Integration profile
AI agent for Zendesk internal helpdesk: options and limits
Two documented ways to put an AI agent on a Zendesk internal desk, the credential question Zendesk has now dated, and the checks that decide between them.
8 min read
Updated on
An AI agent for an internal help desk running on Zendesk comes in two documented forms. Zendesk documents native AI agents, billed per automated resolution, and Employee Service Suite plans for organizations that use Zendesk exclusively for internal services; which AI features and which resolution allowances apply to the Employee Service plan chosen has to be confirmed. The other form is a third-party agent that connects to Zendesk and creates or syncs its tickets, as several vendors document. Three checks apply to that second form. The credential: Zendesk is removing Support API tokens (Ticketing, Help Center and Voice APIs), blocking new ones from October 27, 2026 and stopping all of them on April 30, 2027, so a token-based integration has to move to OAuth. The round trip: how resolution syncs between an agent and Zendesk is not always documented consistently, and has to be tested before a desk depends on it. The load: Zendesk’s API rate limits per plan apply to every client, whichever agent calls.
What does Zendesk offer on its own for an internal desk?
Zendesk’s help center describes Employee Service Suite plans as plans “for organizations that want to use Zendesk products exclusively for internal services, including Human Resources (HR), Finance, Legal, and Information Technology (IT)”. It says they include all features of the equivalent Customer Service Suite plans, and add a Workday integration that gives agents a read-only view of employee information inside tickets, a service catalog, approvals, tasks, and IT asset management, which the article labels EAP.
On AI, the pricing page states that “Zendesk AI agents are included in every Suite and Support plan”, and that the unit billed is the automated resolution: “you pay only for customer requests that were successfully resolved by the AI agent, without any escalation to a human agent”. The same page describes Zendesk pricing as “primarily seat-based (per agent, per month)”, and lists included automated resolutions that vary by plan and agent count. Whether a given Employee Service Suite plan carries those AI agents on the same terms is a question for the plan terms; the two pages read for this guide do not join the two statements.
The native route needs no third-party connection to Zendesk. The credential, mapping and sync questions below concern the other route.
How does a third-party agent work in front of Zendesk?
Risotto’s and Siit’s pages describe one pattern: employees ask in a chat tool or a portal, the agent answers what it can, and Zendesk stays the place where specialist work is tracked. Serval’s page uses Zendesk as one of its help desk channels and pulls its tickets, and Harmony’s page has its AI resolve Zendesk tickets. The pages also differ on what crosses over.
Risotto’s Zendesk page says “Every Risotto conversation creates a Zendesk ticket automatically.
Updates in either system sync in real-time.” Serval registers Zendesk as both a ticket source and a
knowledge source: its ticket sync checks connected channels for new and updated tickets every 30
seconds and writes Serval-side changes back, and Help Center articles enter its knowledge base only
once an admin includes them, since newly discovered items start out excluded. Harmony’s page lists
bidirectional ticket synchronisation and adds an inventory of Zendesk agents and admins, with their
roles, account status and last sign-in. The Siit page describes escalation rather than mirroring:
a request is escalated into a chosen Zendesk group and ticket form, and the ticket is created and
linked on both sides. The same action exists as a workflow step and, with optional approval, as
/zendesk create ticket in IT Agent playbooks; how such approval gates are usually set is covered
in what autonomy means for an IT
agent.
Each of these is a vendor statement about its own product. Why an agent can sit in front of an installed platform at all, and what it costs to get the order wrong, is covered in adding an agent without replacing your ITSM and, for Atlassian’s platform, on the Jira Service Management profile.
Two ways in
Zendesk documents native AI agents, billed per automated resolution, and Employee Service Suite plans; confirm what the chosen plan includes. Third-party agents connect to Zendesk and create or sync its tickets. Both are documented.
API tokens have an end date
Zendesk's announcement blocks new Support API token creation from October 27, 2026 and stops all Support API tokens (Ticketing, Help Center and Voice APIs) on April 30, 2027. Integrations that use them must move to OAuth.
Credentials follow a role
Zendesk documents that an OAuth token created through its API changes permissions when the requester's role changes. Vendor pages that use a service account make that account's role the thing to review.
