# io.usefulapi/checkfront (remote · checkfront.usefulapi.io)

Check Checkfront availability and rates, and manage booking sessions, bookings, customers and notes.

- Trust score: 18/100 (low)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-04

## Components

- remote · `checkfront.usefulapi.io`: 18/100 (this document), [markdown](https://verifymcp.io/servers/io-usefulapi-checkfront/checkfront.md), [page](https://verifymcp.io/servers/io-usefulapi-checkfront/checkfront)

## Channel facts

- Endpoint: `https://checkfront.usefulapi.io/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-04.

- **Endpoint Security**: 46/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not yet verified: we couldn't confirm whether this endpoint requires it.
  - HTTPS enforcement could not be verified: the plaintext port answered with HTTP 429, which proves neither a plaintext path nor enforcement.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 0/100
  - Transport blocked by authentication: the endpoint requires auth we don't have to verify streamable-http.
- **Schema Quality & AI Usability**: 0/100
  - Schema not yet verified: we couldn't read the endpoint's schema, or could read only part of its tool list.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 0/100
  - Tool coverage not yet verified: we couldn't read the endpoint's tools, or could read only part of the list.
- **Tool Safety**: 0/100
  - Tool safety not yet verified: we couldn't read the endpoint's tools, or could read only part of the list.
- **Capabilities**: 0/100
  - Capabilities not yet verified: we couldn't read the endpoint's capabilities.

**Unverified: 6 categories.** Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

## Install

### How do I install the io.usefulapi/checkfront MCP server?

io.usefulapi/checkfront is a hosted endpoint at https://checkfront.usefulapi.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http io-usefulapi-checkfront 'https://checkfront.usefulapi.io/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "io-usefulapi-checkfront": {
      "url": "https://checkfront.usefulapi.io/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "io-usefulapi-checkfront": {
      "type": "http",
      "url": "https://checkfront.usefulapi.io/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.io-usefulapi-checkfront]
url = "https://checkfront.usefulapi.io/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "io-usefulapi-checkfront": {
      "type": "remote",
      "url": "https://checkfront.usefulapi.io/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add io-usefulapi-checkfront --url 'https://checkfront.usefulapi.io/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  io-usefulapi-checkfront:
    url: "https://checkfront.usefulapi.io/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "io-usefulapi-checkfront": {
      "Transport": "http",
      "Url": "https://checkfront.usefulapi.io/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add io-usefulapi-checkfront -t streamable-http -u 'https://checkfront.usefulapi.io/mcp'
```

### Other

```json
{
  "mcpServers": {
    "io-usefulapi-checkfront": {
      "type": "http",
      "url": "https://checkfront.usefulapi.io/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-04 (score 18, −10)

- [security regression] Transport: pass → unverified

### 2026-10-03 (score 28, +10)

- [security improvement] Transport: fail → pass

### 2026-10-01 (score 18, −54)

- [security regression] Endpoint reachability: reachable → not serving MCP
- [security regression] Tool safety: pass → unverified
- [security regression] Authorization: pass → unverified
- [security regression] Transport: pass → fail
- [functional regression] Capabilities: fail → unverified
- [functional regression] Tool coverage: 100 → unverified

### 2026-09-30 (score 72, +54)

- [security improvement] Authorization: unverified → pass
- [security improvement] Injection markers: unverified → pass
- [security improvement] Transport: fail → pass
- [security] First check of Judged manipulation: pass
- [functional regression] MCP protocol: unverified → fail
- [functional improvement] Tool coverage: unverified → 100
- [functional] First check of Schema quality: fail
- [functional] First check of Schema quality: excellent
- [functional] First check of Destructive annotations: pass
- [functional] First check of Schema quality: fail
- [functional] First check of Tool coverage: 100

### 2026-09-29 (score 18)

First indexed and scored.

## MCP tools (20)

### `checkfront_get_company` (~59 tokens)

Get company settings

Fetch the connected Checkfront account's company configuration — name, URL, plan, currency, timezone, locale and date/time formats. A cheap way to confirm the host and credentials work. Checkfront: GET /api/3.0/company.

### `checkfront_list_categories` (~50 tokens)

List item categories

List the inventory categories (e.g. Tours, Rentals, Accommodations) with their ids, names, display order and item counts. Checkfront: GET /api/3.0/category.

