HemmaBo Host Booking Engine
REMOTE · WWW.HEMMABO.COM · SCANNED SEP 20
Host-owned vacation-rental direct booking via VRP. Signed offers, 0% commission. Not an OTA.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security94
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability75
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 6663 tokens (~475/item across 14 items; 13 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 13 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 15 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28. See how to fix → Fail
- Supports UI / widget rendering.Pass
How do I install the HemmaBo Host Booking Engine MCP server?
HemmaBo Host Booking Engine is a hosted endpoint at https://www.hemmabo.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · www.hemmabo.com
claude mcp add --transport http com-hemmabo-hemmabo-mcp-server 'https://www.hemmabo.com/mcp'
{
"mcpServers": {
"com-hemmabo-hemmabo-mcp-server": {
"url": "https://www.hemmabo.com/mcp"
}
}
} {
"servers": {
"com-hemmabo-hemmabo-mcp-server": {
"type": "http",
"url": "https://www.hemmabo.com/mcp"
}
}
} [mcp_servers.com-hemmabo-hemmabo-mcp-server] url = "https://www.hemmabo.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-hemmabo-hemmabo-mcp-server": {
"type": "remote",
"url": "https://www.hemmabo.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-hemmabo-hemmabo-mcp-server --url 'https://www.hemmabo.com/mcp' --transport streamable-http
mcp_servers:
com-hemmabo-hemmabo-mcp-server:
url: "https://www.hemmabo.com/mcp" {
"McpServers": {
"com-hemmabo-hemmabo-mcp-server": {
"Transport": "http",
"Url": "https://www.hemmabo.com/mcp"
}
}
} assistant mcp add com-hemmabo-hemmabo-mcp-server -t streamable-http -u 'https://www.hemmabo.com/mcp'
{
"mcpServers": {
"com-hemmabo-hemmabo-mcp-server": {
"type": "http",
"url": "https://www.hemmabo.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 17 Sept 26 0
- Tool “hemmabo_search_availability” rewrote its description, which is the text the model reads security
- 15 Sept 26 +2
- Stability: fail → pass ▲ security
- 7 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
- 5 Sept 26 0
- Server version: 4.0.8 → 4.0.9 functional
- 26 Aug 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 85 to 88.
- 24 Aug 26 0
- “get_verified_stay_offer” reworded the description of “domain” cosmetic
- “verify_vacation_rental_node” reworded the description of “domain” cosmetic
2 cosmetic changes on this day. Switch on “Show cosmetic changes” to see them.
- 23 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 78 to 82.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://www.hemmabo.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=www.hemmabo.com | CN=YR1,O=Let's Encrypt,C=US | 19 Aug 2026 | 17 Nov 2026 | RSA 2048 | SHA256-RSA | 5b36891016625fe1183e4dfef09dc00741a |
| SANs: www.hemmabo.com | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of www.hemmabo.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| hemmabo.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer realm="hemmabo-mcp", resource_metadata="https://www.hemmabo.com/.well-known/oauth-protected-resource", error="invalid_token"
Bearer realm="hemmabo-mcp", resource_metadata="https://www.hemmabo.com/.well-known/oauth-protected-resource", error="invalid_token" | Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
Protected resource metadata
| Document | https://www.hemmabo.com/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://www.hemmabo.com/mcp |
| Authorisation server | https://www.hemmabo.com |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://www.hemmabo.com/mcp | Verified | 200 | |
| http (plaintext) | http://www.hemmabo.com/mcp | HTTPS enforced | 308 | https://www.hemmabo.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
get_verified_stay_offer ~511
Fetch, verify, and render a live host-domain signed VRP stay offer for exact dates and guest count. Verifies Ed25519 JWS against domain JWKS. Call after hemmabo_search_properties returns a host domain, or after verify_vacation_rental_node confirms a domain from outside search, always before quoting final price or a booking link. Read-only: must not lock a quote, create a booking, collect guest details, or start checkout. Route booking only to the signed direct_booking_url; fall back to hemmabo_booking_negotiate/hemmabo_booking_checkout only when this call returns no signed offer, for a configured non-VRP deployment, after explicit user confirmation. The parameters work as a set: pass the same domain, checkIn, checkOut and guests the guest used at search; checkIn must be strictly before checkOut, and the resulting night count — not the dates themselves — drives the signed price and the host capacity check, so changing either date re-prices the offer. Always pass language as the guest's actual conversation language so the rendered widget matches the guest; it never affects the signed price or availability, only formatting.
