# Elron Club Public Rentals (remote · elron.club)

Search Elron Club furnished apartments, availability, prices, details, and rental applications.

- Trust score: 67/100 (medium)
- Change this week: +1
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-04

> **Recent critical change**: Authorization (2026-08-02). See the changelog below before you install this server.

## Components

- remote · `elron.club`: 67/100 (this document), [markdown](https://verifymcp.io/servers/club-elron-public-rentals/api-agent-public-mcp.md), [page](https://verifymcp.io/servers/club-elron-public-rentals/api-agent-public-mcp)

## Channel facts

- Endpoint: `https://elron.club/api/agent/public/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.2.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-04.

- **Endpoint Security**: 66/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (waitlist.unsubscribe).
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC is configured correctly; the domain's records validate against the full chain to the root.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 66/100
  - AI-judged instruction clarity (good).
  - Tool/resource definitions use about 1964 tokens (~85/item across 23 items; 23 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 30/100
  - Stability observed for 9 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 74/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 8% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add --transport http club-elron-public-rentals https://elron.club/api/agent/public/mcp
```

### Codex

```toml
[mcp_servers.club-elron-public-rentals]
url = "https://elron.club/api/agent/public/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "club-elron-public-rentals": {
      "type": "remote",
      "url": "https://elron.club/api/agent/public/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add club-elron-public-rentals --url https://elron.club/api/agent/public/mcp --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  club-elron-public-rentals:
    url: "https://elron.club/api/agent/public/mcp"
```

### Other

```json
{
  "mcpServers": {
    "club-elron-public-rentals": {
      "type": "http",
      "url": "https://elron.club/api/agent/public/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-04 (score 67, +1)

No change was recorded against any check on this day. Stability & Change Management went from 27 to 30. That category is still filling its 30-day observation window: 8 days of observed history at the previous scan, 9 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-08-03 (score 66, +1)

- [security] Tool “waitlist.subscribe” rewrote its description, which is the text the model reads

### 2026-08-02 (score 65, −8)

- [critical regression] Authorization: partial → fail
- [security] New tool “waitlist.unsubscribe”, which the server declares destructive
- [functional] New tool “waitlist.subscribe”

### 2026-08-01 (score 73, +1)

No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-31 (score 72, +5)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 67, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-28 (score 66, +1)

No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-27 (score 65, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

## MCP tools (23)

### `waitlist.subscribe` (~81 tokens)

Subscribe to regional apartment updates

Activate newsletter updates for one canonical Elron region immediately after the customer explicitly requests them. An explicit customer request may reverse a previous opt-out without a confirmation email; automated inquiry and staff flows cannot override customer opt-outs.

Input parameters:

- `consent` (boolean, required)
- `email` (string, required)
- `locale` (string)
- `regionKey` (string, required)

Output parameters:

- `result` (object)
- `status` (string)

### `waitlist.unsubscribe` (~35 tokens)

Unsubscribe from all apartment updates

Use an opaque unsubscribe token from an Elron marketing email to stop every waitlist marketing update.

Input parameters:

- `token` (string, required)

Output parameters:

- `result` (object)
- `status` (string)

### `rentals.search` (~229 tokens)

Search published Elron Club rentals

Return a compact, actionable shortlist of published furnished apartments by location, availability, capacity, rooms, duration, and monthly rent. Defaults to 10 available or upcoming rentals; call rentals.get for complete details.

Input parameters:

- `availabilityStatus` (string): Availability scope. The default excludes unavailable inventory.
- `availableFrom` (string): Latest acceptable move-in date in ISO YYYY-MM-DD; later or unverified upcoming availability is excluded.
- `city` (string): City name; matching is case- and accent-insensitive.
- `durationMonths`: Minimum rental duration used for price filtering.
- `limit` (integer): Maximum shortlist size; inspect total and hasMore.
- `locale` (string)
- `maximumMonthlyRent` (number): Maximum monthly rent in CHF for the selected duration.
- `minimumOccupancy` (integer): Minimum supported resident count.
- `minimumRooms` (number): Minimum room count.
- `query` (string): Free text across rental, property, city, and region names.
- `region` (string): Region name; common English, German, and unaccented forms are accepted.

Output parameters:

- `result` (object)
- `status` (string)

### `rentals.get` (~52 tokens)

Get a published Elron Club rental

Return localized customer-safe apartment details, verified availability, duration pricing, deposit, included services, terms, eligibility, media, and inquiry/application links.

Input parameters:

- `locale` (string)
- `rentalId` (string, required)

Output parameters:

- `result` (object)
- `status` (string)

### `rentals.check_availability` (~47 tokens)

Check verified rental availability

Check the current published availability state and earliest date for one rental. This does not create a hold or reservation.

