{
  "data": {
    "a": {
      "slug": "one",
      "name": "One",
      "vendor": "One Systems, Inc.",
      "vendorUrl": "https://www.withone.ai",
      "kind": "mcp",
      "category": "aggregator",
      "summary": "One is a hosted MCP server and CLI from One Systems, Inc. (formerly Pica) that lets AI agents find and run actions in a user's connected apps, with credentials held by One and access scoped per connection.",
      "url": "https://www.anchorterminal.com/tools/one",
      "markdownUrl": "https://www.anchorterminal.com/tools/one.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/one.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/one.json",
      "repo": "https://github.com/withoneai/mcp",
      "license": "Proprietary hosted service under One's Terms of Service. The local MCP server package `@withone/mcp` is MIT. The CLI package `@withone/cli` has no licence field or licence file. The knowledge base is under the One Knowledge Commons Licence v1.0, which is not an OSI licence",
      "transports": [
        "streamable-http",
        "stdio"
      ],
      "remoteUrl": "https://mcp.withone.ai/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@withone/mcp"
        },
        {
          "registry": "npm",
          "name": "@withone/cli"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. The remote server uses OAuth 2.1 authorisation code with PKCE (S256). The client registers itself at `https://mcp.withone.ai/oauth/register` as a public client, a person signs in to One in a browser, and the consent screen picks the account, Production or Sandbox, and an access level per connection. Scopes are `connections:read` and `connections:write` under `user:`, `org:` and `project:`, and a client that asks for none gets all six. Access tokens last one hour, with a 30-day refresh token when the client registers that grant. The local package and the REST API take an API key in the `x-one-secret` header, and a key created through the CLI's browser sign-in carries the same per-connection limits. Third-party accounts are connected in the dashboard or with `one add \u003cplatform\u003e`, and One stores those credentials.",
      "pricing": "freemium",
      "pricingNotes": "Free is $0 with 1M requests a month, 20 requests a minute, one organisation and one project. Starter is $29 a month at 100 requests a minute and Pro is $199 a month at 500, each with 1M requests a month. Enterprise is priced on contract. Requests over the limit answer 429 and there is no overage charge. A cloud agent on a dedicated server is $40 a month on any plan. The pricing page doesn't say whether sign-up needs a card. The API authentication page says both environments include unlimited API calls, which doesn't match the 1M a month on the pricing page (https://www.withone.ai/pricing, checked 2026-10-09).",
      "priceSummary": "$29 / mo",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in llms.txt, the MCP docs, the pricing page or the OpenAPI file. The API's 402 responses are described as a plan quota, not a payment protocol (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": 3,
      "popularity": {
        "githubStars": 11,
        "npmWeekly": 681,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://www.withone.ai/docs/mcp",
      "llmsTxt": "https://www.withone.ai/llms.txt",
      "openapi": "https://www.withone.ai/openapi.json",
      "registryName": "ai.withone/mcp",
      "capabilities": [
        "automation.apps",
        "automation.auth",
        "automation.actions",
        "agent.tools",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "mcp",
        "freemium",
        "free-tier",
        "oauth",
        "openapi",
        "llms-txt",
        "cli",
        "typescript",
        "status-page",
        "mcp-registry"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 66.6,
        "grade": "B",
        "agentReady": false,
        "rank": 282,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 86,
          "payments": 30,
          "reliability": 82,
          "schema": 77,
          "security": 69,
          "transparency": 63
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -3,
        "negativeNotes": [
          "Between 13 July and 30 September 2026 the remote MCP server's tools changed from four to three. The changelog entry of 13 July 2026 says the remote server has the same four tools as the local one, and the local package's 2.0.0 commit of 30 September 2026 removes `search_one_platform_actions` and `get_one_action_knowledge` for `find_one_actions`, which it calls the tool the remote server already serves. The site's changelog has no entry for the change. The local package marked it as a major version. Three points off (https://www.withone.ai/changelog, https://github.com/withoneai/mcp)."
