Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

PriceWin

REMOTE · MCP.PRICE.WIN · SCANNED OCT 9

Live hotel and flight prices compared across Booking.com, Agoda, Trip.com and Traveloka, in USD.

Available components

58 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security46
Transport & Reachability100
Schema Quality & AI Usability50
  • 0% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Fail
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 3180 tokens (~117/item across 27 items; 12 tools + 15 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management20
  • Stability observed for 6 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (92% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 13 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
  • Supports UI / widget rendering.Pass
Install

How do I install the PriceWin MCP server?

PriceWin is a hosted endpoint at https://mcp.price.win/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mcp.price.win

# add to Claude Code
claude mcp add --transport http win-price-pricewin 'https://mcp.price.win/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "win-price-pricewin": {
      "url": "https://mcp.price.win/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "win-price-pricewin": {
      "type": "http",
      "url": "https://mcp.price.win/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.win-price-pricewin]
url = "https://mcp.price.win/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "win-price-pricewin": {
      "type": "remote",
      "url": "https://mcp.price.win/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add win-price-pricewin --url 'https://mcp.price.win/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  win-price-pricewin:
    url: "https://mcp.price.win/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "win-price-pricewin": {
      "Transport": "http",
      "Url": "https://mcp.price.win/mcp"
    }
  }
}
# add to Vellum
assistant mcp add win-price-pricewin -t streamable-http -u 'https://mcp.price.win/mcp'
// mcp.json
{
  "mcpServers": {
    "win-price-pricewin": {
      "type": "http",
      "url": "https://mcp.price.win/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 9 Oct 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 10 to 20. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

  • 6 Oct 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 3 to 10. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

  • 4 Oct 26 +1
    • Stability: unverified → 0.03 ▲ functional
  • 3 Oct 26 55

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 9 Oct 2026 · Probed https://mcp.price.win/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=price.win CN=YE2,O=Let's Encrypt,C=US 21 Aug 2026 19 Nov 2026 ECDSA 256 ECDSA-SHA384 69f74b7ee9ffce5da8d5940627c9193516c
SANs: *.price.win, price.win
CN=YE2,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 4df3b15dd6c0784c507cd37b58e6f115
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of mcp.price.win. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
win. present 29737 8 Verified
price.win. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.price.win/mcp Verified 200
http (plaintext) http://mcp.price.win/mcp Inconclusive 406
MCP tools · 12 exposed · ~2,961 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
cancel_booking ~136

Second of two steps to cancel a booking: cancels it and starts any refund due. Irreversible. Requires the confirmation code and the single-use token that request_cancel_token emailed to the guest; a missing, expired or already-used token is rejected. get_cancellation_policy shows the refund terms that apply.

NameTypeReqDescription
cancelTokenstringyesSingle-use cancellation token from the email request_cancel_token sent to the guest.
confirmationCodestringyes8-char booking confirmation code, e.g. K7X9M2P4
reasonstringyesGuest-provided cancellation reason (at least 3 characters)
NameTypeReqDescription
gatewaySettlementEtastring|nullyes–
refundAmountnumberyes–
refundStatusstring|nullyes–
statusstringyes–

No examples provided.

check_booking_status ~72

Returns the current status of a booking request (waiting for the hotel, confirmed or cancelled) by the confirmation code request_booking returned.

NameTypeReqDescription
confirmationCodestringyesconfirmationCode from request_booking structuredContent (e.g. 'K7X9M2P4')
languagestring–Response language
NameTypeReqDescription
bookingIdstringyes–
checkInstringyes–
checkOutstringyes–
confirmationCodestring|nullyes–
guestEmailstringyes–
guestNamestringyes–
paidAtstring|nullyes–
paymentLinkUrlstring|nullyes–
paymentMethodstring|nullyes–
paymentStatusstringyes–
propertyNamestringyes–
roomNumberstring|nullyes–
statusstringyes–

No examples provided.

get_cancellation_policy ~179

Returns the cancellation terms for one rate plan at an OpenTravel partner hotel: whether it is refundable, the free-cancellation window, the refund percentage, a plain-language summary and, given the check-in date, the exact free-cancellation deadline. Takes the propertyId and the ratePlanId from get_hotel_detail.

