AgentShield
How it works Pricing Blog FAQ Contact Sign in

Zapier MCP Security for Zapier Agents and AI by Zapier Tool Approvals

Zapier MCP lets Claude, ChatGPT, Cursor and your own agents run actions across thousands of apps, and Zapier turns it on by default for every account. Zapier Agents are being migrated into AI by Zapier steps, where the tool approval switch starts off. Since ZapConnect on September 23, 2026, agents can also build, deploy and repair Zaps. Zapier governs which apps an agent can reach. Whether a given write should happen is still yours to decide.

OWASP LLM Top 10 Immutable audit trail Never trains on your data

Direct answer

Zapier MCP is secure at the connection level: SOC 2 Type II, OAuth or token auth, admin controls over which apps and actions agents reach, and a history log of tool calls. It does not judge whether a specific action is safe. Zapier says MCP is "an integration layer, not a security scanner." Approval on AI by Zapier tools is off by default. Turn it on for writes, and add a policy gateway when outside agents call Zapier MCP.

Try it live

Watch AgentShield block an attack in real time.

Pick a scenario and drive the inspection lane yourself. No signup needed.

Threat Console
Interactive demo · 0 blocked in this session

Run a request

Runs the live engine on your text. Nothing is stored, no account needed.

Inspection lane

INSPECTING
⌖ untrusted input

Policy trace

High-risk action held for approval

Audit trail

The risk

A US distribution company lets its sales ops team connect Claude to Zapier MCP in March. Nobody asked IT, because Zapier MCP was already enabled for every user on the account. The configured actions include HubSpot update deal, QuickBooks Online create invoice and Gmail send email, all authorized with one manager's connections. In September a rep asks Claude to tidy up stale deals and draft follow ups. A forwarded supplier email in the thread contains an instruction to mark three deals closed won and invoice them. Claude does it in four tool calls. Zapier logs all four in the History tab. Nothing in the path asked whether invoicing a customer from a chat window was a good idea.

How AgentShield handles it

Keep Zapier for what it is good at: thousands of app connections, managed credentials, admin app restrictions and AI Guardrails inside Zaps. Put AgentShield between the AI clients and Zapier MCP. Claude, ChatGPT, Cursor and in-house agents connect to an AgentShield MCP gateway endpoint, the Zapier MCP credential stays with the gateway, and a per-tool, per-argument policy decides which Zapier actions run, which wait for a named approver and which are refused, with every decision logged outside Zapier.

Operations manager reviewing an automation approval request on a laptop

The controls

The controls that secure which Zapier actions an AI agent may run and who approves first.

What Zapier governs for MCP, Zapier Agents and AI by Zapier, and what it leaves to you

Zapier MCP is a hosted Model Context Protocol server that exposes Zapier actions, such as creating a CRM record, sending an email or issuing an invoice, as tools any MCP client can call. Claude, ChatGPT, Cursor and custom agents connect to it with OAuth or a connection token, and Zapier runs the action with the app connections stored in your account. Inside Zapier, the same actions are available to Zapier Agents and to the AI by Zapier step in the Zap editor.

Zapier has invested in governance. In April 2026 it extended admin app access controls, admin-managed app connections and log streaming to Datadog, Splunk and other SIEM tools across the editor, agents and MCP. Its MCP security documentation lists SOC 2 Type II, OAuth and token authentication, workspace-level enable and disable, per-workspace task quotas and a History tab. The table below is the map we use with buyers.

ControlWhat Zapier providesDefault or catchWhat is left to you
Who can use Zapier MCPWorkspace-level enable and disable, restriction by workspace membership"Zapier MCP is enabled by default for all accounts, including Enterprise."Turning it off where nobody asked for it
Which apps and actions an agent reachesAdmin app access controls by workspace, team or user; actions chosen per MCP serverScope is per action, not per valueLimits on amounts, recipients, records and volume
CredentialsManaged connections, keys never pasted into chatEvery action runs as whoever owns the connectionWhich person's access the agent is borrowing
Approval before a write"Require approval before running" on AI by Zapier tools; Human in the Loop step in Zaps"This toggle is off by default"; nothing equivalent on calls from outside MCP clientsGating writes that come from Claude, ChatGPT or Cursor
Prompt injectionAI Guardrails by Zapier, Detect Prompt Attack actionReturns a result you must branch on; it does not block on its ownStopping the action when a check fails
Record of activityHistory tab of tool calls, SIEM streaming, configurable retention on EnterpriseA log describes what ran; it does not stop anythingA decision record with the approver and the rule that applied

Read the third column and the pattern is clear. Zapier decides which doors exist and who holds the keys. It does not decide whether this agent should walk through this door with these arguments right now. Zapier says as much about its own product: "Zapier MCP itself is an integration layer, not a security scanner."