        ],
        "verdict": "One's remote MCP server has three tools, OAuth 2.1 sign-in with PKCE and a consent screen that sets read only, read and write, full or per-action access for each connection. A person must sign in through a browser, the SOC 2 audit is unfinished, and the site's changelog stops at 13 July 2026.",
        "bestFor": "A person or small team that wants one MCP entry with a small tool footprint across many SaaS accounts, with access set per connection and a free plan.",
        "strengths": [
          "The remote server has three tools whatever the number of connections, and `find_one_actions` returns large documents as a digest with sections loaded on request",
          "The consent screen sets Full access, Read \u0026 write, Read only or a ticked list of actions per connection, and One enforces the grant on every call",
          "Access tokens last one hour, and changing or revoking a grant in the dashboard applies on the agent's next call",
          "Every plan, Free included, lists the same platforms and controls. Plans differ by requests per minute (20, 100, 500), organisations and projects, with no overage charge",
          "The server is in the official MCP registry as `ai.withone/mcp`, and the CLI had 14 npm releases between 25 August and 6 October 2026"
        ],
        "weaknesses": [
          "The remote server's tools changed from four to three by 30 September 2026, and the site's changelog, last dated 13 July 2026, has no entry for it",
          "The home and security pages say nothing from a call is stored. The privacy policy says request logs may include integration payloads, kept 14 to 90 days by default",
          "The SOC 2 audit is described as in progress, `/.well-known/security.txt` returned 404, and no bug bounty or published advisories were found",
          "`execute_one_action` takes a free-form `data` body and returns the upstream response whole. No control on response size was found",
          "The Data Processing Agreement is available only on request, and no deprecation policy was found"
        ],
        "agentNotes": [
          "Call `list_one_integrations` first and read each connection's `access` field. When the policy is `actions`, run those ids directly without calling `find_one_actions`",
          "Send every operation a task needs in one `find_one_actions` call, up to 10 `requests`, each a platform and a short intent with no IDs, names or message text",
          "When a document comes back as a digest, call `find_one_actions` again with `load` and a `section` name. Don't guess parameters the digest left out",
          "After a timeout on `execute_one_action`, check whether the write took effect before sending it again. No idempotency key is documented",
          "A 403 for a call outside the grant won't succeed on retry. Ask the user to widen the grant in the dashboard or reconnect"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 66.6
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 86,
          "payments": 30,
          "reliability": 82,
          "schema": 77,
          "security": 69,
          "transparency": 54
        },
        "provenanceScore": 72
      },
      "connect": {
        "install": "npm install -g @withone/cli \u0026\u0026 one init",
        "claudeCode": "claude mcp add --transport http one https://mcp.withone.ai/mcp",
        "config": {
          "mcpServers": {
            "one": {
              "type": "http",
              "url": "https://mcp.withone.ai/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/automation.apps",
        "tool": "https://letme.dev/one"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Starter plan",
          "unit": "month",
          "usd": 29,
          "note": "1M requests a month, 100 requests a minute, 20 organisations and 20 projects"
        },
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 199,
          "note": "1M requests a month, 500 requests a minute, 100 organisations and 100 projects"
        },
        {
          "item": "Cloud agent on a dedicated server",
          "unit": "month",
          "usd": 40,
          "note": "Per agent, added to any plan"
        }
      ],
      "provenance": {
        "legalEntity": "One Systems, Inc.",
        "domain": "withone.ai",
        "domainRegistered": "2026-01-22",
        "endpointOnVendorDomain": true,
        "terms": "https://www.withone.ai/terms",
        "privacy": "https://www.withone.ai/privacy",
        "statusPage": "https://status.withone.ai",
        "changelog": "https://www.withone.ai/changelog",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The Terms of Service, last updated 6 March 2026, name One Systems, Inc. of San Francisco and cover the website, platform, APIs and SDKs under California law. No state of incorporation is given.",
          "The privacy policy, last updated 22 July 2026, governs account and usage data. For data passing through connected apps it points to a Data Processing Agreement that is available on request and not published.",
          "RDAP gives a registration date of 2026-01-22 for withone.ai. The product traded as Pica on picaos.com before 25 March 2026.",
          "www.withone.ai/.well-known/security.txt returned 404. The security page gives security@withone.ai for disclosure.",
          "status.withone.ai is a Better Stack page created in March 2025. We did not find a link to it on the vendor pages we read.",
          "The MCP server answers at mcp.withone.ai and the REST API at api.withone.ai."
