DAG-based planning
Every task compiles into a dependency graph with an immutable plan hash. Nothing executes blind, and an approval can't be reused if the plan changed after it was issued.
Technical architecture
ZAPLIA isn't a chatbot with a long prompt. It's an agent harness with typed tools, persisted human approval, and a real MCP server — so you can connect your own AI to your data, not just ours.
In plain English
Beyond the AI that works across your connected channels, ZAPLIA lets you connect your own AI tool — like Claude — straight to your business data: your contacts, your catalog, your appointments. That lets you ask your AI to look up or update things for you, your way, without going through support. If none of this means much to you, no worries: the rest of ZAPLIA works just as well without touching any of it. This page is for developers or anyone already using AI tools.
Client MCP
MCP (Model Context Protocol) is the open standard for an AI client to use tools from an external server. ZAPLIA exposes a real one, in production, over standard HTTP transport — compatible with Claude Desktop, Claude Code, Cursor, or any generic MCP client.
In Settings → API, create a key with the mcp (or *) scope.
Point your MCP client at the server URL with your key as a Bearer token.
Your AI can now query and operate contacts, products, appointments, and more — the same data you see in your dashboard.
Every MCP client (Claude Desktop, Claude Code, Cursor…) has its own way to add a remote server — use this URL and this header wherever it asks for the connection.
Quick test with curl
curl -X POST https://zaplia.app/api/mcp \
-H "Authorization: Bearer zpk_live_<tu_key>" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'Your MCP key grants full owner-level access to your account (read and write) — there's no granular per-team-member permission inside MCP yet. Store it with the same care as a password.
21 tools, one engine
No duplicated business logic: every MCP tool calls the same execution engine that connects AI to your business data and supported channels.
Read
get_contact_contextFull history, notes, and sales status for a contact
get_contact_by_idLook up a contact by ID
get_contact_by_channelFind a contact by their channel (WhatsApp, email, etc.)
get_recent_messagesLatest messages from a conversation
get_knowledge_answerAnswers with semantic RAG over your Business Brain
get_business_contextYour business profile, catalog, and policies
list_metricsSales and activity metrics for your account
get_open_ticketsOpen support tickets
check_agenda_availabilityAvailable time slots on your calendar
Write
create_contactRegister a new contact
update_contactUpdate a contact's details
create_productAdd a product or service to your catalog
set_contact_communicationPause or block communication with a contact
add_contact_with_welcomeRegister a contact and trigger their welcome message
create_follow_upSchedule a follow-up reminder
create_ticketOpen a support ticket
update_ticket_statusUpdate a ticket's status
create_orderGenerate a sales order
create_appointmentBook an appointment with your customer
book_agenda_slotReserve a specific slot on your calendar
send_whatsapp_messageSend a WhatsApp message to a contact
Why it's a harness, not a prompt on steroids
Every task compiles into a dependency graph with an immutable plan hash. Nothing executes blind, and an approval can't be reused if the plan changed after it was issued.
The agent's autonomous actions go through a real state machine (pending → approved / rejected / expired), not a "trust me." It auto-expires after 24 hours if no one decides.
If a draft reply mentions a price, a percentage, or a quote, it always goes to human review — no matter how confident the AI is. The safety net doesn't depend on the model behaving.
Your verified facts (Business Brain) are indexed with semantic embeddings, not just plain text — the AI searches by meaning, not exact word matches.
Limits, no fine print
Your MCP API key grants full owner-level access to your account — there's no granular per-team-member permission inside MCP yet.
Actions you run yourself via MCP don't go through the human-approval flow — that flow protects what the autonomous agent decides on its own. If you call the tool from your own client, you're already authorizing yourself.
Every account is isolated at the database level (tenant-scoped Row-Level Security) — your key can never see another account's data, no matter what you ask it.
The free plan already includes client MCP access.