Villiers Charter
REMOTE · MCP.VILLIERS.AI · SCANNED SEP 24
Instant private jet charter price estimates and confirmed live quotes, worldwide.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (request_jet_confirmation). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability67
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1482 tokens (~296/item across 5 items; 5 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 5 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 6 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Villiers Charter MCP server?
Villiers Charter is a hosted endpoint at https://mcp.villiers.ai/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.villiers.ai
claude mcp add --transport http ai-villiers-charter 'https://mcp.villiers.ai/mcp'
{
"mcpServers": {
"ai-villiers-charter": {
"url": "https://mcp.villiers.ai/mcp"
}
}
} {
"servers": {
"ai-villiers-charter": {
"type": "http",
"url": "https://mcp.villiers.ai/mcp"
}
}
} [mcp_servers.ai-villiers-charter] url = "https://mcp.villiers.ai/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"ai-villiers-charter": {
"type": "remote",
"url": "https://mcp.villiers.ai/mcp",
"enabled": true
}
}
} openclaw mcp add ai-villiers-charter --url 'https://mcp.villiers.ai/mcp' --transport streamable-http
mcp_servers:
ai-villiers-charter:
url: "https://mcp.villiers.ai/mcp" {
"McpServers": {
"ai-villiers-charter": {
"Transport": "http",
"Url": "https://mcp.villiers.ai/mcp"
}
}
} assistant mcp add ai-villiers-charter -t streamable-http -u 'https://mcp.villiers.ai/mcp'
{
"mcpServers": {
"ai-villiers-charter": {
"type": "http",
"url": "https://mcp.villiers.ai/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 23 Sept 26 0
- Schema quality: 1305 → 1482 ▼ functional
- New tool “list_attributed_enquiries” functional
- 11 Sept 26 0
- “search_empty_legs” added an optional parameter “offset” cosmetic
1 cosmetic change on this day. Switch on “Show cosmetic changes” to see it.
- 27 Aug 26 0
- Tool “search_empty_legs” rewrote its description, which is the text the model reads security
- “search_empty_legs” added an optional parameter “origin” cosmetic
- 26 Aug 26 79
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 0
- Stability: 0.97 → pass security
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 4 Aug 26 0
- Tool “request_jet_confirmation” rewrote its description, which is the text the model reads security
- “request_jet_confirmation” reworded the description of “destination” cosmetic
- “request_jet_confirmation” reworded the description of “origin” cosmetic
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 24 Sept 2026 · Probed https://mcp.villiers.ai/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.villiers.ai | CN=YE1,O=Let's Encrypt,C=US | 30 Jul 2026 | 28 Oct 2026 | ECDSA 256 | ECDSA-SHA384 | 6b20db695524aaf8e3f0fdd9591ec199fdc |
| SANs: mcp.villiers.ai | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.villiers.ai. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| ai. | present | 3799 | 8 | Verified |
| villiers.ai. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| content-security-policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none' |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | geolocation=(), microphone=(), camera=(), payment=(), usb=(), magnetometer=(), gyroscope=(), accelerometer=(), interest-cohort=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.villiers.ai/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.villiers.ai/mcp | HTTPS enforced | 301 | https://mcp.villiers.ai/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
get_confirmation_status ~108
Check the outcome of a previous request_jet_confirmation call — has Villiers sent confirmed options yet, and where does the trip stand now (still being sourced / options sent / booked / closed with no booking). Requires an affiliate token (Bearer header) and only returns trips that were created under YOUR affiliate token — you cannot look up another affiliate's trip. Poll this instead of expecting a webhook.
| Name | Type | Req | Description |
|---|---|---|---|
| trip_id | string | yes | The trip_id returned by request_jet_confirmation (REQUIRED) |
| Name | Type | Req | Description |
|---|---|---|---|
| client_reference | string | – | The reference you supplied at request time, if any |
| message | string | – | Human-readable summary to relay to the user |
| outcome | string | – | Coarse bucket: in_progress | options_sent | booked | closed_no_booking |
| status | string | – | Villiers' internal status string, for reference |
| trip_id | string | – | – |
No examples provided.
