# Fix list: Unified.to MCP Server From Anchor Terminal's listing at https://www.anchorterminal.com/tools/unified-to-mcp, the October 2026 research run, assessed 9 October 2026. Grade C, 61.9 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Unified.to MCP Server: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Security & auth, 50 out of 100, up to 8.8 more on the total Why it scored 50: The default credential is a workspace API key that the docs say reaches all connections and the whole account. A signed token limited to one connection, keys limited to an environment and enterprise-managed tokens with category scopes and a one-hour life raise this to 22. Ten off because `?token=` in the URL is a documented option, deprecated for keys with no end date, and the only way the connection-scoped token is sent (12). `permissions` and `tools` limit the tool list, enterprise scopes hide tools a token may not call, and connections are isolated from one another. No approval step for writes was found (14). Tool results are third-party content. `hide_sensitive` removes PII, and no prompt-injection guidance was found (4). API call logs kept 30 to 365 days by plan, readable through management tools and streamable to Datadog on Pro and Scale. The docs warn that a workspace key leaves no per-person audit trail (10). SOC 2 Type II and yearly penetration tests are stated. security.txt returned 404, no bounty or disclosure policy was found, and the trust centre was not read (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 2. Payments & pricing, 30 out of 100, up to 8.8 more on the total Why it scored 30: No x402, MPP or L402 (0). Plan prices and overage rates per 1,000 API calls are public, and each tool call counts as one request. Two off because every plan price is shown with a plus sign and the terms of the free tester account are not set out (18). A tester account with 2,500 free requests and a 30-day trial are stated. Whether a card is needed is not stated, so part marks (12). A person signs up in a browser. The vendor's September 2026 update says creating the account still takes a person (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 3. Reliability, 73 out of 100, up to 5.4 more on the total Why it scored 73: Read with the hosted lines. status.unified.to on Honeybadger lists seven components, the API and the admin app in three regions and the authentication page. The MCP server has no component of its own (20). The page lists one incident in three months, API performance issues on 13 August 2026, resolved in an hour. Its detail page is closed by robots.txt and was not read, so it is counted as minor (20). Workspace limits are published per plan, from 500 to 10,000 requests a minute (15). The docs describe exponential backoff with jitter on 429 and say Unified does not queue or retry. No `Retry-After` header and no idempotency key were found (8). No uptime SLA is published. The pricing page says SLAs come with a custom Enterprise plan (0). The server launched on 1 June 2025 and carries no beta label (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 4. Agent ergonomics, 71 out of 100, up to 4.7 more on the total Why it scored 71: One HubSpot connection lists 78 tools, about 133 KB of definitions without output schemas and 343 KB with them, which scores 5. Eight back for the `tools`, `permissions` and `defer_tools` filters, which the docs tell users to set (13). List tools take `limit`, `offset`, a `fields` selection, `updated_gte`, `sort`, `order` and `query`. Pages hold 100 records at most and there is no cursor or total (18). The unauthenticated call returned a JSON-RPC error with a plain message naming the header to send, and the REST status table explains 401, 403, 429 and 501. Tool error results are not documented (11). All 78 previewed tools set `readOnlyHint`, `destructiveHint` and `idempotentHint`. Creates are marked not idempotent and there is no idempotency key (15). 44 required fields across 531 properties, and API SDKs in seven languages. Every option travels as a URL parameter (14). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 5. Schema & documentation, 81 out of 100, up to 3.1 more on the total Why it scored 81: One credential-free `tools/list` preview for HubSpot returned 78 tools, each with a JSON Schema input and 66 with an output schema. The API has a published OpenAPI 3.0 file, which we did not read (25). llms.txt on the docs and the site, a full-text file, and a Markdown twin of every docs page (10). Tool descriptions state the action, what is returned, what is required and which sibling tool to use, for example 'Permanently removes the record and cannot be undone'. They follow one template and say nothing about provider differences (15). The 78 inputs hold 531 properties and 135 enums with no open objects at the top level. `limit` and `offset` have no bounds and some filters are plain strings (12). Client set-up examples for eight hosts and a table of eight HTTP status codes. No per-tool examples, and MCP error results are not documented (8). A dated MCP changelog since June 2025. The server has no version scheme beyond the registry's 1.0.0 (11). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 6. Transparency & trust, 66 out of 100, up to 3 more on the total Made of editorial 61, provenance 71. Why it scored 66: The editorial half. Closed service under Terms of Service that name Unified API Inc. and Ontario law. Two off because the terms carry no date and bar sending financial or medical information and birth dates through a service sold for accounting and HR data (13). The privacy policy has an MCP section, says end-customer data is not stored and no models are trained, and gives retention periods by plan. The DPA of 19 March 2026 promises breach notice within 72 hours and deletion within a reasonable period on request. The security page says no data is stored at rest, ever, while the policy lists stored credentials, configuration and logs, and the page says Unified runs on AWS while the sub-processor list also names Render (22). No deprecation policy. `?token=` carries a `Deprecation` header with no end date, a field deprecation notice was published in November 2025, and SSE was removed on the day it was announced (8). Ten sub-processors with locations, dated 2 October 2025, and three named regions. The DPA gives 15 days' notice of new sub-processors on a best-efforts basis (18). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Domain age: unified.to, no registry record we could read (0 of 15) - Terms of service: read, states 5 of the 7 things a reader expects, and has 1 clause that costs points (6.3 of 10) - security.txt: not found (0 of 10) ## 7. Maintenance & community, 84 out of 100, up to 1.4 more on the total Why it scored 84: MCP changelog entry on 8 October 2026 (30). Entries on 22 July, 21 and 23 September and 8 October 2026 (20). A closed service with a daily site changelog, a public Discord for support and a stated response within 24 hours on the Test plan (12). `to.unified/core` is in the official MCP registry under the vendor's domain namespace (15). The docs date all seven API SDKs 21 September 2026. The sample MCP client repository was last changed on 29 August 2025 and its README still documents the removed `dc` option (7). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## Deductions Each comes off the total. A fixed and documented problem counts for less at the next check. - 23 September 2026. The MCP changelog entry of that date removed the SSE transport (`/sse` and `/sse/messages` now return HTTP 410), dropped `sse_url` from the `get_unified_connection_mcp_url` response, which the docs label a breaking change, and stopped regions resolving across one another. No earlier notice was found in the MCP changelog, the site changelog or the September product update. Whether customers were told privately was not established. The migration is a one-word URL change and is documented, so 3 points (https://docs.unified.to/mcp/changelog). ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: the trust centre at app.mycroft.io/trust/unified-to, where the SOC 2 report and policies are requested. We did not open it - unchecked: the detail page of the 13 August 2026 incident, which status.unified.to's robots.txt closes - unchecked: the OpenAPI file at api.unified.to, which we did not fetch, and the OAuth metadata at `/.well-known/oauth-protected-resource/mcp` - unchecked: the registration date of unified.to and the GitHub star count of the sample repository - unchecked: tool lists for integrations other than HubSpot, and the tool list with `include_external_tools` - Whether customers were told before 23 September 2026 that SSE, `sse_url` and cross-region resolution would go - Whether the tester account or the 30-day trial needs a card, and what the tester account's limits are beyond 2,500 requests - Which OAuth flow the privacy policy means by an OAuth token bound to one workspace with read or read and write permission. The 401 response advertises scopes `mcp:read mcp:write`, and the docs describe only the enterprise-managed exchange - When `?token=` authentication will stop working. The docs say a `Sunset` header will appear once a date is set - The Terms of Service forbid probing, scanning or testing the vulnerability of the service, which matters before any probe is run - We typed three `.md` addresses on unified.to that no page links (privacy, sub-processors, changelog). Each answered 404 and nothing was taken from them. The `?integration_type=` preview was named by the server's 401 message, not by a docs page we read ## Weaknesses - The default credential is a workspace API key. The docs say it grants access to all connections and the whole Unified.to account - The `/sse` transport and the `sse_url` response field were removed on 23 September 2026. No earlier notice was found in the MCP changelog, the site changelog or the September update - The connection-scoped signed token travels in the URL as `?token=`. The docs mark `?token=` authentication as deprecated, with no end date set - One HubSpot connection lists 78 tools whose definitions come to about 133 KB without output schemas and 343 KB with them - No uptime SLA is published. The pricing page says SLAs come with a custom Enterprise plan - No security.txt, bug bounty or disclosure policy was found, and the security page gives February 2025 as its last review - The Terms of Service forbid probing, scanning or testing the vulnerability of the service. This matters before any probe is run - The Terms of Service bar transmitting financial or medical information and birth dates through the service, while the product sells accounting and HR integrations ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Use the host for the workspace's region. US is `mcp-api.unified.to`, EU is `mcp-api-eu.unified.to` and AU is `api-au.unified.to`. A credential on another region's host resolves to not found - Send the key as `Authorization: Bearer ` and put `connection=` in the URL. Without `connection` the server lists workspace management tools, not the customer's data tools - Pass `tools` or `permissions` in the URL before listing. An unfiltered connection can list dozens of tools with large output schemas - Expect HTTP 429 on tool calls since 23 September 2026. Unified does not queue or retry, so back off and retry yourself - Page with `limit` (100 at most on most endpoints) and `offset`, and stop when a page returns fewer records than `limit` ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.