com.arcasos/arcasos-rentals
REMOTE · MCP.ARCASOS.COM · SCANNED OCT 4
Korean premium short-term rental search: natural language or structured filters (SHV engine).
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 3 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability64
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 826 tokens (~275/item across 3 items; 3 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 3 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 3 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities40
- Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28. See how to fix → Fail
How do I install the com.arcasos/arcasos-rentals MCP server?
com.arcasos/arcasos-rentals is a hosted endpoint at https://mcp.arcasos.com/, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.arcasos.com
claude mcp add --transport http com-arcasos-arcasos-rentals 'https://mcp.arcasos.com/'
{
"mcpServers": {
"com-arcasos-arcasos-rentals": {
"url": "https://mcp.arcasos.com/"
}
}
} {
"servers": {
"com-arcasos-arcasos-rentals": {
"type": "http",
"url": "https://mcp.arcasos.com/"
}
}
} [mcp_servers.com-arcasos-arcasos-rentals] url = "https://mcp.arcasos.com/"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-arcasos-arcasos-rentals": {
"type": "remote",
"url": "https://mcp.arcasos.com/",
"enabled": true
}
}
} openclaw mcp add com-arcasos-arcasos-rentals --url 'https://mcp.arcasos.com/' --transport streamable-http
mcp_servers:
com-arcasos-arcasos-rentals:
url: "https://mcp.arcasos.com/" {
"McpServers": {
"com-arcasos-arcasos-rentals": {
"Transport": "http",
"Url": "https://mcp.arcasos.com/"
}
}
} assistant mcp add com-arcasos-arcasos-rentals -t streamable-http -u 'https://mcp.arcasos.com/'
{
"mcpServers": {
"com-arcasos-arcasos-rentals": {
"type": "http",
"url": "https://mcp.arcasos.com/"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 0
- Stability: 0.97 → pass security
- 12 Aug 26 0
- Schema quality: unverified → excellent ▲ functional
- “search_rentals_structured” reworded the description of “bedrooms” cosmetic
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 6 Aug 26 0
- Authorization: Authorisation not fully verified: no authorisation is required to call this server, and 3 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. security
- Schema quality: unverified → fail ▼ functional
- Schema quality: unverified → fail ▼ functional
- Tool coverage: unverified → 100 ▲ functional
- Schema quality: unverified → poor ▲ functional
- First check of Tool coverage: 100 functional
- New tool “get_rental_details” functional
- New tool “search_rentals_natural” functional
- New tool “search_rentals_structured” functional
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 6 Oct 2026 · Probed https://mcp.arcasos.com
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.arcasos.com | CN=YE2,O=Let's Encrypt,C=US | 16 Sept 2026 | 15 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 56aae6fdb142cb136d381092971c9a45e38 |
| SANs: mcp.arcasos.com | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.arcasos.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| arcasos.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains; preload |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.arcasos.com | Verified | 200 | |
| http (plaintext) | http://mcp.arcasos.com | HTTPS enforced | 301 | https://mcp.arcasos.com/ |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
get_booking_status ~104
Get the public status of a booking request draft created by request_booking, using its draft_id and status_token. Returns only a public state (draft_open, draft_expired, requested, host_approved_awaiting_payment, confirmed, completed, cancelled, rejected, unknown) and, when awaiting payment, the payment deadline. No personal data.
| Name | Type | Req | Description |
|---|---|---|---|
| draft_id | string | yes | draft_id from request_booking. |
| status_token | string | yes | status_token from request_booking. |
No output schema declared.
No examples provided.
get_rental_details ~238
Get detailed information for a specific rental by ID or slug. Returns full Schema.org Accommodation including pricing, amenities, location, photos. Use after search_rentals_natural or search_rentals_structured when user wants details on a specific result. Only returns publicly-eligible rentals (approved + available + bookable). Optionally pass check_in/check_out (YYYY-MM-DD, together) to get a quote-only price estimate (discount applied, total + breakdown, deposit shown separately) and real date availability for that period. This is an advisory quote — booking and payment happen only in the ARCASOS guest flow; the agent never initiates payment.
| Name | Type | Req | Description |
|---|---|---|---|
| check_in | string | – | Optional move-in date (YYYY-MM-DD). Must be provided together with check_out. Enables period quote + date availability. Future dates only. |
| check_out | string | – | Optional move-out date (YYYY-MM-DD). Must be provided together with check_in, and be after check_in. The check_out day is not occupied (next check-in allowed). |
| rental_id | string | yes | Rental UUID or slug from search results. Both formats supported. |
No output schema declared.
