# One > One is a hosted MCP server and CLI from One Systems, Inc. (formerly Pica) that lets AI agents find and run actions in a user's connected apps, with credentials held by One and access scoped per connection. - Canonical: https://www.anchorterminal.com/tools/one - Markdown: https://www.anchorterminal.com/tools/one.md (~8,250 tokens) - Slim: https://www.anchorterminal.com/tools/one.min.md (~1,730 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/one.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-10 ## Overview **Grade B · 66.6/100 · rank #282 of 950 · #4 in Agent tool access · not agent-ready · confidence medium** ## Assessment One's remote MCP server has three tools, OAuth 2.1 sign-in with PKCE and a consent screen that sets read only, read and write, full or per-action access for each connection. A person must sign in through a browser, the SOC 2 audit is unfinished, and the site's changelog stops at 13 July 2026. ## Facts | Field | Value | | --- | --- | | Vendor | One Systems, Inc. (https://www.withone.ai) | | Kind | MCP server | | Category | Agent tool access (https://www.anchorterminal.com/categories/aggregator) | | Transport | Streamable HTTP, stdio | | Endpoint | `https://mcp.withone.ai/mcp` | | Auth | OAuth or key · Self-serve. The remote server uses OAuth 2.1 authorisation code with PKCE (S256). The client registers itself at `https://mcp.withone.ai/oauth/register` as a public client, a person signs in to One in a browser, and the consent screen picks the account, Production or Sandbox, and an access level per connection. Scopes are `connections:read` and `connections:write` under `user:`, `org:` and `project:`, and a client that asks for none gets all six. Access tokens last one hour, with a 30-day refresh token when the client registers that grant. The local package and the REST API take an API key in the `x-one-secret` header, and a key created through the CLI's browser sign-in carries the same per-connection limits. Third-party accounts are connected in the dashboard or with `one add `, and One stores those credentials. | | Pricing | Freemium ($29 / mo) · Free is $0 with 1M requests a month, 20 requests a minute, one organisation and one project. Starter is $29 a month at 100 requests a minute and Pro is $199 a month at 500, each with 1M requests a month. Enterprise is priced on contract. Requests over the limit answer 429 and there is no overage charge. A cloud agent on a dedicated server is $40 a month on any plan. The pricing page doesn't say whether sign-up needs a card. The API authentication page says both environments include unlimited API calls, which doesn't match the 1M a month on the pricing page (https://www.withone.ai/pricing, checked 2026-10-09). | | x402 | No · No x402, MPP or L402 in llms.txt, the MCP docs, the pricing page or the OpenAPI file. The API's 402 responses are described as a plan quota, not a payment protocol (checked 2026-10-09). | | Licence | Proprietary hosted service under One's Terms of Service. The local MCP server package `@withone/mcp` is MIT. The CLI package `@withone/cli` has no licence field or licence file. The knowledge base is under the One Knowledge Commons Licence v1.0, which is not an OSI licence | | Tools exposed | 3 | | Packages | npm: `@withone/mcp`; npm: `@withone/cli` | | MCP registry name | `ai.withone/mcp` | | Source | https://github.com/withoneai/mcp | | Docs | https://www.withone.ai/docs/mcp | | llms.txt | https://www.withone.ai/llms.txt | | Last release | 2026-10-06 | | GitHub stars | 11 (as of 2026-10-09) | | npm downloads / week | 681 | | MCP endpoint | `https://mcp.withone.ai/mcp`, Streamable HTTP, OAuth sign-in in the browser. The server card gives version 0.1.0 | | Tools | `list_one_integrations`, `find_one_actions` and `execute_one_action`. Knowledge-only mode leaves `find_one_actions` alone on the remote server | | Access levels | Full access, Read & write (GET, POST, PUT, PATCH), Read only (GET) or Custom (ticked actions), set per connection on the consent screen and enforced on every call | | OAuth | Authorisation code with PKCE (S256), dynamic client registration for public clients, six connection scopes, 1-hour access tokens, 30-day refresh tokens | | Coverage | 952 platforms and 127,943 actions per the vendor's llms.txt on 9 October 2026. The registry entry for the server says 700+ apps | | Local server | `@withone/mcp` 2.0.0 on npm (30 September 2026), stdio, API key in `ONE_SECRET`, limits set with `ONE_PERMISSIONS`, `ONE_CONNECTION_KEYS` and `ONE_ACTION_IDS` | | CLI | `@withone/cli` 