Connect
Optimize
Secure
Announcing StackOne Defender: leading open-source prompt injection guard for your agent • Read More →
Production-ready Customer.io MCP server with 48 extensible actions — plus built-in authentication, security, and optimized execution.
Coverage
Create, read, update, and delete across Customer.io — and extend your agent's capabilities with custom actions.
Authentication
Per-user OAuth in one call. Your Customer.io MCP server gets session-scoped tokens with zero credentials stored on your infra.
Agent Auth →Security
Every Customer.io tool response scanned for prompt injection in milliseconds — 88.7% accuracy, all running on CPU.
Prompt Injection Defense →Performance
Free up to 96% of your agent's context window to enhance reasoning and reduce cost, on every Customer.io call.
Tools Discovery →A Customer.io MCP server lets AI agents read and write Customer.io data through the Model Context Protocol — Anthropic's open standard for connecting LLMs to external tools. StackOne's Customer.io MCP server ships with 48 pre-built actions, fully extensible via the Connector Builder — plus managed authentication, prompt injection defense, and optimized agent context. Connect it from MCP clients like Claude Desktop, Cursor, and VS Code, or from agent frameworks like OpenAI Agents SDK, LangChain, and Vercel AI SDK.
Every action from Customer.io's API, ready for your agent. Create, read, update, and delete — scoped to exactly what you need.
List all broadcasts in the workspace
Retrieve a specific broadcast by ID
List all campaigns in the workspace
Retrieve a specific campaign by ID
List all messages in the workspace
Retrieve a specific message by ID
List all newsletters in the workspace
Retrieve a specific newsletter by ID
List all segments in the workspace
Retrieve a specific segment by ID
Create a new snippet
List all snippets in the workspace
Create or update a snippet
Delete a snippet
Add or update a customer
Add or update a customer device
Add customers to a manual segment
List all activities in the workspace
Get metrics for a broadcast
List all actions in a broadcast
Get trigger history for a broadcast
Get metrics for a campaign
List all actions in a campaign
Get customers by email address
Search for customers using advanced filters
List customers with their attributes and devices
Get metrics for a newsletter
Get link click metrics for a newsletter
Get the total number of customers in a segment
List all customers in a specific segment
List all sender identities in the workspace
Retrieve a specific sender identity by ID
Find your account region
Delete a specific newsletter
Delete a specific segment
Delete a customer
Delete a customer device
Remove customers from a manual segment
Get attributes for a specific customer
Get segments a customer belongs to
Get messages sent to a customer
Get activities for a customer
Get relationships for a specific customer
Merge duplicate customers
Track an event for a customer
Track an event for an anonymous user
Suppress a customer profile
Unsuppress a customer profile
One endpoint. Any framework. Your agent is talking to Customer.io in under 10 lines of code.
MCP Clients
Agent Frameworks
{
"mcpServers": {
"stackone": {
"command": "npx",
"args": [
"-y",
"mcp-remote@latest",
"https://api.stackone.com/mcp?x-account-id=<account_id>",
"--header",
"Authorization: Basic <YOUR_BASE64_TOKEN>"
]
}
}
}Anthropic's code_execution processes data already in context. Custom MCP code mode keeps raw tool responses in a sandbox. 14K tokens vs 500.
11 min
Benchmarking BM25, TF-IDF, and hybrid search for MCP tool discovery across 916 tools. The 80/20 TF-IDF/BM25 hybrid hits 21% Top-1 accuracy in under 1ms.
10 min
MCP tools that read emails, CRM records, and tickets are indirect prompt injection vectors. Here's how we built a two-tier defense that scans tool results in ~11ms.
12 min
origin_owner_id.All the tools you need to build and scale AI agent integrations, with best-in-class connectivity, execution, and security.