# brussels.toots/tickets (remote · toots.brussels)

Agenda and ticketing for Toots Jazz Club, Brussels: browse concerts, check seats, reserve tickets.

- Trust score: 77/100 (medium)
- Change this week: 0
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-04

## Components

- remote · `toots.brussels`: 77/100 (this document), [markdown](https://verifymcp.io/servers/brussels-toots-tickets/toots.md), [page](https://verifymcp.io/servers/brussels-toots-tickets/toots)

## Channel facts

- Endpoint: `https://toots.brussels/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-04.

- **Endpoint Security**: 57/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (release_booking).
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 83/100
  - 98% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (good).
  - Tool/resource definitions use about 3133 tokens (~45/item across 69 items; 13 tools + 56 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 100/100
  - No destabilizing schema changes in the last 30 days.
- **Tool Coverage**: 90/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 65% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 15 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 60/100
  - Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28.

## Install

### How do I install the brussels.toots/tickets MCP server?

brussels.toots/tickets is a hosted endpoint at https://toots.brussels/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http brussels-toots-tickets 'https://toots.brussels/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "brussels-toots-tickets": {
      "url": "https://toots.brussels/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "brussels-toots-tickets": {
      "type": "http",
      "url": "https://toots.brussels/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.brussels-toots-tickets]
url = "https://toots.brussels/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "brussels-toots-tickets": {
      "type": "remote",
      "url": "https://toots.brussels/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add brussels-toots-tickets --url 'https://toots.brussels/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  brussels-toots-tickets:
    url: "https://toots.brussels/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "brussels-toots-tickets": {
      "Transport": "http",
      "Url": "https://toots.brussels/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add brussels-toots-tickets -t streamable-http -u 'https://toots.brussels/mcp'
```

### Other

```json
{
  "mcpServers": {
    "brussels-toots-tickets": {
      "type": "http",
      "url": "https://toots.brussels/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-04 (score 77, −1)

- [functional regression] Resource “concert-14232” was removed
- [functional regression] Resource “concert-14309” was removed

### 2026-10-03 (score 78, 0)

- [functional regression] Resource “concert-14228” was removed
- [functional regression] Resource “concert-14264” was removed
- [functional] New resource “concert-13954”
- [functional] New resource “concert-14905”
- [functional] New resource “concert-14909”
- [functional] New resource “concert-15253”
- [functional] New resource “concert-15258”
- [functional] New resource “concert-15265”
- [functional] New resource “concert-15276”
- [functional] New resource “concert-7092”

### 2026-10-02 (score 78, +7)

- [security improvement] Judged manipulation: unverified → pass
- [functional regression] Resource “concert-14226” was removed
- [functional regression] Resource “concert-14257” was removed
- [functional regression] Resource “concert-14259” was removed
- [functional improvement] Schema quality: unverified → good
- [functional] New resource “concert-14897”
- [functional] New resource “concert-14899”
- [functional] New resource “concert-14901”
- [functional] New resource “concert-15179”
- [functional] New resource “concert-15185”
- [functional] New resource “concert-15206”
- [functional] New resource “concert-15208”
- [functional] New resource “concert-15212”

### 2026-10-01 (score 71, −6)

- [security regression] Judged manipulation: pass → unverified
- [functional regression] Schema quality: good → unverified
- [functional regression] Resource “concert-14052” was removed
- [functional improvement] Schema quality: 57 → 48
- [functional] New resource “concert-10519”
- [functional] New resource “concert-13932”
- [functional] New resource “concert-13938”
- [functional] New resource “concert-13957”
- [functional] New resource “concert-14184”
- [functional] New resource “concert-14256”
- [functional] New resource “concert-14871”
- [functional] New resource “concert-14881”
- [functional] New resource “concert-14885”
- [functional] New resource “concert-14887”
- [functional] New resource “concert-14889”
- [functional] New resource “concert-14893”
- [functional] New resource “concert-15096”
- [functional] New resource “concert-15151”
- [functional] New resource “concert-5732”
- [functional] New resource “concert-8322”
- [functional] New resource “concert-8421”

### 2026-09-30 (score 77, 0)

- [functional regression] Resource “concert-14047” was removed

### 2026-09-28 (score 77, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-27 (score 77, +1)

- [functional regression] Resource “concert-14165” was removed
- [functional regression] Resource “concert-14184” was removed

### 2026-09-26 (score 76, 0)

- [functional regression] Resource “concert-13838” was removed
- [functional regression] Resource “concert-14034” was removed

## MCP tools (13)

### `list_events` (~51 tokens)

List upcoming concerts

All upcoming concerts with date, line-up, genres and a price/availability summary. Amounts are euro cents.

