771,664],{"class":335},[329,773,774],{"class":331,"line":655},[329,775,670],{"class":335},[329,777,778],{"class":331,"line":661},[329,779,676],{"class":335},[43,781],{},[46,783,785],{"id":784},"conclusion-which-zammad-mcp-server-is-right-for-you","Conclusion: Which Zammad MCP Server Is Right for You?",[14,787,788],{},"Both projects impressively demonstrate the potential of MCP in the ITSM environment. Your choice primarily depends on your use case:",[59,790,791,797],{},[62,792,793,796],{},[18,794,795],{},"Choose the basher83 server"," if you are a developer or IT professional looking for a fast, feature-rich connection for your local Claude or Cursor client. The built-in prompts and prefixed tool names make daily hacking extremely comfortable.",[62,798,799,802],{},[18,800,801],{},"Choose the Softoft-Orga server"," if you are connecting Zammad in an enterprise environment. When you need to enforce fine-grained access controls, run the server as a centralized SSE service in a Kubernetes cluster, or embed it into a larger automation pipeline, this server is the right choice.",[14,804,805,806,810],{},"You can find further details on compatible extensions and plugins for Zammad in our ",[69,807,809],{"href":808},"\u002Fzammad-plugins","Zammad plugin directory",".",[812,813,814],"style",{},"html pre.shiki code .sn6KH, html code.shiki .sn6KH{--shiki-default:#ABB2BF}html pre.shiki code .sjrmR, html code.shiki .sjrmR{--shiki-default:#56B6C2}html pre.shiki code .sVbv2, html code.shiki .sVbv2{--shiki-default:#61AFEF}html pre.shiki code .s_ZVi, html code.shiki .s_ZVi{--shiki-default:#E06C75;--shiki-default-font-style:italic}html pre.shiki code .sVC51, html code.shiki .sVC51{--shiki-default:#D19A66}html pre.shiki code .subq3, html code.shiki .subq3{--shiki-default:#98C379}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html pre.shiki code .sVyAn, html code.shiki .sVyAn{--shiki-default:#E06C75}",{"title":325,"searchDepth":350,"depth":350,"links":816},[817,821,822,828,832],{"id":48,"depth":350,"text":49,"children":818},[819,820],{"id":53,"depth":368,"text":54},{"id":96,"depth":368,"text":97},{"id":127,"depth":350,"text":128},{"id":291,"depth":350,"text":292,"children":823},[824,825,826,827],{"id":295,"depth":368,"text":296},{"id":438,"depth":368,"text":439},{"id":469,"depth":368,"text":470},{"id":496,"depth":368,"text":497},{"id":522,"depth":350,"text":523,"children":829},[830,831],{"id":533,"depth":368,"text":534},{"id":679,"depth":368,"text":680},{"id":784,"depth":350,"text":785},"2026-05-27","A detailed comparison of the two open-source Model Context Protocol (MCP) servers for Zammad. Learn how to securely connect your AI assistants (Claude, Cursor) to your helpdesk.",false,"md",{"language":838},"en",true,"\u002Fblog\u002Fzammad-mcp-server-vergleich",{"title":5,"description":834},"blog\u002Fzammad-mcp-server-vergleich","ntpCKocRasmOsht_erUAKegF0DYvDVoTOpfMMf3x-ms",1787732994322]