How NexTool MCP for GLPI works
From signing up on the portal to your first question to the AI: how the service links your assistant to your GLPI, what you can ask and how your data stays protected.
Not affiliated with Teclib'. GLPI is a registered trademark of Teclib'.
Overview
NexTool MCP sits in the middle: it receives the assistant's request, checks who you are on the NexTool portal and calls your GLPI API with the credentials you registered.
You chat
You ask in plain language. The assistant picks the right GLPI tool (there are more than 160) and shows what it is about to do.
The connector checks
On every request, NexTool MCP checks with the portal whether the key or sign-in is valid, which connection to use, the plan limit and whether the connection is read-only.
GLPI answers
The call reaches the GLPI API as the token's user. Whatever that user cannot do in GLPI, the AI cannot do either.
Hosted version, step by step Open beta
Open to everyone and free during the beta. Five steps, from sign-up to your first question.
- 1
Create your NexTool portal account
It's free and uses your portal account, with no separate sign-up. Already have an account? Just sign in.
- 2
Open My Account → NexTool MCP
The portal's NexTool MCP page holds your GLPI connections, API keys, authorized apps and your plan.
- 3
Create the connection to your GLPI
Give it a name (e.g. Production), enter the GLPI HTTPS address and pick the API:
- REST API v1 (GLPI 10 and 11): the user token and, if the GLPI API client requires it, the App-Token.
- API v2 (GLPI 11, OAuth): the API v2 address, the client ID and secret of a GLPI OAuth client, plus username and password.
- Both: fill in both with credentials of the same person in GLPI. If v1 and v2 authenticate different users, the test blocks the connection.
Tick the tool groups the AI may use (Essential is ticked by default) and, if you want, turn on read-only.
Credentials are encrypted the moment you save, with a key only the connector can open: neither the portal nor the NexTool team can read them.
- 4
Test the connection
When you save, the portal tests right away and shows the GLPI version plus the user and profile each API authenticated. If it fails, the message tells you why:
What you see What it means What to do GLPI not reachable from the internet It points to a private or blocked network (internal IP, localhost). Publish GLPI on a public HTTPS address or use the open source version inside your network. GLPI could not be reached DNS failure, timeout or connection refused. Check the address, DNS and firewall. Invalid certificate The HTTPS certificate is expired, self-signed or does not match the address. Install a valid certificate (for example, Let's Encrypt). Redirect GLPI redirects to another address (http to https, another domain, a login page). Enter the final address, as the browser shows it after the redirect. Does not answer as the GLPI API The address answers, but not as the GLPI API (proxy, login page, wrong path). Use the GLPI root, without /front or /apirest.php at the end. API disabled The REST API is turned off in GLPI. In Setup → General → API, enable the REST API and login with token. IP not allowed The GLPI API client only accepts some IPs, and the connector's is not one of them. The portal message shows the connector's IP: allow it in the API client (Setup → General → API). Credentials refused GLPI refused the App-Token, the user token or OAuth. Generate the token again and check that the App-Token belongs to the right API client. Different users on the two APIs v1 and v2 authenticated different people in GLPI. Use credentials of the same user on both APIs. A user with the Super-Admin profile does not block the test, but the portal shows a strong warning: prefer a dedicated user with a minimal profile.
- 5
Connect your assistant
Each connection has its own connector URL, shown in the portal list with a copy button:
https://mcp.nextoolsolutions.com/mcp/principalprincipalis the identifier of the account's first connection; the others use the identifier you choose. The address without an identifier (/mcp) also works and uses the first verified connection.
- 1
Under Settings → Connectors, click Add custom connector.
- 2
Give it a name (e.g. GLPI Production) and paste the connection URL:
https://mcp.nextoolsolutions.com/mcp/principal - 3
Click Connect: the NexTool portal sign-in opens. Sign in with your account.
- 4
On the authorization screen, check the app, the return address and the GLPI connection that will be used, then click Authorize.
One connector per GLPI: for another connection, add another connector with its URL. To cut access, revoke it under My Account → NexTool MCP → Authorized apps.
- 1
In ChatGPT, under Settings → Apps & Connectors, turn on developer mode (under Advanced).
- 2
Create a connector with the connection URL and OAuth authentication:
https://mcp.nextoolsolutions.com/mcp/principal - 3
Sign in with your NexTool portal account and authorize access.
Developer mode availability depends on your ChatGPT plan.
- 1
Add the server with the connection URL:
claude mcp add --transport http nextool https://mcp.nextoolsolutions.com/mcp/principal - 2
Inside Claude Code, run
/mcpand choose to authenticate: the browser opens the portal sign-in./mcp - 3
Prefer a key? Generate one under My Account → NexTool MCP in the portal and send it in the header:
claude mcp add --transport http nextool https://mcp.nextoolsolutions.com/mcp/principal \ --header "Authorization: Bearer nxm_..."
For other connections, use another server name (e.g. nextool-staging) with its URL.
Cursor and VS Code use the API key: generate it under My Account → NexTool MCP → Access keys and replace nxm_... with yours.
