# PriceWin (remote · mcp.price.win)

Live hotel and flight prices compared across Booking.com, Agoda, Trip.com and Traveloka, in USD.

- Trust score: 58/100 (low)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-09

## Components

- remote · `mcp.price.win`: 58/100 (this document), [markdown](https://verifymcp.io/servers/win-price-pricewin/mcp.md), [page](https://verifymcp.io/servers/win-price-pricewin/mcp)

## Channel facts

- Endpoint: `https://mcp.price.win/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.19.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-09.

- **Endpoint Security**: 46/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (cancel_booking).
  - HTTPS enforcement could not be verified: the plaintext port answered with HTTP 406, which proves neither a plaintext path nor enforcement.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 50/100
  - 0% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 3180 tokens (~117/item across 27 items; 12 tools + 15 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 20/100
  - Stability observed for 6 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
  - Structured output schemas are declared (92% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 13 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.
  - Supports UI / widget rendering.

## Install

### How do I install the PriceWin MCP server?

PriceWin is a hosted endpoint at https://mcp.price.win/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http win-price-pricewin 'https://mcp.price.win/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "win-price-pricewin": {
      "url": "https://mcp.price.win/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "win-price-pricewin": {
      "type": "http",
      "url": "https://mcp.price.win/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.win-price-pricewin]
url = "https://mcp.price.win/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "win-price-pricewin": {
      "type": "remote",
      "url": "https://mcp.price.win/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add win-price-pricewin --url 'https://mcp.price.win/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  win-price-pricewin:
    url: "https://mcp.price.win/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "win-price-pricewin": {
      "Transport": "http",
      "Url": "https://mcp.price.win/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add win-price-pricewin -t streamable-http -u 'https://mcp.price.win/mcp'
```

### Other

```json
{
  "mcpServers": {
    "win-price-pricewin": {
      "type": "http",
      "url": "https://mcp.price.win/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-09 (score 58, +1)

No change was recorded against any check on this day. Stability & Change Management went from 10 to 20. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-10-06 (score 57, +1)

No change was recorded against any check on this day. Stability & Change Management went from 3 to 10. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-10-04 (score 56, +1)

- [functional improvement] Stability: unverified → 0.03

### 2026-10-03 (score 55)

First indexed and scored.

## MCP tools (12)

### `search_hotels_live` (~468 tokens)

Search Hotels Live

Starts a live hotel search for a city and date range. Prices come from Agoda, Booking.com and Traveloka, plus direct rates from OpenTravel partner hotels. Returns a session ID; poll_search_results returns the results as they arrive. Optional filters narrow the results by hotel name, area or total price for the stay. Prices depend on the party: it defaults to 2 adults in 1 room, and the result states the party searched and flags when it was defaulted. When the city or dates are missing, the result is a question for the user instead of a search; the stay dates searched are echoed back for confirmation.

Input parameters:

- `adults` (integer): Number of adults (default 2). Prices depend on it.
- `area` (string): Optional district, ward, or neighborhood filter within the city
- `checkIn` (string): Check-in date (YYYY-MM-DD), today or later. When omitted, the result asks the user for it.
- `checkOut` (string): Check-out date (YYYY-MM-DD), after checkIn. When omitted, the result asks the user for it.
- `children` (integer): Number of children sharing the room (default 0). OTA prices cannot include children; the result says so when children are given.
- `city` (string): City or broad destination, e.g. 'Da Nang'. When omitted, the result asks the user for it.
- `hotelName` (string): Optional hotel-name filter when the user names a specific property
- `language` (string): Preferred UI language (en/vi/de/ja/ko/zh/fr/es/ru/th/id).
- `priceCurrency` (string): ISO 4217 code of priceMin/priceMax (USD, EUR, VND, …); defaults to the currency of the UI language.
- `priceMax` (number): Maximum total price for the whole stay (not per night), in priceCurrency.
- `priceMin` (number): Minimum total price for the whole stay (not per night), in priceCurrency.
- `queryText` (string): Optional short excerpt of the current request, used only to detect the UI language; it is not stored or forwarded.
- `rooms` (integer): Number of rooms (default 1).

