One
by One Systems, Inc. MCP server in Agent tool access
Hosted Local
One Systems, Inc. · withone.ai since 2026 · status page · who's behind it
One is a hosted MCP server and CLI from One Systems, Inc. (formerly Pica) that lets AI agents find and run actions in a user's connected apps, with credentials held by One and access scoped per connection.
Good for A person or small team that wants one MCP entry with a small tool footprint across many SaaS accounts, with access set per connection and a free plan.
Is this your product? Claim this listing or verify it
Assessment. One's remote MCP server has three tools, OAuth 2.1 sign-in with PKCE and a consent screen that sets read only, read and write, full or per-action access for each connection. A person must sign in through a browser, the SOC 2 audit is unfinished, and the site's changelog stops at 13 July 2026.
Facts
- Transport
- Streamable HTTP, stdio
- Endpoint
https://mcp.withone.ai/mcp- Auth
- OAuth or key
- Pricing
- Freemium · $29 / mo
- x402
- No
- Licence
- Proprietary hosted service under One's Terms of Service. The local MCP server package `@withone/mcp` is MIT. The CLI package `@withone/cli` has no licence field or licence file. The knowledge base is under the One Knowledge Commons Licence v1.0, which is not an OSI licence
- Tools exposed
- 3
- Packages
npm@withone/mcpnpm@withone/cli- MCP registry
ai.withone/mcp- Source
- github.com/withoneai/mcp
- llms.txt
- published
- Last release
- GitHub stars
- 11
- npm / week
- 681
- MCP endpoint
https://mcp.withone.ai/mcp, Streamable HTTP, OAuth sign-in in the browser. The server card gives version 0.1.0- Tools
list_one_integrations,find_one_actionsandexecute_one_action. Knowledge-only mode leavesfind_one_actionsalone on the remote server- Access levels
- Full access, Read & write (GET, POST, PUT, PATCH), Read only (GET) or Custom (ticked actions), set per connection on the consent screen and enforced on every call
- OAuth
- Authorisation code with PKCE (S256), dynamic client registration for public clients, six connection scopes, 1-hour access tokens, 30-day refresh tokens
- Coverage
- 952 platforms and 127,943 actions per the vendor's llms.txt on 9 October 2026. The registry entry for the server says 700+ apps
- Local server
@withone/mcp2.0.0 on npm (30 September 2026), stdio, API key inONE_SECRET, limits set withONE_PERMISSIONS,ONE_CONNECTION_KEYSandONE_ACTION_IDS- CLI
@withone/cli2.5.0 on npm (6 October 2026), Node.js 18 or later.one list,one actions findandone actions executemirror the three tools- REST API
- OpenAPI 3.1 file, version 5.35.0, with 245 operations on 161 paths at
https://api.withone.ai. Calls to connected apps go through/v1/passthrough/{key} - Rate limits
- 20, 100 and 500 requests a minute on Free, Starter and Pro, per account across every key. 429 over the limit
- Logs
- The dashboard records agent, app, action and outcome for each call, including refused calls. Log retention is 14 to 90 days by default per the privacy policy
- Hosting
- Google Cloud Platform in the United States is the only sub-processor of Customer Data on the list updated 22 July 2026
- Certifications
- None completed. A SOC 2 Type II audit is described as under way, with the report to be shared under NDA
Facts verified 2026-10-09 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- The remote server has three tools whatever the number of connections, and
find_one_actionsreturns large documents as a digest with sections loaded on request - The consent screen sets Full access, Read & write, Read only or a ticked list of actions per connection, and One enforces the grant on every call
- Access tokens last one hour, and changing or revoking a grant in the dashboard applies on the agent's next call
- Every plan, Free included, lists the same platforms and controls. Plans differ by requests per minute (20, 100, 500), organisations and projects, with no overage charge
- The server is in the official MCP registry as
ai.withone/mcp, and the CLI had 14 npm releases between 25 August and 6 October 2026
Weaknesses
- The remote server's tools changed from four to three by 30 September 2026, and the site's changelog, last dated 13 July 2026, has no entry for it
- The home and security pages say nothing from a call is stored. The privacy policy says request logs may include integration payloads, kept 14 to 90 days by default
- The SOC 2 audit is described as in progress,
/.well-known/security.txtreturned 404, and no bug bounty or published advisories were found execute_one_actiontakes a free-formdatabody and returns the upstream response whole. No control on response size was found- The Data Processing Agreement is available only on request, and no deprecation policy was found
Before you call it notes for agents
- Call