| Name | Type | Req | Description |
|---|---|---|---|
| checkIn | string | yes | Requested arrival date in YYYY-MM-DD format (e.g. '2026-11-14'). Must be strictly before checkOut. Use the same dates the guest requested in search. |
| checkOut | string | yes | Requested departure date in YYYY-MM-DD format (e.g. '2026-11-17'). Must be strictly after checkIn. Guest does not stay the departure night. |
| domain | string | yes | Host-owned domain without protocol or path (e.g. 'villaakerlyckan.se', 'myvilla.it'). Invalid: 'https://...', paths, ports, or booking URLs. |
| guests | integer | yes | Total guest count as positive integer (e.g. 2, 4). Used by the host node for capacity validation and guest-tier pricing on the signed offer. |
| language | string | – | The guest's conversation language, as a BCP-47 tag (e.g. 'en', 'sv', 'de', 'sv-SE') — ALWAYS pass this, matching the language the guest is chatting in, so the rendered widget's labels, dates and curr… |
| Name | Type | Req | Description |
|---|---|---|---|
| agent_citation | object | – | Citation permission and safe-to-quote status derived from the signed offer. |
| agent_guardrails | object | – | Rules the agent must follow when presenting or acting on this offer. |
| checkIn | string | – | Echoed requested arrival date. |
| checkOut | string | – | Echoed requested departure date. |
| domain | string | yes | Echoed host domain that issued the signed offer. |
| error | string | – | – |
| fresh | boolean | – | True when the signed offer is still within its validity/freshness window. |
| guests | integer | – | Echoed requested guest count. |
| official_offer_summary | object | – | Small signed-offer summary for agents to quote without inventing price, availability, discounts, savings, comparisons, or booking details. |
| payload_matches_offer | boolean | – | True when the signed payload matches the structured offer returned to the agent. |
| signature | object | – | Ed25519/JWS verification details, including key id and verification status. |
| verified | boolean | yes | True only when the host-domain offer signature and payload checks pass. |
| widget_media | object | – | Images and media hydrated from the verified host discovery document for the ChatGPT widget. |
No examples provided.
hemmabo_booking_cancel ~380
Cancel a confirmed booking and process the Stripe refund per host cancellation policy. Use when the guest explicitly requests cancellation — if the guest wants new dates instead of ending the stay, use hemmabo_booking_reschedule instead. Do not use for pending/unpaid bookings — those expire automatically. To preview the applicable policy first, read cancellationPolicy from hemmabo_booking_status. Requires Authorization: Bearer token (MCP_API_KEY or OAuth); rate-limited per token. Destructive and idempotent in effect: a repeat cancel is refused as already cancelled and never triggers a second refund. reservationId is the booking UUID from hemmabo_booking_checkout or hemmabo_booking_create — never a propertyId — and must be paired with the guestToken issued for that same booking. reason is optional free text shown to the host; when omitted the host sees 'Cancelled via MCP'.
| Name | Type | Req | Description |
|---|---|---|---|
| guestToken | string | yes | Per-booking secret returned by hemmabo_booking_create / hemmabo_booking_checkout (the booking's guest_token, a UUID). Required to view or modify this specific booking — a valid Bearer token alone is… |
| reason | string | – | Human-readable cancellation reason for the host (e.g. 'Travel plans changed', 'Flight cancelled'). Optional; omit when the guest did not give a reason. |
| reservationId | string | yes | Booking or reservation UUID from hemmabo_booking_checkout or hemmabo_booking_create (e.g. '7c9e6679-7425-40de-944b-e07fc1f90ae7'). Required to look up, cancel, or reschedule the same booking record. |
| Name | Type | Req | Description |
|---|---|---|---|
| error | string | – | Present only when isError=true. |
| refund | object | – | Refund payload returned by cancel-booking edge function, when present. |
| reservationId | string | yes | – |
| status | string | yes | Final booking status after cancellation. |
No examples provided.
hemmabo_booking_checkout ~695
Create a fallback non-VRP booking and return a host-configured Stripe checkout URL. Use only after explicit user confirmation when no signed VRP direct_booking_url is available; when get_verified_stay_offer returns one, route the guest there instead. Use hemmabo_booking_create to record a pending booking without collecting payment yet. Behavior: existing bookings are never modified — availability is checked and dates briefly locked first; conflicts fail before anything is created or charged. Success creates exactly one pending booking and one Stripe Checkout Session on the host's connected account, returning paymentUrl, reservationId, and a one-time guestToken (required for status/cancel/reschedule). Only the Stripe webhook confirms the booking; unpaid pending bookings expire automatically. Not idempotent — check hemmabo_booking_status before retrying. Params: pass quoteId only for the exact propertyId/dates/guests locked by hemmabo_booking_negotiate (valid 15 min); omit to price fresh. channel selects which locked total is used; paymentMode changes only the handoff form, never the price. Requires Authorization: Bearer token (MCP_API_KEY or OAuth); rate-limited per token.
