com.mydriverparis/booking
REMOTE · MCP-MYDRIVERPARIS.MYDRIVERPARIS.WORKERS.DEV · SCANNED OCT 4
Book a private driver in Paris: live quotes, airport transfers, tours, VIP Meet & Greet. No auth.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 406, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability61
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 3013 tokens (~301/item across 10 items; 10 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 11 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the com.mydriverparis/booking MCP server?
com.mydriverparis/booking is a hosted endpoint at https://mcp-mydriverparis.mydriverparis.workers.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp-mydriverparis.mydriverparis.workers.dev
claude mcp add --transport http com-mydriverparis-booking 'https://mcp-mydriverparis.mydriverparis.workers.dev/mcp'
{
"mcpServers": {
"com-mydriverparis-booking": {
"url": "https://mcp-mydriverparis.mydriverparis.workers.dev/mcp"
}
}
} {
"servers": {
"com-mydriverparis-booking": {
"type": "http",
"url": "https://mcp-mydriverparis.mydriverparis.workers.dev/mcp"
}
}
} [mcp_servers.com-mydriverparis-booking] url = "https://mcp-mydriverparis.mydriverparis.workers.dev/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-mydriverparis-booking": {
"type": "remote",
"url": "https://mcp-mydriverparis.mydriverparis.workers.dev/mcp",
"enabled": true
}
}
} openclaw mcp add com-mydriverparis-booking --url 'https://mcp-mydriverparis.mydriverparis.workers.dev/mcp' --transport streamable-http
mcp_servers:
com-mydriverparis-booking:
url: "https://mcp-mydriverparis.mydriverparis.workers.dev/mcp" {
"McpServers": {
"com-mydriverparis-booking": {
"Transport": "http",
"Url": "https://mcp-mydriverparis.mydriverparis.workers.dev/mcp"
}
}
} assistant mcp add com-mydriverparis-booking -t streamable-http -u 'https://mcp-mydriverparis.mydriverparis.workers.dev/mcp'
{
"mcpServers": {
"com-mydriverparis-booking": {
"type": "http",
"url": "https://mcp-mydriverparis.mydriverparis.workers.dev/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 29 Sept 26 0
- Tool “book_meetgreet” rewrote its description, which is the text the model reads security
- 28 Sept 26 +7
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 17 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
- 15 Sept 26 −1
- Tool “get_quote” rewrote its description, which is the text the model reads security
- 27 Aug 26 0
- Tool “resolve_flight” rewrote its description, which is the text the model reads security
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 0
- Stability: 0.97 → pass security
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 4 Oct 2026 · Probed https://mcp-mydriverparis.mydriverparis.workers.dev/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mydriverparis.workers.dev | CN=YE2,O=Let's Encrypt,C=US | 20 Sept 2026 | 19 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 6475de7584e6f8355877a3bc98b5cb15e82 |
| SANs: *.mydriverparis.workers.dev, mydriverparis.workers.dev | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp-mydriverparis.mydriverparis.workers.dev. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| dev. | present | 60074 | 8 | Verified |
| workers.dev. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp-mydriverparis.mydriverparis.workers.dev/mcp | Verified | 200 | |
| http (plaintext) | http://mcp-mydriverparis.mydriverparis.workers.dev/mcp | Inconclusive | 406 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
book_meetgreet ~956
Create a secure payment link for a VIP Meet & Greet booking, with optional transfer combo. Available locations: CDG, Orly, Gare de Lyon — Meet & Greet is NO LONGER offered at Gare du Nord (do not quote or book it there). M&G prices are FIXED (CDG/Orly 250€ base for 2 pax + 50€/extra, Gare de Lyon 350€ + 75€/extra) — do NOT call get_quote for the M&G part. Some event dates carry a supplement (e.g. Paris Air Show): the mg_price returned here is the amount actually charged for pickup_date. A connection (service_type='connection': arrival flight → connecting departure flight with fast-track between terminals) is billed as TWO M&G services = the location price ×2 (e.g. CDG 2 pax = 500€). For a combo with a transfer (e.g. CDG M&G + transfer to a hotel), call get_quote first for the transfer leg and pass the resulting quote_id + vehicle_id in `transfer`. If lead time is below the minimum (12h before pickup), returns LEAD_TIME_TOO_SHORT — the caller must fall back to manual notification instead of retrying. lead_time_override=true bypasses the 12h minimum ONLY after Sylvain has explicitly confirmed greeter availability for this exact request (WhatsApp admin approval 'mg ok'); never set it on your own initiative. A 90-minute floor always applies. If flight cannot be validated, returns FLIGHT_NOT_FOUND — ask the customer to re-confirm the flight number, or set flight_unverified=true with manual_airline + manual_origin to force-accept.
