Agent Skills

mcp

Connect your agents to every app through a single MCP.

Install

npx -y @withone/mcp
  • ONE_SECRETrequired · secret — One API key from https://app.withone.ai/settings/api-keys
  • ONE_PERMISSIONSoptional — Restrict actions by HTTP method: read (GET), write (GET/POST/PUT/PATCH) or admin (all)
  • ONE_CONNECTION_KEYSoptional — Comma-separated connection keys the agent may see, or * for all
  • ONE_ACTION_IDSoptional — Comma-separated action IDs the agent may see and run, or * for all
  • ONE_KNOWLEDGE_AGENToptional — Set true to drop execute_one_action and run in knowledge-only mode
  • ONE_IDENTITYoptional — Scope connections to a single user, team, organization or project identifier
  • ONE_IDENTITY_TYPEoptional — Type of ONE_IDENTITY: user, team, organization or project
README.md
One MCP — Connect your agents to every app through a single MCP.

One MCP Server

Website  ·  Docs  ·  Dashboard  ·  Changelog  ·  X  ·  LinkedIn

npm version

Connect your AI agents to 700+ apps through a single MCP server. Find the actions a task needs with their documentation, and execute API calls across platforms, without having to manage OAuth tokens or API keys.

npm install -g @withone/cli
one init

That's it. The One CLI will prompt you for your API key (get one from the One dashboard) and configure the MCP server for your environment: Claude Desktop, Cursor, Claude Code, Windsurf, or any MCP-compatible agent.

Capabilities

  • 700+ platforms. Gmail, Slack, Shopify, HubSpot, Stripe, Linear, QuickBooks, and more.
  • Natural language execution. "read my last gmail email", "send a message to #general on Slack"
  • Code generation. "build a form to send emails using Gmail", "create a dashboard that lists my Linear projects"
  • No tool bloat. Only 3 tools exposed regardless of how many platforms or actions you connect. One call finds every action a task needs, across platforms, with its documentation, so your agent's context window stays clean.
  • Fine-grained access control. Restrict which actions, connections, and permission levels (read, write, admin) your agent has access to.
  • Secure by default. All requests proxied through One, secrets automatically redacted, no platform API keys to manage.

Examples

Execute actions directly:

"Get my last 5 emails from Gmail"

"Send a Slack message to #general: 'Meeting in 10 minutes'"

"Get all products from my Shopify store"

Generate integration code:

"Create a React form component that sends emails using Gmail"

"Build a dashboard that displays Linear users and their assigned projects with filtering"

"Create a paginatable table that fetches and displays QuickBooks invoices with search and sort"

Tools

The server exposes three MCP tools:

Tool Description
list_one_integrations List available platforms and active connections, each with the access it confers (full, methods, or specific actions)
find_one_actions Find the action for every operation a task needs, across platforms, with its documentation, in one call; load fetches more of a document or an alternative's
execute_one_action Execute an API action on a connected platform

Finding actions

find_one_actions takes one requests entry per operation, each a kebab-case platform and a short intent naming the operation alone ("send a message to a channel", not the message). An optional task describes the whole job in general terms, which helps choose between similar actions. For each intent, One's decision model picks the action to use; the answer documents it, sets apart a substitute when the model was unsure, and lists a few alternatives. Large documents come back as a digest; call find_one_actions again with load: [{ action_id, section }] for a section it left out, full: true for the whole document, or toc: true for its table of contents. ONE_ACTION_IDS, ONE_PERMISSIONS and ONE_CONNECTION_KEYS apply to every answer: an action they refuse is never offered, and when they refuse the model's pick, the next allowed candidate takes its place.

Upgrading from 1.x: search_one_platform_actions and get_one_action_knowledge are removed. find_one_actions replaces both.

Remote MCP Server

Prefer not to run anything locally? One hosts a remote MCP server at https://mcp.withone.ai/mcp. Point any MCP client that supports remote (HTTP) servers at that URL and authenticate with One via OAuth. There's no npm install and no ONE_SECRET to manage. You approve access in One's consent screen, where you can scope exactly which connections, actions, and permission levels the agent gets. Those choices are surfaced back to the agent through each connection's access field, so it knows what it can run without searching.

