Zapier

Zapier

Included as an action broker that lets a server owner expose a deliberately selected set of connected-app operations to one AI client, with per-tool authentication, call history, task metering, and collaboration roles around the server configuration.

Automation, data & MCP bridgesSystem of orchestrationAgent-accessible SaaS
An illustration of access surfaces surrounding a governed system.
System roleSystem of orchestration
Access maturityAgent-accessible SaaS
MCP supportOfficial MCP server
Reference updatedNot stated by publisher
BYO-UI reviewedJul 22, 2026

Concrete capability record

Data, retrieval, actions, identity, and operating limits

A field-by-field summary of what the reviewed first-party references actually support. Publisher update dates and BYO-UI review dates are shown separately below.

01 · Records and state owned

MCP servers, individual app-action tools, connected app accounts, configured action fields, connection tokens, server members and roles, tool-call history, and Zapier plan tasks.

02 · Data you can retrieve

Read behavior is not a universal Zapier dataset: it consists of the search, find, lookup, or retrieval actions that the server owner explicitly adds and authenticates for particular app accounts.

03 · Actions and write paths

Write behavior consists of explicitly added app actions such as sending messages, creating rows or events, and updating records. Each tool maps to one connected-app action; multi-step outcomes require multiple calls.

04 · Authentication and permissions

The server owner authenticates each app tool and is the only person whose AI client can connect to and execute the server. Editors can add or remove tools but cannot authenticate or change account connections; View only members can inspect tools and history.

05 · Monitoring, approval, and recovery

Server roles control catalog oversight, while tool authentication remains with the owner. Zapier records timestamp, tool name, AI instructions, field values, and output in History. Connection tokens can be rotated to invalidate the prior token immediately.

06 · Limits and caveats

Each successful external-app tool call consumes two Zapier tasks; failed configuration or authentication calls do not. Calls stop when the plan task allowance is exhausted. Server and tool counts and per-session calls are not capped, but connected apps can impose their own rate limits. Server sharing is limited to Team and Enterprise accounts.

Agent access

MCP support

Official MCP serverZapier-hosted integration MCPGenerally available

Support: Official MCP server

Read scope: Expose only owner-selected retrieval actions for named app connections, with any required and AI-supplied fields configured per tool. Tool discovery does not make unconfigured actions available.

Write scope: Expose state-changing operations one action at a time and account by account. Sending, creating, or updating through several apps is a chain of separately logged and separately metered tool calls.

Authentication: Known clients use Zapier’s guided connection flow; generic clients use a one-time-visible bearer connection token, preferably in the Authorization header, and Streamable HTTP. Rotating the token invalidates the previous credential.

Approval boundary: Before a write call, show the app, connected account, action name, destination or record, and all AI-supplied fields. For chains, approve the ordered calls and cumulative task cost rather than treating the natural-language request as one atomic action.

Protocol does not erase product boundaries.

Confirm the current tool catalog, plan, region, scopes, rate limits, terms, and write behavior before implementation.

Editorial assessment

Access-maturity dimensions

A comparative architecture lens—not a quality score, market ranking, or buying recommendation. Scale: 1–5.

Data access4
Action access4
Event access4
Identity2
Governance3
Agent access4
UI extensibility3
Portability4
Observability4
Documentation5

Proposed customer-shaped experiences

What customers could create on top.

The output could be an export, report, graph, artifact, application, agent, workflow, or downstream feed. These proposals are derived from documented access—not claims that Zapier ships them.

Single-platform patterns

  • Rapid MCP wrapper and campaign workflow factory
  • Marcom control plane
  • Data-quality exception console
  • Approved capability registry
Use in the brief builder →

Multi-platform compositions

  • Zapier + systems of record: marcom control plane
  • Zapier + systems of engagement + interface host or builder: cross-system decision workspace
Explore composition recipes →

Evidence and dates

First-party references, with publisher and review dates separated

“Publisher updated” is shown only when the page exposes an update date. “BYO-UI reviewed” records when this research checked the reference. A missing publisher date is reported as missing—not replaced with the review date.

5 recorded sources
MCPRepresentative source
https://zapier.com/mcp ↗

Official product and technical docs confirm hosted MCP; action counts are time-sensitive and should carry verification dates.

Publisher published
Jul 9, 2026
BYO-UI reviewed
Jul 12, 2026

Targeted first-party MCP/agent-role review; broader API inventory retained

Developer docsSource inventory
https://docs.zapier.com/ ↗

First-party developer documentation or platform overview.

Publisher updated
Jun 24, 2026
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

HomepageSource inventory
https://zapier.com/ ↗

First-party product homepage used to confirm product identity and current positioning.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

Webhooks / extensionsSource inventory
https://docs.zapier.com/platform/build ↗

First-party webhook, event, SDK, embedded-app, or extension documentation.

Publisher updated
Jul 6, 2026
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

Verified fact

Tied to cited first-party evidence reviewed for this profile.

Source inventory

Official links recorded for deeper research but not necessarily reopened endpoint by endpoint.

Editorial assessment

System role, maturity interpretation, and architectural boundary.

Proposed design

Interface patterns and compositions—not vendor product claims.