Back to Browse

Tickiti MCP Server

Developer ToolsModerate5.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Connect AI assistants to the Tickiti helpdesk API: tickets, queries, reports and admin.

About

Connect AI assistants to the Tickiti helpdesk API: tickets, queries, reports and admin.

Security Report

5.2
Moderate5.2Moderate Risk

This is a well-designed MCP server that acts as a secure thin shim over the Tickiti API. Authentication and authorization are properly delegated to the underlying Tickiti API via bearer tokens with scope-based access control. The codebase is clean with appropriate input validation via Zod, proper error handling, and no malicious patterns detected. Minor code quality concerns around broad error handling and lack of request/response logging do not significantly impact security. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity).

4 files analyzed ยท 6 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-tickiti-tickiti-mcp": {
      "args": [
        "-y",
        "tickiti-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

tickiti-mcp

An MCP (Model Context Protocol) server that exposes the Tickiti helpdesk API to AI assistants such as Claude. It is a thin shim over the Tickiti Public API v1 (/api/v1/...): each MCP tool forwards to a v1 endpoint, adding your bearer token and โ€” for writes โ€” an idempotency key. The token's abilities are the security boundary: the server only relays calls, it never widens them, so a read-only token gives a read-only assistant.

๐Ÿ“– Full documentation: https://docs.tickiti.com/topic/mcp_server/

Tools

The ticket tools have full, validated inputs; the rest of the API is reachable through two general tools, so the whole surface is available without a separate tool per endpoint.

ToolAbilityPurpose
create_tickettickets:writeOpen a ticket (subject+content, template, or intervention)
respond_to_tickettickets:writePost a response to an existing ticket
query_ticketstickets:readList tickets for a perspective
list_perspectivessettings:readList saved perspectives
list_watchlistssettings:readList watchlists
list_stock_responsessettings:readList stock responses
list_queuesworkflow:readList ticket queues
list_workflowworkflow:readList resolution categories, interventions or escalations
run_reportreports:readRun an analytics report
list_endpointsโ€”Discover every available API endpoint, with abilities and parameters
tickiti_callper endpointCall any /api/v1 endpoint by family and action

For anything beyond the named tools (mail, templates, workflow writes, administration, supervisor), the assistant uses list_endpoints to discover the action, then tickiti_call to run it โ€” covering all of the v1 API.

Requirements

  • Node.js 20 or newer
  • A Tickiti API token, minted from Administration โ†’ API keys, scoped to the abilities you want the assistant to have
  • An MCP-capable client โ€” e.g. Claude Code or the Claude desktop app

Install

git clone https://github.com/tickiti/tickiti-mcp.git
cd tickiti-mcp
npm install
npm run build

The built server is dist/server.js.

Configure

The server reads two environment variables (it fails fast on startup if either is missing):

VariablePurpose
TICKITI_API_BASEYour Tickiti install's public address, no trailing slash โ€” e.g. https://support.example.com. The server appends /api/v1/โ€ฆ.
TICKITI_API_TOKENThe bearer token. Its abilities determine what the assistant can do.

Use with Claude Code

claude mcp add tickiti \
  --env TICKITI_API_BASE=https://support.example.com \
  --env TICKITI_API_TOKEN=YOUR_TICKITI_API_TOKEN \
  -- node /absolute/path/to/tickiti-mcp/dist/server.js

Confirm with claude mcp list (or /mcp in a session). Remove with claude mcp remove tickiti.

Other MCP clients configure servers in their own settings file, but the shape is the same: run node /absolute/path/to/tickiti-mcp/dist/server.js as a stdio server with TICKITI_API_BASE and TICKITI_API_TOKEN set in its environment.

Permissions & security

The server adds no permissions of its own. Every call runs as the staff user the token belongs to, gated by the token's abilities โ€” exactly as a direct API call would be. To limit what an assistant can do, mint a narrowly-scoped token:

  • A read-only token (e.g. tickets:read, reports:read) gives an assistant that can look but not change anything.
  • Grant write abilities only for the families the assistant needs to act on.
  • If a call is refused, the server reports the reason (missing ability, role or plan).

The two ticket-writing tools send an idempotency key with every call, so a retried request never creates a duplicate ticket or response.

How it works

FileRole
src/client.tsRequest core: base URL, bearer auth, idempotency, error normalisation
src/result.tsMaps an API result into the MCP tool-result envelope
src/manifest.tsHelpers over the generated route manifest (lookup, path building)
src/generated/manifest.tsAuto-generated route table (do not edit)
src/tools/tickets.tsTickets family โ€” verified input schemas
src/tools/reads.tsNamed read tools (settings / workflow / reports)
src/tools/generic.tslist_endpoints + tickiti_call
src/server.tsEntry point: registers tools, connects the stdio transport
scripts/build-manifest.mjsRegenerates the manifest from the Tickiti route table

Maintainers

src/generated/manifest.ts is generated from Tickiti's own route table (php artisan route:list --json), so abilities, roles, plan gates and path params are never hand-maintained. Regenerate against a Tickiti checkout after the API changes:

TICKITI_DIR=/path/to/tickiti npm run manifest

There is an end-to-end sweep over every endpoint in tests/all-paths.mjs (npm run test:paths, needs a base URL and a full-ability token against a scratch instance).

License

MIT ยฉ Oxenic

Reviews

No reviews yet

Be the first to review this server!