{
  "data": {
    "a": {
      "slug": "smithery",
      "name": "Smithery",
      "vendor": "Smithery (Arcade.dev)",
      "vendorUrl": "https://smithery.ai",
      "kind": "http-api",
      "category": "aggregator",
      "summary": "Smithery is a hosted registry and connection service for MCP servers, part of Arcade.dev since August 2026. Agents search the registry, create connections and call tools through a REST API, a per-namespace MCP endpoint, a TypeScript client or a CLI.",
      "url": "https://www.anchorterminal.com/tools/smithery",
      "markdownUrl": "https://www.anchorterminal.com/tools/smithery.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/smithery.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/smithery.json",
      "repo": "https://github.com/smithery-ai/cli",
      "license": "Proprietary hosted service, with no terms of service found. The CLI (`smithery`) is AGPL-3.0, the TypeScript client (`@smithery/api`) is Apache-2.0 and the credential layer agent.pw is MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.smithery.ai",
      "packages": [
        {
          "registry": "npm",
          "name": "@smithery/api"
        },
        {
          "registry": "npm",
          "name": "smithery"
        }
      ],
      "auth": "mixed",
      "authNotes": "A person signs in at smithery.ai and creates an API key, which has full access to the namespace and is sent as a Bearer token. `POST /tokens` mints service tokens limited by namespace, resource (connections, servers, namespaces, skills), operation (read, write, execute) and connection metadata, with a default lifetime of one hour and a maximum of 24. Organisation admins can create, list and revoke team API keys. The CLI signs in with OAuth in a browser. Upstream services are authorised by each end user on a hosted setup page, and Smithery stores and refreshes those credentials. Token Scoping is marked preview.",
      "pricing": "freemium",
      "pricingNotes": "Prices were not established. smithery.ai/pricing is drawn by script and showed our reader only the navigation. Arcade's announcement of 5 August 2026 says people can sign up for free. Whether a card is needed, what a paid plan costs and whether tool calls are metered were not read (checked 2026-10-09).",
      "priceSummary": "Freemium",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the OpenAPI file or the CLI source. The pricing page is drawn by script and was not read (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 840,
        "npmWeekly": 2729,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://smithery.ai/docs",
      "llmsTxt": "https://smithery.ai/docs/llms.txt",
      "openapi": "https://smithery.ai/docs/openapi.json",
      "capabilities": [
        "automation.apps",
        "automation.auth",
        "automation.actions",
        "agent.tools",
        "automation.webhooks"
      ],
      "tags": [
        "hosted",
        "mcp",
        "registry",
        "freemium",
        "api-key",
        "oauth",
        "openapi",
        "llms-txt",
        "typescript",
        "cli",
        "status-page",
        "closed-source"
      ],
      "lastRelease": "2026-07-20",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 50.7,
        "grade": "D",
        "agentReady": false,
        "rank": 766,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 43,
          "payments": 10,
          "reliability": 60,
          "schema": 76,
          "security": 50,
          "transparency": 46
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -2,
        "negativeNotes": [
          "22 May 2026. CLI release 1.1.1 removed the `smithery skill` subcommand, and on 9 October 2026 the CLI docs page and the repository README still tell users to run `smithery skill search` and `smithery skill add`. A stale claim in the docs, so 2 points (https://github.com/smithery-ai/cli/blob/main/CHANGELOG.md, https://smithery.ai/docs/concepts/cli.md)."
