StackOne
What is StackOne?
StackOne is an agent-to-app connectivity platform for product, platform, and AI infrastructure teams that routes agents through managed auth and secure execution. It combines Connect, Optimize, Secure, Connector Builder, MCP, Tool Discovery, and Defender to reach 270+ integrations and 18,000+ actions. Customers include Drata, Introist, Popp, GP, Flip, and Mindtools. Plans run Starter free, with Core and Enterprise custom pricing.
Last verifiedHow we evaluate
At a glance
- StackOne is best for product and platform teams that need secure, scalable agent integrations across many business apps.
- Starter Free; Core Custom; Enterprise Custom
Two products under one name, priced on different axes
The most common way to misread StackOne's pricing is to assume it is one product. It is two, and the vendor is explicit about it: "Gateway on platform + seats + usage credits, OEM on platform + usage credits."
Gateway is for your own agents and staff — you connect your company's SaaS tools and let agents act in them. It is billed per seat plus usage. Plans are Starter (free), Team ($600/month, or $6,000/year) and Enterprise (contact sales).
OEM / Embed is the white-label case: you put StackOne inside your own product so your customers connect their tools in one click. There are no seats — it is platform fee plus usage credits. Plans are OEM Core (free to start) and OEM Enterprise (contact sales).
These solve genuinely different problems, and a buyer evaluating the wrong one will get the wrong cost model. If you are a SaaS vendor who needs to offer 200 integrations to your customers, you want OEM and the seat prices below are irrelevant to you. If you are an enterprise wiring up internal agents, you want Gateway and the per-seat maths matters a great deal.
The problem it solves well: 28,000 actions that won't fit in a context window
This is where StackOne is doing something more interesting than a conventional unified API, and it is worth understanding even if you end up buying a competitor.
If you expose an agent to a large connector catalogue the naive way — one tool definition per action — you spend your context window before the agent does any work. StackOne's answer, Search & Execute, collapses the catalogue into two tools: search finds actions by natural-language description and returns ranked action IDs, and execute runs the chosen one. The vendor's own documentation puts the saving concretely: "500 tools loaded · ~150,000 tokens" against "2 tools · ~900 tokens", and notes the footprint stays flat whatever the catalogue size.
The honest trade-off, which the docs also state, is that you are inserting a retrieval step between the agent and the tool. Ranking quality becomes a dependency, and StackOne's own guidance is to use it "when your agent spans many SaaS systems — dozens to thousands of tools" and to prefer individual tools "for a small, focused action set where you want the model to see every tool." That is a fair characterisation and matches what the mechanism can and cannot do.
Access is available through MCP, A2A, CLI, SDK or REST, and MCP access is included even on the free plan rather than held back for paying tiers.
What "479 connectors" means when you actually browse the directory
StackOne's connectors page advertises "28,000+ pre-built actions across 479 connectors" (elsewhere on the site the figure is rounded to "450+").
We checked this rather than repeating it. The connector directory embeds its own data in the page, with a status field per entry. Counting them: 479 carry status live, and a further 718 carry status planned — roughly 1,197 records in total. So the headline number is exactly the live count, and StackOne is not inflating it by folding in the roadmap. That is worth saying plainly, because in this category the opposite is common.
The practical consequence is for you rather than for them: when you browse that directory you are looking at about 1,200 logos, of which around 40% are actually available today. Confirm the status of the specific systems you need before you assume coverage, and treat a logo you recognise as a prompt to check, not as a yes.
A second, softer signal on depth: the public documentation index carries per-connector pages for 334 connectors, fewer than the 479 live. Undocumented does not mean non-functional — the action catalogue is browsable in the dashboard — but if you rely on public docs to scope an integration before buying, expect to hit connectors where you cannot do that.
The original vertical unified APIs are still there and still documented — HRIS, ATS, CRM, LMS, IAM, marketing, accounting, ticketing, documents and messaging — so the agent-gateway repositioning has been additive rather than a replacement.
