Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Move Studios Staff Ops

REMOTE · ZYRWVUIYXMQSBFCKZHKD.SUPABASE.CO · SCANNED OCT 3

Move Studios staff ops: bookings, attendance, clients, memberships, payments. Login required.

0 this week 38 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security94
Transport & Reachability0
Schema Quality & AI Usability0
  • Schema blocked by authentication: the endpoint requires auth we don't have to read it. See how to fix → Unverified
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
  • Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Tool Safety0
  • Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Capabilities0
  • Capabilities blocked by authentication: the endpoint requires auth we don't have to read them. See how to fix → Unverified

Unverified: 6 categories

Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm. Claim this server and supply a read-only token to verify it and lift the score.

Install

How do I install the Move Studios Staff Ops MCP server?

Move Studios Staff Ops is a hosted endpoint at https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · zyrwvuiyxmqsbfckzhkd.supabase.co

# add to Claude Code
claude mcp add --transport http com-move-studios-staff-ops 'https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server'
// .cursor/mcp.json
{
  "mcpServers": {
    "com-move-studios-staff-ops": {
      "url": "https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "com-move-studios-staff-ops": {
      "type": "http",
      "url": "https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.com-move-studios-staff-ops]
url = "https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-move-studios-staff-ops": {
      "type": "remote",
      "url": "https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-move-studios-staff-ops --url 'https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-move-studios-staff-ops:
    url: "https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "com-move-studios-staff-ops": {
      "Transport": "http",
      "Url": "https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server"
    }
  }
}
# add to Vellum
assistant mcp add com-move-studios-staff-ops -t streamable-http -u 'https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server'
// mcp.json
{
  "mcpServers": {
    "com-move-studios-staff-ops": {
      "type": "http",
      "url": "https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 6 Sept 26 −26
    • Endpoint reachability: reachable → behind authorisation ▼ security
    • Tool safety: pass → unverified ▼ security
    • Transport: pass → unverified ▼ security
    • Authorization: fail → pass ▲ security
    • First check of Authorization: partial security
    • Capabilities: fail → unverified ▼ functional
    • Tool coverage: 100 → unverified ▼ functional
    • First check of Schema quality: unverified functional
  • 5 Sept 26 64

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Oct 2026 · Probed https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=supabase.co CN=WE1,O=Google Trust Services,C=US 26 Aug 2026 24 Nov 2026 ECDSA 256 ECDSA-SHA256 7c35296a896c0a6f13f8495266045d45
SANs: supabase.co, *.supabase.co
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of zyrwvuiyxmqsbfckzhkd.supabase.co. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
co. present 7786 8 Verified
supabase.co. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On connection
HTTP status 401

WWW-Authenticate challenge Bearer realm="Move Studios", resource_metadata="https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server/.well-known/oauth-protected-resource"

Bearer realm="Move Studios", resource_metadata="https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server/.well-known/oauth-protected-resource"
Header Value
strict-transport-security max-age=31536000; includeSubDomains; preload
www-authenticate Bearer realm="Move Studios", resource_metadata="https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server/.well-known/oauth-protected-resource"

Protected resource metadata

Document https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server/.well-known/oauth-protected-resource
Retrieved Yes
Resource https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server
Authorisation server https://reports.move-studios.com

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server Auth required 401
http (plaintext) http://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server HTTPS enforced 301 https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server
MCP tools · 41 exposed · ~2,888 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
add_client_note ~74

Add a staff note to a client's MarianaTek profile (e.g. injury, preferences, conversation summary). Pin it to keep it at the top. [requires scope: client]

NameTypeReqDescription
client_idstring––
emailstring––
pinnedboolean––
textstringyes–

No output schema declared.

No examples provided.

add_client_to_class ~117

Book a client into a class session (or its waitlist). Uses the client's first available membership/credit unless payment_option_id is given. [requires scope: book]

NameTypeReqDescription
class_session_idstringyes–
client_idstringyes–
payment_option_idstring–From get_payment_options (optional)
payment_option_typestring–membership | credit (required with payment_option_id)
spot_idstring–Reformer/spot id (optional)
waitlistboolean––

No output schema declared.