list_one_integrationsfirst and read each connection'saccessfield. When the policy isactions, run those ids directly without callingfind_one_actions - Send every operation a task needs in one
find_one_actionscall, up to 10requests, each a platform and a short intent with no IDs, names or message text - When a document comes back as a digest, call
find_one_actionsagain withloadand asectionname. Don't guess parameters the digest left out - After a timeout on
execute_one_action, check whether the write took effect before sending it again. No idempotency key is documented - A 403 for a call outside the grant won't succeed on retry. Ask the user to widen the grant in the dashboard or reconnect
Who's behind it provenance 72/100
- Legal entity namedOne Systems, Inc.20/20
- Domain agewithone.ai, registered 2026-01-22 (under a year)0/15
- Endpoint on the vendor's domainmcp.withone.ai15/15
- Terms of serviceread, states 6 of the 7 things a reader expects, and has 1 clause that costs points7.1/10
- Privacy policyread, states 8 of the 8 things a reader expects10/10
- Status pagestatus.withone.ai10/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2026-03-06, states 6 of 7, 1 to know
TL;DR Dated 2026-03-06. States 6 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, limits on benchmarking.
Restricts benchmarking or competitive usecosts points
Use the Services to build a competing product
A clause against publishing test results or using the service to build something that competes.
Gives the date it was last updated Last updated 2026-03-06
Last updated March 6, 2026
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of California
These Terms are governed by the laws of the State of California, without regard to conflict of law principles.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at the fees paid in the 12 months before the claim
Our total liability for any claim arising from these Terms or the Services shall not exceed the amount you paid us in the 12 months preceding the claim.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
We may suspend or terminate accounts that violate these Terms or pose a security risk.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Gives 30 days of notice before a change
Material changes will be communicated via email or through the Services with at least 30 days' notice.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
Reverse engineer or attempt to extract source code from the Services
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
The customer grants a licence to use its data to improve the Services as well as to run them.
You grant us a limited license to use your data solely to provide and improve the Services.
Noted by a second reader on 2026-10-08.
Fees are non-refundable except as required by law, and pricing may change with 30 days' notice.
All fees are non-refundable except as required by law. We may change pricing with 30 days' notice.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-09 · 1,052 words
Privacy policy dated 2026-07-22, states 8 of 8
TL;DR Dated 2026-07-22. States all 8 things a reader expects. The rules found no clause to flag.
Gives the date it was last updated Last updated 2026-07-22
Last updated July 22, 2026
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
When you create an account, we collect your name, email address, and authentication credentials.
The basic statement a privacy policy exists to make.
Says how long data is kept Names a period of 30 days
Life of the account, then deleted from production systems within 30 days of account deletion;
Says when data sent to the service is deleted.
Says who else receives the data
We use a small number of third-party providers for cloud infrastructure, website hosting, payment processing, analytics, and email delivery.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising Says it does not sell personal data
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
A plain statement either way.
Says what rights people have over their data
You have the right to know, access, correct, delete, and port your personal information, and the right not to be discriminated against for exercising these rights.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact Gives an email address, hidden from our reader by the page
Our processing of Customer Data is governed by our Data Processing Agreement, available on request at [email protected], which incorporates this policy's security commitments.
An address or officer to send a request to.
Says where data is transferred or stored Relies on standard contractual clauses
Where the GDPR or UK GDPR applies, we rely on Standard Contractual Clauses (including the UK International Data Transfer Addendum), incorporated into our Data Processing Agreement, as the legal mechanism for these transfers.
