Connect
Optimize
Secure
The #1 agentic semantic tool search: 91.6% first-try accuracy on S1 Search Bench • Explore Tool Discovery →
MCP Gateway
One MCP gateway to connect AWS Bedrock AgentCore to 310+ enterprise SaaS apps. No auth hassle. Token-efficient by design. Security and governance built-in.
An MCP gateway (also called an MCP aggregator) is a single endpoint that connects an AI agent to multiple
MCP servers via the open Model Context Protocol (opens in new tab).
Some gateways act as proxies, routing traffic to MCP servers customers operate themselves. Others provide the
underlying MCP servers as a managed service.
StackOne is the managed kind. We provide pre-built MCP servers for 310+ enterprise SaaS apps,
including ones with no official MCP server today. For each app you connect, StackOne provides the MCP protocol
layer, the SaaS API integration, action coverage, and the auth orchestration framework. Authentication is
configured per app per organization — your team registers OAuth credentials with the SaaS provider, links them
in StackOne, and end users then authorize access through that flow. Once set up, the agent reaches every
connected app through one URL, with token storage, refresh, and per-user scoping handled by StackOne.
StackOne's MCP gateway — SOC2, HIPAA, CCPA, and GDPR compliant — bundles 310+ pre-built SaaS integrations exposing 20,000+ actions, all reachable from your AgentCore agent through one URL.
One MCP gateway, every enterprise SaaS your AgentCore agent
could ever need to act on.
Coverage
Every action is built and maintained by StackOne, tested against the live API, and updated when vendors change their endpoints.
Browse all connectorsTrust
StackOne handles OAuth, API keys, refresh, and scopes for every connector, giving enterprise IT full control through auth configs in a multi-tenant setup.
Agent AuthPerformance
Tool Discovery and Code Mode keep the AgentCore agent's context lean — only relevant actions, no raw response noise. Sharper agents, lower token costs.
Tools DiscoverySecurity
Defender scans every MCP tool response for prompt injection in real time. Up to 97.44%¹ detection, 0.2% false positives. SOC2, HIPAA, CCPA, GDPR compliant.
Prompt Injection Defense¹ Jayavibhav test, 65,000 samples.
From auth config to first agent tool call in 5 minutes.
Open Settings → AWS Bedrock AgentCore → AI connectors, enable Custom MCP servers, then paste the StackOne gateway URL. Available immediately to every AI Agent in your workspace.
Settings → AWS Bedrock AgentCore → AI connectors
Add Custom MCP server
OAuth or API key per app, done once in your dashboard. Tokens stay server-side.
Read-only, specific objects, or per-role exposure. Toggle from the StackOne dashboard.
StackOne maps your prompt to the right action in the right system. Done.
"Pull the latest pipeline from Salesforce, grab the Q2 forecast spreadsheet from S3, and draft a board update."
salesforce_list_opportunities s3_get_object
Drafted the Q2 board update to s3://drafts/q2-board-update.md. Cross-referenced 38 Salesforce opportunities against the forecast spreadsheet.
Cross-app workflows your AgentCore agent now runs in seconds instead of click-throughs.
> Read Salesforce pipeline + a Lambda function + S3 forecast in one agent flow.
> Build a sales agent that reads HubSpot deals and drafts personalized outreach.
> Give an AgentCore agent Workday access for employee questions and HRIS lookups.
> Pull Google Analytics campaign data into Bedrock for analysis, write back to S3.
Same 310+ MCP servers. Same agent context. Pick yours.
agentcore add gateway-target --name StackOne --type mcp-server --endpoint https://api.stackone.com/mcp --authorizer-type CUSTOM_JWT, then deploy. Same via boto3 (create_gateway_target) or AWS Console. Available immediately to your Bedrock agent, and 310+ pre-built SaaS connectors are reachable through that single target. Full walkthrough in the MCP servers as targets docs. Pay-as-you-go: $0.005 / 1,000 Gateway invocations.One MCP gateway, 310+ pre-built SaaS connectors. Set up in 5 minutes.