Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ”’ Security
  3. Zitadel MCP
Zitadel MCP logo
Health: ActiveRecent health check succeeded.Last checked 9/6/2026, 11:02:22 PM

Zitadel MCP

User RatingsBe the first to rate and review this MCP server!
View Repository10 GitHub StarsTotal stargazers on GitHub for the source repository (10 stars).Visit Website
zitadelidentity-managementaccess-controloidcsecurity

MCP server for managing Zitadel users, projects, OIDC apps, roles, organizations, and service accounts.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

One-click editor setup isn’t available for this listing yet β€” we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ
No confirmed setup config for this listing yet. We only publish a config block when the install details come from the project itself β€” its README, its docs, or a verified owner. We haven’t found those for takleb3rry/zitadel-mcp, and we’d rather show nothing than a guess you’d paste into your client. Follow the project’s own setup instructions for the current steps.
Install Directory Badge Claim listing AlternativesπŸ”’ More in Security

Overview

This server exposes 33 tools for Zitadel identity administration, including user lifecycle management, project and OIDC application setup, role grants, organization manager roles, and service accounts. Provisioning and offboarding tools apply standardized role rules and safety checks. Optional portal tools are enabled when PORTAL_DATABASE_URL is configured.

Use cases

β€’Provision users with standardized admin or standard roles
β€’Create and update Zitadel OIDC applications
β€’Grant or revoke project and organization manager roles
β€’Create service accounts and generate service-account keys
β€’Offboard users with role removal and deactivation

Key features

β€’User search, creation, activation, locking, and deletion
β€’Project and OIDC application management
β€’Project role grants with v2 authorization and v1 fallback
β€’Organization manager role administration
β€’Service account and key management
β€’Optional portal application setup

Capabilities & Tool Schemas

Inspect callable tools, capabilities, and parameters exposed to AI agents by Zitadel MCP.

Extracted Tool Capabilities
User search, creation, activation, locking, and deletion
Project and OIDC application management
Project role grants with v2 authorization and v1 fallback
Organization manager role administration
Service account and key management
Optional portal application setup

Documentation Overview

Zitadel MCP Server

An MCP (Model Context Protocol) server for Zitadel identity management. Manage users, projects, applications, roles, and service accounts through natural language from AI tools like Claude Code.

"Provision jane@example.com as an Admin." β€” One tool call: creates the user, assigns the admin project role (v2 authorization), and grants ORG_USER_MANAGER so she can manage other users β€” no Super Admin required.

Tools (33)

CategoryToolDescription
Userszitadel_list_usersList/search users
zitadel_get_userGet user details
zitadel_create_userCreate user (sends invite email; optional client-supplied userId)
zitadel_deactivate_userDeactivate user
zitadel_reactivate_userReactivate user
zitadel_lock_userLock user
zitadel_unlock_userUnlock user
zitadel_delete_userPermanently delete user
Projectszitadel_list_projectsList projects
zitadel_get_projectGet project details
zitadel_create_projectCreate project
Applicationszitadel_list_appsList apps in a project
zitadel_get_appGet app details + Client ID
zitadel_create_oidc_appCreate OIDC application
zitadel_update_appUpdate app (redirect URIs, etc.)
Roleszitadel_list_project_rolesList roles in a project
zitadel_create_project_roleCreate a role (standardized: admin/standard)
zitadel_list_user_grantsList user's role grants
zitadel_create_user_grantAssign project roles (v2 authorization; flags off-vocabulary drift)
zitadel_remove_user_grantRemove role grant
Org Managerszitadel_list_org_manager_rolesList supported manager roles (ORG_OWNER, ORG_USER_MANAGER, …)
zitadel_list_org_managersList who holds manager grants (filter by role)
zitadel_grant_org_managerGrant manager role(s) (default ORG_USER_MANAGER); idempotent
zitadel_revoke_org_managerRevoke manager role(s); guards the last ORG_OWNER
Provisioningzitadel_provision_userAtomic + idempotent: create user + assign admin/standard + (for Admins) ORG_USER_MANAGER
zitadel_offboard_userRemove role + revoke manager + deactivate; guards last-Admin & self-demotion
Service Accountszitadel_create_service_userCreate machine user
zitadel_create_service_user_keyGenerate key pair
zitadel_list_service_user_keysList keys (metadata only)
Organizationszitadel_get_orgGet current org details
Utilityzitadel_get_auth_configGet .env.local template for an app
Portalportal_register_appRegister app in portal DB
portal_setup_full_appOne-click: Zitadel + portal setup

