MCP server for Marriott - let AI agents book hotels
SaferSkills independently audited mcp-marriott (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server for Marriott Hotels — let AI agents search hotels, manage reservations, check in, and interact with the Marriott Bonvoy loyalty program via browser automation.
Built by Strider Labs.
This MCP server enables AI agents (Claude, etc.) to:
| Tool | Description |
|---|---|
status | Check login status and Bonvoy session info |
login | Log in to Marriott Bonvoy (auto or manual) |
logout | Clear saved session and cookies |
search_hotels | Search hotels by destination, dates, guests |
get_hotel_details | Get amenities, policies, check-in times |
get_room_options | View available room types and rates |
select_room | Choose a room before checkout |
add_extras | Add parking, breakfast, late checkout, etc. |
checkout | Complete booking (requires explicit confirmation) |
get_reservation | Retrieve existing reservations |
modify_reservation | Change dates or room type |
cancel_reservation | Cancel a booking |
check_in | Mobile check-in with room preferences |
get_bonvoy_status | Points balance, tier, nights to upgrade |
redeem_points | Book award stays with Bonvoy points |
get_stay_history | View past stays and points earned |
npm install -g @striderlabs/mcp-marriottOr run directly with npx:
npx @striderlabs/mcp-marriottnpx playwright install chromiumSet environment variables for automatic login:
export MARRIOTT_EMAIL="[email protected]"
export MARRIOTT_PASSWORD="yourpassword"Without these, the login tool returns a URL for manual browser login.
Add to ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"marriott": {
"command": "npx",
"args": ["@striderlabs/mcp-marriott"],
"env": {
"MARRIOTT_EMAIL": "[email protected]",
"MARRIOTT_PASSWORD": "yourpassword"
}
}
}
}{
"mcp": {
"servers": {
"marriott": {
"command": "npx",
"args": ["@striderlabs/mcp-marriott"],
"env": {
"MARRIOTT_EMAIL": "[email protected]",
"MARRIOTT_PASSWORD": "yourpassword"
}
}
}
}
}Search for Marriott hotels in Tokyo from July 10-15 for 2 adultsFind me a room at the W Hotel Times Square for next weekend, then book the cheapest optionHow many Bonvoy points do I have and what's my current tier?Use my Bonvoy points to book a standard room at the Marriott Marquis in NYC for March 20-22Show me my upcoming reservations and cancel the one in ChicagoCookies are saved to ~/.striderlabs/marriott/ so sessions persist between runs. To log out:
Use the logout toolOr delete the directory:
rm -rf ~/.striderlabs/marriott/Destructive actions require explicit confirmation:
checkout — requires confirm: truemodify_reservation — requires confirm: truecancel_reservation — requires confirm: trueredeem_points — requires confirm: trueWithout confirm: true, these tools return a preview of what would happen, giving users a chance to review before committing.
git clone https://github.com/markswendsen-code/mcp-marriott
cd mcp-marriott
npm install
npm run build
node dist/index.js| Variable | Description |
|---|---|
MARRIOTT_EMAIL | Marriott Bonvoy account email |
MARRIOTT_PASSWORD | Marriott Bonvoy account password |
MIT — Strider Labs
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.