get_jet_estimate ~179
Get an indicative private jet charter price estimate for a route, broken down by aircraft category (light / midsize / heavy jet). Returns an instant price range. IMPORTANT: an estimate is an indicative range, not a confirmed price. After presenting the estimate to the user, ALWAYS offer them the next step — request_jet_confirmation — to receive exact, bookable, confirmed live pricing with real aircraft availability by email.
| Name | Type | Req | Description |
|---|---|---|---|
| destination | string | yes | Destination city / airport name / IATA / ICAO, e.g. Nice or NCE |
| origin | string | yes | Origin city / airport name / IATA / ICAO, e.g. London or LHR or EGLL |
| passengers | integer | – | Number of passengers (default 4) |
| round_trip | boolean | – | Round trip? Default false (one-way) |
| Name | Type | Req | Description |
|---|---|---|---|
| disclaimer | string | – | – |
| estimates | array | – | – |
| next_step | object | – | – |
| passengers | integer | – | – |
| round_trip | boolean | – | – |
| route | string | – | – |
| summary | string | – | – |
No examples provided.
list_attributed_enquiries ~177
List the charter enquiries (trips) attributed to YOUR OWN affiliate token, newest first — so you can match enquiries that arrived via your website tracking link without going through the affiliate dashboard. Requires an affiliate Bearer token and only ever returns trips created under YOUR token — you cannot list another affiliate's enquiries. Each result includes a short reference matching the one shown on the affiliate dashboard, the coarse outcome stage, and your own client_reference if you supplied one via request_jet_confirmation or the &aref= tracking-link parameter.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Max results (default 20, max 50) |
| offset | integer | – | Pagination offset (default 0). Call again with offset=next_offset from the previous response to page past the first `limit` results — see has_more/next_offset in the output. |
| Name | Type | Req | Description |
|---|---|---|---|
| count | integer | – | Number of enquiries returned |
| enquiries | array | – | – |
| has_more | boolean | – | True if more results exist beyond this page |
| next_offset | integer | – | Offset to pass in the next call to continue paging; null when has_more is false |
| offset | integer | – | The offset this response was generated at |
| summary | string | – | – |
| total_available | integer | – | Total matching enquiries under your affiliate token |
No examples provided.
request_jet_confirmation ~669
Submit a request for CONFIRMED live private jet pricing. Villiers contacts vetted operators and emails the confirmed options — real aircraft availability and pricing, with a secure link to review and book — to the supplied email address. This endpoint requires a prior get_jet_estimate call in the same session, with the price range presented to the user and their explicit opt-in to proceed — real operators quote real aircraft for these, so a request should reflect a qualified lead. Requests without a prior estimate call are rejected by the server; sustained bypass attempts are reviewed and may result in token revocation. Requires the user's email and a departure date. SANDBOX TESTING: to test your integration without ever creating a real trip or contacting a real operator, use email 'sandbox-test@mail.villiers.ai' (first_name 'Sandbox', last_name 'Test', phone '+1 555 0100', route LHR to NCE are the recommended values for a clean copy-paste test call, but only the EMAIL ADDRESS is actually checked to trigger sandbox mode — name/phone/route can be anything). Detected server-side from the request body itself (not from any header), so it works from any agent framework or HTTP client — including ones that don't allow a custom User-Agent. The response will say 'Test request accepted (sandbox mode detected)'. For further testing guidance, email affiliates@mail.villiers.ai.
