{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "stackone",
    "name": "StackOne",
    "vendor": "StackOne Technologies Limited",
    "vendorUrl": "https://www.stackone.com",
    "kind": "mcp",
    "category": "aggregator",
    "summary": "StackOne is a hosted gateway from StackOne Technologies Limited that gives AI agents actions across more than 540 business apps over MCP, SDKs, A2A or HTTP, with managed authentication, per-user grants, policies and logs.",
    "url": "https://www.anchorterminal.com/tools/stackone",
    "markdownUrl": "https://www.anchorterminal.com/tools/stackone.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/stackone.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/stackone.json",
    "repo": "https://github.com/StackOneHQ/stackone-ai-node",
    "license": "Proprietary service under StackOne's SaaS Terms and Conditions. The Agent SDKs (`@stackone/ai`, `stackone-ai`) and the Defender package (`@stackone/defender`) are Apache-2.0",
    "transports": [
      "streamable-http",
      "http"
    ],
    "remoteUrl": "https://mcp.stackone.com/mcp",
    "packages": [
      {
        "registry": "npm",
        "name": "@stackone/ai"
      },
      {
        "registry": "pypi",
        "name": "stackone-ai"
      },
      {
        "registry": "npm",
        "name": "@stackone/defender"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve. A person signs up in the dashboard, creates a project and a connector profile, and links an account. MCP clients connect to `https://mcp.stackone.com/mcp` with OAuth (scopes `mcp offline_access`, one-hour access tokens, a 90-day grant) and the user picks the linked accounts and actions at consent. Most clients register themselves, and a few need a client ID and secret created in the dashboard. Backend calls go to `https://api.stackone.com/mcp` or `POST /actions/rpc` with a project API key as the Basic auth username and the linked account in `x-account-id`. Keys take scopes (Platform API, Actions, Connectors, Credentials, Unified API) and can be disabled or deleted. Session token URLs (`https://api.stackone.com/mcp?token=...`) cover one linked account, carry the access in the URL and expire after one year by default.",
    "pricing": "freemium",
    "pricingNotes": "Free to start with no card, per the pricing page. Gateway Starter is free with 1,000 credits a seat a month, one credit per tool call or API call, and extra credits at $60 per 20,000. Gateway Team is $600 a month ($6,000 a year) with 5,000 credits a seat a month and extra credits at $20 per 20,000. The pricing calculator's markup gives 10 seats included on Team and $15 a further seat, which the page text doesn't state. OEM Core is free with a monthly credit allowance and volume prices on request. Enterprise plans are priced on contract. Browser use, premium defence and data sync cost more than one credit, at rates not published. The Service Consumption Schedule of 30 March 2026 gives $0.003 per Action Call as overage and counts unsuccessful requests, while the pricing page says background and failed calls aren't billed (https://www.stackone.com/pricing/, checked 2026-10-09).",
    "priceSummary": "$600 / mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs index, the pricing page, the SaaS terms or the Service Consumption Schedule (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 30,
      "npmWeekly": 277,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://docs.stackone.com/introduction",
    "mcpTools": {
      "url": "https://mcp.stackone.com/mcp",
      "checkedAt": "2026-10-09T21:40:55.809059913Z",
      "status": "auth",
      "note": "asks for credentials before listing its tools",
      "changedAt": "2026-10-09T21:40:55.809059913Z"
    },
    "llmsTxt": "https://docs.stackone.com/llms.txt",
    "openapi": "https://api.eu1.stackone.com/v2/oas/stackone.json",
    "registryName": "com.stackone/mcp",
    "capabilities": [
      "automation.apps",
      "automation.auth",
      "automation.actions",
      "agent.tools",
      "auth.audit"
    ],
    "tags": [
      "hosted",
      "mcp",
      "a2a",
      "freemium",
      "free-tier",
      "no-card",
      "oauth",
      "api-key",
      "openapi",
      "llms-txt",
      "typescript",
      "python",
      "enterprise",
      "status-page",
      "soc2",
      "mcp-registry",
      "closed-source"
    ],
    "lastRelease": "2026-09-24",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 69.1,
      "grade": "B",
      "agentReady": false,
      "rank": 198,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 3,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 75,
        "maintenance": 84,
        "payments": 38,
        "reliability": 80,
        "schema": 78,
        "security": 69,
        "transparency": 69
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 80,
          "points": 16,
          "reason": "Read with the hosted lines. status.stackone.com on incident.io lists the Web Dashboard, the API in three regions and the Connectors Hub (20). The page shows July to October 2026 at 100 per cent for the dashboard, the hub and the US and UK API, and 99.990 per cent for the EU API. The incident list is drawn by script and was not read, so 20 of 30 (20). API keys are limited to 1,000 requests a minute (15). 429 responses carry `Retry-After` in seconds, and StackOne retries a provider's 429 up to five times within a 60-second request lifetime before returning 429 or 408. No idempotency key or retry guidance for writes was found (10). The pricing page lists an uptime SLA on Enterprise with no figure, and the Starter plan has none (5). MCP and the RPC endpoint carry no beta label. A2A is in open beta (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 78,
          "points": 12.68,
