Back to Browse

Hostaway Kit Mcp Skills MCP Server

Developer ToolsModerate5.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Read-only Hostaway MCP: listings, calendar, inbox, reports. Fixtures, no key. By STYLABS.

About

Read-only Hostaway MCP: listings, calendar, inbox, reports. Fixtures, no key. By STYLABS.

Security Report

5.2
Moderate5.2Moderate Risk

This is a well-designed read-only MCP server for Hostaway property management. The code demonstrates strong security practices: credentials are properly managed via environment variables, there is no support for write operations, and sensitive fields are systematically stripped from all API responses via a robust denylist. The architecture prevents information leakage of wifi passwords, door codes, and invoicing contacts. Minor code quality issues around error handling in the live API client and lack of request timeout configuration do not materially impact security given the server's read-only scope. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

6 files analyzed · 8 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

What You'll Need

Set these up before or after installing:

Hostaway account id. Optional: omit both credentials to run fixtures.Optional

Environment variable: HOSTAWAY_ACCOUNT_ID

Hostaway API client secret. Optional: omit both credentials to run fixtures.Required

Environment variable: HOSTAWAY_CLIENT_SECRET

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-stylabs-hostaway-kit": {
      "env": {
        "HOSTAWAY_ACCOUNT_ID": "your-hostaway-account-id-here",
        "HOSTAWAY_CLIENT_SECRET": "your-hostaway-client-secret-here"
      },
      "args": [
        "-y",
        "hostaway-kit"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

hostaway-kit

Read-only MCP server plus Cursor / Claude Code / Codex skills for operators who already run Hostaway as their PMS.

Ask an assistant about listings, calendar, inbox, and simple reports. Hostaway stays the system of record. This kit never writes — no messages, no calendar blocks, no reservations.

Shipped by STYLABS, an AI-native venture studio that builds custom Hostaway booking sites and operator dashboards. STYLABS is not an official Hostaway partner.

What you get

  1. Read-only MCP (stdio)list_listings, get_listing, get_calendar, list_reservations, list_conversations, list_messages, plus inbox triage, draft reply, and reports.
  2. Denylist on every listing / reservation / message payload: wifiPassword, wifiUsername, doorSecurityCode, doorCode, doorCodeVendor, doorCodeInstruction, and all invoicing* contact fields.
  3. Inbox intelligence Hostaway does not compute — unanswered / SLA triage and a suggested reply grounded in that listing's fields, house rules, and calendar. Rates come from the calendar or are reported as unknown. Nothing is sent.
  4. Reports Hostaway does not ship as owner statements — occupancy and blocked holes from the calendar, unanswered thread counts, listing completeness (photos / house rules / amenities). No financials.
  5. Skills in this repo (not on npm) that tell the model to use the MCP tools and never invent numbers.

Mapped to the Hostaway Public API:

Kit behaviourHostaway
Active listingsGET /v1/listings?specialStatus[]=active
One listingGET /v1/listings/{id}?includeResources=1
CalendarGET /v1/listings/{id}/calendar?includeResources=1
Stay search on the listavailabilityDateStart, availabilityDateEnd, availabilityGuestNumber
Check-in / check-outintegers 0–23 (checkInTimeStart, checkInTimeEnd, checkOutTime)
AmenitiesamenityId integers, not free-text names (GET /v1/amenities resolves names)
InboxGET /v1/conversations, GET /v1/conversations/{id}/messages
Create reservation / send messageout

If HOSTAWAY_ACCOUNT_ID or HOSTAWAY_CLIENT_SECRET is unset, the server serves bundled fixtures so npx still demos.

Install / run

npx -y hostaway-kit

Or from this repo:

npm install
npm run build
node dist/index.js

stdio only. Logs go to stderr. Credentials are optional.

Environment

VariableRequiredPurpose
HOSTAWAY_ACCOUNT_IDfor live readsHostaway account id (client_id on POST /v1/accessTokens)
HOSTAWAY_CLIENT_SECRETfor live readsClient secret from the Hostaway dashboard
HOSTAWAY_KIT_NOWnoISO timestamp that pins "now" for SLA math (used by tests)

Get an API client secret from the Hostaway dashboard. This kit does not ship or use a Hostaway account.