Portal tools (portal_*) are only available when PORTAL_DATABASE_URL is configured.

Two-role model & no-super-admin (Renewal Initiatives SSO)

The provisioning tools implement a standardized RBAC model for the core apps:

  • Two project (business) roles only: admin and standard β€” these land in the OIDC token and gate what a user can do in the apps. The provisioning tools refuse any other key to prevent drift.
  • No Super Admin: every Admin also receives an org-level ORG_USER_MANAGER grant (a manager role β€” administers Zitadel itself, not in the token), so any Admin can create/manage any user, including other Admins. Keep β‰₯2 ORG_OWNER break-glass accounts for org configuration.
  • Role assignment prefers the v2 AuthorizationService (POST /v2/authorizations) and automatically falls back to v1 user-grants if that endpoint is unavailable on the instance (some Zitadel Cloud versions return 404). Org-manager grants use the Management v1 org-member API.

Prerequisites

  1. A Zitadel instance (Cloud or self-hosted)
  2. A service account with Org Owner or IAM Admin role
  3. A JSON key for the service account

Creating a Service Account

  1. In the Zitadel Console, go to Users > Service Users > New
  2. Give it a name (e.g., mcp-admin) and select Bearer token type
  3. Go to the service user's Keys tab > New > JSON
  4. Save the downloaded key file β€” you'll need the userId, keyId, and base64-encoded key
  5. Grant the service account the Org Owner role under Organization > Authorizations

Setup

bash
git clone https://github.com/takleb3rry/zitadel-mcp.git

cd zitadel-mcp

npm install

npm run build

Configuration

Add the server to your MCP client config. The JSON block below works for both options:

  • Global (all projects): ~/.claude.json under the "mcpServers" key
  • Per-project: .mcp.json in the project root
config.json
{

  "mcpServers": {

    "zitadel": {

      "command": "node",

      "args": ["/path/to/zitadel-mcp/build/index.js"],

      "env": {

        "ZITADEL_ISSUER": "https://your-instance.zitadel.cloud",

        "ZITADEL_SERVICE_ACCOUNT_USER_ID": "...",

        "ZITADEL_SERVICE_ACCOUNT_KEY_ID": "...",

        "ZITADEL_SERVICE_ACCOUNT_PRIVATE_KEY": "...",

        "ZITADEL_ORG_ID": "...",

        "ZITADEL_PROJECT_ID": "..."

      }

    }

  }

}

Restart Claude Code after adding the config. The Zitadel tools will appear automatically.

Environment Variables

VariableRequiredDescription
ZITADEL_ISSUERYesZitadel instance URL
ZITADEL_SERVICE_ACCOUNT_USER_IDYesService account user ID
ZITADEL_SERVICE_ACCOUNT_KEY_IDYesKey ID from the JSON key file
ZITADEL_SERVICE_ACCOUNT_PRIVATE_KEYYesBase64-encoded RSA private key (the key field from the downloaded JSON)
ZITADEL_ORG_IDYesOrganization ID
ZITADEL_PROJECT_IDNoDefault project ID for role operations
PORTAL_DATABASE_URLNoPostgres connection string (enables portal tools)
LOG_LEVELNoDEBUG, INFO, WARN, ERROR (default: INFO)

