The short answer: most small teams should start with Zapier MCP
If the AI's job is a handful of well-defined actions in mainstream apps you already connect to Zapier, like adding a spreadsheet row, drafting an email, or creating a CRM contact, Zapier MCP is enough. It connects with a sign-in and bills two tasks per successful call on your existing plan. A custom MCP server pays when the AI must reach a system Zapier can't, follow rules you set tool by tool, answer questions across lots of your own records, or run at a volume where per-task billing becomes the big number. You can also run both.
Below: how Zapier MCP works and bills as of October 2026, the two compared, when each wins, and what to lock down before any AI writes to your systems. New to MCP? Start with what an MCP server is.
What happens when your AI calls Zapier
Zapier MCP lets an AI client run actions in apps you've connected to Zapier, from a catalog of more than 9,000 apps and 40,000 actions, per Zapier's help center. It works with Claude, ChatGPT, Cursor, VS Code, and any client that speaks MCP over Streamable HTTP, and setup is usually signing in to Zapier from inside the client.
Each tool is one action in one app, like posting a Slack message. When the AI calls it, Zapier runs the action in its cloud through your existing app connections and returns the result. Zapier holds the credentials; the AI client never sees an API key.
The default mode is the looser one. In agentic mode, the AI finds and switches on new actions by itself as requests come up. In managed mode, you pick the tools in advance, the AI can't add any, and you can lock field values, so a messaging tool only posts to the channel you chose. For anything touching customers or money, I'd use managed mode.
Two tasks a call, from the same allowance as your Zaps
There's no separate MCP bill. Per Zapier's usage docs, each successful tool call uses two tasks from the allowance your Zaps draw from. Failed calls are free; test calls count. Repeats add up: Zapier's own example, “search and update 10 records,” is 11 calls and 22 tasks.
Every plan includes it, Free too, and the Free plan's 100 tasks a month cover 50 calls if nothing else uses them. At the limit, calls stop until the billing cycle resets, unless pay-per-task billing is on, which keeps them running, up to a cap, at a higher per-task rate.
What each one reaches, costs, and logs
| Zapier MCP | Custom MCP server | |
|---|---|---|
| What it reaches | Apps with a Zapier integration you’ve connected, and in-house systems only if Zapier’s cloud can reach them | Anything the server can reach, including systems on your own network |
| Setup | A sign-in from your AI client | Days to weeks for a focused server, once the rules are set |
| Cost structure | Your Zapier plan, at two tasks per successful call | A build up front, then hosting and upkeep, with no per-call meter |
| Permission controls | Apps and actions on or off, plus locked field values in managed mode | Per tool, per field, per user, as you write them |
| Approval before a write | Not in Zapier’s MCP docs; it’s up to your AI client | Built in: a gated tool waits for a person’s yes |
| Where data flows and is logged | Through Zapier’s cloud (AWS US-East 1), logged in the History tab | Your infrastructure and region, in a log you own |
| Reading vs. acting | One standard app action per call: find, create, update, send | Tools shaped to your questions, like one read across two systems |
| Who maintains it | Zapier owns the tools; you manage connections and the plan | You, or whoever you hire, including when an API changes |
Zapier details checked against its help center, docs, and pricing page on October 4, 2026; confirm there before you decide. Either way, whatever a tool returns goes to your AI model.
Signs Zapier MCP is all you need
For most small teams, the work they'd hand an AI lives in mainstream apps: email, calendar, chat, spreadsheets, the CRM. If this list fits, Zapier is the better spend, and a build would buy control you won't use.
- Your apps have Zapier integrations, and you’ve connected them.
- The AI’s whole job fits in a few actions: draft the reply, add the row, create the contact.
- Each request is an action or two, not a report built from hundreds of records.
- Your data can pass through a US-hosted cloud service without a compliance problem.
If the job lives in one app, also check whether the app's maker runs its own MCP server. HubSpot's has been generally available to every HubSpot account since April 2026, with read and write access to the CRM, and Intuit has its own QuickBooks options, weighed against a custom build here.
Six cases where a custom MCP server is worth building
A custom server sits on the APIs and databases you already run (here's how that layer relates to an API). It earns its cost in these situations.