The countries data goes to and the safeguard used.
The policy says content, Customer Data and integration credentials are never used to train AI models, and subprocessors are not permitted to use them for model training.
We do not use your content or Customer Data to train AI models.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-09 · 2,031 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The Terms of Service, last updated 6 March 2026, name One Systems, Inc. of San Francisco and cover the website, platform, APIs and SDKs under California law. No state of incorporation is given.
The privacy policy, last updated 22 July 2026, governs account and usage data. For data passing through connected apps it points to a Data Processing Agreement that is available on request and not published.
RDAP gives a registration date of 2026-01-22 for withone.ai. The product traded as Pica on picaos.com before 25 March 2026.
www.withone.ai/.well-known/security.txt returned 404. The security page gives security@withone.ai for disclosure.
status.withone.ai is a Better Stack page created in March 2025. We did not find a link to it on the vendor pages we read.
The MCP server answers at mcp.withone.ai and the REST API at api.withone.ai.
Checked 2026-10-09 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-10 00:51 UTC
Probed every five minutes at https://mcp.withone.ai/mcp. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials. Last note, asks for credentials.
- Vendor status page unknown, no machine-readable status found · 3 minutes ago
- github
withoneai/mcp2.0.0, released 2026-09-30 - npm
@withone/cli2.6.0 - npm
@withone/mcp2.0.0 - GitHub stars 11
- npm downloads a week 681
Pages we watch
| Page | Kind | Last checked | Last changed |
|---|---|---|---|
| www.withone.ai/changelog | changelog | 5 hours ago · 200 | no change seen |
| www.withone.ai/pricing | pricing | 5 hours ago · 200 | no change seen |
| www.withone.ai/privacy | privacy | 5 hours ago · 200 | no change seen |
| www.withone.ai/terms | terms | 5 hours ago · 200 | no change seen |
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/one.json
Tools it lists
https://mcp.withone.ai/mcp asks for credentials before it lists its tools, so we can't show them without an account. Checked 3 hours ago.
Notable
- Pica was renamed One on 25 March 2026 per the changelog, and
https://www.picaos.comanswered 301 tohttps://withone.ai/on 9 October 2026 source - The remote server at
https://mcp.withone.ai/mcpwas announced on 13 July 2026. It answered 401 with aresource_metadatapointer when we called it without a token source - The docs list three tools with annotations.
list_one_integrationsandfind_one_actionsare read-only, andexecute_one_actionis destructive and open-world source - The 13 July 2026 changelog entry says the remote server has four tools. The docs and server card now list three, and the local package replaced
search_one_platform_actionsandget_one_action_knowledgewithfind_one_actionsin 2.0.0 on 30 September 2026 source - OAuth metadata on
mcp.withone.ailists six connection scopes, dynamic client registration for public clients and PKCE with S256 only source - The pricing page gives Free, Starter at $29 a month and Pro at $199 a month, each with 1M requests a month and 20, 100 and 500 requests a minute. Over the limit the API answers 429 and nothing extra is billed source
- The knowledge base is published under the One Knowledge Commons Licence v1.0, which bars use in a competing knowledge base and requires a commercial licence from integration vendors with revenue above $1,000,000. The vendor calls it open source. It is not an OSI licence source
- The privacy policy, last updated 22 July 2026, says One does not use customer content or Customer Data to train AI models and does not permit its sub-processors to source
- status.withone.ai runs on Better Stack with four components (API, Dashboard, Embeddable Auth, Website). Its JSON feed shows one API downtime of about 12 minutes on 15 April 2026 and none since source
- The site carries text addressed to AI models. llms.txt has a list of user queries mapped to One products, and the MCP repository has an installation guide written for AI agents. We read both as data and did not act on them source
- The CLI sends usage telemetry to PostHog by default, recording the command path only per the docs.