| Name | Type | Req | Description |
|---|---|---|---|
| additional_info | string | – | Free-text notes (special requests, tail number for private aviation, etc.). |
| adults | integer | yes | Number of adults (min 1). |
| bags | integer | – | Number of bags (used for vehicle sizing when combo transfer). |
| channel | string | – | Caller channel identifier for observability (whatsapp, chatbot, mcp-direct, ...). |
| children | integer | – | Number of children (in addition to adults). |
| string | yes | Client email — used for booking confirmation and Stripe receipt. | |
| first_name | string | yes | Client first name. |
| flight_number | string | yes | Flight number for airports (AF1234) or train/Eurostar number for stations. |
| flight_unverified | boolean | – | Set true only if the client confirmed the flight after AeroDataBox couldn't validate it. Requires manual_airline + manual_origin. |
| idempotency_key | string | – | Optional UUID for safe retries. Same key returns the same payment_url for 24h. |
| last_name | string | yes | Client last name. |
| lead_time_override | boolean | – | Bypass the 12h minimum lead time. ONLY when Sylvain has explicitly approved this exact booking after manually confirming greeter availability ('mg ok' admin flow) — never on client insistence. Hard 9… |
| location | string | yes | M&G location. cdg/orly = airport, gare_de_lyon = train station. Gare du Nord is no longer available. |
| manual_airline | string | – | Required if flight_unverified=true. The airline name as stated by the client. |
| manual_arrival_time | string | – | Optional. Local arrival time as stated by the client. |
| manual_origin | string | – | Required if flight_unverified=true. Departure city as stated by the client. |
| phone | string | yes | Client phone with country code. |
| pickup_date | string | yes | YYYY-MM-DD format. |
| pickup_time | string | yes | HH:MM in Paris time. For arrivals this is the flight/train arrival time; for departures the time the greeter meets the client. |
| service_type | string | – | arrival (pickup at airport/station), departure (drop-off + greeter for check-in), connection (transit: arrival flight → connecting departure flight; billed as 2 M&G services = location price ×2). |
| terminal | string | – | Terminal number (airports only, e.g. '2E', '3'). |
| train_coach | string | – | Train coach number. Required for train stations. |
| train_pnr | string | – | TGV reservation reference (PNR). Required when location is gare_de_lyon. |
| train_seat | string | – | Train seat number(s). Required for train stations. |
| transfer | object | – | Optional combo: bundles a private transfer in the same Stripe Checkout session. Generates 2 line items + 2 Zeplan bookings (M&G + transfer). |
No output schema declared.
No examples provided.
book_ride ~310
Create a secure payment link to book a private chauffeur transfer. The reservation is created automatically ONLY after the customer completes payment. REQUIRED: call get_quote first and pass the resulting quote_id + the chosen vehicle_id. The price is taken from the stored quote (not from any price field you pass). Pass idempotency_key to make retries safe: the same key returns the same payment link instead of creating a duplicate.
| Name | Type | Req | Description |
|---|---|---|---|
| bags | integer | – | Number of bags |
| channel | string | – | Caller channel identifier for observability. If omitted, the channel stored with the quote (from get_quote) is used. |
| flight_number | string | – | Flight number for airport pickups (e.g. AF123) |
| idempotency_key | string | – | Optional agent-generated key (e.g. UUID) to deduplicate retries. Same key + same params returns the same payment link for 24 h. Same key + different params returns an IDEMPOTENCY_CONFLICT error. |
| passenger_email | string | yes | Passenger email for booking confirmation |
| passenger_name | string | yes | Full name of the passenger |
| passenger_phone | string | yes | Passenger phone with country code (e.g. +33612345678) |
| passengers | integer | – | Number of passengers |
| quote_id | string | yes | quote_id returned by get_quote. Must be passed. Expired quote (>15 min) requires a fresh get_quote. |
| vehicle_id | number | yes | Vehicle ID chosen from the get_quote results |
No output schema declared.
No examples provided.
get_cancellation_policy ~39
Get the full cancellation, refund and modification policy. Use this whenever a customer asks about cancelling, changing, or refunds — never guess the policy.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_quote ~319
Calculate the exact price for a private chauffeur transfer. Returns prices for all available vehicles AND a quote_id valid for 15 minutes. Always call this before book_ride and pass the quote_id to book_ride — it locks the price and prevents drift. IMPORTANT: pickup_date must be in dd/mm/yyyy format. COVERAGE GATE: on customer-facing channels a trip where NEITHER the pickup NOR the drop-off is in the Paris region (Paris, Île-de-France, CDG / Orly / Beauvais airports, Disneyland, Versailles) is refused with OUTSIDE_PARIS_REGION — such trips are priced by the team only: give no price, collect the details and escalate.
| Name | Type | Req | Description |
|---|---|---|---|
| channel | string | – | Caller channel identifier for observability: 'chatbot', 'whatsapp', 'claude-desktop', 'email-agent', or your agent name. Defaults to 'mcp-direct'. |
| dropoff_address | string | yes | Full drop-off address |
| form_type | string | – | Booking type |
| num_hours | number | – | Number of hours (required for hourly, min 3) |
| pickup_address | string | yes | Full pickup address (e.g. 'CDG Terminal 2E' or street address) |
| pickup_date | string | yes | Pickup date in dd/mm/yyyy format (e.g. '27/03/2026') |
| pickup_time | string | yes | Pickup time in HH:MM format (e.g. '14:00') |
| step_address | string | – | Intermediate stop address (optional) |
No output schema declared.
