Back to Browse

Housecallpro MCP Server

Developer ToolsModerate5.2LocalNew
Free

Read Housecall Pro estimates from the customer link your contractor sent you.

About

Read Housecall Pro estimates from the customer link your contractor sent you.

Security Report

5.2
Moderate5.2Moderate Risk

Well-designed MCP server with thoughtful security practices around credential handling and input validation. The codebase demonstrates strong awareness of the sensitive nature of bearer tokens (Housecall Pro links) and implements appropriate safeguards. Minor code quality improvements around error handling and test coverage do not detract from a fundamentally solid implementation. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

6 files analyzed · 8 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

What You'll Need

Set these up before or after installing:

Estimate or invoice link your contractor sent you.Required

Environment variable: HOUSECALLPRO_LINK

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-chrischall-housecallpro-mcp": {
      "env": {
        "HOUSECALLPRO_LINK": "your-housecallpro-link-here"
      },
      "args": [
        "-y",
        "@chrischall/housecallpro-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Housecall Pro MCP

CI npm license

A Model Context Protocol server that connects Claude to the customer side of Housecall Pro — the estimate or invoice link a contractor (HVAC, plumbing, electrical, cleaning) emails or texts you.

[!WARNING] AI-developed project. This codebase was built and is actively maintained by Claude Code. No human has audited the implementation. Review all code and tool permissions before use.

This is the customer side, not the business side

Housecall Pro has two surfaces, and they share nothing:

Public APICustomer portal (this repo)
Hostapi.housecallpro.comapp.housecallpro.com
Servesthe business running on Housecall Prothat business's customers
Authan API key from the pro's accountthe link your contractor sent you
Docsdocs.housecallpro.comdocs/HOUSECALLPRO-API.md

If you run a business on Housecall Pro, you want the public API instead. This server is for being someone's customer.

What you can do

  • "What did Queen City quote me for the tankless flush?"
  • "What's on that estimate, line by line?"
  • "How much of that $346 is tax?"
  • "Am I still on the hook to respond to this?"
  • "Decline option 2."

Install

npx -y @chrischall/housecallpro-mcp

Configure it with the link your contractor sent you:

HOUSECALLPRO_LINK='https://pro.housecallpro.com/mobile_estimate/XXXXXXXXXX'

Estimate and invoice links both work, short or long form — pro.housecallpro.com/mobile_estimate/… and /mobile_invoice/…, or client.housecallpro.com/estimates/… and /invoices/…. For several documents:

HOUSECALLPRO_LINKS='[{"label":"tankless","url":"…"},{"label":"hvac","url":"…"}]'

Then every tool takes an optional link selector; with one configured you never need it.

[!IMPORTANT] Your link is a bearer credential. Anyone holding it can read the document and, for an estimate, decline it. It is read from the environment, never logged, and never returned in a tool result — housecallpro_list_links reports labels only.

Tools

Tool
housecallpro_get_estimateLine items, totals, tax, company, approval state
housecallpro_get_invoiceAmount, subtotal, tax, balance due, payability
housecallpro_get_companyThe contractor: phone, email, website, arrival window
housecallpro_list_linksConfigured links, labels only
housecallpro_decline_estimateDecline options — confirm-gated
housecallpro_approve_estimateAlways refuses; explains why
housecallpro_healthcheckReachability + whether a link still resolves

Estimates and invoices are different documents

They use different token shapes — 129 characters for an estimate, 32 for an invoice — and different endpoints. The client checks the shape and refuses a token pointed at the wrong tool before spending a request, rather than passing along an unexplained 404.

An invoice carries no line items and no tax field: a paid invoice renders as a summary in the portal and the API returns exactly that, so tax_usd is derived as total - subtotal. is_paid comes from the balance, not the status string.

Money is returned twice

The upstream API returns integer cents — the estimate the portal renders as $346.39 arrives as total_amount: 34639. Reporting that raw overstates every figure 100×, so each money field is emitted as both *_cents (verbatim) and *_usd (derived). tax.rate is a fraction (0.0825 = 8.25%) and is never scaled.

Why you can't approve an estimate

housecallpro_approve_estimate always refuses, and that is deliberate.

Approval posts a response_token — a reCAPTCHA v3 token minted in-page for the action estimates_customer_approvals. No server-side client can produce one, and neither can a browser-bridge transport: the bridge issues fetch calls, it does not execute page JS. Declining carries no such token, which is why decline works and approve does not.

Rather than post a request that would be rejected — or worse, might not be, binding you to a quoted price — the tool refuses and tells you to approve in a browser.

Declining is confirm-gated: without confirm: true it makes no network call and returns a preview of exactly what would be sent. After a real decline it re-reads the estimate and reports the option's actual status, because a 2xx is not proof a write landed.

Without the MCP

skills/housecallpro does the same reads from a shell with plain curl and jq, for scripts or machines where the server isn't installed. No browser bridge is involved there either.

No browser bridge

Unlike much of this fleet, app.housecallpro.com is not bot-walled — a bare curl gets a 200. So this server talks to it directly over HTTPS, has no @fetchproxy/server dependency, needs no extension or signed-in tab, and hosts cleanly as a remote connector.

What isn't here

  • Payments and cards. Deliberately out of scope.
  • The account-level portal. Housecall Pro has an OTP/magic-link customer portal that spans every document from one contractor, which is a strictly better surface than per-document links. Standing it up needs a human to receive a one-time code, so it is the obvious next increment rather than part of this first cut.

Development

npm install
npm run build
npm test

License

MIT

Reviews

No reviews yet

Be the first to review this server!