Windsor.ai MCP Server
for AI Agents
Connect your AI agent to StackOne's Windsor.ai MCP server and give it ready-to-use MCP tools out of the box. Auth, tool execution, and security all managed.
Coverage
12 Agent Actions
Create, read, update, and delete across Windsor.ai — and extend your agent's capabilities with custom actions.
Authentication
Agent Tool Authentication
Per-user OAuth in one call. Your Windsor.ai MCP server gets session-scoped tokens with zero credentials stored on your infra.
Agent Auth →Security
Agent Protection
Every Windsor.ai tool response scanned for prompt injection in milliseconds — 88.7% accuracy, all running on CPU.
Prompt Injection Defense →Performance
Max Agent Context. Min Cost.
Free up to 96% of your agent's context window to enhance reasoning and reduce cost, on every Windsor.ai call.
Tools Discovery →What is the Windsor.ai MCP Server?
A Windsor.ai MCP server lets AI agents read and write Windsor.ai data through the Model Context Protocol — Anthropic's open standard for connecting LLMs to external tools. StackOne's Windsor.ai MCP server ships with pre-built actions, fully extensible via the Connector Builder — plus managed authentication, prompt injection defense, observability, and agent execution runtime. Connect it from MCP clients like Claude Desktop, Claude Code, Cursor, Goose, and VS Code, or from agent frameworks like OpenAI Agents SDK, LangChain, and Vercel AI SDK.
All Windsor.ai MCP Tools
Every action from Windsor.ai's API, ready for your agent. Create, read, update, and delete — scoped to exactly what you need.
Connected Accounts
- List Connected Accounts
List the upstream platform accounts connected to the workspace.
Connector Actions
- List Connector Actions
List the write actions a connector supports.
Execute Connector Actions
- Execute Connector Action
Run a write action against one connected account on the upstream platform.
Connectors
- List Connectors
List every upstream data source available through the Windsor.ai API.
Available Connector Fields
- Retrieve Available Connector Fields
List the metrics and dimensions a connector can report on.
Connector Options
- Get Connector Options
List the configuration options a connector supports.
Connector Connect Infos
- Get Connector Connect Info
Get the details needed to connect a data source to the workspace.
Generate Co-User Authorization Links
- Generate Co-User Authorization Link
Generate a link letting a client connect their own data source without sharing credentials.
Co-User Linked Accounts
- List Co-User Linked Accounts
List the accounts clients or teammates connected through an authorization link.
Unlink Co-User Linked Accounts
- Unlink Co-User Linked Account
Remove one co-user connected account from the team.
Custom Fields
- List Custom Fields
List the custom fields defined in the workspace.
Connector Datas
- Get Connector Data
Retrieve reporting rows from one data source, or blended rows across every source.
Windsor.ai AI Agent Use Cases
Connect your AI agent to Windsor.ai and help your team scale the marketing operations they run by hand today.
Use StackOne to connect your AI agent to your marketing automation, CRM, and email tools to automate lead nurture email sequences.
ViewUse StackOne to connect your AI agent to your marketing automation, email, and analytics platforms to automate campaign performance reporting.
ViewUse StackOne to connect your AI agent to your document stores, email platforms, and messaging tools to automate content repurposing and distribution.
ViewSet Up Your Windsor.ai MCP Server in Minutes
One endpoint. Any framework. Your agent is talking to Windsor.ai in under 10 lines of code.
Agent Frameworks
{
"mcpServers": {
"stackone": {
"command": "npx",
"args": [
"-y",
"mcp-remote@latest",
"https://api.stackone.com/mcp?x-account-id=<account_id>",
"--header",
"Authorization: Basic <YOUR_BASE64_TOKEN>"
]
}
}
}Check More marketing MCP Servers
59+ actions
57+ actions
52+ actions
35+ actions
Platform Resources
MCP Code Mode: Keeping Tool Responses Out of Agent Context
Anthropic's code_execution processes data already in context. Custom MCP code mode keeps raw tool responses in a sandbox. 14K tokens vs 500.
11 min
Comparing BM25, TF-IDF, and Hybrid Search for MCP Tool Discovery
Benchmarking BM25, TF-IDF, and hybrid search for MCP tool discovery across 916 tools. The 80/20 TF-IDF/BM25 hybrid hits 21% Top-1 accuracy in under 1ms.
10 min
Indirect Prompt Injection Defense for MCP Tools: A Technical Guide
MCP tools that read emails, CRM records, and tickets are indirect prompt injection vectors. Here's how we built a two-tier defense that scans tool results in ~11ms.
12 min
MCP vs A2A: Architecture, Security, and When to Use Each
MCP vs A2A: what each protocol standardizes, how they differ, their shared security risks including indirect prompt injection, and when to use one, both, or a hybrid architecture.
12 min
MCP vs API: What Hundreds of Connector Builds Taught Us
MCP wraps APIs, it doesn't replace them. After building hundreds of connectors that serve both, here's when each approach wins.
14 min read
Windsor.ai MCP Server FAQ
Does StackOne have a Windsor.ai MCP server?
Windsor.ai MCP server vs direct API integration — what's the difference?
How does Windsor.ai authentication work for AI agents?
origin_owner_id.Are Windsor.ai MCP tools vulnerable to prompt injection?
What is the context bloat of a Windsor.ai agent and how do I avoid it?
Can I limit which actions my Windsor.ai agent can access?
Can I create custom agent actions for my Windsor.ai MCP server?
When should I NOT use a Windsor.ai MCP server?
What AI frameworks and AI clients does the StackOne Windsor.ai MCP server support?
Put your AI agents to work
All the tools you need to build and scale AI agent integrations, with best-in-class connectivity, execution, and security.