Skip to main content The #1 agentic semantic tool search: 91.6% first-try accuracy on S1 Search Bench Explore Tool Discovery
Live 12 Actions

Windsor.ai MCP Server
for AI Agents

Connect your AI agent to StackOne's Windsor.ai MCP server and give it ready-to-use MCP tools out of the box. Auth, tool execution, and security all managed.

Windsor.ai logo
Windsor.ai MCP Server
Built by StackOne StackOne
DrataGPLocalyzeFlipMindtoolsScreenloop

Coverage

12 Agent Actions

Create, read, update, and delete across Windsor.ai — and extend your agent's capabilities with custom actions.

Authentication

Agent Tool Authentication

Per-user OAuth in one call. Your Windsor.ai MCP server gets session-scoped tokens with zero credentials stored on your infra.

Agent Auth →

Security

Agent Protection

Every Windsor.ai tool response scanned for prompt injection in milliseconds — 88.7% accuracy, all running on CPU.

Prompt Injection Defense →

Performance

Max Agent Context. Min Cost.

Free up to 96% of your agent's context window to enhance reasoning and reduce cost, on every Windsor.ai call.

Tools Discovery →

What is the Windsor.ai MCP Server?

A Windsor.ai MCP server lets AI agents read and write Windsor.ai data through the Model Context Protocol — Anthropic's open standard for connecting LLMs to external tools. StackOne's Windsor.ai MCP server ships with pre-built actions, fully extensible via the Connector Builder — plus managed authentication, prompt injection defense, observability, and agent execution runtime. Connect it from MCP clients like Claude Desktop, Claude Code, Cursor, Goose, and VS Code, or from agent frameworks like OpenAI Agents SDK, LangChain, and Vercel AI SDK.

All Windsor.ai MCP Tools

Every action from Windsor.ai's API, ready for your agent. Create, read, update, and delete — scoped to exactly what you need.

Connected Accounts

  • List Connected Accounts

    List the upstream platform accounts connected to the workspace.

Connector Actions

  • List Connector Actions

    List the write actions a connector supports.

Execute Connector Actions

  • Execute Connector Action

    Run a write action against one connected account on the upstream platform.

Connectors

  • List Connectors

    List every upstream data source available through the Windsor.ai API.

Available Connector Fields

  • Retrieve Available Connector Fields

    List the metrics and dimensions a connector can report on.

Connector Options

  • Get Connector Options

    List the configuration options a connector supports.

Connector Connect Infos

  • Get Connector Connect Info

    Get the details needed to connect a data source to the workspace.

Generate Co-User Authorization Links

  • Generate Co-User Authorization Link

    Generate a link letting a client connect their own data source without sharing credentials.

Co-User Linked Accounts

  • List Co-User Linked Accounts

    List the accounts clients or teammates connected through an authorization link.

Unlink Co-User Linked Accounts

  • Unlink Co-User Linked Account

    Remove one co-user connected account from the team.

Custom Fields

  • List Custom Fields

    List the custom fields defined in the workspace.

Connector Datas

  • Get Connector Data

    Retrieve reporting rows from one data source, or blended rows across every source.

Windsor.ai AI Agent Use Cases

Connect your AI agent to Windsor.ai and help your team scale the marketing operations they run by hand today.

Lead Nurture Sequences

Use StackOne to connect your AI agent to your marketing automation, CRM, and email tools to automate lead nurture email sequences.

View
HubSpotSalesforceActiveCampaignKlaviyoSendGridMailchimpLemlistGmail
Campaign Performance Reports

Use StackOne to connect your AI agent to your marketing automation, email, and analytics platforms to automate campaign performance reporting.

View
HubSpotMailchimpActiveCampaignKlaviyoSalesforceBrazeSendGridMarketo
Content Repurposing

Use StackOne to connect your AI agent to your document stores, email platforms, and messaging tools to automate content repurposing and distribution.

View
Google DriveConfluenceNotionMailchimpSendGridSlackGmailMicrosoft Teams

Set Up Your Windsor.ai MCP Server in Minutes

One endpoint. Any framework. Your agent is talking to Windsor.ai in under 10 lines of code.

