Documentation

How NexTool MCP for GLPI works

From signing up on the portal to your first question to the AI: how the service links your assistant to your GLPI, what you can ask and how your data stays protected.

Not affiliated with Teclib'. GLPI is a registered trademark of Teclib'.

Overview

NexTool MCP sits in the middle: it receives the assistant's request, checks who you are on the NexTool portal and calls your GLPI API with the credentials you registered.

You chat

You ask in plain language. The assistant picks the right GLPI tool (there are more than 160) and shows what it is about to do.

The connector checks

On every request, NexTool MCP checks with the portal whether the key or sign-in is valid, which connection to use, the plan limit and whether the connection is read-only.

GLPI answers

The call reaches the GLPI API as the token's user. Whatever that user cannot do in GLPI, the AI cannot do either.

Hosted version, step by step Open beta

Open to everyone and free during the beta. Five steps, from sign-up to your first question.

  1. 1

    Create your NexTool portal account

    It's free and uses your portal account, with no separate sign-up. Already have an account? Just sign in.

  2. 2

    Open My Account → NexTool MCP

    The portal's NexTool MCP page holds your GLPI connections, API keys, authorized apps and your plan.

  3. 3

    Create the connection to your GLPI

    Give it a name (e.g. Production), enter the GLPI HTTPS address and pick the API:

    • REST API v1 (GLPI 10 and 11): the user token and, if the GLPI API client requires it, the App-Token.
    • API v2 (GLPI 11, OAuth): the API v2 address, the client ID and secret of a GLPI OAuth client, plus username and password.
    • Both: fill in both with credentials of the same person in GLPI. If v1 and v2 authenticate different users, the test blocks the connection.

    Tick the tool groups the AI may use (Essential is ticked by default) and, if you want, turn on read-only.

    Credentials are encrypted the moment you save, with a key only the connector can open: neither the portal nor the NexTool team can read them.

  4. 4

    Test the connection

    When you save, the portal tests right away and shows the GLPI version plus the user and profile each API authenticated. If it fails, the message tells you why:

    What you seeWhat it meansWhat to do
    GLPI not reachable from the internetIt points to a private or blocked network (internal IP, localhost).Publish GLPI on a public HTTPS address or use the open source version inside your network.
    GLPI could not be reachedDNS failure, timeout or connection refused.Check the address, DNS and firewall.
    Invalid certificateThe HTTPS certificate is expired, self-signed or does not match the address.Install a valid certificate (for example, Let's Encrypt).
    RedirectGLPI redirects to another address (http to https, another domain, a login page).Enter the final address, as the browser shows it after the redirect.
    Does not answer as the GLPI APIThe address answers, but not as the GLPI API (proxy, login page, wrong path).Use the GLPI root, without /front or /apirest.php at the end.
    API disabledThe REST API is turned off in GLPI.In Setup → General → API, enable the REST API and login with token.
    IP not allowedThe GLPI API client only accepts some IPs, and the connector's is not one of them.The portal message shows the connector's IP: allow it in the API client (Setup → General → API).
    Credentials refusedGLPI refused the App-Token, the user token or OAuth.Generate the token again and check that the App-Token belongs to the right API client.
    Different users on the two APIsv1 and v2 authenticated different people in GLPI.Use credentials of the same user on both APIs.

    A user with the Super-Admin profile does not block the test, but the portal shows a strong warning: prefer a dedicated user with a minimal profile.

  5. 5

    Connect your assistant

    Each connection has its own connector URL, shown in the portal list with a copy button:

    https://mcp.nextoolsolutions.com/mcp/principal

    principal is the identifier of the account's first connection; the others use the identifier you choose. The address without an identifier (/mcp) also works and uses the first verified connection.

  1. 1

    Under Settings → Connectors, click Add custom connector.

  2. 2

    Give it a name (e.g. GLPI Production) and paste the connection URL:

    https://mcp.nextoolsolutions.com/mcp/principal
  3. 3

    Click Connect: the NexTool portal sign-in opens. Sign in with your account.

  4. 4

    On the authorization screen, check the app, the return address and the GLPI connection that will be used, then click Authorize.

One connector per GLPI: for another connection, add another connector with its URL. To cut access, revoke it under My Account → NexTool MCP → Authorized apps.

Done: try list my open tickets. If the account has no verified connection yet, the assistant only gets the nextool_setup tool, which explains what is missing.

Connections and multiple instances

One connection is one GLPI. If you work with production and staging, or with several customers, create one connection for each.

One URL per connection

Each connection has an identifier that forms the connector URL. It does not change once created, because it is the address the assistant uses.

Read-only per connection

Turn it on or off in the list, with no new test. When on, every tool that creates, changes or deletes is refused before it reaches GLPI. Recommended for production.

