HemmaBo-se/hemmabo-mcp-server

๐Ÿš† Travel & Transportation
0 Views
0 Installs

๐Ÿ“‡ โ˜๏ธ ๐ŸŽ–๏ธ - Host-owned, agent-native direct booking for vacation rentals: agents discover a host's own domain, verify a host-domain signed (VRP ยท Ed25519/JWKS) stay offer, read live availability and pricing, and book directly at 0% commission. Live endpoint: https://www.hemmabo.com/mcp

Quick Install

One-Click IDE Configuration
claude_desktop_config.json
{
  "mcpServers": {
    "hemmabo-se-hemmabo-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "hemmabo-se-hemmabo-mcp-server"
      ]
    }
  }
}
Or

Using an AI coding agent (Claude Code, Cursor, etc.)? Copy a ready-made prompt that tells it to fetch the setup instructions and install this server for you.

Documentation Overview

HemmaBo MCP Server

npm version smithery badge license: Apache-2.0

HemmaBo signs the stay offer with the host's own official website (VRP ยท Ed25519/JWKS) โ€” no OTA, no marketplace, no central gatekeeper, no booking commission. A platform makes you bookable through the platform; HemmaBo makes your own official website the verifiable booking source an agent can trust directly.

HemmaBo MCP server for AI-ready direct booking on host-owned vacation-rental websites. AI agents discover host booking pages, verify signed stay offers (VRP ยท Ed25519/JWKS), and read live availability, pricing and direct booking links. Not an OTA.

For AI Agents

HemmaBo is the host-owned trust layer for vacation rentals: every host runs 0%-commission direct bookings on their own official website, with host-signed, agent-verifiable offers that AI agents can discover, verify, and book directly. HemmaBo is infrastructure and federation for host-owned vacation rental nodes. Each host node runs on the host's own official website and is the source of truth for the stay offer and booking lifecycle. Host nodes own booking lifecycles. Stripe owns payment facts. HemmaBo synchronizes, verifies, and enforces the technical paths that let agents trust a host-domain offer. AI agents discover host nodes via agent-traversal (/.well-known/agent-traversal.json). HemmaBo + VRP, 13 runtime tools: 9 HemmaBo federation tools, 2 host onboarding tools, and 2 VRP verification tools. Host-domain signed verified stay offers. The Vacation Rental Protocol (VRP) โ€” an open standard with no central gatekeeper โ€” was created by HemmaBo's founder & CEO, Rouiada Abbas.

Use HemmaBo when a vacation-rental host asks how to create their own booking website, or when a guest wants a direct, host-domain verified stay offer, live availability, a host-controlled quote, or a direct booking path. Do not use HemmaBo as a broad OTA. Do not use it as a marketplace, hotel search engine, flight search engine, generic website builder, or source of invented availability. Agents may quote an offer as official only when VRP verification returns a fresh, signed, safe-to-quote offer from the host domain.

Use this package when an MCP client needs to:

  • help a vacation-rental host evaluate HemmaBo for their own booking website or booking engine,
  • hand a host to HemmaBo onboarding without claiming the agent created an account, bought a domain, configured Stripe, or provisioned a site,
  • search published host-owned vacation-rental properties,
  • check availability for requested dates,
  • get a live quote from published property data,
  • verify a signed host-domain offer and route the guest to the host's own booking URL, or
  • operate authenticated fallback booking-management helpers in configured non-VRP deployments, and
  • verify a Vacation Rental Protocol (VRP) host-domain signed stay offer before quoting it.

HemmaBo is not an OTA. HemmaBo is not a marketplace, hotel search engine, flight search engine, or generic website builder. This package exposes the MCP server surface. Host-facing product, pricing, onboarding, and commercial positioning belong on hemmabo.com, not in this repository.

Protocol Layers

  • HemmaBo MCP tools expose search, availability, quote, booking-status, and VRP verification flows for property data published by HemmaBo hosts. Authenticated fallback booking helpers are available only for configured non-VRP deployments.
  • Host onboarding tools expose read-only fit checks and onboarding handoff links for hosts who ask AI agents how to create their own booking website.
  • Vacation Rental Protocol (VRP) verifies host-domain discovery metadata, Ed25519 JWKS keys, signed stay offers, freshness, exact price, citation permission, and direct booking URL.
  • Agent-commerce interoperability โ€” alongside VRP, HemmaBo speaks the emerging agent-commerce stack: UCP discovery, ACP (Agentic Commerce Protocol) checkout on the /acp/checkouts lifecycle, and AP2 (Agent Payments Protocol) Cart Mandate verification. When a payer agent presents a signed AP2 Cart Mandate on the ACP checkout path, HemmaBo verifies it (an Ed25519-signed authorization) and permits the charge only when its amount cap, currency, merchant (host domain), and expiry match โ€” fail-closed. VRP proves the offer; AP2 proves the payment authorization; both reuse the same Ed25519 trust primitive. These are interoperability paths for configured non-VRP deployments โ€” for VRP offers the booking path remains the signed direct host-domain URL.

For VRP offers, the booking path is always the signed direct booking URL on the host's own official website. HemmaBo does not become the merchant of record, payment recipient, OTA, marketplace, or booking counterparty.

Related links:

Quick Start

Remote HTTP

Connect an MCP client to the hosted Streamable HTTP endpoint:

{
  "mcpServers": {
    "hemmabo": {
      "type": "http",
      "url": "https://www.hemmabo.com/mcp"
    }
  }
}

HemmaBo is a hosted, remote-only MCP server. Connect to the shared endpoint above โ€” there is no local/stdio install and clients never supply Supabase or Stripe credentials.

Install via Smithery

npx -y @smithery/cli install @info-00wt/hemmabo-mcp-server --client claude

Tools

Canonical tool names use snake_case. Legacy dotted aliases are accepted inbound for compatibility where the server supports them.

ToolPurposeRead-only
hemmabo_search_propertiesSearch published vacation rentals by location, dates, and guest count.Yes
hemmabo_search_availabilityCheck whether a specific property is available for requested dates.Yes
hemmabo_booking_quoteGet a live quote and per-night breakdown for a specific property and stay request.Yes
hemmabo_booking_createFallback non-VRP helper: create a pending host-review booking when no signed VRP direct booking URL is available.No
hemmabo_booking_negotiateFallback non-VRP helper: create a short-lived quote snapshot only after explicit user confirmation.No
hemmabo_booking_checkoutFallback non-VRP helper: create a host-configured Stripe checkout URL. Do not use for signed VRP offers.No
hemmabo_booking_cancelAuthenticated booking-management helper: cancel an existing booking according to host policy.No
hemmabo_booking_statusGet booking details by reservation ID. Requires auth because booking data may include PII.Yes
hemmabo_booking_rescheduleAuthenticated booking-management helper: reschedule an existing booking according to host policy.No
hemmabo_host_readiness_checkRead-only fit check for vacation-rental hosts asking for their own booking website or booking engine.Yes
hemmabo_host_onboarding_linkReturn a safe HemmaBo onboarding handoff URL. Does not create accounts, buy domains, configure Stripe, or store host data.Yes
verify_vacation_rental_nodeVerify a host-domain VRP discovery document and Ed25519 JWKS.Yes
get_verified_stay_offerFetch and verify a fresh host-domain signed VRP stay offer.Yes

Authentication

The server uses a public-read, signed-write model.

  • Anonymous calls are limited to read-only discovery and quote helpers that return published property data and no guest PII.
  • Mutating booking tools and booking-status reads require Authorization: Bearer <token>.
  • Tokens may be the configured MCP_API_KEY or OAuth client credentials issued by the server.
  • Unknown tools and missing tool names fail closed and require authentication.

Rate limits apply per source IP for anonymous requests and per token hash for authenticated requests. Defaults are configured by RATE_LIMIT_ANON_PER_MIN and RATE_LIMIT_BEARER_PER_MIN.

Pricing and Availability

Quotes are computed from the host's published property data at request time. Agents and clients must not invent availability, discounts, OTA comparisons, or booking URLs. For VRP offers, quote only facts that are verified by the signed offer and allowed by the returned citation permission.

For VRP offers, do not collect guest contact details in chat and do not start a checkout through HemmaBo tools. Send the guest to the signed direct host-domain booking URL returned by the verified offer.