Cursor

Add to ~/.cursor/mcp.json (or project .cursor/mcp.json):

{
  "mcpServers": {
    "hostaway": {
      "command": "npx",
      "args": ["-y", "hostaway-kit"],
      "env": {
        "HOSTAWAY_ACCOUNT_ID": "your-account-id",
        "HOSTAWAY_CLIENT_SECRET": "your-client-secret"
      }
    }
  }
}

Leave both env values empty, or omit env, to run the fixture demo.

Copy the skills from this repo into Cursor:

cp -R skills/* ~/.cursor/skills/

Claude Code

Add to ~/.claude.json (or project .mcp.json):

{
  "mcpServers": {
    "hostaway": {
      "command": "npx",
      "args": ["-y", "hostaway-kit"],
      "env": {
        "HOSTAWAY_ACCOUNT_ID": "your-account-id",
        "HOSTAWAY_CLIENT_SECRET": "your-client-secret"
      }
    }
  }
}

Skills:

mkdir -p .claude/skills
cp -R skills/* .claude/skills/

Codex

~/.codex/config.toml:

[mcp_servers.hostaway]
command = "npx"
args = ["-y", "hostaway-kit"]

[mcp_servers.hostaway.env]
HOSTAWAY_ACCOUNT_ID = "your-account-id"
HOSTAWAY_CLIENT_SECRET = "your-client-secret"

Skills live in this repository under skills/. Point Codex at that folder or copy the SKILL.md files into your Codex skills path.

Skills (repo only)

SkillWhen to use
skills/hostaway-pmsHostaway stays the PMS. Do not push their website builder.
skills/hostaway-guest-answersAnswer guests from that listing's fields only.
skills/hostaway-availabilityDate-range availability from list filters + calendar.
skills/hostaway-inboxSLA triage and draft. Never send.
skills/hostaway-reportingOccupancy, holes, unanswered counts, completeness.

The npm package is the MCP server only. Skills stay in git.

Tools

ToolWhat it does
list_listingsActive listings; optional city / name / availability filters
get_listingOne listing, resources included, secrets stripped
get_calendarDay rows with status, isAvailable, price (null = unknown)
list_reservationsReservations; door codes stripped
list_conversationsInbox threads
list_messagesMessages in a thread
inbox_triageUnanswered + SLA (breached / waiting / answered)
draft_replyGrounded draft. send is always false.
report_occupancyReserved / available / blocked + blocked holes
report_inboxUnanswered thread counts
report_completenessMissing photos, house rules, amenities

Occupancy rate = reserved nights ÷ (reserved + available). Blocked nights are listed as holes, not folded into occupancy.

Fixtures

Demo inventory (not a real Hostaway account):

  • 101 Harbor View Studio — complete listing. Raw fixture includes wifiPassword / invoicing contacts; the denylist strips them.
  • 102 Riverside Loft — no photos.
  • 103 Pine Cabin — no house rules, no amenities.
  • 199 — archived; omitted unless includeArchived is true.
  • August 2026 calendar on 101 with reserved nights, a two-night blocked hole (6–7 Aug), and 11 Aug with price: null.
  • Unread threads 501 (SLA breach), 502 (within SLA), 504 (pets question on the incomplete listing). 503 is answered.

Tests

npm test

Covers denylist, fixture filters, occupancy math, SLA counts, draft refusal of secrets and invented rates, and the absence of a send path.

Out of scope

Writes of any kind. Guest Payments, Stripe, WordPress plugins, a hosted Claude connector, a Cursor marketplace plugin, Hostaway's website builder, Flagship guest websites, owner statements, or live client data.

License

MIT. See LICENSE.

Hostaway is a trademark of its owner. This project is not affiliated with or endorsed by Hostaway.

Reviews

No reviews yet

Be the first to review this server!