Zapier Agents to AI by Zapier, what the migration changes for approvals

Zapier is moving its standalone agents product into the Zap editor. Its help center puts it plainly: "Zapier is migrating Agents (agents.zapier.com) to AI by Zapier, a more powerful AI experience built directly into the Zap editor." No shutdown date has been set, and Zapier says it will email affected users with notice before anything is turned off. The migration is a button per agent: Zapier converts each one into a Zap with a native trigger and "a single AI by Zapier step that contains your agent's prompt, instructions, and all connected tools", which you test and publish yourself.

The security detail most teams miss is how approval worked before and how it works after.

QuestionZapier Agents (before)AI by Zapier step (after)
How approval is requestedA sentence in the agent's instructions, such as "ask for my confirmation through [messaging app] before continuing"A per-tool switch, "Require approval before running"
Who enforces itThe model, by following its instructionsThe platform, "regardless of how specific your prompt is"
DefaultNo approval unless someone wrote the sentenceOff, the tool runs without interruption
How the approver hears about itWhatever messaging action the agent was givenAn email with a link to review the step
TriggersChat, schedules, app eventsNative Zap triggers; chat-started agents need a webhook trigger

That first row matters. An approval that lives in the prompt is a request to the model, and a prompt injection is precisely an attempt to make the model ignore its instructions. The AI by Zapier switch is a real platform gate, which is an improvement, but the migration copies prompts and tools, not judgment. If nobody turns the switch on for each write tool after migrating, the converted Zap runs every action without a pause.

Two other migration notes worth recording: knowledge sources such as HubSpot, Asana, Zendesk, Zoom and Jira are not yet supported in AI by Zapier, and Zapier warns that "Full-Zap tests currently consume tasks the same way production runs do," so testing write tools against live apps has a cost as well as a risk.

Next Gen Zaps and Agentic Management, agents that edit your automations

At ZapConnect on September 23, 2026, Zapier announced Next Gen Zaps, available on paid plans in early access. You can describe a workflow inside Claude, ChatGPT or Cursor and deploy it to Zapier through MCP, and a monitoring agent "watches your runs, diagnoses failures, and can apply or suggest a fix." Zapier calls the second part Agentic Management.

Zapier's documentation is careful about which fixes run on their own. With "Automatically apply fixes" on, some fixes apply without asking, while "The agent asks you first when: The fix changes what the workflow can do, such as adding a tool call, an action, or a branch. The agent has low confidence in the fix. The fix changes an asset or an authentication, which Zapier treats as high risk." It also states that "Agentic Management and all three agent capabilities are on by default."

That is a sensible design, and we would not tell a buyer to switch it off by reflex. Two questions are still worth asking before you rely on it:

  1. Who answers the "asks you first" prompt? On a Team or Enterprise account with dozens of builders, define which person approves changes to Zaps that write to billing, payroll or customer records, and check that the approval goes to them rather than to whoever built the Zap.
  2. What can an outside agent deploy? If Claude or Cursor can create and publish Zaps through MCP, then a coding assistant session can create a new automation with your production connections. Restrict the deploy and publish actions the same way you restrict invoice and email actions, and pair this with Zapier's Enterprise publishing restrictions where you have them.

When Zapier controls are enough, and when to add a policy gateway

Most Zapier customers do not need us. The question is whether an AI model, rather than a fixed Zap, decides which write happens and with what values.

SituationWhat we would do
Classic Zaps only, no AI steps, no MCP clientsBuy nothing. Turn Zapier MCP off at the workspace level if nobody uses it.
AI by Zapier steps that only read, summarize or draftBuy nothing. Keep draft-only actions and add AI Guardrails on inbound text.
AI by Zapier steps with write tools, migrated from Zapier AgentsTurn on "Require approval before running" for every write tool, then decide if email approval is enough
Claude, ChatGPT or Cursor connected to Zapier MCP with CRM, billing or email send actionsPut a policy gateway in front of Zapier MCP, because there is no per-call approval on that path
In-house agents using Zapier MCP as their action layer for customers or financeGateway with per-argument limits, named approvers and an independent decision log
Agents allowed to create or publish Zaps through MCPGate the deploy actions and require a named approver for anything touching production connections

Two of those six rows say buy nothing, and a third is a setting you already pay for. The case for a runtime layer starts on the MCP path, where a model outside Zapier chooses the action and Zapier executes it with stored credentials.