        ],
        "score": 72
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/one.json",
      "live": {
        "slug": "one",
        "probe": {
          "target": "https://mcp.withone.ai/mcp",
          "method": "mcp-initialize",
          "lastAt": "2026-10-10T02:07:18.567299148Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 186,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 171,
          "p95ms24h": 260,
          "samples24h": 107,
          "samples30d": 107,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 85,
              "ok": 85
            },
            {
              "date": "2026-10-10",
              "probes": 22,
              "ok": 22
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.withone.ai",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-10T00:50:54.124632614Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "withoneai/mcp",
            "version": "2.0.0",
            "released": "2026-09-30",
            "seenAt": "2026-10-09T17:09:32.922283746Z"
          },
          {
            "registry": "npm",
            "name": "@withone/cli",
            "version": "2.6.0",
            "seenAt": "2026-10-09T17:09:31.577452422Z"
          },
          {
            "registry": "npm",
            "name": "@withone/mcp",
            "version": "2.0.0",
            "seenAt": "2026-10-09T17:09:30.715852547Z"
          }
        ],
        "githubStars": 11,
        "npmWeekly": 681,
        "pages": [
          {
            "url": "https://www.withone.ai/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:55:40.085470155Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "7efc2d05b2eb"
          },
          {
            "url": "https://www.withone.ai/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:55:42.392440467Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "991db7361edb"
          },
          {
            "url": "https://www.withone.ai/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:55:44.31680918Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "cf8afffd8c96"
          },
          {
            "url": "https://www.withone.ai/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:55:46.353715719Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6ed34b101d9b"
          }
        ],
        "mcpTools": {
          "url": "https://mcp.withone.ai/mcp",
          "checkedAt": "2026-10-09T21:40:46.685955698Z",
          "status": "auth",
          "note": "asks for credentials before listing its tools",
          "changedAt": "2026-10-09T21:40:46.685955698Z"
        },
        "updatedAt": "2026-10-10T02:07:18.567299148Z"
      }
    },
    "answer": "StackOne scores 69.1 (B) on agent readiness against One's 66.6 (B), and leads in 4 of 7 scored categories.",
    "b": {
      "slug": "stackone",
      "name": "StackOne",
      "vendor": "StackOne Technologies Limited",
      "vendorUrl": "https://www.stackone.com",
      "kind": "mcp",
      "category": "aggregator",
      "summary": "StackOne is a hosted gateway from StackOne Technologies Limited that gives AI agents actions across more than 540 business apps over MCP, SDKs, A2A or HTTP, with managed authentication, per-user grants, policies and logs.",
      "url": "https://www.anchorterminal.com/tools/stackone",
      "markdownUrl": "https://www.anchorterminal.com/tools/stackone.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/stackone.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/stackone.json",
      "repo": "https://github.com/StackOneHQ/stackone-ai-node",
      "license": "Proprietary service under StackOne's SaaS Terms and Conditions. The Agent SDKs (`@stackone/ai`, `stackone-ai`) and the Defender package (`@stackone/defender`) are Apache-2.0",
      "transports": [
        "streamable-http",
        "http"
      ],
      "remoteUrl": "https://mcp.stackone.com/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@stackone/ai"
        },
        {
          "registry": "pypi",
          "name": "stackone-ai"
        },
        {
          "registry": "npm",
          "name": "@stackone/defender"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. A person signs up in the dashboard, creates a project and a connector profile, and links an account. MCP clients connect to `https://mcp.stackone.com/mcp` with OAuth (scopes `mcp offline_access`, one-hour access tokens, a 90-day grant) and the user picks the linked accounts and actions at consent. Most clients register themselves, and a few need a client ID and secret created in the dashboard. Backend calls go to `https://api.stackone.com/mcp` or `POST /actions/rpc` with a project API key as the Basic auth username and the linked account in `x-account-id`. Keys take scopes (Platform API, Actions, Connectors, Credentials, Unified API) and can be disabled or deleted. Session token URLs (`https://api.stackone.com/mcp?token=...`) cover one linked account, carry the access in the URL and expire after one year by default.",
      "pricing": "freemium",
      "pricingNotes": "Free to start with no card, per the pricing page. Gateway Starter is free with 1,000 credits a seat a month, one credit per tool call or API call, and extra credits at $60 per 20,000. Gateway Team is $600 a month ($6,000 a year) with 5,000 credits a seat a month and extra credits at $20 per 20,000. The pricing calculator's markup gives 10 seats included on Team and $15 a further seat, which the page text doesn't state. OEM Core is free with a monthly credit allowance and volume prices on request. Enterprise plans are priced on contract. Browser use, premium defence and data sync cost more than one credit, at rates not published. The Service Consumption Schedule of 30 March 2026 gives $0.003 per Action Call as overage and counts unsuccessful requests, while the pricing page says background and failed calls aren't billed (https://www.stackone.com/pricing/, checked 2026-10-09).",
      "priceSummary": "$600 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the pricing page, the SaaS terms or the Service Consumption Schedule (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 30,
        "npmWeekly": 277,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.stackone.com/introduction",
      "llmsTxt": "https://docs.stackone.com/llms.txt",
      "openapi": "https://api.eu1.stackone.com/v2/oas/stackone.json",
      "registryName": "com.stackone/mcp",
      "capabilities": [
        "automation.apps",
        "automation.auth",
        "automation.actions",
        "agent.tools",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "mcp",
        "a2a",
        "freemium",
        "free-tier",
        "no-card",
        "oauth",
        "api-key",
        "openapi",
        "llms-txt",
        "typescript",
        "python",
        "enterprise",
        "status-page",
        "soc2",
        "mcp-registry",
        "closed-source"
      ],
      "lastRelease": "2026-09-24",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.1,
        "grade": "B",
        "agentReady": false,
        "rank": 198,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 75,
          "maintenance": 84,
          "payments": 38,
          "reliability": 80,
          "schema": 78,
          "security": 69,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -2,
        "negativeNotes": [
          "27 April 2026. `@stackone/ai` v2.8.1 fixed a flaw in which tools fetched concurrently for several accounts were stamped with the wrong `x-account-id`, so a call could run against another linked account. It is recorded as a bug fix in the changelog, with no advisory found. Fixed and documented, so 2 points (https://github.com/StackOneHQ/stackone-ai-node/blob/main/CHANGELOG.md)."