Output parameters:

- `agodaStatus` (string)
- `bookingStatus` (string)
- `cached` (boolean)
- `checkIn` (string)
- `checkOut` (string)
- `city` (string)
- `fxRates` (object)
- `hasMore` (boolean)
- `hotels` (array)
- `language` (string)
- `limit` (number)
- `longStayNotice` (string|null)
- `nights` (number)
- `offset` (number)
- `opentravelIndicativeResults` (array)
- `opentravelResults` (array)
- `opentravelStatus` (string)
- `progress` (number)
- `sessionId` (string)
- `status` (string)
- `tier` (string)
- `tier2AgodaStatus` (string|null)
- `tier2BookingStatus` (string|null)
- `tier2TravelokaStatus` (string|null)
- `totalHotels` (number)
- `travelokaStatus` (string)

### `poll_search_results` (~229 tokens)

Poll Search Results

Returns the current results of a hotel search session started by search_hotels_live: hotels with their price from each source, and OpenTravel direct listings with the propertyId that get_hotel_detail and get_hotel_info take. Results can be partial while the search runs; status reads 'completed' once every source has answered.

Input parameters:

- `area` (string): Optional override for the area filter captured at search time
- `hotelName` (string): Optional override for the hotel-name filter captured at search time
- `limit` (integer): Max hotels to return; 0 = all (default 50)
- `nights` (integer, required): Number of nights
- `offset` (integer): Skip first N hotels for pagination (default 0)
- `priceCurrency` (string): ISO 4217 code of priceMin/priceMax; defaults to the UI language's currency
- `priceMax` (number): Optional override for the maximum-price filter
- `priceMin` (number): Optional override for the minimum-price filter
- `sessionId` (string, required): Session ID from search_hotels_live

Output parameters:

- `agodaStatus` (string)
- `bookingStatus` (string)
- `cached` (boolean)
- `checkIn` (string)
- `checkOut` (string)
- `city` (string)
- `fxRates` (object)
- `hasMore` (boolean)
- `hotels` (array)
- `language` (string)
- `limit` (number)
- `longStayNotice` (string|null)
- `nights` (number)
- `offset` (number)
- `opentravelIndicativeResults` (array)
- `opentravelResults` (array)
- `opentravelStatus` (string)
- `progress` (number)
- `sessionId` (string)
- `status` (string)
- `tier` (string)
- `tier2AgodaStatus` (string|null)
- `tier2BookingStatus` (string|null)
- `tier2TravelokaStatus` (string|null)
- `totalHotels` (number)
- `travelokaStatus` (string)

### `search_flights_live` (~293 tokens)

Search Flights Live

Starts a live flight search for a route and date, one-way or return. Fares come from Agoda, Trip.com, Traveloka and Google Flights. Origin and destination are 3-letter IATA airport codes (for example SGN, HAN, DAD). Returns a session ID; poll_flight_results returns the results. When the route or date is missing, the result is a question for the user instead of a search.

Input parameters:

- `adults` (integer): Number of adults (default 1)
- `cabin` (string): Cabin class (default economy)
- `departureDate` (string): Departure date YYYY-MM-DD, today or later. When omitted, the result asks the user for it.
- `destination` (string): Arrival airport IATA code, e.g. 'HAN'. When omitted, the result asks the user for it.
- `language` (string): Preferred UI language (en/vi/de/ja/ko/zh/fr/es/ru/th/id).
- `origin` (string): Departure airport IATA code, e.g. 'SGN'. When omitted, the result asks the user for it.
- `queryText` (string): Optional short excerpt of the current request, used only to detect the UI language; it is not stored or forwarded.
- `returnDate` (string): Return date YYYY-MM-DD (omit for one-way). Must be on or after departureDate.

