Head to head · App automation · October 2026 research run

Smithery vs StackOne

StackOne scores 69.1 (B) on agent readiness against Smithery's 50.7 (D), and leads in every scored category. Both do app automation.

Best agent tool access platforms · All 28 tool access comparisons

Which one, for what

Smithery D

Good for A developer who wants many MCP servers behind one credential and one endpoint, with per-user connections and short-lived scoped tokens.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

No terms of service are linked from the site, the docs or the footer. The privacy notice of 20 June 2025 is the only legal document found

StackOne B

Good for A company that wants one governed MCP endpoint for staff agents across business systems, and product teams embedding per-customer connections with HR, recruiting and CRM coverage.

Ahead on

  • Reliability, 80 against 60
  • Agent ergonomics, 75 against 65
  • Security & auth, 69 against 50
  • Payments & pricing, 38 against 10
  • Maintenance & community, 84 against 43
  • Transparency & trust, 69 against 46

Also in its favour

  • Free to start without a card

Watch for

Session token URLs (https://api.stackone.com/mcp?token=...) put the credential in the query string, cover one linked account and expire after one year by default

Score by category

CategoryWeight this runSmitheryStackOneEdge
Reliability16%206080StackOne +20
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27678StackOne +2
Agent ergonomics13%16.26575StackOne +10
Security & auth14%17.55069StackOne +19
Payments & pricing10%12.51038StackOne +28
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.84384StackOne +41
Transparency & trust7%8.84669StackOne +23
Negative events≤15-2-2
Total50.7 · D69.1 · B

Facts side by side

FactSmitheryStackOne
KindHTTP APIMCP server
VendorSmithery (Arcade.dev)StackOne Technologies Limited
Hosted endpointhttps://api.smithery.aihttps://mcp.stackone.com/mcp
TransportsHTTP, Streamable HTTPStreamable HTTP, HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceProprietary hosted service, with no terms of service found. The CLI (smithery) is AGPL-3.0, the TypeScript client (@smithery/api) is Apache-2.0 and the credential layer agent.pw is MITProprietary service under StackOne's SaaS Terms and Conditions. The Agent SDKs (@stackone/ai, stackone-ai) and the Defender package (@stackone/defender) are Apache-2.0
Read-only variant documentednono
llms.txtyesyes
MCP registrynot listedcom.stackone/mcp
Last release2026-07-202026-09-24
Terms last updatedno document linked2026-03-30
Privacy policy last updated2025-06-202023-12-01
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity840 stars, 2.7k npm/wk30 stars, 277 npm/wk

Verdicts

Smithery

Service tokens can be limited by namespace, resource, operation and connection metadata, with a lifetime of at most 24 hours. No terms of service, rate limits or SLA were found, the pricing page could not be read, and the newest client release is from 20 July 2026.

StackOne

StackOne's MCP server signs each person in with OAuth, lets them grant individual accounts and actions, and by default exposes two search and execute tools in place of the full catalogue. Session token URLs carry the credential in the query string for a year by default, and the Consumption Schedule and pricing page disagree on whether failed calls are billed.

Before you call either

Smithery

  1. Keep the API key on the backend and hand an agent a service token limited to connections with read and execute and a metadata match
  2. Create connections with PUT /connect/{namespace}/{connectionId}, which is an upsert, and check status.state before calling a tool
  3. On auth_required or input_required, send the person to setupUrl, then retry with the same connectionId
  4. Tool names on the namespace MCP endpoint are prefixed with the connection ID, such as user-123-github.search_repositories
  5. Do not rely on smithery skill commands. Version 1.1.1 of the CLI removed them

StackOne

  1. Send Accept: application/json,text/event-stream on every MCP request to https://api.stackone.com/mcp, by POST only. Without it the server answers 406
  2. In search_execute mode call {provider}_search_actions first and pass the returned action_id to {provider}_execute_action. Never hardcode action ids
  3. Pass the API key as the Basic auth username with an empty password, and name the linked account in x-account-id
  4. On 429 or 408 wait the seconds given in Retry-After. StackOne has already retried a provider's 429 up to five times within a 60-second request lifetime
  5. On 412 read errorCode and details.statusReasons. AccountErrorStatus needs a person to re-authenticate the linked account

Questions

Which is better for AI agents, Smithery or StackOne?

StackOne scores 69.1 (B) on agent readiness against Smithery's 50.7 (D), and leads in every scored category.

Do Smithery and StackOne need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Smithery and StackOne without installing anything?

Yes. Smithery has a hosted endpoint at https://api.smithery.ai and StackOne at https://mcp.stackone.com/mcp.

Other comparisons with Smithery or StackOne

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.