Back to Browse

Getyourguide MCP Server

Developer ToolsModerate7.0Local
Free

GetYourGuide tours & activities for Claude — search, details, options, and reviews

About

GetYourGuide tours & activities for Claude — search, details, options, and reviews

Security Report

7.0
Moderate7.0Moderate Risk

Well-structured MCP server for GetYourGuide Partner API with proper authentication, good error handling, and appropriate permission scoping. Code is clean with comprehensive tests and security-conscious practices like deferred credential checks and error redaction. Minor code quality observations do not materially impact security posture. Supply chain analysis found 2 known vulnerabilities in dependencies (0 critical, 1 high severity). Package verification found 1 issue.

7 files analyzed · 6 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

What You'll Need

Set these up before or after installing:

Your GetYourGuide Partner API key (X-ACCESS-TOKEN). Get one by joining the GetYourGuide partner program at partner.getyourguide.com.Required

Environment variable: GYG_API_KEY

Default currency for prices (ISO 4217, e.g. USD or EUR). Optional — individual tool calls can override it.Optional

Environment variable: GYG_CURRENCY

Default content language (e.g. en, de). Optional — individual tool calls can override it.Optional

Environment variable: GYG_LANGUAGE

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-chrischall-getyourguide-mcp": {
      "env": {
        "GYG_API_KEY": "your-gyg-api-key-here",
        "GYG_CURRENCY": "your-gyg-currency-here",
        "GYG_LANGUAGE": "your-gyg-language-here"
      },
      "args": [
        "-y",
        "getyourguide-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

getyourguide-mcp

MCP server for GetYourGuide — search tours and activities, read tour details, bookable options, and reviews via the GetYourGuide Partner API.

🤖 This project was developed and is maintained by AI (Claude Code). Use at your own discretion.

Tools

All tools are read-only — this server registers no write tools.

ToolWhat it does
gyg_search_toursSearch tours/activities by free text, location, category, or date range; sortable; view
gyg_get_tourFull record for one tour by numeric ID; view
gyg_get_tour_optionsBookable options of a tour (ticket types, times), optionally within a date range
gyg_get_tour_availabilityBooking availability of a tour: participant categories, addons, available dates
gyg_get_tour_reviewsCustomer reviews for a tour
gyg_list_categoriesActivity categories (IDs feed gyg_search_tours / gyg_list_category_tours)
gyg_list_category_toursTours in one category; view
gyg_get_locationDetails for a location (city, POI, region) by ID
gyg_list_location_toursTours available at one location; view
gyg_healthcheckVerify credentials and upstream reachability; reports failures as data, not exceptions

view — response shape

The tools marked view above take view: "compact" | "full", and compact is the default. An efficiency that has to be asked for is one that usually is not, so it is not opt-in — the old compact: true flag on gyg_search_tours is gone.

  • compact — on the three tour LISTINGS it returns the documented slim projection (tour_id, title, abstract, url, price, overall_rating, number_of_ratings, durations, categories, locations), flattened to { _metadata, tours }. On gyg_get_tour — one record, no listing envelope to project — it instead strips image URLs and keeps everything else.
  • full — GetYourGuide's whole validated record, untouched.

Reach for full when you need a field the projection does not carry (picture variants, coordinates, marketing copy). Every response is minified JSON either way: formatting whitespace is dropped, whitespace inside a value is not.

Setup

You need a GetYourGuide Partner API key — join the (free) partner program at partner.getyourguide.com and copy the API key from your dashboard. The key is sent as the X-ACCESS-TOKEN header on every request.

Claude Code / any MCP host

{
  "mcpServers": {
    "getyourguide": {
      "command": "npx",
      "args": ["-y", "getyourguide-mcp"],
      "env": {
        "GYG_API_KEY": "your-partner-api-key"
      }
    }
  }
}

The server also boots with no key set (so hosts can probe tools/list at install time); the first tool call then returns an actionable error telling you which env var to set.

Environment variables

VariableRequiredMeaning
GYG_API_KEYyes (for tool calls)Partner API key, sent as X-ACCESS-TOKEN
GYG_CURRENCYnoDefault currency for prices (ISO 4217; falls back to USD — the API requires one); per-call currency args override
GYG_LANGUAGEnoDefault content language (falls back to en — the API requires one); per-call language args override
GYG_BASE_URLnoAPI base URL (default https://api.getyourguide.com/1)
GYG_REQUEST_TIMEOUT_MSnoPer-request timeout (default 30000)

For local development, put them in a .env next to the server (gitignored; see .env.example).

Behavior notes

  • Rate limits: one automatic retry on 429/503 honoring Retry-After (capped at 10s). If it still fails, the error tells you to back off.
  • Auth errors: a 401/403 names both possible causes — a wrong key, or a key whose partner tier doesn't cover that endpoint.
  • API drift: responses are validated leniently. On an unexpected shape the server logs a precise warning to stderr and returns the raw response rather than breaking; search tools also accept extraParams to pass raw query params through verbatim. See docs/GETYOURGUIDE-API.md — routes and request shapes are live-verified against the API and its official OpenAPI spec; real 200 bodies still need pinning from a keyed capture.
  • Secrets: upstream error bodies are redacted then truncated before they reach a tool result; the API key is never echoed.

Development

npm install
npm run build          # tsc + esbuild bundle → dist/
npm test               # tsc typecheck + vitest (no network — everything mocked)
npm run test:coverage  # tsc typecheck + the CI gate: 100% lines/branches/functions/statements

Releases are automated with release-please; don't hand-bump versions. PR titles must be conventional commits (feat:, fix:, …) because the repo squash-merges.

License

MIT

Reviews

No reviews yet

Be the first to review this server!