io.usefulapi/booqable
REMOTE · BOOQABLE.USEFULAPI.IO · SCANNED OCT 3
Browse rental orders, customers, products and availability, and create bookings in Booqable.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security89
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability68
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 3563 tokens (~169/item across 21 items; 21 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management10
- Stability observed for 3 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 21 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 21 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
How do I install the io.usefulapi/booqable MCP server?
io.usefulapi/booqable is a hosted endpoint at https://booqable.usefulapi.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · booqable.usefulapi.io
claude mcp add --transport http io-usefulapi-booqable 'https://booqable.usefulapi.io/mcp'
{
"mcpServers": {
"io-usefulapi-booqable": {
"url": "https://booqable.usefulapi.io/mcp"
}
}
} {
"servers": {
"io-usefulapi-booqable": {
"type": "http",
"url": "https://booqable.usefulapi.io/mcp"
}
}
} [mcp_servers.io-usefulapi-booqable] url = "https://booqable.usefulapi.io/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"io-usefulapi-booqable": {
"type": "remote",
"url": "https://booqable.usefulapi.io/mcp",
"enabled": true
}
}
} openclaw mcp add io-usefulapi-booqable --url 'https://booqable.usefulapi.io/mcp' --transport streamable-http
mcp_servers:
io-usefulapi-booqable:
url: "https://booqable.usefulapi.io/mcp" {
"McpServers": {
"io-usefulapi-booqable": {
"Transport": "http",
"Url": "https://booqable.usefulapi.io/mcp"
}
}
} assistant mcp add io-usefulapi-booqable -t streamable-http -u 'https://booqable.usefulapi.io/mcp'
{
"mcpServers": {
"io-usefulapi-booqable": {
"type": "http",
"url": "https://booqable.usefulapi.io/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Oct 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 2 Oct 26 0
- Server version: 1.3.0 → 1.5.1 functional
- 1 Oct 26 +5
- HTTPS: unverified → pass ▲ security
- Stability: unverified → 0.03 ▲ functional
- Server version: 1.0.0 → 1.3.0 functional
- 30 Sept 26 +42
- Authorization: unverified → pass ▲ security
- Injection markers: unverified → pass ▲ security
- First check of Judged manipulation: pass security
- First check of Authorization: partial security
- MCP protocol: unverified → fail ▼ functional
- Tool coverage: unverified → 100 ▲ functional
- First check of Schema quality: fail functional
- First check of Schema quality: excellent functional
- First check of Destructive annotations: pass functional
- First check of Schema quality: fail functional
- First check of Tool coverage: 100 functional
- 29 Sept 26 28
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Oct 2026 · Probed https://booqable.usefulapi.io/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=usefulapi.io | CN=WE1,O=Google Trust Services,C=US | 13 Sept 2026 | 12 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | d9be3287b0fde9630e825ba1f79bff3f |
| SANs: usefulapi.io, *.usefulapi.io | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of booqable.usefulapi.io. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| io. | present | 57355 | 8 | Verified |
| usefulapi.io. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer realm="OAuth", resource_metadata="https://booqable.usefulapi.io/.well-known/oauth-protected-resource/mcp"
Bearer realm="OAuth", resource_metadata="https://booqable.usefulapi.io/.well-known/oauth-protected-resource/mcp" Protected resource metadata
| Document | https://booqable.usefulapi.io/.well-known/oauth-protected-resource/mcp |
|---|---|
| Retrieved | Yes |
| Resource | https://booqable.usefulapi.io/mcp |
| Authorisation server | https://booqable.usefulapi.io |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://booqable.usefulapi.io/mcp | Verified | 200 | |
| http (plaintext) | http://booqable.usefulapi.io/mcp | HTTPS enforced | 301 | https://booqable.usefulapi.io/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
booqable_book_product Book a product on an order ~176
Add a quantity of a product to an order, allocating inventory (creates a planning and a line). By default adds to an existing planning for the same product if there is one. Booqable: POST /api/4/order_fulfillments with a book_product action.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm_shortage | boolean | – | true to accept a shortage warning when booking on a reserved or started order. |
| mode | string | – | infer_planning (default): reuse the product's planning if any; create_new: always a new line; update_existing: add to planning_id. |
| order_id | string | yes | The order id (UUID). |
| planning_id | string | – | Required when mode is update_existing. |
| product_id | string | yes | The product id (UUID). |
| quantity | integer | yes | Units to book. |
No output schema declared.
