Zulip for AI agents

Zulip is team chat organized by topic threads, used by distributed teams that want the immediacy of chat with the structure of email threading. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

CommunicationUsername and passwordMCP + RESTzulip.com
AUDIT LOG · ZULIPPOLICY: acme-support
09:41:07 · claude · u_8f2read
zulip.get_icon
Get realm icon✓ allowed · 212ms
09:41:08 · claude · u_8f2read
zulip.get_user
Get user by email✓ allowed · 164ms
09:41:09 · claude · u_8f2write
zulip.create_drafts
Create Drafts✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
zulip.delete_draft
Delete Draft✕ blocked · policy: deny
EVERY ZULIP CALL, ON THE RECORD
01 · USE CASES

What agents do in Zulip.

01

Send a message to a channel

Post a message to a channel and topic thread.

02

Get another user's presence

Check whether a teammate is currently online, a read-only status check.

03

Confirm before deleting a topic

Check with the user before deleting a topic, since its messages go with it.

02 · ACTIONS

111 Zulip actions, graded by risk.

Every Zulip action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

43

Look things up. Allowed by default.

  • zulip.get_icon
    Get realm icon
  • zulip.get_user
    Get user by email
  • zulip.get_drafts
    Get drafts
  • zulip.get_events
    Get Events
  • zulip.get_invites
    Get all invitations
  • zulip.get_message
    Get message
  • zulip.get_streams
    Get All Channels
  • zulip.get_messages
    Get Messages
  • zulip.get_own_user
    Get own user
  • zulip.get_reminders
    Get reminders
  • zulip.get_stream_id
    Get Channel ID
  • zulip.get_linkifiers
    Get linkifiers
  • zulip.get_alert_words
    Get alert words
  • zulip.get_attachments
    Get Attachments
  • zulip.get_subscribers
    Get Channel Subscribers
  • zulip.get_user_groups
    Get user groups
+ 27 MORE

write

49

Create and change things. Allow, or ask the user first.

  • zulip.update_user
    Update user by email
  • zulip.add_reaction
    Add Reaction
  • zulip.send_message
    Send Message
  • zulip.add_linkifier
    Add Linkifier
  • zulip.create_drafts
    Create Drafts
  • zulip.update_status
    Update Status
  • zulip.update_stream
    Update Channel
  • zulip.add_apns_token
    Add APNs Device Token
  • zulip.create_channel
    Create Channel
  • zulip.update_message
    Update Message
  • zulip.add_alert_words
    Add Alert Words
  • zulip.update_settings
    Update Settings
  • zulip.update_linkifier
    Update Linkifier
  • zulip.update_user_topic
    Update User Topic
  • zulip.add_default_stream
    Add Default Stream
  • zulip.create_invite_link
    Create reusable invitation link
+ 33 MORE

destructive

19

Delete, cancel or archive. Ask first, or deny outright.

  • zulip.delete_draft
    Delete Draft
  • zulip.delete_queue
    Delete Event Queue
  • zulip.delete_topic
    Delete Topic
  • zulip.archive_stream
    Archive Channel
  • zulip.delete_message
    Delete Message
  • zulip.delete_reminder
    Delete Reminder
  • zulip.remove_reaction
    Remove Reaction
  • zulip.remove_fcm_token
    Remove FCM Token
  • zulip.remove_linkifier
    Remove Linkifier
  • zulip.remove_attachment
    Remove Attachment
  • zulip.remove_alert_words
    Remove Alert Words
  • zulip.delete_saved_snippet
    Delete Saved Snippet
  • zulip.remove_default_stream
    Remove Default Stream
  • zulip.remove_code_playground
    Remove Code Playground
  • zulip.remove_navigation_view
    Remove Navigation View
  • zulip.delete_scheduled_message
    Delete Scheduled Message
+ 3 MORE
03 · HOW IT WORKS

Zulip in three steps.

  1. 01Your users connect ZulipThey add their Zulip username and password on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create Drafts” can wait for the user, and “delete Draft” can be denied outright.
  3. 03Any agent can actYour agent calls Zulip through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('zulip', {
  read: 'allow',
  write: 'ask',        // create_drafts
  destructive: 'deny',  // delete_draft
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Zulip connects.

Users add their Zulip username and password on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same Zulip connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
Username and password
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Zulip from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Zulip and Arc0, answered.

Q01

Can I use Zulip with Claude, ChatGPT or Cursor?

Yes. Connect Zulip to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Zulip actions you allow.

Q02

How do users connect Zulip?

Users add their Zulip username and password on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which Zulip actions can my agent take?

111 in total: 43 read, 49 write and 19 destructive, such as “create Drafts”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Zulip?

Yes. Actions like “delete Draft” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Zulip too?

Yes. The same Zulip connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Zulip into your agent.

Your users connect Zulip once, under your brand. Your agent gets 111 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan