io.usefulapi/hostaway
REMOTE · HOSTAWAY.USEFULAPI.IO · SCANNED OCT 4
Manage Hostaway listings, reservations, calendar, guest messages, reviews and tasks.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security89
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability68
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 4096 tokens (~204/item across 20 items; 20 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management7
- Stability observed for 2 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 20 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
How do I install the io.usefulapi/hostaway MCP server?
io.usefulapi/hostaway is a hosted endpoint at https://hostaway.usefulapi.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · hostaway.usefulapi.io
claude mcp add --transport http io-usefulapi-hostaway 'https://hostaway.usefulapi.io/mcp'
{
"mcpServers": {
"io-usefulapi-hostaway": {
"url": "https://hostaway.usefulapi.io/mcp"
}
}
} {
"servers": {
"io-usefulapi-hostaway": {
"type": "http",
"url": "https://hostaway.usefulapi.io/mcp"
}
}
} [mcp_servers.io-usefulapi-hostaway] url = "https://hostaway.usefulapi.io/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"io-usefulapi-hostaway": {
"type": "remote",
"url": "https://hostaway.usefulapi.io/mcp",
"enabled": true
}
}
} openclaw mcp add io-usefulapi-hostaway --url 'https://hostaway.usefulapi.io/mcp' --transport streamable-http
mcp_servers:
io-usefulapi-hostaway:
url: "https://hostaway.usefulapi.io/mcp" {
"McpServers": {
"io-usefulapi-hostaway": {
"Transport": "http",
"Url": "https://hostaway.usefulapi.io/mcp"
}
}
} assistant mcp add io-usefulapi-hostaway -t streamable-http -u 'https://hostaway.usefulapi.io/mcp'
{
"mcpServers": {
"io-usefulapi-hostaway": {
"type": "http",
"url": "https://hostaway.usefulapi.io/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Oct 26 +1
- Stability: unverified → 0.03 ▲ functional
- 2 Oct 26 +46
- HTTPS: unverified → pass ▲ security
- Authorization: unverified → pass ▲ security
- Injection markers: unverified → pass ▲ security
- First check of Authorization: partial security
- First check of Judged manipulation: pass security
- MCP protocol: unverified → fail ▼ functional
- Tool coverage: unverified → 100 ▲ functional
- First check of Schema quality: fail functional
- First check of Schema quality: excellent functional
- First check of Schema quality: fail functional
- First check of Destructive annotations: 100 functional
- First check of Tool coverage: 100 functional
- 1 Oct 26 0
- Tool safety: Tool safety not yet verified: we couldn't read the endpoint's tools, or could read only part of the list. security
- Authorization: Authorisation not yet verified: we couldn't confirm whether this endpoint requires it. security
- Tool coverage: Tool coverage not yet verified: we couldn't read the endpoint's tools, or could read only part of the list. functional
- Capabilities: Capabilities not yet verified: we couldn't read the endpoint's capabilities. functional
- Schema quality: Schema not yet verified: we couldn't read the endpoint's schema, or could read only part of its tool list. functional
- 30 Sept 26 +10
- Transport: fail → pass ▲ security
- Authorization: Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the whole tool list to see what that exposes. security
- Tool safety: Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools. security
- Tool coverage: Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools. functional
- Schema quality: Schema blocked by authentication: the endpoint requires auth we don't have to read it. functional
- Capabilities: Capabilities blocked by authentication: the endpoint requires auth we don't have to read them. functional
- 29 Sept 26 18
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 4 Oct 2026 · Probed https://hostaway.usefulapi.io/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=usefulapi.io | CN=WE1,O=Google Trust Services,C=US | 13 Sept 2026 | 12 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | d9be3287b0fde9630e825ba1f79bff3f |
| SANs: usefulapi.io, *.usefulapi.io | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of hostaway.usefulapi.io. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| io. | present | 57355 | 8 | Verified |
| usefulapi.io. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer realm="OAuth", resource_metadata="https://hostaway.usefulapi.io/.well-known/oauth-protected-resource/mcp"
Bearer realm="OAuth", resource_metadata="https://hostaway.usefulapi.io/.well-known/oauth-protected-resource/mcp" Protected resource metadata
| Document | https://hostaway.usefulapi.io/.well-known/oauth-protected-resource/mcp |
|---|---|
| Retrieved | Yes |
| Resource | https://hostaway.usefulapi.io/mcp |
| Authorisation server | https://hostaway.usefulapi.io |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://hostaway.usefulapi.io/mcp | Verified | 200 | |
| http (plaintext) | http://hostaway.usefulapi.io/mcp | HTTPS enforced | 301 | https://hostaway.usefulapi.io/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
hostaway_calculate_price Quote a stay ~153
Calculate what a stay at a listing would cost — total price plus the component breakdown (base rate, cleaning fee, taxes, discounts). A calculation only: nothing is booked or held. Hostaway: POST /v1/listings/{listingId}/calendar/priceDetails (version 2).
| Name | Type | Req | Description |
|---|---|---|---|
| endingDate | string | yes | Departure date (YYYY-MM-DD). |
| listingId | integer | yes | Listing id. |
| markup | number | – | Price markup multiplier (must be more than 1.0). |
| numberOfGuests | integer | yes | Number of guests. |
| reservationCouponId | integer | – | Reservation coupon id to apply. |
| startingDate | string | yes | Arrival date (YYYY-MM-DD). |
No output schema declared.
No examples provided.
hostaway_create_reservation Create a reservation ~473
Create a new reservation on a listing (it blocks the calendar and syncs to connected channels). Only channelId 2000 (direct, the default), 2002 (homeaway) or 2020 (partner) are accepted. To price it correctly, call hostaway_calculate_price first and pass its total as totalPrice. Overbooking protection is always left on. Hostaway: POST /v1/reservations.
| Name | Type | Req | Description |
|---|---|---|---|
| adults | integer | – | Adults. |
| arrivalDate | string | yes | Arrival date (YYYY-MM-DD). |
| channelId | – | – | 2000 direct (default), 2002 homeaway, 2020 partner. |
| checkInTime | integer | – | Check-in time (hour of day, 0-23). |
| checkOutTime | integer | – | Check-out time (hour of day, 0-23). |
| children | integer | – | Children. |
| comment | string | – | Free-text comment. |
| currency | string | – | Currency code, e.g. USD. |
| departureDate | string | yes | Departure date (YYYY-MM-DD). |
| doorCode | string | – | Door / lock code for this stay. |
| doorCodeInstruction | string | – | Door-code instructions. |
| doorCodeVendor | string | – | Lock vendor. |
| guestAddress | string | – | Guest street address. |
| guestCity | string | – | Guest city. |
| guestCountry | string | – | Guest country (ISO 3166 code, e.g. US). |
| guestEmail | string | – | Guest email. |
| guestFirstName | string | – | Guest first name. |
| guestLastName | string | – | Guest last name. |
| guestName | string | – | Guest full name. |
| guestNote | string | – | Note from the guest. |
| guestZipCode | string | – | Guest ZIP / postal code. |
| hostNote | string | – | Internal host note (not shown to the guest). |
| infants | integer | – | Infants. |
| listingMapId | integer | yes | Listing id to book. |
| numberOfGuests | integer | – | Total number of guests. |
| pets | integer | – | Pets. |
| phone | string | – | Guest phone, e.g. +15125551212. |
| totalPrice | number | – | Total price of the stay. |
No output schema declared.
No examples provided.
hostaway_create_task Create a task ~293
Create an operational task — e.g. a cleaning after a checkout or a maintenance job — optionally tied to a listing and reservation, assigned to a user, with a time window, category and cost. Hostaway: POST /v1/tasks.
| Name | Type | Req | Description |
|---|---|---|---|
| assigneeUserId | integer | – | User id to assign the task to. |
| canStartFrom | string | – | Earliest start time ("YYYY-MM-DD HH:MM:SS", UTC). |
| categoriesMap | array | – | Categories: 1 cleaning, 2 maintenance, 3 check-in, 4 check-out, 5 back office, 6 other. |
| color | string | – | Colour in hex, e.g. #FF8800. |
| cost | number | – | Task cost. |
| costCurrency | string | – | Cost currency, e.g. USD. |
| costDescription | string | – | Cost description. |
| description | string | – | Task description. |
| listingMapId | integer | – | Listing id the task belongs to. |
| priority | integer | – | Priority. |
| reservationId | integer | – | Reservation id the task relates to. |
| shouldEndBy | string | – | Deadline ("YYYY-MM-DD HH:MM:SS", UTC). |
| status | string | – | pending, confirmed, inProgress, completed or cancelled. |
| supervisorUserId | integer | – | Supervisor user id. |
| title | string | yes | Task title. |
No output schema declared.