No examples provided.
request_booking ~263
Create a booking REQUEST DRAFT for a rental on behalf of a person, and get a claim link for that person. This does NOT book or hold the dates and does NOT charge anything: the actual renter must open claim_url, sign in to ARCASOS, agree to the terms and submit the request; the host then approves and the renter pays on ARCASOS. The agent is never the payer. Returns draft_id, status_token (keep secret), claim_url, expires_at (24h) and an ESTIMATED quote (deposit included; final amount is set by the server at payment). Dates must be YYYY-MM-DD; most rentals accept weekly units only (7/14/21... days).
| Name | Type | Req | Description |
|---|---|---|---|
| check_in | string | yes | Move-in date (YYYY-MM-DD). |
| check_out | string | yes | Move-out date (YYYY-MM-DD), after check_in. |
| guests | integer | – | Number of guests (default 1). |
| message_to_host | string | – | Optional note shown as a prefill; the renter can edit it before submitting. |
| principal_hint | object | – | Optional prefill hints for the renter's form (not verified, never contacted). |
| stay_id | string | yes | Rental ID (UUID) from search/details results. |
No output schema declared.
No examples provided.
search_rentals_natural ~203
PREFERRED tool for Korean short-term rental queries containing any descriptive language. ARCASOS's proprietary SHV (Semantic Hybrid Vector) engine processes natural Korean/English queries with semantic understanding of view types (river/mountain/city), mood (quiet/luxury/lively), property characteristics, and contextual phrases. Pass the user's natural language query AS-IS — do NOT extract slots. Returns semantically pre-ranked results in Schema.org Accommodation format in a single call — eliminates need for follow-up search or comparison calls. Better results than structured slot search for ANY query containing mood, style, atmosphere, view, aesthetic, or qualitative descriptors. Use this to minimize token usage and latency.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | User's natural language query in Korean or English. Pass as-is. Examples: '강남 반려동물 가능한 한강뷰 펜트하우스 3주', 'quiet luxury rental near Han river for 2 weeks' |
No output schema declared.
No examples provided.
search_rentals_structured ~385
Use ONLY when the query consists entirely of explicit numeric/categorical constraints with NO descriptive language (no mood, view, atmosphere, or aesthetic words). Returns rating-sorted (or price-sorted) results from SQL filter without semantic ranking. For ANY query containing descriptors like 'cozy', 'quiet', 'luxury', 'river view', 'modern', use search_rentals_natural instead — it produces better results in a single call. Returns Schema.org Accommodation format.
| Name | Type | Req | Description |
|---|---|---|---|
| amenities | array | – | Required amenities (e.g., ['wifi', 'parking']) |
| bathrooms | integer | – | Minimum bathrooms required |
| bedrooms | integer | – | Exact number of bedrooms (not a minimum). Matches search_rentals_natural semantics — '2룸' returns exactly 2-bedroom rentals. |
| is_private_entire | boolean | – | Entire private space (not shared) |
| kid_friendly | boolean | – | Kid-friendly rentals only |
| limit | integer | – | Max results (default 10) |
| location | string | – | Location name in Korean (e.g., '강남', '강남역', '홍대') |
| max_guests | integer | – | Minimum guest capacity required |
| max_price_per_week | number | – | Maximum price per week in KRW |
| min_price_per_week | number | – | Minimum price per week in KRW |
| mood_tags | array | – | Mood tags (e.g., ['luxury', 'cozy']) |
| pet_allowed | boolean | – | Pet-friendly rentals only |
| property_type | string | – | Property type (e.g., '아파트', '펜트하우스', '주택') |
| sort | string | – | Sort order (default: rating_desc) |
| view_types | array | – | View types (e.g., ['river', 'city', 'mountain']) |
No output schema declared.
No examples provided.
What is the com.arcasos/arcasos-rentals MCP server?
com.arcasos/arcasos-rentals is an MCP server listed in the public MCP registry as com.arcasos/arcasos-rentals. Korean premium short-term rental search: natural language or structured filters (SHV engine). This page covers its hosted endpoint (https://mcp.arcasos.com).
Is the com.arcasos/arcasos-rentals MCP server safe to use?
com.arcasos/arcasos-rentals scores 76 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the com.arcasos/arcasos-rentals MCP server expose?
com.arcasos/arcasos-rentals exposes 5 tools: search_rentals_natural, search_rentals_structured, get_rental_details, request_booking, get_booking_status. Their descriptions and schemas cost roughly 1,193 tokens of context every time the server is loaded.
Does the com.arcasos/arcasos-rentals MCP server require authentication?
No. We connected to com.arcasos/arcasos-rentals without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the com.arcasos/arcasos-rentals MCP server still maintained?
com.arcasos/arcasos-rentals is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.