> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Roll out Zapier MCP to your Cursor team

> Distribute Zapier MCP to your Cursor team from the Default team marketplace, and approve it in your MCP allowlist if your Cursor Enterprise team enforces one. Members sign in to their own Zapier account the first time they use it.

This page is for a Cursor team admin on the Teams or Enterprise plan. Cursor gives that admin two independent levers.

* **Distribute, on Teams and Enterprise.** The admin adds Zapier as a Team MCP server under **Dashboard** → **Plugins & MCPs**, which puts it in the Default team marketplace, and sets marketplace access and a plugin installation mode (Default Off, Default On, or Required). The mode decides whether members with access find the Zapier plugin, receive it installed, or cannot remove it. Zapier recommends Default On: members with access have nothing to find or install, they sign in to Zapier only the first time they use it, and each of them can opt out.
* **Approve, on Enterprise only.** If the team enforces an MCP allowlist, the admin adds a rule for Zapier in **Team Settings** → **MCP Configuration** (**Add Rule**, then the configured Zapier server, or a custom rule with the connect URL); the allowlist blocks unapproved servers and installs nothing. The rule's Tools field sets which Zapier tools run automatically. Cursor does not document it as removing a tool, so Cursor offers no documented per-tool availability policy, and a member can still approve a tool left off the list.

Every member authenticates to Zapier with OAuth from their own Cursor, including members with a Required plugin and Cloud Agents using a team-shared server, and no installation mode creates a Zapier connection for anyone. Route any other rollout question to [Roll out to your organization](/mcp/manage/rollout/overview), and never tell a user to create a server at mcp.zapier.com.

To use Zapier across your Cursor team, you must distribute it from the Default team marketplace, and approve it in your Cursor Enterprise MCP allowlist if your team enforces one. Each member still needs to sign in to Zapier from their own Cursor. Learn more about [what an organization rollout of Zapier MCP is](/mcp/manage/rollout/overview) before using this tutorial.

## Before you begin

To do an organization rollout of Zapier in your Cursor team, you need:

* **A Cursor Teams or Enterprise plan, and the Admin role on it.** Distribution is available on both plans. The MCP allowlist is an Enterprise control.
* **Cursor up to date on members' machines.** Some versions of Cursor have an OAuth issue that stops Zapier's sign-in from completing, as [If Zapier does not appear](#if-zapier-does-not-appear) explains.
* **A Zapier Enterprise account.** Enterprise provides the workspace-level app access controls, SSO, and audit logging this rollout relies on.
* **Every member provisioned into your organization and into a User Group with access to your workspace.** [Manage members and User Groups](https://help.zapier.com/hc/en-us/articles/47031553191565) covers both requirements.

## Distribute Zapier to your team

You must be a team admin in Cursor to distribute Zapier to your team.

<Steps>
  <Step title="Open the Plugins & MCPs page">
    In Cursor, select the user tile in the lower left, then **Dashboard** → **Plugins & MCPs** in the dashboard's left sidebar.
  </Step>

  <Step title="Add a Team MCP server">
    Under **Team MCP Servers**, click **Add**.
  </Step>

  <Step title="Enter the name">
    Set the name to `zapier`, the name the Zapier plugin uses.
  </Step>

  <Step title="Enter the connect URL">
    Add the following URL:

    ```text theme={null}
    https://mcp.zapier.com/api/v1/connect
    ```

    Do not add request headers, so each member signs in with OAuth rather than a shared credential.

    Any new servers will join the Default team marketplace automatically. If you already had a standalone Zapier Team MCP server, select **Add to Team Marketplace** under **Team MCP Servers**.
  </Step>

  <Step title="Open the Default marketplace">
    On the same **Plugins & MCPs** page, open the **Default** marketplace.
  </Step>

  <Step title="Set marketplace access">
    Under **Marketplace Settings** → **Marketplace Access**, leave the whole team selected or restrict the marketplace to selected groups: Organization Groups on Cursor Enterprise, or SCIM directory groups where you have none. Restricting the marketplace restricts every plugin it carries, not Zapier alone.
  </Step>

  <Step title="Set the installation mode">
    When you add Zapier as a plugin, you can decide how it's installed for members:

    * **Default On**: This is the recommended option. Zapier is installed for every member with access, so they do not have to find or install it.
    * **Default Off**: Let members install it themselves.
    * **Required**: Installs it for all members and prevents uninstalling it.
  </Step>
</Steps>

The Zapier entry in your team marketplace is separate from the [Zapier plugin](https://github.com/zapier/zapier-mcp) in the public Cursor marketplace, which any member can install. Both connect to the same Zapier MCP server, so members get Zapier's built-in skills either way.