No examples provided.
hostaway_get_calendar Get listing calendar ~135
Day-by-day availability and pricing for one listing over a date range: status (available, blocked, reserved, pending), nightly price, min/max stay, closed-to-arrival/departure and notes. Set includeResources to see the reservations occupying each day. Hostaway: GET /v1/listings/{listingId}/calendar.
| Name | Type | Req | Description |
|---|---|---|---|
| endDate | string | yes | Last day (YYYY-MM-DD). |
| includeResources | boolean | – | Include attached sub-resources (sent as includeResources=1). |
| listingId | integer | yes | Listing id. |
| startDate | string | yes | First day (YYYY-MM-DD). |
No output schema declared.
No examples provided.
hostaway_get_listing Get one listing ~87
Fetch a single listing by id — full details including description, house rules, amenities, images, fees, taxes, cancellation policy and access info (door code, wifi). Hostaway: GET /v1/listings/{listingId}.
| Name | Type | Req | Description |
|---|---|---|---|
| includeResources | boolean | – | Include attached sub-resources (sent as includeResources=1). |
| listingId | integer | yes | Listing id. |
No output schema declared.
No examples provided.
hostaway_get_owner_statement Get one owner statement ~76
Fetch one owner statement — the filter it was generated with (listings, date range), summary and per-reservation financial data, grand totals, expenses, and owner / property-manager details. Hostaway: GET /v1/ownerStatement/{ownerStatementId}.
| Name | Type | Req | Description |
|---|---|---|---|
| ownerStatementId | integer | yes | Owner statement id. |
No output schema declared.
No examples provided.
hostaway_get_reservation Get one reservation ~72
Fetch a single reservation by its Hostaway id — guest contact details, dates, guest counts, price breakdown, payment state, door code, notes, channel and cancellation policy. Hostaway: GET /v1/reservations/{reservationId}.
| Name | Type | Req | Description |
|---|---|---|---|
| reservationId | integer | yes | Hostaway reservation id. |
No output schema declared.
No examples provided.
hostaway_get_reservation_logs Get reservation change history ~107
The audit trail for one reservation: every field change with previous and new value, when, and by which user (most recent first). Useful for 'who changed these dates / this price?'. Hostaway: GET /v1/reservations/{reservationId}/logs.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Maximum records to return (1-500). |
| offset | integer | – | Records to skip from the start. |
| reservationId | integer | yes | Hostaway reservation id. |
No output schema declared.
No examples provided.
hostaway_list_conversation_messages Read a conversation ~127
The messages in one guest conversation — body, direction (isIncoming), channel/email/SMS type, send status and timestamps. By default only sent messages; set includeScheduledMessages to also see scheduled, paused or failed ones. Hostaway: GET /v1/conversations/{conversationId}/messages.
| Name | Type | Req | Description |
|---|---|---|---|
| conversationId | integer | yes | Conversation id. |
| includeScheduledMessages | boolean | – | Also return scheduled / failed / paused messages. |
| limit | integer | – | Maximum records to return (1-500). |
| offset | integer | – | Records to skip from the start. |
No output schema declared.
No examples provided.
hostaway_list_conversations List guest conversations ~106
List guest conversations (the unified inbox across channels), each with its latest message and linked reservation. Filter to one reservation. Hostaway: GET /v1/conversations.
| Name | Type | Req | Description |
|---|---|---|---|
| includeResources | boolean | – | Include attached sub-resources (sent as includeResources=1). |
| limit | integer | – | Maximum records to return (1-500). |
| offset | integer | – | Records to skip from the start. |
| reservationId | integer | – | Only conversations for this reservation. |
No output schema declared.
