# Unified.to MCP Server > Unified.to MCP Server is a hosted Streamable HTTP server from Unified API Inc. that turns one end-customer connection to a business app into MCP tools, on top of the vendor's unified API for CRM, HR, accounting and other categories. - Canonical: https://www.anchorterminal.com/tools/unified-to-mcp - Markdown: https://www.anchorterminal.com/tools/unified-to-mcp.md (~9,350 tokens) - Slim: https://www.anchorterminal.com/tools/unified-to-mcp.min.md (~2,030 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/unified-to-mcp.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-10 ## Overview **Grade C · 61.9/100 · rank #455 of 950 · #5 in Agent tool access · not agent-ready · confidence medium** ## Assessment Every previewed tool carries a typed input schema and read-only, destructive and idempotent annotations, and the list can be narrowed by permission or tool name. The default credential is a workspace API key that reaches every connection, and the SSE transport was removed on 23 September 2026 in the changelog entry that announced it. ## Facts | Field | Value | | --- | --- | | Vendor | Unified API Inc. (https://unified.to) | | Kind | MCP server | | Category | Agent tool access (https://www.anchorterminal.com/categories/aggregator) | | Transport | Streamable HTTP | | Endpoint | `https://mcp-api.unified.to/mcp` | | Auth | OAuth or key · Self-serve. A person signs in to app.unified.to with Google or GitHub and copies a workspace API key. Sent as `Authorization: Bearer ` with `connection=` in the URL, it lists that connection's tools, and without a connection it lists workspace management tools. The docs warn that the key reaches every connection and the whole account. The management tool `get_unified_connection_mcp_url` in `user` mode returns a URL with a signed token limited to one connection. Enterprise-managed authorisation exchanges an identity provider's assertion at `POST /oauth/token` for an `ema_` token that lasts 3,600 seconds and carries category read and write scopes. Unified turns it on per workspace on request. `?token=` still works for keys and is marked deprecated. | | Pricing | Paid ($750 / mo) · Plans from $750 a month. Grow is $750+ with 750,000 API calls and $1.00 per 1,000 beyond that, Pro $1,500+ with 2,000,000 and $0.75, Scale $3,000+ with 6,000,000 and $0.50, and Enterprise is priced on contract. Each MCP tool call counts as one API request, and the FAQ says successful calls are billable. A tester account starts with 2,500 free API requests and Grow and Pro start with a 30-day free trial. The page does not say whether a card is needed (https://unified.to/pricing, checked 2026-10-09). | | x402 | No · No x402, MPP or L402 in the docs index, the MCP docs pages, the pricing page or the Terms of Service (checked 2026-10-09). | | Licence | Proprietary service under Unified.to's Terms of Service. The linked repository is sample client code | | Packages | npm: `@unified-api/typescript-sdk` | | MCP registry name | `to.unified/core` | | Source | https://github.com/unified-to/unified-mcp-typescript | | Docs | https://docs.unified.to/mcp/overview | | llms.txt | https://docs.unified.to/llms.txt | | Last release | 2026-10-08 | | npm downloads / week | 22,019 | | Endpoints | `https://mcp-api.unified.to/mcp` (US), `https://mcp-api-eu.unified.to/mcp` (EU) and `https://api-au.unified.to/mcp` (AU). Streamable HTTP only. Regions do not resolve across one another | | Modes | Connection mode lists one end-customer connection's tools. Core mode, with a workspace API key and no connection, lists 21 management tools for connections, webhooks, integrations, issues, API-call logs, environments and docs search | | Credentials | Workspace API key in the `Authorization` header or `x-api-key`, a connection-scoped signed token in `?token=` (`user` mode), or an `ema_` access token from an RFC 7523 `jwt-bearer` exchange, enabled per workspace on request | | Tool filters | `permissions` (for example `crm_contact_read`), `tools` (ids or wildcards such as `list_*`), `defer_tools`, `aliases`, `hide_sensitive` and `include_external_tools`, all as URL parameters | | Tool shape | Names follow `list_`, `get_`, `create_`, `update_` and `remove_` plus category and object, such as `list_crm_contacts`. List tools take `fields`, `limit`, `offset`, `updated_gte`, `sort`, `order` and `query` where the integration supports them | | Annotations | In the HubSpot preview all 78 tools set `readOnlyHint`, `destructiveHint`, `idempotentHint` and `openWorldHint`. Create, update and remove tools are all marked destructive | | Catalogue | 94,258 tools on 8 October 2026, 17,189 of them unified, per the MCP changelog. The pricing page counts 1,236 integrations and 33 unified APIs. All vendor figures | | Rate limits | Per workspace, per minute. Test 500, Grow 5,000, Pro 7,500, Scale 10,000. The connected app's own limits apply first. Unified does not queue or retry synchronous calls | | Free use | A tester account with 2,500 free API requests, per the pricing page description, and a 30-day free trial on Grow and Pro. Whether a card is needed is not stated | | Logs | API call logs kept 30 days on Test, 60 on Grow and Pro and 365 on Scale, per the privacy policy. Pro and Scale can stream logs to Datadog. Core mode tools `list_unified_apicalls` and `get_unified_apicall` read them | | Data handling | The privacy policy says end-customer data is processed in transit and not stored or cached, and that no models are trained on any data. Credentials and configuration are stored in the workspace's region | | Hosting | Separate US, EU and AU regions. The sub-processor list of 2 October 2025 names AWS, Render, MongoDB, Redis and ClickHouse in all three, and Datadog, PostHog, Stripe and Customer.io in the US | | Certifications | SOC 2 Type II, with GDPR, CCPA, HIPAA and PIPEDA compliance stated on the security page. A BAA is on the Scale plan. Reports are requested through a trust centre we did not read | | Other interfaces | The unified REST API with an OpenAPI 3.0 file, SDKs for TypeScript, Python, PHP, Java, Go, C# and Ruby (all dated 21 September 2026 on the docs), a CLI and more than 100 agent skill files | | Capabilities | automation.apps, automation.auth, automation.actions, agent.tools, automation.webhooks | | Tags | hosted, mcp, paid, free-trial, api-key, openapi, llms-txt, typescript, python, status-page, soc2, mcp-registry, closed-source, data-residency | | JSON | https://www.anchorterminal.com/api/v1/tools/unified-to-mcp.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 73 | 14.6 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 81 | 13.2 | | Agent ergonomics | 13% | 16.2 | 71 | 11.5 | | Security & auth | 14% | 17.5 | 50 | 8.8 | | Payments & pricing | 10% | 12.5 | 30 | 3.8 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 84 | 7.3 | | Transparency & trust (editorial 61, provenance 71) | 7% | 8.8 | 66 | 5.8 | | Negative events | up to −15 | up to −15 | 23 September 2026. The MCP changelog entry of that date removed the SSE transport (`/sse` and `/sse/messages` now return HTTP 410), dropped `sse_url` from the `get_unified_connection_mcp_url` response, which the docs label a breaking change, and stopped regions resolving across one another. No earlier notice was found in the MCP changelog, the site changelog or the September product update. Whether customers were told privately was not established. The migration is a one-word URL change and is documented, so 3 points (https://docs.unified.to/mcp/changelog). | -3 | | **Total** | | | | **61.9 → C** | ### Why each score - Reliability 73: Read with the hosted lines. status.unified.to on Honeybadger lists seven components, the API and the admin app in three regions and the authentication page. The MCP server has no component of its own (20). The page lists one incident in three months, API performance issues on 13 August 2026, resolved in an hour. Its detail page is closed by robots.txt and was not read, so it is counted as minor (20). Workspace limits are published per plan, from 500 to 10,000 requests a minute (15). The docs describe exponential backoff with jitter on 429 and say Unified does not queue or retry. No `Retry-After` header and no idempotency key were found (8). No uptime SLA is published. The pricing page says SLAs come with a custom Enterprise plan (0). The server launched on 1 June 2025 and carries no beta label (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 81: One credential-free `tools/list` preview for HubSpot returned 78 tools, each with a JSON Schema input and 66 with an output schema. The API has a published OpenAPI 3.0 file, which we did not read (25). llms.txt on the docs and the site, a full-text file, and a Markdown twin of every docs page (10). Tool descriptions state the action, what is returned, what is required and which sibling tool to use, for example 'Permanently removes the record and cannot be undone'. They follow one template and say