Agent Frameworks

Claude Desktop
{
  "mcpServers": {
    "stackone": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote@latest",
        "https://api.stackone.com/mcp?x-account-id=<account_id>",
        "--header",
        "Authorization: Basic <YOUR_BASE64_TOKEN>"
      ]
    }
  }
}

Check More marketing MCP Servers

Windsor.ai MCP Server FAQ

Does StackOne have a Windsor.ai MCP server?
Yes. StackOne offers a hosted Windsor.ai MCP server, and every action is tested and QA'd by StackOne. Connect it to Claude, Cursor, and any other MCP client, or to any agent framework through the AI Action SDK. It ships with managed agent authentication, prompt injection defense, and tool discovery with server-side execution that preserve your agent's context window and keep reasoning performance.
Windsor.ai MCP server vs direct API integration — what's the difference?
A Windsor.ai MCP server and direct API integration serve different use cases. Direct API integration is for software-to-software — backend code calling Windsor.ai. A Windsor.ai MCP server is for AI agents — MCP clients like Claude and Cursor, plus framework agents built with OpenAI, LangChain, or Vercel AI — discovering and calling Windsor.ai at runtime. StackOne provides both.
How does Windsor.ai authentication work for AI agents?
Windsor.ai authentication for AI agents works through a StackOne Connect Session. Create one via the dashboard or the SDK — you get an auth link and ready-to-paste config for Claude Desktop, Cursor, and other MCP clients. Your user authenticates their own Windsor.ai account; StackOne handles token exchange, storage, and refresh. Credentials never reach the LLM, and each user is isolated via origin_owner_id.
Are Windsor.ai MCP tools vulnerable to prompt injection?
Yes — Windsor.ai MCP tools can be vulnerable to indirect prompt injection. Any tool that reads user-written content — documents, messages, tickets, records, or free-text fields — is a potential vector. StackOne Defender scans every tool response before it enters the agent's context — regex patterns in ~1ms, then a MiniLM classifier in ~4ms. 88.7% accuracy, CPU-only.
What is the context bloat of a Windsor.ai agent and how do I avoid it?
Context bloat happens when Windsor.ai tool schemas and API responses eat your Windsor.ai agent's memory, preventing it from reasoning effectively. A single Windsor.ai query can return a massive JSON response, and connecting multiple tools compounds the problem. Tools Discovery and Code Mode reduce context bloat — loading only relevant tools per query and keeping raw responses out of the agent's context.
Can I limit which actions my Windsor.ai agent can access?
Yes — you can limit which actions your Windsor.ai agent can access directly from the StackOne dashboard. Toggle actions on or off, or restrict them to specific accounts, with no code changes to your agent. Session tokens can be scoped to exact actions so if one leaks, exposure stays contained.
Can I create custom agent actions for my Windsor.ai MCP server?
Yes — you can create custom agent actions for your Windsor.ai MCP server using Connector Builder. It's an integration agent your coding assistant (Claude Code, Cursor, or Copilot) can invoke to research Windsor.ai's API, generate production-ready connector YAML, test against the live API, and validate before you ship.
When should I NOT use a Windsor.ai MCP server?
Skip a Windsor.ai MCP server if your integration is purely software-to-software — direct Windsor.ai API integration is simpler when no AI agent is involved. For deterministic, compliance-critical operations (financial transactions, regulatory reporting), direct API gives you predictable behavior without agent-driven decision-making. MCP shines when AI agents need to dynamically discover and call Windsor.ai actions at runtime.
What AI frameworks and AI clients does the StackOne Windsor.ai MCP server support?
The StackOne Windsor.ai MCP server supports both. MCP clients (paste-and-go apps): Claude Desktop, Claude Code, Cursor, VS Code, Goose. Agent frameworks (code SDKs you build with): OpenAI Agents SDK, Anthropic, Vercel AI, Google ADK, CrewAI, Pydantic AI, LangChain, LangGraph, Azure AI Foundry.

Put your AI agents to work

All the tools you need to build and scale AI agent integrations, with best-in-class connectivity, execution, and security.