StackOne

by StackOne Technologies Limited MCP server in Agent tool access

Hosted

StackOne Technologies Limited · stackone.com since 2013 · status page · who's behind it

StackOne is a hosted gateway from StackOne Technologies Limited that gives AI agents actions across more than 540 business apps over MCP, SDKs, A2A or HTTP, with managed authentication, per-user grants, policies and logs.

Good for A company that wants one governed MCP endpoint for staff agents across business systems, and product teams embedding per-customer connections with HR, recruiting and CRM coverage.

Is this your product? Claim this listing or verify it

Assessment. StackOne's MCP server signs each person in with OAuth, lets them grant individual accounts and actions, and by default exposes two search and execute tools in place of the full catalogue. Session token URLs carry the credential in the query string for a year by default, and the Consumption Schedule and pricing page disagree on whether failed calls are billed.

Facts

Transport
Streamable HTTP, HTTP
Endpoint
https://mcp.stackone.com/mcp
Auth
OAuth or key
Pricing
Freemium · $600 / mo
x402
No
Licence
Proprietary service under StackOne's SaaS Terms and Conditions. The Agent SDKs (`@stackone/ai`, `stackone-ai`) and the Defender package (`@stackone/defender`) are Apache-2.0
Packages
npm @stackone/ai
pypi stackone-ai
npm @stackone/defender
MCP registry
com.stackone/mcp
llms.txt
published
Last release
GitHub stars
30
npm / week
277
MCP endpoints
https://mcp.stackone.com/mcp with OAuth for people using a client, https://api.stackone.com/mcp with an API key and x-account-id for backends, and https://api.stackone.com/mcp?token=<session_token> for unattended use. Streamable HTTP, POST only, stateless, no SSE
Tool modes
individual registers one tool per enabled action. search_execute registers {provider}_search_actions (top_k default 10, maximum 50) and {provider}_execute_action. Set with ?tool-mode= or at the consent screen
Other interfaces
POST /actions/rpc and GET /actions over HTTP, Agent SDKs for TypeScript and Python, and A2A agents at https://a2a.stackone.com, which the docs mark as open beta
Connectors
546 live connectors and more than 33,470 actions per the site index, a vendor figure. Connectors carry semver versions and a connector profile can pin latest, 1.x.x, 1.2.x or one version
Credentials
OAuth grants per user (one-hour access tokens, 90 days, revocable), project API keys with five scope groups, and session tokens fixed to one linked account with a one-year default expiry
End-user authorisation
Linked accounts created in the dashboard, through the embedded StackOne Hub or by an auth link. StackOne's shared OAuth apps or the customer's own
Rate limits
1,000 requests a minute per API key. 429 carries Retry-After in seconds. Provider 429s are retried up to five times within a 60-second request lifetime, then 429 or 408 is returned
Free plan
Gateway Starter, 1,000 credits a seat a month, one project, action logs kept one day, no card. OEM Core is free with a monthly credit allowance
Governance
Connector profiles enable or disable each action. Policies (Team and Enterprise) deny tools, mask fields, bound values and redact PII per user or group. SAML SSO on Team, IP allowlists on Enterprise
Defender
Pattern matching and a local MiniLM classifier on every tool result. Modes Monitor (default), Sanitize and Block. The hosted Deep Scan adds an LLM review that StackOne says runs on its own inference endpoints
Logs
Action logs kept 1, 7 or 30 days on Gateway Starter, Team and Enterprise. Advanced Logs store request and response bodies, off by default, for 1, 7 or 30 days. Logs API, audit logs and SIEM export on Enterprise and OEM plans as listed
Hosting
AWS eu-west-1 (Dublin), GCP europe-west1 (Belgium) and AWS us-east-1 (N. Virginia), chosen per project and fixed at creation. Other regions and self-hosting are Enterprise add-ons
Certifications
SOC 2 Type II, GDPR and HIPAA per the pricing and contact pages, with the SOC 2 report and a Business Associate Agreement on Enterprise. The trust centre answered our reader with a bot check
SDKs
@stackone/ai 2.10.0 (27 July 2026, Node 20.19.6 or later) and stackone-ai 2.10.1 (28 July 2026, Python 3.11 or later), both Apache-2.0. Platform API clients for TypeScript and Ruby, with PHP, Java and C# in beta