Input parameters:

- `locale` (string): Language for titles, labels and the returned URLs. Defaults to fr.

Output parameters:

- `result` (array)

### `get_event` (~64 tokens)

Concert details

Full details of one concert: bio, line-up, other dates of the same run, prices and availability.

Input parameters:

- `event_id` (string, required): The event_id from list_events.
- `locale` (string): Language for titles, labels and the returned URLs. Defaults to fr.

Output parameters:

- `result` (object)

### `get_availability` (~81 tokens)

Live seat availability

Live ticket availability for a concert, per session: the stock_id, category_id and price_id values that hold_tickets needs, with prices in euro cents and the maximum quantity per line.

Input parameters:

- `event_id` (string, required): The event_id from list_events.
- `locale` (string): Language for titles, labels and the returned URLs. Defaults to fr.

Output parameters:

- `result` (object)

### `get_venue_info` (~59 tokens)

Venue information

Address, contact details and the venue's FAQ (house rules, practical questions). Use this to answer buyer questions about the club instead of guessing.

Input parameters:

- `locale` (string): Language for titles, labels and the returned URLs. Defaults to fr.

Output parameters:

- `result` (object)

### `hold_tickets` (~131 tokens)

Reserve tickets

Reserves tickets and returns a booking_uuid. The hold expires after 15 minutes if the order is not paid, releasing the seats. Only call this once the buyer has chosen; do not hold speculatively.

Input parameters:

- `event_id` (string, required): The event_id from list_events.
- `idempotency_key` (string): Optional deduplication key of your choosing. Retrying a timed-out hold with the same key returns the original booking instead of reserving twice.
- `items` (array, required)
- `locale` (string): Language for titles, labels and the returned URLs. Defaults to fr.

Output parameters:

- `result` (object)

### `set_contact` (~170 tokens)

Attach the buyer

Attaches the buyer to a held booking and returns the payment_url. Give that URL to the human buyer: payment (card or Bancontact) happens in their browser, never through this API. The tickets will be emailed to the address given here.

Input parameters:

- `booking_uuid` (string, required)
- `country` (string): Two-letter ISO code, e.g. BE.
- `email` (string, required): The buyer's email; the tickets are sent there.
- `firstname` (string, required)
- `lastname` (string, required)
- `newsletter_opt_in` (boolean): Only true if the buyer explicitly asked to subscribe.
- `promo_code` (string)
- `terms_accepted` (boolean, required): Must be true, and only after the buyer explicitly accepted the terms of sale.
- `zip` (string)

Output parameters:

- `result` (object)

### `redeem_pass` (~136 tokens)

Pay with a Toots Pass

Applies a Toots Pass code (given to you by the buyer; format XXX-XXXXXX-XXX) to a held booking, after set_contact. Covers as many tickets as the pass has concerts left. If the order is fully covered the booking completes immediately (status paid); otherwise the response carries the payment_url for the balance. The code is a venue credential, not a payment instrument.

Input parameters:

- `booking_uuid` (string, required)
- `code` (string, required): The Toots Pass code, exactly as the buyer gave it.
- `locale` (string): Language for titles, labels and the returned URLs. Defaults to fr.

Output parameters:

- `result` (object)

### `redeem_gift_card` (~114 tokens)

Pay with a gift card

Applies a Toots gift card code (given to you by the buyer) to a held booking, after set_contact. Uses as much of the card's balance as the order needs. Fully covered orders complete immediately (status paid); otherwise the response carries the payment_url for the balance.

Input parameters:

- `booking_uuid` (string, required)
- `code` (string, required): The gift card code, exactly as the buyer gave it.
- `locale` (string): Language for titles, labels and the returned URLs. Defaults to fr.

Output parameters:

- `result` (object)

### `pay_with_shared_payment_token` (~213 tokens)

Pay with a Link Shared Payment Token

Pays the remaining balance of a booking (after set_contact, and after any pass or gift card) with a Shared Payment Token from the buyer's Link agent wallet. Request the token for exactly amount_to_pay_cents in EUR, scoped to the Stripe network profile profile_61VNUTvZyhaQmxLgqA6VNUTv7A9CUusxmQZ0xC5doSoy; the buyer approves that spend in Link. Charges the buyer, so only call it once they confirmed the purchase. On success the booking is paid and carries ticket_url; if the response says otherwise (payment_status, next_step) or errors, give the payment_url to the human buyer instead — the booking stays open until its hold expires.