        ],
        "verdict": "Service tokens can be limited by namespace, resource, operation and connection metadata, with a lifetime of at most 24 hours. No terms of service, rate limits or SLA were found, the pricing page could not be read, and the newest client release is from 20 July 2026.",
        "bestFor": "A developer who wants many MCP servers behind one credential and one endpoint, with per-user connections and short-lived scoped tokens.",
        "strengths": [
          "Service tokens are scoped by namespace, resource, operation (read, write, execute) and connection metadata, expire within 24 hours and can be narrowed further",
          "An OpenAPI 3.1 file with 55 operations, `/docs/llms.txt` and a Markdown twin of every docs page",
          "Connections report `auth_required` or `input_required` with a hosted `setupUrl` and the list of missing fields",
          "Stored credentials are write-only per the docs, and the credential layer, agent.pw, is published under MIT",
          "The status page shows 100 per cent uptime over 90 days for the site, the API and the gateway"
        ],
        "weaknesses": [
          "No terms of service are linked from the site, the docs or the footer. The privacy notice of 20 June 2025 is the only legal document found",
          "The privacy notice links a Data Policy at `/docs/use/data-policy`, which answers 404",
          "No rate limits, 429 response or SLA appear in the docs or the API description",
          "The CLI repository has had no commit since 31 May 2026 and the API client's last release is 0.68.0 of 20 July 2026",
          "The CLI docs and README still list `smithery skill` commands that release 1.1.1 removed on 22 May 2026",
          "Token Scoping and the typed SDKs are marked preview, with breaking changes possible without notice"
        ],
        "agentNotes": [
          "Keep the API key on the backend and hand an agent a service token limited to `connections` with `read` and `execute` and a `metadata` match",
          "Create connections with `PUT /connect/{namespace}/{connectionId}`, which is an upsert, and check `status.state` before calling a tool",
          "On `auth_required` or `input_required`, send the person to `setupUrl`, then retry with the same `connectionId`",
          "Tool names on the namespace MCP endpoint are prefixed with the connection ID, such as `user-123-github.search_repositories`",
          "Do not rely on `smithery skill` commands. Version 1.1.1 of the CLI removed them"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 50.7
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 43,
          "payments": 10,
          "reliability": 60,
          "schema": 76,
          "security": 50,
          "transparency": 27
        },
        "provenanceScore": 65
      },
      "connect": {
        "install": "npm install -g smithery@latest",
        "http": "curl -X PUT \"https://smithery.run/my-app/my-browserbase\" \\\n  -H \"Authorization: Bearer $SMITHERY_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"mcpUrl\": \"https://mcp.browserbase.com/mcp\"}'"
      },
      "letme": {
        "capability": "https://letme.dev/automation.apps",
        "tool": "https://letme.dev/smithery"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "Clavia, Inc. (doing business as Smithery)",
        "domain": "smithery.ai",
        "domainRegistered": "2024-12-10",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "https://smithery.ai/privacy",
        "statusPage": "https://status.smithery.ai",
        "changelog": "https://github.com/smithery-ai/typescript-api/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The Smithery Privacy Notice, last updated 20 June 2025, names Clavia, Inc. doing business as Smithery and covers the Smithery platform and the smithery.ai website. It predates the acquisition and does not name Arcade.",
          "No terms of service were found. The home page, the pricing page, the about page and the docs link only the privacy notice, so `terms` is left out.",
          "The privacy notice links a Data Policy at https://smithery.ai/docs/use/data-policy, which answered 404 on 9 October 2026.",
          "Arcade.dev announced the acquisition of Smithery on 5 August 2026. The acquiring company's legal name was not read.",
          "The management API answers at api.smithery.ai. Connection calls, the namespace MCP endpoint and Uplink use a second domain, smithery.run.",
          "smithery.ai/.well-known/security.txt answered 404. The client repository's SECURITY.md sends reports about the service to contact@smithery.ai.",
          "RDAP gives a registration date of 2024-12-10 for smithery.ai, a transfer on 10 September 2026 and Cloudflare as registrar.",
          "The changelog link is the TypeScript client's. No dated changelog for the hosted service was found."
        ],
        "score": 65
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/smithery.json",
      "live": {
        "slug": "smithery",
        "probe": {
          "target": "https://api.smithery.ai",
          "method": "get",
          "lastAt": "2026-10-10T05:39:05.518624885Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 190,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 194,
          "p95ms24h": 316,
          "samples24h": 143,
          "samples30d": 143,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 85,
              "ok": 85
            },
            {
              "date": "2026-10-10",
              "probes": 58,
              "ok": 58
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.smithery.ai",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-10T00:51:16.433925119Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "smithery-ai/cli",
            "version": "v1.2.0",
            "released": "2026-05-31",
            "seenAt": "2026-10-09T17:20:48.992258676Z"
          },
          {
            "registry": "npm",
