Hostaway Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Hostaway Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Read-only, hospitality-shaped MCP server for Hostaway.
This repo owns the operator product only: local/npm stdio, six read-only tools, no Cloudflare Worker, and no Seascape booking surface.
Make Codex and Claude useful in real Hostaway workflows without hand-wiring raw API calls every time.
V1 is intentionally narrow:
list_unread_guest_threadsget_conversation_contextget_reservation_briefget_listing_briefsearch_reservationssearch_conversationsnpm install
npm test
npm run check
npm run buildRun the stdio server locally:
HOSTAWAY_API_TOKEN=your-token-here node dist/cli.jsCreate a local npm package tarball:
npm packAfter publish, run without cloning:
npx hostaway-mcpFor local MCP clients, provide HOSTAWAY_API_TOKEN through the environment and spawn the published npm package over stdio.
The snippets below are pinned to the current published version:
[email protected]Update that version intentionally when you upgrade.
Edit ~/Library/Application Support/Claude/claude_desktop_config.json.
If you already have top-level keys like preferences, keep them and add mcpServers alongside them:
{
"mcpServers": {
"hostaway": {
"command": "npx",
"args": ["-y", "[email protected]"],
"env": {
"HOSTAWAY_API_TOKEN": "your-token-here"
}
}
}
}Restart Claude Desktop after saving the file.
Edit ~/.codex/config.toml and add:
[mcp_servers.hostaway]
command = "npx"
args = ["-y", "[email protected]"]
[mcp_servers.hostaway.env]
HOSTAWAY_API_TOKEN = "your-token-here"Verify the server is registered:
codex mcp listIf you want to run the repo checkout instead of npm, point the client at the built CLI directly:
{
"command": "node",
"args": ["/absolute/path/to/hostaway-mcp/dist/cli.js"],
"env": {
"HOSTAWAY_API_TOKEN": "your-token-here"
}
}| Variable | Required | Default | Description |
|---|---|---|---|
HOSTAWAY_API_TOKEN | Yes | — | Hostaway API token used to authenticate all requests. |
HOSTAWAY_BASE_URL | No | Hostaway production URL | Override the API base URL (useful for testing). |
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.