### `checkfront_list_items` (~393 tokens)

List inventory items (optionally with availability and rates)

List the enabled inventory items (tours, activities, rentals, rooms). With NO dates this is the plain catalogue. Pass start_date (and end_date / param quantities) to get a RATED response: per-item availability, pricing and a SLIP token — the SLIP is what checkfront_add_to_booking_session needs to book the item. Checkfront: GET /api/3.0/item.

Input parameters:

- `available` (integer): (rated) Only items with at least this many left in stock.
- `category_id` (integer): Only items in this category.
- `date` (string): (rated) Alias of start_date for same-day bookings — YYYYMMDD, YYYY-MM-DD, or a relative date such as "today".
- `discount_code` (string): (rated) Discount code to apply to the price.
- `end_date` (string): (rated) Booking end date — YYYYMMDD, YYYY-MM-DD, or a relative date such as "today".
- `end_time` (string): (rated) End time, for hourly bookings.
- `item_id` (string): Comma-separated list of item ids to filter to, e.g. 17,18.
- `keyword` (string): Only items whose name contains this keyword.
- `packages` (boolean): Include package options.
- `param` (object): Booking parameters (quantities) keyed by the parameter ids configured in your account, e.g. {"adults": 2, "children": 1}. Sent as param[adults]=2.
- `rules` (string): 'soft' avoids date-based rule errors; 'off' disables rule checking.
- `start_date` (string): (rated) Booking start date — YYYYMMDD, YYYY-MM-DD, or a relative date such as "today".
- `start_time` (string): (rated) Start time, for hourly bookings.

### `checkfront_get_item` (~328 tokens)

Get an item (optionally with availability and rates)

Fetch one inventory item's details. Pass start_date / end_date and param quantities (e.g. {"adults": 2}) for a RATED response with availability (rate.status, rate.available), the price breakdown and the SLIP used to book it. For parent/child grouped items, rate the CHILD item. Checkfront: GET /api/3.0/item/{item_id}.

Input parameters:

- `date` (string): (rated) Alias of start_date for same-day bookings — YYYYMMDD, YYYY-MM-DD, or a relative date such as "today".
- `discount_code` (string): (rated) Discount code to apply to the price.
- `end_date` (string): (rated) Booking end date — YYYYMMDD, YYYY-MM-DD, or a relative date such as "today".
- `end_time` (string): (rated) End time, for hourly bookings.
- `item_id` (integer, required): The item id.
- `packages` (boolean): Include package options.
- `param` (object): Booking parameters (quantities) keyed by the parameter ids configured in your account, e.g. {"adults": 2, "children": 1}. Sent as param[adults]=2.
- `rules` (string): 'soft' avoids date-based rule errors; 'off' disables rule checking.
- `start_date` (string): (rated) Booking start date — YYYYMMDD, YYYY-MM-DD, or a relative date such as "today".
- `start_time` (string): (rated) Start time, for hourly bookings.

### `checkfront_get_availability_calendar` (~177 tokens)

Get an availability calendar

Day-by-day available inventory over a date range — for one item (item_ids with a single id), several items, or a whole category. Use it to answer 'which days next month still have space?'. Checkfront: GET /api/3.0/item/{item_id}/cal or GET /api/3.0/item/cal.

Input parameters:

- `category_id` (integer): Instead of item ids, a category of items.
- `end_date` (string): Range end date — YYYYMMDD, YYYY-MM-DD, or a relative date such as "today".
- `item_ids` (array): Item ids. One id queries that item's calendar; several query them together.
- `start_date` (string): Range start date — YYYYMMDD, YYYY-MM-DD, or a relative date such as "today".

### `checkfront_list_bookings` (~396 tokens)

List bookings

List bookings, newest filters first — by status, customer, dates, item or partner. Each row has the booking code, status, totals (total, tax_total, paid_total), customer name/email, summary and date_desc. Paged (default 100/page); the response's request.pages tells you how many pages exist. Checkfront: GET /api/3.0/booking/index.

