Zapier MCP is a hosted MCP server. You add one URL to Claude, ChatGPT, Cursor or another MCP client, sign in to Zapier, and your assistant can run actions in the apps you have connected to Zapier: send a Slack message, add a spreadsheet row, create a HubSpot contact. Zapier counts it as "9,000+ apps and 40,000+ actions" on its docs home.

That is the short answer. The longer one matters if you are about to connect it to an agent, because three things catch people out: every successful tool call costs two Zapier tasks from the same pool your Zaps use, the tools you get are Zapier's generic action wrappers rather than each vendor's own, and anything that takes longer than a quick API request (a phone call is the obvious example) does not come back to your chat the way you would expect.

Everything below was checked against Zapier's own docs, help center and pricing page on September 30, 2026. Zapier has changed this product several times in the last year, and several ranking guides still show outdated SSE URLs and incorrect plan names and prices.

What Zapier MCP actually is

Rows of telephone switchboard operators in 1900, each patching calls between many lines by hand
Telephone switchboard operators, 1900. Photo: Salem State Archives / Flickr (CC BY 2.0).

It helps to get the direction right first, because it is easy to flip. In MCP terms, your AI app (Claude, ChatGPT, Cursor, VS Code) is the client. Zapier MCP is a server that the client connects to. Zapier then makes the real API calls to Gmail, Slack, Salesforce and the rest, using the app accounts you have connected in Zapier.

A few facts from the current docs:

  • One endpoint for everyone. "Every MCP client connects to the same endpoint: https://mcp.zapier.com/api/v1/connect" (how connections work). Zapier's current docs no longer use per-server secret URLs.
  • Streamable HTTP only. "An MCP client that can only use SSE (Server-Sent Events) cannot connect." If a guide gives you an /sse URL, it is out of date.
  • One server per client. Zapier creates a separate MCP server for Claude, for Cursor, for ChatGPT, and so on. You can have several, but only one per named client (Cursor and Grok Bot share one).

Agentic mode vs managed mode

New servers start in agentic mode. Instead of one tool per action, your client sees 16 fixed meta-tools, with names like discover_zapier_actions, enable_zapier_action, execute_zapier_read_action and execute_zapier_write_action (how tools work). The model searches for the action it needs, turns it on, and runs it. Zapier pre-enables actions for the apps you already connected.

Managed mode is the stricter shape: you pick the actions in advance at mcp.zapier.com, each becomes its own tool, and you can lock specific field values. If you want an assistant that can draft an email but never send one, or can only post to one Slack channel, managed mode is the one to use. Zapier's own guide puts it plainly: "Only enable the actions you actually want your AI to carry out."

Agentic mode is convenient, but it gives a model a very wide surface by default. For anything that writes to a system of record, the few minutes it takes to switch to managed mode are well spent.

How to connect Zapier MCP to your client

For the clients Zapier supports directly, you sign in with OAuth from inside the client and Zapier creates the server for you. For anything else, you create a server at mcp.zapier.com, choose Other, and generate a connection token.

ClientHow Zapier says to connect
Claude (web and Desktop)Use the Zapier connector from Claude's connector directory. Works on all Claude plans, including Free. Team and Enterprise owners must enable it first.
Claude Codeclaude mcp add --transport http "Zapier-MCP" https://mcp.zapier.com/api/v1/connect, restart, then finish OAuth in the browser. A plugin install is also offered.
ChatGPTTurn on Developer mode, add a plugin with the connect URL, leave auth as is, then sign in to Zapier. Needs a plan with developer mode, unless a Business, Enterprise or Edu admin has already added Zapier.
CursorInstall the Zapier plugin from the Cursor marketplace, then run the onboarding prompt. Zapier notes an RFC 9728 OAuth issue in some Cursor versions.
VS CodeAdd the server to your MCP user configuration (below). Requires GitHub Copilot in Agent mode.
WindsurfAdd the server to ~/.codeium/windsurf/mcp_config.json.
Anything else, or your own codeCreate a server, choose Other, generate a connection token.

