Connect
Optimize
Secure
The #1 agentic semantic tool search: 91.6% first-try accuracy on S1 Search Bench • Explore Tool Discovery →
Connect your AI agent to StackOne's Ironclad MCP server and give it 64 MCP tools out of the box. Auth, tool execution, and security all managed.
Coverage
Create, read, update, and delete across Ironclad — and extend your agent's capabilities with custom actions.
Authentication
Per-user OAuth in one call. Your Ironclad MCP server gets session-scoped tokens with zero credentials stored on your infra.
Agent Auth →Security
Every Ironclad tool response scanned for prompt injection in milliseconds — 88.7% accuracy, all running on CPU.
Prompt Injection Defense →Performance
Free up to 96% of your agent's context window to enhance reasoning and reduce cost, on every Ironclad call.
Tools Discovery →A Ironclad MCP server lets AI agents read and write Ironclad data through the Model Context Protocol — Anthropic's open standard for connecting LLMs to external tools. StackOne's Ironclad MCP server ships with 64 pre-built actions, fully extensible via the Connector Builder — plus managed authentication, prompt injection defense, observability, and agent execution runtime. Connect it from MCP clients like Claude Desktop, Claude Code, Cursor, Goose, and VS Code, or from agent frameworks like OpenAI Agents SDK, LangChain, and Vercel AI SDK.
Every action from Ironclad's API, ready for your agent. Create, read, update, and delete — scoped to exactly what you need.
Create a Record
Retrieve a Record
Delete a Record
Create an Attachment on a Record
Retrieve an Attachment on a Record
Delete an Attachment on a Record
Create a Webhook
Retrieve a Webhook
Update a Webhook
Delete a Webhook
Create an Entity
Retrieve an Entity
Update an Entity
Delete an Entity
Create an Obligation
Retrieve an Obligation
Update an Obligation
Create a Workflow Synchronously
Send Signature Request
Create a Comment on a Workflow
List All Workflows
Retrieve a Workflow
List All Workflow Approvals
Retrieve the Turn History on a Workflow
Retrieve Sign Step Status
List All Workflow Signers
List All Workflow Participants
List all Comments on a Workflow
List a Comment from a Specified Workflow
Retrieve Documents from a Workflow
Retrieve a Workflow Document
List All Workflow Schemas
Retrieve a Workflow Schema
List All Records
Retrieve Records Schema
List All Webhooks
Retrieve Webhook Verification Key
Get All Entity Relationship Types
List All Entities
List All Obligations
Download Data Export File
Update Approval Status on a Workflow
Update Workflow Metadata
Update Record Metadata
Cancel Signature Request
Cancel a Workflow
Pause a Workflow
Resume a Workflow
Replace a Record
Run an Action on a Record
Submit a request to generate a new data export
Check Data Export Job Status
Triggered when an Ironclad workflow is launched (e.g. via the launch_a_new_workflow action). Retrieve the workflow with get_workflow using the eventId (payload.workflowID).
Triggered when an Ironclad workflow reaches completion. payload.recordIDs lists the records created from the workflow; retrieve the workflow with get_workflow using the eventId (payload.workflowID).
Triggered when an Ironclad workflow is cancelled (e.g. via the cancel_a_workflow action). Retrieve the workflow with get_workflow using the eventId (payload.workflowID).
Triggered when an Ironclad workflow is paused (e.g. via the pause_a_workflow action). Retrieve the workflow with get_workflow using the eventId (payload.workflowID).
Triggered when an Ironclad workflow is resumed (e.g. via the resume_a_workflow action). Retrieve the workflow with get_workflow using the eventId (payload.workflowID).
Triggered when the approval status of an Ironclad workflow changes (e.g. via the update_workflow_approval action). Retrieve the workflow with get_workflow using the eventId (payload.workflowID).
Triggered when workflow attributes are modified (e.g. via the update_workflow_metadata action). payload.changedAttributes lists the changed fields; retrieve the workflow with get_workflow using the eventId (payload.workflowID).
Triggered when a comment is added to an Ironclad workflow (e.g. via the create_comment_on_a_workflow action). payload.commentID identifies the comment; retrieve the workflow with get_workflow using the eventId (payload.workflowID).
Triggered when a signature packet is sent out for signature (e.g. via the send_signature_request action). Retrieve the workflow with get_workflow using the eventId (payload.workflowID).
Triggered when a signature request is cancelled (e.g. via the cancel_signature_request action). payload.cause holds the cancellation reason; retrieve the workflow with get_workflow using the eventId (payload.workflowID).
Triggered when all signers have signed the signature packet on an Ironclad workflow. Retrieve the workflow with get_workflow using the eventId (payload.workflowID).
Triggered when the contract status of an Ironclad repository record changes (e.g. via the run_an_action_on_a_record or replace_record action). payload.status holds the new status; retrieve the record with get_record using the eventId (payload.recordID). Subscribe via record_contract_status_changed; Ironclad delivers it with payload.event = contract_status_changed.
One endpoint. Any framework. Your agent is talking to Ironclad in under 10 lines of code.
Agent Frameworks
{
"mcpServers": {
"stackone": {
"command": "npx",
"args": [
"-y",
"mcp-remote@latest",
"https://api.stackone.com/mcp?x-account-id=<account_id>",
"--header",
"Authorization: Basic <YOUR_BASE64_TOKEN>"
]
}
}
}Anthropic's code_execution processes data already in context. Custom MCP code mode keeps raw tool responses in a sandbox. 14K tokens vs 500.
11 min
Benchmarking BM25, TF-IDF, and hybrid search for MCP tool discovery across 916 tools. The 80/20 TF-IDF/BM25 hybrid hits 21% Top-1 accuracy in under 1ms.
10 min
MCP tools that read emails, CRM records, and tickets are indirect prompt injection vectors. Here's how we built a two-tier defense that scans tool results in ~11ms.
12 min
MCP vs A2A: what each protocol standardizes, how they differ, their shared security risks including indirect prompt injection, and when to use one, both, or a hybrid architecture.
12 min
MCP wraps APIs, it doesn't replace them. After building 200+ connectors that serve both, here's when each approach wins.
14 min read
origin_owner_id.All the tools you need to build and scale AI agent integrations, with best-in-class connectivity, execution, and security.