        ],
        "verdict": "StackOne's MCP server signs each person in with OAuth, lets them grant individual accounts and actions, and by default exposes two search and execute tools in place of the full catalogue. Session token URLs carry the credential in the query string for a year by default, and the Consumption Schedule and pricing page disagree on whether failed calls are billed.",
        "bestFor": "A company that wants one governed MCP endpoint for staff agents across business systems, and product teams embedding per-customer connections with HR, recruiting and CRM coverage.",
        "strengths": [
          "The MCP server at `https://mcp.stackone.com/mcp` uses OAuth per person. Access tokens last one hour, a grant lasts 90 days, and each user can revoke it under Connected Apps",
          "Advanced Tool Search replaces the tool list with two tools, search and execute, and is on by default at the OAuth consent screen",
          "Since 24 July 2026 every tool carries `readOnlyHint`, `destructiveHint` and `openWorldHint`, derived from an effects value on each action",
          "API keys are limited to one project and take scopes for the Platform API, Actions, Connectors, Credentials and the Unified API. Credentials access is off by default",
          "Rate limit published at 1,000 requests a minute per API key, with `Retry-After` in seconds on 429 and 408 responses",
          "Defender scans tool results for prompt injection and is on for new projects. Its Light Scan engine is open source under Apache-2.0"
        ],
        "weaknesses": [
          "Session token URLs (`https://api.stackone.com/mcp?token=...`) put the credential in the query string, cover one linked account and expire after one year by default",
          "The Service Consumption Schedule counts every request, successful or not, as an Action Call. The pricing page says failed calls aren't billed",
          "Defender's default mode is Monitor, which records a verdict and passes the tool result to the agent unchanged",
          "Policies apply only to signed-in members. A call made with a project API key is memberless and is governed by connector profile scoping alone",
          "The Logs API, audit logs, SIEM export and an uptime SLA are Enterprise only on Gateway plans, and Starter keeps action logs for one day",
          "The Acceptable Use Policy bars competitive analysis or benchmarking other than for internal comparison, and probing or testing the Service's vulnerability without authorisation. This matters before any probe is run",
          "`@stackone/ai` stamped tools with the wrong `x-account-id` when accounts were fetched concurrently, until v2.8.1 on 27 April 2026. No advisory was found"
        ],
        "agentNotes": [
          "Send `Accept: application/json,text/event-stream` on every MCP request to `https://api.stackone.com/mcp`, by POST only. Without it the server answers 406",
          "In `search_execute` mode call `{provider}_search_actions` first and pass the returned `action_id` to `{provider}_execute_action`. Never hardcode action ids",
          "Pass the API key as the Basic auth username with an empty password, and name the linked account in `x-account-id`",
          "On 429 or 408 wait the seconds given in `Retry-After`. StackOne has already retried a provider's 429 up to five times within a 60-second request lifetime",
          "On 412 read `errorCode` and `details.statusReasons`. `AccountErrorStatus` needs a person to re-authenticate the linked account"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.1
          }
        ],
        "editorialScores": {
          "ergonomics": 75,
          "maintenance": 84,
          "payments": 38,
          "reliability": 80,
          "schema": 78,
          "security": 69,
          "transparency": 50
        },
        "provenanceScore": 88
      },
      "connect": {
        "install": "npm install @stackone/ai",
        "http": "curl -X POST \"https://api.stackone.com/actions/rpc\" \\\n  -u \"$STACKONE_API_KEY:\" \\\n  -H \"x-account-id: your-account-id\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"action\": \"bamboohr_list_employees\", \"query\": {\"page_size\": 25}}'",
        "claudeCode": "claude mcp add --transport http --scope user stackone https://mcp.stackone.com/mcp"
      },
      "letme": {
        "capability": "https://letme.dev/automation.apps",
        "tool": "https://letme.dev/stackone"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Gateway Team plan",
          "unit": "month",
          "usd": 600,
          "note": "5,000 credits a seat a month, one credit per tool call or API call. $6,000 billed yearly"
        },
        {
          "item": "Extra credits, Gateway Starter",
          "unit": "1k-calls",
          "usd": 3,
          "note": "$60 per 20,000 credits, valid 12 months. Advanced capabilities cost more than one credit a call"
        },
        {
          "item": "Extra credits, Gateway Team",
          "unit": "1k-calls",
          "usd": 1,
          "note": "$20 per 20,000 credits, valid 12 months"
        }
      ],
      "provenance": {
        "legalEntity": "StackOne Technologies Limited",
        "domain": "stackone.com",
        "domainRegistered": "2013-06-25",
        "endpointOnVendorDomain": true,
        "terms": "https://www.stackone.com/terms/saas-terms/",
        "privacy": "https://www.stackone.com/terms/privacy-policy/",
        "statusPage": "https://status.stackone.com",
        "changelog": "https://www.stackone.com/changelog/",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The SaaS Terms and Conditions, effective 30 March 2026, name StackOne Technologies Limited, company number 14684360, registered at 2 Communications Road, Newbury, Berkshire, RG19 6AB, under the laws of England and Wales. They take effect when a customer first accesses the Service or signs an order.",
          "The contact page says StackOne operates in the United States as StackOne Technologies Inc., 2261 Market Street, San Francisco.",
          "The Platform Privacy Policy, last updated 1 December 2023, covers the web application and API and says it does not cover the website. A separate Privacy Notice covers the website.",
          "The MCP server answers at mcp.stackone.com, the API at api.stackone.com and A2A at a2a.stackone.com.",
          "www.stackone.com/.well-known/security.txt returned 404.",
          "RDAP for stackone.com gives a registration date of 2013-06-25. The company was incorporated later, per its company number.",
          "status.stackone.com runs on incident.io and lists the Web Dashboard, the API (US, EU and UK) and the Connectors Hub.",
          "trust.stackone.com, which the terms cite for the security policy and the sub-processor list, answered our reader with a bot check and was not read."