            "name": "@smithery/api",
            "version": "0.68.0",
            "seenAt": "2026-10-09T17:20:46.778269251Z"
          },
          {
            "registry": "npm",
            "name": "smithery",
            "version": "1.2.0",
            "seenAt": "2026-10-09T17:20:47.691292694Z"
          }
        ],
        "githubStars": 840,
        "npmWeekly": 2729,
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/smithery-ai/typescript-api/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:46:07.185814834Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8bd4ab2d180a"
          },
          {
            "url": "https://smithery.ai/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:45:32.741358495Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4143bed484bd"
          }
        ],
        "updatedAt": "2026-10-10T05:39:05.518624885Z"
      }
    },
    "answer": "StackOne scores 69.1 (B) on agent readiness against Smithery's 50.7 (D), and leads in every scored category.",
    "b": {
      "slug": "stackone",
      "name": "StackOne",
      "vendor": "StackOne Technologies Limited",
      "vendorUrl": "https://www.stackone.com",
      "kind": "mcp",
      "category": "aggregator",
      "summary": "StackOne is a hosted gateway from StackOne Technologies Limited that gives AI agents actions across more than 540 business apps over MCP, SDKs, A2A or HTTP, with managed authentication, per-user grants, policies and logs.",
      "url": "https://www.anchorterminal.com/tools/stackone",
      "markdownUrl": "https://www.anchorterminal.com/tools/stackone.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/stackone.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/stackone.json",
      "repo": "https://github.com/StackOneHQ/stackone-ai-node",
      "license": "Proprietary service under StackOne's SaaS Terms and Conditions. The Agent SDKs (`@stackone/ai`, `stackone-ai`) and the Defender package (`@stackone/defender`) are Apache-2.0",
      "transports": [
        "streamable-http",
        "http"
      ],
      "remoteUrl": "https://mcp.stackone.com/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@stackone/ai"
        },
        {
          "registry": "pypi",
          "name": "stackone-ai"
        },
        {
          "registry": "npm",
          "name": "@stackone/defender"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. A person signs up in the dashboard, creates a project and a connector profile, and links an account. MCP clients connect to `https://mcp.stackone.com/mcp` with OAuth (scopes `mcp offline_access`, one-hour access tokens, a 90-day grant) and the user picks the linked accounts and actions at consent. Most clients register themselves, and a few need a client ID and secret created in the dashboard. Backend calls go to `https://api.stackone.com/mcp` or `POST /actions/rpc` with a project API key as the Basic auth username and the linked account in `x-account-id`. Keys take scopes (Platform API, Actions, Connectors, Credentials, Unified API) and can be disabled or deleted. Session token URLs (`https://api.stackone.com/mcp?token=...`) cover one linked account, carry the access in the URL and expire after one year by default.",
      "pricing": "freemium",
      "pricingNotes": "Free to start with no card, per the pricing page. Gateway Starter is free with 1,000 credits a seat a month, one credit per tool call or API call, and extra credits at $60 per 20,000. Gateway Team is $600 a month ($6,000 a year) with 5,000 credits a seat a month and extra credits at $20 per 20,000. The pricing calculator's markup gives 10 seats included on Team and $15 a further seat, which the page text doesn't state. OEM Core is free with a monthly credit allowance and volume prices on request. Enterprise plans are priced on contract. Browser use, premium defence and data sync cost more than one credit, at rates not published. The Service Consumption Schedule of 30 March 2026 gives $0.003 per Action Call as overage and counts unsuccessful requests, while the pricing page says background and failed calls aren't billed (https://www.stackone.com/pricing/, checked 2026-10-09).",
      "priceSummary": "$600 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the pricing page, the SaaS terms or the Service Consumption Schedule (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 30,
        "npmWeekly": 277,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.stackone.com/introduction",
      "llmsTxt": "https://docs.stackone.com/llms.txt",
      "openapi": "https://api.eu1.stackone.com/v2/oas/stackone.json",
      "registryName": "com.stackone/mcp",
      "capabilities": [
        "automation.apps",
        "automation.auth",
        "automation.actions",
        "agent.tools",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "mcp",
        "a2a",
        "freemium",
        "free-tier",
        "no-card",
        "oauth",
        "api-key",
        "openapi",
        "llms-txt",
        "typescript",
        "python",
        "enterprise",
        "status-page",
        "soc2",
        "mcp-registry",
        "closed-source"
      ],
      "lastRelease": "2026-09-24",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.1,
        "grade": "B",
        "agentReady": false,
        "rank": 198,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 75,
          "maintenance": 84,
          "payments": 38,
          "reliability": 80,
          "schema": 78,
          "security": 69,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -2,
        "negativeNotes": [
          "27 April 2026. `@stackone/ai` v2.8.1 fixed a flaw in which tools fetched concurrently for several accounts were stamped with the wrong `x-account-id`, so a call could run against another linked account. It is recorded as a bug fix in the changelog, with no advisory found. Fixed and documented, so 2 points (https://github.com/StackOneHQ/stackone-ai-node/blob/main/CHANGELOG.md)."
