Zapier MCP Server
v2026.7Zapier
Zapier's hosted, proprietary MCP server giving AI agents access to user-selected actions from 9,000+ connected apps (40,000+ actions). Users create servers at mcp.zapier.com with per-app and per-action permissioning; listed clients connect via OAuth, unlisted clients use a rotatable connection token sent as an Authorization Bearer header (recommended) or embedded in the server URL. Transport is Streamable HTTP; each tool call consumes two Zapier tasks from the plan quota.
Trust Vector Analysis
Dimension Breakdown
๐Performance & Reliability+
Platform stability and maturity analysis
Action execution success testing across common apps
Integration catalog assessment
Rate and usage limit behavior review
Failure mode and recovery testing
๐ก๏ธSecurity+
Authentication mechanism review; score raised from 70 (2026-06-10) to reflect OAuth for listed clients and rotatable header-based bearer tokens replacing static URL-only auth
Credential exposure threat modeling; score raised from 58 (2026-06-10) for header-based auth guidance and immediate token rotation
Blast radius assessment across connected app categories
Per-app and per-action permission model review
Credential storage and isolation review
๐Privacy & Compliance+
Data flow analysis of action inputs and outputs
Data protection controls assessment
Multi-party data sharing review
Compliance certification review
๐๏ธTrust & Transparency+
Documentation completeness review
Logging and traceability assessment
Source availability review
Tool surface documentation review
โ๏ธOperational Excellence+
Setup complexity assessment
Action latency characterization
Uptime and incident history analysis
Capability breadth assessment
Adoption and ecosystem support analysis
- +Broadest action catalog of any MCP server: 9,000+ apps and 40,000+ actions
- +OAuth for listed clients and rotatable header-based connection tokens for unlisted clients
- +Per-app and per-action permissioning enables least-privilege agent configuration
- +Zero-install hosted setup with a personal endpoint generated at mcp.zapier.com
- +Downstream app credentials held by Zapier under SOC 2 Type II audited controls, never exposed to the agent
- +Action invocation history visible in the per-user MCP dashboard
- +Built on a decade-mature integration platform with high availability
- !Extremely broad blast radius by design: a prompt-injected agent can act across email, CRM, chat, and finance apps
- !Connection tokens (and URL-embedded fallback) act as bearer credentials and must be treated as secrets, though rotation is one click
- !Fully proprietary and hosted-only; no source inspection or self-hosting
- !Business data from connected apps flows through Zapier's cloud and the LLM provider
- !Each MCP tool call consumes two Zapier tasks, so costs scale with agent activity under plan-based quotas
- !Expired downstream app connections require manual reauthorization
Use Case Ratings
customer support
Excellent for agents that triage tickets, draft replies, and update CRM records across support stacks
data analysis
Good for pulling records from business apps into analysis, though not an analytics tool itself
content creation
Strong for publishing and distribution workflows across CMS, email, and social apps
code generation
Not a development tool; mainly useful for wiring deployment or notification side effects
research assistant
Useful for gathering data from connected SaaS tools rather than the open web
financial analysis
Can reach accounting and CRM data, but broad access to financial apps demands strict action scoping
legal compliance
SOC 2 helps, but routing privileged documents through Zapier and an LLM needs careful review
healthcare
Not suitable for PHI workflows; no HIPAA business associate posture for MCP agent traffic