Security & Identity · Integration
Zscaler
Add Zscaler to your product for your customers, and give your AI agents governed access to it.
Zscaler Client Connector is the agent installed on a laptop or a phone that forwards its traffic into Zscaler's cloud, and this connector covers the portal API that manages those enrolments rather than the policy engine sitting behind them. That distinction is the whole scope. You can list the devices a customer has enrolled with their platform, version and current state, export that inventory, force the removal of an enrolment when a machine leaves the estate, and issue the one-time passcode that lets somebody disable or uninstall the client on a device you have authorised. What you cannot do from here is rewrite who may reach which application, because access policy lives in the internet and private access admin APIs instead. Two operational facts shape the build: each customer's tenant sits on a specific Zscaler cloud, so the host is per customer rather than a constant, and the removal endpoint is capped at a few hundred calls a day, which makes bulk offboarding a queue rather than a loop. Every call is scoped to the tenant that authorised it and recorded.
In your product
Embedded for your customers. Per-tenant auth, no per-customer code, maintained by fastn.
Let each customer connect their own tenant and record which Zscaler cloud it sits on, since the API host differs between them.
Read enrolled devices with their platform, version and state, so a customer can see at a glance which machines are actually protected.
Force the removal of an enrolment when a device leaves the estate, under permissions the customer granted for that specific action.
Queue bulk removals instead of looping, because the endpoint is deliberately capped at a few hundred calls a day.
For your AI agents
Governed, audited access for the agents you build, through the MCP server.
An agent lists which devices for a user are still enrolled and when each of them last checked in.
An agent proposes removing an enrolment for a machine that has left the estate and leaves the approval to a person.
An agent explains that it can read and remove enrolments but cannot change access policy, because that lives elsewhere in the platform.
Example prompt
Which devices for this user are still enrolled, and which of them have not checked in for a month?
Set up Zscaler in 4 steps
- 01Enable the Zscaler connector in your fastn dashboard.
- 02Have each customer provide credentials for their own Client Connector portal, along with the Zscaler cloud their tenant sits on.
- 03Map the device fields your product shows, and enable the removal and passcode actions only where you genuinely intend them.
- 04Call it from your product and expose the same connection to your agents through the MCP gateway.
Why teams use the Zscaler integration
What you get by embedding it with fastn instead of building it yourself.
- Ship a Zscaler integration without building it. Your customers connect their own Zscaler account inside your product and work their users, groups and roles there, with no per-customer code on your side.
- Handle the part that actually costs time: the blast radius of an error is large, so least-privilege and auditability are non-negotiable. fastn owns the auth, token refresh, rate limits, pagination and breaking-change fixes, so a Zscaler update is not your on-call problem.
- One integration serves your product and your agents. The same governed Zscaler connection powers in-product features and gives AI agents scoped, audited access, so you keep access and identity in step across a customer's estate without wiring it twice.
Used by these teams
Compare with
Often used alongside
Tools the same teams tend to run next to Zscaler, across other categories.
Zscaler integration FAQ
How do I add a Zscaler integration to my product?
Enable the Zscaler connector in your fastn dashboard, then let each customer authenticate their own Zscaler account. fastn handles the OAuth flow, token storage and refresh per tenant, so there is no Zscaler client code in your app and no per-customer branch in your codebase. Setup is 4 steps.
Do my customers each connect their own Zscaler account?
Yes. Every connection is scoped to the individual customer, so each authorises their own Zscaler account and only ever sees their own users, groups and roles. That per-tenant isolation is the point of an embedded integration: you support the long tail of customer setups without maintaining an integration per customer.
Can AI agents use this Zscaler integration?
Yes. The same connection is exposed to your agents through the fastn MCP gateway, with permissions scoped per tenant and every call audited. An agent lists which devices for a user are still enrolled and when each of them last checked in.
Who maintains the Zscaler integration?
fastn does. When Zscaler changes an endpoint, deprecates a field or alters its auth, the fix lands in the connector rather than in your backlog, and your customers' connections keep working.
What permissions does the Zscaler integration need?
Only the scopes required for the actions you enable. Each customer grants access to their own Zscaler tenant, permissions are scoped per tenant, and every call is recorded so an access change can be traced to its source.
Can access changes be automated safely?
Yes. Provisioning and deprovisioning can be driven from your product or an agent within governed permissions, with every action audited, which is what makes automated access changes reviewable after the fact.
What can I build with the Zscaler integration?
A common starting point: let each customer connect their own tenant and record which Zscaler cloud it sits on, since the API host differs between them. Teams also use it for the other use cases listed above, and expose it to agents for governed reads and writes.
How much does the Zscaler integration cost?
It is included. Pricing is based on connected accounts, not on how many connectors you enable, so adding Zscaler does not change your per-connector cost. You can start free with 3 connected accounts.
Add Zscaler to your product
Start free with 3 connected accounts. No sales call required, and no per-customer integration code.