Security

This server has admin-level access to your Zitadel instance. Understand what that means before using it:

  • The service account needs org-level management rights. Empirically (Zitadel Cloud, verified 2026-06): ORG_USER_MANAGER is enough to create users and assign existing project roles, but ORG_OWNER is required to create project roles, manage org-manager grants (the no-super-admin pattern), and manage applications. For the full provisioning workload, give the service account ORG_OWNER; human Admins can stay at ORG_USER_MANAGER. Keep the key in a gitignored .env (not a shared dotfile) and use ZITADEL_READ_ONLY=true for non-mutating sessions.
  • When you create an OIDC app (zitadel_create_oidc_app), the client secret is returned in the tool response. It is only available at creation time. The AI assistant (and its conversation history) will see it β€” save it immediately and treat it as sensitive.
  • When you generate a service account key (zitadel_create_service_user_key), the full private key is returned in the tool response. Same caveat: save it, and be aware it's visible in your MCP client's conversation.
  • All tool arguments containing PII (email, name, URLs) are redacted from debug logs. IDs and tool names are still logged.
  • All Zitadel IDs are validated against an alphanumeric format before being used in API paths.

Note for new users: I've scanned all source files in this repo and found nothing notable, but I always recommend you have your own AI or tooling audit the code before installing any MCP server that gets access to your infrastructure. The full source is ~800 lines of TypeScript β€” a quick review shouldn't take long.

Development

Terminal
npm run dev    # Run with tsx (hot reload)

npm run build  # Compile TypeScript

npm start      # Run compiled version

npm test       # Run tests

License

MIT

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Security View all alternatives
  • Jadx AI MCP logoJadx AI MCP

    JADX-AI-MCP is a plugin and MCP Server for the JADX decompiler that integrates directly with Model Context Protocol (MCP) to provide live reverse engineering support with LLMs like Claude.

    πŸ”’ Security3 views
    Compare vs Jadx AI MCP β†’
  • Apktool MCP Server logoApktool MCP Server

    APKTool MCP Server is a MCP server for the Apk Tool to provide automation in reverse engineering of Android APKs.

    πŸ”’ Security3 views
    Compare vs Apktool MCP Server β†’
  • MCP Maigret logoMCP Maigret

    MCP server for maigret, a powerful OSINT tool that collects user account information from various public sources. This server provides tools for searching usernames across social networks and analyzing URLs.

    πŸ”’ Security4 views
    Compare vs MCP Maigret β†’
  • OPNSenseMCP logoOPNSenseMCP

    MCP Server for managing & interacting with Open Source NGFW OPNSense via Natural Language

    πŸ”’ Security4 views
    Compare vs OPNSenseMCP β†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks β€” not a rating.

GitHub stars
10
Stargazers on the source repository.
Directory activity
1 views
Config copies, upvotes, and views on AllMCPs.

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about Zitadel MCP

You need a Zitadel service account with an Org Owner or IAM Admin role and a JSON key.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewZitadel MCP AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/takleb3rry-zitadel-mcp?style=directory)](https://allmcps.com/mcp/takleb3rry-zitadel-mcp)
HTML Embed
<a href="https://allmcps.com/mcp/takleb3rry-zitadel-mcp"><img src="https://allmcps.com/api/badge/takleb3rry-zitadel-mcp?style=directory" alt="Zitadel MCP on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ”’Security
PricingFree
More technical detailsExpand β–Ύ
AuthAPI key
Last updatedAug 10, 2026
Views1
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars10
GitHub Star CountTotal stargazers on GitHub representing community popularity (10 stars).
41Quality signal: Fair Β· 41/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools18/30
Adoption & activity3/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… FeaturedMoxie Docs MCP logo

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ”’ Security β†’Best MCP servers for Security β†’Alternatives to Zitadel MCP β†’Install in Claude DesktopInstall in CursorInstall in VS Code