          "reason": "An OpenAPI 3.1 file is published for the Platform API (30 operations under `/v2`), the actions, logs and MCP endpoints have reference pages with embedded definitions, and the docs say each MCP tool has a JSON Schema. Live tool schemas were not read, since that needs an account (22). llms.txt for the docs and the site, and a Markdown twin of every docs page (10). Connector pages give one line per action, such as 'Send a message to a channel or conversation', with the provider scopes each needs and no guidance on when not to use it (11). The Platform API types its parameters and has 26 enum uses, while `POST /actions/rpc` and the execute tool take open `path`, `query`, `body` and `headers` objects (9). curl, Python and TypeScript examples, eleven error statuses declared on every operation and a troubleshooting catalogue for MCP (13). `/v2` paths, connector semver with version pins, per-connector changelogs and a dated product changelog. No API deprecation policy was found (13)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 75,
          "points": 12.19,
          "reason": "The catalogue is large, and `individual` mode registers one tool per enabled action, which scores 5. Ten back for the two-tool search and execute mode (on by default at the OAuth consent screen), per-action grants and connector profile scoping (15). List endpoints take `page` and `page_size` with a total, filters and field expansion, tool search takes `top_k`, and Deep Query returns counts or chosen fields. Offset paging can skip or repeat records, as the docs warn (16). Errors carry `statusCode`, `errorCode`, `details.statusReasons` and provider errors, with documented causes for 400, 401, 406, 412 and the JSON-RPC codes (17). Every tool carries `readOnlyHint` and `destructiveHint` since July 2026. `idempotentHint` is set only by hand and tool calls take no idempotency key (14). Agent SDKs for TypeScript and Python and API clients in five languages. The mandatory `Accept` header and Basic auth encoding are extra steps (13)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 69,
          "points": 12.08,
          "reason": "OAuth per user with one-hour access tokens, a 90-day grant and revocation, and project API keys with scopes that can be disabled or deleted, would score 30. Ten off because session token URLs carry the access in the query string as a documented option, with a one-year default expiry (20). Connector profiles enable individual actions, users grant accounts and actions at consent, the Credentials scope is off by default, and Policies deny tools, mask fields and bound values on Team and Enterprise. Policies skip API-key calls, and no approval step at the gateway was found (16). Defender scans tool results and is on for new projects, in Monitor mode by default, which changes nothing. Large responses skip scanning by default (12). Action logs on every plan (one day on Starter), login security logs and Advanced Logs with credential masking. The Logs API, audit logs and SIEM export are Enterprise only on Gateway plans (11). SOC 2 Type II and HIPAA are stated on the pricing and contact pages, and the DPA promises breach notice within 48 hours. security.txt returned 404, no bounty or disclosure policy was found, and the trust centre answered with a bot check (10)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 38,
          "points": 4.75,
          "reason": "No x402, MPP or L402 (0). Credit prices are public. One credit per tool call or API call, extra credits at $60 per 20,000 on Starter and $20 per 20,000 on Team, and Team at $600 a month. Two off because the per-seat price sits only in the calculator's markup, the rates for advanced capabilities aren't published, and the Service Consumption Schedule and the pricing page disagree on failed calls (18). Free plans on both models with no card, per the pricing page (20). A person signs up in the dashboard, and no keyless or programmatic signup route was found (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 84,
          "points": 7.35,
          "reason": "Changelog entry on 24 September 2026 (Deep Query) and `@stackone/defender` v0.8.3 on 23 September (30). Dated entries on 24 July, 3, 7 and 19 August, and 7 and 24 September (20). A closed service with a dated changelog and in-app chat and email support. The TypeScript SDK repository shows 7 open issues and commits on 9 October 2026 (11). `com.stackone/mcp` is in the official MCP registry under the vendor's domain namespace, version 1.0.1 of 17 August 2026 (15). The SDK repositories carry CI workflows, lockfiles and release automation. The newest Agent SDK releases are from late July (8)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 69,
          "points": 6.04,
          "note": "editorial 50, provenance 88",
          "reason": "The editorial half. Closed service under SaaS terms that name StackOne Technologies Limited, with the Agent SDKs and Defender under Apache-2.0 (17). The DPA of 15 January 2025 promises deletion within 30 days of termination and breach notice within 48 hours, and the AI Services Addendum says AI providers may not train on customer data. The privacy policy of December 2023 says data is stored in the EEA while projects can be created in a US region, and it gives 30 and 90 day retention periods side by side. The SaaS terms let StackOne use anonymised usage data to improve the Service (18). No deprecation policy for the API was found. Preview functions can be withdrawn at any time, and the Starter plan can change with 30 days' notice on a reasonable-efforts basis. Connector versions can be pinned (5). Three hosting regions are named with their data centres. The sub-processor list is on the trust centre, which we could not read. The DPA gives 14 days to object to a new sub-processor (10)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The catalogue is large, and `individual` mode registers one tool per enabled action, which scores 5. Ten back for the two-tool search and execute mode (on by default at the OAuth consent screen), per-action grants and connector profile scoping (15). List endpoints take `page` and `page_size` with a total, filters and field expansion, tool search takes `top_k`, and Deep Query returns counts or chosen fields. Offset paging can skip or repeat records, as the docs warn (16). Errors carry `statusCode`, `errorCode`, `details.statusReasons` and provider errors, with documented causes for 400, 401, 406, 412 and the JSON-RPC codes (17). Every tool carries `readOnlyHint` and `destructiveHint` since July 2026. `idempotentHint` is set only by hand and tool calls take no idempotency key (14). Agent SDKs for TypeScript and Python and API clients in five languages. The mandatory `Accept` header and Basic auth encoding are extra steps (13).",