Input parameters:

- `locale` (string)
- `rentalId` (string, required)

Output parameters:

- `result` (object)
- `status` (string)

### `rentals.get_pricing` (~61 tokens)

Get duration pricing and fees

Return current published monthly pricing by supported duration, parking, deposit, inclusions, payment method, and minimum-stay terms. Pricing is informational until a quote or hold is issued.

Input parameters:

- `locale` (string)
- `rentalId` (string, required)

Output parameters:

- `result` (object)
- `status` (string)

### `applications.start` (~143 tokens)

Start an Elron Club inquiry or application

Create or reuse a duplicate-safe applicant workspace for one published rental. Requires explicit current privacy consent and an idempotency key. Email verification is sent to the applicant; the tool never returns the verification URL.

Input parameters:

- `desiredDurationMonths`
- `email` (string, required)
- `firstName` (string, required)
- `idempotencyKey` (string, required)
- `journey` (string, required)
- `lastName` (string, required)
- `locale` (string)
- `phone` (string, required)
- `privacyConsentAccepted` (boolean, required)
- `privacyConsentVersion` (string, required)
- `rentalId` (string, required)
- `requestedParkingCount`

Output parameters:

- `result` (object)
- `status` (string)

### `applications.get_status` (~33 tokens)

Get public application status

Read the privacy-minimized status and next actions for one scoped application session token.

Input parameters:

- `sessionToken` (string, required)

Output parameters:

- `result` (object)
- `status` (string)

### `applications.update` (~327 tokens)

Update a verified Elron Club application

Update bounded applicant, tenancy, and billing data for one email-verified session using its exact current version and a durable idempotency key.

Input parameters:

- `applicantMessage` (string)
- `billingCity` (string)
- `billingCountryCode` (string)
- `billingEmail`
- `billingIntentType` (string)
- `billingPostalCode` (string)
- `billingPrivateFirstName` (string)
- `billingPrivateLastName` (string)
- `billingStreetLine1` (string)
- `billingStreetLine2` (string)
- `companyBillingName` (string)
- `companyTenantCity` (string)
- `companyTenantCountryCode` (string)
- `companyTenantName` (string)
- `companyTenantPostalCode` (string)
- `companyTenantSigners` (array)
- `companyTenantStreetLine1` (string)
- `companyTenantStreetLine2` (string)
- `contractLanguageCode` (string)
- `desiredDurationMonths`
- `desiredMoveInDate`
- `desiredMoveOutDate`
- `employerOrCompanyName` (string)
- `employmentStatusSummary` (string)
- `expectedVersion` (string, required)
- `idempotencyKey` (string, required)
- `minorCount`
- `petSummary` (string)
- `preferredLanguage` (string)
- `requestedParkingCount`
- `sessionToken` (string, required)
- `tenantPartyMode` (string)
- `tenantProfiles` (array)

Output parameters:

- `result` (object)
- `status` (string)

### `applications.create_document_upload` (~95 tokens)

Create a signed application-document upload

Create a 15-minute, exact-size and exact-content-type signed upload form for one email-verified application at its exact current version.

Input parameters:

- `contextKey` (string, required)
- `expectedVersion` (string, required)
- `fileName` (string, required)
- `idempotencyKey` (string, required)
- `mimeType` (string, required)
- `sessionToken` (string, required)
- `sizeBytes` (integer, required)

Output parameters:

- `result` (object)
- `status` (string)

### `applications.complete_document_upload` (~69 tokens)

Complete a signed application-document upload

Verify the uploaded object, content signature, session ownership, expiry, and exact application version before creating the protected document record.

Input parameters:

- `expectedVersion` (string, required)
- `idempotencyKey` (string, required)
- `sessionToken` (string, required)
- `uploadSessionId` (string, required)

Output parameters:

- `result` (object)
- `status` (string)

### `applications.upload_document` (~109 tokens)

Upload a verified application document

Upload one bounded PDF, JPEG, or PNG identity or company-registry document to an email-verified application using its exact version and a durable idempotency key.

Input parameters:

- `contentBase64` (string, required)
- `contextKey` (string, required)
- `expectedVersion` (string, required)
- `fileName` (string, required)
- `idempotencyKey` (string, required)
- `mimeType` (string, required)
- `sessionToken` (string, required)
- `sizeBytes` (integer, required)

Output parameters:

- `result` (object)
- `status` (string)

### `applications.submit` (~93 tokens)

Submit a verified Elron Club application

Submit one complete email-verified application for review using its exact version, explicit current credit-check and truth-confirmation consent, and a durable idempotency key.