Authorization per connector

A sign-in authorized on one connector is valid only for its URL: a staging connector cannot reach production.

Tool groups

Each connection picks its own groups. Fewer tools make the assistant faster and more accurate.

Free and Pro

In the hosted versionFreePro
Connections (one GLPI each)1up to 10
Requests per minute60300
Read-only per connectionYesYes
How to get itAny NexTool portal account, free during the betaNexTool MCP Pro license of your NexTool environment, or NexBot

If the account goes back to Free, the connections over the limit (the newest ones) are paused, with nothing lost, until you delete others or return to Pro.

What you can ask

Talk as you would to a service desk colleague. The assistant picks the tool; you see which one and, for those that change data, confirm first.

Essential

core

Reads of tickets, problems, changes, assets, knowledge base, documents and users, plus the ticket operations that delete nothing. Ticked by default.

Example requests

  • List my open tickets.
  • Summarize the history of ticket 123.
  • Add a followup to 123 saying the equipment arrives tomorrow.

Tickets

tickets

Full ticket lifecycle: open, update, assign, follow up, solve, tasks and approvals.

Example requests

  • Open a ticket for John: the 3rd floor printer is out of toner.
  • Assign ticket 456 to the Infrastructure group.
  • Ask Mary for approval on ticket 789.

Problems and changes

itil

ITIL problems and changes, with the timeline, tasks and solutions.

Example requests

  • Which changes are planned for this week?
  • Create a problem for the VPN outages reported today.
  • Show the timeline of change 42.

Assets and inventory

assets

Computers, monitors, printers and other assets, with reservations and locations.

Example requests

  • Which computers are assigned to user Carlos?
  • Find the asset with serial number ABC123.
  • Which items are reserved for tomorrow?

Knowledge base

kb

Search and read articles and categories; create and edit when the profile allows.

Example requests

  • Search the knowledge base for VPN.
  • Turn the solution of ticket 321 into an article.
  • List the knowledge base categories.

Documents

documents

Documents and their links to tickets and assets. Reading is already in Essential.

Example requests

  • Which attachments does ticket 123 have?
  • Show the documents linked to laptop NB-045.

Users and groups

users

Look up users and groups, to put a name on requesters and technicians.

Example requests

  • Who is the user with the email [email protected]?
  • Who belongs to the Service Desk L2 group?

Search

search

GLPI's generic search, with filters and counts. Already in Essential and Tickets.

Example requests

  • How many tickets were opened this month in the Network category?
  • List the tickets pending for more than 7 days.

Administration

admin

Entities, business rules, followup templates, webhooks and creating users and groups. Turn it on only if you need it.

Example requests

  • List the ticket assignment rules.
  • Which webhooks failed today?

API v2 (GLPI 11)

v2

The GLPI 11 API v2 tools, with OAuth: ticket team, timeline, knowledge base, documents and rules.

Example requests

  • Show the team of ticket 123.
  • Download document 55.

What “my tickets” means

They are the tickets of the GLPI user whose credential is in the connection, as requester, assigned technician or observer. By default only open ones come back, newest first. You can ask for only the ones you opened, only the ones assigned to you, or include closed ones. This query uses the REST API v1.

The AI follows GLPI permissions

Every action runs as the token's user, with that user's profile and entities: whatever they cannot see or change in GLPI, the AI cannot either. Status and priority names come in that user's GLPI language.

Each group's code is the preset name in the local version (GLPI_TOOLSETS). In the portal, Documents and Search are not separate groups: their reads are already in Essential.

Security and privacy

How the service protects your GLPI and your data.

Annotations and confirmation

Every tool declares itself read-only or destructive. AI clients use this to ask for your confirmation before changing data.

Deletes blocked

In the hosted version, no delete tool is available, on any plan. Deleting stays with you, in GLPI.

Encrypted credentials

Sealed the moment you save, with a key only the connector can open. The portal stores the encrypted envelope and cannot open it; nxm_ keys are stored only as a hash.

No conversation stored

The connector does not store questions, answers or GLPI content. The audit log keeps only metadata: account, connection, tool and time, never the arguments.

No access to internal networks

The connector only calls public addresses: it refuses private IPs, localhost and internal cloud addresses, checks the IP on every connection and never follows a redirect to another host.

Usage limits

There is a per-minute request limit per key or sign-in (60 on Free, 300 on Pro) and another per destination GLPI, so an assistant stuck in a loop cannot overload your GLPI.

Dedicated user, minimal profile

Do not use a Super-Admin: the AI would have full access. Create a user just for the AI, with the profile and entities it needs, and use that user's token.

Revocable access

Revoke a key or an authorized app under My Account → NexTool MCP: access stops within a minute.