Facts verified 2026-10-09 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • The MCP server at https://mcp.stackone.com/mcp uses OAuth per person. Access tokens last one hour, a grant lasts 90 days, and each user can revoke it under Connected Apps
  • Advanced Tool Search replaces the tool list with two tools, search and execute, and is on by default at the OAuth consent screen
  • Since 24 July 2026 every tool carries readOnlyHint, destructiveHint and openWorldHint, derived from an effects value on each action
  • API keys are limited to one project and take scopes for the Platform API, Actions, Connectors, Credentials and the Unified API. Credentials access is off by default
  • Rate limit published at 1,000 requests a minute per API key, with Retry-After in seconds on 429 and 408 responses
  • Defender scans tool results for prompt injection and is on for new projects. Its Light Scan engine is open source under Apache-2.0

Weaknesses

  • Session token URLs (https://api.stackone.com/mcp?token=...) put the credential in the query string, cover one linked account and expire after one year by default
  • The Service Consumption Schedule counts every request, successful or not, as an Action Call. The pricing page says failed calls aren't billed
  • Defender's default mode is Monitor, which records a verdict and passes the tool result to the agent unchanged
  • Policies apply only to signed-in members. A call made with a project API key is memberless and is governed by connector profile scoping alone
  • The Logs API, audit logs, SIEM export and an uptime SLA are Enterprise only on Gateway plans, and Starter keeps action logs for one day
  • The Acceptable Use Policy bars competitive analysis or benchmarking other than for internal comparison, and probing or testing the Service's vulnerability without authorisation. This matters before any probe is run
  • @stackone/ai stamped tools with the wrong x-account-id when accounts were fetched concurrently, until v2.8.1 on 27 April 2026. No advisory was found

Before you call it notes for agents

  1. Send Accept: application/json,text/event-stream on every MCP request to https://api.stackone.com/mcp, by POST only. Without it the server answers 406
  2. In search_execute mode call {provider}_search_actions first and pass the returned action_id to {provider}_execute_action. Never hardcode action ids
  3. Pass the API key as the Basic auth username with an empty password, and name the linked account in x-account-id
  4. On 429 or 408 wait the seconds given in Retry-After. StackOne has already retried a provider's 429 up to five times within a 60-second request lifetime
  5. On 412 read errorCode and details.statusReasons. AccountErrorStatus needs a person to re-authenticate the linked account

Who's behind it provenance 88/100

  • Legal entity namedStackOne Technologies Limited20/20
  • Domain agestackone.com, registered 2013-06-25 (13 years)15/15
  • Endpoint on the vendor's domainmcp.stackone.com15/15
  • Terms of serviceread, states 6 of the 7 things a reader expects9.1/10
  • Privacy policyread, states 6 of the 8 things a reader expects8.5/10
  • Status pagestatus.stackone.com10/10
  • Changelogpublished10/10
  • security.txtnot found0/10

Terms and privacy, as read

Terms of service dated 2026-03-30, states 6 of 7

TL;DR Dated 2026-03-30. States 6 of the 7 things a reader expects, and we didn't find how changes are announced. The rules found no clause to flag.

Gives the date it was last updated Last updated 2026-03-30
Last updated: March 30, 2026

Without a date nobody can tell which version they agreed to.

Names the governing law or courts The law of England and Wales
The Agreement and any disputes or claims arising out of or in connection with it shall be governed by the laws of England and Wales and the parties submit to the exclusive jurisdiction of the courts of England and Wales.

Says where a dispute would be heard and under whose law.

States a limit on its liability Rules out indirect and consequential losses, with no cap named in this sentence
EXCEPT AS SET FORTH IN CLAUSE 11.5 (EXCLUDED LIABILITIES), IN NO EVENT SHALL EITHER PARTY OR ITS AFFILIATES (INCLUDING THEIR DIRECTORS, OFFICERS, EMPLOYEES, REPRESENTATIVES, AGENTS, AND SUPPLIERS) BE LIABLE FOR ANY INDIRECT, INCIDENTAL, RELIANCE, SPECIAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES, INCLUDING LOSS OF PROFITS,…

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
Either party may terminate this Agreement or any Customer Order for cause with immediate effect and without prejudice to any other rights or remedies to which the parties may be entitled by written notice if the other party: (a) materially breaches this Agreement and fails to cure such breach within thirty (30) days a…

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced

Not found in the text.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
If Customer does not agree to this Agreement, Customer must not access or use the Service.

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment
Preview Features are provided “as is” without any warranty, indemnity, service level commitment, or support obligation, except as set out in Clause 2.6(b) with respect to Preview Connectors.

Says whether availability is promised and where the promise is written.

StackOne may anonymise data derived from the customer's use of the service and use it for its own purposes, including developing and improving the service.
StackOne may use Anonymised Data for its own purposes, including to develop and improve the Service.

Noted by a second reader on 2026-10-08.