| Name | Type | Req | Description |
|---|---|---|---|
| channel | string | – | Pricing channel selector. 'federation' (default for agent flows): direct host-source total. 'public': standard website rate without agent channel pricing. Omit to use federation. |
| checkIn | string | yes | Arrival date in ISO 8601 calendar format YYYY-MM-DD (e.g. '2026-07-15'). Must be today or later in the property's timezone. Must be strictly before checkOut; together they define the stay length used… |
| checkOut | string | yes | Departure date in ISO 8601 calendar format YYYY-MM-DD (e.g. '2026-07-22'). Must be strictly after checkIn on the same calendar. The guest does not stay the departure night. |
| guestEmail | string | yes | Primary guest email in RFC 5322 format (e.g. 'anna@example.com'). Used for booking confirmation and host contact; must be deliverable. |
| guestName | string | yes | Primary guest full name as plain text (e.g. 'Anna Svensson'). Stored on the booking for host confirmation; use the name the guest provided. |
| guestPhone | string | – | Primary guest phone in E.164 format with country code (e.g. '+46701234567'). Optional; omit when unknown. Recommended for check-in coordination. |
| guests | integer | yes | Total number of guests as integer >= 1 (e.g. 4). |
| paymentMode | string | – | Stripe payment flow. 'checkout_session' (default): returns a browser redirect URL. 'payment_intent': returns client_secret for embedded/agentic payment integrations. Omit to use checkout_session. |
| propertyId | string | yes | Stable property UUID from hemmabo_search_properties (e.g. '550e8400-e29b-41d4-a716-446655440000'). Pass the exact UUID string — never a property name, host domain, or booking URL. |
| quoteId | string | – | Quote ID string from hemmabo_booking_negotiate (e.g. 'q_abc123'). Optional — omit to calculate a fresh host-source price at checkout. Provide when the guest locked a price within the 15-minute quote… |
| Name | Type | Req | Description |
|---|---|---|---|
| checkIn | string | – | – |
| checkOut | string | – | – |
| createdAt | string | – | – |
| currency | string | yes | – |
| error | string | – | Present only when isError=true. |
| guestToken | string | – | Per-booking secret (guest_token) for this booking. Present it back as guestToken on hemmabo_booking_status / hemmabo_booking_cancel / hemmabo_booking_reschedule to view or modify this booking; a Bear… |
| guests | integer | – | – |
| mpp | object | – | Present when paymentMode='payment_intent'. |
| nights | integer | – | – |
| paymentUrl | string | – | Stripe Checkout redirect URL. |
| payment_modes | array | – | Supported payment modes. |
| propertyId | string | – | – |
| reservationId | string | yes | Booking UUID. Use for subsequent status/cancel/reschedule calls. |
| status | string | – | Booking status (typically 'pending' until payment succeeds). |
| totalPrice | integer | yes | Final total charged (or to be charged), in minor currency units. |
No examples provided.
hemmabo_booking_create ~539
Create a pending direct booking without online payment for configured non-VRP fallback deployments. Use only after explicit user confirmation, with a propertyId from search, and only when no signed VRP direct_booking_url is available. For signed VRP offers, route to the signed host-domain URL instead. Requires Authorization: Bearer token (MCP_API_KEY or OAuth); rate-limited per token. Writes exactly one pending booking awaiting the host's decision; availability is checked first — conflicts or a stale calendar fail the call before anything is written. Not idempotent — check hemmabo_booking_status before retrying on timeout. There is no price or quoteId parameter — the node prices the stay itself at creation (gap-night pricing applies automatically). The booking is identified by propertyId + the checkIn/checkOut range + guests; guestName and guestEmail are required for host confirmation, guestPhone is optional. Returns bookingId and a one-time guestToken for later status/cancel/reschedule.
| Name | Type | Req | Description |
|---|---|---|---|
| checkIn | string | yes | Arrival date in ISO 8601 calendar format YYYY-MM-DD (e.g. '2026-07-15'). Must be today or later in the property's timezone. Must be strictly before checkOut; together they define the stay length used… |
| checkOut | string | yes | Departure date in ISO 8601 calendar format YYYY-MM-DD (e.g. '2026-07-22'). Must be strictly after checkIn on the same calendar. The guest does not stay the departure night. |
| guestEmail | string | yes | Primary guest email in RFC 5322 format (e.g. 'anna@example.com'). Used for booking confirmation and host contact; must be deliverable. |
| guestName | string | yes | Primary guest full name as plain text (e.g. 'Anna Svensson'). Stored on the booking for host confirmation; use the name the guest provided. |
| guestPhone | string | – | Primary guest phone in E.164 format with country code (e.g. '+46701234567'). Optional; omit when unknown. Recommended for check-in coordination. |
| guests | integer | yes | Total guest count as a positive integer (e.g. 2, 4, 6). Used for capacity filtering and staircase pricing tiers. Properties with maxGuests below this value are excluded from search results. |
| propertyId | string | yes | Stable property UUID from hemmabo_search_properties (e.g. '550e8400-e29b-41d4-a716-446655440000'). Pass the exact UUID string — never a property name, host domain, or booking URL. |
| Name | Type | Req | Description |
|---|---|---|---|
| bookingId | string | yes | Persistent booking UUID. Use for status/cancel/reschedule. |
| calendar_freshness | object | – | Incoming OTA calendar-sync freshness at booking time. The same object is embedded in the error payload when a stale calendar blocks the call — declared here so agents can treat it as a first-class fi… |
| channel_mirror | object | – | Outbound channel-manager mirror heartbeat for the host's mapped external channel (status: current|stale|partial|error|not_connected). Informational only — it never affects availability or this bookin… |
| checkIn | string | – | – |
| checkOut | string | – | – |
| createdAt | string | – | – |
| currency | string | – | – |
| error | string | – | Present only when isError=true. |
| federationDiscountPercent | integer | – | – |
| gapDiscountPercent | integer | – | – |
| guestToken | string | – | Per-booking secret (guest_token) for this booking. Present it back as guestToken on hemmabo_booking_status / hemmabo_booking_cancel / hemmabo_booking_reschedule to view or modify this booking; a Bear… |
| guests | integer | – | – |
| nights | integer | – | – |
| packageApplied | string | – | – |
| priceType | string | – | Pricing mode used (federation/gap_night/package_*). |
| propertyId | string | – | – |
| status | string | yes | Host-node booking status. 'completed' is a protocol compatibility output only, not a status this tool writes. |
| totalPrice | integer | – | Final price written to the booking. |
No examples provided.