          "maintenance": "Changelog entry on 24 September 2026 (Deep Query) and `@stackone/defender` v0.8.3 on 23 September (30). Dated entries on 24 July, 3, 7 and 19 August, and 7 and 24 September (20). A closed service with a dated changelog and in-app chat and email support. The TypeScript SDK repository shows 7 open issues and commits on 9 October 2026 (11). `com.stackone/mcp` is in the official MCP registry under the vendor's domain namespace, version 1.0.1 of 17 August 2026 (15). The SDK repositories carry CI workflows, lockfiles and release automation. The newest Agent SDK releases are from late July (8).",
          "payments": "No x402, MPP or L402 (0). Credit prices are public. One credit per tool call or API call, extra credits at $60 per 20,000 on Starter and $20 per 20,000 on Team, and Team at $600 a month. Two off because the per-seat price sits only in the calculator's markup, the rates for advanced capabilities aren't published, and the Service Consumption Schedule and the pricing page disagree on failed calls (18). Free plans on both models with no card, per the pricing page (20). A person signs up in the dashboard, and no keyless or programmatic signup route was found (0).",
          "reliability": "Read with the hosted lines. status.stackone.com on incident.io lists the Web Dashboard, the API in three regions and the Connectors Hub (20). The page shows July to October 2026 at 100 per cent for the dashboard, the hub and the US and UK API, and 99.990 per cent for the EU API. The incident list is drawn by script and was not read, so 20 of 30 (20). API keys are limited to 1,000 requests a minute (15). 429 responses carry `Retry-After` in seconds, and StackOne retries a provider's 429 up to five times within a 60-second request lifetime before returning 429 or 408. No idempotency key or retry guidance for writes was found (10). The pricing page lists an uptime SLA on Enterprise with no figure, and the Starter plan has none (5). MCP and the RPC endpoint carry no beta label. A2A is in open beta (10).",
          "schema": "An OpenAPI 3.1 file is published for the Platform API (30 operations under `/v2`), the actions, logs and MCP endpoints have reference pages with embedded definitions, and the docs say each MCP tool has a JSON Schema. Live tool schemas were not read, since that needs an account (22). llms.txt for the docs and the site, and a Markdown twin of every docs page (10). Connector pages give one line per action, such as 'Send a message to a channel or conversation', with the provider scopes each needs and no guidance on when not to use it (11). The Platform API types its parameters and has 26 enum uses, while `POST /actions/rpc` and the execute tool take open `path`, `query`, `body` and `headers` objects (9). curl, Python and TypeScript examples, eleven error statuses declared on every operation and a troubleshooting catalogue for MCP (13). `/v2` paths, connector semver with version pins, per-connector changelogs and a dated product changelog. No API deprecation policy was found (13).",
          "security": "OAuth per user with one-hour access tokens, a 90-day grant and revocation, and project API keys with scopes that can be disabled or deleted, would score 30. Ten off because session token URLs carry the access in the query string as a documented option, with a one-year default expiry (20). Connector profiles enable individual actions, users grant accounts and actions at consent, the Credentials scope is off by default, and Policies deny tools, mask fields and bound values on Team and Enterprise. Policies skip API-key calls, and no approval step at the gateway was found (16). Defender scans tool results and is on for new projects, in Monitor mode by default, which changes nothing. Large responses skip scanning by default (12). Action logs on every plan (one day on Starter), login security logs and Advanced Logs with credential masking. The Logs API, audit logs and SIEM export are Enterprise only on Gateway plans (11). SOC 2 Type II and HIPAA are stated on the pricing and contact pages, and the DPA promises breach notice within 48 hours. security.txt returned 404, no bounty or disclosure policy was found, and the trust centre answered with a bot check (10).",
          "transparency": "The editorial half. Closed service under SaaS terms that name StackOne Technologies Limited, with the Agent SDKs and Defender under Apache-2.0 (17). The DPA of 15 January 2025 promises deletion within 30 days of termination and breach notice within 48 hours, and the AI Services Addendum says AI providers may not train on customer data. The privacy policy of December 2023 says data is stored in the EEA while projects can be created in a US region, and it gives 30 and 90 day retention periods side by side. The SaaS terms let StackOne use anonymised usage data to improve the Service (18). No deprecation policy for the API was found. Preview functions can be withdrawn at any time, and the Starter plan can change with 30 days' notice on a reasonable-efforts basis. Connector versions can be pinned (5). Three hosting regions are named with their data centres. The sub-processor list is on the trust centre, which we could not read. The DPA gives 14 days to object to a new sub-processor (10)."
