Connect your agents to every app through a single MCP.
Install
npx -y @withone/mcpONE_SECRETrequired · secret — One API key from https://app.withone.ai/settings/api-keysONE_PERMISSIONSoptional — Restrict actions by HTTP method: read (GET), write (GET/POST/PUT/PATCH) or admin (all)ONE_CONNECTION_KEYSoptional — Comma-separated connection keys the agent may see, or * for allONE_ACTION_IDSoptional — Comma-separated action IDs the agent may see and run, or * for allONE_KNOWLEDGE_AGENToptional — Set true to drop execute_one_action and run in knowledge-only modeONE_IDENTITYoptional — Scope connections to a single user, team, organization or project identifierONE_IDENTITY_TYPEoptional — Type of ONE_IDENTITY: user, team, organization or project

One MCP Server
Website · Docs · Dashboard · Changelog · X · LinkedIn
Connect your AI agents to 700+ apps through a single MCP server. Find the actions a task needs with their documentation, and execute API calls across platforms, without having to manage OAuth tokens or API keys.
npm install -g @withone/cli
one init
That's it. The One CLI will prompt you for your API key (get one from the One dashboard) and configure the MCP server for your environment: Claude Desktop, Cursor, Claude Code, Windsurf, or any MCP-compatible agent.
Capabilities
- 700+ platforms. Gmail, Slack, Shopify, HubSpot, Stripe, Linear, QuickBooks, and more.
- Natural language execution. "read my last gmail email", "send a message to #general on Slack"
- Code generation. "build a form to send emails using Gmail", "create a dashboard that lists my Linear projects"
- No tool bloat. Only 3 tools exposed regardless of how many platforms or actions you connect. One call finds every action a task needs, across platforms, with its documentation, so your agent's context window stays clean.
- Fine-grained access control. Restrict which actions, connections, and permission levels (read, write, admin) your agent has access to.
- Secure by default. All requests proxied through One, secrets automatically redacted, no platform API keys to manage.
Examples
Execute actions directly:
"Get my last 5 emails from Gmail"
"Send a Slack message to #general: 'Meeting in 10 minutes'"
"Get all products from my Shopify store"
Generate integration code:
"Create a React form component that sends emails using Gmail"
"Build a dashboard that displays Linear users and their assigned projects with filtering"
"Create a paginatable table that fetches and displays QuickBooks invoices with search and sort"
Tools
The server exposes three MCP tools:
| Tool | Description |
|---|---|
list_one_integrations |
List available platforms and active connections, each with the access it confers (full, methods, or specific actions) |
find_one_actions |
Find the action for every operation a task needs, across platforms, with its documentation, in one call; load fetches more of a document or an alternative's |
execute_one_action |
Execute an API action on a connected platform |
Finding actions
find_one_actions takes one requests entry per operation, each a kebab-case platform and a short intent naming the operation alone ("send a message to a channel", not the message). An optional task describes the whole job in general terms, which helps choose between similar actions. For each intent, One's decision model picks the action to use; the answer documents it, sets apart a substitute when the model was unsure, and lists a few alternatives. Large documents come back as a digest; call find_one_actions again with load: [{ action_id, section }] for a section it left out, full: true for the whole document, or toc: true for its table of contents. ONE_ACTION_IDS, ONE_PERMISSIONS and ONE_CONNECTION_KEYS apply to every answer: an action they refuse is never offered, and when they refuse the model's pick, the next allowed candidate takes its place.
Upgrading from 1.x: search_one_platform_actions and get_one_action_knowledge are removed. find_one_actions replaces both.
Remote MCP Server
Prefer not to run anything locally? One hosts a remote MCP server at https://mcp.withone.ai/mcp. Point any MCP client that supports remote (HTTP) servers at that URL and authenticate with One via OAuth. There's no npm install and no ONE_SECRET to manage. You approve access in One's consent screen, where you can scope exactly which connections, actions, and permission levels the agent gets. Those choices are surfaced back to the agent through each connection's access field, so it knows what it can run without searching.
Add it to your client's MCP configuration. The endpoint speaks the Streamable HTTP transport:
{
"mcpServers": {
"one": {
"type": "http",
"url": "https://mcp.withone.ai/mcp"
}
}
}
Some clients omit type and take the URL alone; UI-based clients (custom connectors) just need the URL itself. On first connect, your client opens a browser to authenticate and authorize with One. After that, the same three tools are available.
