# VistaLink Hotels (remote · api.vistalink.com)

Search 650,000 hotels by place, vibe, photos and reviews. Search needs no key.

- Trust score: 80/100 (high trust)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-02

## Components

- remote · `api.vistalink.com`: 80/100 (this document), [markdown](https://verifymcp.io/servers/com-vistalink-hotels/api.md), [page](https://verifymcp.io/servers/com-vistalink-hotels/api)

## Channel facts

- Endpoint: `https://api.vistalink.com/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-02.

- **Endpoint Security**: 97/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
  - The authorisation server supports Client ID Metadata Documents, the current MCP client-registration mechanism.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 77/100
  - 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 1301 tokens (~260/item across 5 items; 3 tools + 2 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 93/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 79% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 3 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 5 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.
  - Supports UI / widget rendering.

**Unverified: 1 category.** A category scored 0 because we could not verify it: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

## Install

### How do I install the VistaLink Hotels MCP server?

VistaLink Hotels is a hosted endpoint at https://api.vistalink.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-vistalink-hotels 'https://api.vistalink.com/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "com-vistalink-hotels": {
      "url": "https://api.vistalink.com/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-vistalink-hotels": {
      "type": "http",
      "url": "https://api.vistalink.com/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-vistalink-hotels]
url = "https://api.vistalink.com/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-vistalink-hotels": {
      "type": "remote",
      "url": "https://api.vistalink.com/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-vistalink-hotels --url 'https://api.vistalink.com/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-vistalink-hotels:
    url: "https://api.vistalink.com/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "com-vistalink-hotels": {
      "Transport": "http",
      "Url": "https://api.vistalink.com/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-vistalink-hotels -t streamable-http -u 'https://api.vistalink.com/mcp'
```

### Other

```json
{
  "mcpServers": {
    "com-vistalink-hotels": {
      "type": "http",
      "url": "https://api.vistalink.com/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-02 (score 80)

First indexed and scored.

## MCP tools (3)

### `search_hotels` (~559 tokens)

Search hotels

Search the VistaLink hotel catalogue in one city (or around a
        point). Needs city, latitude+longitude, or hotel_name; describe the
        stay in vibe. Returns hotels with ratings, location, amenities,
        images and guest-review insights. A price appears only when both
        check_in and check_out are given (the all-inclusive total for that
        stay). Works without an API key (at most 20 results, cached prices
        only). For open-ended questions use chat_about_hotels.

Input parameters:

- `amenities` (string): Comma-separated amenities the hotel must have, e.g. 'wifi,pool'.
- `budget_max` (number): Maximum price per night, in currency (0 = no maximum).
- `budget_min` (number): Minimum price per night, in currency (0 = no minimum).
- `check_in` (string): Check-in date, YYYY-MM-DD (today or later). Prices need check_in and check_out.
- `check_out` (string): Check-out date, YYYY-MM-DD, after check_in.
- `city` (string): City to search in, e.g. 'Lisbon'. A search needs city, latitude+longitude, or hotel_name.
- `country` (string): ISO 3166-1 alpha-2 country code of the city, e.g. 'PT'. Use it for city names that exist in several countries (Paris FR vs Paris US).
- `currency` (string): ISO 4217 currency code for prices, e.g. 'EUR', 'USD', 'GBP'.
- `guests` (integer): Number of adult guests (0 = default of 2).
- `hotel_name` (string): Hotel name or part of it, e.g. 'Four Seasons'.
- `include_rates` (boolean): Fetch live rates for check_in/check_out (adds about 30-45s). Needs an API key and both dates; ignored otherwise.
- `latitude` (number): Search centre latitude in decimal degrees, used with longitude (0 = not set).
- `limit` (integer): Maximum number of results, 1-20 without an API key (1-50 with one). Larger values are reduced to the maximum.
- `longitude` (number): Search centre longitude in decimal degrees, used with latitude (0 = not set).
- `radius_meters` (integer): Radius around latitude/longitude in metres (0 = default).
- `rooms` (integer): Number of rooms (0 = 1). Prices are only quoted for one room.
- `vibe` (string): What the traveller is looking for, as free text or comma-separated tags, e.g. 'boutique design hotel' or 'romantic,quiet'.