NameTypeReqDescription
checkInDatestringyesCheck-in date YYYY-MM-DD — required to compute the exact free-cancel deadline
languagestring–Reply language. Falls back to queryText, then English.
propertyIdstringyesOpenTravel propertyId UUID from search results
queryTextstring–Short excerpt of the guest's request, used only to pick the reply language.
ratePlanIdstringyesratePlanId from get_hotel_detail roomTypes[].ratePlanId
NameTypeReqDescription
computedDeadlinestring|nullyes–
freeCancelUntilHoursnumber|nullyes–
nonRefundablebooleanyes–
policyTextstringyes–
ratePlanIdstringyes–
refundPercentAfterWindownumber|nullyes–

No examples provided.

get_hotel_detail ~275

Prices and availability for one OpenTravel direct-listed hotel over a date range, with its photos, amenities and room types, each room with its rate plan and total price. Takes the propertyId from search results (source 'OPENTRAVEL_DIRECT'), or a hotel name plus city for a known direct listing. get_hotel_info returns the same hotel's static facts without dates.

NameTypeReqDescription
adultsinteger–Number of adults (default 2)
checkInstringyesCheck-in date YYYY-MM-DD. Must be today or later.
checkOutstringyesCheck-out date YYYY-MM-DD. Must be after checkIn.
childreninteger–Number of children (default 0)
citystring–City of the hotel — required when resolving by hotelName.
hotelNamestring–Fallback name for a confirmed OpenTravel direct listing when propertyId is unavailable
languagestring–Preferred UI language (en/vi/de/ja/ko/zh/fr/es/ru/th/id).
propertyIdstring–OpenTravel propertyId UUID from search results (opentravelResults[].propertyId).
queryTextstring–Optional short excerpt of the current request, used only to detect the UI language; it is not stored or forwarded.
NameTypeReqDescription
adultsnumberyes–
bookingUrlstring––
checkInstringyes–
checkOutstringyes–
discoveryboolean––
languagestringyes–
nightsnumberyes–
propertyobjectyes–
roomTypesarrayyes–

No examples provided.

get_hotel_info ~183

Static facts about an OpenTravel direct-listed hotel, with no check-in or check-out date required: photo gallery, property description, address, facilities (parking, pool, pets and so on), check-in and check-out times, the house cancellation policy, and each room type's description, floor area, capacity, photos and in-room facilities. Carries no prices and no availability — get_hotel_detail covers those for a specific date range. Takes the propertyId UUID from search results.

NameTypeReqDescription
languagestring–Preferred reply language (en/vi/de/ja/ko/zh).
propertyIdstringyesOpenTravel propertyId UUID from search results (opentravelResults[].propertyId).
queryTextstring–Optional short excerpt of the current request, used only to detect the reply language; it is not stored or forwarded.
NameTypeReqDescription
cancellationPolicyobject––
propertyobjectyes–
roomTypesarrayyes–

No examples provided.

get_ota_hotel_detail ~365

Full detail (rooms, live prices, facilities, photos, reviews) from Booking.com for one named hotel over a date range, for requests about a single hotel rather than a whole city (search_hotels_live lists a city). The name is resolved through the city's listings, so it takes the hotel name together with its city; a Booking.com URL from an earlier result skips that lookup. OpenTravel direct listings are covered by get_hotel_detail. The fetch is live and takes up to about two minutes; under heavy load it can return not-found.

NameTypeReqDescription
adultsinteger–Number of adults (default 2)
checkInstringyesCheck-in date YYYY-MM-DD. Must be today or later.
checkOutstringyesCheck-out date YYYY-MM-DD. Must be after checkIn.
citystring–City of the hotel, used to resolve the name, e.g. 'Da Nang'. Required with hotelName.
hotelNamestring–Name of the hotel, e.g. 'Mercure Danang French Village Bana Hills'. Required unless propertyUrl is given.
languagestring–Optional UI language. Indonesian (id) cannot be detected from text, so for Indonesian this is how the language is set.
propertyUrlstring–Booking.com property URL from an earlier result (hotel.prices.booking.url); skips the name lookup.
queryTextstring–Short excerpt (one sentence at most) of the guest's latest message in their own words, used only to detect the reply language; it is not stored or forwarded. It carries no names, contact details or o…
roomsinteger–Number of rooms (default 1)

No output schema declared.

No examples provided.

poll_flight_results ~82

Returns the current results of a flight search session started by search_flights_live: outbound and return options with airline, flight number, times, stops, fare and booking link. Results can be partial while the search runs; status reads 'completed' or 'failed' when it ends.

NameTypeReqDescription
sessionIdstringyesSession ID from search_flights_live
NameTypeReqDescription
adultsnumberyes–
cabinstringyes–
cachedbooleanyes–
departureDatestringyes–
destinationstringyes–
languagestring––
originstringyes–
outboundFlightsarrayyes–
returnDatestring––
returnFlightsarrayyes–
sessionIdstringyes–
statusstringyes–
totalOutboundnumberyes–
totalReturnnumberyes–
tripTypestringyes–

No examples provided.

poll_search_results ~229

Returns the current results of a hotel search session started by search_hotels_live: hotels with their price from each source, and OpenTravel direct listings with the propertyId that get_hotel_detail and get_hotel_info take. Results can be partial while the search runs; status reads 'completed' once every source has answered.