hemmabo_booking_negotiate ~455
PRICE LOCK, not negotiation: the host's price is fixed — this tool never bargains, discounts, or alters it; it only freezes the current host-source price for 15 minutes so it cannot change during checkout. It refuses to lock dates the property's calendar cannot deliver and returns alternative bookable windows instead. Use it only in the non-VRP fallback checkout flow, when no signed direct_booking_url is available and the user explicitly asks to lock a price. Never use this for search, availability, VRP offers, rendering a stay-offer widget, or verified-offer display — use get_verified_stay_offer instead. Requires Authorization: Bearer token (MCP_API_KEY or OAuth); rate-limited per token. Not idempotent: each call writes a new snapshot; validUntil is fixed at creation and never extended — re-locking returns a new quoteId. The lock freezes both the public and the direct host-source total; hemmabo_booking_checkout's channel picks which one is redeemed. Redeem the quoteId only for the identical propertyId + checkIn/checkOut + guests, and only until validUntil — changing any of them requires a new quote. Night count and guest count together select the locked price tier.
| Name | Type | Req | Description |
|---|---|---|---|
| checkIn | string | yes | Arrival date in ISO 8601 calendar format YYYY-MM-DD (e.g. '2026-07-15'). Must be today or later in the property's timezone. Must be strictly before checkOut; together they define the stay length used… |
| checkOut | string | yes | Departure date in ISO 8601 calendar format YYYY-MM-DD (e.g. '2026-07-22'). Must be strictly after checkIn on the same calendar. The guest does not stay the departure night. |
| guests | integer | yes | Total number of guests as integer >= 1 (e.g. 4). Determines which price tier is applied. |
| propertyId | string | yes | Stable property UUID from hemmabo_search_properties (e.g. '550e8400-e29b-41d4-a716-446655440000'). Pass the exact UUID string — never a property name, host domain, or booking URL. |
| Name | Type | Req | Description |
|---|---|---|---|
| breakdown | object | – | – |
| checkIn | string | – | – |
| checkOut | string | – | – |
| currency | string | – | – |
| error | string | – | Present only when isError=true. |
| federationDiscountPercent | integer | – | – |
| federationTotal | integer | yes | – |
| gapDiscountPercent | integer | – | – |
| gapNight | boolean | – | – |
| gapTotal | integer | – | – |
| guests | integer | – | – |
| nights | integer | – | – |
| packageApplied | string | – | – |
| propertyId | string | – | – |
| publicTotal | integer | – | – |
| quoteId | string | yes | Snapshot ID. Pass to hemmabo_booking_checkout to lock this price. |
| validUntil | string | yes | Quote expiry (ISO 8601). Typically 15 minutes after creation. |
No examples provided.
hemmabo_booking_quote ~348
Get a detailed pricing quote for a specific property, dates, and guest count. Use this tool after confirming availability to show the user exact pricing before booking. Do NOT use before checking availability — the quote may be invalid if dates are unavailable. Returns the final host-source total for the booking flow, per-night breakdown, and package pricing context. All prices are integers in the property's local currency (e.g. SEK). The quote is the propertyId priced for the exact checkIn/checkOut range and guests; the night count and party size together select the price tier, so changing any of them re-quotes.
