Unified.to MCP Server
by Unified API Inc. MCP server in Agent tool access
Hosted
Unified API Inc. · unified.to · status page · who's behind it
Unified.to MCP Server is a hosted Streamable HTTP server from Unified API Inc. that turns one end-customer connection to a business app into MCP tools, on top of the vendor's unified API for CRM, HR, accounting and other categories.
Good for A B2B software team that already uses or plans to use Unified's API and wants the same customer connections exposed to an LLM, with data read live from the source app.
Is this your product? Claim this listing or verify it
Assessment. Every previewed tool carries a typed input schema and read-only, destructive and idempotent annotations, and the list can be narrowed by permission or tool name. The default credential is a workspace API key that reaches every connection, and the SSE transport was removed on 23 September 2026 in the changelog entry that announced it.
Facts
- Transport
- Streamable HTTP
- Endpoint
https://mcp-api.unified.to/mcp- Auth
- OAuth or key
- Pricing
- Paid · $750 / mo
- x402
- No
- Licence
- Proprietary service under Unified.to's Terms of Service. The linked repository is sample client code
- Packages
npm@unified-api/typescript-sdk- MCP registry
to.unified/core- llms.txt
- published
- Last release
- npm / week
- 22k
- Endpoints
https://mcp-api.unified.to/mcp(US),https://mcp-api-eu.unified.to/mcp(EU) andhttps://api-au.unified.to/mcp(AU). Streamable HTTP only. Regions do not resolve across one another- Modes
- Connection mode lists one end-customer connection's tools. Core mode, with a workspace API key and no connection, lists 21 management tools for connections, webhooks, integrations, issues, API-call logs, environments and docs search
- Credentials
- Workspace API key in the
Authorizationheader orx-api-key, a connection-scoped signed token in?token=(usermode), or anema_access token from an RFC 7523jwt-bearerexchange, enabled per workspace on request - Tool filters
permissions(for examplecrm_contact_read),tools(ids or wildcards such aslist_*),defer_tools,aliases,hide_sensitiveandinclude_external_tools, all as URL parameters- Tool shape
- Names follow
list_,get_,create_,update_andremove_plus category and object, such aslist_crm_contacts. List tools takefields,limit,offset,updated_gte,sort,orderandquerywhere the integration supports them - Annotations
- In the HubSpot preview all 78 tools set
readOnlyHint,destructiveHint,idempotentHintandopenWorldHint. Create, update and remove tools are all marked destructive - Catalogue
- 94,258 tools on 8 October 2026, 17,189 of them unified, per the MCP changelog. The pricing page counts 1,236 integrations and 33 unified APIs. All vendor figures
- Rate limits
- Per workspace, per minute. Test 500, Grow 5,000, Pro 7,500, Scale 10,000. The connected app's own limits apply first. Unified does not queue or retry synchronous calls
- Free use
- A tester account with 2,500 free API requests, per the pricing page description, and a 30-day free trial on Grow and Pro. Whether a card is needed is not stated
- Logs
- API call logs kept 30 days on Test, 60 on Grow and Pro and 365 on Scale, per the privacy policy. Pro and Scale can stream logs to Datadog. Core mode tools
list_unified_apicallsandget_unified_apicallread them - Data handling
- The privacy policy says end-customer data is processed in transit and not stored or cached, and that no models are trained on any data. Credentials and configuration are stored in the workspace's region
- Hosting
- Separate US, EU and AU regions. The sub-processor list of 2 October 2025 names AWS, Render, MongoDB, Redis and ClickHouse in all three, and Datadog, PostHog, Stripe and Customer.io in the US
- Certifications
- SOC 2 Type II, with GDPR, CCPA, HIPAA and PIPEDA compliance stated on the security page. A BAA is on the Scale plan. Reports are requested through a trust centre we did not read
- Other interfaces
- The unified REST API with an OpenAPI 3.0 file, SDKs for TypeScript, Python, PHP, Java, Go, C# and Ruby (all dated 21 September 2026 on the docs), a CLI and more than 100 agent skill files
Facts verified 2026-10-09 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- A credential-free preview of the HubSpot tool list returned 78 tools, each with a JSON Schema input and
readOnlyHint,destructiveHintandidempotentHintannotations, and 66 with an output schema - The
permissionsandtoolsURL parameters limit which tools a connection lists, andhide_sensitivestrips names, emails and telephone numbers from results - A
usermode URL carries a signed token limited to one connection, so the workspace API key need not be shared with an end customer - Rate limits are published per plan, from 500 requests a minute on Test to 10,000 on Scale, shared across the workspace
- The privacy policy has an MCP section. It says end-customer data is not stored or cached and that Unified does not train models on any data
- The MCP changelog is dated and had entries on 22 July, 21 and 23 September and 8 October 2026
Weaknesses
- The default credential is a workspace API key. The docs say it grants access to all connections and the whole Unified.to account
- The
/ssetransport and thesse_urlresponse field were removed on 23 September 2026. No earlier notice was found in the MCP changelog, the site changelog or the September update - The connection-scoped signed token travels in the URL as
