Skip to main content

Announcing StackOne Defender: leading open-source prompt injection guard for your agent Read More

Cornerstone MCP Server
for AI Agents

Production-ready Cornerstone MCP server with 21 extensible actions — plus built-in authentication, security, and optimized execution.

Cornerstone logo
Cornerstone MCP Server
Built by StackOne StackOne

Coverage

21 Agent Actions

Create, read, update, and delete across Cornerstone — and extend your agent's capabilities with custom actions.

Authentication

Agent Tool Authentication

Per-user OAuth in one call. Your Cornerstone MCP server gets session-scoped tokens with zero credentials stored on your infra.

Agent Auth →

Security

Agent Protection

Every Cornerstone tool response scanned for prompt injection in milliseconds — 88.7% accuracy, all running on CPU.

Prompt Injection Defense →

Performance

Max Agent Context. Min Cost.

Free up to 96% of your agent's context window to enhance reasoning and reduce cost, on every Cornerstone call.

Tools Discovery →

What is the Cornerstone MCP Server?

A Cornerstone MCP server lets AI agents read and write Cornerstone data through the Model Context Protocol — Anthropic's open standard for connecting LLMs to external tools. StackOne's Cornerstone MCP server ships with 21 pre-built actions, fully extensible via the Connector Builder — plus managed authentication, prompt injection defense, and optimized agent context. Connect it from MCP clients like Claude Desktop, Cursor, and VS Code, or from agent frameworks like OpenAI Agents SDK, LangChain, and Vercel AI SDK.

All Cornerstone MCP Tools and Actions

Every action from Cornerstone's API, ready for your agent. Create, read, update, and delete — scoped to exactly what you need.

Learning Assignments

  • Search Learning Assignments

    Search for and retrieve details on assignments created via API or Learning Assignment Tool

  • Get Learning Assignment

    Retrieve details of a specific learning assignment by ID

Other (19)

  • Create Express Class

    Submit an Express Class for one or more attendees

  • Create Learning Object

    Create a new learning object in Cornerstone Learning

  • Get Learning Object Details

    Retrieve details of a learning object available to an active user

  • Search Transcripts

    Search and retrieve users transcript information from Cornerstone Learning

  • Get Transcript Enhanced Details

    Returns enhanced details for a transcript record

  • Get Transcript Curricula Child Details

    Returns child related details for a curricula transcript record

  • Get Remaining Assignment Count

    Get the count of remaining assignments by date

  • List Users

    Retrieve a list of users from the users_core object with OData query support

  • Get Approvals

    Retrieve pending approvals for a manager or approver

  • Get Assigned Trainings

    Retrieve all training assigned to a user with statuses and due dates

  • Get Inbox Items

    Retrieve transcript records for a user from their inbox

  • Get Sessions

    Retrieve upcoming sessions in a user's transcript

  • Get Suggested Trainings

    Retrieve a user's transcript and task data for suggested trainings

  • Get Tasks

    Retrieve all incomplete tasks assigned to a user

  • Get Transcripts (Legacy)

    Retrieve transcript records for a user (legacy endpoint)

  • Update Transcript Progress

    Change a registered transcript record to "In Progress" status

  • Catalog Search

    Search the training catalog based on specific criteria

  • Assign Training

    Assign training to a user transcript

  • Complete Training

    Mark a transcript record as completed

Set Up Your Cornerstone MCP Server in Minutes

One endpoint. Any framework. Your agent is talking to Cornerstone in under 10 lines of code.

MCP Clients

Agent Frameworks

Claude Desktop
{
  "mcpServers": {
    "stackone": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote@latest",
        "https://api.stackone.com/mcp?x-account-id=<account_id>",
        "--header",
        "Authorization: Basic <YOUR_BASE64_TOKEN>"
      ]
    }
  }
}

More Learning / LMS MCP Servers

Cornerstone MCP Server FAQ

Cornerstone MCP server vs direct API integration — what's the difference?
A Cornerstone MCP server and direct API integration serve different use cases. Direct API integration is for software-to-software — backend code calling Cornerstone. A Cornerstone MCP server is for AI agents — MCP clients like Claude and Cursor, plus framework agents built with OpenAI, LangChain, or Vercel AI — discovering and calling Cornerstone at runtime. StackOne provides both.
How does Cornerstone authentication work for AI agents?
Cornerstone authentication for AI agents works through a StackOne Connect Session. Create one via the dashboard or the SDK — you get an auth link and ready-to-paste config for Claude Desktop, Cursor, and other MCP clients. Your user authenticates their own Cornerstone account; StackOne handles token exchange, storage, and refresh. Credentials never reach the LLM, and each user is isolated via origin_owner_id.
Are Cornerstone MCP tools vulnerable to prompt injection?
Yes — Cornerstone MCP tools can be vulnerable to indirect prompt injection. Any tool that reads user-written content — documents, messages, tickets, records, or free-text fields — is a potential vector. StackOne Defender scans every tool response before it enters the agent's context — regex patterns in ~1ms, then a MiniLM classifier in ~4ms. 88.7% accuracy, CPU-only.
What is the context bloat of a Cornerstone agent and how do I avoid it?
Context bloat happens when Cornerstone tool schemas and API responses eat your Cornerstone agent's memory, preventing it from reasoning effectively. A single Cornerstone query can return a massive JSON response, and connecting multiple tools compounds the problem. Tools Discovery and Code Mode reduce context bloat — loading only relevant tools per query and keeping raw responses out of the agent's context.
Can I limit which actions my Cornerstone agent can access?
Yes — you can limit which actions your Cornerstone agent can access directly from the StackOne dashboard. Toggle actions on or off, or restrict them to specific accounts, with no code changes to your agent. Session tokens can be scoped to exact actions so if one leaks, exposure stays contained.
Can I create custom agent actions for my Cornerstone MCP server?
Yes — you can create custom agent actions for your Cornerstone MCP server using Connector Builder. It's an integration agent your coding assistant (Claude Code, Cursor, or Copilot) can invoke to research Cornerstone's API, generate production-ready connector YAML, test against the live API, and validate before you ship.
When should I NOT use a Cornerstone MCP server?
Skip a Cornerstone MCP server if your integration is purely software-to-software — direct Cornerstone API integration is simpler when no AI agent is involved. For deterministic, compliance-critical operations (financial transactions, regulatory reporting), direct API gives you predictable behavior without agent-driven decision-making. MCP shines when AI agents need to dynamically discover and call Cornerstone actions at runtime.
What AI frameworks and AI clients does the StackOne Cornerstone MCP server support?
The StackOne Cornerstone MCP server supports both. MCP clients (paste-and-go apps): Claude Desktop, Claude Code, Cursor, VS Code, Goose. Agent frameworks (code SDKs you build with): OpenAI Agents SDK, Anthropic, Vercel AI, Google ADK, CrewAI, Pydantic AI, LangChain, LangGraph, Azure AI Foundry.

Put your AI agents to work

All the tools you need to build and scale AI agent integrations, with best-in-class connectivity, execution, and security.