No examples provided.
booqable_check_inventory_availability Check inventory availability ~213
How many units of one or more products can be booked for an exact period at a location. Returns `available` and `plannable` (plannable can exceed available when shortage is allowed). Get location ids from booqable_list_locations. Booqable: GET /api/4/inventory_availabilities.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | yes | Period start, ISO 8601 at the company's local time written as UTC, e.g. 2026-07-01T10:00:00Z means 10:00 at the shop. Do not convert to real UTC. |
| location_id | string | yes | The pickup location id. |
| product_ids | array | yes | Product ids to check. |
| till | string | yes | Period end, ISO 8601 at the company's local time written as UTC, e.g. 2026-07-01T10:00:00Z means 10:00 at the shop. Do not convert to real UTC. |
No output schema declared.
No examples provided.
booqable_create_customer Create a customer ~111
Create a new customer. Booqable: POST /api/4/customers.
| Name | Type | Req | Description |
|---|---|---|---|
| discount_percentage | number | – | Default discount % applied to this customer's new orders. |
| string | – | Email address used for communication. | |
| email_marketing_consented | boolean | – | Whether the customer consented to email marketing. |
| legal_type | string | – | person or commercial. |
| name | string | yes | Person or company name. |
| tag_list | array | – | Tags (case-insensitive). |
No output schema declared.
No examples provided.
booqable_create_note Add a note ~77
Attach an internal note to a customer, order, product or other record. Booqable: POST /api/4/notes.
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | yes | The note text. |
| owner_id | string | yes | The id of the record the note is about. |
| owner_type | string | yes | The owner's resource type. |
No output schema declared.
No examples provided.
booqable_create_order Create an order ~252
Create an EMPTY order for a rental period (status new or draft). Then add products with booqable_book_product and reserve it with booqable_transition_order_status. Locations default to the first active location. Booqable: POST /api/4/orders.
| Name | Type | Req | Description |
|---|---|---|---|
| customer_id | string | – | The customer this order is for. |
| start_location_id | string | – | Pickup location id. |
| starts_at | string | yes | Rental start, ISO 8601 at the company's local time written as UTC, e.g. 2026-07-01T10:00:00Z means 10:00 at the shop. Do not convert to real UTC. |
| status | string | – | Initial status. Default new (visible only to its creator); draft is visible but reserves nothing. |
| stop_location_id | string | – | Return location id. |
| stops_at | string | yes | Rental end, ISO 8601 at the company's local time written as UTC, e.g. 2026-07-01T10:00:00Z means 10:00 at the shop. Do not convert to real UTC. |
| tag_list | array | – | Tags (case-insensitive). |
No output schema declared.
No examples provided.
booqable_get_availability_calendar Get a product's availability calendar ~129
Day-by-day availability for one product over a month: status (available/partial/unavailable) and bookable quantity per day. Booqable: GET /api/4/availabilities with subject_type=item.
| Name | Type | Req | Description |
|---|---|---|---|
| location_id | string | – | Location id to check at. |
| month | integer | yes | Calendar month, 1-12. |
| product_id | string | yes | The product id (UUID). |
| quantity | integer | – | Units needed; sets the threshold for available vs partial. |
| year | integer | yes | Calendar year, e.g. 2026. |
No output schema declared.
