Skip to content

Limited-time launch: lifetime access from $49.

View lifetime deal

Zendesk MCP server and 7 help desk servers compared

Udit Goenka
Udit Goenka

Zendesk MCP server status, plus Intercom, Freshdesk, Salesforce, Dynamics, Plain, Pylon and Gorgias compared on auth and write access.

TL;DR: As of October 2026, Salesforce, Microsoft Dynamics 365, Freshdesk, Plain, Pylon and Intercom each document an official hosted MCP server, Gorgias lists one in open beta, and Zendesk has announced one without confirming availability. They differ most on sign-in. Plain, Pylon and Salesforce run as the signed-in user, while Freshdesk accepts an API key only. Each row below links the vendor's own page and was checked in October 2026.

Searches for a Zendesk MCP server return a mix of official announcements, community projects and third-party roundups, and the roundups often disagree. This guide is written for buyers. It uses only the vendor's own documentation, changelog or announcement for each claim, and it says so when a claim cannot be confirmed.

Every row covers the same four questions. Is there an official server, does it read or write, how does it sign people in, and what is its status on a stated date. The background on what MCP is and why it matters to a help desk is in the MCP hub guide, so this page stays on the comparison.

Dates matter because this market moves monthly. A fact that was true in June may be wrong in October, and several third-party summaries I found were out of date by weeks. Treat the checked-in October 2026 label as part of the data, and re-check before you sign anything.

How I checked each vendor

A claim about a vendor counts only if that vendor's own documentation, help center, developer site, changelog or announcement says it. A competitor's blog or a reseller's roundup is a lead, and I followed leads to the vendor page before using them. When I could not find a vendor page, the cell says unconfirmed.

I recorded the page, the date I read it and what it said. Where two vendor pages disagree, as Microsoft's announcement and its configuration page do on preview status, I report both. I did not test the servers with live customer data, so this guide covers documented behavior and not measured accuracy.

If you plan to test, the companion guide on connecting Claude and ChatGPT to a support inbox covers a safe setup, and the guide on tool curation shows how to measure what an assistant does with each server's tools.

The comparison table

Read the table row by row. A tick means the vendor documents it, and a cross means the vendor's documentation says it does not or lists nothing. The last column is the single vendor page behind the row, written out so you can open it yourself.

VendorOfficial hosted serverRead or writeSign-inStatus in October 2026Vendor source (checked October 2026)
Zendesk✗ (announced at Relate 2026, availability unconfirmed)Not applicableNot applicableMCP client generally available, server not confirmedzendesk.com/newsroom/articles/relate-2026/
Intercom✓Read, plus article writes and internal notesOAuth or bearer tokenAvailable, 14 tools, US and EUdevelopers.intercom.com/docs/guides/mcp
Freshdesk✓Read and writeAPI key onlyGenerally available from September 10, 2026support.freshdesk.com/support/solutions/articles/50000012670
Salesforce✓Read and write, plus a read-only serverOAuth with PKCE, runs as the userGenerally available since April 2026developer.salesforce.com/blogs/2026/04/salesforce-hosted-mcp-servers-are-now-generally-available
Microsoft Dynamics 365 Customer Service✓Read and writeDataverse roles through the Agent 365 Tooling GatewayGenerally available since July 30, 2026microsoft.com/en-us/dynamics-365/blog/it-professional/2026/07/30/dynamics-365-customer-service-mcp-server-ga/
Plain✓Read and writeOAuth with the user account, no API keysAvailable, 30 toolsplain.com/docs/integrations/mcp-server
Pylon✓Read and writeOAuth 2.0, user permissions applyAvailabledocs.usepylon.com/pylon-docs/integrations/pylon-mcp
Gorgias✓Reads live, some writes gatedAccount authorization on connectOpen betaupdates.gorgias.com/publications/gorgias-mcp-is-now-in-open-beta

Three patterns stand out. Sign-in splits the field into per-user models and shared-key models. Writes range from none to wide, and the line between internal notes and customer-visible replies is the one to watch.

Status ranges from open beta to general availability, which matters for support commitments. The sections below give the detail, and the MCP vs API guide helps you decide whether you need the server at all.