The VS Code configuration from Zapier's VS Code page:

{
  "servers": {
    "Zapier": { "url": "https://mcp.zapier.com/api/v1/connect" }
  }
}

For a client that is not on the list, send the token as a header:

Authorization: Bearer YOUR_CONNECTION_TOKEN

Zapier also accepts it as a ?token= query parameter, but says to "prefer the header: a URL is more likely to end up in a log, a shell history, or a committed config file." The token is shown once, and rotating it kills the old one straight away.

The same pattern works for any remote MCP server, not just Zapier. If you are setting up a client for the first time, our guides to adding an MCP server to Claude and Claude Code MCP setup cover the client side in more detail.

What Zapier MCP costs

There is no separate MCP bill. Zapier MCP draws on your normal Zapier task allowance (usage docs):

  • Each successful tool call uses two tasks. Zapier calls this "a fixed rate."
  • Failed calls are free. So are listing the available tools, authentication and setup, and viewing history.
  • Test calls count. "All successful tool calls count toward your task usage, including tests."
  • The pool is shared. "Zap workflows, AI steps, code, MCP, and SDK all draw from the same task allocation" (pricing).

On the pricing page today, Free is $0 with 100 tasks a month, Professional starts at $19.99 a month and Team at $69 a month, both billed annually (monthly billing costs more). Zapier MCP is included on all of them. On Free, 100 tasks works out to about 50 successful MCP calls a month, and that is before any Zaps run.

What one agent session costs

Say you ask Claude: "Find last week's invoice email from Acme, add it to the Payments sheet, and tell #finance in Slack." A clean run is three successful actions (a Gmail search, a Sheets row, a Slack message), so six tasks. If the model searches Gmail three times before it finds the right thread, that is four more. Batches add up quickly too: Zapier's own example is that adding five spreadsheet rows is five calls, or ten tasks.

Zapier says discovery doesn't use tasks ("asking what tools are available"). Its usage page doesn't list the agentic meta-tools by name, though, so check the MCP Tasks counter in your dashboard after a first session rather than assuming.

What happens when you run out

If pay-per-task billing is on, calls keep working up to a cap and Zapier bills the extra tasks. If it is off, "tool calls stop until your billing cycle resets, you upgrade your plan, or you turn on pay-per-task billing."

Because the pool is shared, the real risk is not the assistant failing. It is the assistant quietly using up the tasks your production Zaps need in the last week of the month. Admins on accounts with Workspaces can set MCP task quotas per workspace. Everyone else should keep an eye on the "MCP Tasks" figure in the sidebar.

Zapier no longer publishes per-hour or per-month MCP call limits. The usage page says "the only usage limit is the task allowance." You will still find 2025 beta figures like "80 calls per hour" quoted in older guides. None of them appears in Zapier's current docs, help center or pricing pages.

Auth, security and what runs as you

Every Zapier MCP action runs with your connected app accounts. If you connected your work Gmail to Zapier years ago for a Zap, an agentic-mode server can act as that Gmail account. That is the point of the product, and also the thing to think about before handing it to an autonomous agent.

What Zapier publishes about security (security docs):

  • The connection token, or any URL containing it, works like a password: "Anyone with the token, or with a server URL that contains it, can run tools on this server and access your data" (connect other clients).
  • The History tab logs each tool call, including the values used and the output. MCP events also land in the account audit log. Deleting a server deletes its logs, per the usage page.
  • It operates under Zapier's SOC 2 Type II certification, with customer data stored in AWS US-East 1.
  • "Users cannot bring tools in from third-party sources. All tools are owned and controlled by Zapier." That closes off tool poisoning from outside servers. It also means you cannot plug another company's MCP server into your Zapier server, though you can still build a private Zapier integration and expose its actions.
  • Account-level app and action restrictions apply to MCP, but "cannot currently be set exclusively for Zapier MCP."

We sent a few unauthenticated requests to Zapier's endpoint. /api/v1/connect without a token returns HTTP 401 and a WWW-Authenticate header pointing to protected-resource metadata, which names https://mcp.zapier.com as the authorization server. That server advertises dynamic client registration, PKCE with S256 and refresh tokens. This is the standard MCP discovery flow, and it is why supported clients connect with a sign-in instead of a pasted key. (The 2026-07-28 spec now prefers Client ID Metadata Documents and keeps dynamic registration for backward compatibility.)

