Head to head · App automation · October 2026 research run

One vs Smithery

One scores 66.6 (B) on agent readiness against Smithery's 50.7 (D), and leads in every scored category. Both do app automation.

Best agent tool access platforms · All 28 tool access comparisons

Which one, for what

One B

Good for A person or small team that wants one MCP entry with a small tool footprint across many SaaS accounts, with access set per connection and a free plan.

Ahead on

  • Reliability, 82 against 60
  • Agent ergonomics, 73 against 65
  • Security & auth, 69 against 50
  • Payments & pricing, 30 against 10
  • Maintenance & community, 86 against 43
  • Transparency & trust, 63 against 46

Also in its favour

  • Runs on your own machine

Watch for

The remote server's tools changed from four to three by 30 September 2026, and the site's changelog, last dated 13 July 2026, has no entry for it

Smithery D

Good for A developer who wants many MCP servers behind one credential and one endpoint, with per-user connections and short-lived scoped tokens.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

No terms of service are linked from the site, the docs or the footer. The privacy notice of 20 June 2025 is the only legal document found

Score by category

CategoryWeight this runOneSmitheryEdge
Reliability16%208260One +22
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27776One +1
Agent ergonomics13%16.27365One +8
Security & auth14%17.56950One +19
Payments & pricing10%12.53010One +20
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88643One +43
Transparency & trust7%8.86346One +17
Negative events≤15-3-2
Total66.6 · B50.7 · D

Facts side by side

FactOneSmithery
KindMCP serverHTTP API
VendorOne Systems, Inc.Smithery (Arcade.dev)
Hosted endpointhttps://mcp.withone.ai/mcphttps://api.smithery.ai
TransportsStreamable HTTP, stdioHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceProprietary hosted service under One's Terms of Service. The local MCP server package @withone/mcp is MIT. The CLI package @withone/cli has no licence field or licence file. The knowledge base is under the One Knowledge Commons Licence v1.0, which is not an OSI licenceProprietary hosted service, with no terms of service found. The CLI (smithery) is AGPL-3.0, the TypeScript client (@smithery/api) is Apache-2.0 and the credential layer agent.pw is MIT
Tools exposed3none
Read-only variant documentednono
llms.txtyesyes
MCP registryai.withone/mcpnot listed
Last release2026-10-062026-07-20
Terms last updated2026-03-06no document linked
Privacy policy last updated2026-07-222025-06-20
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingyes
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity11 stars, 681 npm/wk840 stars, 2.7k npm/wk

Verdicts

One

One's remote MCP server has three tools, OAuth 2.1 sign-in with PKCE and a consent screen that sets read only, read and write, full or per-action access for each connection. A person must sign in through a browser, the SOC 2 audit is unfinished, and the site's changelog stops at 13 July 2026.

Smithery

Service tokens can be limited by namespace, resource, operation and connection metadata, with a lifetime of at most 24 hours. No terms of service, rate limits or SLA were found, the pricing page could not be read, and the newest client release is from 20 July 2026.

Before you call either

One

  1. Call list_one_integrations first and read each connection's access field. When the policy is actions, run those ids directly without calling find_one_actions
  2. Send every operation a task needs in one find_one_actions call, up to 10 requests, each a platform and a short intent with no IDs, names or message text
  3. When a document comes back as a digest, call find_one_actions again with load and a section name. Don't guess parameters the digest left out
  4. After a timeout on execute_one_action, check whether the write took effect before sending it again. No idempotency key is documented
  5. A 403 for a call outside the grant won't succeed on retry. Ask the user to widen the grant in the dashboard or reconnect

Smithery

  1. Keep the API key on the backend and hand an agent a service token limited to connections with read and execute and a metadata match
  2. Create connections with PUT /connect/{namespace}/{connectionId}, which is an upsert, and check status.state before calling a tool
  3. On auth_required or input_required, send the person to setupUrl, then retry with the same connectionId
  4. Tool names on the namespace MCP endpoint are prefixed with the connection ID, such as user-123-github.search_repositories
  5. Do not rely on smithery skill commands. Version 1.1.1 of the CLI removed them

Questions

Which is better for AI agents, One or Smithery?

One scores 66.6 (B) on agent readiness against Smithery's 50.7 (D), and leads in every scored category.

Do One and Smithery need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call One and Smithery without installing anything?

Yes. One has a hosted endpoint at https://mcp.withone.ai/mcp and Smithery at https://api.smithery.ai.

Other comparisons with One or Smithery

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.