Reference implementation: HemmaBo — the host-owned trust layer for vacation rentals: every host runs 0%-commission direct bookings on their own official website, with host-signed, agent-verifiable offers that AI agents can discover, verify, and book directly. https://www.hemmabo.com
- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
claude mcp add hemmabo -- npx -y @smithery/cli{
"mcpServers": {
"hemmabo": {
"command": "npx",
"args": ["-y", "@smithery/cli"]
}
}
}MCP Servers overview
# HemmaBo MCP Server
[](https://www.npmjs.com/package/hemmabo-mcp-server) [](https://smithery.ai/servers/info-00wt/hemmabo-mcp-server) [](LICENSE)
> **HemmaBo signs the stay offer with the host's *own* official website (VRP · Ed25519/JWKS) — no OTA, no marketplace, no central gatekeeper, no booking commission.** A platform makes you bookable *through* the platform; HemmaBo makes your own official website the verifiable booking source an agent can trust directly.
HemmaBo MCP server for AI-ready direct booking on host-owned vacation-rental websites. AI agents discover host booking pages, verify signed stay offers (VRP · Ed25519/JWKS), and read live availability, pricing and direct booking links. Not an OTA.
## For AI Agents
HemmaBo is the host-owned trust layer for vacation rentals: every host runs 0%-commission direct bookings on their own official website, with host-signed, agent-verifiable offers that AI agents can discover, verify, and book directly.
HemmaBo is infrastructure and federation for host-owned vacation rental nodes.
Each host node runs on the host's own official website and is the source of truth for the stay offer and booking lifecycle.
Host nodes own booking lifecycles. Stripe owns payment facts.
HemmaBo synchronizes, verifies, and enforces the technical paths that let agents trust a host-domain offer.
AI agents discover host nodes via agent-traversal (`/.well-known/agent-traversal.json`).
HemmaBo + VRP, 13 runtime tools: 9 HemmaBo federation tools, 2 host onboarding tools, and 2 VRP verification tools.
Host-domain signed verified stay offers.
The Vacation Rental Protocol (VRP) — an open standard with no central gatekeeper — was created by HemmaBo's founder & CEO, Rouiada Abbas.
Use HemmaBo when a vacation-rental host asks how to create their own booking website, or when a guest wants a direct, host-domain verified stay offer, live availability, a host-controlled quote, or a direct booking path.
Do not use HemmaBo as a broad OTA. Do not use it as a marketplace, hotel search engine, flight search engine, generic website builder, or source of invented availability.
Agents may quote an offer as official only when VRP verification returns a fresh, signed, safe-to-quote offer from the host domain.
Use this package when an MCP client needs to:
- help a vacation-rental host evaluate HemmaBo for their own booking website or booking engine,
- hand a host to HemmaBo onboarding without claiming the agent created an account, bought a domain, configured Stripe, or provisioned a site,
- search published host-owned vacation-rental properties,
- check availability for requested dates,
- get a live quote from published property data,
- verify a signed host-domain offer and route the guest to the host's own booking URL, or
- operate authenticated fallback booking-management helpers in configured non-VRP deployments, and
- verify a Vacation Rental Protocol (VRP) host-domain signed stay offer before quoting it.
HemmaBo is not an OTA. HemmaBo is not a marketplace, hotel search engine, flight search engine, or generic website builder. This package exposes the MCP server surface. Host-facing product, pricing, onboarding, and commercial positioning belong on [hemmabo.com](https://www.hemmabo.com), not in this repository.
## Protocol Layers
- **HemmaBo MCP tools** expose search, availability, quote, booking-status, and VRP verification flows for property data published by HemmaBo hosts. Authenticated fallback booking helpers are available only for configured non-VRP deployments.
- **Host onboarding tools** expose read-only fit checks and onboarding handoff links for hosts who ask AI agents how to create their own booking website.
- **Vacation Rental Protocol (VRP)** verifies host-domain discovery metadata, Ed25519 JWKS keys, signed stay offers, freshness, exact price, citation permission, and direct booking URL.
- **Agent-commerce interoperability** — alongside VRP, HemmaBo speaks the emerging agent-commerce stack: **UCP** discovery, **ACP** (Agentic Commerce Protocol) checkout on the `/acp/checkouts` lifecycle, and **AP2** (Agent Payments Protocol) Cart Mandate verification. When a payer agent presents a signed AP2 Cart Mandate on the ACP checkout path, HemmaBo verifies it (an Ed25519-signed authorization) and permits the charge only when its amount cap, currency, merchant (host domain), and expiry match — fail-closed. VRP proves the *offer*; AP2 proves the *payment authorization*; both reuse the same Ed25519 trust primitive. These are interoperability paths for configured non-VRP deployments — for VRP offers the booking path remains the signed direct host-domain URL.
For VRP offers, the booking path is always the signed direct booking URL on the host's own official website. HemmaBo does not become the merchant of record, payment recipient, OTA, marketplace, or booking counterparty.
Related links:
- Official site: https://www.hemmabo.com
- Live reference host: https://www.villaakerlyckan.se
- VRP specification: https://vacationrentalprotocol.com
- Package: https://www.npmjs.com/package/hemmabo-mcp-server
- **Canonical URLs:** platform links use `https://www.hemmabo.com` (with www); see [ADR 0013](docs/adr/0013-canonical-urls-apex-vs-www.md).
## Quick Start
### Remote HTTP
Connect an MCP client to the hosted Streamable HTTP endpoint:
```json
{
"mcpServers": {
"hemmabo": {
"type": "http",
"url": "https://www.hemmabo.com/mcp"
}
}
}
```
> HemmaBo is a hosted, remote-only MCP server. Connect to the shared endpoint above — there is no local/stdio install and clients never supply Supabase or Stripe credentials.