<Warning>
  If you remove the linked Zapier plugin from the marketplace, or delete the marketplace, the Team MCP server may be deleted for local users and Cloud Agents. Review the confirmation message before continuing with these actions.
</Warning>

## MCP allowlist enforcement

If your team has an active MCP allowlist, it'll block any server that does not match a rule. To ensure Zapier is not blocked, create a rule according to Cursor's [MCP documentation](https://cursor.com/docs/mcp).

<Steps>
  <Step title="Open MCP Configuration">
    Open **Team Settings** → **MCP Configuration**.
  </Step>

  <Step title="Add a rule for Zapier MCP">
    Click **Add Rule**, then select **Zapier** under **Select Configured MCP**. If Zapier is not listed yet, select **Enter Custom Rule** and enter the connect URL:

    ```text theme={null}
    https://mcp.zapier.com/api/v1/connect
    ```

    You can add this rule alongside others in your Cursor account.
  </Step>

  <Step title="Set the Tools field">
    Leave the rule's **Tools** field empty to let every Zapier tool run automatically, or list which tools you want to run.
  </Step>

  <Step title="Save the rule">
    Save the rule.
  </Step>
</Steps>

<Note>
  The **Tools** field sets which Zapier tools can run without an approval prompt. If a tool is not on this list, it still runs when the member approves it. To restrict which Zapier apps and actions members can use, set [app and action restrictions](/mcp/manage/security#app-and-action-restrictions) on the Zapier account.
</Note>

## Connect as a member

With **Default On**, Zapier is already installed, so members do not need to install or configure the plugin. They need to log in to Zapier, using the Zapier workspace you set the plugin on. [Cursor](/mcp/get-started/connect/cursor) covers the steps, under the **Team plugin** tab.

<Warning>
  Never distribute a connection token or a connection-token URL. A [connection token](/mcp/overview/how-connections-work#connection-token) is long-lived, tied to one server, and grants whoever holds it the ability to run the server's tools and read the data they return.
</Warning>

<AccordionGroup>
  <Accordion title="Announcement you can send to members">
    Replace `WORKSPACE_NAME` with the workspace your members select:

    ```text theme={null}
    Zapier is now available in Cursor for our team, and it is already installed. The first time you ask Cursor's Agent to use Zapier, sign in with your Zapier account when prompted.
    If Zapier asks which account to use, select WORKSPACE_NAME.
    If you have not connected any apps to Zapier yet, paste the onboarding prompt from https://docs.zapier.com/mcp/get-started/quickstart#2-set-up-your-tools.
    ```
  </Accordion>
</AccordionGroup>

## Verify the result

* **Check a non-admin account.** Sign in as a test account in a group you gave access to (admins keep access regardless), and confirm Zapier from your team marketplace appears in **Customize** in the state you chose: installed for **Default On** and **Required**, available to install for **Default Off**.
* **As a member, check Zapier is listed.** Confirm Zapier is listed under **Customize** with its toggle on.
* **As a member, run one call.** In a new **Agent** chat, ask Cursor to list the Zapier actions you have enabled. An empty list plus the built-in meta-tools is also a working result, covered in [auto-provisioning](/mcp/overview/how-tools-work#auto-provisioning).

### If Zapier does not appear

* Reload the window or restart the editor.
* If sign-in fails repeatedly, update Cursor to the latest version and try again. [Sign-in completes in browser but MCP client does not connect](/mcp/troubleshoot/sign-in-not-completing) covers the other causes.
* On a Cursor Enterprise account with an active allowlist, confirm the MCP allowlist has a rule for the connect URL.
* If you restricted the Default marketplace, confirm the member belongs to a selected group.
* Check the MCP logs: open the Output panel (`Cmd+Shift+U` on Mac, `Ctrl+Shift+U` on Windows and Linux) and select **MCP Logs**.
* If Zapier is connected but its tools are missing, learn how to troubleshoot [missing tools in an MCP client](/mcp/troubleshoot/tools-missing-in-client).

## Related

<CardGroup cols={2}>
  <Card title="Roll out to your organization" href="/mcp/manage/rollout/overview">
    The rollout model every client guide relies on, and the Zapier controls that govern it.
  </Card>

  <Card title="Cursor" href="/mcp/get-started/connect/cursor">
    Connecting to a team plugin, or installing it yourself from the marketplace.
  </Card>

  <Card title="How connections work" href="/mcp/overview/how-connections-work">
    One endpoint, and the two ways an MCP client authenticates.
  </Card>

  <Card title="Security" href="/mcp/manage/security">
    Access control, app and action restrictions, SSO, and audit logging.
  </Card>
</CardGroup>