Ticket forms depend on the plan
Zendesk's reference says ticket forms are supported on Suite Growth plans and above and on Support Enterprise plans. An escalation built on a form presumes such a plan.
Which credential should hold the connection now that API tokens are ending?
Zendesk’s security page labels API tokens deprecated: as passwords, they “can be used to impersonate anyone in the account, including admins”, and Zendesk points to OAuth access tokens as the more secure alternative. An OAuth token gives access to a single Zendesk instance. A vendor that distributes an app or integration to multiple Zendesk customers must use global OAuth tokens; Zendesk says that requirement does not apply to integrations built for internal use.
The retirement is now dated. Zendesk’s announcement of June 1, 2026 sets three phases: from July 28, 2026, tokens unused for 30 days are deactivated and new accounts cannot create or use tokens; from October 27, 2026, no account can create new API tokens; on April 30, 2027, all remaining tokens are deactivated permanently. It covers APIs that use API tokens, including the Ticketing, Help Center and Voice APIs, and says “There is no opt-out or extension beyond April 30, 2027.”
The vendor pages read for this guide sit at different points of that transition. Serval connects
with an OAuth 2.0 client-credentials grant from a confidential client, requests the read write
scopes, and documents how to move an older API-token connection to OAuth before April 30, 2027.
Harmony’s page has the admin create an API token and enter the admin email it belongs to, and
states that Zendesk “has not announced a shutdown date”; the Zendesk announcement above gives one.
The Siit page has a Zendesk admin sign in and approve the requested scopes after entering the
subdomain; it does not name the token type, and the word OAuth does not appear on it.
Zendesk’s page on creating tokens with the API says only admins or agents with the Manage APIs permission can make the request, and “if the requester’s role later changes, the token’s access permissions automatically changes to reflect the new role”. Serval’s page states that Zendesk attributes every action taken with a client-credentials token to the user who created the OAuth client, and that Serval’s access is bounded by that user’s role. Serval and Siit both recommend a dedicated service account, so that the connection, or its attribution, survives staff changes. Read together, those pages make the role of that account the thing to review, and to keep stable.
What does the agent write into Zendesk, and what decides where it lands?
Groups and ticket forms decide where an escalation lands. The Siit page has the admin pick the groups and forms available for escalation, and its troubleshooting entry for a group missing from the destination picker gives the cause as the Siit Zendesk user lacking access to that group: on that page, the connecting account’s group access decides which groups can be picked. Serval reads Zendesk groups and their membership only once an admin turns on resource sync, and never writes membership back.
Ticket forms are a Zendesk object with published rules. Zendesk’s reference says they “allow an
admin to define a subset of ticket fields for display to both agents and end users”, that end
users only see forms with end_user_visible set to true, and that forms are supported on Suite
Growth plans and above, as well as on Support Enterprise plans. A form carries ticket_field_ids,
restricted_brand_ids, agent_conditions and end_user_conditions.
Harmony’s troubleshooting for duplicate tickets begins with checking custom field mapping for unique identifiers. Serval maps priorities between the two systems and writes its “none” priority to Zendesk as low.
Where are the limits, and whose are they?
Zendesk’s own limits apply to any client of its API. Its rate-limit page gives Support and Help
Center API requests per minute by Suite plan: 200 on Team, 400 on Growth, 400 on Professional, 700
on Enterprise and 2,500 on Enterprise Plus. An excess is answered with HTTP 429 and a Retry-After
header. Some endpoints carry their own limit: Update Ticket allows 30 updates to the same ticket by
the same user within 10 minutes, and the incremental export endpoints have a global limit of 10
requests per minute. The High Volume API add-on raises a qualifying plan to 2,500 requests per minute and
requires at least 10 agent seats. Serval and Harmony both say they retry automatically when Zendesk
rate-limits a request. Serval adds that very high-volume workflows can still exhaust an instance’s
limit; neither page says how close a typical deployment comes to it.
Plan level is the last boundary. Ticket forms, as quoted above, need Suite Growth or Support Enterprise, so an escalation path built on a form presumes one of those plans.