?token=. The docs mark?token=authentication as deprecated, with no end date set - One HubSpot connection lists 78 tools whose definitions come to about 133 KB without output schemas and 343 KB with them
- No uptime SLA is published. The pricing page says SLAs come with a custom Enterprise plan
- No security.txt, bug bounty or disclosure policy was found, and the security page gives February 2025 as its last review
- The Terms of Service forbid probing, scanning or testing the vulnerability of the service. This matters before any probe is run
- The Terms of Service bar transmitting financial or medical information and birth dates through the service, while the product sells accounting and HR integrations
Before you call it notes for agents
- Use the host for the workspace's region. US is
mcp-api.unified.to, EU ismcp-api-eu.unified.toand AU isapi-au.unified.to. A credential on another region's host resolves to not found - Send the key as
Authorization: Bearer <key>and putconnection=<id>in the URL. Withoutconnectionthe server lists workspace management tools, not the customer's data tools - Pass
toolsorpermissionsin the URL before listing. An unfiltered connection can list dozens of tools with large output schemas - Expect HTTP 429 on tool calls since 23 September 2026. Unified does not queue or retry, so back off and retry yourself
- Page with
limit(100 at most on most endpoints) andoffset, and stop when a page returns fewer records thanlimit
Who's behind it provenance 71/100
- Legal entity namedUnified API Inc.20/20
- Domain ageunified.to, no registry record we could read0/15
- Endpoint on the vendor's domainmcp-api.unified.to15/15
- Terms of serviceread, states 5 of the 7 things a reader expects, and has 1 clause that costs points6.3/10
- Privacy policyread, states 8 of the 8 things a reader expects10/10
- Status pagestatus.unified.to10/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service gives no date, states 5 of 7, 2 to know
TL;DR Gives no date. States 5 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, limits on benchmarking and cut-off without notice or for any reason.
Restricts benchmarking or competitive usecosts points
(C) use or access the Service to build or support, and/or assist a third party in building or supporting, products or services competitive to Unified.to;
A clause against publishing test results or using the service to build something that competes.
Says access can be ended without notice or for any reason
(e) Termination and Suspension by Unified.to: Unified.to may terminate your User Account and/or these Terms of Service at any time and for any reason upon notice to you.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the Province of Ontario
These Terms of Service will be governed by and construed in accordance with the laws of the Province of Ontario, without reference to its conflict of laws principles.
Says where a dispute would be heard and under whose law.
States a limit on its liability Rules out indirect and consequential losses, with no cap named in this sentence
…of Liability: TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, YOU AGREE THAT Unified.to SHALL NOT BE LIABLE TO YOU FOR ANY (A) INDIRECT, INCIDENTAL, CONSEQUENTIAL, PUNITIVE, SPECIAL, EXEMPLARY OR STATUTORY DAMAGES (INCLUDING, WITHOUT LIMITATION, LOSS OF BUSINESS, LOSS OR PROFITS, LOSS OF REVENUE, LOSS OF DATA, LOSS…
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
You acknowledge that Unified.to will terminate your access to the Site and/or the Service if you repeatedly infringe the copyright of third parties.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Says it gives notice of a change
Unified.to expressly reserves the right to modify the Terms of Service at any time in its sole discretion by including such alteration and/or modification in these Terms of Service, along with a notice of the effective date of such modified Terms of Service.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
If you do not agree to these Terms of Service, you may not use the Site or the Service.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
An account with no login for 12 months or more may be treated as inactive and permanently deleted with all its data.
If you do not log in to your User Account for 12 or more months, we may treat your User Account as "inactive" and permanently delete the User Account and all the data associated with it.
Noted by a second reader on 2026-10-08.
Users may not transmit, import or upload financial or medical information, or sensitive personal information, through the site or service.
transmitting, importing, uploading, or incorporating any financial or medical information of any nature, or any sensitive personal information
Noted by a second reader on 2026-10-08.
Unified.to may use aggregated or anonymised data, including data derived from user content, to improve its own products and may disclose it in de-identified form.
Unified.to will be free at any time to: (i) use such information and data to improve and enhance Unified.to's offerings; and (ii) disclose such data in aggregate or other de-identified form in connection with its business.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-09 · 8,760 words
Privacy policy dated 2026-10-02, states 8 of 8
TL;DR Dated 2026-10-02. States all 8 things a reader expects. The rules found no clause to flag.