No examples provided.
booqable_get_company Get the company ~55
Fetch the Booqable account this token belongs to — name, currency, default timezone, address. A cheap way to confirm the slug and token work. Booqable: GET /api/4/companies/current.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
booqable_get_customer Get one customer ~88
Fetch one customer with order count, revenue and balance due, sideloading their properties (addresses, phone, custom fields) by default. Booqable: GET /api/4/customers/{id}.
| Name | Type | Req | Description |
|---|---|---|---|
| customer_id | string | yes | The customer id (UUID). |
| include | string | – | Comma-separated relationships to sideload, e.g. properties,tax_region. |
No output schema declared.
No examples provided.
booqable_get_order Get one order ~108
Fetch one order with its totals, deposit and payment state, sideloading the customer and order lines by default (override with include, e.g. customer,lines,payments,documents,notes). Booqable: GET /api/4/orders/{id}.
| Name | Type | Req | Description |
|---|---|---|---|
| include | string | – | Comma-separated relationships to sideload, e.g. customer,lines,payments,documents,notes,start_location. |
| order_id | string | yes | The order id (UUID). |
No output schema declared.
No examples provided.
booqable_list_customers List customers ~179
List customers, optionally searched by name/email or filtered by email, tag or archived state. Booqable: GET /api/4/customers.
| Name | Type | Req | Description |
|---|---|---|---|
| archived | boolean | – | true = only archived, false = only active. |
| string | – | Only the customer with exactly this email. | |
| include | string | – | Comma-separated relationships to sideload, e.g. properties. |
| page | integer | – | Page number (1-based). Default 1. |
| page_size | integer | – | Results per page, 1-100 (Booqable default 25). |
| q | string | – | Free-text search over customers. |
| sort | string | – | Sort, comma-separated attributes; prefix with - for descending, e.g. -created_at. |
| tag | string | – | Only customers carrying this tag. |
No output schema declared.
No examples provided.
booqable_list_documents List documents ~197
List invoices, quotes and contracts, with totals and payment status. Filter by type, order, customer or status. Booqable: GET /api/4/documents.
| Name | Type | Req | Description |
|---|---|---|---|
| customer_id | string | – | Only documents for this customer. |
| document_type | string | – | Only this document type. |
| include | string | – | Comma-separated relationships to sideload, e.g. customer,order. |
| order_id | string | – | Only documents for this order. |
| page | integer | – | Page number (1-based). Default 1. |
| page_size | integer | – | Results per page, 1-100 (Booqable default 25). |
| q | string | – | Free-text search. |
| sort | string | – | Sort, comma-separated attributes; prefix with - for descending, e.g. -created_at. |
| status | string | – | Only documents in this status (values depend on document type). |
No output schema declared.
No examples provided.
booqable_list_locations List locations ~107
List pickup/return locations (warehouses, stores) with address and pickup/delivery capability. Location ids are needed for availability checks and orders. Booqable: GET /api/4/locations.
| Name | Type | Req | Description |
|---|---|---|---|
| archived | boolean | – | true = only archived, false = only active. |
| page | integer | – | Page number (1-based). Default 1. |
| page_size | integer | – | Results per page, 1-100 (Booqable default 25). |
No output schema declared.
No examples provided.
booqable_list_notes List notes ~106
List internal notes attached to a customer, order, product or other record. Booqable: GET /api/4/notes.
| Name | Type | Req | Description |
|---|---|---|---|
| owner_id | string | yes | The id of the record the notes are about. |
| owner_type | string | – | The owner's resource type. |
| page | integer | – | Page number (1-based). Default 1. |
| page_size | integer | – | Results per page, 1-100 (Booqable default 25). |
No output schema declared.