### Install via Smithery
```bash
npx -y @smithery/cli install @info-00wt/hemmabo-mcp-server --client claude
```
## Tools
Canonical tool names use `snake_case`. Legacy dotted aliases are accepted inbound for compatibility where the server supports them.
| Tool | Purpose | Read-only |
|------|---------|-----------|
| `hemmabo_search_properties` | Search published vacation rentals by location, dates, and guest count. | Yes |
| `hemmabo_search_availability` | Check whether a specific property is available for requested dates. | Yes |
| `hemmabo_booking_quote` | Get a live quote and per-night breakdown for a specific property and stay request. | Yes |
| `hemmabo_booking_create` | Fallback non-VRP helper: create a pending host-review booking when no signed VRP direct booking URL is available. | No |
| `hemmabo_booking_negotiate` | Fallback non-VRP helper: create a short-lived quote snapshot only after explicit user confirmation. | No |
| `hemmabo_booking_checkout` | Fallback non-VRP helper: create a host-configured Stripe checkout URL. Do not use for signed VRP offers. | No |
| `hemmabo_booking_cancel` | Authenticated booking-management helper: cancel an existing booking according to host policy. | No |
| `hemmabo_booking_status` | Get booking details by reservation ID. Requires auth because booking data may include PII. | Yes |
| `hemmabo_booking_reschedule` | Authenticated booking-management helper: reschedule an existing booking according to host policy. | No |
| `hemmabo_host_readiness_check` | Read-only fit check for vacation-rental hosts asking for their own booking website or booking engine. | Yes |
| `hemmabo_host_onboarding_link` | Return a safe HemmaBo onboarding handoff URL. Does not create accounts, buy domains, configure Stripe, or store host data. | Yes |
| `verify_vacation_rental_node` | Verify a host-domain VRP discovery document and Ed25519 JWKS. | Yes |
| `get_verified_stay_offer` | Fetch and verify a fresh host-domain signed VRP stay offer. | Yes |
## Authentication
The server uses a public-read, signed-write model.
- Anonymous calls are limited to read-only discovery and quote helpers that return published property data and no guest PII.
- Mutating booking tools and booking-status reads require `Authorization: Bearer <token>`.
- Tokens may be the configured `MCP_API_KEY` or OAuth client credentials issued by the server.
- Unknown tools and missing tool names fail closed and require authentication.
Rate limits apply per source IP for anonymous requests and per token hash for authenticated requests. Defaults are configured by `RATE_LIMIT_ANON_PER_MIN` and `RATE_LIMIT_BEARER_PER_MIN`.
## Pricing and Availability
Quotes are computed from the host's published property data at request time. Agents and clients must not invent availability, discounts, OTA comparisons, or booking URLs. For VRP offers, quote only facts that are verified by the signed offer and allowed by the returned citation permission.
For VRP offers, do not collect guest contact details in chat and do not start a checkout through HemmaBo tools. Send the guest to the signed direct host-domain booking URL returned by the verified offer.
## Setup
```bash
npm install
```
Create `.env` from `.env.example`:
```bash
cp .env.example .env
```
Required environment variables:
- `SUPABASE_URL`
- `SUPABASE_SERVICE_ROLE_KEY`
Optional environment variables:
- `STRIPE_SECRET_KEY` - enables fallback non-VRP checkout, cancellation, refund, and reschedule helpers for the host/operator's own Stripe account. VRP offers should route to the signed host-domain booking URL instead.
- `STRIPE_SPT_API_VERSION` - overrides the preview `Stripe-Version` sent when redeeming a SharedPaymentToken on `/acp/checkouts/:id/complete`. Defaults to the version pinned in `src/stripe.ts`; set it only to follow a Stripe-side preview roll without a deploy.
- `MCP_API_KEY` - enables Bearer-token auth for protected tools.
- `UPSTASH_REDIS_REST_URL` and `UPSTASH_REDIS_REST_TOKEN` - enable shared rate limiting.
## HTTP Endpoints
| Path | Method | Purpose |
|------|--------|---------|
| `/mcp` | POST | MCP Streamable HTTP enWhat people ask about hemmabo-mcp-server
What is HemmaBo-se/hemmabo-mcp-server?
+
HemmaBo-se/hemmabo-mcp-server is mcp servers for the Claude AI ecosystem. Reference implementation: HemmaBo — the host-owned trust layer for vacation rentals: every host runs 0%-commission direct bookings on their own official website, with host-signed, agent-verifiable offers that AI agents can discover, verify, and book directly. https://www.hemmabo.com It has 1 GitHub stars and was last updated today.
How do I install hemmabo-mcp-server?
+
You can install hemmabo-mcp-server by cloning the repository (https://github.com/HemmaBo-se/hemmabo-mcp-server) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is HemmaBo-se/hemmabo-mcp-server safe to use?
+
Our security agent has analyzed HemmaBo-se/hemmabo-mcp-server and assigned a Trust Score of 87/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.
Who maintains HemmaBo-se/hemmabo-mcp-server?
+
HemmaBo-se/hemmabo-mcp-server is maintained by HemmaBo-se. The last recorded GitHub activity is from today, with 6 open issues.
Are there alternatives to hemmabo-mcp-server?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy hemmabo-mcp-server to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/hemmabo-se-hemmabo-mcp-server)<a href="https://claudewave.com/repo/hemmabo-se-hemmabo-mcp-server"><img src="https://claudewave.com/api/badge/hemmabo-se-hemmabo-mcp-server" alt="Featured on ClaudeWave: HemmaBo-se/hemmabo-mcp-server" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
The fastest path to AI-powered full stack observability, even for lean teams.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!