| Name | Type | Req | Description |
|---|---|---|---|
| checkIn | string | yes | Arrival date in ISO 8601 calendar format YYYY-MM-DD (e.g. '2026-07-15'). Must be today or later in the property's timezone. Must be strictly before checkOut; together they define the stay length used… |
| checkOut | string | yes | Departure date in ISO 8601 calendar format YYYY-MM-DD (e.g. '2026-07-22'). Must be strictly after checkIn on the same calendar. The guest does not stay the departure night. |
| guests | integer | yes | Total guest count as a positive integer (e.g. 2, 4, 6). Used for capacity filtering and staircase pricing tiers. Properties with maxGuests below this value are excluded from search results. |
| propertyId | string | yes | Stable property UUID from hemmabo_search_properties (e.g. '550e8400-e29b-41d4-a716-446655440000'). Pass the exact UUID string — never a property name, host domain, or booking URL. |
| Name | Type | Req | Description |
|---|---|---|---|
| breakdown | object | – | Detailed pricing breakdown. |
| checkIn | string | – | – |
| checkOut | string | – | – |
| currency | string | – | ISO 4217 currency code. |
| directBookingDiscountPercent | integer | – | Legacy internal field. Do not present this as a guest-facing discount, savings, or comparison. |
| directBookingTotal | integer | – | Preferred user-facing field: direct host-source total. |
| error | string | – | Present only when isError=true. |
| federationDiscountPercent | integer | – | Legacy internal field. Do not present this as a guest-facing discount, savings, or comparison. |
| federationTotal | integer | – | Legacy field: direct host-source total. Prefer directBookingTotal in user-facing copy. |
| gapDiscountPercent | integer | – | Gap-night discount percentage when applied. |
| gapNight | boolean | – | True when the stay qualifies as a gap fill. |
| gapTotal | integer | – | Gap-night adjusted total when applicable; otherwise null. |
| guests | integer | – | – |
| hostSourcePublicTotal | integer | – | Preferred user-facing field: public host-source total. |
| nights | integer | – | Number of nights in the range. |
| packageApplied | string | – | Applied package, if any. |
| propertyId | string | – | – |
| publicTotal | integer | – | Website rate total in minor currency units. |
No examples provided.
hemmabo_booking_reschedule ~474
Reschedule a confirmed or pending booking to new dates with automatic repricing and Stripe charge/refund. Use when the guest wants to change dates on an existing booking — if the guest wants to end the stay entirely rather than move it, use hemmabo_booking_cancel instead. Do not use if cancelled or if a protocol compatibility client reports completed — check hemmabo_booking_status first. Requires Authorization: Bearer token (MCP_API_KEY or OAuth). Destructive write: the original dates are released back to the host calendar and the original price no longer applies — the booking keeps the same reservationId (updated in place, never recreated), and the price difference is charged or refunded via Stripe. Rate-limited per token. Identify the existing booking by reservationId, then give the new stay as newCheckIn/newCheckOut (newCheckIn strictly before newCheckOut); the new night count re-prices the stay exactly like a fresh quote.
| Name | Type | Req | Description |
|---|---|---|---|
| guestToken | string | yes | Per-booking secret returned by hemmabo_booking_create / hemmabo_booking_checkout (the booking's guest_token, a UUID). Required to view or modify this specific booking — a valid Bearer token alone is… |
| newCheckIn | string | yes | New arrival date in YYYY-MM-DD format (e.g. '2026-08-01'). Must be today or later. Must be strictly before newCheckOut. |
| newCheckOut | string | yes | New departure date in YYYY-MM-DD format (e.g. '2026-08-08'). Must be strictly after newCheckIn. |
| reason | string | – | Human-readable reschedule reason for host records (e.g. 'Flight delayed', 'Extended conference'). Optional; omit when not provided by the guest. |
| reservationId | string | yes | Booking or reservation UUID from hemmabo_booking_checkout or hemmabo_booking_create (e.g. '7c9e6679-7425-40de-944b-e07fc1f90ae7'). Required to look up, cancel, or reschedule the same booking record. |
| Name | Type | Req | Description |
|---|---|---|---|
| error | string | – | Present only when isError=true. |
| newDates | object | – | – |
| previousDates | object | – | – |
| pricing | object | – | – |
| reason | string | – | – |
| reservationId | string | yes | – |
| status | string | yes | Booking status after reschedule. |
No examples provided.
hemmabo_booking_status ~341
Retrieve current status and full details of an existing booking by reservationId. Use to confirm checkout/create succeeded or before cancel/reschedule. Do NOT use for property discovery, availability, or pricing — use hemmabo_search_properties, hemmabo_search_availability, or hemmabo_booking_quote for those. Requires Authorization: Bearer token (MCP_API_KEY or OAuth); rate-limited per token. Read-only against the database — never writes, so it is safe to poll after a checkout timeout — but returns guest PII (name, email). reservationId is the booking UUID returned by hemmabo_booking_checkout or hemmabo_booking_create — never a propertyId — and guestToken is the secret issued with that same booking: a mismatched pair reveals nothing, not even that the booking exists. Without a reservationId there is no booking to look up yet.