Input parameters:

- `created_date` (string): Date the booking was created. A date string or unix timestamp; prefix with '<' or '>' for before/after (e.g. ">2026-01-01").
- `customer_email` (string): Only bookings for this customer email.
- `customer_id` (integer): Only bookings for this customer id.
- `end_date` (string): Booking end (check-out) date. A date string or unix timestamp; prefix with '<' or '>' for before/after (e.g. ">2026-01-01").
- `item_id` (integer): Only bookings containing this item.
- `last_modified` (string): Date the booking last changed — useful for 'changed since' syncs. A date string or unix timestamp; prefix with '<' or '>' for before/after (e.g. ">2026-01-01").
- `limit` (integer): Bookings per page, 1-100 (default 100).
- `page` (integer): Page number, starting at 1.
- `partner_id` (string): Only bookings attributed to this partner account.
- `start_date` (string): Booking start (check-in) date. A date string or unix timestamp; prefix with '<' or '>' for before/after (e.g. ">2026-01-01").
- `status_id` (string): Booking status code, e.g. PEND, HOLD, PART, PAID, WAIT, STOP, VOID.

### `checkfront_get_booking` (~70 tokens)

Get a booking

Fetch extended information on one booking — status, dates, customer, form fields, line items and totals. Checkfront: GET /api/3.0/booking/{booking_id}.

Input parameters:

- `booking_id` (string, required): The booking code identifying the booking, e.g. CFPP-290317.

### `checkfront_list_booking_notes` (~101 tokens)

List booking notes

List the notes left on bookings across the account (default: the past 30 days), each with its booking code, author account id (0 = customer), date, body and whether it is private. Checkfront: GET /api/3.0/booking/notes.

Input parameters:

- `date` (string): Filter by a day (YYYY-MM-DD or ISO-8601) or a whole month (e.g. "2026-09").

### `checkfront_get_booking_form` (~77 tokens)

Get the booking form fields

Fetch the customer-details form for a booking (booking_form_ui): every field id (customer_name, customer_email, …), its label, type and whether it is required. Call this before checkfront_create_booking to know which `form` fields to send. Checkfront: GET /api/3.0/booking/form.

### `checkfront_get_booking_session` (~79 tokens)

Get a booking session (cart)

Read a booking session — the in-progress 'cart' — with its line items (keyed by line_id), dates, sub_total, tax, total and amount due. Checkfront: GET /api/3.0/booking/session.

Input parameters:

- `session_id` (string, required): The session_id returned by checkfront_add_to_booking_session.

### `checkfront_search_customers` (~104 tokens)

Search customers

Look up customers by exact email, full name or phone number (exact matches; non-unique fields such as name can return several). Results are in the `customers` object. Checkfront: GET /api/3.0/customer.

Input parameters:

- `customer_email` (string): Exact customer email address.
- `customer_id` (string): Customer code/id.
- `customer_name` (string): Exact full name.
- `customer_phone` (string): Exact phone number.

### `checkfront_get_customer` (~60 tokens)

Get a customer

Fetch one customer's contact details and their bookings (codes with created dates). Checkfront: GET /api/3.0/customer/{customer_id}.

Input parameters:

- `customer_id` (string, required): The customer id (e.g. 25) or customer code.

### `checkfront_list_events` (~68 tokens)

List events (seasons, specials, closures, discounts)

List the date-based events that change price or availability — seasonal rates (SE), specials (SP), discounts (DC), closures (status U) — with their dates, recurrence, pricing rule and the items/categories they apply to. Checkfront: GET /api/3.0/event.

### `checkfront_list_staff_accounts` (~63 tokens)

List staff accounts

List the staff (and partner) accounts on the Checkfront account — ids, names, emails, login ids and whether enabled. The account_id is what CHECKFRONT_ON_BEHALF takes. Checkfront: GET /api/3.0/account.

### `checkfront_add_to_booking_session` (~242 tokens)

Add items to a booking session (cart)

Start or modify a booking session: add one or more SLIPs (from a rated checkfront_get_item / checkfront_list_items call), replace a line with a new SLIP (line_id + slip), or alter lines (quantity, 'remove', 'optin'/'optout' for package add-ons). Holds the inventory while the session is open; NOTHING is booked until checkfront_create_booking. Returns the session_id to reuse. Checkfront: POST /api/3.0/booking/session.

Input parameters:

- `alter` (object): Changes keyed by line_id, e.g. {"3": 5, "2.1": "optin", "1": "remove"} (a number sets the quantity).
- `line_id` (string): With a single slip: the session line to REPLACE with it (to change a regular item's options).
- `session_id` (string): Existing session to modify. Omit to start a new session.
- `slip` (array): One or more SLIP strings to add, e.g. ["18.20171005X1-adults.1-children.0"].

### `checkfront_end_booking_session` (~101 tokens)

End or clear a booking session

Abandon a booking session: 'clear' empties its items, 'end' closes it. Releases the inventory it was holding; no booking is affected. Checkfront: POST /api/3.0/booking/session/clear or /booking/session/end.

