# One (slim) > One is a hosted MCP server and CLI from One Systems, Inc. (formerly Pica) that lets AI agents find and run actions in a user's connected apps, with credentials held by One and access scoped per connection. - Full: https://www.anchorterminal.com/tools/one.md (~8,250 tokens) · this version ~1,730 tokens · JSON https://www.anchorterminal.com/tools/one.json · canonical https://www.anchorterminal.com/tools/one - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-10 **B · 66.6/100 · rank #282 of 950 · #4 in Agent tool access · not agent-ready · confidence medium** Assessment: One's remote MCP server has three tools, OAuth 2.1 sign-in with PKCE and a consent screen that sets read only, read and write, full or per-action access for each connection. A person must sign in through a browser, the SOC 2 audit is unfinished, and the site's changelog stops at 13 July 2026. ## Facts - Kind: MCP server · vendor: One Systems, Inc. · category: Agent tool access · legal entity: One Systems, Inc. · provenance 72/100 - Endpoint: `https://mcp.withone.ai/mcp` (Streamable HTTP, stdio) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary hosted service under One's Terms of Service. The local MCP server package `@withone/mcp` is MIT. The CLI package `@withone/cli` has no licence field or licence file. The knowledge base is under the One Knowledge Commons Licence v1.0, which is not an OSI licence - Probe metrics: not measured yet (probes haven't run) - MCP endpoint: `https://mcp.withone.ai/mcp`, Streamable HTTP, OAuth sign-in in the browser. The server card gives version 0.1.0 - Tools: `list_one_integrations`, `find_one_actions` and `execute_one_action`. Knowledge-only mode leaves `find_one_actions` alone on the remote server - Access levels: Full access, Read & write (GET, POST, PUT, PATCH), Read only (GET) or Custom (ticked actions), set per connection on the consent screen and enforced on every call - OAuth: Authorisation code with PKCE (S256), dynamic client registration for public clients, six connection scopes, 1-hour access tokens, 30-day refresh tokens - Coverage: 952 platforms and 127,943 actions per the vendor's llms.txt on 9 October 2026. The registry entry for the server says 700+ apps - Local server: `@withone/mcp` 2.0.0 on npm (30 September 2026), stdio, API key in `ONE_SECRET`, limits set with `ONE_PERMISSIONS`, `ONE_CONNECTION_KEYS` and `ONE_ACTION_IDS` - CLI: `@withone/cli` 2.5.0 on npm (6 October 2026), Node.js 18 or later. `one list`, `one actions find` and `one actions execute` mirror the three tools - REST API: OpenAPI 3.1 file, version 5.35.0, with 245 operations on 161 paths at `https://api.withone.ai`. Calls to connected apps go through `/v1/passthrough/{key}` - Rate limits: 20, 100 and 500 requests a minute on Free, Starter and Pro, per account across every key. 429 over the limit - Logs: The dashboard records agent, app, action and outcome for each call, including refused calls. Log retention is 14 to 90 days by default per the privacy policy - Hosting: Google Cloud Platform in the United States is the only sub-processor of Customer Data on the list updated 22 July 2026 - Certifications: None completed. A SOC 2 Type II audit is described as under way, with the report to be shared under NDA - Prices: Starter plan $29 per month (plan); Pro plan $199 per month (plan); Cloud agent on a dedicated server $40 per month (plan) - Scores: Reliability 82, Performance pending, Schema & documentation 77, Agent ergonomics 73, Security & auth 69, Payments & pricing 30, Task success pending, Maintenance & community 86, Transparency & trust 63 · negative events -3 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines. · Schema & documentation, The three tools have typed inputs in the open-source local server, and the REST API has a public OpenAPI 3.1 file with 245 operations (25). · Agent ergonomics, Three compact tools however many apps are connected. · Security & auth, OAuth 2.1 authorisation code with PKCE, scopes, one-hour access tokens, and a grant that can be narrowed or revoked from the dashboard with… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, `@withone/cli` 2.5.0 was published on 6 October 2026 and `@withone/mcp` 2.0.0 on 30 September (30). · Transparency & trust, The editorial half. - Sources: 34, open questions: 9, both in the full twin - Capabilities: automation.apps, automation.auth, automation.actions, agent.tools, auth.audit - JSON: https://www.anchorterminal.com/api/v1/tools/one.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/one.svg` or a link to https://www.anchorterminal.com/tools/one from a page on withone.ai or one of its subdomains, or the README of github.com/withoneai/mcp, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Call `list_one_integrations` first and read each connection's `access` field. When the policy is `actions`, run those ids directly without calling `find_one_actions` 2. Send every operation a task needs in one `find_one_actions` call, up to 10 `requests`, each a platform and a short intent with no IDs, names or message text 3. When a document comes back as a digest, call `find_one_actions` again with `load` and a `section` name. Don't guess parameters the digest left out 4. After a timeout on `execute_one_action`, check whether the write took effect before sending it again. No idempotency key is documented 5. A 403 for a call outside the grant won't succeed on retry. Ask the user to widen the grant in the dashboard or reconnect ## Connect ```bash npm install -g @withone/cli && one init ``` ```bash claude mcp add --transport http one https://mcp.withone.ai/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/one ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Merge Agent Handler | B | 69.5 | automation.apps, automation.auth, automation.actions, agent.tools, auth.audit | https://www.anchorterminal.com/tools/merge-agent-handler.min.md | | StackOne | B | 69.1 | automation.apps, automation.auth, automation.actions, agent.tools, auth.audit | https://www.anchorterminal.com/tools/stackone.min.md | | Composio (API + MCP) | BB | 75.1 | automation.apps, automation.auth, automation.actions, agent.tools | https://www.anchorterminal.com/tools/composio-rube.min.md | | Unified.to MCP Server | C | 61.9 | automation.apps, automation.auth, automation.actions, agent.tools | https://www.anchorterminal.com/tools/unified-to-mcp.min.md | | Zapier MCP (agent actions) | C | 58.1 | automation.apps, automation.auth, automation.actions, agent.tools | https://www.anchorterminal.com/tools/zapier-mcp.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)