Output parameters:

- `adults` (number)
- `cabin` (string)
- `cached` (boolean)
- `departureDate` (string)
- `destination` (string)
- `language` (string)
- `origin` (string)
- `outboundFlights` (array)
- `returnDate` (string)
- `returnFlights` (array)
- `sessionId` (string)
- `status` (string)
- `totalOutbound` (number)
- `totalReturn` (number)
- `tripType` (string)

### `poll_flight_results` (~82 tokens)

Poll Flight Results

Returns the current results of a flight search session started by search_flights_live: outbound and return options with airline, flight number, times, stops, fare and booking link. Results can be partial while the search runs; status reads 'completed' or 'failed' when it ends.

Input parameters:

- `sessionId` (string, required): Session ID from search_flights_live

Output parameters:

- `adults` (number)
- `cabin` (string)
- `cached` (boolean)
- `departureDate` (string)
- `destination` (string)
- `language` (string)
- `origin` (string)
- `outboundFlights` (array)
- `returnDate` (string)
- `returnFlights` (array)
- `sessionId` (string)
- `status` (string)
- `totalOutbound` (number)
- `totalReturn` (number)
- `tripType` (string)

### `get_hotel_detail` (~275 tokens)

Get Hotel Detail (by propertyId / OpenTravel-direct)

Prices and availability for one OpenTravel direct-listed hotel over a date range, with its photos, amenities and room types, each room with its rate plan and total price. Takes the propertyId from search results (source 'OPENTRAVEL_DIRECT'), or a hotel name plus city for a known direct listing. get_hotel_info returns the same hotel's static facts without dates.

Input parameters:

- `adults` (integer): Number of adults (default 2)
- `checkIn` (string, required): Check-in date YYYY-MM-DD. Must be today or later.
- `checkOut` (string, required): Check-out date YYYY-MM-DD. Must be after checkIn.
- `children` (integer): Number of children (default 0)
- `city` (string): City of the hotel — required when resolving by hotelName.
- `hotelName` (string): Fallback name for a confirmed OpenTravel direct listing when propertyId is unavailable
- `language` (string): Preferred UI language (en/vi/de/ja/ko/zh/fr/es/ru/th/id).
- `propertyId` (string): OpenTravel propertyId UUID from search results (opentravelResults[].propertyId).
- `queryText` (string): Optional short excerpt of the current request, used only to detect the UI language; it is not stored or forwarded.

Output parameters:

- `adults` (number)
- `bookingUrl` (string)
- `checkIn` (string)
- `checkOut` (string)
- `discovery` (boolean)
- `language` (string)
- `nights` (number)
- `property` (object)
- `roomTypes` (array)

### `get_ota_hotel_detail` (~365 tokens)

Hotel Detail by Name (one specific hotel)

Full detail (rooms, live prices, facilities, photos, reviews) from Booking.com for one named hotel over a date range, for requests about a single hotel rather than a whole city (search_hotels_live lists a city). The name is resolved through the city's listings, so it takes the hotel name together with its city; a Booking.com URL from an earlier result skips that lookup. OpenTravel direct listings are covered by get_hotel_detail. The fetch is live and takes up to about two minutes; under heavy load it can return not-found.

Input parameters:

- `adults` (integer): Number of adults (default 2)
- `checkIn` (string, required): Check-in date YYYY-MM-DD. Must be today or later.
- `checkOut` (string, required): Check-out date YYYY-MM-DD. Must be after checkIn.
- `city` (string): City of the hotel, used to resolve the name, e.g. 'Da Nang'. Required with hotelName.
- `hotelName` (string): Name of the hotel, e.g. 'Mercure Danang French Village Bana Hills'. Required unless propertyUrl is given.
- `language` (string): Optional UI language. Indonesian (id) cannot be detected from text, so for Indonesian this is how the language is set.
- `propertyUrl` (string): Booking.com property URL from an earlier result (hotel.prices.booking.url); skips the name lookup.
- `queryText` (string): Short excerpt (one sentence at most) of the guest's latest message in their own words, used only to detect the reply language; it is not stored or forwarded. It carries no names, contact details or o…
- `rooms` (integer): Number of rooms (default 1)

### `check_booking_status` (~72 tokens)

Check Booking Status

Returns the current status of a booking request (waiting for the hotel, confirmed or cancelled) by the confirmation code request_booking returned.