Each Customer Order renews automatically for successive one-year periods, or another period the order specifies.
Each Customer Order shall have the initial term specified therein and shall automatically renew for successive periods of one (1) year, or for any other period specified in a Customer Order (each a “Renewal Term”)

Noted by a second reader on 2026-10-08.

StackOne may display the customer's name and logo on its website and in marketing materials.
StackOne may use and display Customer’s name and logo (“Customer Marks”) on its website and in marketing materials to identify Customer as a customer.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-09 · 6,983 words

Privacy policy dated 2023-12-01, states 6 of 8

TL;DR Dated 2023-12-01. States 6 of the 8 things a reader expects, and we didn't find whether data is sold or where data goes. The rules found no clause to flag.

Gives the date it was last updated Last updated 2023-12-01
Last updated: December 1, 2023

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
We may collect certain information, including personal information, from you as a data controller.

The basic statement a privacy policy exists to make.

Says how long data is kept Names a period of 30 days
Unless specifically requested by a Customer, StackOne shall retain data no longer than 30 days after a Customer has ceased instructing StackOne.

Says when data sent to the service is deleted.

Says who else receives the data
We share data with third-party partners for the purposes of providing the StackOne services, including but not limited to registered users’ email addresses and device information for the purpose of providing better user experience, in compliance with all applicable data protection laws and regulations.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising

Not found in the text.

A plain statement either way.

Says what rights people have over their data
StackOne acknowledges that you have the right to access your personal information.

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact dpo@stackone.com
If you have any questions relating to any of this policy then please email us at dpo@stackone.com.

An address or officer to send a request to.

Says where data is transferred or stored

Not found in the text.

The countries data goes to and the safeguard used.

Data from a closed account enters an expired state and may be retained for up to 90 days.
Expired account data may be retained for up to 90 days.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-09 · 1,468 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The SaaS Terms and Conditions, effective 30 March 2026, name StackOne Technologies Limited, company number 14684360, registered at 2 Communications Road, Newbury, Berkshire, RG19 6AB, under the laws of England and Wales. They take effect when a customer first accesses the Service or signs an order.

The contact page says StackOne operates in the United States as StackOne Technologies Inc., 2261 Market Street, San Francisco.

The Platform Privacy Policy, last updated 1 December 2023, covers the web application and API and says it does not cover the website. A separate Privacy Notice covers the website.

The MCP server answers at mcp.stackone.com, the API at api.stackone.com and A2A at a2a.stackone.com.

www.stackone.com/.well-known/security.txt returned 404.

RDAP for stackone.com gives a registration date of 2013-06-25. The company was incorporated later, per its company number.

status.stackone.com runs on incident.io and lists the Web Dashboard, the API (US, EU and UK) and the Connectors Hub.

trust.stackone.com, which the terms cite for the security policy and the sub-processor list, answered our reader with a bot check and was not read.

Checked 2026-10-09 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-10 00:51 UTC

Right nowUpHTTP 401 · 99 ms · 1 minute ago
Uptime 24h100.0%94 probes
Uptime 30 days100.0%94 probes
p50 24h103 msmcp-initialize
p95 24h251 msanswers, asks for auth

Probed every five minutes at https://mcp.stackone.com/mcp. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials. Last note, asks for credentials.

  • Vendor status page all systems normal, All Systems Operational · 2 minutes ago
  • github StackOneHQ/stackone-ai-node v2.10.0, released 2026-07-27
  • npm @stackone/ai 2.10.0
  • npm @stackone/defender 0.8.3
  • pypi stackone-ai 2.10.1, released 2026-07-28
  • GitHub stars 30
  • npm downloads a week 277
  • PyPI downloads a week 120

Pages we watch

PageKindLast checkedLast changed
www.stackone.com/changelogchangelog5 hours ago · 200no change seen
www.stackone.com/pricingpricing5 hours ago · 200no change seen
www.stackone.com/terms/privacy-policyprivacy5 hours ago · 200no change seen
www.stackone.com/terms/saas-termsterms5 hours ago · 200no change seen

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/stackone.json

Tools it lists

https://mcp.stackone.com/mcp asks for credentials before it lists its tools, so we can't show them without an account. Checked 3 hours ago.