No examples provided.
hostaway_list_expenses List expenses and extras ~81
List expenses (negative amounts) and extras (positive amounts) recorded against listings and reservations, with date, concept, categories and the owner statements they appear on. Hostaway: GET /v1/expenses.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Maximum records to return (1-500). |
| offset | integer | – | Records to skip from the start. |
No output schema declared.
No examples provided.
hostaway_list_listings List listings ~238
List the account's properties (listings) with name, address, capacity, base price, fees and check-in times. Filter by name, city, country, property type, availability for a date range and guest count, or active/archived status. Hostaway: GET /v1/listings.
| Name | Type | Req | Description |
|---|---|---|---|
| availabilityDateEnd | string | – | Only listings available until (YYYY-MM-DD). |
| availabilityDateStart | string | – | Only listings available from (YYYY-MM-DD). |
| availabilityGuestNumber | integer | – | Only listings that fit this many guests. |
| city | string | – | City. |
| country | string | – | Country. |
| includeResources | boolean | – | Include attached sub-resources (sent as includeResources=1). |
| limit | integer | – | Maximum records to return (1-500). |
| match | string | – | Search by listing name. |
| offset | integer | – | Records to skip from the start. |
| propertyTypeId | integer | – | Property type id. |
| sortOrder | string | – | Sort order. |
| specialStatus | array | – | Filter by status; omit for both active and archived. |
No output schema declared.
No examples provided.
hostaway_list_owner_statements List owner statements ~34
List the account's owner statements (id and name). Hostaway: GET /v1/ownerStatements.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
hostaway_list_reservations List reservations ~531
List reservations across all channels (Airbnb, Vrbo, Booking.com, direct…) with guest, dates, status, price and channel. Filter by listing, channel, arrival/departure window, guest name or email, unread messages, and more. Default order is newest first; for large accounts page with afterId (the id of the last reservation on the previous page). Channel ids: 2000 direct, 2018 airbnbOfficial, 2002 homeaway/Vrbo, 2005 bookingcom, 2007 expedia, 2013 bookingengine, 2019 marriott, 2020 partner, 2022 google. Hostaway: GET /v1/reservations.
| Name | Type | Req | Description |
|---|---|---|---|
| afterId | integer | – | Cursor: the id of the last reservation from the previous page (offset is then ignored). |
| arrivalEndDate | string | – | Arrival on or before (YYYY-MM-DD). |
| arrivalStartDate | string | – | Arrival on or after (YYYY-MM-DD). |
| assigneeUserId | integer | – | Only reservations assigned to this user. |
| channelId | integer | – | Only this channel id. |
| dateType | string | – | Which date startDate/endDate bound (only on accounts with the new reservations query; 'cancellation' also restricts to cancelled). |
| departureEndDate | string | – | Departure on or before (YYYY-MM-DD). |
| departureStartDate | string | – | Departure on or after (YYYY-MM-DD). |
| endDate | string | – | Upper bound for dateType (YYYY-MM-DD). |
| guestEmail | string | – | Filter by guest email. |
| hasUnreadConversationMessages | boolean | – | Only reservations with unread guest messages. |
| includeCancellationPolicy | boolean | – | Attach the cancellation-policy snapshot to each reservation. |
| includeResources | boolean | – | Include attached sub-resources (sent as includeResources=1). |
| isArchived | boolean | – | Archived or not. |
| isStarred | boolean | – | Only starred. |
| latestActivityEnd | string | – | Latest activity on or before (YYYY-MM-DD). |
| latestActivityStart | string | – | Latest activity on or after (YYYY-MM-DD). |
| limit | integer | – | Maximum records to return (1-500). |
| listingId | integer | – | Only reservations for this listing. |
| match | string | – | Search by guest name. |
| offset | integer | – | Records to skip from the start. |
| sortOrder | string | – | Sort order. |
| startDate | string | – | Lower bound for dateType (YYYY-MM-DD). |
No output schema declared.