        ],
        "score": 88
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/stackone.json",
      "live": {
        "slug": "stackone",
        "probe": {
          "target": "https://mcp.stackone.com/mcp",
          "method": "mcp-initialize",
          "lastAt": "2026-10-10T02:07:26.369561075Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 377,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 112,
          "p95ms24h": 295,
          "samples24h": 107,
          "samples30d": 107,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 85,
              "ok": 85
            },
            {
              "date": "2026-10-10",
              "probes": 22,
              "ok": 22
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.stackone.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-10T02:06:29.204045169Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "StackOneHQ/stackone-ai-node",
            "version": "v2.10.0",
            "released": "2026-07-27",
            "seenAt": "2026-10-09T17:21:48.091098138Z"
          },
          {
            "registry": "npm",
            "name": "@stackone/ai",
            "version": "2.10.0",
            "seenAt": "2026-10-09T17:21:45.859326927Z"
          },
          {
            "registry": "npm",
            "name": "@stackone/defender",
            "version": "0.8.3",
            "seenAt": "2026-10-09T17:21:46.919917579Z"
          },
          {
            "registry": "pypi",
            "name": "stackone-ai",
            "version": "2.10.1",
            "released": "2026-07-28",
            "seenAt": "2026-10-09T17:21:46.731430671Z"
          }
        ],
        "githubStars": 30,
        "npmWeekly": 277,
        "pypiWeekly": 120,
        "pages": [
          {
            "url": "https://www.stackone.com/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:54:33.415845489Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a8dc254bb424"
          },
          {
            "url": "https://www.stackone.com/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:54:35.567295878Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "98687cfb089f"
          },
          {
            "url": "https://www.stackone.com/terms/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:54:37.551620202Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "011ecd948b67"
          },
          {
            "url": "https://www.stackone.com/terms/saas-terms/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:54:39.532884111Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "393a890498df"
          }
        ],
        "mcpTools": {
          "url": "https://mcp.stackone.com/mcp",
          "checkedAt": "2026-10-09T21:40:55.809059913Z",
          "status": "auth",
          "note": "asks for credentials before listing its tools",
          "changedAt": "2026-10-09T21:40:55.809059913Z"
        },
        "updatedAt": "2026-10-10T02:07:26.369561075Z"
      }
    },
    "facts": [
      {
        "a": "MCP server",
        "b": "MCP server",
        "name": "Kind"
      },
      {
        "a": "One Systems, Inc.",
        "b": "StackOne Technologies Limited",
        "name": "Vendor"
      },
      {
        "a": "https://mcp.withone.ai/mcp",
        "b": "https://mcp.stackone.com/mcp",
        "name": "Hosted endpoint"
      },
      {
        "a": "Streamable HTTP, stdio",
        "b": "Streamable HTTP, HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary hosted service under One's Terms of Service. The local MCP server package `@withone/mcp` is MIT. The CLI package `@withone/cli` has no licence field or licence file. The knowledge base is under the One Knowledge Commons Licence v1.0, which is not an OSI licence",
        "b": "Proprietary service under StackOne's SaaS Terms and Conditions. The Agent SDKs (`@stackone/ai`, `stackone-ai`) and the Defender package (`@stackone/defender`) are Apache-2.0",
        "name": "Licence"
      },
      {
        "a": "3",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "ai.withone/mcp",
        "b": "com.stackone/mcp",
        "name": "MCP registry"
      },
      {
        "a": "2026-10-06",
        "b": "2026-09-24",
        "name": "Last release"
      },
      {
        "a": "2026-03-06",
        "b": "2026-03-30",
        "name": "Terms last updated"
      },
      {
        "a": "2026-07-22",
        "b": "2023-12-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "11 stars, 681 npm/wk",
        "b": "30 stars, 277 npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "StackOne scores 69.1 (B) on agent readiness against One's 66.6 (B), and leads in 4 of 7 scored categories.",
        "question": "Which is better for AI agents, One or StackOne?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do One and StackOne need an API key?"
