MCP servers, individual app-action tools, connected app accounts, configured action fields, connection tokens, server members and roles, tool-call history, and Zapier plan tasks.
Zapier
Included as an action broker that lets a server owner expose a deliberately selected set of connected-app operations to one AI client, with per-tool authentication, call history, task metering, and collaboration roles around the server configuration.
Concrete capability record
Data, retrieval, actions, identity, and operating limits
A field-by-field summary of what the reviewed first-party references actually support. Publisher update dates and BYO-UI review dates are shown separately below.
Read behavior is not a universal Zapier dataset: it consists of the search, find, lookup, or retrieval actions that the server owner explicitly adds and authenticates for particular app accounts.
Write behavior consists of explicitly added app actions such as sending messages, creating rows or events, and updating records. Each tool maps to one connected-app action; multi-step outcomes require multiple calls.
The server owner authenticates each app tool and is the only person whose AI client can connect to and execute the server. Editors can add or remove tools but cannot authenticate or change account connections; View only members can inspect tools and history.
Server roles control catalog oversight, while tool authentication remains with the owner. Zapier records timestamp, tool name, AI instructions, field values, and output in History. Connection tokens can be rotated to invalidate the prior token immediately.
Each successful external-app tool call consumes two Zapier tasks; failed configuration or authentication calls do not. Calls stop when the plan task allowance is exhausted. Server and tool counts and per-session calls are not capped, but connected apps can impose their own rate limits. Server sharing is limited to Team and Enterprise accounts.
Agent access
MCP support
Support: Official MCP server
Read scope: Expose only owner-selected retrieval actions for named app connections, with any required and AI-supplied fields configured per tool. Tool discovery does not make unconfigured actions available.
Write scope: Expose state-changing operations one action at a time and account by account. Sending, creating, or updating through several apps is a chain of separately logged and separately metered tool calls.
Authentication: Known clients use Zapier’s guided connection flow; generic clients use a one-time-visible bearer connection token, preferably in the Authorization header, and Streamable HTTP. Rotating the token invalidates the previous credential.
Approval boundary: Before a write call, show the app, connected account, action name, destination or record, and all AI-supplied fields. For chains, approve the ordered calls and cumulative task cost rather than treating the natural-language request as one atomic action.
Confirm the current tool catalog, plan, region, scopes, rate limits, terms, and write behavior before implementation.
Editorial assessment
Access-maturity dimensions
A comparative architecture lens—not a quality score, market ranking, or buying recommendation. Scale: 1–5.
Proposed customer-shaped experiences
What customers could create on top.
The output could be an export, report, graph, artifact, application, agent, workflow, or downstream feed. These proposals are derived from documented access—not claims that Zapier ships them.
Single-platform patterns
- Rapid MCP wrapper and campaign workflow factory
- Marcom control plane
- Data-quality exception console
- Approved capability registry
Multi-platform compositions
- Zapier + systems of record: marcom control plane
- Zapier + systems of engagement + interface host or builder: cross-system decision workspace
Evidence and dates
First-party references, with publisher and review dates separated
“Publisher updated” is shown only when the page exposes an update date. “BYO-UI reviewed” records when this research checked the reference. A missing publisher date is reported as missing—not replaced with the review date.
5 recorded sources
Official product and technical docs confirm hosted MCP; action counts are time-sensitive and should carry verification dates.
- Publisher published
- Jul 9, 2026
- BYO-UI reviewed
- Jul 12, 2026
Targeted first-party MCP/agent-role review; broader API inventory retained
First-party API reference or API overview recorded for this platform.
- Publisher updated
- Jul 6, 2026
- BYO-UI reviewed
- Jul 12, 2026
Full-profile first-party re-verification on 2026-07-12; see the private audit ledger.
First-party developer documentation or platform overview.
- Publisher updated
- Jun 24, 2026
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
First-party product homepage used to confirm product identity and current positioning.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
First-party webhook, event, SDK, embedded-app, or extension documentation.
- Publisher updated
- Jul 6, 2026
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
Verified fact
Tied to cited first-party evidence reviewed for this profile.
Source inventory
Official links recorded for deeper research but not necessarily reopened endpoint by endpoint.
Editorial assessment
System role, maturity interpretation, and architectural boundary.
Proposed design
Interface patterns and compositions—not vendor product claims.