ONE_NO_TELEMETRY=1orDO_NOT_TRACKturns it off source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 9 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 16.4 | |
| Read with the hosted lines. status.withone.ai lists API, Dashboard, Embeddable Auth and Website with daily history (20). Its feed shows no downtime in the last 90 days and no incidents posted from August to October 2026. The last recorded downtime was about 12 minutes on the API on 15 April 2026. The MCP host is not a component of its own, so 25 of 30 (25). Rate limits are published per plan at 20, 100 and 500 requests a minute, per account (15). Over the limit the API answers 429 and requests pass again as the limit refills, and a timed-out call tells the agent to check whether a write took effect. No Retry-After header and no idempotency key were found (7). The Enterprise plan lists an SLA with no published figure (5). The remote server was announced on 13 July 2026 with no beta or preview label (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 12.5 | |
The three tools have typed inputs in the open-source local server, and the REST API has a public OpenAPI 3.1 file with 245 operations (25). llms.txt and a Markdown twin of every page (10). Tool descriptions state purpose, order of use and when not to call execute_one_action (17). find_one_actions bounds its arrays at 1 to 10, but data, queryParams and platform are untyped or free strings with no enums (7). The docs give request examples for find_one_actions and a short list of failure types, and the OpenAPI file documents 400 to 503 responses on most operations (10). The API sits under /v1/ and registry versions are numbered, but the site's changelog has no entry after 13 July 2026 and does not record the change from four tools to three (8). We could not read the remote server's live tool schemas without an account. The remote docs use action_id and connection_key where the local source uses actionId and connectionKey. | |||
| Agent ergonomics | 13%16.2 | 11.9 | |
Three compact tools however many apps are connected. The vendor puts the definitions at about 1.2K tokens, which we did not measure (25). find_one_actions takes up to 10 operations in one call and returns large documents as a digest, with sections, a table of contents or the whole document on request. execute_one_action returns the upstream response whole, with no size control found (14). Failures come back as tool errors the agent can read, a call outside the grant is refused with a reason, and a missing token gets a 401 with a WWW-Authenticate pointer. No error code catalogue for the MCP server was found (14). The docs give read-only annotations on two tools and destructive and open-world on execute_one_action. We could not confirm them on the live server, the local package's source sets none, and there is no idempotency key (12). list_one_integrations takes no parameters and execute_one_action needs three. Beyond the MCP server and the Node CLI, no SDK in two languages was found for this surface (8). | |||
| Security & auth | 14%17.5 | 12.1 | |
OAuth 2.1 authorisation code with PKCE, scopes, one-hour access tokens, and a grant that can be narrowed or revoked from the dashboard with effect on the next call (30). Read only, Read & write, Full access and per-action levels for each connection, plus a knowledge-only mode with no execution. execute_one_action is marked destructive so a client can ask first, and no server-side approval step was found (17). execute_one_action returns third-party content. Credentials are redacted from responses and sensitive headers stripped from the request echo, and no guidance on prompt injection was found (4). The dashboard logs agent, app, action and outcome per call, including refused calls, with retention of 14 to 90 days. No export or log API was confirmed (12). security@withone.ai is given for disclosure. security.txt returned 404, the SOC 2 audit is in progress, and no bounty or published advisories were found (6). | |||
| Payments & pricing | 10%12.5 | 3.8 | |
| No x402, MPP or L402 (0). Plan prices are public with their limits, $0, $29 and $199 a month, and nothing is billed over the limit. There is no per-call price and Enterprise is on contract, so 15 of 20 (15). The Free plan includes every platform and 1M requests a month. The pricing page doesn't say whether sign-up needs a card and we did not create an account, so 15 of 20 (15). A person must sign in through a browser to approve the grant or create an API key (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 7.5 | |