| Name | Type | Req | Description |
|---|---|---|---|
| guestToken | string | yes | Per-booking secret returned by hemmabo_booking_create / hemmabo_booking_checkout (the booking's guest_token, a UUID). Required to view or modify this specific booking — a valid Bearer token alone is… |
| reservationId | string | yes | Booking or reservation UUID from hemmabo_booking_checkout or hemmabo_booking_create (e.g. '7c9e6679-7425-40de-944b-e07fc1f90ae7'). Required to look up, cancel, or reschedule the same booking record. |
| Name | Type | Req | Description |
|---|---|---|---|
| cancellationPolicy | object | – | Host cancellation-policy details applicable to this booking. |
| checkIn | string | – | Booked arrival date. |
| checkOut | string | – | Booked departure date. |
| createdAt | string | – | Booking creation timestamp. |
| currency | string | – | ISO 4217 currency code for the booking total. |
| error | string | – | Present only when isError=true. |
| guestEmail | string | – | Primary guest email stored on the booking. |
| guestName | string | – | Primary guest name stored on the booking. |
| guests | integer | – | Booked guest count. |
| propertyDomain | string | – | Host-owned domain associated with the property. |
| propertyId | string | – | Property UUID associated with the booking. |
| propertyName | string | – | Display name of the booked property. |
| reservationId | string | yes | Echoed booking or reservation UUID. |
| status | string | yes | Host-node booking status. 'completed' is a protocol compatibility output only, not the active lifecycle truth. |
| totalPrice | integer | – | Total amount in minor currency units. |
| updatedAt | string | – | Last update timestamp for the booking record. |
No examples provided.
hemmabo_host_onboarding_link ~432
Return a safe HemmaBo onboarding handoff URL for a vacation-rental host who wants their own booking website or booking engine. Not for guests — guests should use hemmabo_search_properties instead. Use after explaining the fit or when the host asks to start; if the host is still evaluating whether HemmaBo fits, run hemmabo_host_readiness_check first — it already returns the same prefilled URL in its next_step. This tool is read-only and does not create a HemmaBo account, buy a domain, configure Stripe, write to Supabase, or provision a booking site. It returns the URL, what the host gets, and what the host should prepare. All parameters are optional prefill: they never change where the host lands — the URL always opens the same onboarding page with the passed details filled in; blank values are simply left out, and nothing is stored server-side.
| Name | Type | Req | Description |
|---|---|---|---|
| city | string | – | City or municipality (e.g. 'Kävlinge', 'Florence'). Optional; used in onboarding URL prefill when provided. |
| country | string | – | Country where the property operates (e.g. 'Sweden', 'Italy', 'Morocco'). Optional; improves onboarding URL locale and fit assessment. |
| domain | string | – | Host-owned domain without protocol or path (e.g. 'villaakerlyckan.se', 'myvilla.it'). Optional; omit when the host has not chosen a domain yet. Invalid: 'https://...', paths, ports, or booking URLs. |
| language | string | – | ISO 639-1 language hint for onboarding copy (e.g. 'sv', 'en', 'de', 'fr'). Optional; omit to default to English. |
| propertyName | string | – | Property or business display name (e.g. 'Villa Åkerlyckan'). Optional; carried into onboarding URL when provided. |
| region | string | – | Region or area (e.g. 'Skåne', 'Toscana', 'Marrakech-Safi'). Optional; narrows onboarding handoff and proof examples. |
| Name | Type | Req | Description |
|---|---|---|---|
| capabilities | array | yes | Host-facing capabilities included in HemmaBo. |
| next_step | object | yes | Safe handoff action for the host. |
| ok | boolean | yes | – |
| privacy_note | string | – | Clarifies that the call is read-only and does not store host data. |
| product | object | yes | HemmaBo product, pricing, onboarding URL, and live proof URLs. |
| setup_items | array | yes | Inputs the host should prepare before onboarding. |
No examples provided.
hemmabo_host_readiness_check ~643
Read-only fit check for a vacation-rental host evaluating HemmaBo for their own booking website or booking engine. Use when the user is a host or property owner, not a guest booking a stay; guests should use hemmabo_search_properties instead. Returns a fit verdict, what the host gets, the setup inputs to prepare, and a safe onboarding next step. Does not create an account, buy a domain, configure Stripe, store host data, or provision a website. When the host is ready to start, follow up with hemmabo_host_onboarding_link. Only five inputs sharpen the fit verdict: a domain (hasOwnDomain or domain), currentChannels, one location signal (city/region/country), and the wants* booleans, which count unless explicitly false — omitting them never lowers the verdict; propertyName and preferredLanguage only prefill the onboarding URL, and with no inputs the summary is generic.
