# Move Studios Staff Ops (remote · zyrwvuiyxmqsbfckzhkd.supabase.co)

Move Studios staff ops: bookings, attendance, clients, memberships, payments. Login required.

- Trust score: 38/100 (low)
- Change this week: 0
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-03

## Components

- remote · `zyrwvuiyxmqsbfckzhkd.supabase.co`: 38/100 (this document), [markdown](https://verifymcp.io/servers/com-move-studios-staff-ops/functions-v1-mcp-server.md), [page](https://verifymcp.io/servers/com-move-studios-staff-ops/functions-v1-mcp-server)

## Channel facts

- Endpoint: `https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.1.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-03.

- **Endpoint Security**: 94/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
  - The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents.
- **Transport & Reachability**: 0/100
  - Transport blocked by authentication: the endpoint requires auth we don't have to verify streamable-http.
- **Schema Quality & AI Usability**: 0/100
  - Schema blocked by authentication: the endpoint requires auth we don't have to read it.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 0/100
  - Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.
- **Tool Safety**: 0/100
  - Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.
- **Capabilities**: 0/100
  - Capabilities blocked by authentication: the endpoint requires auth we don't have to read them.

**Unverified: 6 categories.** Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

## Install

### How do I install the Move Studios Staff Ops MCP server?

Move Studios Staff Ops is a hosted endpoint at https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-move-studios-staff-ops 'https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server'
```

### Cursor

```json
{
  "mcpServers": {
    "com-move-studios-staff-ops": {
      "url": "https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-move-studios-staff-ops": {
      "type": "http",
      "url": "https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-move-studios-staff-ops]
url = "https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-move-studios-staff-ops": {
      "type": "remote",
      "url": "https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-move-studios-staff-ops --url 'https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-move-studios-staff-ops:
    url: "https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server"
```

### Netclaw

```json
{
  "McpServers": {
    "com-move-studios-staff-ops": {
      "Transport": "http",
      "Url": "https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-move-studios-staff-ops -t streamable-http -u 'https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server'
```

### Other

```json
{
  "mcpServers": {
    "com-move-studios-staff-ops": {
      "type": "http",
      "url": "https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-28 (score 38, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-25 (score 38, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-06 (score 38, −26)

- [security regression] Endpoint reachability: reachable → behind authorisation
- [security regression] Tool safety: pass → unverified
- [security regression] Transport: pass → unverified
- [security improvement] Authorization: fail → pass
- [security] First check of Authorization: partial
- [functional regression] Capabilities: fail → unverified
- [functional regression] Tool coverage: 100 → unverified
- [functional] First check of Schema quality: unverified

### 2026-09-05 (score 64)

First indexed and scored.

## MCP tools (41)

### `login` (~49 tokens)

Login

Sign in with your Move Studios dashboard email and password. Required before using any other tool. Your dashboard role decides which tools you can use.

Input parameters:

- `email` (string, required)
- `password` (string, required)

### `logout` (~14 tokens)

Logout

Sign out of this MCP session.

### `whoami` (~29 tokens)

Whoami

Show who is logged in on this session, their roles, scopes, and the tools they may use.

### `search_clients` (~60 tokens)

Search clients

Find clients by name or email. Returns client_id, name, email. Use the client_id in other tools. [requires scope: read]

Input parameters:

- `limit` (integer)
- `query` (string, required): Name or email fragment (min 2 chars)

### `get_client` (~54 tokens)

Get client

Full profile for one client: contact info, memberships, account balance, saved cards (masked), upcoming reservations, recent attendance. [requires scope: read]

Input parameters:

- `client_id` (string)
- `email` (string)

### `list_classes` (~99 tokens)

List classes

List class sessions in a Pacific-time date range (default: today) with booked counts. Filter by instructor or class name. [requires scope: read]

Input parameters:

- `class_name` (string): Class name fragment (optional)
- `date_from` (string): YYYY-MM-DD (Pacific). Default today.
- `date_to` (string): YYYY-MM-DD inclusive. Default = date_from.
- `instructor` (string): Instructor first or last name (optional)

### `get_class_roster` (~51 tokens)

Get class roster

Who is booked into one class session: each attendee's name, email, status, check-in time, and membership type used. [requires scope: read]

Input parameters:

- `class_session_id` (string, required)

### `attendance_report` (~100 tokens)

Attendance report

Attendance for every class in a Pacific date range (default: last 7 days), grouped by class, instructor, or day. Includes member / ClassPass / WellHub / family-staff / other breakdown and no-show counts. [requires scope: read]

