Skip to main content

Zscaler Private Access MCP server

Zscaler Private Access (ZPA) provides zero trust access to private applications without exposing them to the internet. An MCP server for ZPA allows AI agents to manage application access policies, connectors, user groups, and security controls across your zero trust environment without needing direct portal access.

Setting up an MCP server

This article covers the standard steps for creating an MCP server in AI Gateway and connecting it to an AI client. The steps are the same for every integration — application-specific details (API credentials, OAuth endpoints, and scopes) are covered in the Authentication section on this page.

Before you begin

You'll need:

  • Access to AI Gateway with permission to create MCP servers.
  • API credentials for the application you're connecting (see the Authentication section on this page for what to collect).

Create an MCP server

Find the app in the catalog

  1. Sign in to AI Gateway and select App Catalog from the left navigation.
  2. Search for the application you want to connect, then select it from the catalog.
  3. Select Create MCP Server to start the wizard.

App Configuration

Confirm the Base URL for the API, then, under Tools, select the endpoints you want to expose. Select Next.

MCP Server Setup

  1. Enter a Name for your server — something descriptive that identifies both the application and its purpose.
  2. Enter a Description so your team knows what the server is for.
  3. Set the log level: choose Production Mode for terser logs, or Non-Production Mode for more verbose logs that can help with debugging.
  4. Select Next.

Authentication

Enter the authentication details for the application. This varies by service — see the Authentication section on this page for the specific credentials, OAuth URLs, and scopes to use.

Review

Look over the summary of your MCP server configuration, then select Create & Deploy. AI Gateway provisions the server and provides a server URL you'll use when configuring your AI client.


Connect to an AI client

Once your server is deployed, you'll need to add it to the AI client your team uses. Select your client for setup instructions:

Tips

  • You can create multiple MCP servers for the same application — for example, a read-only server for reporting agents and a read-write server for automation workflows.
  • If you're unsure which OAuth scopes to request, start with the minimum read-only set and add write scopes only when needed. Most application pages include scope recommendations.

Authentication

Zscaler ZPA uses OAuth 2.0 with client credentials flow. Generate a client ID and secret from Administration > API Keys in the ZPA admin portal, then note your customer ID.

ValueSetting
Token endpointhttps://config.private.zscaler.com/signin
Base URLhttps://config.private.zscaler.com

Available tools

The tools enable configuration of application access policies, connector management, user and group provisioning, and security monitoring. They allow you to define zero trust access rules, manage application segments, configure microsegmentation, and monitor user activity.

ToolDescription
Application ConfigurationAdd applications, configure segments, set domains, define health checks
Application GroupsCreate groups, assign members, set group policies, manage inheritance
Access PoliciesCreate policies, set conditional access, require MFA, configure time-based rules
Policy TestingTest policies before deployment, simulate user access, validate rule logic
Connector DeploymentDeploy connectors, create connector groups, set redundancy and failover rules
Connector OperationsUpdate versions, restart connectors, check health, view diagnostics
Load BalancingConfigure distribution, set failover rules, monitor performance, optimize routing
User AccessGrant and revoke access, set access duration, track user activity
Group PoliciesCreate groups, sync from Active Directory, set permissions, manage inheritance
SCIM ProvisioningSync users from identity provider, automate provisioning, handle deprovisioning
Access AnalyticsShow user patterns, track app usage, monitor failed attempts, analyze trends
Performance MetricsMeasure latency, track connector performance, monitor user experience
Browser IsolationEnable for risky apps, configure isolation policies, control downloads
SIEM IntegrationStream access logs, send security events, configure webhooks, export trails
Access InvestigationInvestigate suspicious access, trace user activity, analyze patterns

Tips

Use OAuth 2.0 token rotation to limit credential exposure.

Monitor API usage regularly to maintain security.

Implement least privilege access by creating granular policies.

Require MFA for sensitive applications.

Conduct regular access reviews to ensure permissions remain appropriate.

Enable session recording for high-risk applications.

Set up real-time alerting for anomalous access attempts to detect unauthorized activity quickly.