One
Search, document and execute authenticated API calls across all your apps (Gmail, Slack, Stripe, Notion, GitHub, and more) through 4 universal tools whose context footprint stays constant no matter how many connections you add. Hosted remote server with OAuth at https://mcp.withone.ai/mcp, or run locally via npx @withone/mcp.
README
<img src="https://assets.withone.ai/banners/mcp.png?v=3" alt="One MCP — Connect your agents to every app through a single MCP." style="border-radius: 5px;">
<h3 align="center">One MCP Server</h3>
<p align="center"> <a href="https://withone.ai"><strong>Website</strong></a> · <a href="https://withone.ai/docs"><strong>Docs</strong></a> · <a href="https://app.withone.ai"><strong>Dashboard</strong></a> · <a href="https://withone.ai/changelog"><strong>Changelog</strong></a> · <a href="https://x.com/withoneai"><strong>X</strong></a> · <a href="https://linkedin.com/company/withoneai"><strong>LinkedIn</strong></a> </p>
<p align="center"> <a href="https://npmjs.com/package/@withone/mcp"><img src="https://img.shields.io/npm/v/%40withone%2Fmcp" alt="npm version"></a> </p>
Connect your AI agents to 500+ apps through a single MCP server. Search for actions, read documentation, and execute API calls across platforms, without having to manage OAuth tokens or API keys.
npm install -g @withone/cli
one init
That's it. The One CLI will prompt you for your API key (get one from the One dashboard) and configure the MCP server for your environment: Claude Desktop, Cursor, Claude Code, Windsurf, or any MCP-compatible agent.
Capabilities
- 500+ platforms. Gmail, Slack, Shopify, HubSpot, Stripe, Linear, QuickBooks, and more.
- Natural language execution. "read my last gmail email", "send a message to #general on Slack"
- Code generation. "build a form to send emails using Gmail", "create a dashboard that lists my Linear projects"
- No tool bloat. Only 4 tools exposed regardless of how many platforms or actions you connect. Actions are search-based, so your agent's context window stays clean.
- Fine-grained access control. Restrict which actions, connections, and permission levels (read, write, admin) your agent has access to.
- Secure by default. All requests proxied through One, secrets automatically redacted, no platform API keys to manage.
Examples
Execute actions directly:
"Get my last 5 emails from Gmail"
"Send a Slack message to #general: 'Meeting in 10 minutes'"
"Get all products from my Shopify store"
Generate integration code:
"Create a React form component that sends emails using Gmail"
"Build a dashboard that displays Linear users and their assigned projects with filtering"
"Create a paginatable table that fetches and displays QuickBooks invoices with search and sort"
Tools
The server exposes four MCP tools:
| Tool | Description |
|---|---|
list_one_integrations |
List available platforms and active connections, each with the access it confers (full, methods, or specific actions) |
search_one_platform_actions |
Search for actions on a specific platform |
get_one_action_knowledge |
Get detailed documentation for an action |
execute_one_action |
Execute an API action on a connected platform |
Remote MCP Server
Prefer not to run anything locally? One hosts a remote MCP server at https://mcp.withone.ai/mcp. Point any MCP client that supports remote (HTTP) servers at that URL and authenticate with One via OAuth. There's no npm install and no ONE_SECRET to manage. You approve access in One's consent screen, where you can scope exactly which connections, actions, and permission levels the agent gets. Those choices are surfaced back to the agent through each connection's access field, so it knows what it can run without searching.
Add it to your client's MCP configuration. The endpoint speaks the Streamable HTTP transport:
{
"mcpServers": {
"one": {
"type": "http",
"url": "https://mcp.withone.ai/mcp"
}
}
}
Some clients omit type and take the URL alone; UI-based clients (custom connectors) just need the URL itself. On first connect, your client opens a browser to authenticate and authorize with One. After that, the same four tools are available.
Manual Installation
If you prefer to configure the server manually instead of using one init, install the package directly:
npm install @withone/mcp
Then set the required environment variable:
ONE_SECRET=your-one-secret-key
Identity Scoping
Scope connections to a specific identity (e.g., a user, team, or organization):
ONE_IDENTITY=user_123
ONE_IDENTITY_TYPE=user
| Variable | Description | Values |
|---|---|---|
ONE_IDENTITY |
The identifier for the entity (e.g., user ID, team ID) | Any string |
ONE_IDENTITY_TYPE |
The type of identity | user, team, organization, project |
When set, the MCP server will only return connections associated with the specified identity. This is useful for multi-tenant applications where you want to scope integrations to specific users or entities.
Access Control
Fine-tune what the MCP server can see and do:
ONE_PERMISSIONS=read
ONE_CONNECTION_KEYS=conn_key_1,conn_key_2
ONE_ACTION_IDS=action_id_1,action_id_2
ONE_KNOWLEDGE_AGENT=true
| Variable | Type | Default | Description |
|---|---|---|---|
ONE_PERMISSIONS |
read | write | admin |
admin |
Filter actions by HTTP method. read = GET only, write = GET/POST/PUT/PATCH, admin = all methods |
ONE_CONNECTION_KEYS |
* or comma-separated keys |
* |
Restrict visible connections and platforms to specific connection keys |
ONE_ACTION_IDS |
* or comma-separated IDs |
* |
Restrict visible and executable actions to specific action IDs |
ONE_KNOWLEDGE_AGENT |
true | false |
false |
Remove the execute_one_action tool entirely, forcing knowledge-only mode. get_one_action_knowledge responses additionally include an Integration Code Guide (passthrough URL, x-one-* headers, ONE_SECRET / ONE_{PLATFORM}_CONNECTION_KEY env vars, backend-only placement) for writing application code |
All defaults preserve current behavior. If no access control env vars are set, the server starts with full access and all tools available.
Whatever you configure here is surfaced back to the agent: list_one_integrations stamps each connection with an access field so the agent knows up front what it can run there, without spending a turn searching. It is one of:
access |
When |
|---|---|
{ "policy": "full" } |
No action allowlist and ONE_PERMISSIONS=admin — every action is runnable. |
{ "policy": "methods", "methods": ["GET", ...] } |
No action allowlist, but ONE_PERMISSIONS is read/write — only these HTTP methods are runnable. |
{ "policy": "actions", "actions": [{ "actionId", "title", "method" }] } |
ONE_ACTION_IDS is set — exactly these actions (the ones on that connection's platform) are runnable, so no search is needed. |
Manual Configuration
If you used one init, the configuration below is already done for you. These examples are for reference or manual setups.
Standalone
npx @withone/mcp
Claude Desktop / Cursor
Add the following to your MCP config:
- Claude Desktop: MacOS:
~/Library/Application\ Support/Claude/claude_desktop_config.json· Windows:%APPDATA%/Claude/claude_desktop_config.json - Cursor: Open the Cursor menu and select "MCP Settings"
{
"mcpServers": {
"one": {
"command": "npx",
"args": ["@withone/mcp"],
"env": {
"ONE_SECRET": "your-one-secret-key"
}
}
}
}
Docker
docker build -t one-mcp-server .
docker run -e ONE_SECRET=your_one_secret_key one-mcp-server
All environment variables listed above can be passed as -e flags.
Security
All requests to third-party platforms are authenticated and proxied through One's API. The MCP server never handles OAuth tokens or platform API keys directly. The ONE_SECRET key is the sole credential required, and it is automatically redacted from all response payloads returned to clients. Sensitive headers are stripped from logged and returned request configurations.
License
MIT
Support
For support, please contact support@withone.ai or visit https://withone.ai
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。