No examples provided.
booqable_list_orders List orders ~313
List rental orders. Filter by free-text search (order number, customer name/email/address, tags, custom fields), status, payment status, customer, or rental-period range. Booqable: GET /api/4/orders.
| Name | Type | Req | Description |
|---|---|---|---|
| customer_id | string | – | Only orders for this customer id. |
| include | string | – | Comma-separated relationships to sideload, e.g. customer,start_location,stop_location. |
| page | integer | – | Page number (1-based). Default 1. |
| page_size | integer | – | Results per page, 1-100 (Booqable default 25). |
| payment_status | string | – | Only orders with this payment status. |
| q | string | – | Search: order number (exact), customer name, e-mail, address, tags, custom field values. |
| sort | string | – | Sort, comma-separated attributes; prefix with - for descending, e.g. -created_at. |
| starts_at_gte | string | – | Rental starts at or after this datetime (ISO 8601). |
| starts_at_lte | string | – | Rental starts at or before this datetime (ISO 8601). |
| status | string | – | Only orders with this simplified status. |
| stops_at_gte | string | – | Rental ends at or after this datetime (ISO 8601). |
| stops_at_lte | string | – | Rental ends at or before this datetime (ISO 8601). |
| tag | string | – | Only orders carrying this tag. |
No output schema declared.
No examples provided.
booqable_list_payments List payments ~186
List payments (charges, authorizations and refunds) with amount, deposit, currency, provider and status. Filter by order, customer or payment type. Read only — this server never moves money. Booqable: GET /api/4/payments.
| Name | Type | Req | Description |
|---|---|---|---|
| customer_id | string | – | Only payments for this customer. |
| include | string | – | Comma-separated relationships to sideload, e.g. order,payment_method. |
| order_id | string | – | Only payments for this order. |
| page | integer | – | Page number (1-based). Default 1. |
| page_size | integer | – | Results per page, 1-100 (Booqable default 25). |
| sort | string | – | Sort, comma-separated attributes; prefix with - for descending, e.g. -created_at. |
| type | string | – | Only this payment type. |
No output schema declared.
No examples provided.
booqable_list_plannings List plannings ~278
List plannings — which product is booked on which order, how many, when, and how many are started (out) or stopped (returned). Filter by order, product, or reservation window. Booqable: GET /api/4/plannings.
| Name | Type | Req | Description |
|---|---|---|---|
| include | string | – | Comma-separated relationships to sideload, e.g. item,order,order.customer. |
| order_id | string | – | Only plannings on this order. |
| page | integer | – | Page number (1-based). Default 1. |
| page_size | integer | – | Results per page, 1-100 (Booqable default 25). |
| product_id | string | – | Only plannings for this product or bundle (item_id). |
| sort | string | – | Sort, comma-separated attributes; prefix with - for descending, e.g. -created_at. |
| starts_at_gte | string | – | Planned start at or after this datetime (ISO 8601). |
| starts_at_lte | string | – | Planned start at or before this datetime (ISO 8601). |
| stops_at_gte | string | – | Planned end at or after this datetime (ISO 8601). |
| stops_at_lte | string | – | Planned end at or before this datetime (ISO 8601). |
No output schema declared.
No examples provided.
booqable_list_product_groups List product groups ~196
List product groups — the catalogue entries (name, SKU, product type, tracking type, pricing). A group holds one or more bookable products (variations). Booqable: GET /api/4/product_groups.
| Name | Type | Req | Description |
|---|---|---|---|
| archived | boolean | – | true = only archived, false = only active. |
| include | string | – | Comma-separated relationships to sideload, e.g. products,photo. |
| page | integer | – | Page number (1-based). Default 1. |
| page_size | integer | – | Results per page, 1-100 (Booqable default 25). |
| product_type | string | – | Only this product type. |
| q | string | – | Free-text search over name/SKU. |
| sort | string | – | Sort, comma-separated attributes; prefix with - for descending, e.g. -created_at. |
| tag | string | – | Only groups carrying this tag. |
No output schema declared.