No examples provided.

adjust_account_balance ~80

Add (positive) or remove (negative) store credit on a client's MarianaTek account balance. Use for goodwill credits or credit-based refunds instead of a card refund. [requires scope: money]

NameTypeReqDescription
amountnumberyesUSD, e.g. 25 or -25
client_idstringyes–
notestringyes–

No output schema declared.

No examples provided.

attendance_report ~100

Attendance for every class in a Pacific date range (default: last 7 days), grouped by class, instructor, or day. Includes member / ClassPass / WellHub / family-staff / other breakdown and no-show counts. [requires scope: read]

NameTypeReqDescription
date_fromstring–YYYY-MM-DD. Default 7 days ago.
date_tostring–YYYY-MM-DD inclusive. Default today.
group_bystring––

No output schema declared.

No examples provided.

cancel_class ~134

Cancel an entire class session in MarianaTek (every booking is cancelled and the membership/credit returned) and notify everyone who was booked. By default each attendee also gets the studio's standard $1 apology credit via the emergency-cancel flow. Irreversible: confirm with the user first. [requires scope: book]

NameTypeReqDescription
apology_creditboolean–Add the standard $1 comp credit to each attendee (existing studio policy)
class_session_idstringyes–
confirm_class_namestringyesMust match the class name exactly, as a safety check
notifyboolean–Email every booked attendee

No output schema declared.

No examples provided.

cancel_membership ~91

Cancel a membership. mode='end_of_cycle' (default) lets the client keep using it until the current paid period ends and stops future billing; mode='immediate' terminates it right now. Confirm with the user first. [requires scope: money]

NameTypeReqDescription
membership_idstringyes–
modestring––
notestring––
reasonstringyes–

No output schema declared.

No examples provided.

charge_client ~149

Sell a product to a client and charge their saved card on file. Safety: you must pass expected_total (what you told the client) and it must match the cart total to the cent, or nothing is charged. Run list_products and get_client first. [requires scope: money]

NameTypeReqDescription
bankcard_idstring–Specific saved card (optional; default = newest non-expired card)
client_idstringyes–
expected_totalnumberyesTotal incl. tax the client agreed to, e.g. 289.00
product_idstringyeschild_product_id from list_products (a parent product id is also accepted)
quantityinteger––

No output schema declared.

No examples provided.

check_in_client ~47

Mark a client as checked in (arrived) for a class session. [requires scope: book]

NameTypeReqDescription
class_session_idstringyes–
client_idstringyes–

No output schema declared.

No examples provided.

create_client ~85

Create a brand-new client (customer account) in MarianaTek. Fails if the email already exists. [requires scope: client]

NameTypeReqDescription
birth_datestring–YYYY-MM-DD
emailstringyes–
first_namestringyes–
last_namestringyes–
marketing_opt_inboolean––
phonestring––

No output schema declared.

No examples provided.

extend_membership ~64

Push a membership's end date later (e.g. goodwill days after a cancelled class). Date is YYYY-MM-DD Pacific. [requires scope: money]

NameTypeReqDescription
membership_idstringyes–
new_end_datestringyes–
notestringyes–

No output schema declared.

No examples provided.

freeze_membership ~74

Freeze a membership from a start date until a reactivation date (billing and usage pause). Dates are YYYY-MM-DD Pacific. [requires scope: money]

NameTypeReqDescription
freeze_fromstring–Default today
membership_idstringyes–
notestring––
reactivate_onstringyes–

No output schema declared.

No examples provided.

get_class_roster ~51

Who is booked into one class session: each attendee's name, email, status, check-in time, and membership type used. [requires scope: read]

NameTypeReqDescription
class_session_idstringyes–

No output schema declared.

No examples provided.

get_client ~54

Full profile for one client: contact info, memberships, account balance, saved cards (masked), upcoming reservations, recent attendance. [requires scope: read]

NameTypeReqDescription
client_idstring––
emailstring––

No output schema declared.

No examples provided.

get_client_notes ~46

Staff notes on a client's MarianaTek profile, newest first, plus their tags. [requires scope: read]

NameTypeReqDescription
client_idstring––
emailstring––

No output schema declared.