### `chat_about_hotels` (~349 tokens)

Chat about hotels

Conversational hotel search for natural-language requests,
        comparisons and subjective preferences. Slower than search_hotels.
        Requires signing in (a linked Parley account) or an API key.

        Guest context (travel style, purpose, accessibility needs, loyalty
        programs, dietary needs) can be passed in the context parameter as a
        JSON object.

        Clarifications: if a previous response included a
        ``clarification_pending`` payload, show the question to the user and
        either pass ``clarification_id`` + ``clarification_option_id`` for the
        chosen option, or pass the user's free-text answer in ``message`` and
        leave the clarification params empty.

        Args:
            message: The user's message or question
            session_id: Session id from a previous response to continue the conversation (empty for a new session)
            currency: Currency code for prices (default EUR)
            context: JSON object with guest context (empty to skip). Example: {"travel_style": "luxury", "purpose": "honeymoon", "accessibility": "wheelchair", "loyalty_programs": ["Marriott Bonvoy"], "dietary": "vegetarian"}
            clarification_id: When replying to a prior clarification, the id from ``clarification_pending.clarification_id`` in that response.
            clarification_option_id: When replying to a prior clarification, the id of the option the user selected.

Input parameters:

- `clarification_id` (string)
- `clarification_option_id` (string)
- `context` (string)
- `currency` (string)
- `message` (string, required)
- `session_id` (string)

### `get_hotel_details` (~218 tokens)

Get hotel details

Full profile of one hotel by its hotel_id from search_hotels:
        description, amenities, images, rooms, guest reviews and guest
        insights. A price is included only when both check_in and check_out
        are given, as the all-inclusive total for that stay. Works without an
        API key (cached prices only).

Input parameters:

- `check_in` (string): Check-in date, YYYY-MM-DD (today or later). Prices need check_in and check_out.
- `check_out` (string): Check-out date, YYYY-MM-DD, after check_in.
- `currency` (string): ISO 4217 currency code for prices, e.g. 'EUR', 'USD', 'GBP'.
- `guests` (integer): Number of adult guests (0 = default of 2).
- `hotel_id` (string, required): The hotel's id (a UUID), as returned in hotel_id by search_hotels.
- `rooms` (integer): Number of rooms (0 = 1). Prices are only quoted for one room.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-vistalink-hotels/api#diagnostics

## Score history

- 2026-10-02: 80

## Common questions

### What is the VistaLink Hotels MCP server?

VistaLink Hotels is an MCP server listed in the public MCP registry as com.vistalink/hotels. Search 650,000 hotels by place, vibe, photos and reviews. Search needs no key. This page covers its hosted endpoint (https://api.vistalink.com/mcp).

### Is the VistaLink Hotels MCP server safe to use?

VistaLink Hotels scores 80 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the VistaLink Hotels MCP server expose?

VistaLink Hotels exposes 3 tools: search_hotels, chat_about_hotels, get_hotel_details. Their descriptions and schemas cost roughly 1,126 tokens of context every time the server is loaded.

### Does the VistaLink Hotels MCP server require authentication?

Yes. VistaLink Hotels asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

### Is the VistaLink Hotels MCP server still maintained?

VistaLink Hotels is still listed as active in the MCP registry. We last reached this channel on 2 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://api.vistalink.com/mcp
- Website: https://vistalink.com/developers
- Changelog RSS feed: https://verifymcp.io/servers/com-vistalink-hotels/api.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-vistalink-hotels/api.json
- HTML version of this page: https://verifymcp.io/servers/com-vistalink-hotels/api