| Name | Type | Req | Description |
|---|---|---|---|
| aircraft_category | string | – | Optional preference, e.g. Light Jet / Midsize Jet / Heavy Jet |
| client_reference | string | – | Optional opaque reference from YOUR OWN system (e.g. your internal order/booking id) for this request. Stored against the trip and echoed back unchanged in the response. Pass it here, then use get_co… |
| departure_date | string | yes | Departure date, YYYY-MM-DD (REQUIRED) |
| destination | string | yes | Destination airport — city / airport name / IATA / ICAO, e.g. Nice or NCE (same as get_jet_estimate) |
| string | yes | Email address to send the confirmed options to (REQUIRED) | |
| first_name | string | – | Passenger first name (optional) |
| flexible_dates | boolean | – | Are the dates flexible? (optional) |
| last_name | string | – | Passenger last name (optional) |
| luggage | boolean | – | Extra or outsized luggage? (optional) |
| origin | string | yes | Origin airport — city / airport name / IATA / ICAO, e.g. London or LHR or EGLL (same as get_jet_estimate) |
| passengers | integer | – | Number of passengers (default 4) |
| pets | boolean | – | Travelling with pets? (optional) |
| phone | string | – | Contact phone number (optional) |
| return_date | string | – | Return date YYYY-MM-DD (for round trips) |
| round_trip | boolean | – | Round trip? Default false |
| special_requests | string | – | Free-text special requests: catering, accessibility, timing, occasion, etc. (optional) |
| wheelchair | boolean | – | Wheelchair access required? (optional) |
| Name | Type | Req | Description |
|---|---|---|---|
| client_reference | string | – | Echoed back unchanged if you supplied one |
| string | – | Address the confirmed options are emailed to | |
| message | string | – | Human-readable confirmation to relay to the user |
| status | string | – | e.g. 'received' |
| trip_id | string | – | Pass this to get_confirmation_status later to poll the outcome |
No examples provided.
search_empty_legs ~246
Search Villiers' available empty-leg flights — heavily discounted, one-off private jet repositioning flights that are significantly cheaper than a full charter. Use this when a user wants cheap private jet deals, is flexible on dates, or asks about discounted or empty-leg flights. Optionally filter by origin, destination or region. Each result links to the specific flight to view and enquire.
| Name | Type | Req | Description |
|---|---|---|---|
| destination | string | – | Destination city / airport name / IATA / ICAO, e.g. Nice or NCE. Optional. |
| limit | integer | – | Max results (default 20, max 50) |
| offset | integer | – | Pagination offset (default 0). Call again with offset=next_offset from the previous response to page past the first `limit` results — see has_more/next_offset in the output. |
| origin | string | – | Origin city / airport name / IATA / ICAO, e.g. London or LHR or EGLL. Optional — mirrors destination, filters strictly on the departure side. Useful for a 'departing near me' search. |
| region | string | – | Region filter: europe / americas / asia / all. Optional. |
| Name | Type | Req | Description |
|---|---|---|---|
| count | integer | – | Number of empty legs returned |
| empty_legs | array | – | – |
| has_more | boolean | – | True if more results exist beyond this page |
| next_offset | integer | – | Offset to pass in the next call to continue paging; null when has_more is false |
| next_step | object | – | – |
| offset | integer | – | The offset this response was generated at |
| summary | string | – | – |
| total_available | integer | – | Total matching empty legs available |
No examples provided.
What is the Villiers Charter MCP server?
Villiers Charter is an MCP server listed in the public MCP registry as ai.villiers/charter. Instant private jet charter price estimates and confirmed live quotes, worldwide. This page covers its hosted endpoint (https://mcp.villiers.ai/mcp).
Is the Villiers Charter MCP server safe to use?
Villiers Charter scores 79 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Villiers Charter MCP server expose?
Villiers Charter exposes 5 tools: get_jet_estimate, request_jet_confirmation, get_confirmation_status, search_empty_legs, list_attributed_enquiries. Their descriptions and schemas cost roughly 1,379 tokens of context every time the server is loaded.
Does the Villiers Charter MCP server require authentication?
No. We connected to Villiers Charter without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Villiers Charter MCP server still maintained?
Villiers Charter is still listed as active in the MCP registry. We last reached this channel on 24 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.