Add it to your client's MCP configuration. The endpoint speaks the Streamable HTTP transport:

{
  "mcpServers": {
    "one": {
      "type": "http",
      "url": "https://mcp.withone.ai/mcp"
    }
  }
}

Some clients omit type and take the URL alone; UI-based clients (custom connectors) just need the URL itself. On first connect, your client opens a browser to authenticate and authorize with One. After that, the same three tools are available.

One-click install:

Install in VS Code Install in VS Code Insiders Add to Cursor Open in Windsurf

The Windsurf link opens One's page in the editor's MCP marketplace, which is served from the official MCP registry where One is published as ai.withone/mcp. Windsurf handles the OAuth sign-in itself once you install from that page.

Manual Installation

If you prefer to configure the server manually instead of using one init, install the package directly:

npm install @withone/mcp

Then set the required environment variable:

ONE_SECRET=your-one-secret-key

Identity Scoping

Scope connections to a specific identity (e.g., a user, team, or organization):

ONE_IDENTITY=user_123
ONE_IDENTITY_TYPE=user
Variable Description Values
ONE_IDENTITY The identifier for the entity (e.g., user ID, team ID) Any string
ONE_IDENTITY_TYPE The type of identity user, team, organization, project

When set, the MCP server will only return connections associated with the specified identity. This is useful for multi-tenant applications where you want to scope integrations to specific users or entities.

Access Control

Fine-tune what the MCP server can see and do:

ONE_PERMISSIONS=read
ONE_CONNECTION_KEYS=conn_key_1,conn_key_2
ONE_ACTION_IDS=action_id_1,action_id_2
ONE_KNOWLEDGE_AGENT=true
Variable Type Default Description
ONE_PERMISSIONS read | write | admin admin Filter actions by HTTP method. read = GET only, write = GET/POST/PUT/PATCH, admin = all methods
ONE_CONNECTION_KEYS * or comma-separated keys * Restrict visible connections and platforms to specific connection keys
ONE_ACTION_IDS * or comma-separated IDs * Restrict visible and executable actions to specific action IDs
ONE_KNOWLEDGE_AGENT true | false false Remove the execute_one_action tool entirely, forcing knowledge-only mode. find_one_actions then returns each chosen action's whole document with how to call it from code, and an Integration Code Guide (passthrough URL, x-one-* headers, ONE_SECRET / ONE_{PLATFORM}_CONNECTION_KEY env vars, backend-only placement) for writing application code

All defaults preserve current behavior. If no access control env vars are set, the server starts with full access and all tools available.

Whatever you configure here is surfaced back to the agent: list_one_integrations stamps each connection with an access field so the agent knows up front what it can run there, without spending a turn searching. It is one of:

access When
{ "policy": "full" } No action allowlist and ONE_PERMISSIONS=admin — every action is runnable.
{ "policy": "methods", "methods": ["GET", ...] } No action allowlist, but ONE_PERMISSIONS is read/write — only these HTTP methods are runnable.
{ "policy": "actions", "actions": [{ "actionId", "title", "method" }] } ONE_ACTION_IDS is set — exactly these actions (the ones on that connection's platform) are runnable, so no search is needed.

Manual Configuration

If you used one init, the configuration below is already done for you. These examples are for reference or manual setups.

Standalone

npx @withone/mcp

Claude Desktop / Cursor

Add the following to your MCP config:

  • Claude Desktop: MacOS: ~/Library/Application\ Support/Claude/claude_desktop_config.json · Windows: %APPDATA%/Claude/claude_desktop_config.json
  • Cursor: Open the Cursor menu and select "MCP Settings"
{
  "mcpServers": {
    "one": {
      "command": "npx",
      "args": ["@withone/mcp"],
      "env": {
        "ONE_SECRET": "your-one-secret-key"
      }
    }
  }
}

Docker

docker build -t one-mcp-server .
docker run -e ONE_SECRET=your_one_secret_key one-mcp-server

All environment variables listed above can be passed as -e flags.

Security

All requests to third-party platforms are authenticated and proxied through One's API. The MCP server never handles OAuth tokens or platform API keys directly. The ONE_SECRET key is the sole credential required, and it is automatically redacted from all response payloads returned to clients. Sensitive headers are stripped from logged and returned request configurations.

License

MIT

Support

For support, please contact support@withone.ai or visit https://withone.ai

Search skills and MCP servers

Fuzzy search across 23,137 skills and servers