        ],
        "verdict": "StackOne's MCP server signs each person in with OAuth, lets them grant individual accounts and actions, and by default exposes two search and execute tools in place of the full catalogue. Session token URLs carry the credential in the query string for a year by default, and the Consumption Schedule and pricing page disagree on whether failed calls are billed.",
        "bestFor": "A company that wants one governed MCP endpoint for staff agents across business systems, and product teams embedding per-customer connections with HR, recruiting and CRM coverage.",
        "strengths": [
          "The MCP server at `https://mcp.stackone.com/mcp` uses OAuth per person. Access tokens last one hour, a grant lasts 90 days, and each user can revoke it under Connected Apps",
          "Advanced Tool Search replaces the tool list with two tools, search and execute, and is on by default at the OAuth consent screen",
          "Since 24 July 2026 every tool carries `readOnlyHint`, `destructiveHint` and `openWorldHint`, derived from an effects value on each action",
          "API keys are limited to one project and take scopes for the Platform API, Actions, Connectors, Credentials and the Unified API. Credentials access is off by default",
          "Rate limit published at 1,000 requests a minute per API key, with `Retry-After` in seconds on 429 and 408 responses",
          "Defender scans tool results for prompt injection and is on for new projects. Its Light Scan engine is open source under Apache-2.0"
        ],
        "weaknesses": [
          "Session token URLs (`https://api.stackone.com/mcp?token=...`) put the credential in the query string, cover one linked account and expire after one year by default",
          "The Service Consumption Schedule counts every request, successful or not, as an Action Call. The pricing page says failed calls aren't billed",
          "Defender's default mode is Monitor, which records a verdict and passes the tool result to the agent unchanged",
          "Policies apply only to signed-in members. A call made with a project API key is memberless and is governed by connector profile scoping alone",
          "The Logs API, audit logs, SIEM export and an uptime SLA are Enterprise only on Gateway plans, and Starter keeps action logs for one day",
          "The Acceptable Use Policy bars competitive analysis or benchmarking other than for internal comparison, and probing or testing the Service's vulnerability without authorisation. This matters before any probe is run",
          "`@stackone/ai` stamped tools with the wrong `x-account-id` when accounts were fetched concurrently, until v2.8.1 on 27 April 2026. No advisory was found"
        ],
        "agentNotes": [
          "Send `Accept: application/json,text/event-stream` on every MCP request to `https://api.stackone.com/mcp`, by POST only. Without it the server answers 406",
          "In `search_execute` mode call `{provider}_search_actions` first and pass the returned `action_id` to `{provider}_execute_action`. Never hardcode action ids",
          "Pass the API key as the Basic auth username with an empty password, and name the linked account in `x-account-id`",
          "On 429 or 408 wait the seconds given in `Retry-After`. StackOne has already retried a provider's 429 up to five times within a 60-second request lifetime",
          "On 412 read `errorCode` and `details.statusReasons`. `AccountErrorStatus` needs a person to re-authenticate the linked account"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.1
          }
        ],
        "editorialScores": {
          "ergonomics": 75,
          "maintenance": 84,
          "payments": 38,
          "reliability": 80,
          "schema": 78,
          "security": 69,
          "transparency": 50
        },
        "provenanceScore": 88
      },
      "connect": {
        "install": "npm install @stackone/ai",
        "http": "curl -X POST \"https://api.stackone.com/actions/rpc\" \\\n  -u \"$STACKONE_API_KEY:\" \\\n  -H \"x-account-id: your-account-id\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"action\": \"bamboohr_list_employees\", \"query\": {\"page_size\": 25}}'",
        "claudeCode": "claude mcp add --transport http --scope user stackone https://mcp.stackone.com/mcp"
      },
      "letme": {
        "capability": "https://letme.dev/automation.apps",
        "tool": "https://letme.dev/stackone"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Gateway Team plan",
          "unit": "month",
          "usd": 600,
          "note": "5,000 credits a seat a month, one credit per tool call or API call. $6,000 billed yearly"
        },
        {
          "item": "Extra credits, Gateway Starter",
          "unit": "1k-calls",
          "usd": 3,
          "note": "$60 per 20,000 credits, valid 12 months. Advanced capabilities cost more than one credit a call"
        },
        {
          "item": "Extra credits, Gateway Team",
          "unit": "1k-calls",
          "usd": 1,
          "note": "$20 per 20,000 credits, valid 12 months"
        }
      ],
      "provenance": {
        "legalEntity": "StackOne Technologies Limited",
        "domain": "stackone.com",
        "domainRegistered": "2013-06-25",
        "endpointOnVendorDomain": true,
        "terms": "https://www.stackone.com/terms/saas-terms/",
        "privacy": "https://www.stackone.com/terms/privacy-policy/",
        "statusPage": "https://status.stackone.com",
        "changelog": "https://www.stackone.com/changelog/",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The SaaS Terms and Conditions, effective 30 March 2026, name StackOne Technologies Limited, company number 14684360, registered at 2 Communications Road, Newbury, Berkshire, RG19 6AB, under the laws of England and Wales. They take effect when a customer first accesses the Service or signs an order.",
          "The contact page says StackOne operates in the United States as StackOne Technologies Inc., 2261 Market Street, San Francisco.",
          "The Platform Privacy Policy, last updated 1 December 2023, covers the web application and API and says it does not cover the website. A separate Privacy Notice covers the website.",
          "The MCP server answers at mcp.stackone.com, the API at api.stackone.com and A2A at a2a.stackone.com.",
          "www.stackone.com/.well-known/security.txt returned 404.",
          "RDAP for stackone.com gives a registration date of 2013-06-25. The company was incorporated later, per its company number.",
          "status.stackone.com runs on incident.io and lists the Web Dashboard, the API (US, EU and UK) and the Connectors Hub.",
          "trust.stackone.com, which the terms cite for the security policy and the sub-processor list, answered our reader with a bot check and was not read."
