Connect
Optimize
Secure
Announcing StackOne Defender: leading open-source prompt injection guard for your agent • Read More →
Production-ready Retool MCP server with 44 extensible actions — plus built-in authentication, security, and optimized execution.
Coverage
Create, read, update, and delete across Retool — and extend your agent's capabilities with custom actions.
Authentication
Per-user OAuth in one call. Your Retool MCP server gets session-scoped tokens with zero credentials stored on your infra.
Agent Auth →Security
Every Retool tool response scanned for prompt injection in milliseconds — 88.7% accuracy, all running on CPU.
Prompt Injection Defense →Performance
Free up to 96% of your agent's context window to enhance reasoning and reduce cost, on every Retool call.
Tools Discovery →A Retool MCP server lets AI agents read and write Retool data through the Model Context Protocol — Anthropic's open standard for connecting LLMs to external tools. StackOne's Retool MCP server ships with 44 pre-built actions, fully extensible via the Connector Builder — plus managed authentication, prompt injection defense, and optimized agent context. Connect it from MCP clients like Claude Desktop, Cursor, and VS Code, or from agent frameworks like OpenAI Agents SDK, LangChain, and Vercel AI SDK.
Every action from Retool's API, ready for your agent. Create, read, update, and delete — scoped to exactly what you need.
Create a new custom component library
Get a custom component library by ID
Create a new folder
Get all folders in the organization
Get a folder by ID
Update a folder by ID
Delete a folder by ID
Create a new permission group
Get all permission groups
Get a group by ID
Update a group using JSON Patch
Delete a permission group
Get all resources in the organization
Delete a resource by ID
Create a new role
Get all roles in the organization
Update a role by ID
Delete a role by ID
Create a new child space
Get all child spaces
Get a space by ID
Update a space by ID
Delete a space by ID
Create a new user invite
Get all user invites in the organization
Get a user invite by ID
Delete a user invite by ID
Create a new user in the organization
Get all users in the organization
Get a specific user by ID
Update a user by ID
Disable a user from the organization
Get all workflows in the organization
Get a workflow by ID
Add users to a permission group
Copy apps, queries, resources, and workflows to another space
Add or update a user attribute
Add user invites to a group
Get all custom component libraries in the organization
Get all revisions of a custom component library
Get all files for a custom component library revision
Get details for a workflow run
Remove a user from a permission group
Remove a user invite from a group
One endpoint. Any framework. Your agent is talking to Retool in under 10 lines of code.
MCP Clients
Agent Frameworks
{
"mcpServers": {
"stackone": {
"command": "npx",
"args": [
"-y",
"mcp-remote@latest",
"https://api.stackone.com/mcp?x-account-id=<account_id>",
"--header",
"Authorization: Basic <YOUR_BASE64_TOKEN>"
]
}
}
}172+ actions
137+ actions
134+ actions
128+ actions
125+ actions
118+ actions
109+ actions
Anthropic's code_execution processes data already in context. Custom MCP code mode keeps raw tool responses in a sandbox. 14K tokens vs 500.
11 min
Benchmarking BM25, TF-IDF, and hybrid search for MCP tool discovery across 916 tools. The 80/20 TF-IDF/BM25 hybrid hits 21% Top-1 accuracy in under 1ms.
10 min
MCP tools that read emails, CRM records, and tickets are indirect prompt injection vectors. Here's how we built a two-tier defense that scans tool results in ~11ms.
12 min
origin_owner_id.All the tools you need to build and scale AI agent integrations, with best-in-class connectivity, execution, and security.