Gives the date it was last updated Last updated 2026-10-02
Date of Last Revision: October 2, 2026
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
This Privacy Policy explains how we collect, use, and protect data for individuals who interact directly with our platform, including our customers and their employees, developers, and other users who log into and use the platform.
The basic statement a privacy policy exists to make.
Says how long data is kept Names a period of 30 days
deleted or anonymized within 30 days of account closure, except where retention is required to comply with applicable law, to detect or prevent fraud or security incidents, or to resolve disputes or enforce our agreements.
Says when data sent to the service is deleted.
Says who else receives the data
Customers and registered users of the Service ("Customers") use the Service to connect Customer applications and services ("Customer Services") to their users' third-party accounts ("End-User Accounts") and transfer data ("Customer Services Data") between the Service and End-User Accounts.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
We do not share or sell your personal information to third-parties except as detailed below or as otherwise instructed by our Customers.
A plain statement either way.
Says what rights people have over their data
Your rights — You may ask us to provide you with information about our processing of your personal information, opt-out of marketing communication, correct or delete certain personal information, transfer it to you or a third-party of your choice, restrict further processing of your personal information, or object to…
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@unified.to
You can also request changes or access to your information by emailing privacy@unified.to.
An address or officer to send a request to.
Says where data is transferred or stored Relies on standard contractual clauses
Where required, we rely on adequacy decisions or the European Commission's Standard Contractual Clauses (SCCs).
The countries data goes to and the safeguard used.
Unified.to states that it does not train machine-learning models on any data.
We also do not train machine-learning models on any data.
Noted by a second reader on 2026-10-08.
The MCP server is described as receiving only the parameters of each tool call, with no access to the AI assistant's conversations, prompts, memory or files.
It does not access your AI assistant's conversations, chat history, prompts, memory, or files — it receives only the specific parameters of each tool call (for example, an object id or a search filter) and returns the corresponding Unified.to API data.
Noted by a second reader on 2026-10-08.
Data partners may use cookies to link website visits and logins to other personal information, including an email address, and marketing may then be sent to that address.
When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-09 · 8,024 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The Terms of Service say the site and the service are operated by Unified API Inc. and are governed by the laws of the Province of Ontario. The page carries no date.
The DPA, last revised 19 March 2026, names UNIFIED API Inc., an Ontario corporation at 325 Front Street West, 4th floor, Toronto.
The privacy policy covers unified.to, api.unified.to, app.unified.to and sub-domains, and has a section on the MCP server at mcp-api.unified.to.
The MCP endpoints answer at mcp-api.unified.to, mcp-api-eu.unified.to and api-au.unified.to.
unified.to/.well-known/security.txt returned 404.
status.unified.to runs on Honeybadger and lists the API and the admin app in three regions and the authentication page. The MCP server has no component of its own. The docs say it runs as part of the API.
The registration date of unified.to was not looked up. The .to registry publishes no RDAP record we know of.
The trust centre at app.mycroft.io/trust/unified-to was not read.
Checked 2026-10-09 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-10 00:52 UTC
Probed every five minutes at https://mcp-api.unified.to/mcp. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials. Last note, asks for credentials.
- Vendor status page unknown, no machine-readable status found · 2 minutes ago
- npm
@unified-api/typescript-sdk2.85.49 - GitHub stars 1
- npm downloads a week 22k
Pages we watch
| Page | Kind | Last checked | Last changed |
|---|---|---|---|
| docs.unified.to/mcp/changelog | changelog | 6 hours ago · 200 | no change seen |
| unified.to/pricing | pricing | 6 hours ago · 200 | no change seen |
| unified.to/privacy | privacy | 6 hours ago · 200 | no change seen |
| unified.to/tos | terms | 6 hours ago · 200 | no change seen |
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/unified-to-mcp.json
Tools it lists
https://mcp-api.unified.to/mcp asks for credentials before it lists its tools, so we can't show them without an account. Checked 3 hours ago.
