# me.cancun4/reservas

Pesquise, cote e reserve hoteis de Cancun/Riviera Maya direto de uma IA (Cancun4me).

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.0
- **Author:** me.cancun4
- **License:** Unknown
- **Endpoints:** streamable-http https://cancun4-mcp.fly.dev/mcp
- **Source:** https://cancun4-mcp.fly.dev/mcp
- **Endpoint health:** reachable (last checked 2026-09-09T16:53:58.129Z, 3 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 0 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-09T16:53:58.129Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

13 declared. Observed from a live `tools/list` probe.
- `list_hotels` — Lista o catalogo curado de hoteis do Cancun4me (nome, zona, descricao, destaques, fotos), sem precisar de datas ou chave pessoal. Bom para descobrir/descrever h
- `get_hotel_info` — Detalhe de UM hotel do catalogo pelo slug (retornado por list_hotels ou search_hotels). language: 'en', 'pt' ou 'es'.
- `search_hotels` — Busca tarifas AO VIVO (sempre em tempo real, nunca cache) nos hoteis do catalogo Cancun4me para as datas informadas, agrupadas por hotel (menor preco de cada um
- `ver_quartos` — Lista TODOS os apartamentos/tipos de quarto disponiveis de UM hotel dentro de uma busca ja feita (use o search_id e o hotel_slug devolvidos por search_hotels). 
- `get_quote` — Recotacao ao vivo de UM quarto especifico (preco final revalidado, politica de cancelamento, prazo-limite para cancelar de graca, observacoes do quarto). Chame 
- `create_payment` — Cria o pedido e devolve o LINK DE PAGAMENTO (Stripe Checkout). O hospede tem que abrir esse `payment_url` e pagar com o cartao na pagina do Stripe — NUNCA peca 
- `get_order_status` — Status atual de um pedido (aguardando_pagamento, reservado, cancelado, falhou), numero de localizador (booking_id) quando ja reservado, e se o voucher ja esta p
- `list_my_bookings` — Lista todas as reservas do hospede (passadas e futuras), com status, hotel, datas, preco e se ainda da para cancelar de graca (cancelavel_gratis).
- `get_voucher` — Voucher completo (HTML) de uma reserva ja confirmada — mostre/descreva ao hospede ou oriente a salvar/imprimir para o check-in. So funciona apos a reserva estar
- `cancel_booking` — Cancela uma reserva. Se ainda estiver dentro do prazo gratis de uma tarifa reembolsavel, cancela e estorna automaticamente. Se estiver fora do prazo (ou for tar
- `get_welcome_coupon` — Cupom pessoal de desconto ainda disponivel do hospede (ex.: o cupom de boas-vindas do primeiro cadastro), se houver. Retorna {cupom: null} se nao houver nenhum 
- `get_membership_status` — Status do Clube Cancun4me do hospede: se e membro ativo (creditos de 20% da primeira reserva e 10% das seguintes, para a proxima reserva, + acesso ao assistente
- `join_club` — Inicia a assinatura anual do Clube Cancun4me (USD 1.000/ano, renovacao automatica — 20% da primeira reserva de volta em credito, 10% das seguintes, + assistente

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"reservas\": {\n      \"type\": \"http\",\n      \"url\": \"https://cancun4-mcp.fly.dev/mcp\"\n    }\n  }\n}"
```

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on someone else's infrastructure; read-only tool surface.
- Floor 9, ceiling 27 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/me.cancun4%2Freservas
- Install plan: https://forgeregistry.com/api/v1/packages/me.cancun4%2Freservas/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/me.cancun4%2Freservas
- HTML page: https://forgeregistry.com/registry/me.cancun4%2Freservas
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