@withone/cli 2.5.0 was published on 6 October 2026 and @withone/mcp 2.0.0 on 30 September (30). The CLI had 14 npm releases between 25 August and 6 October and the MCP package had nine between 12 August and 30 September (20). In the CLI repository an outside pull request was merged the day it was opened in August, and two outside issues opened on 31 August 2026 had no reply on 9 October (14). The server is in the official MCP registry as ai.withone/mcp, version 2.0.0, under the vendor's domain namespace (15). The CLI runs CI on Node 18, 20 and 22 on Linux and Windows. The MCP repository has tests but only a publish workflow (7). | |||
| Transparency & trusteditorial 54, provenance 72 | 7%8.8 | 5.5 | |
| The editorial half. A closed hosted service under Terms of Service that name One Systems, Inc. The local MCP package is MIT, the CLI has no licence, and the knowledge base the vendor calls open source is under its own licence with anti-competition and revenue-threshold terms (15). The privacy policy has a retention table, a 72-hour breach notice and a commitment not to train AI models on customer content. The home and security pages say nothing from a call is stored, while the policy says request logs may include integration payloads for 14 to 90 days, and the DPA is not published (18). No deprecation policy or dated sunset notices were found. The terms promise 30 days' notice of price changes and material changes to the terms (3). The sub-processor list, updated 22 July 2026, names Google Cloud Platform in the United States for Customer Data and six service providers with locations (18). | |||
| Negative events | ≤15 |
| -3 |
| Total | 66.6 · B | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 20 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on One, or have the agent fetch /fixes/one.md. A fix counts at the next check, once it's public.
Show it
# Fix list: One From Anchor Terminal's listing at https://www.anchorterminal.com/tools/one, the October 2026 research run, assessed 9 October 2026. Grade B, 66.6 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on One: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Payments & pricing, 30 out of 100, up to 8.8 more on the total Why it scored 30: No x402, MPP or L402 (0). Plan prices are public with their limits, $0, $29 and $199 a month, and nothing is billed over the limit. There is no per-call price and Enterprise is on contract, so 15 of 20 (15). The Free plan includes every platform and 1M requests a month. The pricing page doesn't say whether sign-up needs a card and we did not create an account, so 15 of 20 (15). A person must sign in through a browser to approve the grant or create an API key (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 2. Security & auth, 69 out of 100, up to 5.4 more on the total Why it scored 69: OAuth 2.1 authorisation code with PKCE, scopes, one-hour access tokens, and a grant that can be narrowed or revoked from the dashboard with effect on the next call (30). Read only, Read & write, Full access and per-action levels for each connection, plus a knowledge-only mode with no execution. `execute_one_action` is marked destructive so a client can ask first, and no server-side approval step was found (17). `execute_one_action` returns third-party content. Credentials are redacted from responses and sensitive headers stripped from the request echo, and no guidance on prompt injection was found (4). The dashboard logs agent, app, action and outcome per call, including refused calls, with retention of 14 to 90 days. No export or log API was confirmed (12). security@withone.ai is given for disclosure. security.txt returned 404, the SOC 2 audit is in progress, and no bounty or published advisories were found (6). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 3. Agent ergonomics, 73 out of 100, up to 4.4 more on the total Why it scored 73: Three compact tools however many apps are connected. The vendor puts the definitions at about 1.2K tokens, which we did not measure (25). `find_one_actions` takes up to 10 operations in one call and returns large documents as a digest, with sections, a table of contents or the whole document on request. `execute_one_action` returns the upstream response whole, with no size control found (14). Failures come back as tool errors the agent can read, a call outside the grant is refused with a reason, and a missing token gets a 401 with a `WWW-Authenticate` pointer. No error code catalogue for the MCP server was found (14). The docs give read-only annotations on two tools and destructive and open-world on `execute_one_action`. We could not confirm them on the live server, the local package's source sets none, and there is no idempotency key (12). `list_one_integrations` takes no parameters and `execute_one_action` needs three. Beyond the MCP server and the Node CLI, no SDK in two languages was found for this surface (8). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 4. Schema & documentation, 77 out of 100, up to 3.7 more on the total Why it scored 77: The three tools have typed inputs in the open-source local server, and the REST API has a public OpenAPI 3.1 file with 245 operations (25). llms.txt and a Markdown twin of every page (10). Tool descriptions state purpose, order of use and when not to call `execute_one_action` (17). `find_one_actions` bounds its arrays at 1 to 10, but `data`, `queryParams` and `platform` are untyped or free strings with no enums (7). The docs give request examples for `find_one_actions` and a short list of failure types, and the OpenAPI file documents 400 to 503 responses on most operations (10). The API sits under `/v1/` and registry versions are numbered, but the site's changelog has no entry after 13 July 2026 and does not record the change from four tools to three (8). We could not read the remote server's live tool schemas without an account. The remote docs use `action_id` and `connection_key` where the local source uses `actionId` and `connectionKey`. The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 5. Reliability, 82 out of 100, up to 3.6 more on the total Why it scored 82: Read with the hosted lines. status.withone.ai lists API, Dashboard, Embeddable Auth and Website with daily history (20). Its feed shows no downtime in the last 90 days and no incidents posted from August to October 2026. The last recorded downtime was about 12 minutes on the API on 15 April 2026. The MCP host is not a component of its own, so 25 of 30 (25). Rate limits are published per plan at 20, 100 and 500 requests a minute, per account (15). Over the limit the API answers 429 and requests pass again as the limit refills, and a timed-out call tells the agent to check whether a write took effect. No Retry-After header and no idempotency key were found (7). The Enterprise plan lists an SLA with no published figure (5). The remote server was announced on 13 July 2026 with no beta or preview label (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 6. Transparency & trust, 63 out of 100, up to 3.2 more on the total Made of editorial 54, provenance 72. Why it scored 63: The editorial half. A closed hosted service under Terms of Service that name One Systems, Inc. The local MCP package is MIT, the CLI has no licence, and the knowledge base the vendor calls open source is under its own licence with anti-competition and revenue-threshold terms (15). The privacy policy has a retention table, a 72-hour breach notice and a commitment not to train AI models on customer content. The home and security pages say nothing from a call is stored, while the policy says request logs may include integration payloads for 14 to 90 days, and the DPA is not published (18). No deprecation policy or dated sunset notices were found. The terms promise 30 days' notice of price changes and material changes to the terms (3). The sub-processor list, updated 22 July 2026, names Google Cloud Platform in the United States for Customer Data and six service providers with locations (18). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Domain age: withone.ai, registered 2026-01-22 (under a year) (0 of 15) - Terms of service: read, states 6 of the 7 things a reader expects, and has 1 clause that costs points (7.1 of 10) - security.txt: not found (0 of 10) ## 7. Maintenance & community, 86 out of 100, up to 1.2 more on the total Why it scored 86: `@withone/cli` 2.5.0 was published on 6 October 2026 and `@withone/mcp` 2.0.0 on 30 September (30). The CLI had 14 npm releases between 25 August and 6 October and the MCP package had nine between 12 August and 30 September (20). In the CLI repository an outside pull request was merged the day it was opened in August, and two outside issues opened on 31 August 2026 had no reply on 9 October (14). The server is in the official MCP registry as `ai.withone/mcp`, version 2.0.0, under the vendor's domain namespace (15). The CLI runs CI on Node 18, 20 and 22 on Linux and Windows. The MCP repository has tests but only a publish workflow (7). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## Deductions Each comes off the total. A fixed and documented problem counts for less at the next check. - Between 13 July and 30 September 2026 the remote MCP server's tools changed from four to three. The changelog entry of 13 July 2026 says the remote server has the same four tools as the local one, and the local package's 2.0.0 commit of 30 September 2026 removes `search_one_platform_actions` and `get_one_action_knowledge` for `find_one_actions`, which it calls the tool the remote server already serves. The site's changelog has no entry for the change. The local package marked it as a major version. Three points off (https://www.withone.ai/changelog, https://github.com/withoneai/mcp). ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: the remote server's live `tools/list`, including input schemas and annotation hints, because reading it needs an account and we did not create one. Tool schemas were read from the open-source local package, which the docs say has the same three tools - unchecked: whether sign-up for the Free plan needs a card. The pricing page doesn't say and we did not sign up - unchecked: the dashboard's activity log, its export options and any log API - unchecked: the Data Processing Agreement, which is available only on request - The date the remote server moved from four tools to three. The evidence gives only a window from 13 July to 30 September 2026 - Whether refused and failed calls count against the 1M requests a month, and whether a 429 carries a Retry-After header - Whether the monthly figure on the pricing page or the unlimited API calls on the API authentication page is current - The state of incorporation of One Systems, Inc., which the terms and privacy policy do not give - The lead named the vendor as One. The legal entity on the terms is One Systems, Inc. The rest of the lead held ## Weaknesses - The remote server's tools changed from four to three by 30 September 2026, and the site's changelog, last dated 13 July 2026, has no entry for it - The home and security pages say nothing from a call is stored. The privacy policy says request logs may include integration payloads, kept 14 to 90 days by default - The SOC 2 audit is described as in progress, `/.well-known/security.txt` returned 404, and no bug bounty or published advisories were found - `execute_one_action` takes a free-form `data` body and returns the upstream response whole. No control on response size was found - The Data Processing Agreement is available only on request, and no deprecation policy was found ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Call `list_one_integrations` first and read each connection's `access` field. When the policy is `actions`, run those ids directly without calling `find_one_actions` - Send every operation a task needs in one `find_one_actions` call, up to 10 `requests`, each a platform and a short intent with no IDs, names or message text - When a document comes back as a digest, call `find_one_actions` again with `load` and a `section` name. Don't guess parameters the digest left out - After a timeout on `execute_one_action`, check whether the write took effect before sending it again. No idempotency key is documented - A 403 for a call outside the grant won't succeed on retry. Ask the user to widen the grant in the dashboard or reconnect ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: the remote server's live
tools/list, including input schemas and annotation hints, because reading it needs an account and we did not create one. Tool schemas were read from the open-source local package, which the docs say has the same three tools - unchecked: whether sign-up for the Free plan needs a card. The pricing page doesn't say and we did not sign up
- unchecked: the dashboard's activity log, its export options and any log API
- unchecked: the Data Processing Agreement, which is available only on request
- The date the remote server moved from four tools to three. The evidence gives only a window from 13 July to 30 September 2026
- Whether refused and failed calls count against the 1M requests a month, and whether a 429 carries a Retry-After header
- Whether the monthly figure on the pricing page or the unlimited API calls on the API authentication page is current
- The state of incorporation of One Systems, Inc., which the terms and privacy policy do not give
- The lead named the vendor as One. The legal entity on the terms is One Systems, Inc. The rest of the lead held
Sources 34
- robots.txt with Content-Signal ai-input=yes withone.ai · seen 2026-10-09
- llms.txt withone.ai · seen 2026-10-09
- agent catalogue withone.ai · seen 2026-10-09
- MCP server card withone.ai · seen 2026-10-09
- MCP docs withone.ai · seen 2026-10-09
- MCP product page withone.ai · seen 2026-10-09
- CLI docs withone.ai · seen 2026-10-09
- getting started withone.ai · seen 2026-10-09
- pricing withone.ai · seen 2026-10-09
- changelog withone.ai · seen 2026-10-09
- security overview withone.ai · seen 2026-10-09
- enterprise page withone.ai · seen 2026-10-09
- Terms of Service withone.ai · seen 2026-10-09
- privacy policy withone.ai · seen 2026-10-09
- sub-processors withone.ai · seen 2026-10-09