nothing about provider differences (15). The 78 inputs hold 531 properties and 135 enums with no open objects at the top level. `limit` and `offset` have no bounds and some filters are plain strings (12). Client set-up examples for eight hosts and a table of eight HTTP status codes. No per-tool examples, and MCP error results are not documented (8). A dated MCP changelog since June 2025. The server has no version scheme beyond the registry's 1.0.0 (11). - Agent ergonomics 71: One HubSpot connection lists 78 tools, about 133 KB of definitions without output schemas and 343 KB with them, which scores 5. Eight back for the `tools`, `permissions` and `defer_tools` filters, which the docs tell users to set (13). List tools take `limit`, `offset`, a `fields` selection, `updated_gte`, `sort`, `order` and `query`. Pages hold 100 records at most and there is no cursor or total (18). The unauthenticated call returned a JSON-RPC error with a plain message naming the header to send, and the REST status table explains 401, 403, 429 and 501. Tool error results are not documented (11). All 78 previewed tools set `readOnlyHint`, `destructiveHint` and `idempotentHint`. Creates are marked not idempotent and there is no idempotency key (15). 44 required fields across 531 properties, and API SDKs in seven languages. Every option travels as a URL parameter (14). - Security & auth 50: The default credential is a workspace API key that the docs say reaches all connections and the whole account. A signed token limited to one connection, keys limited to an environment and enterprise-managed tokens with category scopes and a one-hour life raise this to 22. Ten off because `?token=` in the URL is a documented option, deprecated for keys with no end date, and the only way the connection-scoped token is sent (12). `permissions` and `tools` limit the tool list, enterprise scopes hide tools a token may not call, and connections are isolated from one another. No approval step for writes was found (14). Tool results are third-party content. `hide_sensitive` removes PII, and no prompt-injection guidance was found (4). API call logs kept 30 to 365 days by plan, readable through management tools and streamable to Datadog on Pro and Scale. The docs warn that a workspace key leaves no per-person audit trail (10). SOC 2 Type II and yearly penetration tests are stated. security.txt returned 404, no bounty or disclosure policy was found, and the trust centre was not read (10). - Payments & pricing 30: No x402, MPP or L402 (0). Plan prices and overage rates per 1,000 API calls are public, and each tool call counts as one request. Two off because every plan price is shown with a plus sign and the terms of the free tester account are not set out (18). A tester account with 2,500 free requests and a 30-day trial are stated. Whether a card is needed is not stated, so part marks (12). A person signs up in a browser. The vendor's September 2026 update says creating the account still takes a person (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 84: MCP changelog entry on 8 October 2026 (30). Entries on 22 July, 21 and 23 September and 8 October 2026 (20). A closed service with a daily site changelog, a public Discord for support and a stated response within 24 hours on the Test plan (12). `to.unified/core` is in the official MCP registry under the vendor's domain namespace (15). The docs date all seven API SDKs 21 September 2026. The sample MCP client repository was last changed on 29 August 2025 and its README still documents the removed `dc` option (7). - Transparency & trust 66: The editorial half. Closed service under Terms of Service that name Unified API Inc. and Ontario law. Two off because the terms carry no date and bar sending financial or medical information and birth dates through a service sold for accounting and HR data (13). The privacy policy has an MCP section, says end-customer data is not stored and no models are trained, and gives retention periods by plan. The DPA of 19 March 2026 promises breach notice within 72 hours and deletion within a reasonable period on request. The security page says no data is stored at rest, ever, while the policy lists stored credentials, configuration and logs, and the page says Unified runs on AWS while the sub-processor list also names Render (22). No deprecation policy. `?token=` carries a `Deprecation` header with no end date, a field deprecation notice was published in November 2025, and SSE was removed on the day it was announced (8). Ten sub-processors with locations, dated 2 October 2025, and three named regions. The DPA gives 15 days' notice of new sub-processors on a best-efforts basis (18). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (22 items): https://www.anchorterminal.com/fixes/unified-to-mcp.md (JSON https://www.anchorterminal.com/fixes/unified-to-mcp.json) ### What we couldn't check - unchecked: the trust centre at app.mycroft.io/trust/unified-to, where the SOC 2 report and policies are requested. We did not open it - unchecked: the detail page of the 13 August 2026 incident, which status.unified.to's robots.txt closes - unchecked: the OpenAPI file at api.unified.to, which we did not fetch, and the OAuth metadata at `/.well-known/oauth-protected-resource/mcp` - unchecked: the registration date of unified.to and the GitHub star count of the sample repository - unchecked: tool lists for integrations other than HubSpot, and the tool list with `include_external_tools` - Whether customers were told before 23 September 2026 that SSE, `sse_url` and cross-region resolution would go - Whether the tester account or the 30-day trial needs a card, and what the tester account's limits are beyond 2,500 requests - Which OAuth flow the privacy policy means by an OAuth token bound to one workspace with read or read and write permission. The 401 response advertises scopes `mcp:read mcp:write`, and the docs describe only the enterprise-managed exchange - When `?token=` authentication will stop working. The docs say a `Sunset` header will appear once a date is set - The Terms of Service forbid probing, scanning or testing the vulnerability of the service, which matters before any probe is run - We typed three `.md` addresses on unified.to that no page links (privacy, sub-processors, changelog). Each answered 404 and nothing was taken from them. The `?integration_type=` preview was named by the server's 401 message, not by a docs page we read ### Sources - robots.txt, which allows every path and names Anthropic's agents as allowed: (seen 2026-10-09) - docs robots.txt, which allows every path: (seen 2026-10-09) - docs index: (seen 2026-10-09) - site index: (seen 2026-10-09) - MCP overview: (seen 2026-10-09) - MCP authentication: (seen 2026-10-09) - MCP changelog: (seen 2026-10-09) - MCP core mode, endpoints, transport and client configuration: (seen 2026-10-09) - MCP server options: (seen 2026-10-09) - MCP installation and usage: (seen 2026-10-09) - MCP additional API endpoints: (seen 2026-10-09) - rate limits: (seen 2026-10-09) - pagination: (seen 2026-10-09) - REST API, regions and status codes: (seen 2026-10-09) - SDKs and specification files: (seen 2026-10-09) - log retention guide of April 2024: (seen 2026-10-09) - pricing: (seen 2026-10-09) - Terms of Service: (seen 2026-10-09) - security page: (seen 2026-10-09) - privacy policy: (seen 2026-10-09) - Data Processing Agreement: (seen 2026-10-09) - sub-processor list: (seen 2026-10-09) - support terms: (seen 2026-10-09) - site changelog: (seen 2026-10-09) - blog post on the 2026-07-28 MCP revision: (seen 2026-10-09) - September 2026 product update: (seen 2026-10-09) - security.txt, 404: (seen 2026-10-09) - status page: (seen 2026-10-09) - MCP endpoint. robots.txt answered 404. One `initialize` (401 with a `WWW-Authenticate` header) and one `tools/list` with `?integration_type=hubspot`, both without credentials: (seen 2026-10-09) - official MCP registry search: (seen 2026-10-09) - sample MCP client repository, cloned: (seen 2026-10-09) - Python SDK repository, commit history: (seen 2026-10-09) - npm weekly downloads for @unified-api/typescript-sdk: (seen 2026-10-09) ## Who's behind it (provenance 71/100, checked 2026-10-09) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Unified API Inc. | 20/20 | | Domain age | unified.to, no registry record we could read | 0/15 | | Endpoint on the vendor's domain | mcp-api.unified.to | 15/15 | | Terms of service | read, states 5 of the 7 things a reader expects, and has 1 clause that costs points | 6.3/10 | | Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 | | Status page | status.unified.to | 10/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The Terms of Service say the site and the service are operated by Unified API Inc. and are governed by the laws of the Province of Ontario. The page carries no date. The DPA, last revised 19 March 2026, names UNIFIED API Inc., an Ontario corporation at 325 Front Street