Input parameters:

- `confirmationCode` (string, required): confirmationCode from request_booking structuredContent (e.g. 'K7X9M2P4')
- `language` (string): Response language

Output parameters:

- `bookingId` (string)
- `checkIn` (string)
- `checkOut` (string)
- `confirmationCode` (string|null)
- `guestEmail` (string)
- `guestName` (string)
- `paidAt` (string|null)
- `paymentLinkUrl` (string|null)
- `paymentMethod` (string|null)
- `paymentStatus` (string)
- `propertyName` (string)
- `roomNumber` (string|null)
- `status` (string)

### `request_booking` (~563 tokens)

Request a Booking (hotel confirms, pay at the hotel)

Sends a booking request for a room at an OpenTravel partner hotel. Nothing is charged and no room is held: the hotel confirms the request by email, and the guest pays at the property on arrival. There is no payment step, now or later. Takes the room and rate from get_hotel_detail and the guest's name, phone number and email; when any of these is missing, the result asks for it and, in clients that show widgets, opens a form for it. A few properties require payment at booking time, and the result says so for those. One request covers several rooms of the same room type (roomCount), with adults and children counted across all of them; each call is a separate request with its own code, so rooms of one type booked call by call reach the hotel as unrelated requests. Returns one confirmation code for the whole request.

Input parameters:

- `adults` (integer, required): Number of adults across ALL rooms of the request — at least one per room
- `checkIn` (string, required): Check-in date YYYY-MM-DD. Must be today or later.
- `checkOut` (string, required): Check-out date YYYY-MM-DD. Must be after checkIn.
- `children` (integer): Number of children across ALL rooms of the request (default 0)
- `currency` (string, required): Currency of totalAmount, as quoted by get_hotel_detail for the chosen room.
- `guestEmail` (string): Email address the confirmation is sent to, as the guest gave it; it cannot be changed after the request is sent. When omitted, the result asks the user for it.
- `guestName` (string): Full name of the primary guest. When omitted, the result asks the user for it.
- `guestPhone` (string): Guest phone number; the hotel calls it to confirm the request. When omitted, the result asks the user for it.
- `language` (string): Optional response language hint. Only used when queryText gives no signal.
- `propertyId` (string, required): OpenTravel propertyId from get_hotel_detail
- `queryText` (string): Short excerpt (one sentence at most) of the guest's latest message in their own words, used only to detect the reply language; it is not stored or forwarded. It carries no names, contact details or o…
- `roomCount` (integer): How many rooms of this room type the guest wants (default 1). All of them go in this one request, under one confirmation code.
- `roomTypeId` (string, required): roomTypeId from get_hotel_detail roomTypes array
- `totalAmount` (number, required): Total amount for ALL rooms in the property's base currency: the room's price for the stay × roomCount

Output parameters:

- `assignedRoomId` (string|null)
- `bookingId` (string)
- `confirmationCode` (string)
- `nextStep` (string)
- `paymentRequired` (boolean)
- `quotedAmount` (number)
- `quotedCurrency` (string)
- `roomCount` (number)
- `status` (string)

### `get_hotel_info` (~183 tokens)

Hotel Info (no dates needed)

Static facts about an OpenTravel direct-listed hotel, with no check-in or check-out date required: photo gallery, property description, address, facilities (parking, pool, pets and so on), check-in and check-out times, the house cancellation policy, and each room type's description, floor area, capacity, photos and in-room facilities. Carries no prices and no availability — get_hotel_detail covers those for a specific date range. Takes the propertyId UUID from search results.

Input parameters:

- `language` (string): Preferred reply language (en/vi/de/ja/ko/zh).
- `propertyId` (string, required): OpenTravel propertyId UUID from search results (opentravelResults[].propertyId).
- `queryText` (string): Optional short excerpt of the current request, used only to detect the reply language; it is not stored or forwarded.