No examples provided.

get_credit_history ~62

A client's class-credit transactions (packs bought/used/expired, comps) and account-balance (store credit) history. [requires scope: read]

NameTypeReqDescription
client_idstring––
emailstring––
limitinteger––

No output schema declared.

No examples provided.

get_instructor_schedule ~65

Classes one instructor is teaching in a Pacific date range (default: next 7 days), with booked counts. [requires scope: read]

NameTypeReqDescription
date_fromstring––
date_tostring––
instructorstringyesFirst or last name

No output schema declared.

No examples provided.

get_membership ~48

Live details for one membership instance (status, dates, next charge, freeze, cancellation). membership ids come from get_client. [requires scope: read]

NameTypeReqDescription
membership_idstringyes–

No output schema declared.

No examples provided.

get_order ~47

Live order details from MarianaTek including refundability, items with item_id (needed for partial refunds), payments and prior refunds. [requires scope: read]

NameTypeReqDescription
order_idstringyes–

No output schema declared.

No examples provided.

get_payment_options ~61

Ways a client can pay for a specific class (membership, credits). Use before add_client_to_class when you want to pick a specific option. [requires scope: read]

NameTypeReqDescription
class_session_idstringyes–
client_idstringyes–

No output schema declared.

No examples provided.

get_reservation_history ~82

A client's booking history with counts of attended, late/penalty cancels, no-shows and graced cancels. Use it to decide on fee waivers. [requires scope: read]

NameTypeReqDescription
client_idstring––
daysinteger–Look-back window
emailstring––
limitinteger––

No output schema declared.

No examples provided.

get_spot_map ~50

Reformer/spot layout for a class session: each spot number, who is on it, and which spots are free. [requires scope: read]

NameTypeReqDescription
class_session_idstringyes–

No output schema declared.

No examples provided.

get_waitlist ~42

List the waitlist for a class session in order, plus current booked count and capacity. [requires scope: read]

NameTypeReqDescription
class_session_idstringyes–

No output schema declared.

No examples provided.

list_classes ~99

List class sessions in a Pacific-time date range (default: today) with booked counts. Filter by instructor or class name. [requires scope: read]

NameTypeReqDescription
class_namestring–Class name fragment (optional)
date_fromstring–YYYY-MM-DD (Pacific). Default today.
date_tostring–YYYY-MM-DD inclusive. Default = date_from.
instructorstring–Instructor first or last name (optional)

No output schema declared.

No examples provided.

list_client_orders ~57

Recent orders for a client (from the synced orders table). Use get_order for live refund eligibility. [requires scope: read]

NameTypeReqDescription
client_idstring––
emailstring––
limitinteger––

No output schema declared.

No examples provided.

list_instructors ~50

All instructors with contact info, active flag, classes taught in the last 30 days and scheduled in the next 14 days. [requires scope: read]

NameTypeReqDescription
include_inactiveboolean––

No output schema declared.

No examples provided.

list_products ~53

Sellable products (memberships, class packs, retail) with prices. Use child_product_id with charge_client. [requires scope: read]

NameTypeReqDescription
include_inactiveboolean––
querystring––

No output schema declared.

No examples provided.

list_tags ~35

Available client tags in MarianaTek (VIP, Extra Care, etc.). System tags cannot be assigned manually. [requires scope: read]

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

login ~49

Sign in with your Move Studios dashboard email and password. Required before using any other tool. Your dashboard role decides which tools you can use.

NameTypeReqDescription
emailstringyes–
passwordstringyes–

No output schema declared.

No examples provided.

logout ~14

Sign out of this MCP session.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

move_client_spot ~83

Move a booked client to a different reformer/spot in the same class. Use get_spot_map to see spot ids and which are free. [requires scope: book]

NameTypeReqDescription
class_session_idstringyes–
client_idstringyes–
spotstringyesSpot number/name (e.g. '7') or spot_id

No output schema declared.

No examples provided.

move_client_to_class ~71

Move a client from one class session to another (cancels the first, then books the second using their available membership/credits). [requires scope: book]

NameTypeReqDescription
client_idstringyes–
from_class_session_idstringyes–
to_class_session_idstringyes–

No output schema declared.