West, 4th floor, Toronto. The privacy policy covers unified.to, api.unified.to, app.unified.to and sub-domains, and has a section on the MCP server at mcp-api.unified.to. The MCP endpoints answer at mcp-api.unified.to, mcp-api-eu.unified.to and api-au.unified.to. unified.to/.well-known/security.txt returned 404. status.unified.to runs on Honeybadger and lists the API and the admin app in three regions and the authentication page. The MCP server has no component of its own. The docs say it runs as part of the API. The registration date of unified.to was not looked up. The .to registry publishes no RDAP record we know of. The trust centre at app.mycroft.io/trust/unified-to was not read. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://unified.to/tos), read 2026-10-09, gives no date, states 5 of the 7 things a reader expects. - To know. Restricts benchmarking or competitive use (costs points). "(C) use or access the Service to build or support, and/or assist a third party in building or supporting, products or services competitive to Unified.to;" - To know. Says access can be ended without notice or for any reason. "(e) Termination and Suspension by Unified.to: Unified.to may terminate your User Account and/or these Terms of Service at any time and for any reason upon notice to you." - Not found in the text. Gives the date it was last updated. - Names the governing law or courts. The law of the Province of Ontario. - States a limit on its liability. Rules out indirect and consequential losses, with no cap named in this sentence. - Says how changes to the terms are announced. Says it gives notice of a change. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). An account with no login for 12 months or more may be treated as inactive and permanently deleted with all its data. "If you do not log in to your User Account for 12 or more months, we may treat your User Account as "inactive" and permanently delete the User Account and all the data associated with it." - Also in the text (2026-10-08). Users may not transmit, import or upload financial or medical information, or sensitive personal information, through the site or service. "transmitting, importing, uploading, or incorporating any financial or medical information of any nature, or any sensitive personal information" - Also in the text (2026-10-08). Unified.to may use aggregated or anonymised data, including data derived from user content, to improve its own products and may disclose it in de-identified form. "Unified.to will be free at any time to: (i) use such information and data to improve and enhance Unified.to's offerings; and (ii) disclose such data in aggregate or other de-identified form in connection with its business." **Privacy policy** (https://unified.to/privacy), read 2026-10-09, dated 2026-10-02, states 8 of the 8 things a reader expects. - Gives the date it was last updated. Last updated 2026-10-02. - Says how long data is kept. Names a period of 30 days. - Gives a privacy contact. privacy@unified.to. - Says where data is transferred or stored. Relies on standard contractual clauses. - Also in the text (2026-10-08). Unified.to states that it does not train machine-learning models on any data. "We also do not train machine-learning models on any data." - Also in the text (2026-10-08). The MCP server is described as receiving only the parameters of each tool call, with no access to the AI assistant's conversations, prompts, memory or files. "It does not access your AI assistant's conversations, chat history, prompts, memory, or files — it receives only the specific parameters of each tool call (for example, an object id or a search filter) and returns the corresponding Unified.to API data." - Also in the text (2026-10-08). Data partners may use cookies to link website visits and logins to other personal information, including an email address, and marketing may then be sent to that address. "When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email." ## Live (updated 2026-10-10 02:55 UTC) - Right now: up, HTTP 401, 379 ms, checked 2026-10-10 02:55 UTC (mcp-initialize on `https://mcp-api.unified.to/mcp`, asks for auth) - Uptime 24h 100.0% (115 probes) · 30 days 100.0% (115 probes) · p50 273 ms · p95 810 ms - Vendor status page: unknown, no machine-readable status found - npm `@unified-api/typescript-sdk` 2.85.49 - Watching changelog - Watching pricing - Watching privacy - Watching terms - Tools: the endpoint asks for credentials before listing them (checked 2026-10-09 21:40 UTC) - Always current: https://www.anchorterminal.com/api/v1/live/unified-to-mcp.