Defender: a real open-source component, and a third-party benchmark
StackOne publishes @stackone/defender under Apache-2.0 — a prompt-injection filter for tool results, bundling a ~22MB ONNX classifier that runs on CPU. It is not a demo repo: it recorded 25,917 npm downloads in the month to 9 August 2026, and the GitHub repository carries 115 stars. It is genuinely usable without buying StackOne, and the same capability is wired into the paid platform as "premium defense", which consumes credits at a higher rate than an ordinary call.
On effectiveness, there are two numbers and they deserve separating.
StackOne's own README reports an average F1 of 0.9079 across three public datasets. That is a self-run evaluation.
Separately, an open head-to-head benchmark called AgentShield scores StackOne Defender 79.8, third of seven providers — ahead of Lakera Guard (79.4) but behind Deepset DeBERTa (87.6) and the top entry AgentGuard (98.4). The relevant caveat is that this benchmark is maintained by the team behind Agent Guard, whose own product tops the table; that conflict is disclosed in the README itself. We verified that StackOne's fork of the benchmark carries results identical to the upstream repository, so the figures have not been re-cut in StackOne's favour. Read the table as a competitor-run comparison — but a reproducible, openly published one, which is more than most vendors in this space offer.
A note if you go looking: the benchmark repository sits in StackOne's GitHub organisation, but it is a fork. It is not StackOne's benchmark.
How pricing works, and where it changes shape
All figures verified against the pricing page on 15 August 2026.
The credit unit. "One tool call or API call costs 1 credit; advanced capabilities — browser use, premium defense, data sync — cost more." This is the number to model. Included allowances refresh monthly per seat; purchased top-up credits are valid 12 months and pooled across the organisation.
Gateway Starter — free. 1 seat included, 1,000 credits per seat per month, $10 per additional seat, capped at 10 seats. All 479 live connectors and MCP access are included. At 1,000 calls a month this is an evaluation tier, not a production one.
Gateway Team — $600/month, or $6,000/year. 10 seats included, 5,000 credits per seat per month, $15 per additional seat, capped at 100 seats. Fully loaded at 100 seats that is $1,950/month.
Gateway Enterprise — contact sales.
Three things a buyer should notice:
Top-up credits cost three times as much on Starter. Additional credits are $60 per 20,000 bundle on Starter against $20 per 20,000 on Team — $0.003 versus $0.001 per call. If your usage is real, the $600 platform fee partly buys a cheaper marginal rate, not just features.
SAML SSO arrives on Team, not Enterprise. Google sign-in is on every plan; SAML 2.0 through Okta, Entra and similar, plus project-level RBAC, is included at $600/month. Plenty of comparable vendors hold SSO back for a sales conversation, so this is a point in StackOne's favour.
Self-hosting is an Enterprise add-on. On-premise/VPC deployment is unavailable on Starter and Team, and on Enterprise it is listed as "Add-on" — priced separately, on top of an already custom-quoted tier. If a self-hosted deployment is a hard requirement, budget for it as a distinct line item and get the number in writing early.
On the OEM side, OEM Core starts free with 1,000 credits included and scales in 1,000-credit steps; the calculator's own parameters price each additional 1,000 credits at $3, which is consistent with the $60-per-20,000 Starter rate. OEM Enterprise is contact-sales. Audit logs and SIEM export sit on Enterprise on both product lines.
Operational track record you can check yourself
StackOne runs a public status page with 90-day per-component uptime, which is more accountability than most vendors at this stage offer. For the window May–August 2026 it reports 99.990% for the StackOne API, 100% for the Connectors Hub, and 99.25% for the web dashboard. The dashboard figure is materially worse than the API figure — worth knowing if your team lives in the UI, largely irrelevant if you only call the API.
Documented API limits are concrete: 1,000 requests per minute per API key, returning 429 with a Retry-After header, and the docs note the limit "may change in the future". Requests have a 60-second lifetime. When an upstream provider rate-limits StackOne, it retries automatically up to 5 times using the provider's own Retry-After, returning a 408 if the retries exceed the request lifetime. That last behaviour is a sensible default and saves you writing per-provider backoff logic, but it also means a slow upstream shows up in your application as a timeout rather than as a rate-limit signal — worth handling explicitly.