2.5.0 on npm (6 October 2026), Node.js 18 or later. `one list`, `one actions find` and `one actions execute` mirror the three tools | | REST API | OpenAPI 3.1 file, version 5.35.0, with 245 operations on 161 paths at `https://api.withone.ai`. Calls to connected apps go through `/v1/passthrough/{key}` | | Rate limits | 20, 100 and 500 requests a minute on Free, Starter and Pro, per account across every key. 429 over the limit | | Logs | The dashboard records agent, app, action and outcome for each call, including refused calls. Log retention is 14 to 90 days by default per the privacy policy | | Hosting | Google Cloud Platform in the United States is the only sub-processor of Customer Data on the list updated 22 July 2026 | | Certifications | None completed. A SOC 2 Type II audit is described as under way, with the report to be shared under NDA | | Capabilities | automation.apps, automation.auth, automation.actions, agent.tools, auth.audit | | Tags | hosted, mcp, freemium, free-tier, oauth, openapi, llms-txt, cli, typescript, status-page, mcp-registry | | JSON | https://www.anchorterminal.com/api/v1/tools/one.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 82 | 16.4 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 77 | 12.5 | | Agent ergonomics | 13% | 16.2 | 73 | 11.9 | | Security & auth | 14% | 17.5 | 69 | 12.1 | | Payments & pricing | 10% | 12.5 | 30 | 3.8 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 86 | 7.5 | | Transparency & trust (editorial 54, provenance 72) | 7% | 8.8 | 63 | 5.5 | | Negative events | up to −15 | up to −15 | Between 13 July and 30 September 2026 the remote MCP server's tools changed from four to three. The changelog entry of 13 July 2026 says the remote server has the same four tools as the local one, and the local package's 2.0.0 commit of 30 September 2026 removes `search_one_platform_actions` and `get_one_action_knowledge` for `find_one_actions`, which it calls the tool the remote server already serves. The site's changelog has no entry for the change. The local package marked it as a major version. Three points off (https://www.withone.ai/changelog, https://github.com/withoneai/mcp). | -3 | | **Total** | | | | **66.6 → B** | ### Why each score - Reliability 82: Read with the hosted lines. status.withone.ai lists API, Dashboard, Embeddable Auth and Website with daily history (20). Its feed shows no downtime in the last 90 days and no incidents posted from August to October 2026. The last recorded downtime was about 12 minutes on the API on 15 April 2026. The MCP host is not a component of its own, so 25 of 30 (25). Rate limits are published per plan at 20, 100 and 500 requests a minute, per account (15). Over the limit the API answers 429 and requests pass again as the limit refills, and a timed-out call tells the agent to check whether a write took effect. No Retry-After header and no idempotency key were found (7). The Enterprise plan lists an SLA with no published figure (5). The remote server was announced on 13 July 2026 with no beta or preview label (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 77: The three tools have typed inputs in the open-source local server, and the REST API has a public OpenAPI 3.1 file with 245 operations (25). llms.txt and a Markdown twin of every page (10). Tool descriptions state purpose, order of use and when not to call `execute_one_action` (17). `find_one_actions` bounds its arrays at 1 to 10, but `data`, `queryParams` and `platform` are untyped or free strings with no enums (7). The docs give request examples for `find_one_actions` and a short list of failure types, and the OpenAPI file documents 400 to 503 responses on most operations (10). The API sits under `/v1/` and registry versions are numbered, but the site's changelog has no entry after 13 July 2026 and does not record the change from four tools to three (8). We could not read the remote server's live tool schemas without an account. The remote docs use `action_id` and `connection_key` where the local source uses `actionId` and `connectionKey`. - Agent ergonomics 73: Three compact tools however many apps are connected. The vendor puts the definitions at about 1.2K tokens, which we did not measure (25). `find_one_actions` takes up to 10 operations in one call and returns large documents as a digest, with sections, a table of contents or the whole document on request. `execute_one_action` returns the upstream response whole, with no size control found (14). Failures come back as tool errors the agent can read, a call outside the grant