Zendesk: a client today, a server announced

Zendesk is the vendor people ask about most, and the answer needs two parts. Zendesk has an MCP client, which lets Zendesk action flows use tools from other MCP servers. Zendesk's help center announced the client's early access program in June 2026 and later recorded it as generally available, in a post edited on August 10, 2026.

The MCP server is a different thing. It would let external AI systems read and act on your Zendesk data. Zendesk's Relate 2026 newsroom release describes a Zendesk MCP Server connecting tickets, knowledge and customer data to outside AI platforms, with availability listed as early access this summer.

That is the vendor's own statement, in the Zendesk Relate 2026 release.

Whether it has shipped is the open question. When I read Zendesk's own list of current and upcoming early access programs in October 2026, the only entry that mentioned MCP was the program for ChatGPT as a customer support channel, which Zendesk says uses OpenAI's Apps SDK and the Model Context Protocol. I found no Zendesk page that confirms a general-purpose server, as the Zendesk early access programs list shows.

Geckoboard reached the same conclusion on August 14, writing that it could not find evidence of even an early access program, in its Zendesk MCP options comparison. That is a third-party observation, so I treat it as a lead that matches what the vendor's own pages show.

The practical advice is to treat the Zendesk server as unconfirmed. Community projects and marketplace apps from partners such as Swifteq exist, and they are third-party products with their own terms. If you need MCP access to Zendesk today, review those on their own merits and ask Zendesk for a dated answer in writing.

If MCP access is a reason to reconsider your help desk, the Zendesk alternatives guide and the migration guide cover the options and the effort involved.

Intercom: read-heavy with limited writes

Intercom's developer documentation describes a hosted remote MCP server with streamable HTTP at mcp.intercom.com for US workspaces and mcp.eu.intercom.com for EU workspaces. It lists 14 tools, covering search and fetch, conversations, contacts, companies and articles. Australian-hosted workspaces are not supported, according to the Intercom MCP guide.

Older summaries call this server read-only. The current documentation is more nuanced. It can create and update Help Center articles, and it can add internal notes to conversations, which only teammates see.

It does not send customer-visible replies.

One behavior is easy to miss. Intercom's page notes that a note added to a snoozed conversation assigned to someone else unsnoozes it. A harmless-looking write can therefore change what a teammate sees in the inbox, so include it in your review.

For sign-in, the documentation recommends OAuth and offers a bearer token as the alternative. It notes that the OAuth consent page does not verify the name of the connecting app, so tell staff to check which client they are approving. Scopes cover reading users and companies, reading and writing conversations for notes, and reading and writing articles.

For a broader view of Intercom's AI offering against its competitors, see the Intercom alternatives guide and the comparison of Intercom Fin and Zendesk AI.

Freshdesk: generally available, API key only

Freshworks introduced MCP in its May 2026 launch note, which described Freshdesk MCP as an early access program at that time. The Freshdesk support article now states that the Freshworks MCP integration is generally available starting September 10, 2026. The server address follows the pattern of your Freshdesk subdomain followed by /mcp, and custom domains are not supported, per the Freshdesk MCP integration article.

The sign-in model is the thing to weigh. The article says, in a note, that Freshdesk currently allows you to authenticate requests involved in MCP integration by using an API key only. A key is a shared secret that carries the permissions of the account that created it.

It does not tie each call to the person using the assistant.

Plan and pricing terms also matter. The article describes rate limits and monthly action allowances per plan, with add-on action packs. For customers who joined during early access, standard pricing and limits take effect on October 5, 2026.

There is a compatibility warning. The article says that if you used the integration during early access on a plan other than the latest Freshdesk Standalone 2021 version or the Freshdesk Unified Omni 2026 variant, it stops working after September 10, 2026. Check your plan before you rely on it.

If you are weighing Freshdesk against other tools for AI support, the Freshdesk alternatives guide compares the field.

Salesforce: generally available and runs as the user

Salesforce announced on April 29, 2026 that its hosted MCP servers are generally available for Enterprise Edition and above. An administrator has to enable them, and each client connects through an External Client App using OAuth with PKCE and the mcp_api and refresh_token scopes. The details are in Salesforce's hosted MCP servers announcement.