Input parameters:

- `date_from` (string): YYYY-MM-DD. Default 7 days ago.
- `date_to` (string): YYYY-MM-DD inclusive. Default today.
- `group_by` (string)

### `list_instructors` (~50 tokens)

List instructors

All instructors with contact info, active flag, classes taught in the last 30 days and scheduled in the next 14 days. [requires scope: read]

Input parameters:

- `include_inactive` (boolean)

### `get_instructor_schedule` (~65 tokens)

Get instructor schedule

Classes one instructor is teaching in a Pacific date range (default: next 7 days), with booked counts. [requires scope: read]

Input parameters:

- `date_from` (string)
- `date_to` (string)
- `instructor` (string, required): First or last name

### `list_client_orders` (~57 tokens)

List client orders

Recent orders for a client (from the synced orders table). Use get_order for live refund eligibility. [requires scope: read]

Input parameters:

- `client_id` (string)
- `email` (string)
- `limit` (integer)

### `get_order` (~47 tokens)

Get order

Live order details from MarianaTek including refundability, items with item_id (needed for partial refunds), payments and prior refunds. [requires scope: read]

Input parameters:

- `order_id` (string, required)

### `list_products` (~53 tokens)

List products

Sellable products (memberships, class packs, retail) with prices. Use child_product_id with charge_client. [requires scope: read]

Input parameters:

- `include_inactive` (boolean)
- `query` (string)

### `get_payment_options` (~61 tokens)

Get payment options

Ways a client can pay for a specific class (membership, credits). Use before add_client_to_class when you want to pick a specific option. [requires scope: read]

Input parameters:

- `class_session_id` (string, required)
- `client_id` (string, required)

### `add_client_to_class` (~117 tokens)

Add client to class

Book a client into a class session (or its waitlist). Uses the client's first available membership/credit unless payment_option_id is given. [requires scope: book]

Input parameters:

- `class_session_id` (string, required)
- `client_id` (string, required)
- `payment_option_id` (string): From get_payment_options (optional)
- `payment_option_type` (string): membership | credit (required with payment_option_id)
- `spot_id` (string): Reformer/spot id (optional)
- `waitlist` (boolean)

### `remove_client_from_class` (~76 tokens)

Remove client from class

Cancel a client's reservation for a class session. MarianaTek applies its normal late-cancel policy; the membership/credit is returned per that policy. [requires scope: book]

Input parameters:

- `class_session_id` (string, required)
- `client_id` (string, required)
- `reservation_id` (string): Optional: cancel this exact reservation

### `check_in_client` (~47 tokens)

Check in client

Mark a client as checked in (arrived) for a class session. [requires scope: book]

Input parameters:

- `class_session_id` (string, required)
- `client_id` (string, required)

### `move_client_to_class` (~71 tokens)

Move client to class

Move a client from one class session to another (cancels the first, then books the second using their available membership/credits). [requires scope: book]

Input parameters:

- `client_id` (string, required)
- `from_class_session_id` (string, required)
- `to_class_session_id` (string, required)

### `create_client` (~85 tokens)

Create client

Create a brand-new client (customer account) in MarianaTek. Fails if the email already exists. [requires scope: client]

Input parameters:

- `birth_date` (string): YYYY-MM-DD
- `email` (string, required)
- `first_name` (string, required)
- `last_name` (string, required)
- `marketing_opt_in` (boolean)
- `phone` (string)

### `send_email` (~114 tokens)

Send email

Send a plain-text email from Move Studios to a client (by client_id) or any address. Replies go to the logged-in staff member unless reply_to is set. [requires scope: email]

Input parameters:

- `bcc_me` (boolean): BCC the sender
- `body` (string, required): Plain text; blank lines separate paragraphs
- `client_id` (string)
- `reply_to` (string)
- `subject` (string, required)
- `to` (string): Email address (used when client_id not given)

### `charge_client` (~149 tokens)

Charge client

Sell a product to a client and charge their saved card on file. Safety: you must pass expected_total (what you told the client) and it must match the cart total to the cent, or nothing is charged. Run list_products and get_client first. [requires scope: money]

Input parameters:

- `bankcard_id` (string): Specific saved card (optional; default = newest non-expired card)
- `client_id` (string, required)
- `expected_total` (number, required): Total incl. tax the client agreed to, e.g. 289.00
- `product_id` (string, required): child_product_id from list_products (a parent product id is also accepted)
- `quantity` (integer)