is refused with a reason, and a missing token gets a 401 with a `WWW-Authenticate` pointer. No error code catalogue for the MCP server was found (14). The docs give read-only annotations on two tools and destructive and open-world on `execute_one_action`. We could not confirm them on the live server, the local package's source sets none, and there is no idempotency key (12). `list_one_integrations` takes no parameters and `execute_one_action` needs three. Beyond the MCP server and the Node CLI, no SDK in two languages was found for this surface (8). - Security & auth 69: OAuth 2.1 authorisation code with PKCE, scopes, one-hour access tokens, and a grant that can be narrowed or revoked from the dashboard with effect on the next call (30). Read only, Read & write, Full access and per-action levels for each connection, plus a knowledge-only mode with no execution. `execute_one_action` is marked destructive so a client can ask first, and no server-side approval step was found (17). `execute_one_action` returns third-party content. Credentials are redacted from responses and sensitive headers stripped from the request echo, and no guidance on prompt injection was found (4). The dashboard logs agent, app, action and outcome per call, including refused calls, with retention of 14 to 90 days. No export or log API was confirmed (12). security@withone.ai is given for disclosure. security.txt returned 404, the SOC 2 audit is in progress, and no bounty or published advisories were found (6). - Payments & pricing 30: No x402, MPP or L402 (0). Plan prices are public with their limits, $0, $29 and $199 a month, and nothing is billed over the limit. There is no per-call price and Enterprise is on contract, so 15 of 20 (15). The Free plan includes every platform and 1M requests a month. The pricing page doesn't say whether sign-up needs a card and we did not create an account, so 15 of 20 (15). A person must sign in through a browser to approve the grant or create an API key (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 86: `@withone/cli` 2.5.0 was published on 6 October 2026 and `@withone/mcp` 2.0.0 on 30 September (30). The CLI had 14 npm releases between 25 August and 6 October and the MCP package had nine between 12 August and 30 September (20). In the CLI repository an outside pull request was merged the day it was opened in August, and two outside issues opened on 31 August 2026 had no reply on 9 October (14). The server is in the official MCP registry as `ai.withone/mcp`, version 2.0.0, under the vendor's domain namespace (15). The CLI runs CI on Node 18, 20 and 22 on Linux and Windows. The MCP repository has tests but only a publish workflow (7). - Transparency & trust 63: The editorial half. A closed hosted service under Terms of Service that name One Systems, Inc. The local MCP package is MIT, the CLI has no licence, and the knowledge base the vendor calls open source is under its own licence with anti-competition and revenue-threshold terms (15). The privacy policy has a retention table, a 72-hour breach notice and a commitment not to train AI models on customer content. The home and security pages say nothing from a call is stored, while the policy says request logs may include integration payloads for 14 to 90 days, and the DPA is not published (18). No deprecation policy or dated sunset notices were found. The terms promise 30 days' notice of price changes and material changes to the terms (3). The sub-processor list, updated 22 July 2026, names Google Cloud Platform in the United States for Customer Data and six service providers with locations (18). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (20 items): https://www.anchorterminal.com/fixes/one.md (JSON https://www.anchorterminal.com/fixes/one.json) ### What we couldn't check - unchecked: the remote server's live `tools/list`, including input schemas and annotation hints, because reading it needs an account and we did not create one. Tool schemas were read from the open-source local package, which the docs say has the same three tools - unchecked: whether sign-up for the Free plan needs a card. The pricing page doesn't say and we did not sign up - unchecked: the dashboard's activity log, its export options and any log API - unchecked: the Data Processing Agreement, which is available only on request - The date the remote server moved from four tools to three. The evidence gives only a window from 13 July to 30 September 2026 - Whether refused and failed calls count against the 1M requests a month, and whether a 429 