# StackOne (slim) > StackOne is a hosted gateway from StackOne Technologies Limited that gives AI agents actions across more than 540 business apps over MCP, SDKs, A2A or HTTP, with managed authentication, per-user grants, policies and logs. - Full: https://www.anchorterminal.com/tools/stackone.md (~9,200 tokens) · this version ~2,130 tokens · JSON https://www.anchorterminal.com/tools/stackone.json · canonical https://www.anchorterminal.com/tools/stackone - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-10 **B · 69.1/100 · rank #198 of 950 · #3 in Agent tool access · not agent-ready · confidence medium** Assessment: StackOne's MCP server signs each person in with OAuth, lets them grant individual accounts and actions, and by default exposes two search and execute tools in place of the full catalogue. Session token URLs carry the credential in the query string for a year by default, and the Consumption Schedule and pricing page disagree on whether failed calls are billed. ## Facts - Kind: MCP server · vendor: StackOne Technologies Limited · category: Agent tool access · legal entity: StackOne Technologies Limited · provenance 88/100 - Endpoint: `https://mcp.stackone.com/mcp` (Streamable HTTP, HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under StackOne's SaaS Terms and Conditions. The Agent SDKs (`@stackone/ai`, `stackone-ai`) and the Defender package (`@stackone/defender`) are Apache-2.0 - Probe metrics: not measured yet (probes haven't run) - MCP endpoints: `https://mcp.stackone.com/mcp` with OAuth for people using a client, `https://api.stackone.com/mcp` with an API key and `x-account-id` for backends, and `https://api.stackone.com/mcp?token=` for unattended use. Streamable HTTP, POST only, stateless, no SSE - Tool modes: `individual` registers one tool per enabled action. `search_execute` registers `{provider}_search_actions` (`top_k` default 10, maximum 50) and `{provider}_execute_action`. Set with `?tool-mode=` or at the consent screen - Other interfaces: `POST /actions/rpc` and `GET /actions` over HTTP, Agent SDKs for TypeScript and Python, and A2A agents at `https://a2a.stackone.com`, which the docs mark as open beta - Connectors: 546 live connectors and more than 33,470 actions per the site index, a vendor figure. Connectors carry semver versions and a connector profile can pin `latest`, `1.x.x`, `1.2.x` or one version - Credentials: OAuth grants per user (one-hour access tokens, 90 days, revocable), project API keys with five scope groups, and session tokens fixed to one linked account with a one-year default expiry - End-user authorisation: Linked accounts created in the dashboard, through the embedded StackOne Hub or by an auth link. StackOne's shared OAuth apps or the customer's own - Rate limits: 1,000 requests a minute per API key. 429 carries `Retry-After` in seconds. Provider 429s are retried up to five times within a 60-second request lifetime, then 429 or 408 is returned - Free plan: Gateway Starter, 1,000 credits a seat a month, one project, action logs kept one day, no card. OEM Core is free with a monthly credit allowance - Governance: Connector profiles enable or disable each action. Policies (Team and Enterprise) deny tools, mask fields, bound values and redact PII per user or group. SAML SSO on Team, IP allowlists on Enterprise - Defender: Pattern matching and a local MiniLM classifier on every tool result. Modes Monitor (default), `Sanitize` and Block. The hosted Deep Scan adds an LLM review that StackOne says runs on its own inference endpoints - Logs: Action logs kept 1, 7 or 30 days on Gateway Starter, Team and Enterprise. Advanced Logs store request and response bodies, off by default, for 1, 7 or 30 days. Logs API, audit logs and SIEM export on Enterprise and OEM plans as listed - Hosting: AWS eu-west-1 (Dublin), GCP europe-west1 (Belgium) and AWS us-east-1 (N. Virginia), chosen per project and fixed at creation. Other regions and self-hosting are Enterprise add-ons - Certifications: SOC 2 Type II, GDPR and HIPAA per the pricing and contact pages, with the SOC 2 report and a Business Associate Agreement on Enterprise. The trust centre answered our reader with a bot check - SDKs: `@stackone/ai` 2.10.0 (27 July 2026, Node 20.19.6 or later) and `stackone-ai` 2.10.1 (28 July 2026, Python 3.11 or later), both Apache-2.0. Platform API clients for TypeScript and Ruby, with PHP, Java and C# in beta - Prices: Gateway Team plan $600 per month (plan); Extra credits, Gateway Starter $3 per 1,000 tool calls; Extra credits, Gateway Team $1 per 1,000 tool calls - Scores: Reliability 80, Performance pending, Schema & documentation 78, Agent ergonomics 75, Security & auth 69, Payments & pricing 38, Task success pending, Maintenance & community 84, Transparency & trust 69 · negative events -2 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines. · Schema & documentation, An OpenAPI 3.1 file is published for the Platform API (30 operations under `/v2`), the actions, logs and MCP endpoints have reference pages… · Agent ergonomics, The catalogue is large, and `individual` mode registers one tool per enabled action, which scores 5. Ten back for the two-tool search and ex… · Security & auth, OAuth per user with one-hour access tokens, a 90-day grant and revocation, and project API keys with scopes that can be disabled or deleted… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, Changelog entry on 24 September 2026 (Deep Query) and `@stackone/defender` v0.8.3 on 23 September (30). · Transparency & trust, The editorial half. - Sources: 41, open questions: 10, both in the full twin - Capabilities: automation.apps, automation.auth, automation.actions, agent.tools, auth.audit - JSON: https://www.anchorterminal.com/api/v1/tools/stackone.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/stackone.svg` or a link to https://www.anchorterminal.com/tools/stackone from a page on stackone.com or one of its subdomains, or the README of github.com/StackOneHQ/stackone-ai-node, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send `Accept: application/json,text/event-stream` on every MCP request to `https://api.stackone.com/mcp`, by POST only. Without it the server answers 406 2. In `search_execute` mode call `{provider}_search_actions` first and pass the returned `action_id` to `{provider}_execute_action`. Never hardcode action ids 3. Pass the API key as the Basic auth username with an empty password, and name the linked account in `x-account-id` 4. On 429 or 408 wait the seconds given in `Retry-After`. StackOne has already retried a provider's 429 up to five times within a 60-second request lifetime 5. On 412 read `errorCode` and `details.statusReasons`. `AccountErrorStatus` needs a person to re-authenticate the linked account ## Connect ```bash npm install @stackone/ai ``` ```bash curl -X POST "https://api.stackone.com/actions/rpc" \ -u "$STACKONE_API_KEY:" \ -H "x-account-id: your-account-id" \ -H "Content-Type: application/json" \ -d '{"action": "bamboohr_list_employees", "query": {"page_size": 25}}' ``` ```bash claude mcp add --transport http --scope user stackone https://mcp.stackone.com/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/stackone ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Merge Agent Handler | B | 69.5 | automation.apps, automation.auth, automation.actions, agent.tools, auth.audit | https://www.anchorterminal.com/tools/merge-agent-handler.min.md | | One | B | 66.6 | automation.apps, automation.auth, automation.actions, agent.tools, auth.audit | https://www.anchorterminal.com/tools/one.min.md | | Composio (API + MCP) | BB | 75.1 | automation.apps, automation.auth, automation.actions, agent.tools | https://www.anchorterminal.com/tools/composio-rube.min.md | | Unified.to MCP Server | C | 61.9 | automation.apps, automation.auth, automation.actions, agent.tools | https://www.anchorterminal.com/tools/unified-to-mcp.min.md | | Zapier MCP (agent actions) | C | 58.1 | automation.apps, automation.auth, automation.actions, agent.tools | https://www.anchorterminal.com/tools/zapier-mcp.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)