StackOne states it is SOC 2 Type II certified and GDPR, HIPAA and CCPA compliant, with the SOC 2 report and a BAA available on Enterprise. It runs a Drata-backed trust centre at trust.stackone.com. We could not read the trust centre's contents — it renders client-side — so treat the certifications as vendor-stated until you pull the report under NDA.
Company, funding and size
The operating entity is StackOne Technologies LTD, registered in England and Wales, company number 14684360, incorporated 23 February 2023 and currently active. Founders Romain Sestier (CEO) and Guillaume Lebedel (CTO) are both directors of record.
StackOne raised a $20M Series A led by GV (Google Ventures) announced 6 May 2025, with Workday Ventures, XTX Ventures, Episode 1 and Playfair participating, taking total funding to $24M. Workday Ventures on the cap table is a meaningful detail given how much of the connector catalogue is HR systems. No further round has been publicly announced in the fifteen months since.
On size, the only independent figure is from Companies House: accounts made up to 31 December 2024 report an average of 13 employees during that period, up from 5 the year before. That predates the Series A and the entire agent-gateway build-out, so it tells you the company was small before the money arrived and nothing reliable about today. Current headcount is not established. The company files under small-company exemptions, so no turnover figure is disclosed. Accounts for the year to 31 December 2025 had not been filed as of 15 August 2026 and are not yet due.
The growth in the catalogue is, however, documented at two points by primary sources: the May 2025 press release claimed "10,000+ actions on 200+ connectors", against 28,000+ actions and 479 live connectors on the site today. Both are vendor figures, but they are the vendor's own figures fifteen months apart, and the direction is consistent with a team that shipped.
What we could not establish
Stated plainly, so you can go and check these yourself rather than assume we looked and found nothing bad.
Independent user reviews. G2's StackOne page blocks automated access (403 to both direct fetch and proxy), so we could not read a rating or review count. We are not reporting that reviews are absent — only that we could not see them. Comparison articles ranking StackOne against Merge, Unified.to and similar are, in every case we found, published by a competitor, and we have not used any of them as evidence here.
Customer claims. Drata, Attensi, Localyze and Mindtools are named by StackOne, along with "1 billion API calls" and Drata launching "100 integrations". None of these is corroborated by an independent source and all should be read as vendor claims.
Compliance certifications. SOC 2 Type II, HIPAA and GDPR are asserted on the site and behind a trust centre we could not read programmatically. Ask for the report.
Current headcount and revenue. Not disclosed; the 2024 accounts are the last filed.
Real-world Search & Execute ranking quality. The token-saving figures come from StackOne's docs. We found no published evaluation of how often the search step returns the correct action, and StackOne's action-search-eval repository has no public README. If your use case depends on the agent reliably finding the right action among thousands, ask for eval numbers during a trial and run your own.
How much does StackOne cost?
| Plan | Price | What's included |
|---|---|---|
| Starter | Free |
|
| Core | Contact Us |
|
| Enterprise | Contact Us |
|
Frequently asked questions
What is StackOne?
StackOne is an agent-to-app connectivity platform for product, platform, and AI infrastructure teams that routes agents through managed auth and secure execution. It combines Connect, Optimize, Secure, Connector Builder, MCP, and Tool Discovery to reach 270+ integrations and 18,000+ actions. Customers include Drata, Introist, and Popp. Plans run Starter free, with Core and Enterprise both custom pricing.
How much does StackOne cost? Is it free?
StackOne has a free plan, with paid tiers including Core at Contact Us, Enterprise at Contact Us.
What is StackOne used for? Who is it for?
StackOne is used for Connect, Optimize, and Secure. It's built for Platform engineers, Product teams that want AI agents to operate across business systems with real-time execution and permissions control, and AI infrastructure teams that need MCP, SDK, and API access for the same integration layer.
Does StackOne have an API and what does it integrate with?
StackOne doesn't publish a public API. It integrates with Workday, OneLogin, Docebo, BambooHR, Slack, and 25 more.
Editor's read
Starter includes 1 custom connector and up to 1,000 free action calls per month, then $3 per 1,000 calls. Check whether your expected connector count and call volume will push you into Core or Enterprise before you commit.