        },
        "sources": [
          {
            "what": "docs index",
            "url": "https://docs.stackone.com/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "site index with connector counts and legal links",
            "url": "https://www.stackone.com/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "introduction",
            "url": "https://docs.stackone.com/introduction.md",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP for AI platforms, OAuth and session tokens",
            "url": "https://docs.stackone.com/connect/ai-platforms/overview.md",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP from a backend, tool modes",
            "url": "https://docs.stackone.com/embed/call-actions/mcp.md",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP troubleshooting and error codes",
            "url": "https://docs.stackone.com/embed/call-actions/mcp/troubleshooting.md",
            "seen": "2026-10-09"
          },
          {
            "what": "RPC over HTTP",
            "url": "https://docs.stackone.com/embed/call-actions/rpc-http.md",
            "seen": "2026-10-09"
          },
          {
            "what": "RPC endpoint reference",
            "url": "https://docs.stackone.com/platform/api-reference/actions/make-an-rpc-call-to-an-action.md",
            "seen": "2026-10-09"
          },
          {
            "what": "API keys and scopes",
            "url": "https://docs.stackone.com/embed/api-keys.md",
            "seen": "2026-10-09"
          },
          {
            "what": "Platform API authentication",
            "url": "https://docs.stackone.com/platform-api/authentication.md",
            "seen": "2026-10-09"
          },
          {
            "what": "rate limiting",
            "url": "https://docs.stackone.com/platform-api/rate-limiting.md",
            "seen": "2026-10-09"
          },
          {
            "what": "pagination",
            "url": "https://docs.stackone.com/platform-api/request-parameters/pagination.md",
            "seen": "2026-10-09"
          },
          {
            "what": "Advanced Tool Search",
            "url": "https://docs.stackone.com/optimize/advanced-tool-search.md",
            "seen": "2026-10-09"
          },
          {
            "what": "Defender",
            "url": "https://docs.stackone.com/secure/defender.md",
            "seen": "2026-10-09"
          },
          {
            "what": "Policies",
            "url": "https://docs.stackone.com/secure/policies.md",
            "seen": "2026-10-09"
          },
          {
            "what": "scoping connectors",
            "url": "https://docs.stackone.com/secure/scoping-connectors.md",
            "seen": "2026-10-09"
          },
          {
            "what": "observability and Advanced Logs",
            "url": "https://docs.stackone.com/secure/observability.md",
            "seen": "2026-10-09"
          },
          {
            "what": "projects and regions",
            "url": "https://docs.stackone.com/gateway/concepts/organizations-and-projects.md",
            "seen": "2026-10-09"
          },
          {
            "what": "connector versioning",
            "url": "https://docs.stackone.com/connector-building/connector-versioning.md",
            "seen": "2026-10-09"
          },
          {
            "what": "A2A, open beta",
            "url": "https://docs.stackone.com/embed/call-actions/agent2agent.md",
            "seen": "2026-10-09"
          },
          {
            "what": "Slack connector page",
            "url": "https://docs.stackone.com/connectors/slack/index.md",
            "seen": "2026-10-09"
          },
          {
            "what": "API SDKs",
            "url": "https://docs.stackone.com/platform-api/api-sdks.md",
            "seen": "2026-10-09"
          },
          {
            "what": "OpenAPI file, read as the description file and not a rendered page",
            "url": "https://api.eu1.stackone.com/v2/oas/stackone.json",
            "seen": "2026-10-09"
          },
          {
            "what": "pricing",
            "url": "https://www.stackone.com/pricing/",
            "seen": "2026-10-09"
          },
          {
            "what": "changelog",
            "url": "https://www.stackone.com/changelog/",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP tool annotations changelog entry",
            "url": "https://www.stackone.com/changelog/mcp-tool-annotations/",
            "seen": "2026-10-09"
          },
          {
            "what": "contact page with company details",
            "url": "https://www.stackone.com/contact/",
            "seen": "2026-10-09"
          },
          {
            "what": "legal index",
            "url": "https://www.stackone.com/legal/",
            "seen": "2026-10-09"
          },
          {
            "what": "SaaS Terms and Conditions",
            "url": "https://www.stackone.com/terms/saas-terms/",
            "seen": "2026-10-09"
          },
          {
            "what": "Service Consumption Schedule",
            "url": "https://www.stackone.com/terms/service-consumption-schedule/",
            "seen": "2026-10-09"
          },
          {
            "what": "Acceptable Use Policy",
            "url": "https://www.stackone.com/terms/acceptable-use-policy/",
            "seen": "2026-10-09"
          },
          {
