Zapier MCP: Letting an AI Assistant Run App Actions
Zapier MCP gives an AI assistant one connection to the apps in your Zapier account. How it works, how to connect Claude, ChatGPT, Cursor and VS Code, how to choose which actions it may run, where approvals go, what to watch for, and when n8n fits better.
7 min read
Zapier MCP is a hosted MCP server that lets an AI assistant run actions in the apps connected to your Zapier account: send a Slack message, add a row to a sheet, create a calendar event, update a CRM record. Your assistant connects to one address, signs in to Zapier, and Zapier holds the app credentials, so the assistant never sees an API key. You decide how much it can reach: in the default agentic mode the assistant finds and enables actions as it needs them, and in managed mode it gets only the fixed list you picked. Approvals sit in the assistant, not in Zapier, so the settings that matter most are split between the two.
How Zapier MCP works
Zapier’s overview of Zapier MCP (opens in a new tab) describes three parts. Your MCP server holds the tools your assistant may call, and each client gets its own server, so you might have one for Claude and another for Cursor. Your MCP client is the assistant. A tool is one action in one connected app, such as Send Channel Message in Slack, and it runs through the same app connections your Zaps use. Zapier says it covers more than 9,000 apps and 40,000 actions.
- One endpoint for every client:
https://mcp.zapier.com/api/v1/connect. - Streamable HTTP only. A client that can only speak Server-Sent Events cannot connect.
- One server per named client. Cursor and Grok Bot are the exception: they share one connection.
- Each successful tool call counts against your Zapier plan’s task allowance; failed calls do not.
If MCP itself is new to you, start with what MCP is; this post assumes the basics.
Two ways to sign in
Zapier’s page on how connections work (opens in a new tab) gives two paths, and your client decides which applies.
- OAuth, for listed clients such as Claude, ChatGPT, Cursor and VS Code. The client sends you through a Zapier sign-in, Zapier creates the server and names it after the client, and the client stores and refreshes the token. You revoke it from the client or from mcp.zapier.com.
- A connection token, for unlisted clients and your own code. You create the server at mcp.zapier.com and generate a token. It is long-lived, tied to that one server, and lets whoever holds it run the server’s tools and read what they return. It is shown once, and regenerating it cuts off every client still using the old one.
Zapier prefers the token in an Authorization: Bearer header over the ?token= query form, because a URL ends up in logs, shell history and committed config files. Give each person their own server and token rather than sharing one.
Setting it up in four clients
Claude
Per Zapier’s Claude setup page, you ask Claude in a chat to connect Zapier; it shows the Zapier connector card, you click Connect, review the access on Zapier’s authorization screen and click Allow. One connection covers Claude in the browser, Claude Desktop and Claude Cowork. On Team and Enterprise plans an Owner must first enable Zapier in Organization settings, and each member still signs in individually. For Claude Code, Zapier’s page gives one command:
claude mcp add --transport http "Zapier-MCP" https://mcp.zapier.com/api/v1/connect
ChatGPT
If your workspace admin has already added Zapier, pick it with @ or from the + menu and sign in when asked. If nobody has, Zapier’s ChatGPT setup page (opens in a new tab) has you turn on Developer mode under Security and login settings, create a new plugin named Zapier MCP, paste the endpoint above as the MCP server URL, leave authentication as it is, and click Connect. That plugin stays private to your account until an Admin or Owner enables it for others.
Cursor
Either sign in to a plugin your team already distributed, from a new Agent chat, or install the Zapier plugin from the Cursor marketplace and paste Zapier’s onboarding prompt into an Agent chat. Zapier warns that some older Cursor versions have an OAuth issue that stops sign-in from finishing, so update Cursor first.
VS Code
VS Code needs MCP support through GitHub Copilot in Agent mode. Use Zapier’s one-click install, or run MCP: Open User Configuration from the command palette, add the server, and authenticate when prompted.
