Configuration parameters: Zabbix MCP server
Overview
The Zabbix MCP server is a process that allows AI agents to work with Zabbix using the Model Context Protocol (MCP).
The parameters supported by the Zabbix MCP server configuration file (zabbix_mcp_server.conf) are listed in this section.
The parameters are listed without additional information. Click the parameter to see the full details.
| Parameter | Description |
|---|---|
| AllowedIP | A list of comma delimited IP addresses, optionally in CIDR notation, or DNS names of MCP clients. |
| AllowTool | A wildcard rule that allows a tool. |
| AllowToolRegexp | A regular expression rule that allows tools. |
| DebugLevel | The debug level. |
| DenyTool | A wildcard rule that denies a tool. |
| DenyToolRegexp | A regular expression rule that denies tools. |
| FrontendURL | The Zabbix API endpoint. |
| IgnoreURLCertErrors | Specifies TLS certificate validation error handling when accessing the Zabbix API. |
| ListenIP | The IP address to listen on. |
| ListenPort | The port to listen on. |
| LogFile | The name of the log file. |
| LogFileSize | The maximum size of the log file. |
| LogType | The type of the log output. |
| MaxResponseSize | The maximum size of a response returned by a read tool. |
| PidFile | The name of the PID file. |
| Timeout | The maximum time (in seconds) to wait for a response from the Zabbix API. |
| TLSAccept | What incoming connections to accept. |
| TLSCertFile | The full pathname of a file containing the server certificate or certificate chain. |
| TLSKeyFile | The full pathname of a file containing the server private key. |
| ToolPrefix | A prefix added to the names of all tools. |
All parameters are non-mandatory unless explicitly stated that the parameter is mandatory.
Note that:
- The default values reflect process defaults, not the values in the shipped configuration files;
- Values support environment variables in the
${NAME}format; - Zabbix supports configuration files only in UTF-8 encoding without BOM;
- Comments starting with
#are only supported at the beginning of the line.
Parameter details
AllowedIP
A list of comma delimited IP addresses, optionally in CIDR notation, or DNS names of MCP clients. Incoming connections will be accepted only from the hosts listed here.
Example:
AllowedIP=127.0.0.1,192.168.1.0/24,::1,2001:db8::/32,mcp-client.example.com
Mandatory: yes
AllowTool
A wildcard rule that allows a tool. The parameter can be specified multiple times.
Wildcard patterns use the item key syntax, where * matches any characters. The rule matches the plain tool name and ignores ToolPrefix.
All AllowTool, DenyTool, AllowToolRegexp and DenyToolRegexp rules form a single list in the order in which they are specified; the first matching rule decides. A tool that matches no rule is allowed.
Example:
AllowTool=host_get
AllowToolRegexp
A regular expression rule that allows tools. The parameter can be specified multiple times.
Regular expressions use the RE2 syntax and match any part of the plain tool name unless anchored.
Example:
AllowToolRegexp=^(host|hostgroup|trigger|problem)_get$
DebugLevel
Specify the debug level:
- 0 - basic information about starting and stopping of Zabbix processes;
- 1 - critical information;
- 2 - error information;
- 3 - warnings;
- 4 - for debugging (produces lots of information);
- 5 - extended debugging (produces even more information).
Default: 3
Range: 0-5
DenyTool
A wildcard rule that denies a tool. The parameter can be specified multiple times.
A denied tool is not included in the list of tools and cannot be called.
See AllowTool for details.
Example:
DenyTool=maintenance_delete
DenyToolRegexp
A regular expression rule that denies tools. The parameter can be specified multiple times.
See AllowToolRegexp for details.
Example:
DenyToolRegexp=^problem_(close|suppress)$
FrontendURL
The Zabbix API endpoint: the URL of the Zabbix frontend ending with api_jsonrpc.php.
Example:
FrontendURL=https://zabbix.example.com/api_jsonrpc.php
Mandatory: yes
IgnoreURLCertErrors
Specifies TLS certificate validation error handling when accessing the Zabbix API:
false - do not ignore certificate errors;
true - ignore certificate errors (use only in a development environment).
Default: false
ListenIP
The IP address to listen on.
Default: 0.0.0.0
ListenPort
The port to listen on. The MCP endpoint path is /mcp.
Default: 8443
Range: 1024-32767
LogFile
The name of the log file.
Default: /tmp/zabbix_mcp_server.log
Mandatory: No
LogFileSize
The maximum size of a log file in MB.
0 - disable automatic log rotation.
Default: 1
Range: 0-1024
LogType
The type of the log output:
- file - write log to the file specified by LogFile parameter;
- system - write log to syslog;
- console - write log to standard output.
Default: file
MaxResponseSize
The maximum size of a response returned by a read tool. Whichever of this limit and the limit argument of the tool is reached first stops the response.
Supports unit suffixes.
Default: 64K
Range: 16K-256K
PidFile
The name of the PID file.
Default: /tmp/zabbix_mcp_server.pid
Timeout
The maximum time (in seconds) to wait for a response from the Zabbix API.
Default: 10
Range: 3-30
TLSAccept
What incoming connections to accept:
- unencrypted - accept connections without encryption (default);
- cert - accept connections with TLS and a certificate.
Default: unencrypted
TLSCertFile
The full pathname of the file containing the server certificate or certificate chain.
Mandatory: Yes, if TLSAccept is set to cert; otherwise, no
TLSKeyFile
The full pathname of the file containing the server private key.
Mandatory: Yes, if TLSAccept is set to cert; otherwise, no
ToolPrefix
A prefix added to the names of all tools, for example, to avoid name conflicts with tools of other MCP servers. For example, with ToolPrefix=zbx_, the host_get tool is exposed as zbx_host_get.
Allowed characters: letters, digits, underscore (_), hyphen (-) and dot (.).
Tool access rules match the tool names without the prefix.
Example:
ToolPrefix=zbx_