For the per-value rules in rows four to six, see AI agent permissions management. For the approver experience, see approval gates for AI agents. Teams comparing Zapier with self-hosted workflow tools should also read our n8n security page, since the trade-offs differ when you run the platform yourself.

How to put AgentShield in front of Zapier MCP

Your team keeps Zapier. The change is which endpoint the AI clients talk to and where the Zapier MCP credential lives.

  1. Find who uses Zapier MCP today. Because it is on by default, start with the History tab and the MCP servers list. Owners and super admins can see every server. Note each client (Claude, ChatGPT, Cursor, custom) and each configured action.
  2. Turn it off where it is not needed. Disable Zapier MCP for workspaces that have no use for it and restrict it by membership elsewhere. This costs nothing and removes the largest share of exposure.
  3. Route the rest through the gateway. Point each MCP client at an AgentShield MCP gateway endpoint instead of the Zapier MCP URL. The Zapier token lives with the gateway, so a leaked client config unlocks a policy-checked endpoint, not your app connections.
  4. Write policy per action and argument. Allow lookups broadly, let drafts run, hold sends, invoices, refunds, deal stage changes and bulk updates for a named approver, and deny actions an agent should never call, including publishing Zaps.
  5. Inspect what the model read. Email threads, tickets and form submissions are untrusted input. AgentShield checks content for injected instructions before a tool call acts on it, see prompt injection protection.
  6. Keep the decision record outside Zapier. Every allowed, held and denied call goes to the AI agent audit trail with the client, the user, the Zapier action, the arguments, the rule and the approver. Zapier's History tab and SIEM stream keep working alongside it.

Inside Zapier, keep using the approval switch and AI Guardrails for agents that run there. Teams that connect the same clients to other MCP servers should read MCP server security and Claude agent security, because one gateway policy covers them all.

FAQ

Common questions about zapier mcp security.

Is Zapier MCP secure?

At the connection level, yes: SOC 2 Type II, OAuth or token authentication, managed credentials, admin controls over apps and actions, and a History tab of tool calls. It does not judge whether a specific call is safe. Zapier describes MCP as an integration layer, not a security scanner, so per-call approval and argument limits are yours to add.

Is Zapier MCP enabled by default?

Yes. Zapier documents that Zapier MCP is enabled by default for all accounts, including Enterprise, and that all users within the account can access it. Admins can disable it per workspace, restrict it to specific workspace members and set MCP task quotas. Account owners and super admins can see every MCP server.

Can Zapier agents require approval before taking action?

Yes. In an AI by Zapier step you can switch on "Require approval before running" for each tool, and the step pauses and emails a review link. The switch is off by default. Legacy Zapier Agents asked for approval through a sentence in their instructions, which the model enforces rather than the platform.

What is the difference between Zapier Agents and AI by Zapier?

Zapier Agents is the standalone product at agents.zapier.com. AI by Zapier is an AI step inside the Zap editor with tools and knowledge attached. Zapier is migrating Agents into AI by Zapier: each agent becomes a Zap with a native trigger and one AI step. No shutdown date for Agents has been set.

Does Zapier detect prompt injection?

AI Guardrails by Zapier includes a Detect Prompt Attack action that checks text for injection and jailbreak attempts and returns a status. It does not block on its own: you add a filter, path or human review step to act on the result. Zapier notes that no AI detection system is 100% accurate.

Can admins restrict which apps Zapier agents can use?

Yes. Zapier app access controls let admins decide which apps teams can use by workspace, team or individual user, enforced across the editor, agents and MCP connections. Enterprise accounts can also make apps admin-managed so connections are created and shared centrally. These controls scope apps and actions, not individual values.

What is Agentic Management in Next Gen Zaps?

It is a monitoring agent announced September 23, 2026 that watches Zap runs, diagnoses failures and can apply or suggest fixes. It is on by default where available. Fixes that add a tool call, action or branch, low-confidence fixes and changes to assets or authentication always ask a person first.

Does AgentShield work with Zapier MCP?

Yes. Claude, ChatGPT, Cursor or your own agents connect to an AgentShield MCP gateway endpoint instead of Zapier MCP directly. The gateway holds the Zapier credential, checks every call against per-action, per-argument policy, holds risky writes for a named approver, inspects inputs for injected instructions and logs each decision.

Secure your zapier mcp security.