Notable

  • One MCP URL for a whole organisation. It carries no access on its own, and each person signs in and picks the linked accounts and actions the client may use source
  • The site index counts 546 live connectors and more than 33,470 actions, a vendor figure. The Slack connector page lists 50 actions at connector version 4.0.0 source
  • Tool annotations on every tool since 24 July 2026. readOnlyHint is true when every effect is read or search, destructiveHint when any effect is delete, and idempotentHint is never inferred source
  • Policies deny tools, mask fields, bound argument values and redact PII per user or group, on Gateway Team and Enterprise. They don't apply to calls made with a project API key source
  • Defender is on for new projects in Monitor mode at the Low protection level, and responses over 1 MB or 10,000 words skip scanning by default source
  • The official MCP registry lists com.stackone/mcp version 1.0.1, published 17 August 2026, with the remote https://mcp.stackone.com/mcp source
  • The published OpenAPI 3.1 file holds 30 operations on 19 paths under /v2. The actions, logs and MCP endpoints are described on their own reference pages source
  • Every Markdown docs page opens with a line telling the reader to fetch the docs index, and the introduction gives a prompt for users to paste into an agent. We read both as data source
  • The site's llms.txt lists the legal documents under /legal/, where each answered 404 on 9 October 2026. The working pages are under /terms/ source
  • The Acceptable Use Policy bars benchmarking other than for internal comparison and vulnerability testing without authorisation source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 9 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 16.0
Read with the hosted lines. status.stackone.com on incident.io lists the Web Dashboard, the API in three regions and the Connectors Hub (20). The page shows July to October 2026 at 100 per cent for the dashboard, the hub and the US and UK API, and 99.990 per cent for the EU API. The incident list is drawn by script and was not read, so 20 of 30 (20). API keys are limited to 1,000 requests a minute (15). 429 responses carry Retry-After in seconds, and StackOne retries a provider's 429 up to five times within a 60-second request lifetime before returning 429 or 408. No idempotency key or retry guidance for writes was found (10). The pricing page lists an uptime SLA on Enterprise with no figure, and the Starter plan has none (5). MCP and the RPC endpoint carry no beta label. A2A is in open beta (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 12.7
An OpenAPI 3.1 file is published for the Platform API (30 operations under /v2), the actions, logs and MCP endpoints have reference pages with embedded definitions, and the docs say each MCP tool has a JSON Schema. Live tool schemas were not read, since that needs an account (22). llms.txt for the docs and the site, and a Markdown twin of every docs page (10). Connector pages give one line per action, such as 'Send a message to a channel or conversation', with the provider scopes each needs and no guidance on when not to use it (11). The Platform API types its parameters and has 26 enum uses, while POST /actions/rpc and the execute tool take open path, query, body and headers objects (9). curl, Python and TypeScript examples, eleven error statuses declared on every operation and a troubleshooting catalogue for MCP (13). /v2 paths, connector semver with version pins, per-connector changelogs and a dated product changelog. No API deprecation policy was found (13).
Agent ergonomics 13%16.2 12.2
The catalogue is large, and individual mode registers one tool per enabled action, which scores 5. Ten back for the two-tool search and execute mode (on by default at the OAuth consent screen), per-action grants and connector profile scoping (15). List endpoints take page and page_size with a total, filters and field expansion, tool search takes top_k, and Deep Query returns counts or chosen fields. Offset paging can skip or repeat records, as the docs warn (16). Errors carry statusCode, errorCode, details.statusReasons and provider errors, with documented causes for 400, 401, 406, 412 and the JSON-RPC codes (17). Every tool carries readOnlyHint and destructiveHint since July 2026. idempotentHint is set only by hand and tool calls take no idempotency key (14). Agent SDKs for TypeScript and Python and API clients in five languages. The mandatory Accept header and Basic auth encoding are extra steps (13).
Security & auth 14%17.5 12.1
OAuth per user with one-hour access tokens, a 90-day grant and revocation, and project API keys with scopes that can be disabled or deleted, would score 30. Ten off because session token URLs carry the access in the query string as a documented option, with a one-year default expiry (20). Connector profiles enable individual actions, users grant accounts and actions at consent, the Credentials scope is off by default, and Policies deny tools, mask fields and bound values on Team and Enterprise. Policies skip API-key calls, and no approval step at the gateway was found (16). Defender scans tool results and is on for new projects, in Monitor mode by default, which changes nothing. Large responses skip scanning by default (12). Action logs on every plan (one day on Starter), login security logs and Advanced Logs with credential masking. The Logs API, audit logs and SIEM export are Enterprise only on Gateway plans (11). SOC 2 Type II and HIPAA are stated on the pricing and contact pages, and the DPA promises breach notice within 48 hours. security.txt returned 404, no bounty or disclosure policy was found, and the trust centre answered with a bot check (10).
Payments & pricing 10%12.5 4.8
No x402, MPP or L402 (0). Credit prices are public. One credit per tool call or API call, extra credits at $60 per 20,000 on Starter and $20 per 20,000 on Team, and Team at $600 a month. Two off because the per-seat price sits only in the calculator's markup, the rates for advanced capabilities aren't published, and the Service Consumption Schedule and the pricing page disagree on failed calls (18). Free plans on both models with no card, per the pricing page (20). A person signs up in the dashboard, and no keyless or programmatic signup route was found (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 7.3
Changelog entry on 24 September 2026 (Deep Query) and @stackone/defender v0.8.3 on 23 September (30). Dated entries on 24 July, 3, 7 and 19 August, and 7 and 24 September (20). A closed service with a dated changelog and in-app chat and email support. The TypeScript SDK repository shows 7 open issues and commits on 9 October 2026 (11). com.stackone/mcp is in the official MCP registry under the vendor's domain namespace, version 1.0.1 of 17 August 2026 (15). The SDK repositories carry CI workflows, lockfiles and release automation. The newest Agent SDK releases are from late July (8).
Transparency & trusteditorial 50, provenance 88 7%8.8 6.0
The editorial half. Closed service under SaaS terms that name StackOne Technologies Limited, with the Agent SDKs and Defender under Apache-2.0 (17). The DPA of 15 January 2025 promises deletion within 30 days of termination and breach notice within 48 hours, and the AI Services Addendum says AI providers may not train on customer data. The privacy policy of December 2023 says data is stored in the EEA while projects can be created in a US region, and it gives 30 and 90 day retention periods side by side. The SaaS terms let StackOne use anonymised usage data to improve the Service (18). No deprecation policy for the API was found. Preview functions can be withdrawn at any time, and the Starter plan can change with 30 days' notice on a reasonable-efforts basis. Connector versions can be pinned (5). Three hosting regions are named with their data centres. The sub-processor list is on the trust centre, which we could not read. The DPA gives 14 days to object to a new sub-processor (10).
Negative events≤15
  • 27 April 2026. @stackone/ai v2.8.1 fixed a flaw in which tools fetched concurrently for several accounts were stamped with the wrong x-account-id, so a call could run against another linked account. It is recorded as a bug fix in the changelog, with no advisory found. Fixed and documented, so 2 points (https://github.com/StackOneHQ/stackone-ai-node/blob/main/CHANGELOG.md).
-2
Total69.1 · B