No examples provided.
get_service_info ~33
Get information about MyDriverParis services, coverage areas, airports served, and policies. Use this to answer customer questions.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_vehicles ~33
List all available vehicles with capacity and base rates. Use this to help the customer choose the right vehicle for their trip.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
resolve_flight ~239
Resolve a flight number to its airports, terminals, scheduled times, and status. Codeshares are resolved automatically (e.g. DL8742 → operated by Air France as AF9): the response then carries codeshare:true, marketing_flight and operating_flight — record/track the OPERATING flight. Use BEFORE book_ride whenever the customer provides a flight number so that pickup time and terminal are correct. Input is tolerant: accepts 'AF007', 'AF 007', 'AF-007', 'af7', 'AFR007' — the tool normalizes internally. Returns an array of matching operations (usually 1 when direction is set).
| Name | Type | Req | Description |
|---|---|---|---|
| date | string | yes | Date in YYYY-MM-DD (NOT dd/mm/yyyy). This is the arrival date for pickups, departure date for dropoffs. |
| direction | string | – | 'arrival' (default) when picking the passenger up at an airport, 'departure' when dropping off for a flight. |
| flight_number | string | yes | Flight number in any format: 'AF007', 'AF 007', 'af-7', 'AFR007'. Server normalizes. |
No output schema declared.
No examples provided.
resolve_location ~195
Resolve a free-text location (city, airport, hotel, station, full address) to a canonical address + coordinates, using the same geocoder that Zeplan consumes for bookings. Use this BEFORE get_quote when the customer gives a fuzzy pickup/drop-off (e.g. 'CDG', 'Le Bristol', 'Gare du Nord', raw GPS). Returns up to 5 candidates with place_id, full address, type hint, and optionally coordinates.
| Name | Type | Req | Description |
|---|---|---|---|
| include_coords | boolean | – | If true, also fetch GPS coords for the first result (extra API call). Defaults to false — request only when the agent has picked the right candidate. |
| query | string | yes | Free-text location. Examples: 'CDG', 'Charles de Gaulle Terminal 2E', 'Hotel Le Bristol Paris', 'Gare du Nord', '15 rue de la Paix Paris', '48.8566, 2.3522'. |
No output schema declared.
No examples provided.
resolve_train ~219
Resolve a TRAIN NUMBER to its route, stations and scheduled times via the official SNCF API (covers TGV inOui/Ouigo, TER, Intercités, TGV Lyria, Eurostar and international TGVs — everything serving a French station). Use whenever a customer books a station pickup/drop-off or a station Meet & Greet and gives a train number, to verify the departure/arrival time. A train number is DIGITS ONLY (TGV 6503, Lyria 9211, Eurostar 9031); a 6-char code like 'JWVLHH' is a ticket PNR and a long ref like 'W209656898' is an agency booking reference — those cannot be looked up here: extract route + time from the customer's confirmation instead.
| Name | Type | Req | Description |
|---|---|---|---|
| date | string | yes | Travel date in YYYY-MM-DD. |
| train_number | string | yes | Train number, digits only or with prefix: '9211', 'TGV 6503', 'Eurostar 9031'. Server normalizes. |
No output schema declared.
No examples provided.
send_driver_contact ~163
Email the booking's client their assigned driver's first name + phone. Pass `email` if you already have the client's address (e.g. from Zeplan get-booking); otherwise WP looks it up on the booking post. Returns { sent, to (masked), client_phone }. Voice agent use.
| Name | Type | Req | Description |
|---|---|---|---|
| booking_id | string | yes | Booking / reservation ID (= the WP payment post ID). |
| channel | string | – | Caller channel for observability. |
| driver_first_name | string | yes | Driver's FIRST NAME only (never last name/company). |
| driver_phone | string | yes | Driver's phone number. |
| string | – | Client email to send to. If omitted, WP looks it up on the booking post. | |
| lang | string | – | Email language. |
No output schema declared.
No examples provided.
What is the com.mydriverparis/booking MCP server?
com.mydriverparis/booking is an MCP server listed in the public MCP registry as com.mydriverparis/booking. Book a private driver in Paris: live quotes, airport transfers, tours, VIP Meet & Greet. No auth. This page covers its hosted endpoint (https://mcp-mydriverparis.mydriverparis.workers.dev/mcp).
Is the com.mydriverparis/booking MCP server safe to use?
com.mydriverparis/booking scores 78 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the com.mydriverparis/booking MCP server expose?
com.mydriverparis/booking exposes 10 tools: get_vehicles, get_quote, book_ride, book_meetgreet, resolve_location, and 5 more. Their descriptions and schemas cost roughly 2,506 tokens of context every time the server is loaded.
Does the com.mydriverparis/booking MCP server require authentication?
No. We connected to com.mydriverparis/booking without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the com.mydriverparis/booking MCP server still maintained?
com.mydriverparis/booking is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.