Notable
- Streamable HTTP at
/mcpis the only transport./sseand/sse/messagesreturn HTTP 410 since 23 September 2026 source - Three credentials. A workspace API key with a
connectionparameter, a workspace API key alone for management tools, and enterprise-managed tokens with theema_prefix that expire after 3,600 seconds and carry<category>.readand<category>.writescopes source - The vendor's changelog counts 94,258 tools on 8 October 2026, of which 17,189 are unified tools, up from 69,948 on 21 September. These are vendor figures across the whole catalogue source
- One unauthenticated
tools/listrequest with?integration_type=hubspot, a preview the server's own 401 message describes, returned 78 tools. 41 are read-only, 13 create, 12 update and 12 remove. Creates carrydestructiveHinttrue andidempotentHintfalse source - Each tool call counts as one API request on the plan, and tool calls are checked against the workspace rate limit source
include_external_tools=trueadds the integration's raw provider endpoints as further tools. Enterprise-managed tokens cannot reach them sourceGET /tools?type=returns the tool list shaped for OpenAI, Anthropic, Gemini, Cohere, Grok or Groq, andPOST /tools/{id}/callruns one tool over plain HTTP source- The official MCP registry lists
to.unified/coreat version 1.0.0 with a Streamable HTTP remote source - The vendor says the server runs the stateless 2026-07-28 MCP revision since 28 July 2026 and does not implement MCP Apps, Tasks or the revision's authorisation changes source
- The docs index and the site index open with lines that point coding agents to a skill file and a plugin install command. We read them as data source
- The overview page still says most OpenAI models handle only 20 tools, and the options page still describes a public generated token, which the changelog says was removed on 17 December 2025 source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 9 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 14.6 | |
Read with the hosted lines. status.unified.to on Honeybadger lists seven components, the API and the admin app in three regions and the authentication page. The MCP server has no component of its own (20). The page lists one incident in three months, API performance issues on 13 August 2026, resolved in an hour. Its detail page is closed by robots.txt and was not read, so it is counted as minor (20). Workspace limits are published per plan, from 500 to 10,000 requests a minute (15). The docs describe exponential backoff with jitter on 429 and say Unified does not queue or retry. No Retry-After header and no idempotency key were found (8). No uptime SLA is published. The pricing page says SLAs come with a custom Enterprise plan (0). The server launched on 1 June 2025 and carries no beta label (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 13.2 | |
One credential-free tools/list preview for HubSpot returned 78 tools, each with a JSON Schema input and 66 with an output schema. The API has a published OpenAPI 3.0 file, which we did not read (25). llms.txt on the docs and the site, a full-text file, and a Markdown twin of every docs page (10). Tool descriptions state the action, what is returned, what is required and which sibling tool to use, for example 'Permanently removes the record and cannot be undone'. They follow one template and say nothing about provider differences (15). The 78 inputs hold 531 properties and 135 enums with no open objects at the top level. limit and offset have no bounds and some filters are plain strings (12). Client set-up examples for eight hosts and a table of eight HTTP status codes. No per-tool examples, and MCP error results are not documented (8). A dated MCP changelog since June 2025. The server has no version scheme beyond the registry's 1.0.0 (11). | |||
| Agent ergonomics | 13%16.2 | 11.5 | |
One HubSpot connection lists 78 tools, about 133 KB of definitions without output schemas and 343 KB with them, which scores 5. Eight back for the tools, permissions and defer_tools filters, which the docs tell users to set (13). List tools take limit, offset, a fields selection, updated_gte, sort, order and query. Pages hold 100 records at most and there is no cursor or total (18). The unauthenticated call returned a JSON-RPC error with a plain message naming the header to send, and the REST status table explains 401, 403, 429 and 501. Tool error results are not documented (11). All 78 previewed tools set readOnlyHint, destructiveHint and idempotentHint. Creates are marked not idempotent and there is no idempotency key (15). 44 required fields across 531 properties, and API SDKs in seven languages. Every option travels as a URL parameter (14). | |||
| Security & auth | 14%17.5 | 8.8 | |
The default credential is a workspace API key that the docs say reaches all connections and the whole account. A signed token limited to one connection, keys limited to an environment and enterprise-managed tokens with category scopes and a one-hour life raise this to 22. Ten off because ?token= in the URL is a documented option, deprecated for keys with no end date, and the only way the connection-scoped token is sent (12). permissions and tools limit the tool list, enterprise scopes hide tools a token may not call, and connections are isolated from one another. No approval step for writes was found (14). Tool results are third-party content. hide_sensitive removes PII, and no prompt-injection guidance was found (4). API call logs kept 30 to 365 days by plan, readable through management tools and streamable to Datadog on Pro and Scale. The docs warn that a workspace key leaves no per-person audit trail (10). SOC 2 Type II and yearly penetration tests are stated. security.txt returned 404, no bounty or disclosure policy was found, and the trust centre was not read (10). | |||