      },
      {
        "answer": "Yes. One has a hosted endpoint at https://mcp.withone.ai/mcp and StackOne at https://mcp.stackone.com/mcp.",
        "question": "Can an agent call One and StackOne without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": null,
        "also": [
          "Runs on your own machine"
        ],
        "goodFor": "A person or small team that wants one MCP entry with a small tool footprint across many SaaS accounts, with access set per connection and a free plan.",
        "slug": "one",
        "watchFor": "The remote server's tools changed from four to three by 30 September 2026, and the site's changelog, last dated 13 July 2026, has no entry for it"
      },
      {
        "aheadOn": [
          "Payments \u0026 pricing, 38 against 30",
          "Transparency \u0026 trust, 69 against 63"
        ],
        "also": [
          "Free to start without a card"
        ],
        "goodFor": "A company that wants one governed MCP endpoint for staff agents across business systems, and product teams embedding per-customer connections with HR, recruiting and CRM coverage.",
        "slug": "stackone",
        "watchFor": "Session token URLs (`https://api.stackone.com/mcp?token=...`) put the credential in the query string, cover one linked account and expire after one year by default"
      }
    ],
    "job": {
      "capability": "automation.apps",
      "name": "App automation"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/composio-rube-vs-one.json",
        "title": "Composio (API + MCP) vs One",
        "url": "https://www.anchorterminal.com/compare/composio-rube-vs-one"
      },
      {
        "json": "https://www.anchorterminal.com/compare/composio-rube-vs-stackone.json",
        "title": "Composio (API + MCP) vs StackOne",
        "url": "https://www.anchorterminal.com/compare/composio-rube-vs-stackone"
      },
      {
        "json": "https://www.anchorterminal.com/compare/merge-agent-handler-vs-one.json",
        "title": "Merge Agent Handler vs One",
        "url": "https://www.anchorterminal.com/compare/merge-agent-handler-vs-one"
      },
      {
        "json": "https://www.anchorterminal.com/compare/merge-agent-handler-vs-stackone.json",
        "title": "Merge Agent Handler vs StackOne",
        "url": "https://www.anchorterminal.com/compare/merge-agent-handler-vs-stackone"
      },
      {
        "json": "https://www.anchorterminal.com/compare/one-vs-smithery.json",
        "title": "One vs Smithery",
        "url": "https://www.anchorterminal.com/compare/one-vs-smithery"
      },
      {
        "json": "https://www.anchorterminal.com/compare/one-vs-unified-to-mcp.json",
        "title": "One vs Unified.to MCP Server",
        "url": "https://www.anchorterminal.com/compare/one-vs-unified-to-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/one-vs-zapier-mcp.json",
        "title": "One vs Zapier MCP (agent actions)",
        "url": "https://www.anchorterminal.com/compare/one-vs-zapier-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/smithery-vs-stackone.json",
        "title": "Smithery vs StackOne",
        "url": "https://www.anchorterminal.com/compare/smithery-vs-stackone"
      },
      {
        "json": "https://www.anchorterminal.com/compare/stackone-vs-unified-to-mcp.json",
        "title": "StackOne vs Unified.to MCP Server",
        "url": "https://www.anchorterminal.com/compare/stackone-vs-unified-to-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/stackone-vs-zapier-mcp.json",
        "title": "StackOne vs Zapier MCP (agent actions)",
        "url": "https://www.anchorterminal.com/compare/stackone-vs-zapier-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/letme-vs-one.json",
        "title": "letme vs One",
        "url": "https://www.anchorterminal.com/compare/letme-vs-one"
      },
      {
        "json": "https://www.anchorterminal.com/compare/letme-vs-stackone.json",
        "title": "letme vs StackOne",
        "url": "https://www.anchorterminal.com/compare/letme-vs-stackone"
      }
    ],
    "scores": [
      {
        "by": 2,
        "edge": "one",
        "key": "reliability",
        "name": "Reliability",
        "one": 82,
        "stackone": 80,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 1,
        "edge": "stackone",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "one": 77,
        "stackone": 78,
        "weight": 13
      },
      {
        "by": 2,
        "edge": "stackone",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "one": 73,
        "stackone": 75,
        "weight": 13
      },
      {
        "by": 0,
        "edge": "",
        "key": "security",
        "name": "Security \u0026 auth",
        "one": 69,
        "stackone": 69,
        "weight": 14
      },
      {
        "by": 8,
        "edge": "stackone",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "one": 30,
        "stackone": 38,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 2,