### `refund_order` (~117 tokens)

Refund order

Refund an order back to the original payment source. Refunds the whole order unless item_ids (from get_order) are given. Memberships/packs are terminated on refund unless refund_without_termination is true. [requires scope: money]

Input parameters:

- `item_ids` (array): Partial refund: item_id values from get_order
- `note` (string)
- `order_id` (string, required)
- `reason` (string): Cancellation reason (short)
- `refund_without_termination` (boolean)
- `restock` (boolean)

### `adjust_account_balance` (~80 tokens)

Adjust account balance

Add (positive) or remove (negative) store credit on a client's MarianaTek account balance. Use for goodwill credits or credit-based refunds instead of a card refund. [requires scope: money]

Input parameters:

- `amount` (number, required): USD, e.g. 25 or -25
- `client_id` (string, required)
- `note` (string, required)

### `send_sms` (~102 tokens)

Send sms

Text a client via Twilio using the mobile number on their MarianaTek profile. Only sends if the client has opted in to transactional SMS unless override_opt_in is true. [requires scope: email]

Input parameters:

- `client_id` (string)
- `email` (string)
- `message` (string, required): Plain text, max 600 chars
- `override_opt_in` (boolean): Send even if the client has not opted in (use only for urgent class changes)

### `cancel_class` (~134 tokens)

Cancel class

Cancel an entire class session in MarianaTek (every booking is cancelled and the membership/credit returned) and notify everyone who was booked. By default each attendee also gets the studio's standard $1 apology credit via the emergency-cancel flow. Irreversible: confirm with the user first. [requires scope: book]

Input parameters:

- `apology_credit` (boolean): Add the standard $1 comp credit to each attendee (existing studio policy)
- `class_session_id` (string, required)
- `confirm_class_name` (string, required): Must match the class name exactly, as a safety check
- `notify` (boolean): Email every booked attendee

### `get_waitlist` (~42 tokens)

Get waitlist

List the waitlist for a class session in order, plus current booked count and capacity. [requires scope: read]

Input parameters:

- `class_session_id` (string, required)

### `promote_from_waitlist` (~96 tokens)

Promote from waitlist

Move a waitlisted client into the class as a confirmed booking (removes their waitlist spot, then books them with their available membership/credits). Fails cleanly if the class is full unless allow_overbook is true. [requires scope: book]

Input parameters:

- `allow_overbook` (boolean)
- `class_session_id` (string, required)
- `client_id` (string, required)
- `spot_id` (string)

### `get_client_notes` (~46 tokens)

Get client notes

Staff notes on a client's MarianaTek profile, newest first, plus their tags. [requires scope: read]

Input parameters:

- `client_id` (string)
- `email` (string)

### `add_client_note` (~74 tokens)

Add client note

Add a staff note to a client's MarianaTek profile (e.g. injury, preferences, conversation summary). Pin it to keep it at the top. [requires scope: client]

Input parameters:

- `client_id` (string)
- `email` (string)
- `pinned` (boolean)
- `text` (string, required)

### `list_tags` (~35 tokens)

List tags

Available client tags in MarianaTek (VIP, Extra Care, etc.). System tags cannot be assigned manually. [requires scope: read]

### `set_client_tag` (~74 tokens)

Set client tag

Add or remove a manual tag (by name) on a client, e.g. 'VIP' or 'Extra Care'. [requires scope: client]

Input parameters:

- `action` (string)
- `client_id` (string)
- `email` (string)
- `tag` (string, required): Tag name from list_tags

### `get_membership` (~48 tokens)

Get membership

Live details for one membership instance (status, dates, next charge, freeze, cancellation). membership ids come from get_client. [requires scope: read]

Input parameters:

- `membership_id` (string, required)

### `freeze_membership` (~74 tokens)

Freeze membership

Freeze a membership from a start date until a reactivation date (billing and usage pause). Dates are YYYY-MM-DD Pacific. [requires scope: money]

Input parameters:

- `freeze_from` (string): Default today
- `membership_id` (string, required)
- `note` (string)
- `reactivate_on` (string, required)

### `unfreeze_membership` (~34 tokens)

Unfreeze membership

End an active freeze today so the membership resumes. [requires scope: money]

Input parameters:

- `membership_id` (string, required)