| Payments & pricing | 10%12.5 | 3.8 | |
| No x402, MPP or L402 (0). Plan prices and overage rates per 1,000 API calls are public, and each tool call counts as one request. Two off because every plan price is shown with a plus sign and the terms of the free tester account are not set out (18). A tester account with 2,500 free requests and a 30-day trial are stated. Whether a card is needed is not stated, so part marks (12). A person signs up in a browser. The vendor's September 2026 update says creating the account still takes a person (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 7.3 | |
MCP changelog entry on 8 October 2026 (30). Entries on 22 July, 21 and 23 September and 8 October 2026 (20). A closed service with a daily site changelog, a public Discord for support and a stated response within 24 hours on the Test plan (12). to.unified/core is in the official MCP registry under the vendor's domain namespace (15). The docs date all seven API SDKs 21 September 2026. The sample MCP client repository was last changed on 29 August 2025 and its README still documents the removed dc option (7). | |||
| Transparency & trusteditorial 61, provenance 71 | 7%8.8 | 5.8 | |
The editorial half. Closed service under Terms of Service that name Unified API Inc. and Ontario law. Two off because the terms carry no date and bar sending financial or medical information and birth dates through a service sold for accounting and HR data (13). The privacy policy has an MCP section, says end-customer data is not stored and no models are trained, and gives retention periods by plan. The DPA of 19 March 2026 promises breach notice within 72 hours and deletion within a reasonable period on request. The security page says no data is stored at rest, ever, while the policy lists stored credentials, configuration and logs, and the page says Unified runs on AWS while the sub-processor list also names Render (22). No deprecation policy. ?token= carries a Deprecation header with no end date, a field deprecation notice was published in November 2025, and SSE was removed on the day it was announced (8). Ten sub-processors with locations, dated 2 October 2025, and three named regions. The DPA gives 15 days' notice of new sub-processors on a best-efforts basis (18). | |||
| Negative events | ≤15 |
| -3 |
| Total | 61.9 · C | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 22 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Unified.to MCP Server, or have the agent fetch /fixes/unified-to-mcp.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Unified.to MCP Server From Anchor Terminal's listing at https://www.anchorterminal.com/tools/unified-to-mcp, the October 2026 research run, assessed 9 October 2026. Grade C, 61.9 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Unified.to MCP Server: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Security & auth, 50 out of 100, up to 8.8 more on the total Why it scored 50: The default credential is a workspace API key that the docs say reaches all connections and the whole account. A signed token limited to one connection, keys limited to an environment and enterprise-managed tokens with category scopes and a one-hour life raise this to 22. Ten off because `?token=` in the URL is a documented option, deprecated for keys with no end date, and the only way the connection-scoped token is sent (12). `permissions` and `tools` limit the tool list, enterprise scopes hide tools a token may not call, and connections are isolated from one another. No approval step for writes was found (14). Tool results are third-party content. `hide_sensitive` removes PII, and no prompt-injection guidance was found (4). API call logs kept 30 to 365 days by plan, readable through management tools and streamable to Datadog on Pro and Scale. The docs warn that a workspace key leaves no per-person audit trail (10). SOC 2 Type II and yearly penetration tests are stated. security.txt returned 404, no bounty or disclosure policy was found, and the trust centre was not read (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 2. Payments & pricing, 30 out of 100, up to 8.8 more on the total Why it scored 30: No x402, MPP or L402 (0). Plan prices and overage rates per 1,000 API calls are public, and each tool call counts as one request. Two off because every plan price is shown with a plus sign and the terms of the free tester account are not set out (18). A tester account with 2,500 free requests and a 30-day trial are stated. Whether a card is needed is not stated, so part marks (12). A person signs up in a browser. The vendor's September 2026 update says creating the account still takes a person (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 3. Reliability, 73 out of 100, up to 5.4 more on the total Why it scored 73: Read with the hosted lines. status.unified.to on Honeybadger lists seven components, the API and the admin app in three regions and the authentication page. The MCP server has no component of its own (20). The page lists one incident in three months, API performance issues on 13 August 2026, resolved in an hour. Its detail page is closed by robots.txt and was not read, so it is counted as minor (20). Workspace limits are published per plan, from 500 to 