One-click install:
The Windsurf link opens One's page in the editor's MCP marketplace, which is served from the official MCP registry where One is published as ai.withone/mcp. Windsurf handles the OAuth sign-in itself once you install from that page.
Manual Installation
If you prefer to configure the server manually instead of using one init, install the package directly:
npm install @withone/mcp
Then set the required environment variable:
ONE_SECRET=your-one-secret-key
Identity Scoping
Scope connections to a specific identity (e.g., a user, team, or organization):
ONE_IDENTITY=user_123
ONE_IDENTITY_TYPE=user
| Variable | Description | Values |
|---|---|---|
ONE_IDENTITY |
The identifier for the entity (e.g., user ID, team ID) | Any string |
ONE_IDENTITY_TYPE |
The type of identity | user, team, organization, project |
When set, the MCP server will only return connections associated with the specified identity. This is useful for multi-tenant applications where you want to scope integrations to specific users or entities.
Access Control
Fine-tune what the MCP server can see and do:
ONE_PERMISSIONS=read
ONE_CONNECTION_KEYS=conn_key_1,conn_key_2
ONE_ACTION_IDS=action_id_1,action_id_2
ONE_KNOWLEDGE_AGENT=true
| Variable | Type | Default | Description |
|---|---|---|---|
ONE_PERMISSIONS |
read | write | admin |
admin |
Filter actions by HTTP method. read = GET only, write = GET/POST/PUT/PATCH, admin = all methods |
ONE_CONNECTION_KEYS |
* or comma-separated keys |
* |
Restrict visible connections and platforms to specific connection keys |
ONE_ACTION_IDS |
* or comma-separated IDs |
* |
Restrict visible and executable actions to specific action IDs |
ONE_KNOWLEDGE_AGENT |
true | false |
false |
Remove the execute_one_action tool entirely, forcing knowledge-only mode. find_one_actions then returns each chosen action's whole document with how to call it from code, and an Integration Code Guide (passthrough URL, x-one-* headers, ONE_SECRET / ONE_{PLATFORM}_CONNECTION_KEY env vars, backend-only placement) for writing application code |
All defaults preserve current behavior. If no access control env vars are set, the server starts with full access and all tools available.
Whatever you configure here is surfaced back to the agent: list_one_integrations stamps each connection with an access field so the agent knows up front what it can run there, without spending a turn searching. It is one of:
access |
When |
|---|---|
{ "policy": "full" } |
No action allowlist and ONE_PERMISSIONS=admin — every action is runnable. |
{ "policy": "methods", "methods": ["GET", ...] } |
No action allowlist, but ONE_PERMISSIONS is read/write — only these HTTP methods are runnable. |
{ "policy": "actions", "actions": [{ "actionId", "title", "method" }] } |
ONE_ACTION_IDS is set — exactly these actions (the ones on that connection's platform) are runnable, so no search is needed. |
Manual Configuration
If you used one init, the configuration below is already done for you. These examples are for reference or manual setups.
Standalone
npx @withone/mcp
Claude Desktop / Cursor
Add the following to your MCP config:
- Claude Desktop: MacOS:
~/Library/Application\ Support/Claude/claude_desktop_config.json· Windows:%APPDATA%/Claude/claude_desktop_config.json - Cursor: Open the Cursor menu and select "MCP Settings"
{
"mcpServers": {
"one": {
"command": "npx",
"args": ["@withone/mcp"],
"env": {
"ONE_SECRET": "your-one-secret-key"
}
}
}
}
Docker
docker build -t one-mcp-server .
docker run -e ONE_SECRET=your_one_secret_key one-mcp-server
All environment variables listed above can be passed as -e flags.
Security
All requests to third-party platforms are authenticated and proxied through One's API. The MCP server never handles OAuth tokens or platform API keys directly. The ONE_SECRET key is the sole credential required, and it is automatically redacted from all response payloads returned to clients. Sensitive headers are stripped from logged and returned request configurations.
License
MIT
Support
For support, please contact support@withone.ai or visit https://withone.ai