        ],
        "score": 88
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/stackone.json",
      "live": {
        "slug": "stackone",
        "probe": {
          "target": "https://mcp.stackone.com/mcp",
          "method": "mcp-initialize",
          "lastAt": "2026-10-10T05:39:06.349484924Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 147,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 110,
          "p95ms24h": 295,
          "samples24h": 143,
          "samples30d": 143,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 85,
              "ok": 85
            },
            {
              "date": "2026-10-10",
              "probes": 58,
              "ok": 58
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.stackone.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-10T05:35:42.618528885Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "StackOneHQ/stackone-ai-node",
            "version": "v2.10.0",
            "released": "2026-07-27",
            "seenAt": "2026-10-09T17:21:48.091098138Z"
          },
          {
            "registry": "mcp-registry",
            "name": "com.stackone/mcp",
            "version": "1.0.1",
            "seenAt": "2026-10-10T03:11:32.438759038Z"
          },
          {
            "registry": "npm",
            "name": "@stackone/ai",
            "version": "2.10.0",
            "seenAt": "2026-10-09T17:21:45.859326927Z"
          },
          {
            "registry": "npm",
            "name": "@stackone/defender",
            "version": "0.8.3",
            "seenAt": "2026-10-09T17:21:46.919917579Z"
          },
          {
            "registry": "pypi",
            "name": "stackone-ai",
            "version": "2.10.1",
            "released": "2026-07-28",
            "seenAt": "2026-10-09T17:21:46.731430671Z"
          }
        ],
        "githubStars": 30,
        "npmWeekly": 277,
        "pypiWeekly": 120,
        "pages": [
          {
            "url": "https://www.stackone.com/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:54:33.415845489Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a8dc254bb424"
          },
          {
            "url": "https://www.stackone.com/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:54:35.567295878Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "98687cfb089f"
          },
          {
            "url": "https://www.stackone.com/terms/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:54:37.551620202Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "011ecd948b67"
          },
          {
            "url": "https://www.stackone.com/terms/saas-terms/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:54:39.532884111Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "393a890498df"
          }
        ],
        "mcpTools": {
          "url": "https://mcp.stackone.com/mcp",
          "checkedAt": "2026-10-09T21:40:55.809059913Z",
          "status": "auth",
          "note": "asks for credentials before listing its tools",
          "changedAt": "2026-10-09T21:40:55.809059913Z"
        },
        "updatedAt": "2026-10-10T05:39:06.349484924Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "MCP server",
        "name": "Kind"
      },
      {
        "a": "Smithery (Arcade.dev)",
        "b": "StackOne Technologies Limited",
        "name": "Vendor"
      },
      {
        "a": "https://api.smithery.ai",
        "b": "https://mcp.stackone.com/mcp",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "Streamable HTTP, HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary hosted service, with no terms of service found. The CLI (`smithery`) is AGPL-3.0, the TypeScript client (`@smithery/api`) is Apache-2.0 and the credential layer agent.pw is MIT",
        "b": "Proprietary service under StackOne's SaaS Terms and Conditions. The Agent SDKs (`@stackone/ai`, `stackone-ai`) and the Defender package (`@stackone/defender`) are Apache-2.0",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "not listed",
        "b": "com.stackone/mcp",
        "name": "MCP registry"
      },
      {
        "a": "2026-07-20",
        "b": "2026-09-24",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "2026-03-30",
        "name": "Terms last updated"
      },
      {
        "a": "2025-06-20",
        "b": "2023-12-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "840 stars, 2.7k npm/wk",
        "b": "30 stars, 277 npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "StackOne scores 69.1 (B) on agent readiness against Smithery's 50.7 (D), and leads in every scored category.",
        "question": "Which is better for AI agents, Smithery or StackOne?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Smithery and StackOne need an API key?"