Limits and large answers

A large GLPI has thousands of tickets. So the answer fits in the conversation, the connector delivers it in parts.

Paginated listings

25 items per page by default, up to 100 per call.

Size cap

Each answer stays under 50,000 characters. A longer listing is trimmed at the end, and the answer says so.

Long texts shortened

In listings, texts over 300 characters are cut; opening the item brings the full text. Ticket history is never cut.

Next page

Every partial answer says how to get the rest. Just ask: show the next page or get the next 50.

Tip: filter in the request itself (status, period, category, technician). Pending tickets in the Network category opened this month answers faster and uses less context than all tickets.

Hit the request limit? The assistant gets a notice to wait a few seconds and try again.

Local open source version

The same tools, running on your machine or server, under the MIT license.

When to use it

  • Your GLPI only exists on the intranet, with no internet access.
  • You want everything to stay inside your network, without going through an external service.
  • You need something the hosted version does not offer, such as the delete tools (with a mandatory written reason).

Installation

claude mcp add glpi \ -e GLPI_URL=https://glpi.example.com \ -e GLPI_USER_TOKEN=<user-token> \ -e GLPI_APP_TOKEN=<app-token> \ -- npx -y @nextoolsolutions/mcp-glpi

Published on npm (@nextoolsolutions/mcp-glpi) and in the official MCP Registry as com.nextoolsolutions/glpi. npx downloads and runs the latest version, with no cloning or building. The installation guide has the examples for Claude Desktop, Cursor and VS Code.

Main variables

VariableEffect
GLPI_URLGLPI address (REST API v1)
GLPI_USER_TOKENThe user's API token
GLPI_APP_TOKENAPI client App-Token (optional)
GLPI_V2_*GLPI 11 API v2, with OAuth (optional)
GLPI_TOOLSETSTool presets, comma-separated
GLPI_READ_ONLY=trueBlocks every write before it reaches GLPI. Recommended to start with.
GLPI_ALLOW_DELETE=trueEnables the delete tools, off by default. Each deletion requires a written reason.

To start safely, use GLPI_READ_ONLY=true: every write is blocked before it reaches GLPI.

Troubleshooting

The most common cases, from symptom to fix. For connection test errors, see the table in step 4.

SymptomLikely causeWhat to do
The assistant says no GLPI is connectedThe account has no verified connection, or the connector URL uses an identifier that does not exist.In the portal, test the connection until it is Verified and check the connector URL.
The authorization screen shows no Authorize buttonThe connection for that URL does not exist, is not verified or is over the plan limit.Use the link on that screen to create or test the connection, then come back to finish.
401 (unauthorized) error in the clientWrong or revoked nxm_ key, or an expired or revoked sign-in.Generate another key or reconnect the connector (in Claude Code, /mcp).
The AI cannot change anythingRead-only connection, tool group unticked or a GLPI profile without the right.Turn off read-only, tick the group or adjust the user's profile in GLPI.
A tool you expected is missingIts group is not ticked on the connection, or its API (v1 or v2) is not configured.Edit the connection and tick the group or fill in the API; the change applies within a minute.
“My tickets” is empty or someone else'sThe list belongs to the token's user, not to whoever is chatting with the AI.Use your own user's token or ask for a person's tickets by name.
Request limit noticeThe assistant made too many calls in one minute.Wait a few seconds and ask for more filtered lists. On Pro, the limit is higher.
A connection shows as Over the plan limitThe account went back to Free with more than one connection.Delete connections or return to Pro; nothing was erased.
I asked twice and only one record was createdDuplicate protection: the same create call, with the same data, within 2 minutes returns the first result.This is expected. If you really want another record, change some detail in the request.

Frequently asked questions

No. You only need the NexTool portal account, the GLPI connection and the connector URL in your assistant. In Claude Code, Cursor and VS Code, just the MCP server configuration.

Yes, on the Pro plan: up to 10 connections, one per GLPI, each with its own connector URL. On Free, one connection.

Calls to your GLPI go through the connector, which stores no questions, answers or GLPI content. The audit log keeps only usage metadata, and credentials are encrypted with a key only the connector can open.

Access stops within a minute. To use it again, generate another key or authorize the connector again.

Yes, through the REST API v1. API v2 and the glpi_v2 tools require GLPI 11.

v1 is the classic REST API of GLPI 10 and 11, with a user token. v2 is the new GLPI 11 API, with OAuth. You can use one or both on the same connection, always with the same GLPI user.

Ready to connect your GLPI?

Create your free account and connect your GLPI in a few minutes, or start with the open source version.

Not affiliated with Teclib'. GLPI is a registered trademark of Teclib'.

Need help?