| Name | Type | Req | Description |
|---|---|---|---|
| city | string | – | City or municipality (e.g. 'Kävlinge', 'Florence'). Optional; used in onboarding URL prefill when provided. |
| country | string | – | Country where the property operates (e.g. 'Sweden', 'Italy', 'Morocco'). Optional; improves onboarding URL locale and fit assessment. |
| currentChannels | array | – | Optional list of channels the host uses today. Omit when unknown. Helps assess migration fit from OTAs to their own booking website. |
| domain | string | – | Host-owned domain without protocol or path (e.g. 'villaakerlyckan.se', 'myvilla.it'). Optional; omit when the host has not chosen a domain yet. Invalid: 'https://...', paths, ports, or booking URLs. |
| hasOwnDomain | boolean | – | True if the host already owns a domain or explicitly wants one (e.g. true for 'I have villaakerlyckan.se'). False or omit when still undecided. |
| preferredLanguage | string | – | ISO 639-1 language hint for onboarding copy (e.g. 'sv', 'en', 'de', 'fr'). Optional; omit to default to English. |
| propertyName | string | – | Property or business display name (e.g. 'Villa Åkerlyckan'). Optional; carried into onboarding URL when provided. |
| propertyType | string | – | Property category enum. Optional; omit when unknown. 'villa'/'holiday_home' fit best; 'hotel' may indicate a poor HemmaBo fit for large chains. |
| region | string | – | Region or area (e.g. 'Skåne', 'Toscana', 'Marrakech-Safi'). Optional; narrows onboarding handoff and proof examples. |
| wantsAiAgentBooking | boolean | – | True if the host wants AI agents (ChatGPT, Claude, Cursor) to discover and book via their own official website. False or omit when they only want a guest website. |
| wantsDirectPayments | boolean | – | True if the host wants Stripe Connect payouts direct to their account. False or omit when they expect HemmaBo to be merchant of record (not supported). |
| Name | Type | Req | Description |
|---|---|---|---|
| agent_instruction | string | yes | How an AI agent should describe HemmaBo without overclaiming. |
| capabilities | array | yes | Host-facing capabilities included in HemmaBo. |
| next_step | object | yes | Safe handoff action for the host. |
| ok | boolean | yes | True when the fit check completed. |
| product | object | yes | HemmaBo product summary, pricing, onboarding URL, and live proof URLs. |
| readiness | object | yes | Fit verdict and boundaries for the host's described need. |
| setup_items | array | yes | Inputs the host should prepare before onboarding. |
No examples provided.
hemmabo_search_availability ~456
Check whether a specific property is available for the requested dates. Use this tool after the user has selected a property from hemmabo_search_properties and wants to confirm availability before getting a quote. Do NOT use for general browsing — use hemmabo_search_properties instead. Read-only, open to anonymous callers (no Bearer token), and rate-limited: checking availability never places a hold or reserves dates. Returns available=true/false with conflict details and, when unavailable, the host node's own next available window (alternativeDates, at most one entry — the same window the node's /api/availability reports, never a platform-invented date); a stale inbound calendar sync blocks an available answer (fails closed with calendar_freshness) instead of guessing. Omit guests to check dates only; pass it to price the alternative windows and to gate capacity — counts above the property's maximum return available=false (guests_exceed_max) with no alternatives. Stays shorter than the host's effective minimum nights return available=false with reasonCode min_nights_violation — extend the stay rather than shifting dates. The verdict always matches the host node's own availability API.
| Name | Type | Req | Description |
|---|---|---|---|
| checkIn | string | yes | Arrival date in ISO 8601 calendar format YYYY-MM-DD (e.g. '2026-07-15'). Must be today or later in the property's timezone. Must be strictly before checkOut; together they define the stay length used… |
| checkOut | string | yes | Departure date in ISO 8601 calendar format YYYY-MM-DD (e.g. '2026-07-22'). Must be strictly after checkIn on the same calendar. The guest does not stay the departure night. |
| guests | integer | – | Optional guest count (e.g. 4). Omit when only checking date availability without pricing. When provided, alternative date windows in the response include live host-source totals for that guest count. |
| propertyId | string | yes | Stable property UUID from hemmabo_search_properties (e.g. '550e8400-e29b-41d4-a716-446655440000'). Pass the exact UUID string — never a property name, host domain, or booking URL. |
| Name | Type | Req | Description |
|---|---|---|---|
| alternativeDates | array | – | The host node's own next available window (at most one) to offer when the requested dates are unavailable — identical to the node's /api/availability nextAvailable. Empty when the node offers none. |
| available | boolean | yes | True if the property is bookable for the entire range. |
| calendar_freshness | object | – | Incoming OTA calendar-sync freshness at answer time. The same object is embedded in the error payload when a stale calendar blocks the call — declared here so agents can treat it as a first-class fie… |
| channel_mirror | object | – | Outbound channel-manager mirror heartbeat for the host's mapped external channel (status: current|stale|partial|error|not_connected). Informational only — it never affects `available`; the host node… |
| checkIn | string | – | – |
| checkOut | string | – | – |
| error | string | – | Present only when isError=true. |
| propertyId | string | – | – |
| reason | string | – | Reason when available=false. |
No examples provided.