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 21 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on StackOne, or have the agent fetch /fixes/stackone.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: StackOne

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/stackone, the October 2026 research run, assessed 9 October 2026. Grade B, 69.1 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on StackOne: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Payments & pricing, 38 out of 100, up to 7.8 more on the total

Why it scored 38: No x402, MPP or L402 (0). Credit prices are public. One credit per tool call or API call, extra credits at $60 per 20,000 on Starter and $20 per 20,000 on Team, and Team at $600 a month. Two off because the per-seat price sits only in the calculator's markup, the rates for advanced capabilities aren't published, and the Service Consumption Schedule and the pricing page disagree on failed calls (18). Free plans on both models with no card, per the pricing page (20). A person signs up in the dashboard, and no keyless or programmatic signup route was found (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 2. Security & auth, 69 out of 100, up to 5.4 more on the total

Why it scored 69: OAuth per user with one-hour access tokens, a 90-day grant and revocation, and project API keys with scopes that can be disabled or deleted, would score 30. Ten off because session token URLs carry the access in the query string as a documented option, with a one-year default expiry (20). Connector profiles enable individual actions, users grant accounts and actions at consent, the Credentials scope is off by default, and Policies deny tools, mask fields and bound values on Team and Enterprise. Policies skip API-key calls, and no approval step at the gateway was found (16). Defender scans tool results and is on for new projects, in Monitor mode by default, which changes nothing. Large responses skip scanning by default (12). Action logs on every plan (one day on Starter), login security logs and Advanced Logs with credential masking. The Logs API, audit logs and SIEM export are Enterprise only on Gateway plans (11). SOC 2 Type II and HIPAA are stated on the pricing and contact pages, and the DPA promises breach notice within 48 hours. security.txt returned 404, no bounty or disclosure policy was found, and the trust centre answered with a bot check (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 3. Agent ergonomics, 75 out of 100, up to 4.1 more on the total

Why it scored 75: The catalogue is large, and `individual` mode registers one tool per enabled action, which scores 5. Ten back for the two-tool search and execute mode (on by default at the OAuth consent screen), per-action grants and connector profile scoping (15). List endpoints take `page` and `page_size` with a total, filters and field expansion, tool search takes `top_k`, and Deep Query returns counts or chosen fields. Offset paging can skip or repeat records, as the docs warn (16). Errors carry `statusCode`, `errorCode`, `details.statusReasons` and provider errors, with documented causes for 400, 401, 406, 412 and the JSON-RPC codes (17). Every tool carries `readOnlyHint` and `destructiveHint` since July 2026. `idempotentHint` is set only by hand and tool calls take no idempotency key (14). Agent SDKs for TypeScript and Python and API clients in five languages. The mandatory `Accept` header and Basic auth encoding are extra steps (13).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 4. Reliability, 80 out of 100, up to 4 more on the total