            "what": "AI Services Addendum",
            "url": "https://www.stackone.com/terms/ai-services-addendum/",
            "seen": "2026-10-09"
          },
          {
            "what": "Data Processing Addendum",
            "url": "https://www.stackone.com/terms/dpa/",
            "seen": "2026-10-09"
          },
          {
            "what": "Platform Privacy Policy",
            "url": "https://www.stackone.com/terms/privacy-policy/",
            "seen": "2026-10-09"
          },
          {
            "what": "status page",
            "url": "https://status.stackone.com/",
            "seen": "2026-10-09"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=stackone",
            "seen": "2026-10-09"
          },
          {
            "what": "TypeScript Agent SDK repository, tags and changelog",
            "url": "https://github.com/StackOneHQ/stackone-ai-node",
            "seen": "2026-10-09"
          },
          {
            "what": "Python Agent SDK repository, tags",
            "url": "https://github.com/StackOneHQ/stackone-ai-python",
            "seen": "2026-10-09"
          },
          {
            "what": "Defender repository, tags",
            "url": "https://github.com/StackOneHQ/defender",
            "seen": "2026-10-09"
          },
          {
            "what": "npm weekly downloads for @stackone/ai",
            "url": "https://api.npmjs.org/downloads/point/last-week/@stackone/ai",
            "seen": "2026-10-09"
          },
          {
            "what": "RDAP for stackone.com",
            "url": "https://rdap.verisign.com/com/v1/domain/stackone.com",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: trust.stackone.com (security policy, sub-processor list, certifications, any disclosure programme), which answered our reader with a bot check. We did not retry",
          "unchecked: the incident list on status.stackone.com, which is drawn by script. Only the component uptime figures were read",
          "unchecked: live tool definitions from `tools/list`, including the size of schemas and the annotations, because reading them needs an account and we did not create one",
          "unchecked: api.stackone.com and mcp.stackone.com answered 403 to a robots.txt request, so no further request was sent to either, and the OAuth metadata was not read",
          "unchecked: weekly downloads of `stackone-ai` on PyPI",
          "Whether failed calls are billed. The pricing page says no and the Service Consumption Schedule counts them",
          "The credit cost of browser use, premium defence and data sync, and the figure in the Enterprise uptime SLA",
          "Whether the seat prices in the pricing calculator's markup ($15 a further seat on Team, 10 included) are what a customer is charged",
          "Whether the Platform Privacy Policy of December 2023, which says data is stored in the EEA, still describes projects created in the US region",
          "The Acceptable Use Policy bars benchmarking other than for internal comparison and vulnerability testing without authorisation, which matters before any probe is run"
        ]
      },
      "negative": -2,
      "negativeNotes": [
        "27 April 2026. `@stackone/ai` v2.8.1 fixed a flaw in which tools fetched concurrently for several accounts were stamped with the wrong `x-account-id`, so a call could run against another linked account. It is recorded as a bug fix in the changelog, with no advisory found. Fixed and documented, so 2 points (https://github.com/StackOneHQ/stackone-ai-node/blob/main/CHANGELOG.md)."
      ],
      "verdict": "StackOne's MCP server signs each person in with OAuth, lets them grant individual accounts and actions, and by default exposes two search and execute tools in place of the full catalogue. Session token URLs carry the credential in the query string for a year by default, and the Consumption Schedule and pricing page disagree on whether failed calls are billed.",
      "bestFor": "A company that wants one governed MCP endpoint for staff agents across business systems, and product teams embedding per-customer connections with HR, recruiting and CRM coverage.",
      "strengths": [
        "The MCP server at `https://mcp.stackone.com/mcp` uses OAuth per person. Access tokens last one hour, a grant lasts 90 days, and each user can revoke it under Connected Apps",
        "Advanced Tool Search replaces the tool list with two tools, search and execute, and is on by default at the OAuth consent screen",
        "Since 24 July 2026 every tool carries `readOnlyHint`, `destructiveHint` and `openWorldHint`, derived from an effects value on each action",
        "API keys are limited to one project and take scopes for the Platform API, Actions, Connectors, Credentials and the Unified API. Credentials access is off by default",
        "Rate limit published at 1,000 requests a minute per API key, with `Retry-After` in seconds on 429 and 408 responses",
        "Defender scans tool results for prompt injection and is on for new projects. Its Light Scan engine is open source under Apache-2.0"
      ],
      "weaknesses": [
        "Session token URLs (`https://api.stackone.com/mcp?token=...`) put the credential in the query string, cover one linked account and expire after one year by default",
        "The Service Consumption Schedule counts every request, successful or not, as an Action Call. The pricing page says failed calls aren't billed",