NameTypeReqDescription
areastring–Optional override for the area filter captured at search time
hotelNamestring–Optional override for the hotel-name filter captured at search time
limitinteger–Max hotels to return; 0 = all (default 50)
nightsintegeryesNumber of nights
offsetinteger–Skip first N hotels for pagination (default 0)
priceCurrencystring–ISO 4217 code of priceMin/priceMax; defaults to the UI language's currency
priceMaxnumber–Optional override for the maximum-price filter
priceMinnumber–Optional override for the minimum-price filter
sessionIdstringyesSession ID from search_hotels_live
NameTypeReqDescription
agodaStatusstringyes–
bookingStatusstringyes–
cachedboolean––
checkInstringyes–
checkOutstringyes–
citystringyes–
fxRatesobjectyes–
hasMorebooleanyes–
hotelsarrayyes–
languagestring––
limitnumberyes–
longStayNoticestring|null––
nightsnumberyes–
offsetnumberyes–
opentravelIndicativeResultsarrayyes–
opentravelResultsarrayyes–
opentravelStatusstringyes–
progressnumberyes–
sessionIdstring––
statusstringyes–
tierstringyes–
tier2AgodaStatusstring|nullyes–
tier2BookingStatusstring|nullyes–
tier2TravelokaStatusstring|nullyes–
totalHotelsnumberyes–
travelokaStatusstringyes–

No examples provided.

request_booking ~563

Sends a booking request for a room at an OpenTravel partner hotel. Nothing is charged and no room is held: the hotel confirms the request by email, and the guest pays at the property on arrival. There is no payment step, now or later. Takes the room and rate from get_hotel_detail and the guest's name, phone number and email; when any of these is missing, the result asks for it and, in clients that show widgets, opens a form for it. A few properties require payment at booking time, and the result says so for those. One request covers several rooms of the same room type (roomCount), with adults and children counted across all of them; each call is a separate request with its own code, so rooms of one type booked call by call reach the hotel as unrelated requests. Returns one confirmation code for the whole request.

NameTypeReqDescription
adultsintegeryesNumber of adults across ALL rooms of the request — at least one per room
checkInstringyesCheck-in date YYYY-MM-DD. Must be today or later.
checkOutstringyesCheck-out date YYYY-MM-DD. Must be after checkIn.
childreninteger–Number of children across ALL rooms of the request (default 0)
currencystringyesCurrency of totalAmount, as quoted by get_hotel_detail for the chosen room.
guestEmailstring–Email address the confirmation is sent to, as the guest gave it; it cannot be changed after the request is sent. When omitted, the result asks the user for it.
guestNamestring–Full name of the primary guest. When omitted, the result asks the user for it.
guestPhonestring–Guest phone number; the hotel calls it to confirm the request. When omitted, the result asks the user for it.
languagestring–Optional response language hint. Only used when queryText gives no signal.
propertyIdstringyesOpenTravel propertyId from get_hotel_detail
queryTextstring–Short excerpt (one sentence at most) of the guest's latest message in their own words, used only to detect the reply language; it is not stored or forwarded. It carries no names, contact details or o…
roomCountinteger–How many rooms of this room type the guest wants (default 1). All of them go in this one request, under one confirmation code.
roomTypeIdstringyesroomTypeId from get_hotel_detail roomTypes array
totalAmountnumberyesTotal amount for ALL rooms in the property's base currency: the room's price for the stay × roomCount
NameTypeReqDescription
assignedRoomIdstring|nullyes–
bookingIdstringyes–
confirmationCodestringyes–
nextStepstringyes–
paymentRequiredbooleanyes–
quotedAmountnumberyes–
quotedCurrencystringyes–
roomCountnumberyes–
statusstringyes–

No examples provided.

request_cancel_token ~116

First of two steps to cancel a booking. Emails a single-use cancellation token to the address on the booking, given its confirmation code and that same email address. Nothing is cancelled, charged or refunded by this step. The token expires after 24 hours and works once; cancel_booking completes the cancellation with it.

NameTypeReqDescription
confirmationCodestringyes8-char booking confirmation code, e.g. K7X9M2P4
guestEmailstringyesGuest email address — must match the booking primary guest email
NameTypeReqDescription
messagestringyes–
successbooleanyes–

No examples provided.

search_flights_live ~293

Starts a live flight search for a route and date, one-way or return. Fares come from Agoda, Trip.com, Traveloka and Google Flights. Origin and destination are 3-letter IATA airport codes (for example SGN, HAN, DAD). Returns a session ID; poll_flight_results returns the results. When the route or date is missing, the result is a question for the user instead of a search.

