# @nextoolsolutions/mcp-glpi

MCP server for GLPI (service desk / ITSM): 166 GLPI tools for tickets, ITIL problems and changes, assets and inventory, knowledge base, users, rules and webhooks. GLPI 10 and 11, REST API v1 + GLPI 11 API v2 (OAuth2). Not affiliated with Teclib'.

- **Type:** MCP server
- **Trust:** 85/100 (A), scored on the package rubric
- **Verification:** verified (build provenance)
- **Version:** 3.5.5
- **Author:** NexTool Solutions
- **License:** MIT
- **npm:** @nextoolsolutions/mcp-glpi
- **Endpoints:** streamable-http https://mcp.nextoolsolutions.com/mcp
- **Source:** https://github.com/NexTools-Solutions/nextool-mcp-glpi
- **Endpoint health:** reachable (last checked 2026-10-08T05:57:03.653Z, 1 sample) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

85/100 (A), scored on the package rubric
- Publisher verified: no
- Build provenance: verified attestation
- npm trusted publishing (OIDC): yes
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 0 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-10-08T05:56:50.773Z
- **Version scanned:** 3.5.5
- **CVEs:** none found by OSV at scan time

## Tools

40 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `mcp-glpi`
- `triage_ticket` — Read a ticket and its timeline, then propose category, urgency/impact and the group
- `investigate_recurrence` — Given a ticket, find similar past tickets and their solutions, and judge whether this
- `requester_history` — Everything a technician should know before picking up a call from this person: open
- `asset_context` — Hardware profile of an asset plus the tickets around it — the picture to have open
- `glpi_list_tickets` — List GLPI tickets of the whole instance (every ticket the connected user may see), most recently
- `glpi_list_my_tickets` — "My tickets": tickets of the connected GLPI user (or of users_id) where they are requester,
- `glpi_get_ticket` — Retrieve a single ticket by ID. IDs come with names beside them (recipient_name, category_name,
- `glpi_create_ticket` — Create a new ticket. Common fields: name (title), content (description),
- `glpi_update_ticket` — Update an existing ticket by ID.
- `glpi_list_changes` — List change management items, most recently updated first by default, with status_name and
- `glpi_get_change` — Retrieve a change by ID, with names beside the IDs and status/priority labels in the GLPI user's language.
- `glpi_create_change` — Create a new change. Common fields: name, content, entities_id, users_id_requester.
- `glpi_update_change` — Update an existing change by ID.
- `glpi_list_change_followups` — List followups (comments) of a change, with the author's name (user_name).
- `glpi_list_problems` — List problem management items, most recently updated first by default, with status_name and
- `glpi_get_problem` — Retrieve a problem by ID, with names beside the IDs and status/priority labels in the GLPI user's language.
- `glpi_create_problem` — Create a new problem. Common fields: name, content, entities_id, users_id_requester.
- `glpi_update_problem` — Update an existing problem by ID.
- `glpi_list_problem_followups` — List followups (comments) of a problem, with the author's name (user_name).
- `glpi_search` — Search GLPI items with criteria. itemtype: Ticket, User, Change, Problem, Computer, etc.
- `glpi_add_followup` — Add a comment/followup to a ticket.
- `glpi_list_followups` — List followups (comments) of a ticket, oldest first, with the author's name (user_name).
- `glpi_add_solution` — Add a solution to a ticket (status changes to Solved).
- `glpi_list_ticket_validations` — List approval/validation requests for a ticket, with requester and approver names
- `glpi_create_ticket_validation` — Create an approval request assigning a validator (users_id_validate).
- `glpi_update_ticket_validation` — Approve/refuse a validation (status: accepted/refused) or change the approver.
- `glpi_delete_ticket_validation` — Remove a validation request by ID.
- `glpi_get_user` — Retrieve a user by ID.
- `glpi_search_user_by_email` — Find users by exact email address (returns the user items: id, login, real name, first name...).
- `glpi_list_users` — List all users with optional pagination and dropdown expansion.
- `glpi_create_user` — Create a new GLPI user. Required: name (login). Common: realname, firstname, password, email (via _useremails array).
- `glpi_update_user` — Update an existing user by ID.
- `glpi_list_documents` — List documents with optional pagination.
- `glpi_get_document` — Retrieve a document by ID.
- `glpi_create_document` — Create a document (metadata). Fields: name, entities_id, comment, etc.
- `glpi_delete_document` — Permanently delete a document by ID.
- `glpi_list_document_items` — List links between documents and other items.
- `glpi_get_document_item` — Retrieve a Document_Item link by ID.
- `glpi_create_document_item` — Create a link between a document and an item (Ticket, KnowbaseItem, etc.).

## Install

**Verdict: install** — No blocking findings and no open coverage gaps — safe to install as configured.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"mcp-glpi\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"@nextoolsolutions/mcp-glpi\"\n      ],\n      \"env\": {\n        \"GLPI_USER_TOKEN\": \"<YOUR_GLPI_USER_TOKEN>\",\n        \"GLPI_APP_TOKEN\": \"<YOUR_GLPI_APP_TOKEN>\",\n        \"GLPI_V2_CLIENT_SECRET\": \"<YOUR_GLPI_V2_CLIENT_SECRET>\",\n        \"GLPI_V2_PASSWORD\": \"<YOUR_GLPI_V2_PASSWORD>\"\n      }\n    }\n  }\n}"
```
**Credentials it will ask for** (names only — Forge never holds a value):
- `GLPI_USER_TOKEN` — Glpi User Token (optional)
- `GLPI_APP_TOKEN` — Glpi App Token (optional)
- `GLPI_V2_CLIENT_SECRET` — Glpi V2 Client Secret (optional)
- `GLPI_V2_PASSWORD` — Glpi V2 Password (optional)
Placeholders only. Forge never holds, brokers, or transmits a credential value — replace each <YOUR_NAME> in your own config file. Do not send a value back to Forge; no Forge endpoint accepts one.
- This entry needs 4 credentials (0 required). The generated config carries placeholders, so it will fail in the editor rather than at runtime if they are left unset.

## Blast radius

Critical blast radius — deletes data; holds an oauth grant.
- Floor 65, ceiling 65 (tier: critical)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/%40nextoolsolutions%2Fmcp-glpi
- Install plan: https://forgeregistry.com/api/v1/packages/%40nextoolsolutions%2Fmcp-glpi/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/%40nextoolsolutions%2Fmcp-glpi
- HTML page: https://forgeregistry.com/registry/%40nextoolsolutions%2Fmcp-glpi
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