        "Defender's default mode is Monitor, which records a verdict and passes the tool result to the agent unchanged",
        "Policies apply only to signed-in members. A call made with a project API key is memberless and is governed by connector profile scoping alone",
        "The Logs API, audit logs, SIEM export and an uptime SLA are Enterprise only on Gateway plans, and Starter keeps action logs for one day",
        "The Acceptable Use Policy bars competitive analysis or benchmarking other than for internal comparison, and probing or testing the Service's vulnerability without authorisation. This matters before any probe is run",
        "`@stackone/ai` stamped tools with the wrong `x-account-id` when accounts were fetched concurrently, until v2.8.1 on 27 April 2026. No advisory was found"
      ],
      "agentNotes": [
        "Send `Accept: application/json,text/event-stream` on every MCP request to `https://api.stackone.com/mcp`, by POST only. Without it the server answers 406",
        "In `search_execute` mode call `{provider}_search_actions` first and pass the returned `action_id` to `{provider}_execute_action`. Never hardcode action ids",
        "Pass the API key as the Basic auth username with an empty password, and name the linked account in `x-account-id`",
        "On 429 or 408 wait the seconds given in `Retry-After`. StackOne has already retried a provider's 429 up to five times within a 60-second request lifetime",
        "On 412 read `errorCode` and `details.statusReasons`. `AccountErrorStatus` needs a person to re-authenticate the linked account"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 69.1
        }
      ],
      "editorialScores": {
        "ergonomics": 75,
        "maintenance": 84,
        "payments": 38,
        "reliability": 80,
        "schema": 78,
        "security": 69,
        "transparency": 50
      },
      "provenanceScore": 88
    },
    "connect": {
      "install": "npm install @stackone/ai",
      "http": "curl -X POST \"https://api.stackone.com/actions/rpc\" \\\n  -u \"$STACKONE_API_KEY:\" \\\n  -H \"x-account-id: your-account-id\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"action\": \"bamboohr_list_employees\", \"query\": {\"page_size\": 25}}'",
      "claudeCode": "claude mcp add --transport http --scope user stackone https://mcp.stackone.com/mcp"
    },
    "letme": {
      "capability": "https://letme.dev/automation.apps",
      "tool": "https://letme.dev/stackone"
    },
    "notable": [
      "One MCP URL for a whole organisation. It carries no access on its own, and each person signs in and picks the linked accounts and actions the client may use (https://docs.stackone.com/connect/ai-platforms/overview.md)",
      "The site index counts 546 live connectors and more than 33,470 actions, a vendor figure. The Slack connector page lists 50 actions at connector version 4.0.0 (https://www.stackone.com/llms.txt)",
      "Tool annotations on every tool since 24 July 2026. `readOnlyHint` is true when every effect is read or search, `destructiveHint` when any effect is delete, and `idempotentHint` is never inferred (https://www.stackone.com/changelog/mcp-tool-annotations/)",
      "Policies deny tools, mask fields, bound argument values and redact PII per user or group, on Gateway Team and Enterprise. They don't apply to calls made with a project API key (https://docs.stackone.com/secure/policies.md)",
      "Defender is on for new projects in Monitor mode at the Low protection level, and responses over 1 MB or 10,000 words skip scanning by default (https://docs.stackone.com/secure/defender.md)",
      "The official MCP registry lists `com.stackone/mcp` version 1.0.1, published 17 August 2026, with the remote `https://mcp.stackone.com/mcp` (https://registry.modelcontextprotocol.io/v0/servers?search=stackone)",
      "The published OpenAPI 3.1 file holds 30 operations on 19 paths under `/v2`. The actions, logs and MCP endpoints are described on their own reference pages (https://api.eu1.stackone.com/v2/oas/stackone.json)",
      "Every Markdown docs page opens with a line telling the reader to fetch the docs index, and the introduction gives a prompt for users to paste into an agent. We read both as data (https://docs.stackone.com/introduction.md)",
      "The site's llms.txt lists the legal documents under `/legal/`, where each answered 404 on 9 October 2026. The working pages are under `/terms/` (https://www.stackone.com/legal/)",
      "The Acceptable Use Policy bars benchmarking other than for internal comparison and vulnerability testing without authorisation (https://www.stackone.com/terms/acceptable-use-policy/)"
    ],
    "area": "business",
    "details": [
      {
        "label": "MCP endpoints",
        "value": "`https://mcp.stackone.com/mcp` with OAuth for people using a client, `https://api.stackone.com/mcp` with an API key and `x-account-id` for backends, and `https://api.stackone.com/mcp?token=\u003csession_token\u003e` for unattended use. Streamable HTTP, POST only, stateless, no SSE"
      },
      {
        "label": "Tool modes",
        "value": "`individual` registers one tool per enabled action. `search_execute` registers `{provider}_search_actions` (`top_k` default 10, maximum 50) and `{provider}_execute_action`. Set with `?tool-mode=` or at the consent screen"
      },