- 01
The system lives on your own network
An older ERP on a back-office server, a production database. Zapier can reach in-house systems through a private integration or, on some accounts, a code action, but only from its cloud; for a server behind a firewall, its instructions are to allowlist Zapier’s IP addresses. A custom server can run beside the system and expose only the tools you approve.
- 02
Your rules are per tool, not per app
“Read orders, never touch prices.” “Add notes, never change balances.” Zapier’s app and action restrictions apply across your whole Zapier account, not to MCP alone. A custom server can draw the line at one field or one user.
- 03
The questions are read-heavy and cross systems
“Which open orders are waiting on parts already in the warehouse?” needs the order system and inventory at once. Through app actions, that’s a chain of lookups at two tasks apiece; a custom read tool can do the join on your side and return just the answer.
- 04
You need approvals and an audit trail you control
Who asked, which tool ran, with what arguments, and what was refused, kept as long as your policies say. Zapier logs calls in its History tab, but deleting a server deletes its logs, and configurable retention is an Enterprise feature.
- 05
Compliance or data-location rules
Zapier stores customer data in AWS US-East 1, offers other regions only by separate agreement, and has no on-premises option. Its SOC 2 Type II certification may satisfy your review; if your rules keep data on your own infrastructure, build.
- 06
Volume
An agent making 300 calls a day uses about 18,000 tasks a month at two tasks each, and pay-per-task overage costs more per task than your plan’s included tasks. Price that against a build. At low volume, the subscription wins.
Skip the build if you can't name the system Zapier can't reach or the rule it can't enforce. For scale, the servers I build are usually part of a fixed-scope sprint from $45,000 that includes the agents that use them; here's what drives the price of a build.
You don't have to pick one
An AI client can connect to several MCP servers at once. A sensible split: Zapier for everyday actions like messages, calendar invites, and email drafts, and a custom server for the system of record, where money, inventory, and customer accounts live. Each keeps its own permissions and its own log.
A two-week trial that tells you which one you need
Turn on Zapier MCP in managed mode with three actions you'd trust a new hire to take. For two weeks, write down every time the AI couldn't reach something, every time you wished it had asked first, and every answer that needed two systems. If the list stays short, you're done. If it fills up, that list is the brief for a custom MCP server build.
Settings to decide before an AI can write to anything
Reading is low risk. Writing is where it goes wrong, and prompt injection is why: OWASP's 2025 Top 10 for LLM applications ranks it first, including the indirect kind: instructions planted in a document, a site, or a message the model reads, which then steer what it does. An AI that reads your inbox reads whatever a stranger puts in an email. So limit what the tools can do, not only what the model is told.
- 01Turn on only the actions the job needs, and pin what shouldn't vary, like the channel or the sender. In Zapier, that's managed mode with locked fields; in a custom server, a tool you never write can't be misused. OWASP's guidance on excessive agency says the same.
- 02Keep reads, writes, and destructive actions apart. Deleting, refunding, and sending to a customer each get a narrow tool of their own, never one general “update anything” tool.
- 03Put a person in front of outbound writes and anything destructive. The MCP specification says a human in the loop should always be able to deny a tool call. Zapier's MCP docs don't describe an approval step, so check what your AI client asks before a tool runs.
- 04Give each connection the least access that works. Zapier says permissions inside your apps still apply through MCP, and the spec's security guidance says to start a custom server's tokens with minimal scopes.
- 05Log every call, refusals included, somewhere you control. The spec tells clients to log tool usage for audit, and you'll want that log the first time a customer asks why they got an email.
- 06Guard connection tokens like passwords. Zapier's are long-lived and let whoever holds one run the server's tools and read what they return.
If you build, you don't have to invent the gate. I maintain mcp-gatehouse, an open-source Python library (MIT licensed, on PyPI) that does this inside an MCP server. Every tool is declared READ, WRITE, or DESTRUCTIVE. The tiers you choose wait for a sign-off from an approver you connect, like a Slack message or a ticket, and a gated tool with no approver configured is refused. Every call, allowed, denied, or failed, goes to an append-only JSONL log with secrets such as API keys masked. By default only destructive tools wait for approval; one line adds writes. It isn't authentication or a sandbox, and its README says so.