Back to Browse

Invgate Service Desk MCP Server

Developer ToolsUse Caution4.8MCP RegistryLocal
Free

Server data from the Official MCP Registry

InvGate Service Desk MCP: 96 tools/11 domains, 3-tier access (none/support/full), OTel.

About

InvGate Service Desk MCP: 96 tools/11 domains, 3-tier access (none/support/full), OTel.

Security Report

4.8
Use Caution4.8High Risk

This is a well-structured MCP server for InvGate Service Desk with solid security architecture. Authentication is properly implemented via HTTP Basic with API tokens stored in environment variables or config files (not hardcoded). Write operations are gated behind explicit opt-in profiles (none/support/full), and the codebase shows good input handling and validation patterns. Minor quality observations around broad exception handling and telemetry configuration do not materially impact the security posture. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

4 files analyzed · 8 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

What You'll Need

Set these up before or after installing:

InvGate SD instance base URL, e.g. https://acme.sd.cloud.invgate.netOptional

Environment variable: INVGATE_BASE_URL

InvGate Service Desk API tokenRequired

Environment variable: INVGATE_API_TOKEN

Write access profile: none (default, read-only) | support | fullOptional

Environment variable: INVGATE_WRITE_PROFILE

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-tracegazer-invgate-service-desk-mcp": {
      "env": {
        "INVGATE_BASE_URL": "your-invgate-base-url-here",
        "INVGATE_API_TOKEN": "your-invgate-api-token-here",
        "INVGATE_WRITE_PROFILE": "your-invgate-write-profile-here"
      },
      "args": [
        "invgate-service-desk-mcp"
      ],
      "command": "uvx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

invgate-service-desk-mcp

CI PyPI Python License: MIT MCP Registry Smithery

A Model Context Protocol server for InvGate Service Desk / Service Management.

Give your AI assistant full access to your InvGate Service Desk — query incidents, look up users, search the knowledge base, check assets, and manage tickets — all through natural language.

96 tools across 11 domains. Read-only by default, with optional write operations behind explicit opt-in.

Install in one click

The easiest way to use this server with Claude Desktop (and other MCPB-compatible clients) is the prebuilt bundle:

➡️ Download invgate-service-desk.mcpb — then double-click it. Claude Desktop opens the installer, prompts for your InvGate base URL and API token, and you're done. No Python, no npx/uvx, no config files.

The .mcpb is attached to every GitHub Release and mirrored on Smithery. Prefer a package manager or container? See Quick start below.

What can it do?

DomainToolsExamples
Catalog5List priorities, statuses, incident types, categories (with search), sources
Incidents34Get ticket details, list by status/agent/customer, create & update tickets, reassign, comment, manage approvals
Users & Groups7Look up users, find by email/phone, list group members
Knowledge Base10Search articles, browse categories, create & update articles
Custom Fields9List field definitions, get options (list/tree), fields by category
Organization11Helpdesks, levels, locations, company structure
Assets / CIs6Find assets linked to incidents, CI relationships
Time Tracking4View logged hours, log new time entries
Triggers2List automation rules and their executions
Workflows3Inspect workflow fields, processes, and field values
Breaking News5View announcements, statuses, types

63 read-only tools work out of the box. 33 write tools (incidents, KB, time tracking) activate only when you explicitly opt in.

Quick start

1. Install

pip install invgate-service-desk-mcp

Or run without installing (requires uv):

uvx invgate-service-desk-mcp

2. Connect to Claude Desktop

Add this to your claude_desktop_config.json:

{
  "mcpServers": {
    "invgate": {
      "command": "uvx",
      "args": ["invgate-service-desk-mcp"],
      "env": {
        "INVGATE_BASE_URL": "https://acme.sd.cloud.invgate.net",
        "INVGATE_API_TOKEN": "your-api-token"
      }
    }
  }
}

Restart Claude Desktop. That's it — start asking about your tickets.