        "edge": "one",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "one": 86,
        "stackone": 84,
        "weight": 7
      },
      {
        "by": 6,
        "edge": "stackone",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "one": 63,
        "stackone": 69,
        "weight": 7
      }
    ],
    "summary": "StackOne scores 69.1 (B) on agent readiness against One's 66.6 (B), and leads in 4 of 7 scored categories. Both do app automation.",
    "verdicts": {
      "one": "One's remote MCP server has three tools, OAuth 2.1 sign-in with PKCE and a consent screen that sets read only, read and write, full or per-action access for each connection. A person must sign in through a browser, the SOC 2 audit is unfinished, and the site's changelog stops at 13 July 2026.",
      "stackone": "StackOne's MCP server signs each person in with OAuth, lets them grant individual accounts and actions, and by default exposes two search and execute tools in place of the full catalogue. Session token URLs carry the credential in the query string for a year by default, and the Consumption Schedule and pricing page disagree on whether failed calls are billed."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/one-vs-stackone",
    "json": "https://www.anchorterminal.com/compare/one-vs-stackone.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/one-vs-stackone.md",
    "slim": "https://www.anchorterminal.com/compare/one-vs-stackone.min.md"
  },
  "markdown": "StackOne scores 69.1 (B) on agent readiness against One's 66.6 (B), and leads in 4 of 7 scored categories. Both do app automation.\n\n- One: grade B, 66.6/100, rank #282 of 950. Markdown https://www.anchorterminal.com/tools/one.md · JSON https://www.anchorterminal.com/api/v1/tools/one.json\n- StackOne: grade B, 69.1/100, rank #198 of 950. Markdown https://www.anchorterminal.com/tools/stackone.md · JSON https://www.anchorterminal.com/api/v1/tools/stackone.json\n- Best agent tool access platforms: https://www.anchorterminal.com/best/aggregator/index.md\n- All 28 tool access comparisons: https://www.anchorterminal.com/compare/aggregator/index.md\n\n## Which one, for what\n\n### One (B)\n\nGood for: A person or small team that wants one MCP entry with a small tool footprint across many SaaS accounts, with access set per connection and a free plan.\n\nAlso in its favour:\n- Runs on your own machine\n\nWatch for: The remote server's tools changed from four to three by 30 September 2026, and the site's changelog, last dated 13 July 2026, has no entry for it\n\n### StackOne (B)\n\nGood for: A company that wants one governed MCP endpoint for staff agents across business systems, and product teams embedding per-customer connections with HR, recruiting and CRM coverage.\n\nAhead on:\n- Payments \u0026 pricing, 38 against 30\n- Transparency \u0026 trust, 69 against 63\n\nAlso in its favour:\n- Free to start without a card\n\nWatch for: Session token URLs (`https://api.stackone.com/mcp?token=...`) put the credential in the query string, cover one linked account and expire after one year by default\n\n\n## Score by category\n\n| Category | Weight | One | StackOne | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 82 | 80 | One +2 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 77 | 78 | StackOne +1 |\n| Agent ergonomics | 13% (16.2 this run) | 73 | 75 | StackOne +2 |\n| Security \u0026 auth | 14% (17.5 this run) | 69 | 69 | even |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 38 | StackOne +8 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 86 | 84 | One +2 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 63 | 69 | StackOne +6 |\n| Negative events | ≤15 | -3 | -2 | |\n| **Total** | | **66.6 · B** | **69.1 · B** | |\n\n## Facts side by side\n\n| Fact | One | StackOne |\n| --- | --- | --- |\n| Kind | MCP server | MCP server |\n| Vendor | One Systems, Inc. | StackOne Technologies Limited |\n| Hosted endpoint | `https://mcp.withone.ai/mcp` | `https://mcp.stackone.com/mcp` |\n| Transports | Streamable HTTP, stdio | Streamable HTTP, HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary hosted service under One's Terms of Service. The local MCP server package `@withone/mcp` is MIT. The CLI package `@withone/cli` has no licence field or licence file. The knowledge base is under the One Knowledge Commons Licence v1.0, which is not an OSI licence | Proprietary service under StackOne's SaaS Terms and Conditions. The Agent SDKs (`@stackone/ai`, `stackone-ai`) and the Defender package (`@stackone/defender`) are Apache-2.0 |\n| Tools exposed | 3 | none |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | `ai.withone/mcp` | `com.stackone/mcp` |\n| Last release | 2026-10-06 | 2026-09-24 |\n| Terms last updated | 2026-03-06 | 2026-03-30 |\n| Privacy policy last updated | 2026-07-22 | 2023-12-01 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n| Popularity | 11 stars, 681 npm/wk | 30 stars, 277 npm/wk |\n\n## Verdicts\n\n**One.