No examples provided.

promote_from_waitlist ~96

Move a waitlisted client into the class as a confirmed booking (removes their waitlist spot, then books them with their available membership/credits). Fails cleanly if the class is full unless allow_overbook is true. [requires scope: book]

NameTypeReqDescription
allow_overbookboolean––
class_session_idstringyes–
client_idstringyes–
spot_idstring––

No output schema declared.

No examples provided.

refund_order ~117

Refund an order back to the original payment source. Refunds the whole order unless item_ids (from get_order) are given. Memberships/packs are terminated on refund unless refund_without_termination is true. [requires scope: money]

NameTypeReqDescription
item_idsarray–Partial refund: item_id values from get_order
notestring––
order_idstringyes–
reasonstring–Cancellation reason (short)
refund_without_terminationboolean––
restockboolean––

No output schema declared.

No examples provided.

remove_client_from_class ~76

Cancel a client's reservation for a class session. MarianaTek applies its normal late-cancel policy; the membership/credit is returned per that policy. [requires scope: book]

NameTypeReqDescription
class_session_idstringyes–
client_idstringyes–
reservation_idstring–Optional: cancel this exact reservation

No output schema declared.

No examples provided.

search_clients ~60

Find clients by name or email. Returns client_id, name, email. Use the client_id in other tools. [requires scope: read]

NameTypeReqDescription
limitinteger––
querystringyesName or email fragment (min 2 chars)

No output schema declared.

No examples provided.

send_email ~114

Send a plain-text email from Move Studios to a client (by client_id) or any address. Replies go to the logged-in staff member unless reply_to is set. [requires scope: email]

NameTypeReqDescription
bcc_meboolean–BCC the sender
bodystringyesPlain text; blank lines separate paragraphs
client_idstring––
reply_tostring––
subjectstringyes–
tostring–Email address (used when client_id not given)

No output schema declared.

No examples provided.

send_sms ~102

Text a client via Twilio using the mobile number on their MarianaTek profile. Only sends if the client has opted in to transactional SMS unless override_opt_in is true. [requires scope: email]

NameTypeReqDescription
client_idstring––
emailstring––
messagestringyesPlain text, max 600 chars
override_opt_inboolean–Send even if the client has not opted in (use only for urgent class changes)

No output schema declared.

No examples provided.

set_class_capacity ~52

Change a class session's capacity and/or waitlist capacity. [requires scope: book]

NameTypeReqDescription
capacityinteger––
class_session_idstringyes–
waitlist_capacityinteger––

No output schema declared.

No examples provided.

set_client_tag ~74

Add or remove a manual tag (by name) on a client, e.g. 'VIP' or 'Extra Care'. [requires scope: client]

NameTypeReqDescription
actionstring––
client_idstring––
emailstring––
tagstringyesTag name from list_tags

No output schema declared.

No examples provided.

unfreeze_membership ~34

End an active freeze today so the membership resumes. [requires scope: money]

NameTypeReqDescription
membership_idstringyes–

No output schema declared.

No examples provided.

whoami ~29

Show who is logged in on this session, their roles, scopes, and the tools they may use.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

Common questions

What is the Move Studios Staff Ops MCP server?

Move Studios Staff Ops is an MCP server listed in the public MCP registry as com.move-studios/staff-ops. Move Studios staff ops: bookings, attendance, clients, memberships, payments. Login required. This page covers its hosted endpoint (https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server).

Is the Move Studios Staff Ops MCP server safe to use?

Move Studios Staff Ops scores 38 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Move Studios Staff Ops MCP server expose?

Move Studios Staff Ops exposes 41 tools: login, logout, whoami, search_clients, get_client, and 36 more. Their descriptions and schemas cost roughly 2,888 tokens of context every time the server is loaded.

Does the Move Studios Staff Ops MCP server require authentication?

Yes. Move Studios Staff Ops asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

Is the Move Studios Staff Ops MCP server still maintained?

Move Studios Staff Ops is still listed as active in the MCP registry. We last reached this channel on 3 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.