Input parameters:

- `booking_uuid` (string, required)
- `locale` (string): Language for titles, labels and the returned URLs. Defaults to fr.
- `shared_payment_token` (string, required): The spt_… token granted by the buyer's Link wallet.

Output parameters:

- `result` (object)

### `release_booking` (~73 tokens)

Release a hold

Gives an unpaid hold's seats back immediately, instead of letting them sit reserved until the 15-minute expiry. Call this when the buyer changes their mind. Paid bookings cannot be released.

Input parameters:

- `booking_uuid` (string, required)
- `locale` (string): Language for titles, labels and the returned URLs. Defaults to fr.

Output parameters:

- `result` (object)

### `wait_for_payment` (~102 tokens)

Wait for the payment

Like get_booking_status, but holds the request open (up to 25 seconds) and returns as soon as the booking is paid. Call it after handing the buyer the payment_url instead of polling in a loop; repeat while status is still awaiting_payment and the hold has time left.

Input parameters:

- `booking_uuid` (string, required)
- `locale` (string): Language for titles, labels and the returned URLs. Defaults to fr.
- `timeout_seconds` (integer)

Output parameters:

- `result` (object)

### `get_booking_status` (~113 tokens)

Booking status

Current status of a booking: awaiting_contact, awaiting_payment (with payment_url and amount left), paid or expired. A paid booking carries ticket_url — the one link to share with the buyer, which adapts to their device (wallet on a phone, PDF and choices elsewhere) — plus the explicit ticket_pdf_url and, when configured, apple_wallet_url / google_wallet_url.

Input parameters:

- `booking_uuid` (string, required)
- `locale` (string): Language for titles, labels and the returned URLs. Defaults to fr.

Output parameters:

- `result` (object)

### `recover_tickets` (~100 tokens)

Re-send tickets by email

For a buyer who lost their tickets: sends the ticket links of their past paid orders to their email address. The links go to the inbox only — the response never contains them — so the inbox is the proof of ownership. Tell the buyer to check their email (and spam folder).

Input parameters:

- `email` (string, required): The email address the buyer ordered with.
- `locale` (string): Language for titles, labels and the returned URLs. Defaults to fr.

Output parameters:

- `result` (object)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/brussels-toots-tickets/toots#diagnostics

## Score history

- 2026-10-04: 77
- 2026-10-03: 78
- 2026-10-02: 78
- 2026-10-01: 71
- 2026-09-30: 77
- 2026-09-29: 77
- 2026-09-28: 77
- 2026-09-27: 77
- 2026-09-26: 76
- 2026-09-25: 76
- 2026-09-24: 76
- 2026-09-23: 75
- 2026-09-22: 75
- 2026-09-21: 74
- 2026-09-20: 74
- 2026-09-19: 73
- 2026-09-18: 73
- 2026-09-17: 72
- 2026-09-16: 72
- 2026-09-15: 72
- 2026-09-14: 71
- 2026-09-13: 70
- 2026-09-12: 70
- 2026-09-11: 70
- 2026-09-10: 69
- 2026-09-09: 69
- 2026-09-08: 68
- 2026-09-07: 68
- 2026-09-06: 67
- 2026-09-05: 67

## Common questions

### What is the brussels.toots/tickets MCP server?

brussels.toots/tickets is an MCP server listed in the public MCP registry as brussels.toots/tickets. Agenda and ticketing for Toots Jazz Club, Brussels: browse concerts, check seats, reserve tickets. This page covers its hosted endpoint (https://toots.brussels/mcp).

### Is the brussels.toots/tickets MCP server safe to use?

brussels.toots/tickets scores 77 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the brussels.toots/tickets MCP server expose?

brussels.toots/tickets exposes 13 tools: list_events, get_event, get_availability, get_venue_info, hold_tickets, and 8 more. Their descriptions and schemas cost roughly 1,407 tokens of context every time the server is loaded.

### Does the brussels.toots/tickets MCP server require authentication?

No. We connected to brussels.toots/tickets without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the brussels.toots/tickets MCP server still maintained?

brussels.toots/tickets is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://toots.brussels/mcp
- Website: https://toots.brussels/api
- Changelog RSS feed: https://verifymcp.io/servers/brussels-toots-tickets/toots.xml
- Changelog JSON feed: https://verifymcp.io/servers/brussels-toots-tickets/toots.json
- HTML version of this page: https://verifymcp.io/servers/brussels-toots-tickets/toots