No examples provided.
hostaway_list_reviews List reviews ~303
List guest-to-host and host-to-guest reviews with rating (0-10), public review, private feedback and the host's reply. Filter by listings, reservation, type, status, rating range, dates, guest name, or whether the host has replied. Hostaway: GET /v1/reviews.
| Name | Type | Req | Description |
|---|---|---|---|
| departureDateEnd | string | – | Reservation departure on or before (YYYY-MM-DD). |
| departureDateStart | string | – | Reservation departure on or after (YYYY-MM-DD). |
| guestName | string | – | Partial, case-insensitive guest-name match. |
| hasHostReply | boolean | – | true = only replied-to reviews; false = only unanswered. |
| limit | integer | – | Maximum records to return (1-500). |
| listingMapIds | array | – | Only reviews for these listing ids. |
| offset | integer | – | Records to skip from the start. |
| ratingMax | number | – | Maximum rating (0-10). |
| ratingMin | number | – | Minimum rating (0-10). |
| reservationId | integer | – | Hostaway reservation id. |
| sortBy | string | – | Sort field. |
| sortOrder | string | – | Sort direction (default desc). |
| statuses | array | – | Review statuses. |
| submittedAtEnd | string | – | Submitted on or before (YYYY-MM-DD). |
| submittedAtStart | string | – | Submitted on or after (YYYY-MM-DD). |
| type | string | – | Review direction. |
No output schema declared.
No examples provided.
hostaway_list_tasks List tasks ~196
List operational tasks (cleaning, maintenance, check-in/out) with assignee, status, time window and cost. Filter by reservation, status, text match, channel, or start/deadline windows. Hostaway: GET /v1/tasks.
| Name | Type | Req | Description |
|---|---|---|---|
| canStartFromEnd | string | – | Start window until (YYYY-MM-DD). |
| canStartFromStart | string | – | Start window from (YYYY-MM-DD). |
| channelId | integer | – | Channel id. |
| limit | integer | – | Maximum records to return (1-500). |
| match | string | – | Text search. |
| offset | integer | – | Records to skip from the start. |
| reservationId | integer | – | Only tasks for this reservation. |
| shouldEndByEnd | string | – | Deadline until (YYYY-MM-DD). |
| shouldEndByStart | string | – | Deadline from (YYYY-MM-DD). |
| status | string | – | Task status. |
No output schema declared.
No examples provided.
hostaway_send_message Send a guest message ~122
Send a message to the guest in a conversation — it is delivered immediately and cannot be recalled. Delivered by email by default, or via the booking channel, SMS or WhatsApp. Attachments are not supported. Rate-limited by Hostaway to 30 messages per minute. Hostaway: POST /v1/conversations/{conversationId}/messages.
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | yes | Message text. |
| communicationType | string | – | Delivery method (Hostaway default: email). |
| conversationId | integer | yes | Conversation id (see hostaway_list_conversations). |
No output schema declared.
No examples provided.
hostaway_update_calendar Update listing calendar ~237
Change availability and/or pricing for a date range on one listing, pushed to every connected channel: block (isAvailable=false) or open days, set the nightly price, min/max stay, closed-to-arrival/departure, or a note. For multi-unit listings set desiredUnitsToSell instead of isAvailable (0 blocks). Hostaway: PUT /v1/listings/{listingId}/calendar.
| Name | Type | Req | Description |
|---|---|---|---|
| closedOnArrival | boolean | – | Closed to arrival. |
| closedOnDeparture | boolean | – | Closed to departure. |
| desiredUnitsToSell | integer | – | Multi-unit listings: units to sell (0 blocks). |
| endDate | string | yes | Last day to change (YYYY-MM-DD). |
| isAvailable | boolean | – | false blocks the days, true opens them (single-unit listings). |
| listingId | integer | yes | Listing id. |
| maximumStay | integer | – | Maximum nights. |
| minimumStay | integer | – | Minimum nights. |
| note | string | – | Calendar note. |
| price | number | – | Nightly price. |
| startDate | string | yes | First day to change (YYYY-MM-DD). |
No output schema declared.