What should be checked before an internal desk depends on it?
The sources read here support five checks. First, the plan: Employee Service Suite plans are the ones Zendesk describes for exclusively internal use, and ticket forms depend on plan level. Second, the billing unit: Zendesk bills its AI agents per automated resolution on a seat-based plan, which, as this guide’s inference rather than a Zendesk statement, makes the definition of a resolution part of the bill; the definitions behind any resolution or deflection figure are laid out in what the deflection number covers. Third, the credential: whether a third-party connection uses OAuth or an API token that stops working on April 30, 2027. Fourth, the role: which Zendesk account holds the connection, and what its role allows. Fifth, the round trip: what happens on each side when a ticket is resolved on the other.
Each of these is answered in Zendesk’s admin settings or in the agent vendor’s documentation, and each can be tested on a sandbox request before an internal desk depends on it.
Which vendors document a Zendesk connection for an internal-support agent?
Listed here: vendors of an AI agent for internal support whose public documentation, read in October 2026, describes a Zendesk connection and says what the agent creates in Zendesk or syncs from it. Zendesk’s own AI agents run inside Zendesk and are covered above.
- Harmony: its Zendesk integration page lists bidirectional ticket sync and an inventory of Zendesk agents and admins, connected with an API token and the admin email it belongs to.
- Risotto: its Zendesk integration page says every Risotto conversation creates a Zendesk ticket and that updates in either system sync in real time; the page does not name the credential used.
- Serval: its Zendesk integration page describes two-way ticket sync and Help Center knowledge sync over an OAuth 2.0 client-credentials connection.
- Siit: its Zendesk connector page describes escalating a request into a chosen Zendesk group and ticket form, with the ticket linked on both sides, after a Zendesk admin approves the requested scopes.
The tools involved
Zendesk
A ticketing platform with Employee Service Suite plans for organizations that use Zendesk exclusively for internal services. Zendesk says these plans include all features of the equivalent Customer Service Suite plans, plus a Workday integration, a service catalog, approvals, tasks and IT asset management.
Frequently asked questions
What are the options for an AI agent for Zendesk internal helpdesk?
Two are documented. Zendesk documents native AI agents, billed per automated resolution, and Employee Service Suite plans for internal services; confirm which AI features and resolution allowances apply to the plan you choose. Or a third-party agent connects to Zendesk and creates or syncs its tickets, which several vendors describe on their Zendesk integration pages.
Do Zendesk API tokens still work for an agent integration?
For a limited time. Zendesk's announcement says that since July 28, 2026 any token unused for 30 days is deactivated automatically, that accounts can no longer create API tokens from October 27, 2026, that existing active tokens remain usable until April 30, 2027 unless deactivated, and that all Support API tokens (Ticketing, Help Center and Voice APIs) stop working on that date. Integrations that rely on them have to move to OAuth before then.
Does resolution sync back between an agent and Zendesk?
It depends on the vendor, and the public pages are not always consistent: some describe two-way status sync, while another page offers a resolution sync setting and also advises tracking resolution manually. Resolve a test ticket in Zendesk and check the agent side, then resolve one on the agent side and check Zendesk, before relying on it.
Which vendors offer an AI agent that connects to a Zendesk internal helpdesk?
Among vendors of an AI agent for internal support whose public documentation, read in October 2026, describes a Zendesk connection and says what the agent creates in Zendesk or syncs from it: Harmony, Risotto, Serval and Siit, in alphabetical order. Zendesk's own AI agents run inside Zendesk and need no connection.
Sources
- Zendesk integration (Siit documentation) · Siit
- Announcing the removal of API tokens as an authentication method for API requests · Zendesk
- Security and authentication (Zendesk API reference) · Zendesk
- Creating and using OAuth access tokens with the API · Zendesk
- Ticket Forms API reference · Zendesk
- Rate limits (Zendesk API reference) · Zendesk
- About the Zendesk Employee Service Suite · Zendesk
- Zendesk pricing plans · Zendesk
- Zendesk integration (Harmony documentation) · Harmony
- Zendesk integration (Serval documentation) · Serval
- Zendesk integration · Risotto