Input parameters:

- `action` (string): 'end' (default) closes the session; 'clear' empties it.
- `session_id` (string, required): The session to clear or end.

### `checkfront_create_booking` (~179 tokens)

Create a booking

Commit a booking: from a session_id (built with checkfront_add_to_booking_session) or directly from SLIPs, plus the customer form fields (see checkfront_get_booking_form for which are required — typically customer_name and customer_email). Creates a real reservation that consumes inventory and may notify the customer; change it later with checkfront_update_booking_status. Returns the new booking's ids and any invoice/payment URL. Checkfront: POST /api/3.0/booking/create.

Input parameters:

- `form` (object, required): Customer form fields, e.g. {"customer_name": "John Smith", "customer_email": "john@example.com"}. Sent as form[customer_name]=….
- `session_id` (string): The session holding the items to book.
- `slip` (array): Instead of a session: SLIP strings to book directly.

### `checkfront_update_booking_status` (~176 tokens)

Change a booking's status

Set a booking's status — e.g. confirm a pending booking (PAID/PART), put it on HOLD or WAIT(list), or cancel it (VOID/STOP). Reversible: set it back to the previous status the same way. Does NOT record a payment. Optionally triggers the account's customer notifications. Checkfront: POST /api/3.0/booking/{booking_id}/update.

Input parameters:

- `booking_id` (string, required): The booking code identifying the booking, e.g. CFPP-290317.
- `notify` (boolean): Send the account's notifications for this change (default false).
- `status_id` (string, required): The new status code. Defaults: PEND, HOLD, PART, PAID, WAIT, STOP, VOID (plus any custom statuses in Manage > Layout > Statuses).

### `checkfront_add_booking_note` (~88 tokens)

Add a note to a booking

Add a note to a booking, logged under the staff account the API acts on behalf of. Checkfront: POST /api/3.0/booking/{booking_id}/note.

Input parameters:

- `body` (string, required): The note text, up to 3000 characters.
- `booking_id` (string, required): The booking code identifying the booking, e.g. CFPP-290317.

### `checkfront_check_in_booking` (~109 tokens)

Check a booking in or out

Mark a guest as arrived (check in) or departed (check out). Checkfront adds a note under the acting account. VOID and cancelled bookings cannot be checked in or out. Checkfront: POST /api/3.0/booking/{booking_id}/checkin or /checkout.

Input parameters:

- `action` (string): 'checkin' (default) or 'checkout'.
- `booking_id` (string, required): The booking code identifying the booking, e.g. CFPP-290317.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/io-usefulapi-checkfront/checkfront#diagnostics

## Score history

- 2026-10-04: 18
- 2026-10-03: 28
- 2026-10-02: 18
- 2026-10-01: 18
- 2026-09-30: 72
- 2026-09-29: 18

## Common questions

### What is the io.usefulapi/checkfront MCP server?

io.usefulapi/checkfront is an MCP server listed in the public MCP registry as io.usefulapi/checkfront. Check Checkfront availability and rates, and manage booking sessions, bookings, customers and notes. This page covers its hosted endpoint (https://checkfront.usefulapi.io/mcp).

### Is the io.usefulapi/checkfront MCP server safe to use?

io.usefulapi/checkfront scores 18 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the io.usefulapi/checkfront MCP server expose?

io.usefulapi/checkfront exposes 20 tools: checkfront_get_company, checkfront_list_categories, checkfront_list_items, checkfront_get_item, checkfront_get_availability_calendar, and 15 more. Their descriptions and schemas cost roughly 2,920 tokens of context every time the server is loaded.

### Does the io.usefulapi/checkfront MCP server require authentication?

Its publisher declares no required credentials for io.usefulapi/checkfront. We have not been able to confirm that against the live endpoint, and a server can require authorisation without declaring it here.

### Is the io.usefulapi/checkfront MCP server still maintained?

io.usefulapi/checkfront is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://checkfront.usefulapi.io/mcp
- Repository: https://github.com/m190/usefulapi-mcp
- Changelog RSS feed: https://verifymcp.io/servers/io-usefulapi-checkfront/checkfront.xml
- Changelog JSON feed: https://verifymcp.io/servers/io-usefulapi-checkfront/checkfront.json
- HTML version of this page: https://verifymcp.io/servers/io-usefulapi-checkfront/checkfront