Cursor: ~/.cursor/mcp.json (or .cursor/mcp.json in the project)
VS Code: .vscode/mcp.json in the project
The nxm_ key is shown only once, when it is generated. Keep it like a password and revoke it in the portal if it leaks.
Done: try list my open tickets. If the account has no verified connection yet, the assistant only gets the nextool_setup tool, which explains what is missing.
Connections and multiple instances
One connection is one GLPI. If you work with production and staging, or with several customers, create one connection for each.
One URL per connection
Each connection has an identifier that forms the connector URL. It does not change once created, because it is the address the assistant uses.
Read-only per connection
Turn it on or off in the list, with no new test. When on, every tool that creates, changes or deletes is refused before it reaches GLPI. Recommended for production.
Authorization per connector
A sign-in authorized on one connector is valid only for its URL: a staging connector cannot reach production.
Tool groups
Each connection picks its own groups. Fewer tools make the assistant faster and more accurate.
Free and Pro
| In the hosted version | Free | Pro |
|---|---|---|
| Connections (one GLPI each) | 1 | up to 10 |
| Requests per minute | 60 | 300 |
| Read-only per connection | Yes | Yes |
| How to get it | Any NexTool portal account, free during the beta | NexTool MCP Pro license of your NexTool environment, or NexBot |
If the account goes back to Free, the connections over the limit (the newest ones) are paused, with nothing lost, until you delete others or return to Pro.
What you can ask
Talk as you would to a service desk colleague. The assistant picks the tool; you see which one and, for those that change data, confirm first.
Essential
coreReads of tickets, problems, changes, assets, knowledge base, documents and users, plus the ticket operations that delete nothing. Ticked by default.
Example requests
- List my open tickets.
- Summarize the history of ticket 123.
- Add a followup to 123 saying the equipment arrives tomorrow.
Tickets
ticketsFull ticket lifecycle: open, update, assign, follow up, solve, tasks and approvals.
Example requests
- Open a ticket for John: the 3rd floor printer is out of toner.
- Assign ticket 456 to the Infrastructure group.
- Ask Mary for approval on ticket 789.
Problems and changes
itilITIL problems and changes, with the timeline, tasks and solutions.
Example requests
- Which changes are planned for this week?
- Create a problem for the VPN outages reported today.
- Show the timeline of change 42.
Assets and inventory
assetsComputers, monitors, printers and other assets, with reservations and locations.
Example requests
- Which computers are assigned to user Carlos?
- Find the asset with serial number ABC123.
- Which items are reserved for tomorrow?
Knowledge base
kbSearch and read articles and categories; create and edit when the profile allows.
Example requests
- Search the knowledge base for VPN.
- Turn the solution of ticket 321 into an article.
- List the knowledge base categories.
Documents
documentsDocuments and their links to tickets and assets. Reading is already in Essential.
Example requests
- Which attachments does ticket 123 have?
- Show the documents linked to laptop NB-045.
Users and groups
usersLook up users and groups, to put a name on requesters and technicians.
Example requests
- Who is the user with the email [email protected]?
- Who belongs to the Service Desk L2 group?
Search
searchGLPI's generic search, with filters and counts. Already in Essential and Tickets.
Example requests
- How many tickets were opened this month in the Network category?
- List the tickets pending for more than 7 days.
Administration
adminEntities, business rules, followup templates, webhooks and creating users and groups. Turn it on only if you need it.
Example requests
- List the ticket assignment rules.
- Which webhooks failed today?
API v2 (GLPI 11)
v2The GLPI 11 API v2 tools, with OAuth: ticket team, timeline, knowledge base, documents and rules.
Example requests
- Show the team of ticket 123.
- Download document 55.
What “my tickets” means
They are the tickets of the GLPI user whose credential is in the connection, as requester, assigned technician or observer. By default only open ones come back, newest first. You can ask for only the ones you opened, only the ones assigned to you, or include closed ones. This query uses the REST API v1.
The AI follows GLPI permissions
Every action runs as the token's user, with that user's profile and entities: whatever they cannot see or change in GLPI, the AI cannot either. Status and priority names come in that user's GLPI language.
Each group's code is the preset name in the local version (GLPI_TOOLSETS). In the portal, Documents and Search are not separate groups: their reads are already in Essential.
Security and privacy
How the service protects your GLPI and your data.
Annotations and confirmation
Every tool declares itself read-only or destructive. AI clients use this to ask for your confirmation before changing data.
Deletes blocked
In the hosted version, no delete tool is available, on any plan. Deleting stays with you, in GLPI.
Encrypted credentials
Sealed the moment you save, with a key only the connector can open. The portal stores the encrypted envelope and cannot open it; nxm_ keys are stored only as a hash.
No conversation stored
The connector does not store questions, answers or GLPI content. The audit log keeps only metadata: account, connection, tool and time, never the arguments.
No access to internal networks
The connector only calls public addresses: it refuses private IPs, localhost and internal cloud addresses, checks the IP on every connection and never follows a redirect to another host.
Usage limits
There is a per-minute request limit per key or sign-in (60 on Free, 300 on Pro) and another per destination GLPI, so an assistant stuck in a loop cannot overload your GLPI.