Input parameters:

- `consentVersion` (string, required)
- `creditCheckConsentAccepted` (boolean, required)
- `expectedVersion` (string, required)
- `idempotencyKey` (string, required)
- `sessionToken` (string, required)
- `truthConfirmationAccepted` (boolean, required)

Output parameters:

- `result` (object)
- `status` (string)

### `viewings.get_status` (~35 tokens)

Get scoped viewing coordination status

Read customer-safe viewing proposals and confirmed viewing state for one email-verified application session.

Input parameters:

- `sessionToken` (string, required)

Output parameters:

- `result` (object)
- `status` (string)

### `viewings.propose_availability` (~72 tokens)

Propose viewing availability

Propose one to five bounded future viewing slots from an email-verified application at its exact version using a durable idempotency key.

Input parameters:

- `expectedVersion` (string, required)
- `idempotencyKey` (string, required)
- `sessionToken` (string, required)
- `slots` (array, required)

Output parameters:

- `result` (object)
- `status` (string)

### `viewings.respond_to_proposal` (~96 tokens)

Accept or decline a viewing proposal

Accept or decline one pending Elron Club proposal with explicit confirmation, an exact application version, and a durable idempotency key. Acceptance may send the existing viewing confirmation communication.

Input parameters:

- `action` (string, required)
- `expectedVersion` (string, required)
- `idempotencyKey` (string, required)
- `proposalId` (string, required)
- `responseConfirmed` (boolean, required)
- `sessionToken` (string, required)

Output parameters:

- `result` (object)
- `status` (string)

### `quotes.create` (~74 tokens)

Create an approved Elron Club rental quote

Snapshot customer-safe approved request terms into a 24-hour quote. The application must be submitted, internally approved, due-diligence positive, and solvency passed. This does not hold inventory.

Input parameters:

- `expectedApplicationVersion` (string, required)
- `idempotencyKey` (string, required)
- `sessionToken` (string, required)

Output parameters:

- `result` (object)
- `status` (string)

### `quotes.get` (~47 tokens)

Get a scoped Elron Club rental quote

Read one privacy-minimized quote and its live expiry/availability-hold state using the application session that owns it.

Input parameters:

- `quoteId` (string, required)
- `sessionToken` (string, required)

Output parameters:

- `result` (object)
- `status` (string)

### `quotes.accept` (~88 tokens)

Accept a quote and claim an expiry-bound availability hold

With explicit customer confirmation, accept one exact active quote and atomically claim a 30-minute request-owned availability hold. This does not create or sign a contract and does not authorize payment.

Input parameters:

- `acceptanceConfirmed` (boolean, required)
- `expectedQuoteVersion` (string, required)
- `idempotencyKey` (string, required)
- `quoteId` (string, required)
- `sessionToken` (string, required)

Output parameters:

- `result` (object)
- `status` (string)

### `reservations.get_status` (~39 tokens)

Get scoped reservation progression status

Read privacy-minimized hold, contract, signature, payment, reservation, or confirmation state for one application session.

Input parameters:

- `sessionToken` (string, required)

Output parameters:

- `result` (object)
- `status` (string)

### `contracts.get_signing_link` (~52 tokens)

Get the verified applicant's contract signing link

Return a secure signing URL only when the active signer invitation email matches the email-verified application session. Human verification, review, and signature remain in the signing flow.

Input parameters:

- `sessionToken` (string, required)

Output parameters:

- `result` (object)
- `status` (string)

### `payments.get_status` (~51 tokens)

Get first-payment status

Return due and received payment truth for the scoped application. An approved human-action URL is returned only from an exact, unexpired provider session; no authorization URL is fabricated.

Input parameters:

- `sessionToken` (string, required)

Output parameters:

- `result` (object)
- `status` (string)

### `bookings.get_confirmation` (~36 tokens)

Get booking confirmation

Return a privacy-minimized booking confirmation only after the request has converted into the authoritative Stay workflow.

Input parameters:

- `sessionToken` (string, required)

Output parameters:

- `result` (object)
- `status` (string)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/club-elron-public-rentals/api-agent-public-mcp#diagnostics

## Score history

- 2026-08-04: 67
- 2026-08-03: 66
- 2026-08-02: 65
- 2026-08-01: 73
- 2026-07-31: 72
- 2026-07-30: 67
- 2026-07-29: 66
- 2026-07-28: 66
- 2026-07-27: 65
- 2026-07-26: 64

## Links

- Remote endpoint: https://elron.club/api/agent/public/mcp
- Changelog RSS feed: https://verifymcp.io/servers/club-elron-public-rentals/api-agent-public-mcp/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/club-elron-public-rentals/api-agent-public-mcp/changelog.json
- HTML version of this page: https://verifymcp.io/servers/club-elron-public-rentals/api-agent-public-mcp