The central design choice is that the assistant acts as the signed-in user. Object permissions, field-level security and sharing rules all apply, so the assistant cannot see a record that the person could not open in Salesforce itself. For a support team that stores cases, accounts and entitlements in Service Cloud, this is the most familiar permission model on the list.

Salesforce offers standard servers and lets you build custom ones from flows, Apex actions and Named Query APIs. It also publishes a read-only server for sObject reads, which is a clean starting point when you want an assistant to look things up and never change anything. Teams that need a narrow, task-shaped menu can define it themselves.

Ross Belmont, Senior Director of Product Management at Salesforce, put the safety argument plainly in that post: "Structured tool calls replace unstructured API access. The server defines exactly which operations are available; there's no way for an AI assistant to call an API that hasn't been explicitly exposed." That is a useful sentence to put in front of a security reviewer, and it matches the approach in the guide to curating MCP tools.

The trade-off is cost and scope. The servers are a feature of a large platform, so the buying decision is really a Salesforce decision. A team on a lighter help desk will not get this from Salesforce unless it already runs Service Cloud.

Microsoft Dynamics 365 Customer Service: broad menu, one conflicting label

Microsoft announced general availability of the Dynamics 365 Customer Service MCP server on July 30, 2026. The post describes more than 90 service-oriented tools, a gateway called the Agent 365 Tooling Gateway that handles sign-in to Dataverse, and access that follows Dataverse security roles. It is titled in the Dynamics 365 Customer Service MCP server announcement and frames the benefit as minimizing the need for one-off custom integrations.

Microsoft's own Learn page tells a different story. When I read the Customer Service MCP configuration page in October 2026, it still carried a preview label, listed five Customer Service tools alongside eleven Dataverse tools, and said Claude Desktop was not supported.

I cannot tell from outside which page is ahead. A reasonable reading is that the announcement describes the product's direction and the configuration page lags behind it. Before you plan around the 90 tool figure or a given client, confirm both with your Microsoft contact in writing.

The client list matters here. The announcement names Microsoft 365 Copilot, Copilot Studio, Visual Studio Code and GitHub Copilot CLI, and says other clients such as ChatGPT and Claude Code can connect. A menu of 90 tools also invites the selection problems covered in the guide on tool curation, so plan to switch most of them off.

Plain: OAuth as yourself, with replies sent as you

Plain documents an MCP server with 30 tools covering threads, customers, companies, labels, knowledge and more. Sign-in is OAuth with your own Plain account and the documentation says there are no API keys, so actions are attributed to the person using the assistant. Replies the assistant sends appear as that user, according to the Plain MCP server documentation.

That attribution is a real strength for audit. Every write in the help desk's own history shows a named human, which is what a reviewer wants to see. It also means the person who approved the action is the person on record.

Plain announced the server in a launch post and recorded it in a changelog entry dated March 3, 2026. It reads and writes, so the same caution about customer-visible replies applies. A setup that lets the assistant draft and a person press send keeps the benefit of speed without the exposure.

Pylon: workspace roles control who can connect

Pylon's documentation describes an MCP server at mcp.usepylon.com that uses OAuth 2.0 and performs actions on behalf of the signed-in user. It can read and update issues, accounts, contacts, knowledge base articles, tasks, projects and triggers. The page, titled Pylon MCP, lists tools in tables that mark each one as read or write.

Two controls stand out. An administrator turns the server on under the AI Controls section of settings, and each member needs the MCP Access role before they can use it. The page also says the server cannot return data that the user cannot already see or perform writes that the user cannot already make in the dashboard.

Pylon documents per-tool rate limits and some tools that depend on a plan feature. Earlier third-party roundups counted only six tools, and that count is out of date against the vendor's current page. This is a good example of why the table cites the vendor and not a summary.

Gorgias: open beta with live reads

Gorgias announced its MCP server on May 27, 2026 in its product updates feed, calling it an open beta. The post says reads are fully live, some writes are gated, it works on any plan at no extra cost, and the first connection asks you to authorize your account. The announcement is the Gorgias MCP open beta update, and the endpoint is listed at mcp.gorgias.com.