Why it scored 80: Read with the hosted lines. status.stackone.com on incident.io lists the Web Dashboard, the API in three regions and the Connectors Hub (20). The page shows July to October 2026 at 100 per cent for the dashboard, the hub and the US and UK API, and 99.990 per cent for the EU API. The incident list is drawn by script and was not read, so 20 of 30 (20). API keys are limited to 1,000 requests a minute (15). 429 responses carry `Retry-After` in seconds, and StackOne retries a provider's 429 up to five times within a 60-second request lifetime before returning 429 or 408. No idempotency key or retry guidance for writes was found (10). The pricing page lists an uptime SLA on Enterprise with no figure, and the Starter plan has none (5). MCP and the RPC endpoint carry no beta label. A2A is in open beta (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 5. Schema & documentation, 78 out of 100, up to 3.6 more on the total

Why it scored 78: An OpenAPI 3.1 file is published for the Platform API (30 operations under `/v2`), the actions, logs and MCP endpoints have reference pages with embedded definitions, and the docs say each MCP tool has a JSON Schema. Live tool schemas were not read, since that needs an account (22). llms.txt for the docs and the site, and a Markdown twin of every docs page (10). Connector pages give one line per action, such as 'Send a message to a channel or conversation', with the provider scopes each needs and no guidance on when not to use it (11). The Platform API types its parameters and has 26 enum uses, while `POST /actions/rpc` and the execute tool take open `path`, `query`, `body` and `headers` objects (9). curl, Python and TypeScript examples, eleven error statuses declared on every operation and a troubleshooting catalogue for MCP (13). `/v2` paths, connector semver with version pins, per-connector changelogs and a dated product changelog. No API deprecation policy was found (13).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 6. Transparency & trust, 69 out of 100, up to 2.7 more on the total

Made of editorial 50, provenance 88.

Why it scored 69: The editorial half. Closed service under SaaS terms that name StackOne Technologies Limited, with the Agent SDKs and Defender under Apache-2.0 (17). The DPA of 15 January 2025 promises deletion within 30 days of termination and breach notice within 48 hours, and the AI Services Addendum says AI providers may not train on customer data. The privacy policy of December 2023 says data is stored in the EEA while projects can be created in a US region, and it gives 30 and 90 day retention periods side by side. The SaaS terms let StackOne use anonymised usage data to improve the Service (18). No deprecation policy for the API was found. Preview functions can be withdrawn at any time, and the Starter plan can change with 30 days' notice on a reasonable-efforts basis. Connector versions can be pinned (5). Three hosting regions are named with their data centres. The sub-processor list is on the trust centre, which we could not read. The DPA gives 14 days to object to a new sub-processor (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Terms of service: read, states 6 of the 7 things a reader expects (9.1 of 10)
- Privacy policy: read, states 6 of the 8 things a reader expects (8.5 of 10)
- security.txt: not found (0 of 10)

## 7. Maintenance & community, 84 out of 100, up to 1.4 more on the total

Why it scored 84: Changelog entry on 24 September 2026 (Deep Query) and `@stackone/defender` v0.8.3 on 23 September (30). Dated entries on 24 July, 3, 7 and 19 August, and 7 and 24 September (20). A closed service with a dated changelog and in-app chat and email support. The TypeScript SDK repository shows 7 open issues and commits on 9 October 2026 (11). `com.stackone/mcp` is in the official MCP registry under the vendor's domain namespace, version 1.0.1 of 17 August 2026 (15). The SDK repositories carry CI workflows, lockfiles and release automation. The newest Agent SDK releases are from late July (8).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## Deductions

Each comes off the total. A fixed and documented problem counts for less at the next check.

- 27 April 2026. `@stackone/ai` v2.8.1 fixed a flaw in which tools fetched concurrently for several accounts were stamped with the wrong `x-account-id`, so a call could run against another linked account. It is recorded as a bug fix in the changelog, with no advisory found. Fixed and documented, so 2 points (https://github.com/StackOneHQ/stackone-ai-node/blob/main/CHANGELOG.md).