      },
      {
        "answer": "Yes. Smithery has a hosted endpoint at https://api.smithery.ai and StackOne at https://mcp.stackone.com/mcp.",
        "question": "Can an agent call Smithery and StackOne without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": null,
        "also": null,
        "goodFor": "A developer who wants many MCP servers behind one credential and one endpoint, with per-user connections and short-lived scoped tokens.",
        "slug": "smithery",
        "watchFor": "No terms of service are linked from the site, the docs or the footer. The privacy notice of 20 June 2025 is the only legal document found"
      },
      {
        "aheadOn": [
          "Reliability, 80 against 60",
          "Agent ergonomics, 75 against 65",
          "Security \u0026 auth, 69 against 50",
          "Payments \u0026 pricing, 38 against 10",
          "Maintenance \u0026 community, 84 against 43",
          "Transparency \u0026 trust, 69 against 46"
        ],
        "also": [
          "Free to start without a card"
        ],
        "goodFor": "A company that wants one governed MCP endpoint for staff agents across business systems, and product teams embedding per-customer connections with HR, recruiting and CRM coverage.",
        "slug": "stackone",
        "watchFor": "Session token URLs (`https://api.stackone.com/mcp?token=...`) put the credential in the query string, cover one linked account and expire after one year by default"
      }
    ],
    "job": {
      "capability": "automation.apps",
      "name": "App automation"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/composio-rube-vs-smithery.json",
        "title": "Composio (API + MCP) vs Smithery",
        "url": "https://www.anchorterminal.com/compare/composio-rube-vs-smithery"
      },
      {
        "json": "https://www.anchorterminal.com/compare/composio-rube-vs-stackone.json",
        "title": "Composio (API + MCP) vs StackOne",
        "url": "https://www.anchorterminal.com/compare/composio-rube-vs-stackone"
      },
      {
        "json": "https://www.anchorterminal.com/compare/merge-agent-handler-vs-smithery.json",
        "title": "Merge Agent Handler vs Smithery",
        "url": "https://www.anchorterminal.com/compare/merge-agent-handler-vs-smithery"
      },
      {
        "json": "https://www.anchorterminal.com/compare/merge-agent-handler-vs-stackone.json",
        "title": "Merge Agent Handler vs StackOne",
        "url": "https://www.anchorterminal.com/compare/merge-agent-handler-vs-stackone"
      },
      {
        "json": "https://www.anchorterminal.com/compare/one-vs-smithery.json",
        "title": "One vs Smithery",
        "url": "https://www.anchorterminal.com/compare/one-vs-smithery"
      },
      {
        "json": "https://www.anchorterminal.com/compare/one-vs-stackone.json",
        "title": "One vs StackOne",
        "url": "https://www.anchorterminal.com/compare/one-vs-stackone"
      },
      {
        "json": "https://www.anchorterminal.com/compare/smithery-vs-unified-to-mcp.json",
        "title": "Smithery vs Unified.to MCP Server",
        "url": "https://www.anchorterminal.com/compare/smithery-vs-unified-to-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/smithery-vs-zapier-mcp.json",
        "title": "Smithery vs Zapier MCP (agent actions)",
        "url": "https://www.anchorterminal.com/compare/smithery-vs-zapier-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/stackone-vs-unified-to-mcp.json",
        "title": "StackOne vs Unified.to MCP Server",
        "url": "https://www.anchorterminal.com/compare/stackone-vs-unified-to-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/stackone-vs-zapier-mcp.json",
        "title": "StackOne vs Zapier MCP (agent actions)",
        "url": "https://www.anchorterminal.com/compare/stackone-vs-zapier-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/letme-vs-smithery.json",
        "title": "letme vs Smithery",
        "url": "https://www.anchorterminal.com/compare/letme-vs-smithery"
      },
      {
        "json": "https://www.anchorterminal.com/compare/letme-vs-stackone.json",
        "title": "letme vs StackOne",
        "url": "https://www.anchorterminal.com/compare/letme-vs-stackone"
      }
    ],
    "scores": [
      {
        "by": 20,
        "edge": "stackone",
        "key": "reliability",
        "name": "Reliability",
        "smithery": 60,
        "stackone": 80,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 2,
        "edge": "stackone",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "smithery": 76,
        "stackone": 78,
        "weight": 13
      },
      {
        "by": 10,
        "edge": "stackone",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "smithery": 65,
        "stackone": 75,
        "weight": 13
      },
      {
        "by": 19,
        "edge": "stackone",
        "key": "security",
        "name": "Security \u0026 auth",
        "smithery": 50,
        "stackone": 69,
        "weight": 14
      },
      {
        "by": 28,
        "edge": "stackone",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "smithery": 10,