I could not find a page that spells out the sign-in method beyond account authorization, so the table says exactly that. For an ecommerce team the useful question is which writes are gated, since refunds, cancellations and order edits sit close to money. Ask Gorgias for the current list before connecting an assistant that can act.

If you are choosing a store help desk and not only an MCP server, the Gorgias alternatives guide covers the wider field.

How the sign-in models differ

Sign-in is the row that should drive a security review. The vendors fall into three groups, and each group answers a different question about who is responsible for an action.

  • Per-user OAuth. Plain, Pylon and Salesforce run as the person, so the help desk's own permissions apply and the history shows a named user.
  • Gateway or role based. Dynamics 365 hands sign-in to a gateway and follows Dataverse security roles, which suits companies already managing roles there.
  • Shared key. Freshdesk accepts an API key only, so the key carries the permissions of whoever created it and calls are not tied to the person asking.
  • Mixed. Intercom recommends OAuth and also accepts a bearer token, so the choice is yours and your policy should name the preferred one.
  • Not described. Gorgias documents account authorization on connect and no more, so ask what the token can do and how it is revoked.

The MCP specification says there should always be a human able to deny tool invocations, which is why per-user sign-in matters. The MCP security guide goes through scopes, logging and rate limits in detail.

A shared key is not wrong for every team. A small team with one trusted administrator and a read-only use may accept it. The risk grows with the number of people and with the width of the key.

What each server can change

Reading is the easy half. The questions that decide your risk are which actions change customer-visible state, which change internal state, and which can be undone.

VendorCustomer-visible reply possibleInternal notes or draftsRecords can be created or updatedDocumented narrowing option
Intercom✗✓ (internal notes)✓ (articles)✓ (scopes)
Freshdesk✓✓✓✗ (API key only)
Salesforce✓✓✓✓ (read-only server, custom servers)
Dynamics 365✓✓✓✓ (Dataverse roles)
Plain✓ (sent as the user)✓✓✓ (user permissions)
Pylon✓✓✓✓ (MCP Access role)
GorgiasGatedNot documentedGatedNot documented

Treat each tick as a statement about what the vendor documents, and not as proof of what happens in your account. A tick for a reply only means the capability exists, since your own roles and settings can still block it. Where the cell says not documented, the vendor page I read did not say.

The guardrails guide describes how to place a confirmation step in front of every write that a customer can see. That one habit covers most of the risk in the table.

Dates, plans and the cost of waiting

Three of these servers changed status within the last six months, and two have plan limits that took effect in October. A table without dates would have been wrong by the time you read it. For a buyer, the dates are part of the product.

The Freshdesk article ties availability to plan versions and to monthly action allowances. Intercom's page ties availability to US and EU hosting. Salesforce ties it to Enterprise Edition and above, and Gorgias ties it to an open beta that may change.

Put the checked date in your own vendor file, and re-check before renewal. The vendor questions checklist has wording you can paste into a security questionnaire. If the vendor will not give a dated answer in writing, treat the feature as absent.

How I would choose

Start from the help desk you already run, since switching a help desk to gain one connector is rarely worth it. If your vendor has a server, read its tool list and decide which tools you will switch on. If it does not, decide whether you can wait for it or need another route.

Teams that cannot wait have two routes. One is a custom server that exposes a short list of task-shaped actions over your help desk's API, which the MCP vs API guide compares with a direct integration. The other is a support platform that offers its own actions layer, discussed below.

For a buyer with no strong tie to a vendor, the sign-in model is the best tiebreaker. Per-user OAuth gives you attribution and a smaller blast radius. A shared key gives you speed to set up and less accountability.

Questions to ask every vendor

Whatever the vendor, ask the same short list. Write the answers down with the date, and keep them with the contract.

  • Is the server generally available, in early access or in beta today, and where is that written?
  • Which tools can send something a customer will see?
  • Does each call run as a named user, and can I revoke one person without affecting the rest?
  • Can I switch off individual tools, and can I do it per role?
  • What are the rate limits and monthly allowances, and what happens at the limit?
  • Where are calls logged, and how long are the logs kept?
  • Which plans include the server, and does pricing change after an early access period?
  • Which clients are supported, and which are known not to work?