10,000 requests a minute (15). The docs describe exponential backoff with jitter on 429 and say Unified does not queue or retry. No `Retry-After` header and no idempotency key were found (8). No uptime SLA is published. The pricing page says SLAs come with a custom Enterprise plan (0). The server launched on 1 June 2025 and carries no beta label (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 4. Agent ergonomics, 71 out of 100, up to 4.7 more on the total Why it scored 71: One HubSpot connection lists 78 tools, about 133 KB of definitions without output schemas and 343 KB with them, which scores 5. Eight back for the `tools`, `permissions` and `defer_tools` filters, which the docs tell users to set (13). List tools take `limit`, `offset`, a `fields` selection, `updated_gte`, `sort`, `order` and `query`. Pages hold 100 records at most and there is no cursor or total (18). The unauthenticated call returned a JSON-RPC error with a plain message naming the header to send, and the REST status table explains 401, 403, 429 and 501. Tool error results are not documented (11). All 78 previewed tools set `readOnlyHint`, `destructiveHint` and `idempotentHint`. Creates are marked not idempotent and there is no idempotency key (15). 44 required fields across 531 properties, and API SDKs in seven languages. Every option travels as a URL parameter (14). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 5. Schema & documentation, 81 out of 100, up to 3.1 more on the total Why it scored 81: One credential-free `tools/list` preview for HubSpot returned 78 tools, each with a JSON Schema input and 66 with an output schema. The API has a published OpenAPI 3.0 file, which we did not read (25). llms.txt on the docs and the site, a full-text file, and a Markdown twin of every docs page (10). Tool descriptions state the action, what is returned, what is required and which sibling tool to use, for example 'Permanently removes the record and cannot be undone'. They follow one template and say nothing about provider differences (15). The 78 inputs hold 531 properties and 135 enums with no open objects at the top level. `limit` and `offset` have no bounds and some filters are plain strings (12). Client set-up examples for eight hosts and a table of eight HTTP status codes. No per-tool examples, and MCP error results are not documented (8). A dated MCP changelog since June 2025. The server has no version scheme beyond the registry's 1.0.0 (11). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 6. Transparency & trust, 66 out of 100, up to 3 more on the total Made of editorial 61, provenance 71. Why it scored 66: The editorial half. Closed service under Terms of Service that name Unified API Inc. and Ontario law. Two off because the terms carry no date and bar sending financial or medical information and birth dates through a service sold for accounting and HR data (13). The privacy policy has an MCP section, says end-customer data is not stored and no models are trained, and gives retention periods by plan. The DPA of 19 March 2026 promises breach notice within 72 hours and deletion within a reasonable period on request. The security page says no data is stored at rest, ever, while the policy lists stored credentials, configuration and logs, and the page says Unified runs on AWS while the sub-processor list also names Render (22). No deprecation policy. `?token=` carries a `Deprecation` header with no end date, a field deprecation notice was published in November 2025, and SSE was removed on the day it was announced (8). Ten sub-processors with locations, dated 2 October 2025, and three named regions. The DPA gives 15 days' notice of new sub-processors on a best-efforts basis (18). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Domain age: unified.to, no registry record we could read (0 of 15) - Terms of service: read, states 5 of the 7 things a reader expects, and has 1 clause that costs points (6.3 of 10) - security.txt: not found (0 of 10) ## 7. Maintenance & community, 84 out of 100, up to 1.4 more on the total Why it scored 84: MCP changelog entry on 8 October 2026 (30). Entries on 22 July, 21 and 23 September and 8 October 2026 (20). A closed service with a daily site changelog, a public Discord for support and a stated response within 24 hours on the Test plan (12). `to.unified/core` is in the official MCP registry under the vendor's domain namespace (15). The docs date all seven API SDKs 21 September 2026. The sample MCP client repository was last changed on 29 August 2025 and its README still documents the removed `dc` option (7). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## Deductions Each comes off the total. A fixed and documented problem counts for less at the next check. - 23 September 2026. The MCP changelog entry of that date removed the SSE transport (`/sse` and `/sse/messages` now return HTTP 410), dropped `sse_url` from the `get_unified_connection_mcp_url` response, which the docs label a breaking change, and stopped regions resolving across one another. No earlier notice was found in the MCP changelog, the site changelog or the September product update. Whether customers were told privately was not established. The migration is a one-word URL change and is documented, so 3 points (https://docs.unified.to/mcp/changelog). ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: the trust centre at app.mycroft.io/trust/unified-to, where the SOC 2 report and policies are requested. We did not open it - unchecked: the detail page of the 13 August 2026 incident, which status.unified.to's robots.txt closes - unchecked: the OpenAPI file at api.unified.to, which we did not fetch, and the OAuth metadata at `/.well-known/oauth-protected-resource/mcp` - unchecked: the registration date of unified.to and the GitHub star count of the sample repository - unchecked: tool lists for integrations other than HubSpot, and the tool list with `include_external_tools` - Whether customers were told before 23 September 2026 that SSE, `sse_url` and cross-region resolution would go - Whether the tester account or the 30-day trial needs a card, and what the tester account's limits are beyond 2,500 requests - Which OAuth flow the privacy policy means by an OAuth token bound to one workspace with read or read and write permission. The 401 response advertises scopes `mcp:read mcp:write`, and the docs describe only the enterprise-managed exchange - When `?token=` authentication will stop working. The docs say a `Sunset` header will appear once a date is set - The Terms of Service forbid probing, scanning or testing the vulnerability of the service, which matters before any probe is run - We typed three `.md` addresses on unified.to that no page links (privacy, sub-processors, changelog). Each answered 404 and nothing was taken from them. The `?integration_type=` preview was named by the server's 401 message, not by a docs page we read ## Weaknesses - The default credential is a workspace API key. The docs say it grants access to all connections and the whole Unified.to account - The `/sse` transport and the `sse_url` response field were removed on 23 September 2026. No earlier notice was found in the MCP changelog, the site changelog or the September update - The connection-scoped signed token travels in the URL as `?token=`. The docs mark `?token=` authentication as deprecated, with no end date set - One HubSpot connection lists 78 tools whose definitions come to about 133 KB without output schemas and 343 KB with them - No uptime SLA is published. The pricing page says SLAs come with a custom Enterprise plan - No security.txt, bug bounty or disclosure policy was found, and the security page gives February 2025 as its last review - The Terms of Service forbid probing, scanning or testing the vulnerability of the service. This matters before any probe is run - The Terms of Service bar transmitting financial or medical information and birth dates through the service, while the product sells accounting and HR integrations ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Use the host for the workspace's region. US is `mcp-api.unified.to`, EU is `mcp-api-eu.unified.to` and AU is `api-au.unified.to`. A credential on another region's host resolves to not found - Send the key as `Authorization: Bearer <key>` and put `connection=<id>` in the URL. Without `connection` the server lists workspace management tools, not the customer's data tools - Pass `tools` or `permissions` in the URL before listing. An unfiltered connection can list dozens of tools with large output schemas - Expect HTTP 429 on tool calls since 23 September 2026. Unified does not queue or retry, so back off and retry yourself - Page with `limit` (100 at most on most endpoints) and `offset`, and stop when a page returns fewer records than `limit` ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: the trust centre at app.mycroft.io/trust/unified-to, where the SOC 2 report and policies are requested. We did not open it
- unchecked: the detail page of the 13 August 2026 incident, which status.unified.to's robots.txt closes
- unchecked: the OpenAPI file at api.unified.to, which we did not fetch, and the OAuth metadata at
/.well-known/oauth-protected-resource/mcp - unchecked: the registration date of unified.to and the GitHub star count of the sample repository
- unchecked: tool lists for integrations other than HubSpot, and the tool list with
include_external_tools - Whether customers were told before 23 September 2026 that SSE,
sse_urland cross-region resolution would go - Whether the tester account or the 30-day trial needs a card, and what the tester account's limits are beyond 2,500 requests
- Which OAuth flow the privacy policy means by an OAuth token bound to one workspace with read or read and write permission. The 401 response advertises scopes
mcp:read mcp:write, and the docs describe only the enterprise-managed exchange - When
?token=authentication will stop working. The docs say aSunsetheader will appear once a date is set - The Terms of Service forbid probing, scanning or testing the vulnerability of the service, which matters before any probe is run
- We typed three
.mdaddresses on unified.to that no page links (privacy, sub-processors, changelog). Each answered 404 and nothing was taken from them. The?integration_type=preview was named by the server's 401 message, not by a docs page we read
Sources 33
- robots.txt, which allows every path and names Anthropic's agents as allowed unified.to · seen 2026-10-09
- docs robots.txt, which allows every path docs.unified.to · seen 2026-10-09
- docs index docs.unified.to · seen 2026-10-09
- site index unified.to · seen 2026-10-09
- MCP overview docs.unified.to · seen 2026-10-09
- MCP authentication docs.unified.to · seen 2026-10-09
- MCP changelog docs.unified.to · seen 2026-10-09
- MCP core mode, endpoints, transport and client configuration docs.unified.to · seen 2026-10-09
- MCP server options docs.unified.to · seen 2026-10-09
- MCP installation and usage docs.unified.to · seen 2026-10-09