NameTypeReqDescription
adultsinteger–Number of adults (default 1)
cabinstring–Cabin class (default economy)
departureDatestring–Departure date YYYY-MM-DD, today or later. When omitted, the result asks the user for it.
destinationstring–Arrival airport IATA code, e.g. 'HAN'. When omitted, the result asks the user for it.
languagestring–Preferred UI language (en/vi/de/ja/ko/zh/fr/es/ru/th/id).
originstring–Departure airport IATA code, e.g. 'SGN'. When omitted, the result asks the user for it.
queryTextstring–Optional short excerpt of the current request, used only to detect the UI language; it is not stored or forwarded.
returnDatestring–Return date YYYY-MM-DD (omit for one-way). Must be on or after departureDate.
NameTypeReqDescription
adultsnumberyes–
cabinstringyes–
cachedbooleanyes–
departureDatestringyes–
destinationstringyes–
languagestring––
originstringyes–
outboundFlightsarrayyes–
returnDatestring––
returnFlightsarrayyes–
sessionIdstringyes–
statusstringyes–
totalOutboundnumberyes–
totalReturnnumberyes–
tripTypestringyes–

No examples provided.

search_hotels_live ~468

Starts a live hotel search for a city and date range. Prices come from Agoda, Booking.com and Traveloka, plus direct rates from OpenTravel partner hotels. Returns a session ID; poll_search_results returns the results as they arrive. Optional filters narrow the results by hotel name, area or total price for the stay. Prices depend on the party: it defaults to 2 adults in 1 room, and the result states the party searched and flags when it was defaulted. When the city or dates are missing, the result is a question for the user instead of a search; the stay dates searched are echoed back for confirmation.

NameTypeReqDescription
adultsinteger–Number of adults (default 2). Prices depend on it.
areastring–Optional district, ward, or neighborhood filter within the city
checkInstring–Check-in date (YYYY-MM-DD), today or later. When omitted, the result asks the user for it.
checkOutstring–Check-out date (YYYY-MM-DD), after checkIn. When omitted, the result asks the user for it.
childreninteger–Number of children sharing the room (default 0). OTA prices cannot include children; the result says so when children are given.
citystring–City or broad destination, e.g. 'Da Nang'. When omitted, the result asks the user for it.
hotelNamestring–Optional hotel-name filter when the user names a specific property
languagestring–Preferred UI language (en/vi/de/ja/ko/zh/fr/es/ru/th/id).
priceCurrencystring–ISO 4217 code of priceMin/priceMax (USD, EUR, VND, …); defaults to the currency of the UI language.
priceMaxnumber–Maximum total price for the whole stay (not per night), in priceCurrency.
priceMinnumber–Minimum total price for the whole stay (not per night), in priceCurrency.
queryTextstring–Optional short excerpt of the current request, used only to detect the UI language; it is not stored or forwarded.
roomsinteger–Number of rooms (default 1).
NameTypeReqDescription
agodaStatusstringyes–
bookingStatusstringyes–
cachedboolean––
checkInstringyes–
checkOutstringyes–
citystringyes–
fxRatesobjectyes–
hasMorebooleanyes–
hotelsarrayyes–
languagestring––
limitnumberyes–
longStayNoticestring|null––
nightsnumberyes–
offsetnumberyes–
opentravelIndicativeResultsarrayyes–
opentravelResultsarrayyes–
opentravelStatusstringyes–
progressnumberyes–
sessionIdstring––
statusstringyes–
tierstringyes–
tier2AgodaStatusstring|nullyes–
tier2BookingStatusstring|nullyes–
tier2TravelokaStatusstring|nullyes–
totalHotelsnumberyes–
travelokaStatusstringyes–

No examples provided.

Common questions

What is the PriceWin MCP server?

PriceWin is an MCP server listed in the public MCP registry as win.price/pricewin. Live hotel and flight prices compared across Booking.com, Agoda, Trip.com and Traveloka, in USD. This page covers its hosted endpoint (https://mcp.price.win/mcp).

Is the PriceWin MCP server safe to use?

PriceWin scores 58 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the PriceWin MCP server expose?

PriceWin exposes 12 tools: search_hotels_live, poll_search_results, search_flights_live, poll_flight_results, get_hotel_detail, and 7 more. Their descriptions and schemas cost roughly 2,961 tokens of context every time the server is loaded.

Does the PriceWin MCP server require authentication?

No. We connected to PriceWin without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the PriceWin MCP server still maintained?

PriceWin is still listed as active in the MCP registry. We last reached this channel on 9 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.