MCP Client by Zapier: the other direction

"How to use MCP Client by Zapier" gets more searches than you might expect, and it is a different product. MCP Client by Zapier is a Zapier app that lets a Zap call tools on someone else's remote MCP server (help article). Zapier is the client there, not the server.

To set it up, add a connection for "MCP Client" on Zapier's Apps page and fill in:

  1. Server URL, the remote server's MCP endpoint.
  2. Transport, either Streamable HTTP or SSE.
  3. OAuth (yes or no). If yes, you log in to the remote server; if no, you can supply a bearer token.

Then use it in a Zap. It offers a Run Tool action, a Run Read-Only Tool search, and two triggers: New Tool, and New Tool Result, which fires when a read-only tool returns a new result.

The limits are stated plainly: it is in beta, it "only supports tool calls" (no prompts or resources), and "connection to Zapier's MCP servers is not supported." Zapier also warns that "you should only connect to remote MCP servers you trust." The article doesn't say how many tasks each MCP Client step uses.

Where Zapier MCP stops: phone calls

Here is the gap we care about, because we build a phone-call MCP server. What happens if you ask an assistant with Zapier MCP to "call the dentist and move my appointment to Thursday"?

A Zapier action is a single, short request. Zapier's developer docs give create and search actions a 30-second limit. A phone call that sits through a phone menu and a hold queue, then talks to a person, takes minutes. So the phone apps on Zapier handle it in one of two ways: they play a message, or they start a call and return straight away.

These are the call-placing actions we found on Zapier's app pages:

App on ZapierActionWhat it actually doesCalls from
TwilioCall Phone"Call a number or numbers and say a message." One-way text-to-speech. "Send Digits" dials tones after connecting.A Twilio number you were given or bought
RingCentralGenerate Ringout CallConnects two phone legs for a live call between humansYour RingCentral line
AircallStart Outbound Call, Click to DialStarts a call for an Aircall user, a human, to take. Lookup actions include Retrieve Call Details and Get a Call Transcription.Your company's Aircall number
VapiCreate Call"Creates an outbound phone call using a Vapi voice assistant." You build the assistant in Vapi first. A Find Call search fetches the call later.A phone number in your Vapi account
Dial (getdial.ai, not DialMCP)Make CallStarts an AI call. A separate Call Status Changed trigger reports progress.Numbers provisioned in Dial

Two things stand out. First, none of these has the model in your chat holding the conversation. Either a recording plays, a human talks, or another company's voice agent that you configured separately takes the call.

Second, getting the outcome back takes a separate step. Twilio, RingCentral and Dial report call results only through Zap triggers, and a trigger starts a Zap. It does not post back into the Claude conversation that asked for the call. Vapi (Find Call) and Aircall (Retrieve Call Details, Get a Call Transcription) do offer lookup actions, so the assistant can come back later and fetch the call by ID, at two more tasks per lookup.

That is not a flaw in Zapier. It is what a general action layer is for: quick, stateless requests across thousands of apps. A phone call is a long, stateful job, and it fits better as its own tool.

Zapier MCP vs a dedicated phone-call MCP server

The comparison only makes sense for the phone-call job. For "update the CRM and ping Slack," Zapier MCP wins easily, and there is no reason to connect anything else.

Zapier MCP + a phone appA dedicated phone-call MCP server (DialMCP)
What the model seesA generic Zapier write action with instructions and fieldsTyped tools: place_call, get_call, end_call, list_calls
Who talks on the callA TTS recording, a human, or a separately built voice agentDialMCP's voice agent, working toward the objective your assistant passed in
Where the result goesA Zap trigger, or a separate lookup action where the app has one (Vapi, Aircall)Back to the same assistant: get_call returns a resolution, summary, transcript and recording link
Caller IDA Twilio, Aircall, RingCentral or vendor numberYour own mobile number, verified by SMS
Metering2 Zapier tasks per call, plus the phone vendor's chargesFree during launch, with hard usage limits
GuardrailsWhatever the phone app enforcesDisclosure, calling hours, rate limits and a permanent opt-out list, enforced on the server (Safety)
Breadth9,000+ appsPhone calls, US and Canada, and nothing else

The trade-off is breadth against fit. Zapier covers thousands of apps with one tool shape. A single-purpose server does one thing, with tools built for it. place_call returns a call ID immediately, so a long call never runs into a request timeout. The assistant then checks get_call until the call ends and reads the transcript and outcome in the same conversation.