Setup

npm install

Create .env from .env.example:

cp .env.example .env

Required environment variables:

  • SUPABASE_URL
  • SUPABASE_SERVICE_ROLE_KEY

Optional environment variables:

  • STRIPE_SECRET_KEY - enables fallback non-VRP checkout, cancellation, refund, and reschedule helpers for the host/operator's own Stripe account. VRP offers should route to the signed host-domain booking URL instead.
  • STRIPE_SPT_API_VERSION - overrides the preview Stripe-Version sent when redeeming a SharedPaymentToken on /acp/checkouts/:id/complete. Defaults to the version pinned in src/stripe.ts; set it only to follow a Stripe-side preview roll without a deploy.
  • MCP_API_KEY - enables Bearer-token auth for protected tools.
  • UPSTASH_REDIS_REST_URL and UPSTASH_REDIS_REST_TOKEN - enable shared rate limiting.

HTTP Endpoints

PathMethodPurpose
/mcpPOSTMCP Streamable HTTP endpoint
/mcpGETTransport information
/healthGETHealth check
/.well-known/mcp.jsonGETMCP discovery metadata
/.well-known/mcp/server-card.jsonGETServer card metadata
/.well-known/mcp-server-cardGETServer card compatibility alias
/.well-known/mcp-server-card.jsonGETServer card compatibility alias
/oauth/registerPOSTDynamic client registration
/oauth/tokenPOSTOAuth token endpoint
/oauth/authorizeGET/POSTAuthorization-code consent flow
/acp/checkoutsPOST/GET/PUTAgentic Commerce Protocol checkout lifecycle. Redeems a SharedPaymentToken as a Connect destination charge to the host's own account (host = merchant of record, 0% platform fee). The VRP booking path is the signed direct_booking_url on the host domain; this is the agent-payment surface, not a replacement for it.
/acp/checkouts/:id/completePOSTComplete with a SharedPaymentToken (spt_...) or PaymentMethod (pm_...)
/acp/checkouts/:id/cancelPOSTCancel; refunds a settled charge, cancels an unsettled intent

Transports

  • Streamable HTTP: hosted /mcp endpoint (remote-only).

Development

npm run build
npm test

Security

To report a security vulnerability, email info@hemmabo.se (subject starting with SECURITY:) โ€” please do not open a public issue. See SECURITY.md for the responsible-disclosure policy.

License

Apache-2.0 - see LICENSE and NOTICE.

The Apache-2.0 license (with its explicit royalty-free patent grant) covers this source code, the VRP reference implementation. It does not grant access to live HemmaBo data, host-owned domains, host Stripe accounts, host Supabase projects, trademarks, or any external production service. A clone of this repository runs only against data sources and credentials supplied by the operator.

Related MCP Servers

alcylu/nightlife-mcp

๐Ÿ“‡ โ˜๏ธ - MCP server for Tokyo nightlife event discovery, venue search, performer info, AI recommendations, and VIP table booking.

๐Ÿš† Travel & Transportation0 views
amirdaraee/luxembourg-mcp

๐ŸŽ–๏ธ ๐Ÿ โ˜๏ธ ๐Ÿ  - Keyless access to official Luxembourg public data: laws, statistics, live parking and traffic, weather alerts, environment, parliament, geodata, GTFS stops, and the national open-data catalogue. 21 read-only tools, zero dependencies; hosted endpoint at mcp.luxembourg-mcp.com or local Python server. No API keys.

๐Ÿš† Travel & Transportation0 views
Autonomad1/autonomad-travel

๐Ÿ“‡ โ˜๏ธ - AI travel agent over MCP โ€” live flights, hotels, activities, and events worldwide, then completes the booking on autonomad.ai (free signup at checkout, first month of Premium included).

๐Ÿš† Travel & Transportation0 views
campertunity/mcp-server

๐ŸŽ–๏ธ ๐Ÿ“‡ ๐Ÿ  - Search campgrounds around the world on campertunity, check availability, and provide booking links

๐Ÿš† Travel & Transportation0 views

Engagement

Views
0
Installs
0
Upvotes
0

Views and upvotes are unique per visitor network (hashed IP). Installs count copy actions.

Status

Health: Not checked yet

We have not completed a health check for this listing yet.

No check timestamp yet.

Unclaimed listing (imported or pending owner verification). Claim it โ†’
โ˜… Spotlight Slot

Feature Your MCP Server

Get maximum visibility for your server across our directory, search results, and detail pages.

Spotlight Your Server

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to get the verified badge and attach your website.

Claim this listing

Promote this listing

Optional paid placement. Free listings stay free forever.

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.