{
"servers": {
"Zapier": {
"url": "https://mcp.zapier.com/api/v1/connect"
}
}
}Choosing which actions to expose
This is the decision that matters most. According to Zapier’s page on how tools work (opens in a new tab), every new server starts in agentic mode. Zapier auto-provisions actions from the apps already connected to your account, and the assistant gets a set of meta-tools to search for more actions, enable them, and run them. Reads and writes run through separate meta-tools, execute_zapier_read_action and execute_zapier_write_action, which gives a client a clean line to hang an approval on.
Managed mode is the alternative: you choose the actions at mcp.zapier.com, each one becomes its own tool, you can lock field values, and the assistant cannot enable anything new. Switch under the server’s Settings tab, then refresh the client’s tool list, since most clients cache it. A rough guide:
- Agentic mode suits one person, their own apps, and requests that change from day to day.
- Managed mode suits anything shared, anything that writes to customer-facing apps, and any assistant running without someone watching.
- Either way, account-level app and action restrictions still apply, and so do each app’s own permissions: someone who cannot change a record in the app cannot change it through Zapier MCP.
Approvals: whose job they are
Zapier MCP does not pause a call for a human yes; your client does. Zapier’s quickstart notes that the client asks you to approve the first Zapier tool run, and suggests approving for the session to save a prompt on every action. That is convenient, and it is also the moment you decide how much to trust the assistant for the rest of the conversation. Approve once per call for anything that sends, deletes or spends.
Organizations get a firmer control. Zapier’s guide to rolling out to a Claude organization (opens in a new tab) has an Owner set each tool to Always allow, Needs approval or Blocked. Those settings apply across the organization, including Claude Code, where Needs approval overrides Claude Code’s own permission modes, and Blocked hides the tool entirely. Where approvals belong in general is covered in the AI agent approval workflow.
Security, including prompt injection
Zapier’s security and governance page (opens in a new tab) covers the platform side: SOC 2 Type II, a History tab at mcp.zapier.com that logs tool calls per user, MCP events in the account audit log, and tools that are all owned by Zapier, which it says prevents tool poisoning from third-party tools. It also notes that MCP is enabled by default for every account, and that customer data is stored in the United States.
The risk Zapier cannot remove is the assistant itself. A model that reads an email, a web page or a spreadsheet row can be steered by instructions hidden in that text, and with Zapier connected it has real actions to misuse. Indirect prompt injection explains how that happens. The practical defenses are the ones above, plus a few habits:
- Do not give one server both a way to read untrusted content and a way to send it somewhere, unless every send needs approval.
- Keep a separate server, in managed mode, for anything unattended.
- Treat a connection token as a password: an environment variable or secret manager, never a committed file.
- Read the History tab now and then, not only after something goes wrong.
The wider checklist is in MCP security best practices.
Zapier MCP vs n8n
They solve different problems. Zapier MCP brings actions to an assistant you are already talking to: the conversation is the workflow. n8n puts an agent inside a workflow you build on a canvas, with its own trigger, fixed steps and a human review step on chosen tools; n8n AI agents with MCP walks through that setup.
- Choose Zapier MCP when the request starts with a person in Claude, ChatGPT or an editor, when the apps are already connected in Zapier, and when nobody wants to run a server.
- Choose n8n when the job runs on a schedule or a webhook without a person present, when you want approvals built into the workflow rather than the client, or when you need to self-host. Zapier says dedicated or on-premises deployments are not available for Zapier MCP.
- Both can sit side by side: n8n for the scheduled jobs, Zapier MCP for the ad hoc ones.
Where fenbs fits
fenbs is not a Zapier app, and it does not need to be one for an assistant to use it: connect the assistant to fenbs’s own MCP server at https://fenbs.ai/api/mcp alongside Zapier. The two do different jobs. Zapier runs the action in the outside app; fenbs is where the work behind it is written down, as a task with a note, a plan and test notes, with every change recorded in the board’s history with the assistant named alongside the person it acts for. When a person decides which Zapier actions an assistant may run unattended, record that as a rule on the Decisions and rules page, and every connected assistant reads it before it starts. A token issued by hand under Settings carries a name, scopes (read, write, comment) and an optional expiry, and revoking it there ends it.
Related
Connect an assistant to fenbs with the MCP setup guide. What a token can do: assistant tokens and scopes. Who may connect what, and how to keep a record of it: MCP governance.