### `cancel_membership` (~91 tokens)

Cancel membership

Cancel a membership. mode='end_of_cycle' (default) lets the client keep using it until the current paid period ends and stops future billing; mode='immediate' terminates it right now. Confirm with the user first. [requires scope: money]

Input parameters:

- `membership_id` (string, required)
- `mode` (string)
- `note` (string)
- `reason` (string, required)

### `extend_membership` (~64 tokens)

Extend membership

Push a membership's end date later (e.g. goodwill days after a cancelled class). Date is YYYY-MM-DD Pacific. [requires scope: money]

Input parameters:

- `membership_id` (string, required)
- `new_end_date` (string, required)
- `note` (string, required)

### `get_credit_history` (~62 tokens)

Get credit history

A client's class-credit transactions (packs bought/used/expired, comps) and account-balance (store credit) history. [requires scope: read]

Input parameters:

- `client_id` (string)
- `email` (string)
- `limit` (integer)

### `set_class_capacity` (~52 tokens)

Set class capacity

Change a class session's capacity and/or waitlist capacity. [requires scope: book]

Input parameters:

- `capacity` (integer)
- `class_session_id` (string, required)
- `waitlist_capacity` (integer)

### `get_spot_map` (~50 tokens)

Get spot map

Reformer/spot layout for a class session: each spot number, who is on it, and which spots are free. [requires scope: read]

Input parameters:

- `class_session_id` (string, required)

### `move_client_spot` (~83 tokens)

Move client spot

Move a booked client to a different reformer/spot in the same class. Use get_spot_map to see spot ids and which are free. [requires scope: book]

Input parameters:

- `class_session_id` (string, required)
- `client_id` (string, required)
- `spot` (string, required): Spot number/name (e.g. '7') or spot_id

### `get_reservation_history` (~82 tokens)

Get reservation history

A client's booking history with counts of attended, late/penalty cancels, no-shows and graced cancels. Use it to decide on fee waivers. [requires scope: read]

Input parameters:

- `client_id` (string)
- `days` (integer): Look-back window
- `email` (string)
- `limit` (integer)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-move-studios-staff-ops/functions-v1-mcp-server#diagnostics

## Score history

- 2026-10-03: 38
- 2026-10-02: 38
- 2026-10-01: 38
- 2026-09-30: 38
- 2026-09-29: 38
- 2026-09-28: 38
- 2026-09-27: 38
- 2026-09-26: 38
- 2026-09-25: 38
- 2026-09-24: 38
- 2026-09-23: 38
- 2026-09-22: 38
- 2026-09-21: 38
- 2026-09-20: 38
- 2026-09-19: 38
- 2026-09-18: 38
- 2026-09-17: 38
- 2026-09-16: 38
- 2026-09-15: 38
- 2026-09-14: 38
- 2026-09-13: 38
- 2026-09-12: 38
- 2026-09-11: 38
- 2026-09-10: 38
- 2026-09-09: 38
- 2026-09-08: 38
- 2026-09-07: 38
- 2026-09-06: 38
- 2026-09-05: 64

## Common questions

### What is the Move Studios Staff Ops MCP server?

Move Studios Staff Ops is an MCP server listed in the public MCP registry as com.move-studios/staff-ops. Move Studios staff ops: bookings, attendance, clients, memberships, payments. Login required. This page covers its hosted endpoint (https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server).

### Is the Move Studios Staff Ops MCP server safe to use?

Move Studios Staff Ops scores 38 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Move Studios Staff Ops MCP server expose?

Move Studios Staff Ops exposes 41 tools: login, logout, whoami, search_clients, get_client, and 36 more. Their descriptions and schemas cost roughly 2,888 tokens of context every time the server is loaded.

### Does the Move Studios Staff Ops MCP server require authentication?

Yes. Move Studios Staff Ops asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

### Is the Move Studios Staff Ops MCP server still maintained?

Move Studios Staff Ops is still listed as active in the MCP registry. We last reached this channel on 3 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://zyrwvuiyxmqsbfckzhkd.supabase.co/functions/v1/mcp-server
- Repository: https://github.com/hananzlot/move-studios
- Website: https://reports.move-studios.com/
- Changelog RSS feed: https://verifymcp.io/servers/com-move-studios-staff-ops/functions-v1-mcp-server.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-move-studios-staff-ops/functions-v1-mcp-server.json
- HTML version of this page: https://verifymcp.io/servers/com-move-studios-staff-ops/functions-v1-mcp-server