- One Knowledge Commons Licence withone.ai · seen 2026-10-09
- API authentication withone.ai · seen 2026-10-09
- Management API overview withone.ai · seen 2026-10-09
- Connect management, refusals and logs withone.ai · seen 2026-10-09
- OpenAPI file withone.ai · seen 2026-10-09
- security.txt (404) withone.ai · seen 2026-10-09
- status page status.withone.ai · seen 2026-10-09
- status page JSON feed status.withone.ai · seen 2026-10-09
- status page incident history status.withone.ai · seen 2026-10-09
- OAuth protected resource metadata mcp.withone.ai · seen 2026-10-09
- OAuth authorisation server metadata mcp.withone.ai · seen 2026-10-09
- MCP server repository (tool schemas, server.json, commits) github.com · seen 2026-10-09
- CLI repository (CI, telemetry source) github.com · seen 2026-10-09
- knowledge repository github.com · seen 2026-10-09
- CLI issues and pull requests api.github.com · seen 2026-10-09
- npm metadata for the MCP package registry.npmjs.org · seen 2026-10-09
- npm metadata for the CLI registry.npmjs.org · seen 2026-10-09
- official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-09
- RDAP record for withone.ai rdap.org · seen 2026-10-09
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium $29 / mo Free is $0 with 1M requests a month, 20 requests a minute, one organisation and one project. Starter is $29 a month at 100 requests a minute and Pro is $199 a month at 500, each with 1M requests a month. Enterprise is priced on contract. Requests over the limit answer 429 and there is no overage charge. A cloud agent on a dedicated server is $40 a month on any plan. The pricing page doesn't say whether sign-up needs a card. The API authentication page says both environments include unlimited API calls, which doesn't match the 1M a month on the pricing page (https://www.withone.ai/pricing, checked 2026-10-09).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Starter plan | $29 | per month (plan) | 1M requests a month, 100 requests a minute, 20 organisations and 20 projects |
| Pro plan | $199 | per month (plan) | 1M requests a month, 500 requests a minute, 100 organisations and 100 projects |
| Cloud agent on a dedicated server | $40 | per month (plan) | Per agent, added to any plan |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/one.xml, or this listing's score history at history.json.
Connect
Install
npm install -g @withone/cli && one init
Claude Code
claude mcp add --transport http one https://mcp.withone.ai/mcp
MCP client configuration
{
"mcpServers": {
"one": {
"type": "http",
"url": "https://mcp.withone.ai/mcp"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/one
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Alternatives to One
#4 of 8 in Best agent tool access platforms · All 28 tool access comparisons
Merge Agent Handler BStackOne BComposio (API + MCP) BBUnified.to MCP Server CZapier MCP (agent actions) CSmithery D
Head to head Composio (API + MCP) vs One · Merge Agent Handler vs One · One vs Smithery · One vs StackOne · One vs Unified.to MCP Server · One vs Zapier MCP (agent actions) · letme vs One
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Merge Agent Handler Merge API, Inc. | B | 69.5 | automation.apps automation.auth automation.actions agent.tools auth.audit | no |
| StackOne StackOne Technologies Limited | B | 69.1 | automation.apps automation.auth automation.actions agent.tools auth.audit | no |
| Composio (API + MCP) Composio | BB | 75.1 | automation.apps automation.auth automation.actions agent.tools | no |
| Unified.to MCP Server Unified API Inc. | C | 61.9 | automation.apps automation.auth automation.actions agent.tools | no |
| Zapier MCP (agent actions) Zapier | C | 58.1 | automation.apps automation.auth automation.actions agent.tools | no |
| Smithery Smithery (Arcade.dev) | D | 50.7 | automation.apps automation.auth automation.actions agent.tools | no |
Machine-readable
- JSON
/api/v1/tools/one.json· historyhistory.json· badge/badges/one.svg· changes feed/feeds/tools/one.xml - Markdown
/tools/one.md· slim/tools/one.min.md(or sendAccept: text/markdown) - Fix list
/fixes/one.md·/fixes/one.json - From a terminal
anchor tool one --md(the CLI) · over MCPget_tool {"slug": "one"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/one"><img src="https://www.anchorterminal.com/badges/one.svg" alt="One on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/one)<a href="https://www.anchorterminal.com/tools/one">One on Anchor Terminal</a>It counts on a page on withone.ai or one of its subdomains, or the README of github.com/withoneai/mcp.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "one", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