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Grow plan | $750 | per month (plan) | Listed as $750+ a month. 750,000 API calls a month, each tool call counting as one | | Pro plan | $1500 | per month (plan) | Listed as $1,500+ a month. 2,000,000 API calls a month | | Scale plan | $3000 | per month (plan) | Listed as $3,000+ a month. 6,000,000 API calls a month | | Overage, Grow | $1 | per 1,000 requests | Per 1,000 API calls beyond the plan allowance | | Overage, Pro | $0.75 | per 1,000 requests | Per 1,000 API calls beyond the plan allowance | | Overage, Scale | $0.50 | per 1,000 requests | Per 1,000 API calls beyond the plan allowance | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - A credential-free preview of the HubSpot tool list returned 78 tools, each with a JSON Schema input and `readOnlyHint`, `destructiveHint` and `idempotentHint` annotations, and 66 with an output schema - The `permissions` and `tools` URL parameters limit which tools a connection lists, and `hide_sensitive` strips names, emails and telephone numbers from results - A `user` mode URL carries a signed token limited to one connection, so the workspace API key need not be shared with an end customer - Rate limits are published per plan, from 500 requests a minute on Test to 10,000 on Scale, shared across the workspace - The privacy policy has an MCP section. It says end-customer data is not stored or cached and that Unified does not train models on any data - The MCP changelog is dated and had entries on 22 July, 21 and 23 September and 8 October 2026 ## Weaknesses - The default credential is a workspace API key. The docs say it grants access to all connections and the whole Unified.to account - The `/sse` transport and the `sse_url` response field were removed on 23 September 2026. No earlier notice was found in the MCP changelog, the site changelog or the September update - The connection-scoped signed token travels in the URL as `?token=`. The docs mark `?token=` authentication as deprecated, with no end date set - One HubSpot connection lists 78 tools whose definitions come to about 133 KB without output schemas and 343 KB with them - No uptime SLA is published. The pricing page says SLAs come with a custom Enterprise plan - No security.txt, bug bounty or disclosure policy was found, and the security page gives February 2025 as its last review - The Terms of Service forbid probing, scanning or testing the vulnerability of the service. This matters before any probe is run - The Terms of Service bar transmitting financial or medical information and birth dates through the service, while the product sells accounting and HR integrations ## Before you call it (notes for agents) 1. Use the host for the workspace's region. US is `mcp-api.unified.to`, EU is `mcp-api-eu.unified.to` and AU is `api-au.unified.to`. A credential on another region's host resolves to not found 2. Send the key as `Authorization: Bearer ` and put `connection=` in the URL. Without `connection` the server lists workspace management tools, not the customer's data tools 3. Pass `tools` or `permissions` in the URL before listing. An unfiltered connection can list dozens of tools with large output schemas 4. Expect HTTP 429 on tool calls since 23 September 2026. Unified does not queue or retry, so back off and retry yourself 5. Page with `limit` (100 at most on most endpoints) and `offset`, and stop when a page returns fewer records than `limit` ## Connect Claude Code: ```bash claude mcp add --transport http unified-core https://mcp-api.unified.to/mcp \ --header "Authorization: Bearer $UNIFIED_API_KEY" ``` MCP client configuration: ```json { "mcpServers": { "unified-mcp": { "headers": { "Authorization": "Bearer XXXXXXXX" }, "url": "https://mcp-api.unified.to/mcp?connection=YYYYYYY" } } } ``` Through letme (picks today, calling later): https://letme.dev/unified-to-mcp. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Composio (API + MCP) | BB | 75.1 | 55 | automation.apps, automation.auth, automation.actions, agent.tools, automation.webhooks | no | https://www.anchorterminal.com/tools/composio-rube.md | | Smithery | D | 50.7 | 766 | automation.apps, automation.auth, automation.actions, agent.tools, automation.webhooks | no | https://www.anchorterminal.com/tools/smithery.md | | Merge Agent Handler | B | 69.5 | 183 | automation.apps, automation.auth, automation.actions, agent.tools | no | https://www.anchorterminal.com/tools/merge-agent-handler.md | | StackOne | B | 69.1 | 198 | automation.apps, automation.auth, automation.actions, agent.tools | no | https://www.anchorterminal.com/tools/stackone.md | | One | B | 66.6 | 282 | automation.apps, automation.auth, automation.actions, agent.tools | no | https://www.anchorterminal.com/tools/one.md | | Pipedream API + MCP | B | 65.5 | 315 | automation.apps, automation.webhooks, automation.auth, agent.tools | no | https://www.anchorterminal.com/tools/pipedream.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - Streamable HTTP at `/mcp` is the only transport. `/sse` and `/sse/messages` return HTTP 410 since 23 September 2026 (source: ) - Three credentials. A workspace API key with a `connection` parameter, a workspace API key alone for management tools, and enterprise-managed tokens with the `ema_` prefix that expire after 3,600 seconds and carry `.read` and `.write` scopes (source: ) - The vendor's changelog counts 94,258 tools on 8 October 2026, of which 17,189 are unified tools, up from 69,948 on 21 September. These are vendor figures across the whole catalogue (source: ) - One unauthenticated `tools/list` request with `?integration_type=hubspot`, a preview the server's own 401 message describes, returned 78 tools. 41 are read-only, 13 create, 12 update and 12 remove. Creates carry `destructiveHint` true and `idempotentHint` false (source: ) - Each tool call counts as one API request on the plan, and tool calls are checked against the workspace rate limit (source: ) - `include_external_tools=true` adds the integration's raw provider endpoints as further tools. Enterprise-managed tokens cannot reach them (source: ) - `GET /tools?type=` returns the tool list shaped for OpenAI, Anthropic, Gemini, Cohere, Grok or Groq, and `POST /tools/{id}/call` runs one tool over plain HTTP (source: ) - The official MCP registry lists `to.unified/core` at version 1.0.0 with a Streamable HTTP remote (source: ) - The vendor says the server runs the stateless 2026-07-28 MCP revision since 28 July 2026 and does not implement MCP Apps, Tasks or the revision's authorisation changes (source: ) - The docs index and the site index open with lines that point coding agents to a skill file and a plugin install command. We read them as data (source: ) - The overview page still says most OpenAI models handle only 20 tools, and the options page still describes a public generated token, which the changelog says was removed on 17 December 2025 (source: ) - #5 of 8 in Best agent tool access platforms: https://www.anchorterminal.com/best/aggregator/index.md - All 28 tool access comparisons: https://www.anchorterminal.com/compare/aggregator/index.md ## Compare - [Composio (API + MCP) vs Unified.to MCP Server](https://www.anchorterminal.com/compare/composio-rube-vs-unified-to-mcp.md): BB 75.1 vs C 61.9 - [Merge Agent Handler vs Unified.to MCP Server](https://www.anchorterminal.com/compare/merge-agent-handler-vs-unified-to-mcp.md): B 69.5 vs C 61.9 - [One vs Unified.to MCP Server](https://www.anchorterminal.com/compare/one-vs-unified-to-mcp.md): B 66.6 vs C 61.9 - [Smithery vs Unified.to MCP Server](https://www.anchorterminal.com/compare/smithery-vs-unified-to-mcp.md): D 50.7 vs C 61.9 - [StackOne vs Unified.to MCP Server](https://www.anchorterminal.com/compare/stackone-vs-unified-to-mcp.md): B 69.1 vs C 61.9 - [Unified.to MCP Server vs Zapier MCP (agent actions)](https://www.anchorterminal.com/compare/unified-to-mcp-vs-zapier-mcp.md): C 61.9 vs C 58.1 - [letme vs Unified.to MCP Server](https://www.anchorterminal.com/compare/letme-vs-unified-to-mcp.md): F 36.4 vs C 61.9 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on unified.to or one of its subdomains, or the README of github.com/unified-to/unified-mcp-typescript. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "unified-to-mcp", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Unified.to MCP Server on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Unified.to MCP Server on Anchor Terminal](https://www.anchorterminal.com/badges/unified-to-mcp.svg)](https://www.anchorterminal.com/tools/unified-to-mcp) ``` Plain link: ```html Unified.to MCP Server on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Unified.to MCP Server is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/unified-to-mcp-dark.png - Light: https://www.anchorterminal.com/assets/share/unified-to-mcp-light.png