A vendor that answers these in writing is ahead of most. The audit trail guide explains why the logging answer is the one worth pressing on.

What this means if your help desk has no server

Not every team runs one of the eight. Many small teams use a lighter tool, a shared inbox or a chat widget, and their vendor may never ship an MCP server. That is fine, because MCP is one route to automation and not the only one.

communicate.so takes the other route. Its actions layer lets an AI agent look up an order, check a subscription, update a ticket or call your own API mid-conversation, inside the permissions and confirmation rules you set. It also publishes a public, read-only MCP server named communicate-docs with three tools for developer guidance, an API summary and a support contact.

That server does not access workspaces, customer data or product actions, so it is a reference for builders and not a way to reach your inbox.

Where the work lives in a shared inbox, the shared inbox keeps people and AI agents on the same thread, and the help center MCP guide covers publishing documentation for outside assistants.

What stays uncertain

Four things in this guide are open as of October 2026. Whether Zendesk has shipped a general-purpose MCP server is unconfirmed. Whether Microsoft's announcement or its configuration page reflects the current state is unresolved.

Which Gorgias writes are gated is not listed in the pages I read.

The fourth is how any of these servers behave under real load. I checked documentation, not accuracy, so I make no claim about how often an assistant picks the right tool. The only way to learn that is to test it on your own tickets.

The evaluation guide describes a small test set that does this. Run it before you widen access, and again whenever a vendor adds tools.

A worked comparison for a ten-person support team

Consider a ten-person team that wants an assistant to summarize long threads, find similar past tickets and draft replies. This is a scenario I made up to show the method, and it uses no customer data. The goal is to show how the table turns into a decision.

First, list the tasks by risk. Summaries and searches only read data, so any server in the table can do them. Drafting a reply is an internal write if it lands as a draft, and a customer-visible write if it sends.

Second, match tasks to sign-in. If the team wants every drafted reply attributed to the agent who approved it, Plain, Pylon and Salesforce document that model. If the team accepts a shared key for read-only work, Freshdesk's API key route is enough for the first month.

Third, check the status. A beta, such as Gorgias, suits a pilot with a test queue and does not suit a commitment to customers. A generally available server suits a rollout, once you have read its tool list and switched off what you do not need.

Fourth, measure. Run the same twenty tickets through the assistant before and after you narrow the tool list, and record the right and wrong tool choices. The resolution rate guide explains why you should count outcomes and not only responses.

Fifth, write the decision down with the date, the tools switched on and the person who owns the review. That record is what you show the security team and what you re-open when a vendor changes its terms. It takes under an hour and saves a long argument later.

Common mistakes when comparing vendors

The first mistake is counting tools. A server with 90 tools is not better than one with 14, because a large menu makes selection harder for the model and review harder for you. The count says how much there is to switch off.

The second is trusting a roundup. Roundups helped me find leads, and several were wrong or stale by the time I checked the vendor page. Use the vendor's documentation as the source, and use the roundup to know where to look.

The third is skipping the plan check. A server can be generally available and still be out of reach on your plan, as the Freshdesk and Salesforce pages show. The fourth is forgetting the client, since a server that does not work with the assistant your team uses is no help.

The fifth is treating MCP as a replacement for process. A server only exposes actions, and your team still needs rules for approval, escalation and handoff. The human handoff guide covers the rules that keep a person in control of the hard cases.

Frequently asked questions

Does Zendesk have an MCP server?

As of October 2026 I could not confirm one. Zendesk announced a Zendesk MCP Server at Relate 2026 with early access listed for the summer, but its early access programs list shows only the ChatGPT support channel program, which uses MCP in a narrower way. Ask Zendesk for a dated answer in writing.

Is the Zendesk MCP client the same as a Zendesk MCP server?

No. The client lets Zendesk use tools hosted elsewhere. The server would let outside AI tools reach Zendesk data.

Zendesk's help center records the client as generally available, and that says nothing about the server.

Is the Intercom MCP server read-only?

Older summaries say so, and the current documentation says otherwise. It lists 14 tools and allows limited writes, namely Help Center articles and internal notes on conversations. It does not send customer-visible replies.