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: trust.stackone.com (security policy, sub-processor list, certifications, any disclosure programme), which answered our reader with a bot check. We did not retry
- unchecked: the incident list on status.stackone.com, which is drawn by script. Only the component uptime figures were read
- unchecked: live tool definitions from `tools/list`, including the size of schemas and the annotations, because reading them needs an account and we did not create one
- unchecked: api.stackone.com and mcp.stackone.com answered 403 to a robots.txt request, so no further request was sent to either, and the OAuth metadata was not read
- unchecked: weekly downloads of `stackone-ai` on PyPI
- Whether failed calls are billed. The pricing page says no and the Service Consumption Schedule counts them
- The credit cost of browser use, premium defence and data sync, and the figure in the Enterprise uptime SLA
- Whether the seat prices in the pricing calculator's markup ($15 a further seat on Team, 10 included) are what a customer is charged
- Whether the Platform Privacy Policy of December 2023, which says data is stored in the EEA, still describes projects created in the US region
- The Acceptable Use Policy bars benchmarking other than for internal comparison and vulnerability testing without authorisation, which matters before any probe is run

## Weaknesses

- Session token URLs (`https://api.stackone.com/mcp?token=...`) put the credential in the query string, cover one linked account and expire after one year by default
- The Service Consumption Schedule counts every request, successful or not, as an Action Call. The pricing page says failed calls aren't billed
- Defender's default mode is Monitor, which records a verdict and passes the tool result to the agent unchanged
- Policies apply only to signed-in members. A call made with a project API key is memberless and is governed by connector profile scoping alone
- The Logs API, audit logs, SIEM export and an uptime SLA are Enterprise only on Gateway plans, and Starter keeps action logs for one day
- The Acceptable Use Policy bars competitive analysis or benchmarking other than for internal comparison, and probing or testing the Service's vulnerability without authorisation. This matters before any probe is run
- `@stackone/ai` stamped tools with the wrong `x-account-id` when accounts were fetched concurrently, until v2.8.1 on 27 April 2026. No advisory was found

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Send `Accept: application/json,text/event-stream` on every MCP request to `https://api.stackone.com/mcp`, by POST only. Without it the server answers 406
- In `search_execute` mode call `{provider}_search_actions` first and pass the returned `action_id` to `{provider}_execute_action`. Never hardcode action ids
- Pass the API key as the Basic auth username with an empty password, and name the linked account in `x-account-id`
- On 429 or 408 wait the seconds given in `Retry-After`. StackOne has already retried a provider's 429 up to five times within a 60-second request lifetime
- On 412 read `errorCode` and `details.statusReasons`. `AccountErrorStatus` needs a person to re-authenticate the linked account

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: trust.stackone.com (security policy, sub-processor list, certifications, any disclosure programme), which answered our reader with a bot check. We did not retry
  • unchecked: the incident list on status.stackone.com, which is drawn by script. Only the component uptime figures were read
  • unchecked: live tool definitions from tools/list, including the size of schemas and the annotations, because reading them needs an account and we did not create one
  • unchecked: api.stackone.com and mcp.stackone.com answered 403 to a robots.txt request, so no further request was sent to either, and the OAuth metadata was not read
  • unchecked: weekly downloads of stackone-ai on PyPI
  • Whether failed calls are billed. The pricing page says no and the Service Consumption Schedule counts them
  • The credit cost of browser use, premium defence and data sync, and the figure in the Enterprise uptime SLA
  • Whether the seat prices in the pricing calculator's markup ($15 a further seat on Team, 10 included) are what a customer is charged
  • Whether the Platform Privacy Policy of December 2023, which says data is stored in the EEA, still describes projects created in the US region
  • The Acceptable Use Policy bars benchmarking other than for internal comparison and vulnerability testing without authorisation, which matters before any probe is run