{
  "mcpServers": {
    "invgate": {
      "command": "invgate-service-desk-mcp",
      "env": {
        "INVGATE_BASE_URL": "https://acme.sd.cloud.invgate.net",
        "INVGATE_API_TOKEN": "your-api-token"
      }
    }
  }
}

By default the server is read-only. Opt into writes with INVGATE_WRITE_PROFILE:

ProfileReadsWrites
none (default)everythingnothing
supporteverythingincidents (tickets, comments, reassign, approve) + time tracking
fulleverythingincidents + time tracking + Knowledge Base
{
  "mcpServers": {
    "invgate": {
      "command": "uvx",
      "args": ["invgate-service-desk-mcp"],
      "env": {
        "INVGATE_BASE_URL": "https://acme.sd.cloud.invgate.net",
        "INVGATE_API_TOKEN": "your-api-token",
        "INVGATE_WRITE_PROFILE": "support"
      }
    }
  }
}

Compatibility: the legacy INVGATE_ENABLE_WRITES=1 still works and maps to full. If both are set, the profile wins and a warning is printed to stderr. Note: support deliberately keeps the Knowledge Base read-only. An invalid profile name fails fast at startup.

Warning: write mode lets the connected agent create, modify, and delete real content through your InvGate credential. There is no API to delete a ticket — created tickets can only be cancelled, not removed.

3. Get your API token

In your InvGate Service Desk instance: Settings > Integrations > API (or ask your admin). The server authenticates via HTTP Basic with username api and your token as the password.

Configuration

Configuration resolves in this order (highest priority first):

  1. Environment variables (always win)
  2. TOML config at ~/.config/invgate-service-desk-mcp/config.toml
Env varTOML keyDescription
INVGATE_BASE_URLbase_urlInstance URL, e.g. https://acme.sd.cloud.invgate.net
INVGATE_API_TOKENapi_tokenAPI token (HTTP Basic password)
INVGATE_API_USERNAMEapi_usernameHTTP Basic username (optional, defaults to api)
INVGATE_WRITE_PROFILEwrite_profileWrite access profile: none (default), support, or full
INVGATE_TELEMETRYtelemetry_enabledEnable OpenTelemetry (default: false)
INVGATE_TELEMETRY_DETAILtelemetry_detailSpan detail: metadata (default), ids, or full
# ~/.config/invgate-service-desk-mcp/config.toml
base_url = "https://acme.sd.cloud.invgate.net"
api_token = "..."
# api_username = "api"
# write_profile = "none"  # "none" (default) | "support" | "full"
# telemetry_enabled = false
# telemetry_detail = "metadata"

Tip: create the config directory first: mkdir -p ~/.config/invgate-service-desk-mcp

See config.toml.example for a copy-paste template.

Running the server

invgate-service-desk-mcp                 # STDIO transport (default)
invgate-service-desk-mcp --transport sse # SSE/HTTP transport

Security note: STDIO (the default) keeps everything local. The sse and streamable-http transports have no built-in authentication — only use them bound to loopback or behind an authenticated reverse proxy.

Observability (optional)

The server can emit OpenTelemetry traces, metrics, and logs — completely opt-in and vendor-neutral. Export to any OTLP-compatible backend (Dynatrace, Grafana, Datadog, Jaeger, etc.).

pip install "invgate-service-desk-mcp[telemetry]"

export INVGATE_TELEMETRY=1

OTLP endpoint and headers are configured via standard OpenTelemetry env vars (not in the TOML file):

export OTEL_EXPORTER_OTLP_ENDPOINT="https://<your-env>.live.dynatrace.com/api/v2/otlp"
export OTEL_EXPORTER_OTLP_HEADERS="Authorization=Api-Token <YOUR_DT_TOKEN>"
export OTEL_EXPORTER_OTLP_METRICS_TEMPORALITY_PREFERENCE=delta
export OTEL_SERVICE_NAME=invgate-service-desk-mcp

Token scopes needed: openTelemetryTrace.ingest, metrics.ingest, logs.ingest. See docs/observability-dynatrace.md for a detailed guide.

export OTEL_EXPORTER_OTLP_ENDPOINT="http://localhost:4318"
export OTEL_SERVICE_NAME=invgate-service-desk-mcp

Signals emitted:

  • Traces — tool execution spans (GenAI semantic conventions) + InvGate API request spans with response size and item count
  • Metricsmcp.tool.duration, invgate.client.request.duration, mcp.tool.errors, invgate.response.item_count, invgate.response.size
  • Logs — tool errors and unexpected API response shapes, correlated to traces (OTLP only, never stdout)

Development

git clone https://github.com/tracegazer/invgate-service-desk-mcp.git
cd invgate-service-desk-mcp
uv venv && uv pip install -e ".[dev]"
pytest

License

MIT

Reviews

No reviews yet

Be the first to review this server!