** One's remote MCP server has three tools, OAuth 2.1 sign-in with PKCE and a consent screen that sets read only, read and write, full or per-action access for each connection. A person must sign in through a browser, the SOC 2 audit is unfinished, and the site's changelog stops at 13 July 2026.\n\n**StackOne.** StackOne's MCP server signs each person in with OAuth, lets them grant individual accounts and actions, and by default exposes two search and execute tools in place of the full catalogue. Session token URLs carry the credential in the query string for a year by default, and the Consumption Schedule and pricing page disagree on whether failed calls are billed.\n\n## Before you call either\n\n### One\n\n1. Call `list_one_integrations` first and read each connection's `access` field. When the policy is `actions`, run those ids directly without calling `find_one_actions`\n2. Send every operation a task needs in one `find_one_actions` call, up to 10 `requests`, each a platform and a short intent with no IDs, names or message text\n3. When a document comes back as a digest, call `find_one_actions` again with `load` and a `section` name. Don't guess parameters the digest left out\n4. After a timeout on `execute_one_action`, check whether the write took effect before sending it again. No idempotency key is documented\n5. A 403 for a call outside the grant won't succeed on retry. Ask the user to widen the grant in the dashboard or reconnect\n\n### StackOne\n\n1. Send `Accept: application/json,text/event-stream` on every MCP request to `https://api.stackone.com/mcp`, by POST only. Without it the server answers 406\n2. In `search_execute` mode call `{provider}_search_actions` first and pass the returned `action_id` to `{provider}_execute_action`. Never hardcode action ids\n3. Pass the API key as the Basic auth username with an empty password, and name the linked account in `x-account-id`\n4. On 429 or 408 wait the seconds given in `Retry-After`. StackOne has already retried a provider's 429 up to five times within a 60-second request lifetime\n5. On 412 read `errorCode` and `details.statusReasons`. `AccountErrorStatus` needs a person to re-authenticate the linked account\n\n## Questions\n\n### Which is better for AI agents, One or StackOne?\n\nStackOne scores 69.1 (B) on agent readiness against One's 66.6 (B), and leads in 4 of 7 scored categories.\n\n### Do One and StackOne need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call One and StackOne without installing anything?\n\nYes. One has a hosted endpoint at https://mcp.withone.ai/mcp and StackOne at https://mcp.stackone.com/mcp.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/one-vs-stackone.json, and with the fewest tokens: https://www.anchorterminal.com/compare/one-vs-stackone.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"one\", \"b\": \"stackone\"}`. From a terminal: `anchor compare one stackone`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/one.json and https://www.anchorterminal.com/api/v1/tools/stackone.json\n\n## Other comparisons with One or StackOne\n\n- [Composio (API + MCP) vs One](https://www.anchorterminal.com/compare/composio-rube-vs-one.md)\n- [Composio (API + MCP) vs StackOne](https://www.anchorterminal.com/compare/composio-rube-vs-stackone.md)\n- [Merge Agent Handler vs One](https://www.anchorterminal.com/compare/merge-agent-handler-vs-one.md)\n- [Merge Agent Handler vs StackOne](https://www.anchorterminal.com/compare/merge-agent-handler-vs-stackone.md)\n- [One vs Smithery](https://www.anchorterminal.com/compare/one-vs-smithery.md)\n- [One vs Unified.to MCP Server](https://www.anchorterminal.com/compare/one-vs-unified-to-mcp.md)\n- [One vs Zapier MCP (agent actions)](https://www.anchorterminal.com/compare/one-vs-zapier-mcp.md)\n- [Smithery vs StackOne](https://www.anchorterminal.com/compare/smithery-vs-stackone.md)\n- [StackOne vs Unified.to MCP Server](https://www.anchorterminal.com/compare/stackone-vs-unified-to-mcp.md)\n- [StackOne vs Zapier MCP (agent actions)](https://www.anchorterminal.com/compare/stackone-vs-zapier-mcp.md)\n- [letme vs One](https://www.anchorterminal.com/compare/letme-vs-one.md)\n- [letme vs StackOne](https://www.anchorterminal.com/compare/letme-vs-stackone.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "One vs StackOne",
        "url": ""
      }
    ],
    "description": "StackOne scores 69.1 (B) to One's 66.6 (B) for app automation. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "One B 66.6",
      "StackOne B 69.1",
      "scores"
    ],
    "h1": "One vs StackOne",
    "image": "https://www.anchorterminal.com/assets/og/compare-one-vs-stackone.png",
    "path": "/compare/one-vs-stackone",
    "published": "2026-10-01",
    "section": "tools",
    "title": "One vs StackOne for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/one-vs-stackone"
  },
  "tokens": {
    "markdown": 2250,
    "slim": 680
  },
  "version": 1
}
