---
title: "MCP Server — point Claude at your property"
description: "The HolidayHero MCP server connects your workspace to Claude, ChatGPT or an agent you built. It exposes the stay — conversations, tasks, guidebooks, offers — behind a scoped role with a full audit trail. Included in the platform."
url: "https://www.holidayhero.com/mcp-server"
---

# MCP Server — point Claude at your property

## MCP Server

### MCP Server · Generally available

Point Claude at your property.

The HolidayHero MCP server connects your workspace to Claude, to ChatGPT, or to an agent you built yourself. Your PMS holds the booking. We hold the stay — so the stay is what the server exposes.

### Stats

Included

#### in the platform you already pay for

25+

#### PMS integrations, one server

Role

#### not a master key

### Audit trail · 07:12 CET

Agent

Round complete · 9 calls · every one attributed

Two writes were drafts. A person published them.

## Band

An agent connected to a PMS can change a booking. An agent connected to HolidayHero can run the stay.

### What it actually does

### Reception opens at eight. The agent starts at seven.

Every action below is one the platform already does, and one a member of staff already does by clicking. What an MCP server changes is who clicks.

Your own AI can work the queue of things our AI did not know.

### Two layers

### An MCP server can only expose what its system holds.

A PMS holds the booking: the reservation, the rate, the room, the folio. HolidayHero holds the stay — the conversation at midnight, the task it created, the itinerary, the offer on day three, the note left at handover.

Different jobs, different layers. If your PMS ships an MCP server, use it for the booking and point the same assistant at us for everything after it.

### Your PMS holds

- Reservation
- Rate & room
- Folio

MCP

### HolidayHero holds

- Conversations & notes
- Itineraries & guidebooks
- Tasks & offers

Amenities & experiences

Because we sit above the PMS by design, the server behaves the same whichever one is underneath — across 25+ PMS integrations.

### The tool list

### The protocol is not the interesting part. The tool list is.

Published in full, with no form in front of it. Here is where it stands today.

### Tabs

Reads

Writes

Deliberately absent

### Heads

Tool

What it returns

What it does

Not available

Why

### list_properties / get_property

Properties and units inside the granted scope

### list_reservations / get_reservation

Bookings, stay dates, status, linked guest

### list_guests / get_guest

Guest records, languages, groups, metafields

### list_conversations / get_conversation

Threads by channel, status and property, with internal notes

### list_tasks / get_task

Open, assigned and completed tasks, including AI-created ones

### list_offers / get_offer_uptake

What is on offer, and what a guest has bought

### list_guidebooks / get_guidebook

Guidebooks, house rules, curated recommendations

### list_amenities

Amenities and experiences attached to a listing

### draft_message

Writes a reply into a thread as a draft. Never sends

### send_message

Sends a reply, under house rules and tone of voice. Off by default

### add_internal_note

Staff-only note. Never visible to the guest

### suggest_experience

Puts an experience or offer into a thread

### create_task / assign_task / complete_task

Creates, routes and closes tasks

### draft_guidebook_content

Writes guidebook or recommendation content as a draft

### set_guest_metafield

Writes to operator-defined guest fields only

### Create, amend or cancel a reservation in the PMS

No PMS write beyond what the platform already does

### Take a payment, refund, or post to the folio

Money moves through the payment flow, not an agent

### Read card data

Never in reach of the agent. PCI DSS Level 1 stands

### Read ID documents, passport scans or signed forms

Out of scope entirely

### Issue a door code or operate a lock

Physical access is not an agent action

### Publish content live

Content writes are drafts. A person publishes

### Delete a guest, conversation, task or audit record

No destructive deletes, at any role

### Change roles, permissions, users or credentials

An agent cannot widen its own access

### Bulk-export the guest database

Reads are scoped and rate-limited, not a tap

### Change billing or account settings

Commercial settings are human-only

### Talk to a guest unsupervised as "the agent"

Operator-side infrastructure only

The canonical version lives on support.holidayhero.com/api/mcp and stays current as the server changes.

### Permission model

### A role, not a key.

An API key is a master key. Anyone holding it can do anything the key can do, and you find out afterwards.

An MCP connection is a role: the same platform role you would give a member of staff. A night manager's role at two properties is a night manager at two properties, whatever it is asked to do.

- Scope it to chosen properties, and switch individual tools off
- Set any write tool to draft-only — the agent proposes, a person disposes
- Agent actions sit in the same activity history as staff actions, marked as agent
- Revocable in one click, and revoking stops it mid-session

### Connection · Night desk agent

### Rows

Role

Night manager

Properties

2 of 14

send_message

Off

draft_guidebook_content

Draft only

Audit trail

Every call attributed

### The limits

### What an agent must never do.

Plainly, so you hear the limits from us first. None of these are configuration choices. They are absent from the server.

- Widen its own access
- Move money or touch card data
- Read identity documents
- Open a door
- Delete anything, or edit the record of what it did
- Publish guest-facing content no person has read

Reach data the platform does not already hold on your behalf. This is an interface onto your workspace, not a new collection of anything.

### How to turn it on

### Yourself, in about the time this page takes to read.

Nobody here is involved, and there is nothing to be admitted to.

# your assistant's MCP config

Included in the platform, from

€6.50 per unit per month

. No separate charge, no add-on tier.

### In our own house

### We run our own company on this.

Our product board, our sales pipeline and our marketing site are all operated through internal MCP servers, and have been for months.

- What broke
- An agent with a broad role on our product board was asked to tidy a backlog and archived a column of work that was still live. Nothing was lost, and it was our board rather than a property. The hard part was never the protocol. It was deciding what an agent must not be allowed to touch.
- What it changed
- Our marketing site server now refuses to write anything live. An agent creates and edits drafts, a person publishes. Guidebook content here works the same way.
- What is not ready
- The audit trail has no webhook or export yet, so reviewing agent activity happens in the app. Bulk reads across a large portfolio hit rate limits sooner than we would like. And an agent working a hundred content tasks does it in batches. All three are on the list.

### FAQ

### The questions operators ask.

### What is an MCP server and why would a hotel want one?

An MCP server publishes a list of tools an AI assistant can call inside another system. For a hotel it means the assistant your team already uses, whether Claude, ChatGPT or one you built, can read your reservations, guests, conversations, tasks, offers and guidebooks and act on them, instead of staff copying information between a chat window and your software. The value is in the dull work: the overnight queue, the tasks nobody reaches, the content gaps your guests keep finding.

### Can I connect my property to Claude or ChatGPT?

Yes. The HolidayHero MCP server works with any MCP-capable assistant, including Claude and ChatGPT, and with agents operators build themselves. It connects to your HolidayHero workspace rather than to your PMS directly, so it exposes the stay rather than the booking, and behaves the same across 25+ PMS integrations. You turn it on yourself: create a connection in your workspace settings, choose its role and properties, generate a token, and paste it into the assistant. It is included in the platform at no extra cost.

### Is it safe to give an AI agent access to guest data?

Not unconditionally, and we would not ask you to. The agent inherits a platform role, not a master key: the same permissions you would grant a member of staff, scoped to chosen properties, with individual tools switchable off and write tools settable to draft-only. Every action is attributed and auditable, and connections are revocable mid-session. Payments, card data, identity documents, door codes, deletions and permission changes are not in the tool list at all. GDPR, EU data residency and PCI DSS Level 1 apply as before. The MCP layer changes the interface, not the compliance posture.