        "stackone": 38,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 41,
        "edge": "stackone",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "smithery": 43,
        "stackone": 84,
        "weight": 7
      },
      {
        "by": 23,
        "edge": "stackone",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "smithery": 46,
        "stackone": 69,
        "weight": 7
      }
    ],
    "summary": "StackOne scores 69.1 (B) on agent readiness against Smithery's 50.7 (D), and leads in every scored category. Both do app automation.",
    "verdicts": {
      "smithery": "Service tokens can be limited by namespace, resource, operation and connection metadata, with a lifetime of at most 24 hours. No terms of service, rate limits or SLA were found, the pricing page could not be read, and the newest client release is from 20 July 2026.",
      "stackone": "StackOne's MCP server signs each person in with OAuth, lets them grant individual accounts and actions, and by default exposes two search and execute tools in place of the full catalogue. Session token URLs carry the credential in the query string for a year by default, and the Consumption Schedule and pricing page disagree on whether failed calls are billed."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/smithery-vs-stackone",
    "json": "https://www.anchorterminal.com/compare/smithery-vs-stackone.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/smithery-vs-stackone.md",
    "slim": "https://www.anchorterminal.com/compare/smithery-vs-stackone.min.md"
  },
  "markdown": "StackOne scores 69.1 (B) on agent readiness against Smithery's 50.7 (D), and leads in every scored category. Both do app automation.\n\n- Smithery: grade D, 50.7/100, rank #766 of 950. Markdown https://www.anchorterminal.com/tools/smithery.md · JSON https://www.anchorterminal.com/api/v1/tools/smithery.json\n- StackOne: grade B, 69.1/100, rank #198 of 950. Markdown https://www.anchorterminal.com/tools/stackone.md · JSON https://www.anchorterminal.com/api/v1/tools/stackone.json\n- Best agent tool access platforms: https://www.anchorterminal.com/best/aggregator/index.md\n- All 28 tool access comparisons: https://www.anchorterminal.com/compare/aggregator/index.md\n\n## Which one, for what\n\n### Smithery (D)\n\nGood for: A developer who wants many MCP servers behind one credential and one endpoint, with per-user connections and short-lived scoped tokens.\n\nWatch for: No terms of service are linked from the site, the docs or the footer. The privacy notice of 20 June 2025 is the only legal document found\n\n### StackOne (B)\n\nGood for: A company that wants one governed MCP endpoint for staff agents across business systems, and product teams embedding per-customer connections with HR, recruiting and CRM coverage.\n\nAhead on:\n- Reliability, 80 against 60\n- Agent ergonomics, 75 against 65\n- Security \u0026 auth, 69 against 50\n- Payments \u0026 pricing, 38 against 10\n- Maintenance \u0026 community, 84 against 43\n- Transparency \u0026 trust, 69 against 46\n\nAlso in its favour:\n- Free to start without a card\n\nWatch for: Session token URLs (`https://api.stackone.com/mcp?token=...`) put the credential in the query string, cover one linked account and expire after one year by default\n\n\n## Score by category\n\n| Category | Weight | Smithery | StackOne | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 60 | 80 | StackOne +20 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 76 | 78 | StackOne +2 |\n| Agent ergonomics | 13% (16.2 this run) | 65 | 75 | StackOne +10 |\n| Security \u0026 auth | 14% (17.5 this run) | 50 | 69 | StackOne +19 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 10 | 38 | StackOne +28 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 43 | 84 | StackOne +41 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 46 | 69 | StackOne +23 |\n| Negative events | ≤15 | -2 | -2 | |\n| **Total** | | **50.7 · D** | **69.1 · B** | |\n\n## Facts side by side\n\n| Fact | Smithery | StackOne |\n| --- | --- | --- |\n| Kind | HTTP API | MCP server |\n| Vendor | Smithery (Arcade.dev) | StackOne Technologies Limited |\n| Hosted endpoint | `https://api.smithery.ai` | `https://mcp.stackone.com/mcp` |\n| Transports | HTTP, Streamable HTTP | Streamable HTTP, HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary hosted service, with no terms of service found. The CLI (`smithery`) is AGPL-3.0, the TypeScript client (`@smithery/api`) is Apache-2.0 and the credential layer agent.pw is MIT | Proprietary service under StackOne's SaaS Terms and Conditions. The Agent SDKs (`@stackone/ai`, `stackone-ai`) and the Defender package (`@stackone/defender`) are Apache-2.0 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | `com.stackone/mcp` |\n| Last release | 2026-07-20 | 2026-09-24 |\n| Terms last updated | no document linked | 2026-03-30 |\n| Privacy policy last updated | 2025-06-20 | 2023-12-01 |\n| Customer content may train models |  | not found in the text |\n| Terms restrict automated access |  | not found in the text |\n| Terms restrict benchmarking |  | not found in the text |\n| Terms or service can change without notice |  | not found in the text |\n| Arbitration or class-action waiver |  | not found in the text |\n| Popularity | 840 stars, 2.7k npm/wk | 30 stars, 277 npm/wk |\n\n## Verdicts\n\n**Smithery.