Dedicated user, minimal profile
Do not use a Super-Admin: the AI would have full access. Create a user just for the AI, with the profile and entities it needs, and use that user's token.
Revocable access
Revoke a key or an authorized app under My Account → NexTool MCP: access stops within a minute.
Limits and large answers
A large GLPI has thousands of tickets. So the answer fits in the conversation, the connector delivers it in parts.
Paginated listings
25 items per page by default, up to 100 per call.
Size cap
Each answer stays under 50,000 characters. A longer listing is trimmed at the end, and the answer says so.
Long texts shortened
In listings, texts over 300 characters are cut; opening the item brings the full text. Ticket history is never cut.
Next page
Every partial answer says how to get the rest. Just ask: show the next page or get the next 50.
Tip: filter in the request itself (status, period, category, technician). Pending tickets in the Network category opened this month answers faster and uses less context than all tickets.
Hit the request limit? The assistant gets a notice to wait a few seconds and try again.
Local open source version
The same tools, running on your machine or server, under the MIT license.
When to use it
- Your GLPI only exists on the intranet, with no internet access.
- You want everything to stay inside your network, without going through an external service.
- You need something the hosted version does not offer, such as the delete tools (with a mandatory written reason).
Installation
Published on npm (@nextoolsolutions/mcp-glpi) and in the official MCP Registry as com.nextoolsolutions/glpi. npx downloads and runs the latest version, with no cloning or building. The installation guide has the examples for Claude Desktop, Cursor and VS Code.
Main variables
| Variable | Effect |
|---|---|
GLPI_URL | GLPI address (REST API v1) |
GLPI_USER_TOKEN | The user's API token |
GLPI_APP_TOKEN | API client App-Token (optional) |
GLPI_V2_* | GLPI 11 API v2, with OAuth (optional) |
GLPI_TOOLSETS | Tool presets, comma-separated |
GLPI_READ_ONLY=true | Blocks every write before it reaches GLPI. Recommended to start with. |
GLPI_ALLOW_DELETE=true | Enables the delete tools, off by default. Each deletion requires a written reason. |
To start safely, use GLPI_READ_ONLY=true: every write is blocked before it reaches GLPI.
Troubleshooting
The most common cases, from symptom to fix. For connection test errors, see the table in step 4.
| Symptom | Likely cause | What to do |
|---|---|---|
| The assistant says no GLPI is connected | The account has no verified connection, or the connector URL uses an identifier that does not exist. | In the portal, test the connection until it is Verified and check the connector URL. |
| The authorization screen shows no Authorize button | The connection for that URL does not exist, is not verified or is over the plan limit. | Use the link on that screen to create or test the connection, then come back to finish. |
| 401 (unauthorized) error in the client | Wrong or revoked nxm_ key, or an expired or revoked sign-in. | Generate another key or reconnect the connector (in Claude Code, /mcp). |
| The AI cannot change anything | Read-only connection, tool group unticked or a GLPI profile without the right. | Turn off read-only, tick the group or adjust the user's profile in GLPI. |
| A tool you expected is missing | Its group is not ticked on the connection, or its API (v1 or v2) is not configured. | Edit the connection and tick the group or fill in the API; the change applies within a minute. |
| “My tickets” is empty or someone else's | The list belongs to the token's user, not to whoever is chatting with the AI. | Use your own user's token or ask for a person's tickets by name. |
| Request limit notice | The assistant made too many calls in one minute. | Wait a few seconds and ask for more filtered lists. On Pro, the limit is higher. |
| A connection shows as Over the plan limit | The account went back to Free with more than one connection. | Delete connections or return to Pro; nothing was erased. |
| I asked twice and only one record was created | Duplicate protection: the same create call, with the same data, within 2 minutes returns the first result. | This is expected. If you really want another record, change some detail in the request. |
Frequently asked questions
Do I need to install anything to use the hosted version?
No. You only need the NexTool portal account, the GLPI connection and the connector URL in your assistant. In Claude Code, Cursor and VS Code, just the MCP server configuration.
Can I connect more than one GLPI?
Yes, on the Pro plan: up to 10 connections, one per GLPI, each with its own connector URL. On Free, one connection.
Can NexTool see my tickets?
Calls to your GLPI go through the connector, which stores no questions, answers or GLPI content. The audit log keeps only usage metadata, and credentials are encrypted with a key only the connector can open.
What happens if I revoke a key or an app?
Access stops within a minute. To use it again, generate another key or authorize the connector again.
Does it work with GLPI 10?
Yes, through the REST API v1. API v2 and the glpi_v2 tools require GLPI 11.
What is the difference between API v1 and API v2?
v1 is the classic REST API of GLPI 10 and 11, with a user token. v2 is the new GLPI 11 API, with OAuth. You can use one or both on the same connection, always with the same GLPI user.
Ready to connect your GLPI?
Create your free account and connect your GLPI in a few minutes, or start with the open source version.
Not affiliated with Teclib'. GLPI is a registered trademark of Teclib'.