Using both together

You don't have to choose. MCP clients connect to several servers at once, and here two connections, each good at its half, beat forcing one to do both. Connect Zapier MCP and DialMCP side by side in the same client:

  1. Ask the assistant to call the pharmacy and ask whether the prescription is ready. It uses DialMCP's place_call, then get_call for the result.
  2. In the same conversation, ask it to add the pickup time to your calendar and text your partner. It uses Zapier MCP's Google Calendar and SMS actions, at two tasks each.

Each server does the part it is built for, and the assistant ties them together. Both endpoints are remote, both use OAuth, and neither needs anything installed locally. If you want the background on why that works, remote MCP servers explained covers the transport, and MCP gateway covers what changes if your company puts a gateway in front of them.

Could you go the other way and point MCP Client by Zapier at DialMCP, so a Zap places calls? We haven't tested it, and we wouldn't recommend it. DialMCP is built for a person asking their own assistant to make a call. It allows one call at a time, three an hour and ten a day. It bans telemarketing, lead generation and robocalling. A trigger that fires a call on every new row is the pattern those limits exist to stop.

When Zapier MCP is the right choice

Use Zapier MCP when:

  • The job is a quick action in an app you already use: create, update, search, send.
  • You want one connection that covers many apps, and you're fine with Zapier's action shapes.
  • Your team already runs on Zapier, and its app connections and audit log are where governance happens.

Look elsewhere, or add a second server, when:

  • The vendor has its own MCP server with richer, typed tools. Many do now. Our review of the best MCP servers lists some good ones.
  • The job is long-running or stateful, like a phone call, and the result has to come back to the conversation.
  • You can't afford to share a task pool with production automations.

Further reading

Want the phone call next to your Zapier actions? Add https://mcp.dialmcp.com/mcp to the same client, verify your own mobile number, and your assistant can place a real call and read back the transcript. Free during launch.

Connect DialMCP to your client

FAQ

Is Zapier MCP free?

It is included on every Zapier plan, including Free, with no separate MCP charge. Each successful tool call uses two tasks, and the Free plan has 100 tasks a month shared with your Zaps, so about 50 calls.

Is Zapier MCP a client or a server?

Zapier MCP is a server that your AI client connects to. MCP Client by Zapier is a separate beta app that makes Zapier the client, so a Zap can call tools on another remote MCP server.

What URL does Zapier MCP use?

Every client connects to https://mcp.zapier.com/api/v1/connect over Streamable HTTP. Supported clients sign in with OAuth. Other clients use a connection token sent as a Bearer header. SSE-only clients cannot connect.

Does Zapier MCP work with Claude, ChatGPT and Cursor?

Yes. Claude uses the Zapier connector on all plans, ChatGPT needs Developer mode, Cursor uses the Zapier marketplace plugin, and Claude Code, VS Code and Windsurf take the connect URL directly.

Can Zapier MCP make a phone call?

Only through phone apps' Zapier actions. Twilio's Call Phone plays a one-way text-to-speech message, and RingCentral and Aircall connect a human. Voice-AI apps such as Vapi start a call run by their own agent. The result comes back through a Zap trigger or, for Vapi and Aircall, a separate lookup action the assistant must call later. A dedicated phone-call MCP server like DialMCP returns the transcript and outcome to the assistant.

Does Zapier MCP have rate limits?

Zapier publishes no per-hour or per-month MCP call limits today. Its usage docs say the only limit is your plan's task allowance. Older figures such as 80 calls an hour came from the 2025 beta and are not in Zapier's current docs or help center.