      {
        "label": "Other interfaces",
        "value": "`POST /actions/rpc` and `GET /actions` over HTTP, Agent SDKs for TypeScript and Python, and A2A agents at `https://a2a.stackone.com`, which the docs mark as open beta"
      },
      {
        "label": "Connectors",
        "value": "546 live connectors and more than 33,470 actions per the site index, a vendor figure. Connectors carry semver versions and a connector profile can pin `latest`, `1.x.x`, `1.2.x` or one version"
      },
      {
        "label": "Credentials",
        "value": "OAuth grants per user (one-hour access tokens, 90 days, revocable), project API keys with five scope groups, and session tokens fixed to one linked account with a one-year default expiry"
      },
      {
        "label": "End-user authorisation",
        "value": "Linked accounts created in the dashboard, through the embedded StackOne Hub or by an auth link. StackOne's shared OAuth apps or the customer's own"
      },
      {
        "label": "Rate limits",
        "value": "1,000 requests a minute per API key. 429 carries `Retry-After` in seconds. Provider 429s are retried up to five times within a 60-second request lifetime, then 429 or 408 is returned"
      },
      {
        "label": "Free plan",
        "value": "Gateway Starter, 1,000 credits a seat a month, one project, action logs kept one day, no card. OEM Core is free with a monthly credit allowance"
      },
      {
        "label": "Governance",
        "value": "Connector profiles enable or disable each action. Policies (Team and Enterprise) deny tools, mask fields, bound values and redact PII per user or group. SAML SSO on Team, IP allowlists on Enterprise"
      },
      {
        "label": "Defender",
        "value": "Pattern matching and a local MiniLM classifier on every tool result. Modes Monitor (default), `Sanitize` and Block. The hosted Deep Scan adds an LLM review that StackOne says runs on its own inference endpoints"
      },
      {
        "label": "Logs",
        "value": "Action logs kept 1, 7 or 30 days on Gateway Starter, Team and Enterprise. Advanced Logs store request and response bodies, off by default, for 1, 7 or 30 days. Logs API, audit logs and SIEM export on Enterprise and OEM plans as listed"
      },
      {
        "label": "Hosting",
        "value": "AWS eu-west-1 (Dublin), GCP europe-west1 (Belgium) and AWS us-east-1 (N. Virginia), chosen per project and fixed at creation. Other regions and self-hosting are Enterprise add-ons"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type II, GDPR and HIPAA per the pricing and contact pages, with the SOC 2 report and a Business Associate Agreement on Enterprise. The trust centre answered our reader with a bot check"
      },
      {
        "label": "SDKs",
        "value": "`@stackone/ai` 2.10.0 (27 July 2026, Node 20.19.6 or later) and `stackone-ai` 2.10.1 (28 July 2026, Python 3.11 or later), both Apache-2.0. Platform API clients for TypeScript and Ruby, with PHP, Java and C# in beta"
      }
    ],
    "unitPrices": [
      {
        "item": "Gateway Team plan",
        "unit": "month",
        "usd": 600,
        "note": "5,000 credits a seat a month, one credit per tool call or API call. $6,000 billed yearly"
      },
      {
        "item": "Extra credits, Gateway Starter",
        "unit": "1k-calls",
        "usd": 3,
        "note": "$60 per 20,000 credits, valid 12 months. Advanced capabilities cost more than one credit a call"
      },
      {
        "item": "Extra credits, Gateway Team",
        "unit": "1k-calls",
        "usd": 1,
        "note": "$20 per 20,000 credits, valid 12 months"
      }
    ],
    "provenance": {
      "legalEntity": "StackOne Technologies Limited",
      "domain": "stackone.com",
      "domainRegistered": "2013-06-25",
      "endpointOnVendorDomain": true,
      "terms": "https://www.stackone.com/terms/saas-terms/",
      "privacy": "https://www.stackone.com/terms/privacy-policy/",
      "statusPage": "https://status.stackone.com",
      "changelog": "https://www.stackone.com/changelog/",
      "securityTxt": "none",
      "checked": "2026-10-09",
      "notes": [
        "The SaaS Terms and Conditions, effective 30 March 2026, name StackOne Technologies Limited, company number 14684360, registered at 2 Communications Road, Newbury, Berkshire, RG19 6AB, under the laws of England and Wales. They take effect when a customer first accesses the Service or signs an order.",
        "The contact page says StackOne operates in the United States as StackOne Technologies Inc., 2261 Market Street, San Francisco.",
        "The Platform Privacy Policy, last updated 1 December 2023, covers the web application and API and says it does not cover the website. A separate Privacy Notice covers the website.",
        "The MCP server answers at mcp.stackone.com, the API at api.stackone.com and A2A at a2a.stackone.com.",
        "www.stackone.com/.well-known/security.txt returned 404.",
        "RDAP for stackone.com gives a registration date of 2013-06-25. The company was incorporated later, per its company number.",
        "status.stackone.com runs on incident.io and lists the Web Dashboard, the API (US, EU and UK) and the Connectors Hub.",
        "trust.stackone.com, which the terms cite for the security policy and the sub-processor list, answered our reader with a bot check and was not read."
