io.github.Everyways/upsalt-booking

MCPcommunitylive
v1.0.1io.github.EverywaysUnknownUpdated 1mo ago

Search Upsalt venues, check availability, and book, view, or cancel a reservation.

Endpoint healthlive
checked 9 days ago · 1435ms
100% of the last 5 checks reached this endpoint
Works in
ClaudeCursorCopilotChatGPTGemini

Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
1mo agoLast update
Package
Authorio.github.Everyways
LicenseUnknown
Version1.0.1
Sourcemcp-registry
Trust Status
B
60/100Good
✓Listed in Forge index+10/10
—Publisher identity verified+0/30
→ Publisher: this listing has no repository on file, so `forge publish` cannot verify ownership automatically. Use "Claim this listing" above — Forge reviews these by hand.
—Domain verification+0/10
→ Not currently available for this listing type — the domain-verification check only runs for npm-backed packages today, so this row cannot be earned here yet regardless of what's hosted at the domain.
✓Prompt-injection scan · clean+30/30
✓Obfuscation / exfil scan · clean+20/20
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
DependenciesNot audited
Tool surface5 tools · none privileged
Security scan✓ Cleanvlive · 9d agoHow well does this scan work?
EvalsNone
IndexedAug 17, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

5 tools · none privileged
Observed live from the vendor's endpoint9d ago

Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.

  • https://ai.upsalt.io/mcp/booking5 tools · 1435ms
find-companyFind a company by its slug and return its public profile: services, opening hours, and booking configuration. Use this first to obtain the company_id needed by the other tools.

Find a company by its slug and return its public profile: services, opening hours, and booking configuration. Use this first to obtain the company_id needed by the other tools.

ParameterTypeDescription
slug*stringThe company slug, as found in its booking page URL.
business_typestringOptional business type filter.
list-available-slotsList the available booking slots for a company on a given date. Returns shifts and bookable hours; use the shift_id and hour when creating a booking.

List the available booking slots for a company on a given date. Returns shifts and bookable hours; use the shift_id and hour when creating a booking.

ParameterTypeDescription
company_id*integerThe company id, as returned by the find-company tool.
date*stringThe date to check, in YYYY-MM-DD format (e.g. 2026-07-20).
create-bookingCreate a booking for a company as a guest. Requires a date (YYYY/MM/DD), an hour and shift_id obtained from list-available-slots, and the guest contact details. On success, returns the reservation details including a token that can be used with get-booking-info and cancel-booking.

Create a booking for a company as a guest. Requires a date (YYYY/MM/DD), an hour and shift_id obtained from list-available-slots, and the guest contact details. On success, returns the reservation details including a token that can be used with get-booking-info and cancel-booking.

ParameterTypeDescription
company_id*integerThe company id, as returned by the find-company tool.
date*stringBooking date in YYYY/MM/DD format (e.g. 2026/07/20). Note the slashes.
hour*stringBooking hour in HH:MM format, taken from list-available-slots.
shift_id*integerThe shift id, taken from list-available-slots.
adults*integerNumber of adults.
name*stringGuest first name.
surname*stringGuest last name.
email*stringGuest email address. The booking confirmation and management token are sent here.
phone*stringGuest phone number.
childrenintegerNumber of children.
babiesintegerNumber of babies.
petsintegerNumber of pets.
veganbooleanWhether the party includes vegan guests.
vegetarianbooleanWhether the party includes vegetarian guests.
gluten_freebooleanWhether the party needs gluten-free options.
nuts_allergybooleanWhether the party has a nut allergy.
messagestringOptional message for the business.
pushchairintegerNumber of pushchairs.
wheelchairintegerNumber of wheelchairs.
highchairintegerNumber of highchairs.
optinintegerMarketing opt-in flag (1 or 0).
latitudenumberGuest latitude, if known.
longitudenumberGuest longitude, if known.
countrystringGuest country.
get-booking-infoRetrieve the details of an existing booking using the management token returned by create-booking.

Retrieve the details of an existing booking using the management token returned by create-booking.

ParameterTypeDescription
company_id*integerThe company id the booking belongs to.
token*stringThe booking management token returned by create-booking.
cancel-bookingCancel an existing booking using the management token returned by create-booking. This action is irreversible; confirm with the guest before calling it.

Cancel an existing booking using the management token returned by create-booking. This action is irreversible; confirm with the guest before calling it.

ParameterTypeDescription
token*stringThe booking management token returned by create-booking.

5 of 5 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Search Upsalt venues, check availability, and book, view, or cancel a reservation.

Keywords
mcp
Alternatives
Comparing tool surfaces…

No dependency coverage

This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.

Topics

Related in travel & booking