** Service tokens can be limited by namespace, resource, operation and connection metadata, with a lifetime of at most 24 hours. No terms of service, rate limits or SLA were found, the pricing page could not be read, and the newest client release is from 20 July 2026.\n\n**StackOne.** StackOne's MCP server signs each person in with OAuth, lets them grant individual accounts and actions, and by default exposes two search and execute tools in place of the full catalogue. Session token URLs carry the credential in the query string for a year by default, and the Consumption Schedule and pricing page disagree on whether failed calls are billed.\n\n## Before you call either\n\n### Smithery\n\n1. Keep the API key on the backend and hand an agent a service token limited to `connections` with `read` and `execute` and a `metadata` match\n2. Create connections with `PUT /connect/{namespace}/{connectionId}`, which is an upsert, and check `status.state` before calling a tool\n3. On `auth_required` or `input_required`, send the person to `setupUrl`, then retry with the same `connectionId`\n4. Tool names on the namespace MCP endpoint are prefixed with the connection ID, such as `user-123-github.search_repositories`\n5. Do not rely on `smithery skill` commands. Version 1.1.1 of the CLI removed them\n\n### StackOne\n\n1. Send `Accept: application/json,text/event-stream` on every MCP request to `https://api.stackone.com/mcp`, by POST only. Without it the server answers 406\n2. In `search_execute` mode call `{provider}_search_actions` first and pass the returned `action_id` to `{provider}_execute_action`. Never hardcode action ids\n3. Pass the API key as the Basic auth username with an empty password, and name the linked account in `x-account-id`\n4. On 429 or 408 wait the seconds given in `Retry-After`. StackOne has already retried a provider's 429 up to five times within a 60-second request lifetime\n5. On 412 read `errorCode` and `details.statusReasons`. `AccountErrorStatus` needs a person to re-authenticate the linked account\n\n## Questions\n\n### Which is better for AI agents, Smithery or StackOne?\n\nStackOne scores 69.1 (B) on agent readiness against Smithery's 50.7 (D), and leads in every scored category.\n\n### Do Smithery and StackOne need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Smithery and StackOne without installing anything?\n\nYes. Smithery has a hosted endpoint at https://api.smithery.ai and StackOne at https://mcp.stackone.com/mcp.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/smithery-vs-stackone.json, and with the fewest tokens: https://www.anchorterminal.com/compare/smithery-vs-stackone.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"smithery\", \"b\": \"stackone\"}`. From a terminal: `anchor compare smithery stackone`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/smithery.json and https://www.anchorterminal.com/api/v1/tools/stackone.json\n\n## Other comparisons with Smithery or StackOne\n\n- [Composio (API + MCP) vs Smithery](https://www.anchorterminal.com/compare/composio-rube-vs-smithery.md)\n- [Composio (API + MCP) vs StackOne](https://www.anchorterminal.com/compare/composio-rube-vs-stackone.md)\n- [Merge Agent Handler vs Smithery](https://www.anchorterminal.com/compare/merge-agent-handler-vs-smithery.md)\n- [Merge Agent Handler vs StackOne](https://www.anchorterminal.com/compare/merge-agent-handler-vs-stackone.md)\n- [One vs Smithery](https://www.anchorterminal.com/compare/one-vs-smithery.md)\n- [One vs StackOne](https://www.anchorterminal.com/compare/one-vs-stackone.md)\n- [Smithery vs Unified.to MCP Server](https://www.anchorterminal.com/compare/smithery-vs-unified-to-mcp.md)\n- [Smithery vs Zapier MCP (agent actions)](https://www.anchorterminal.com/compare/smithery-vs-zapier-mcp.md)\n- [StackOne vs Unified.to MCP Server](https://www.anchorterminal.com/compare/stackone-vs-unified-to-mcp.md)\n- [StackOne vs Zapier MCP (agent actions)](https://www.anchorterminal.com/compare/stackone-vs-zapier-mcp.md)\n- [letme vs Smithery](https://www.anchorterminal.com/compare/letme-vs-smithery.md)\n- [letme vs StackOne](https://www.anchorterminal.com/compare/letme-vs-stackone.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Smithery vs StackOne",
        "url": ""
      }
    ],
    "description": "StackOne scores 69.1 (B) to Smithery's 50.7 (D) for app automation. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Smithery D 50.7",
      "StackOne B 69.1",
      "scores"
    ],
    "h1": "Smithery vs StackOne",
    "image": "https://www.anchorterminal.com/assets/og/compare-smithery-vs-stackone.png",
    "path": "/compare/smithery-vs-stackone",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Smithery vs StackOne for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/smithery-vs-stackone"
  },
  "tokens": {
    "markdown": 2250,
    "slim": 780
  },
  "version": 1
}