Output parameters:

- `cancellationPolicy` (object)
- `property` (object)
- `roomTypes` (array)

### `get_cancellation_policy` (~179 tokens)

Get Cancellation Policy

Returns the cancellation terms for one rate plan at an OpenTravel partner hotel: whether it is refundable, the free-cancellation window, the refund percentage, a plain-language summary and, given the check-in date, the exact free-cancellation deadline. Takes the propertyId and the ratePlanId from get_hotel_detail.

Input parameters:

- `checkInDate` (string, required): Check-in date YYYY-MM-DD — required to compute the exact free-cancel deadline
- `language` (string): Reply language. Falls back to queryText, then English.
- `propertyId` (string, required): OpenTravel propertyId UUID from search results
- `queryText` (string): Short excerpt of the guest's request, used only to pick the reply language.
- `ratePlanId` (string, required): ratePlanId from get_hotel_detail roomTypes[].ratePlanId

Output parameters:

- `computedDeadline` (string|null)
- `freeCancelUntilHours` (number|null)
- `nonRefundable` (boolean)
- `policyText` (string)
- `ratePlanId` (string)
- `refundPercentAfterWindow` (number|null)

### `request_cancel_token` (~116 tokens)

Request Cancellation Link (step 1 of 2)

First of two steps to cancel a booking. Emails a single-use cancellation token to the address on the booking, given its confirmation code and that same email address. Nothing is cancelled, charged or refunded by this step. The token expires after 24 hours and works once; cancel_booking completes the cancellation with it.

Input parameters:

- `confirmationCode` (string, required): 8-char booking confirmation code, e.g. K7X9M2P4
- `guestEmail` (string, required): Guest email address — must match the booking primary guest email

Output parameters:

- `message` (string)
- `success` (boolean)

### `cancel_booking` (~136 tokens)

Cancel Booking (step 2 of 2)

Second of two steps to cancel a booking: cancels it and starts any refund due. Irreversible. Requires the confirmation code and the single-use token that request_cancel_token emailed to the guest; a missing, expired or already-used token is rejected. get_cancellation_policy shows the refund terms that apply.

Input parameters:

- `cancelToken` (string, required): Single-use cancellation token from the email request_cancel_token sent to the guest.
- `confirmationCode` (string, required): 8-char booking confirmation code, e.g. K7X9M2P4
- `reason` (string, required): Guest-provided cancellation reason (at least 3 characters)

Output parameters:

- `gatewaySettlementEta` (string|null)
- `refundAmount` (number)
- `refundStatus` (string|null)
- `status` (string)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/win-price-pricewin/mcp#diagnostics

## Score history

- 2026-10-09: 58
- 2026-10-06: 57
- 2026-10-04: 56
- 2026-10-03: 55

## Common questions

### What is the PriceWin MCP server?

PriceWin is an MCP server listed in the public MCP registry as win.price/pricewin. Live hotel and flight prices compared across Booking.com, Agoda, Trip.com and Traveloka, in USD. This page covers its hosted endpoint (https://mcp.price.win/mcp).

### Is the PriceWin MCP server safe to use?

PriceWin scores 58 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the PriceWin MCP server expose?

PriceWin exposes 12 tools: search_hotels_live, poll_search_results, search_flights_live, poll_flight_results, get_hotel_detail, and 7 more. Their descriptions and schemas cost roughly 2,961 tokens of context every time the server is loaded.

### Does the PriceWin MCP server require authentication?

No. We connected to PriceWin without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the PriceWin MCP server still maintained?

PriceWin is still listed as active in the MCP registry. We last reached this channel on 9 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://mcp.price.win/mcp
- Website: https://www.price.win/
- Changelog RSS feed: https://verifymcp.io/servers/win-price-pricewin/mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/win-price-pricewin/mcp.json
- HTML version of this page: https://verifymcp.io/servers/win-price-pricewin/mcp