No examples provided.
hostaway_update_reservation Update a reservation ~415
Change fields on an existing reservation — guest details and counts, dates, check-in/out hours, door code, host note or comment. Send only the fields to change. The listing cannot be changed, and this tool never cancels or reprices a booking. Date changes on channel bookings may be overwritten by the channel. Hostaway: PUT /v1/reservations/{reservationId}.
| Name | Type | Req | Description |
|---|---|---|---|
| adults | integer | – | Adults. |
| arrivalDate | string | – | New arrival date (YYYY-MM-DD). |
| checkInTime | integer | – | Check-in time (hour of day, 0-23). |
| checkOutTime | integer | – | Check-out time (hour of day, 0-23). |
| children | integer | – | Children. |
| comment | string | – | Free-text comment. |
| departureDate | string | – | New departure date (YYYY-MM-DD). |
| doorCode | string | – | Door / lock code for this stay. |
| doorCodeInstruction | string | – | Door-code instructions. |
| doorCodeVendor | string | – | Lock vendor. |
| guestAddress | string | – | Guest street address. |
| guestCity | string | – | Guest city. |
| guestCountry | string | – | Guest country (ISO 3166 code, e.g. US). |
| guestEmail | string | – | Guest email. |
| guestFirstName | string | – | Guest first name. |
| guestLastName | string | – | Guest last name. |
| guestName | string | – | Guest full name. |
| guestNote | string | – | Note from the guest. |
| guestZipCode | string | – | Guest ZIP / postal code. |
| hostNote | string | – | Internal host note (not shown to the guest). |
| infants | integer | – | Infants. |
| numberOfGuests | integer | – | Total number of guests. |
| pets | integer | – | Pets. |
| phone | string | – | Guest phone, e.g. +15125551212. |
| reservationId | integer | yes | Hostaway reservation id. |
No output schema declared.
No examples provided.
hostaway_update_task Update a task ~310
Update a task — change its status (e.g. completed), reassign it, move its window, or add a resolution note. Send only the fields to change. Hostaway: PUT /v1/tasks/{taskId}.
| Name | Type | Req | Description |
|---|---|---|---|
| assigneeUserId | integer | – | User id to assign the task to. |
| canStartFrom | string | – | Earliest start time ("YYYY-MM-DD HH:MM:SS", UTC). |
| categoriesMap | array | – | Categories: 1 cleaning, 2 maintenance, 3 check-in, 4 check-out, 5 back office, 6 other. |
| color | string | – | Colour in hex, e.g. #FF8800. |
| cost | number | – | Task cost. |
| costCurrency | string | – | Cost currency, e.g. USD. |
| costDescription | string | – | Cost description. |
| description | string | – | Task description. |
| listingMapId | integer | – | Listing id the task belongs to. |
| priority | integer | – | Priority. |
| reservationId | integer | – | Reservation id the task relates to. |
| resolutionNote | string | – | Resolution note. |
| shouldEndBy | string | – | Deadline ("YYYY-MM-DD HH:MM:SS", UTC). |
| status | string | – | pending, confirmed, inProgress, completed or cancelled. |
| supervisorUserId | integer | – | Supervisor user id. |
| taskId | integer | yes | Task id. |
| title | string | – | Task title. |
No output schema declared.
No examples provided.
What is the io.usefulapi/hostaway MCP server?
io.usefulapi/hostaway is an MCP server listed in the public MCP registry as io.usefulapi/hostaway. Manage Hostaway listings, reservations, calendar, guest messages, reviews and tasks. This page covers its hosted endpoint (https://hostaway.usefulapi.io/mcp).
Is the io.usefulapi/hostaway MCP server safe to use?
io.usefulapi/hostaway scores 75 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.usefulapi/hostaway MCP server expose?
io.usefulapi/hostaway exposes 20 tools: hostaway_list_listings, hostaway_get_listing, hostaway_list_reservations, hostaway_get_reservation, hostaway_get_reservation_logs, and 15 more. Their descriptions and schemas cost roughly 4,096 tokens of context every time the server is loaded.
Does the io.usefulapi/hostaway MCP server require authentication?
Yes. io.usefulapi/hostaway asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the io.usefulapi/hostaway MCP server still maintained?
io.usefulapi/hostaway is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.