No examples provided.
booqable_list_products List products ~186
List bookable products (the variations inside product groups). Use a product id for availability checks and booking. Booqable: GET /api/4/products.
| Name | Type | Req | Description |
|---|---|---|---|
| archived | boolean | – | true = only archived, false = only active. |
| include | string | – | Comma-separated relationships to sideload, e.g. product_group,photo. |
| page | integer | – | Page number (1-based). Default 1. |
| page_size | integer | – | Results per page, 1-100 (Booqable default 25). |
| product_group_id | string | – | Only products in this product group. |
| product_type | string | – | Only this product type. |
| q | string | – | Free-text search over name/SKU. |
| sort | string | – | Sort, comma-separated attributes; prefix with - for descending, e.g. -created_at. |
No output schema declared.
No examples provided.
booqable_transition_order_status Change an order's status ~187
Move an order between statuses: new→draft, draft→reserved (reserves the items and assigns an order number), stopped→archived, or back to an earlier status with revert: true. Canceling is deliberately NOT offered (Booqable cannot un-cancel). started/stopped are reached by picking up/returning items, so they are only valid here with revert: true. Booqable: POST /api/4/order_status_transitions.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm_shortage | boolean | – | true to accept a shortage warning when reserving. |
| order_id | string | yes | The order id (UUID). |
| revert | boolean | – | true when going back to an earlier status (required for started/stopped). |
| transition_from | string | yes | The order's CURRENT status (Booqable checks it). |
| transition_to | string | yes | The new status. |
No output schema declared.
No examples provided.
booqable_update_customer Update a customer ~146
Update a customer's name, email, legal type, tags, default discount or marketing consent. Only the fields you pass change. Booqable: PUT /api/4/customers/{id}.
| Name | Type | Req | Description |
|---|---|---|---|
| customer_id | string | yes | The customer id (UUID). |
| discount_percentage | number | – | Default discount % applied to this customer's new orders. |
| string | – | Email address used for communication. | |
| email_marketing_consented | boolean | – | Whether the customer consented to email marketing. |
| legal_type | string | – | person or commercial. |
| name | string | – | Person or company name. |
| tag_list | array | – | Tags (case-insensitive). |
No output schema declared.
No examples provided.
booqable_update_order Update an order ~273
Change an order's rental period, customer, locations or tags. Moving dates can cause a shortage: the call then fails with the shortage details, and a shortage *warning* can be accepted by retrying with confirm_shortage: true. Booqable: PUT /api/4/orders/{id}.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm_shortage | boolean | – | true to proceed despite a shortage warning. |
| customer_id | string | – | Assign this customer (re-applies their discount, deposit and tax region). |
| order_id | string | yes | The order id (UUID). |
| start_location_id | string | – | Pickup location id. |
| starts_at | string | – | New rental start, ISO 8601 at the company's local time written as UTC, e.g. 2026-07-01T10:00:00Z means 10:00 at the shop. Do not convert to real UTC. |
| stop_location_id | string | – | Return location id. |
| stops_at | string | – | New rental end, ISO 8601 at the company's local time written as UTC, e.g. 2026-07-01T10:00:00Z means 10:00 at the shop. Do not convert to real UTC. |
| tag_list | array | – | Replace the tag list. |
No output schema declared.
No examples provided.
What is the io.usefulapi/booqable MCP server?
io.usefulapi/booqable is an MCP server listed in the public MCP registry as io.usefulapi/booqable. Browse rental orders, customers, products and availability, and create bookings in Booqable. This page covers its hosted endpoint (https://booqable.usefulapi.io/mcp).
Is the io.usefulapi/booqable MCP server safe to use?
io.usefulapi/booqable scores 76 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.usefulapi/booqable MCP server expose?
io.usefulapi/booqable exposes 21 tools: booqable_get_company, booqable_list_orders, booqable_get_order, booqable_list_customers, booqable_get_customer, and 16 more. Their descriptions and schemas cost roughly 3,563 tokens of context every time the server is loaded.
Does the io.usefulapi/booqable MCP server require authentication?
Yes. io.usefulapi/booqable asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the io.usefulapi/booqable MCP server still maintained?
io.usefulapi/booqable is still listed as active in the MCP registry. We last reached this channel on 3 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.