      ],
      "score": 88,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "StackOne Technologies Limited",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "stackone.com, registered 2013-06-25 (13 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "mcp.stackone.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects",
          "points": 9.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 6 of the 8 things a reader expects",
          "points": 8.5,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.stackone.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.stackone.com/terms/saas-terms/",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2026-03-30",
          "words": 6983,
          "points": 9.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: March 30, 2026",
              "says": "Last updated 2026-03-30"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "The Agreement and any disputes or claims arising out of or in connection with it shall be governed by the laws of England and Wales and the parties submit to the exclusive jurisdiction of the courts of England and Wales.",
              "says": "The law of England and Wales"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "EXCEPT AS SET FORTH IN CLAUSE 11.5 (EXCLUDED LIABILITIES), IN NO EVENT SHALL EITHER PARTY OR ITS AFFILIATES (INCLUDING THEIR DIRECTORS, OFFICERS, EMPLOYEES, REPRESENTATIVES, AGENTS, AND SUPPLIERS) BE LIABLE FOR ANY INDIRECT, INCIDENTAL, RELIANCE, SPECIAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES, INCLUDING LOSS OF PROFITS,…",
              "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Either party may terminate this Agreement or any Customer Order for cause with immediate effect and without prejudice to any other rights or remedies to which the parties may be entitled by written notice if the other party: (a) materially breaches this Agreement and fails to cure such breach within thirty (30) days a…"
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "If Customer does not agree to this Agreement, Customer must not access or use the Service."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "Preview Features are provided “as is” without any warranty, indemnity, service level commitment, or support obligation, except as set out in Clause 2.6(b) with respect to Preview Connectors."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "StackOne may anonymise data derived from the customer's use of the service and use it for its own purposes, including developing and improving the service.",
              "quote": "StackOne may use Anonymised Data for its own purposes, including to develop and improve the Service."
            },
            {
              "date": "2026-10-08",
              "text": "Each Customer Order renews automatically for successive one-year periods, or another period the order specifies.",
              "quote": "Each Customer Order shall have the initial term specified therein and shall automatically renew for successive periods of one (1) year, or for any other period specified in a Customer Order (each a “Renewal Term”)"
            },
            {
              "date": "2026-10-08",
              "text": "StackOne may display the customer's name and logo on its website and in marketing materials.",
              "quote": "StackOne may use and display Customer’s name and logo (“Customer Marks”) on its website and in marketing materials to identify Customer as a customer."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.stackone.com/terms/privacy-policy/",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2023-12-01",
          "words": 1468,
          "points": 8.5,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: December 1, 2023",
              "says": "Last updated 2023-12-01"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "We may collect certain information, including personal information, from you as a data controller."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Unless specifically requested by a Customer, StackOne shall retain data no longer than 30 days after a Customer has ceased instructing StackOne.",
              "says": "Names a period of 30 days"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We share data with third-party partners for the purposes of providing the StackOne services, including but not limited to registered users’ email addresses and device information for the purpose of providing better user experience, in compliance with all applicable data protection laws and regulations."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "StackOne acknowledges that you have the right to access your personal information."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have any questions relating to any of this policy then please email us at dpo@stackone.com.",
              "says": "dpo@stackone.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": false
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Data from a closed account enters an expired state and may be retained for up to 90 days.",
              "quote": "Expired account data may be retained for up to 90 days."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/stackone.json",
    "live": {
      "slug": "stackone",
      "probe": {
        "target": "https://mcp.stackone.com/mcp",
        "method": "mcp-initialize",
        "lastAt": "2026-10-10T01:38:08.853279394Z",
        "lastOk": true,
        "lastStatus": 401,
        "lastMs": 477,
        "lastNote": "asks for credentials",
        "authRequired": true,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 104,
        "p95ms24h": 251,
        "samples24h": 102,
        "samples30d": 102,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 85,
            "ok": 85
          },
          {
            "date": "2026-10-10",
            "probes": 17,
            "ok": 17
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.stackone.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-10T01:34:10.416366468Z"
      },
      "versions": [
        {
          "registry": "github",
          "name": "StackOneHQ/stackone-ai-node",
          "version": "v2.10.0",
          "released": "2026-07-27",
          "seenAt": "2026-10-09T17:21:48.091098138Z"
        },
        {
          "registry": "npm",
          "name": "@stackone/ai",
          "version": "2.10.0",
          "seenAt": "2026-10-09T17:21:45.859326927Z"
        },
        {
          "registry": "npm",
          "name": "@stackone/defender",
          "version": "0.8.3",
          "seenAt": "2026-10-09T17:21:46.919917579Z"
        },
        {
          "registry": "pypi",
          "name": "stackone-ai",
          "version": "2.10.1",
          "released": "2026-07-28",
          "seenAt": "2026-10-09T17:21:46.731430671Z"
        }
      ],
      "githubStars": 30,
      "npmWeekly": 277,
      "pypiWeekly": 120,
      "pages": [
        {
          "url": "https://www.stackone.com/changelog/",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-09T18:54:33.415845489Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "a8dc254bb424"
        },
        {
          "url": "https://www.stackone.com/pricing/",
          "kind": "pricing",
          "status": 200,
          "checkedAt": "2026-10-09T18:54:35.567295878Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "98687cfb089f"
        },
        {
          "url": "https://www.stackone.com/terms/privacy-policy/",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-09T18:54:37.551620202Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "011ecd948b67"
        },
        {
          "url": "https://www.stackone.com/terms/saas-terms/",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-09T18:54:39.532884111Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "393a890498df"
        }
      ],
      "mcpTools": {
        "url": "https://mcp.stackone.com/mcp",
        "checkedAt": "2026-10-09T21:40:55.809059913Z",
        "status": "auth",
        "note": "asks for credentials before listing its tools",
        "changedAt": "2026-10-09T21:40:55.809059913Z"
      },
      "updatedAt": "2026-10-10T01:38:08.853279394Z"
    }
  }
}