Sources 41

  1. docs index docs.stackone.com · seen 2026-10-09
  2. site index with connector counts and legal links stackone.com · seen 2026-10-09
  3. introduction docs.stackone.com · seen 2026-10-09
  4. MCP for AI platforms, OAuth and session tokens docs.stackone.com · seen 2026-10-09
  5. MCP from a backend, tool modes docs.stackone.com · seen 2026-10-09
  6. MCP troubleshooting and error codes docs.stackone.com · seen 2026-10-09
  7. RPC over HTTP docs.stackone.com · seen 2026-10-09
  8. RPC endpoint reference docs.stackone.com · seen 2026-10-09
  9. API keys and scopes docs.stackone.com · seen 2026-10-09
  10. Platform API authentication docs.stackone.com · seen 2026-10-09
  11. rate limiting docs.stackone.com · seen 2026-10-09
  12. pagination docs.stackone.com · seen 2026-10-09
  13. Advanced Tool Search docs.stackone.com · seen 2026-10-09
  14. Defender docs.stackone.com · seen 2026-10-09
  15. Policies docs.stackone.com · seen 2026-10-09
  16. scoping connectors docs.stackone.com · seen 2026-10-09
  17. observability and Advanced Logs docs.stackone.com · seen 2026-10-09
  18. projects and regions docs.stackone.com · seen 2026-10-09
  19. connector versioning docs.stackone.com · seen 2026-10-09
  20. A2A, open beta docs.stackone.com · seen 2026-10-09
  21. Slack connector page docs.stackone.com · seen 2026-10-09
  22. API SDKs docs.stackone.com · seen 2026-10-09
  23. OpenAPI file, read as the description file and not a rendered page api.eu1.stackone.com · seen 2026-10-09
  24. pricing stackone.com · seen 2026-10-09
  25. changelog stackone.com · seen 2026-10-09
  26. MCP tool annotations changelog entry stackone.com · seen 2026-10-09
  27. contact page with company details stackone.com · seen 2026-10-09
  28. legal index stackone.com · seen 2026-10-09
  29. SaaS Terms and Conditions stackone.com · seen 2026-10-09
  30. Service Consumption Schedule stackone.com · seen 2026-10-09
  31. Acceptable Use Policy stackone.com · seen 2026-10-09
  32. AI Services Addendum stackone.com · seen 2026-10-09
  33. Data Processing Addendum stackone.com · seen 2026-10-09
  34. Platform Privacy Policy stackone.com · seen 2026-10-09
  35. status page status.stackone.com · seen 2026-10-09
  36. official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-09
  37. TypeScript Agent SDK repository, tags and changelog github.com · seen 2026-10-09
  38. Python Agent SDK repository, tags github.com · seen 2026-10-09
  39. Defender repository, tags github.com · seen 2026-10-09
  40. npm weekly downloads for @stackone/ai api.npmjs.org · seen 2026-10-09
  41. RDAP for stackone.com rdap.verisign.com · seen 2026-10-09

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Freemium $600 / mo Free to start with no card, per the pricing page. Gateway Starter is free with 1,000 credits a seat a month, one credit per tool call or API call, and extra credits at $60 per 20,000. Gateway Team is $600 a month ($6,000 a year) with 5,000 credits a seat a month and extra credits at $20 per 20,000. The pricing calculator's markup gives 10 seats included on Team and $15 a further seat, which the page text doesn't state. OEM Core is free with a monthly credit allowance and volume prices on request. Enterprise plans are priced on contract. Browser use, premium defence and data sync cost more than one credit, at rates not published. The Service Consumption Schedule of 30 March 2026 gives $0.003 per Action Call as overage and counts unsuccessful requests, while the pricing page says background and failed calls aren't billed (https://www.stackone.com/pricing/, checked 2026-10-09).

Prices

ItemPriceUnitNote
Gateway Team plan$600per month (plan)5,000 credits a seat a month, one credit per tool call or API call. $6,000 billed yearly
Extra credits, Gateway Starter$3per 1,000 tool calls$60 per 20,000 credits, valid 12 months. Advanced capabilities cost more than one credit a call
Extra credits, Gateway Team$1per 1,000 tool calls$20 per 20,000 credits, valid 12 months

Compared across listings on the price index.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/stackone.xml, or this listing's score history at history.json.

Connect

Install

npm install @stackone/ai

First request

curl -X POST "https://api.stackone.com/actions/rpc" \
  -u "$STACKONE_API_KEY:" \
  -H "x-account-id: your-account-id" \
  -H "Content-Type: application/json" \
  -d '{"action": "bamboohr_list_employees", "query": {"page_size": 25}}'

Claude Code

claude mcp add --transport http --scope user stackone https://mcp.stackone.com/mcp

Through letme picks today, calling later

GET https://letme.dev/stackone

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Merge Agent Handler Merge API, Inc.B69.5automation.apps automation.auth automation.actions agent.tools auth.auditno
One One Systems, Inc.B66.6automation.apps automation.auth automation.actions agent.tools auth.auditno
Composio (API + MCP) ComposioBB75.1automation.apps automation.auth automation.actions agent.toolsno
Unified.to MCP Server Unified API Inc.C61.9automation.apps automation.auth automation.actions agent.toolsno
Zapier MCP (agent actions) ZapierC58.1automation.apps automation.auth automation.actions agent.toolsno
Smithery Smithery (Arcade.dev)D50.7automation.apps automation.auth automation.actions agent.toolsno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    StackOne on Anchor Terminal, B, 69.1/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/stackone"><img src="https://www.anchorterminal.com/badges/stackone.svg" alt="StackOne on Anchor Terminal" height="20"></a>
    [![StackOne on Anchor Terminal](https://www.anchorterminal.com/badges/stackone.svg)](https://www.anchorterminal.com/tools/stackone)

    It counts on a page on stackone.com or one of its subdomains, or the README of github.com/StackOneHQ/stackone-ai-node.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "stackone", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.