Zapier announced that its connector is now available inside Muse, the agent built by Meta, making Zapier a named connector within that product. The announcement is Zapier's own. The company describes the integration as staged for deployment and says that whether Meta users see it depends on Meta's rollout schedule and on each user's authorization.
The mechanism is Zapier's hosted Model Context Protocol endpoint, which the company calls Zapier MCP. Instead of every agent vendor building a separate API integration for each service, an AI client connects once to that endpoint and can then discover and run tools configured for it. Zapier says it handles app authentication, credentials and the underlying integrations on its side of the connection.
According to Zapier, the scope is broad: after a user grants authorization for the connection, Muse is able to access over 40,000 actions and in excess of 9,000 apps by way of Zapier MCP. That scope, Zapier notes, is limited by permissions — the only apps and actions made available are those a given user approves, and the connections and permissions that user already possesses control access.
Zapier also cites workspace-level controls and activity history as part of the offering, and says the service operates under its SOC 2 Type II certification. It notes that connected apps keep applying their own permissions and API limits, so the effective ceiling on any given action is set by the third-party service as well as by Zapier and the user.
Zapier's own illustration of the intended pattern is deliberately narrow: grant Muse read-only access to a CRM plus permission to post in Slack, then ask it to identify which customers need a follow-up. That is an agent reading from one system and writing to another, with the write scope limited to what the user granted.
For longer-running work, Zapier says an MCP-enabled agent can build and deploy an automation to Zapier when a user with Next Gen Zaps access describes it in plain language, rather than the agent repeating a fixed sequence of actions. Zapier states that Next Gen Zaps is available through a separate early access program, so whether any particular user has it depends on their Zapier account.
Zapier states that, on the technical front, Streamable HTTP is what Zapier MCP relies on. The announcement indicates that separate servers, along with distinct connection tokens, can be configured by teams for testing, production and development. A Zapier Team or Enterprise plan is needed to share access to a server, whereas through what Zapier terms a tool bundle, a copy of a tool configuration can be shared by users on any plan.
The quoted comments come from Dan Slagen, Zapier's Chief AI Transformation Officer and CMO. Slagen links the Muse connector to Zapier's earlier move of launching Muse Spark 1.3 into AI by Zapier, and argues that AI becomes more useful when it can act across the tools people already use. He also frames the value as starting with one action an agent can take now and building repeatable workflows later.
For freelancers, designers and developers, the significance is less about Muse specifically than about the pattern it represents: agent vendors are outsourcing breadth of integrations to a connector layer rather than building each one themselves. If that pattern holds, integration work a freelancer might previously have been paid to build — a bespoke bridge between an agent and a client's CRM, for instance — becomes increasingly a configuration task inside a tool like Zapier MCP.
That cuts both ways. Configuration work is faster to deliver and easier to hand over, but it is also less defensible as a billable specialty, and it ties the client's automation to Zapier's account, plan tier and permission model. The Team or Enterprise requirement for sharing server access is a concrete example of how plan boundaries shape what a small studio can hand off to a client.
There is also a governance angle for anyone advising clients. Zapier's description places authentication and credentials on its side of the connection, with per-user connections and permissions governing what is reachable, plus workspace controls and activity history. That is a cleaner story to tell a client than a pile of one-off API keys, but it also concentrates trust in a single intermediary.
The most important caveat is availability. Zapier states plainly that the integration is staged for deployment and that access for Meta users depends on Meta's rollout and on user authorization. Zapier's announcement does not establish that the connector is live for any particular Meta user today, and it gives no date for general availability.
A further gap concerns pricing. That a Zapier Team or Enterprise plan is needed to share access to a server is mentioned, yet what the Muse connection itself costs, whether existing plans bundle it, or how usage is metered are not stated. Cost should be treated as unresolved by anyone budgeting for a client engagement.
The 9,000 apps and 40,000 actions figures are Zapier's own counts for its ecosystem, not a measure of what any individual Muse user can reach. Because access is scoped to a user's connections and permissions, and because connected apps enforce their own limits, the realistic surface area for a given account is likely far smaller than the headline numbers suggest.
Zapier's security claims rest on its SOC 2 Type II certification and on the permission model it describes. Those are vendor statements about the service; the announcement includes no independent testing, no third-party audit report, and no detail on how the connector handles prompt-injection style risks that arise when an agent can both read untrusted content and take actions in connected apps.
The Next Gen Zaps capability deserves scrutiny separate from the connector itself. Zapier says an agent can build and deploy an automation from a plain-language description, but it also says that feature sits behind a separate early access program. Muse reaching Zapier tools and an agent authoring Zaps are related but not the same thing, and their availability differs.
A reasonable read for this audience is that the connector is worth tracking as a signal about where agent integrations are heading, and worth testing only once it is actually reachable in your own account. The concrete, verifiable facts are narrow: Zapier says its connector is available in Muse, that it runs over Zapier MCP using Streamable HTTP, that access is permission-scoped, and that Meta's rollout governs who gets it.
What remains unknown is substantial: no general availability date, no pricing for the Muse connection, no independent verification of the security posture, and no detail on how the connector behaves when an agent's read access and write access span systems with different trust levels. Those gaps are the ones to close before recommending it to a client.