Which help desks have an official MCP server?

Intercom, Freshdesk, Salesforce, Dynamics 365 Customer Service, Plain, Pylon and Gorgias each document one as of October 2026. Gorgias calls its server an open beta, and Dynamics 365 shows conflicting preview and general availability labels. Zendesk is unconfirmed.

Which servers sign in as the individual user?

Plain, Pylon and Salesforce document OAuth in which actions run as the signed-in person. Dynamics 365 follows Dataverse roles through a gateway. Intercom offers OAuth as the recommended option, and Freshdesk accepts an API key only.

Is an API key a problem for Freshdesk MCP?

It depends on your size and use. A key carries the permissions of the account that made it and does not identify the person asking the assistant. Small teams with one trusted administrator and read-only use may accept that, and larger teams usually will not.

Can an assistant send replies to customers through these servers?

Several can, and Intercom documents that it cannot. Plain documents that replies appear as the signed-in user. Whatever the vendor allows, keep a person pressing send until you have tested the assistant on your own tickets.

How many tools does each server expose?

Intercom lists 14, Plain lists 30, and Microsoft's announcement for Dynamics 365 cites more than 90, while its Learn page listed five Customer Service tools and eleven Dataverse tools. Counts change often, so read the vendor page on the day you decide.

Why do third-party comparisons disagree with vendor pages?

Products change monthly and many roundups are written once. I found a competitor's list claiming Freshdesk was in closed beta and a roundup counting six Pylon tools, and both were out of date against vendor pages. Use roundups as leads and confirm each claim at the source.

What does generally available mean for support planning?

It means the vendor presents the feature as supported and ready for production use, and early access or beta means it may change. Freshdesk dates its general availability to September 10, 2026, and Salesforce to April 2026. For a customer-facing workflow, prefer generally available.

Do I need an enterprise plan to use these servers?

Sometimes. Salesforce requires Enterprise Edition or above, Freshdesk limits support to named plan versions, and Pylon notes that some tools need a plan feature. Gorgias says its beta works on any plan at no extra cost.

Does Claude or ChatGPT work with all of them?

Not necessarily. Microsoft's Learn page said Claude Desktop was unsupported for the Customer Service server, while the announcement named other clients as able to connect. Check the client list on the vendor page and test your own setup.

Are community MCP servers for Zendesk safe to use?

They are third-party software with their own authors, terms and security posture. Review the code and the permissions they request, use a low-privilege account, and prefer read-only access. Treat them as a stopgap and not as a vendor commitment.

What is the safest way to start?

Connect with a read-only role or a test account, switch on a handful of read tools, and ask the assistant to summarize threads. Review the logs after a week. Add writes one at a time, each with a confirmation step.

Should I switch help desks to get an MCP server?

Rarely. Migration costs time and risk, and a connector is only one part of the value. If MCP access matters, compare vendors on sign-in, write scope and dates, and weigh that against the migration effort in the guides linked above.

How often should I re-check this?

Monthly during the first year, and before every renewal. Several vendors changed status between June and October 2026. Put a recurring review date in your policy.

What if my vendor has no MCP server?

You can build a custom server over the help desk's API with a short list of task-shaped actions, wait for the vendor, or use a platform with its own actions layer. The right choice depends on who drives the conversation.

Is the communicate.so MCP server connected to my inbox?

No. The public communicate-docs server is read-only and offers three tools for developer guidance, an API summary and a support contact. Its instructions say it does not access workspaces, customer data or product actions.

Do these servers replace a help desk integration?

No. MCP gives an AI client a menu of actions it can read and call. Your existing integrations, webhooks and automations keep working, and you may want both.

What should I tell my security team?

Give them the table, the dates, the sign-in model for each server and the list of tools you plan to switch on. Ask them to decide on logging and revocation before you connect. A one-page policy with a review date is usually enough.

The short answer

As of October 2026, seven of the eight help desks document an official MCP server, and Zendesk's remains announced and unconfirmed. Choose by sign-in model first, write scope second and status date third. If your help desk has no server, a platform with its own actions layer is a sound alternative, and you can see how communicate.so handles it on the AI agents page or start from the pricing page at communicate.so.