Skip to content

MCP Server ​

KOOB exposes its v3 API as a Model Context Protocol server, so AI assistants (claude.ai, Claude Desktop, Claude Code, ChatGPT connectors) can search the catalog, check availability and create bookings on your behalf.

Endpoint ​

EnvironmentURL
Productionhttps://mcp.koob.tech/mcp
Staginghttps://mcp.v2koob.tech/mcp

The transport is Streamable HTTP (JSON responses, stateless). One tool is exposed per v3 operation; tool schemas mirror the API reference.

Authentication ​

Two options:

OAuth (hosted assistants). Add the endpoint URL as a custom connector in claude.ai or ChatGPT. The assistant registers itself, then sends you to KOOB to log in and approve the connection. Tools run with your user account: your organizations, roles and permissions apply. The connection is tied to the KOOB session you approved it from: it ends when that session expires or when you log out, and you will be asked to approve it again. A connection approved while impersonating a user ends with the impersonation.

API key (integrations and scripts). Send your organization API key in the x-api-key header (or as Authorization: Bearer), exactly like on the REST API. For Claude Desktop or Claude Code:

json
{
  "mcpServers": {
    "koob": {
      "type": "http",
      "url": "https://mcp.koob.tech/mcp",
      "headers": { "x-api-key": "<your API key>" }
    }
  }
}

Several organizations ​

If your account or API key belongs to several organizations (for example one per country), every tool gets an actingOrganizationId input. Its allowed values are your own organizations, so the assistant can see what to choose from.

  • Reads without it act as your first organization. An API key linked to several organizations has no default: name one on reads too.
  • Writes (creating or changing hotels, experiences, bookings…) must name the organization. A write without it is refused, so nothing lands in the wrong organization by accident.
  • Groups: a group member sees the group first (labelled "all of <group name>"), then each child. Reads default to the whole group. Writes list only the children and refuse the group.

The input is sent to the API as the X-Organization-Id header (see Authentication). A client that sets custom headers can also send X-Organization-Id on the whole connection; actingOrganizationId on a call still takes precedence.

Rate limits are the same as on the REST API. Bookings created through MCP are real bookings: only grant access to assistants you trust.