carries a Retry-After header - Whether the monthly figure on the pricing page or the unlimited API calls on the API authentication page is current - The state of incorporation of One Systems, Inc., which the terms and privacy policy do not give - The lead named the vendor as One. The legal entity on the terms is One Systems, Inc. The rest of the lead held ### Sources - robots.txt with Content-Signal ai-input=yes: (seen 2026-10-09) - llms.txt: (seen 2026-10-09) - agent catalogue: (seen 2026-10-09) - MCP server card: (seen 2026-10-09) - MCP docs: (seen 2026-10-09) - MCP product page: (seen 2026-10-09) - CLI docs: (seen 2026-10-09) - getting started: (seen 2026-10-09) - pricing: (seen 2026-10-09) - changelog: (seen 2026-10-09) - security overview: (seen 2026-10-09) - enterprise page: (seen 2026-10-09) - Terms of Service: (seen 2026-10-09) - privacy policy: (seen 2026-10-09) - sub-processors: (seen 2026-10-09) - One Knowledge Commons Licence: (seen 2026-10-09) - API authentication: (seen 2026-10-09) - Management API overview: (seen 2026-10-09) - Connect management, refusals and logs: (seen 2026-10-09) - OpenAPI file: (seen 2026-10-09) - security.txt (404): (seen 2026-10-09) - status page: (seen 2026-10-09) - status page JSON feed: (seen 2026-10-09) - status page incident history: (seen 2026-10-09) - OAuth protected resource metadata: (seen 2026-10-09) - OAuth authorisation server metadata: (seen 2026-10-09) - MCP server repository (tool schemas, server.json, commits): (seen 2026-10-09) - CLI repository (CI, telemetry source): (seen 2026-10-09) - knowledge repository: (seen 2026-10-09) - CLI issues and pull requests: (seen 2026-10-09) - npm metadata for the MCP package: (seen 2026-10-09) - npm metadata for the CLI: (seen 2026-10-09) - official MCP registry search: (seen 2026-10-09) - RDAP record for withone.ai: (seen 2026-10-09) ## Who's behind it (provenance 72/100, checked 2026-10-09) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | One Systems, Inc. | 20/20 | | Domain age | withone.ai, registered 2026-01-22 (under a year) | 0/15 | | Endpoint on the vendor's domain | mcp.withone.ai | 15/15 | | Terms of service | read, states 6 of the 7 things a reader expects, and has 1 clause that costs points | 7.1/10 | | Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 | | Status page | status.withone.ai | 10/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The Terms of Service, last updated 6 March 2026, name One Systems, Inc. of San Francisco and cover the website, platform, APIs and SDKs under California law. No state of incorporation is given. The privacy policy, last updated 22 July 2026, governs account and usage data. For data passing through connected apps it points to a Data Processing Agreement that is available on request and not published. RDAP gives a registration date of 2026-01-22 for withone.ai. The product traded as Pica on picaos.com before 25 March 2026. www.withone.ai/.well-known/security.txt returned 404. The security page gives security@withone.ai for disclosure. status.withone.ai is a Better Stack page created in March 2025. We did not find a link to it on the vendor pages we read. The MCP server answers at mcp.withone.ai and the REST API at api.withone.ai. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.withone.ai/terms), read 2026-10-09, dated 2026-03-06, states 6 of the 7 things a reader expects. - To know. Restricts benchmarking or competitive use (costs points). "Use the Services to build a competing product" - Gives the date it was last updated. Last updated 2026-03-06. - Names the governing law or courts. The law of the State of California. - States a limit on its liability. Capped at the fees paid in the 12 months before the claim. - Says how changes to the terms are announced. Gives 30 days of notice before a change. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). The customer grants a licence to use its data to improve the Services as well as to run them. "You grant us a limited license to use your data solely to provide and improve the Services." - Also in the text (2026-10-08). Fees are non-refundable except as required by law, and pricing may change with 30 days' notice. "All fees are non-refundable except as required by law. We may change pricing with 30 days' notice." **Privacy policy** (https://www.withone.ai/privacy), read 2026-10-09, dated 2026-07-22, states 8 of the 8 things a reader expects. - Gives the date it was last updated. Last updated 2026-07-22. - Says how long data is kept. Names a period of 30 days. - Says whether personal