hemmabo_search_properties ~453
Search available vacation rental properties by location and travel dates. Use when the user wants to find or browse places to stay. Discovery only — call get_verified_stay_offer with the host domain and same dates before the final answer so the client can render the verified stay offer widget; never quote a final price or booking link from search alone. Do NOT use when the user already has a propertyId or host domain. Returns propertyId, host domain, live availability, host-source pricing, and capacity. Parameters combine as one filter with guests and the checkIn/checkOut range (checkIn strictly before checkOut): region matches broadly against region, city, and country names, while country matches the country field alone — omit both and the search spans every published property. Capacity misses are excluded; date-unavailable matches return separately in unavailableMatches with up to three alternative windows.
| Name | Type | Req | Description |
|---|---|---|---|
| checkIn | string | yes | Arrival date in ISO 8601 calendar format YYYY-MM-DD (e.g. '2026-07-15'). Must be today or later in the property's timezone. Must be strictly before checkOut; together they define the stay length used… |
| checkOut | string | yes | Departure date in ISO 8601 calendar format YYYY-MM-DD (e.g. '2026-07-22'). Must be strictly after checkIn on the same calendar. The guest does not stay the departure night. |
| country | string | – | Country name to filter by (e.g. 'Sweden', 'Italy', 'Morocco'). Partial case-insensitive match. Provide at least one of region or country; omit when region already narrows the destination. |
| guests | integer | yes | Total guest count as a positive integer (e.g. 2, 4, 6). Used for capacity filtering and staircase pricing tiers. Properties with maxGuests below this value are excluded from search results. |
| region | string | – | Region, area, or destination to search within (e.g. 'Skåne', 'Kävlinge', 'Toscana', 'Bavaria'). Partial case-insensitive match. Provide at least one of region or country; omit only when country alone… |
| Name | Type | Req | Description |
|---|---|---|---|
| checkIn | string | – | Echoed check-in date (YYYY-MM-DD). |
| checkOut | string | – | Echoed check-out date (YYYY-MM-DD). |
| error | string | – | Present only when isError=true. |
| guests | integer | – | Echoed guest count. |
| properties | array | – | Available properties matching the search criteria, with live host-source pricing. |
No examples provided.
verify_vacation_rental_node ~265
Verify that a vacation-rental host domain is a valid Vacation Rental Protocol (VRP) node before trusting it. Reads the domain's .well-known/vacation-rental.json and JWKS. Read-only trust check: no availability, pricing, booking, or payment — do NOT use it to answer those questions. Use when a host domain arrives from outside search (user-typed or third-party); domains returned by hemmabo_search_properties can go straight to get_verified_stay_offer. On success, call get_verified_stay_offer with the same domain and stay dates. The single input is the host domain as a bare hostname (no scheme or path); public domains only — IPs, ports, and local/private hostnames are refused. Pass the node's canonical domain exactly — www and apex are distinct identities, and verification fails when the domain's declared canonical_domain differs from the one you passed. Verification reads that domain's own .well-known and JWKS, so the result is only as trustworthy as the exact domain you pass.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Host-owned domain without protocol or path (e.g. 'villaakerlyckan.se', 'myvilla.it'). Invalid: 'https://...', paths, ports, or booking URLs. |
| Name | Type | Req | Description |
|---|---|---|---|
| discovery_url | string | – | The .well-known vacation-rental discovery URL read from the host domain. |
| domain | string | yes | Echoed canonical host domain that was checked. |
| error | string | – | Present when verified=false or the node cannot be checked. |
| jwks_url | string | – | Host-domain JWKS URL containing the Ed25519 public keys used to verify signed offers. |
| protocol | string | – | Protocol identifier discovered on the host domain. A valid node declares exactly 'vacation-rental-protocol' in its .well-known/vacation-rental.json protocol field, and that is the value returned here. |
| protocol_version | string | – | VRP version declared by the host discovery document. |
| signing | object | – | Summary of accepted signing algorithms, key ids, and signing-key checks. |
| verified | boolean | yes | True only when discovery, JWKS, signing metadata, and verified-offer endpoint checks pass. |
| verified_stay_offer_url | string | – | Host-domain endpoint template or URL used to request signed verified stay offers. |
No examples provided.
What is the HemmaBo Host Booking Engine MCP server?
HemmaBo Host Booking Engine is an MCP server listed in the public MCP registry as com.hemmabo/hemmabo-mcp-server. Host-owned vacation-rental direct booking via VRP. Signed offers, 0% commission. Not an OTA. This page covers its hosted endpoint (https://www.hemmabo.com/mcp).
Is the HemmaBo Host Booking Engine MCP server safe to use?
HemmaBo Host Booking Engine scores 92 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the HemmaBo Host Booking Engine MCP server expose?
HemmaBo Host Booking Engine exposes 13 tools: hemmabo_search_properties, hemmabo_search_availability, hemmabo_booking_quote, hemmabo_booking_create, hemmabo_booking_negotiate, and 8 more. Their descriptions and schemas cost roughly 5,992 tokens of context every time the server is loaded.
Does the HemmaBo Host Booking Engine MCP server require authentication?
Yes. HemmaBo Host Booking Engine asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the HemmaBo Host Booking Engine MCP server still maintained?
HemmaBo Host Booking Engine is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.