- MCP additional API endpoints docs.unified.to · seen 2026-10-09
- rate limits docs.unified.to · seen 2026-10-09
- pagination docs.unified.to · seen 2026-10-09
- REST API, regions and status codes docs.unified.to · seen 2026-10-09
- SDKs and specification files docs.unified.to · seen 2026-10-09
- log retention guide of April 2024 docs.unified.to · seen 2026-10-09
- pricing unified.to · seen 2026-10-09
- Terms of Service unified.to · seen 2026-10-09
- security page unified.to · seen 2026-10-09
- privacy policy unified.to · seen 2026-10-09
- Data Processing Agreement unified.to · seen 2026-10-09
- sub-processor list unified.to · seen 2026-10-09
- support terms unified.to · seen 2026-10-09
- site changelog unified.to · seen 2026-10-09
- blog post on the 2026-07-28 MCP revision unified.to · seen 2026-10-09
- September 2026 product update unified.to · seen 2026-10-09
- security.txt, 404 unified.to · seen 2026-10-09
- status page status.unified.to · seen 2026-10-09
- MCP endpoint. robots.txt answered 404. One `initialize` (401 with a `WWW-Authenticate` header) and one `tools/list` with `?integration_type=hubspot`, both without credentials mcp-api.unified.to · seen 2026-10-09
- official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-09
- sample MCP client repository, cloned github.com · seen 2026-10-09
- Python SDK repository, commit history github.com · seen 2026-10-09
- npm weekly downloads for @unified-api/typescript-sdk api.npmjs.org · seen 2026-10-09
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Paid $750 / mo Plans from $750 a month. Grow is $750+ with 750,000 API calls and $1.00 per 1,000 beyond that, Pro $1,500+ with 2,000,000 and $0.75, Scale $3,000+ with 6,000,000 and $0.50, and Enterprise is priced on contract. Each MCP tool call counts as one API request, and the FAQ says successful calls are billable. A tester account starts with 2,500 free API requests and Grow and Pro start with a 30-day free trial. The page does not say whether a card is needed (https://unified.to/pricing, checked 2026-10-09).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Grow plan | $750 | per month (plan) | Listed as $750+ a month. 750,000 API calls a month, each tool call counting as one |
| Pro plan | $1500 | per month (plan) | Listed as $1,500+ a month. 2,000,000 API calls a month |
| Scale plan | $3000 | per month (plan) | Listed as $3,000+ a month. 6,000,000 API calls a month |
| Overage, Grow | $1 | per 1,000 requests | Per 1,000 API calls beyond the plan allowance |
| Overage, Pro | $0.75 | per 1,000 requests | Per 1,000 API calls beyond the plan allowance |
| Overage, Scale | $0.50 | per 1,000 requests | Per 1,000 API calls beyond the plan allowance |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/unified-to-mcp.xml, or this listing's score history at history.json.
Connect
Claude Code
claude mcp add --transport http unified-core https://mcp-api.unified.to/mcp \
--header "Authorization: Bearer $UNIFIED_API_KEY"
MCP client configuration
{
"mcpServers": {
"unified-mcp": {
"headers": {
"Authorization": "Bearer XXXXXXXX"
},
"url": "https://mcp-api.unified.to/mcp?connection=YYYYYYY"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/unified-to-mcp
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Alternatives to Unified.to MCP Server
#5 of 8 in Best agent tool access platforms · All 28 tool access comparisons
Composio (API + MCP) BBSmithery DMerge Agent Handler BStackOne BOne BZapier MCP (agent actions) C
Head to head Composio (API + MCP) vs Unified.to MCP Server · Merge Agent Handler vs Unified.to MCP Server · One vs Unified.to MCP Server · Smithery vs Unified.to MCP Server · StackOne vs Unified.to MCP Server · Unified.to MCP Server vs Zapier MCP (agent actions) · letme vs Unified.to MCP Server
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Composio (API + MCP) Composio | BB | 75.1 | automation.apps automation.auth automation.actions agent.tools automation.webhooks | no |
| Smithery Smithery (Arcade.dev) | D | 50.7 | automation.apps automation.auth automation.actions agent.tools automation.webhooks | no |
| Merge Agent Handler Merge API, Inc. | B | 69.5 | automation.apps automation.auth automation.actions agent.tools | no |
| StackOne StackOne Technologies Limited | B | 69.1 | automation.apps automation.auth automation.actions agent.tools | no |
| One One Systems, Inc. | B | 66.6 | automation.apps automation.auth automation.actions agent.tools | no |
| Pipedream API + MCP Pipedream (Workday) | B | 65.5 | automation.apps automation.webhooks automation.auth agent.tools | no |
Machine-readable
- JSON
/api/v1/tools/unified-to-mcp.json· historyhistory.json· badge/badges/unified-to-mcp.svg· changes feed/feeds/tools/unified-to-mcp.xml - Markdown
/tools/unified-to-mcp.md· slim/tools/unified-to-mcp.min.md(or sendAccept: text/markdown) - Fix list
/fixes/unified-to-mcp.md·/fixes/unified-to-mcp.json - From a terminal
anchor tool unified-to-mcp --md(the CLI) · over MCPget_tool {"slug": "unified-to-mcp"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/unified-to-mcp"><img src="https://www.anchorterminal.com/badges/unified-to-mcp.svg" alt="Unified.to MCP Server on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/unified-to-mcp)<a href="https://www.anchorterminal.com/tools/unified-to-mcp">Unified.to MCP Server on Anchor Terminal</a>It counts on a page on unified.to or one of its subdomains, or the README of github.com/unified-to/unified-mcp-typescript.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "unified-to-mcp", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