data is sold or shared for advertising. Says it does not sell personal data. - Gives a privacy contact. Gives an email address, hidden from our reader by the page. - Says where data is transferred or stored. Relies on standard contractual clauses. - Also in the text (2026-10-08). The policy says content, Customer Data and integration credentials are never used to train AI models, and subprocessors are not permitted to use them for model training. "We do not use your content or Customer Data to train AI models." ## Live (updated 2026-10-10 02:07 UTC) - Right now: up, HTTP 401, 186 ms, checked 2026-10-10 02:07 UTC (mcp-initialize on `https://mcp.withone.ai/mcp`, asks for auth) - Uptime 24h 100.0% (107 probes) · 30 days 100.0% (107 probes) · p50 171 ms · p95 260 ms - Vendor status page: unknown, no machine-readable status found - github `withoneai/mcp` 2.0.0, released 2026-09-30 - npm `@withone/cli` 2.6.0 - npm `@withone/mcp` 2.0.0 - Watching changelog - Watching pricing - Watching privacy - Watching terms - Tools: the endpoint asks for credentials before listing them (checked 2026-10-09 21:40 UTC) - Always current: https://www.anchorterminal.com/api/v1/live/one.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Starter plan | $29 | per month (plan) | 1M requests a month, 100 requests a minute, 20 organisations and 20 projects | | Pro plan | $199 | per month (plan) | 1M requests a month, 500 requests a minute, 100 organisations and 100 projects | | Cloud agent on a dedicated server | $40 | per month (plan) | Per agent, added to any plan | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - The remote server has three tools whatever the number of connections, and `find_one_actions` returns large documents as a digest with sections loaded on request - The consent screen sets Full access, Read & write, Read only or a ticked list of actions per connection, and One enforces the grant on every call - Access tokens last one hour, and changing or revoking a grant in the dashboard applies on the agent's next call - Every plan, Free included, lists the same platforms and controls. Plans differ by requests per minute (20, 100, 500), organisations and projects, with no overage charge - The server is in the official MCP registry as `ai.withone/mcp`, and the CLI had 14 npm releases between 25 August and 6 October 2026 ## Weaknesses - The remote server's tools changed from four to three by 30 September 2026, and the site's changelog, last dated 13 July 2026, has no entry for it - The home and security pages say nothing from a call is stored. The privacy policy says request logs may include integration payloads, kept 14 to 90 days by default - The SOC 2 audit is described as in progress, `/.well-known/security.txt` returned 404, and no bug bounty or published advisories were found - `execute_one_action` takes a free-form `data` body and returns the upstream response whole. No control on response size was found - The Data Processing Agreement is available only on request, and no deprecation policy was found ## Before you call it (notes for agents) 1. Call `list_one_integrations` first and read each connection's `access` field. When the policy is `actions`, run those ids directly without calling `find_one_actions` 2. Send every operation a task needs in one `find_one_actions` call, up to 10 `requests`, each a platform and a short intent with no IDs, names or message text 3. When a document comes back as a digest, call `find_one_actions` again with `load` and a `section` name. Don't guess parameters the digest left out 4. After a timeout on `execute_one_action`, check whether the write took effect before sending it again. No idempotency key is documented 5. A 403 for a call outside the grant won't succeed on retry. Ask the user to widen the grant in the dashboard or reconnect ## Connect Install: ```bash npm install -g @withone/cli && one init ``` Claude Code: ```bash claude mcp add --transport http one https://mcp.withone.ai/mcp ``` MCP client configuration: ```json { "mcpServers": { "one": { "type": "http", "url": "https://mcp.withone.ai/mcp" } } } ``` Through letme (picks today, calling later): https://letme.dev/one. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Merge Agent Handler | B | 69.5 | 183 | automation.apps, automation.auth, automation.actions, agent.tools, auth.audit | no | https://www.anchorterminal.com/tools/merge-agent-handler.md | | StackOne | B | 69.1 | 198 | automation.apps, automation.auth, automation.actions, agent.tools, auth.audit | no | https://www.anchorterminal.com/tools/stackone.md | | Composio (API + MCP) | BB | 75.1 | 55 | automation.apps, automation.auth, automation.actions, agent.tools | no | https://www.anchorterminal.com/tools/composio-rube.md | | Unified.to MCP Server | C | 61.9 | 455 | automation.apps, automation.auth, automation.actions, agent.tools | no | https://www.anchorterminal.com/tools/unified-to-mcp.md | | Zapier MCP (agent actions) | C | 58.1 | 588 | automation.apps, automation.auth, automation.actions, agent.tools | no | https://www.anchorterminal.com/tools/zapier-mcp.md | | Smithery | D | 50.7 | 766 | automation.apps, automation.auth, automation.actions, agent.tools | no | https://www.anchorterminal.com/tools/smithery.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - Pica was renamed One on 25 March 2026 per the changelog, and `https://www.picaos.com` answered 301 to `https://withone.ai/` on 9 October 2026 (source: ) - The remote server at `https://mcp.withone.ai/mcp` was announced on 13 July 2026. It answered 401 with a `resource_metadata` pointer when we called it without a token (source: ) - The docs list three tools with annotations. `list_one_integrations` and `find_one_actions` are read-only, and `execute_one_action` is destructive and open-world (source: ) - The 13 July 2026 changelog entry says the remote server has four tools. The docs and server card now list three, and the local package replaced `search_one_platform_actions` and `get_one_action_knowledge` with `find_one_actions` in 2.0.0 on 30 September 2026 (source: ) - OAuth metadata on `mcp.withone.ai` lists six connection scopes, dynamic client registration for public clients and PKCE with S256 only (source: ) - The pricing page gives Free, Starter at $29 a month and Pro at $199 a month, each with 1M requests a month and 20, 100 and 500 requests a minute. Over the limit the API answers 429 and nothing extra is billed (source: ) - The knowledge base is published under the One Knowledge Commons Licence v1.0, which bars use in a competing knowledge base and requires a commercial licence from integration vendors with revenue above $1,000,000. The vendor calls it open source. It is not an OSI licence (source: ) - The privacy policy, last updated 22 July 2026, says One does not use customer content or Customer Data to train AI models and does not permit its sub-processors to (source: ) - status.withone.ai runs on Better Stack with four components (API, Dashboard, Embeddable Auth, Website). Its JSON feed shows one API downtime of about 12 minutes on 15 April 2026 and none since (source: ) - The site carries text addressed to AI models. llms.txt has a list of user queries mapped to One products, and the MCP repository has an installation guide written for AI agents. We read both as data and did not act on them (source: ) - The CLI sends usage telemetry to PostHog by default, recording the command path only per the docs. `ONE_NO_TELEMETRY=1` or `DO_NOT_TRACK` turns it off (source: ) - #4 of 8 in Best agent tool access platforms: https://www.anchorterminal.com/best/aggregator/index.md - All 28 tool access comparisons: https://www.anchorterminal.com/compare/aggregator/index.md ## Compare - [Composio (API + MCP) vs One](https://www.anchorterminal.com/compare/composio-rube-vs-one.md): BB 75.1 vs B 66.6 - [Merge Agent Handler vs One](https://www.anchorterminal.com/compare/merge-agent-handler-vs-one.md): B 69.5 vs B 66.6 - [One vs Smithery](https://www.anchorterminal.com/compare/one-vs-smithery.md): B 66.6 vs D 50.7 - [One vs StackOne](https://www.anchorterminal.com/compare/one-vs-stackone.md): B 66.6 vs B 69.1 - [One vs Unified.to MCP Server](https://www.anchorterminal.com/compare/one-vs-unified-to-mcp.md): B 66.6 vs C 61.9 - [One vs Zapier MCP (agent actions)](https://www.anchorterminal.com/compare/one-vs-zapier-mcp.md): B 66.6 vs C 58.1 - [letme vs One](https://www.anchorterminal.com/compare/letme-vs-one.md): F 36.4 vs B 66.6 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on withone.ai or one of its subdomains, or the README of github.com/withoneai/mcp. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "one", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html One on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![One on Anchor Terminal](https://www.anchorterminal.com/badges/one.svg)](https://www.anchorterminal.com/tools/one) ``` Plain link: ```html One on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say One is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/one-dark.png - Light: https://www.anchorterminal.com/assets/share/one-light.png