Back to Browse

Nomadstays MCP Server

Developer ToolsModerate6.8MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Search remote-work accommodations worldwide; Trusted Stay Partners can manage their own listings.

About

Search remote-work accommodations worldwide; Trusted Stay Partners can manage their own listings.

Remote endpoints: streamable-http: https://mcp.nomadstays.com/mcp

Security Report

6.8
Moderate6.8Moderate Risk

This MCP server provides accommodation search and management tools with appropriate authentication mechanisms for sensitive operations. The codebase demonstrates good security practices for token handling and database access control, but has some concerns: the `signupNomadStaysAccount` tool allows unauthenticated account creation without verification (relying only on email confirmation as a CAPTCHA substitute), and there are code quality issues with repetitive connection string parsing and broad exception handling. Permissions align well with the server's stated purpose of accommodation management.

3 files analyzed · 6 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

database

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

NomadStays MCP Server

An MCP (Model Context Protocol) server that gives AI agents access to Nomad Stays accommodation data — search by country, continent, location, lifestyle, budget, amenities, and availability.

Compatible with Claude, ChatGPT, and any MCP-aware AI agent.

Tools available

Full, current tool list: 76 tools total. See mcp.nomadstays.com for the complete reference with parameters — this README lists them grouped by category; keep both in sync when tools are added or changed.

Search, availability, and reference (public, no auth)

ToolDescription
getStaysByCountrySearch stays by 2-letter country code or country name
getStaysByContinentSearch by continent (Europe, Asia, Africa, etc.)
getStaysByLocationFree-text search across city, region, location description
getStaysByLifestyleFilter by lifestyle category (Digital Nomad, Beach, City…)
getStaysByBudgetFind stays within a budget for a given duration and currency
getStaysByAmenitiesFilter by amenities (WiFi, Pool, Air Conditioning…)
getStaysByWiFiSpeedFilter by minimum WiFi download speed (Mbps)
getStayByIDFull details for a single stay
getAllLifestylesList all available lifestyle categories
getAllAmenitiesList all available amenities
checkStayAvailabilityCheck if a stay is available for given dates
findNearestAvailabilityFind nearest available dates when preferred dates are taken
getAvailabilityByMonthAll available windows in a specific month
getRoomAvailabilityPer-room availability for a date range
getRoomAmenitiesFull amenity list for a specific room including WiFi metrics
searchHelpCenterSearch Nomad Stays help centre articles
getHelpCenterArticleFetch a specific help article by ID
listHelpCenterCategoriesList all help centre categories

Account signup for AI agents

If the person you're assisting doesn't have a Nomad Stays account yet, use the signupNomadStaysAccount tool to create one for them — no authentication, browser, or CAPTCHA required.

ToolDescription
signupNomadStaysAccountCreate a new Nomad Stays account for someone who doesn't have one yet. Returns pending_email_confirmation — no session or token.

Notes:

  • The account is created but inactive until the human clicks the confirmation link emailed to them — no session or token is returned by this call, and the agent cannot sign in or act as the user itself. This is the trust boundary: it proves a real inbox exists behind the request, standing in for the CAPTCHA/honeypot checks the public browser signup form uses instead.
  • Rate-limited to 2 requests per 5 minutes per source IP, server-side (Controllers/AgentSignupApiController.cs in the main repo).
  • Once the human confirms their email and logs in normally at www.nomadstays.com/Account/Login, they can request an MCP bearer token or complete OAuth (see "Trusted Stay Partner management tools" below) to let their own agent act on their behalf going forward.

Product, purchase, and application tools (require an MCP agent token)

Stay, Experience, and Coworking applications each go through the same list / get / create / save / submit lifecycle. Stay and Experience applications carry a one-time EUR 39 Application Fee (products 8 and 9); Coworking applications have no fee.

ToolDescription
getProductInfoLook up a product's price and purchasability (product 8 = Stay Application, 9 = Experience Application)
purchaseProductStart a purchase on the caller's own behalf; returns a checkoutUrl or resolves as "waived"
getPurchaseStatusCheck whether a purchase has been paid, verified fresh against the payment provider
listStayApplications / getStayApplication / createStayApplication / saveStayApplication / submitStayApplicationFull Stay Application lifecycle
listExperienceApplications / getExperienceApplication / createExperienceApplication / saveExperienceApplication / submitExperienceApplicationFull Experience Application lifecycle (min. 4-day experiences, enforced server-side)
listCoworkingApplications / getCoworkingApplication / createCoworkingApplication / saveCoworkingApplication / submitCoworkingApplicationFull Coworking Application lifecycle — no Application Fee

Booking (require an MCP agent token)

ToolDescription
quoteStayBookingPrice a prospective booking (package, dates, guests) before committing
bookStayCreate a booking on the caller's own behalf; returns a checkoutUrl or resolves as confirmed
getBookingStatusCheck whether a booking is confirmed, verified fresh against the payment provider
listMyBookingsList the caller's own bookings, including needsAction/checkoutUrl for anything still pending

Trusted Stay Partner management tools

The tools above are read-only and public (aside from applications, which are self-service but still token-gated). A separate set of tools lets an authorized Trusted Stay Partner's own AI agent read AND write their own listing data — with the same capabilities (no more, no less) as they have via the Nomad Stays admin UI. These require a bearer token issued from the partner's Operator Information page at www.nomadstays.com/stayadmin/user-profile-stays (2FA must be enabled on the account to request one), set as NOMADSTAYS_MCP_AGENT_TOKEN. Every call is scoped server-side to Stays the authenticated account actually owns.

ToolDescription
getMyStays / getMyStayDetail / updateStayDetailRead/update a Stay's core details (title, description, address, policies)
getMyStayOnboardingStatusThe six "Listing Completion" scores from the Stay dashboard (Stay Details, Availability, Rooms, Packages, Wi-Fi, Operator Information) plus an overall percentage — Wi-Fi is a test-freshness score, not a speed rating
getMyStayRooms / createStayRoom / updateStayRoom / deleteStayRoomFull room CRUD, including bed sizes, facilities, and photos
getRoomTypeOptions / getRoomFacilityOptionsReference lookups for valid room types/facilities (differ for boutique vs standard Stays)
uploadStayPhoto / getMyStayPhotos / deleteStayPhoto / reorderStayPhotosStay-level photo management, including reordering
deleteRoomPhoto / reorderRoomPhotosRoom-level photo management
getMyStayPackages / createStayPackage / updateStayPackage / deleteStayPackagePricing package CRUD — sellPrice is always server-computed, never directly settable
getCurrencyOptions / getBusinessModelOptionsReference lookups for package currency and business model
getMyStayOrganisationalData / updateStayOrganisationalDataAddress, check-in/out policy, cancellation policy, pets/children/parking rules
getStayTypeOptions / getCountryOptions / getCancellationPolicyOptions / getAdditionalInformationOptionsReference lookups for organisational-data fields
getMyStayContacts / updateStayContactsPublic-facing contact details
getMyStayFacilities / updateStayFacilities / getFacilityGroupsFacility checkboxes, grouped exactly as on the admin UI
getMyBusinessProfile / updateHostBusinessProfileBusiness profile (excludes personal, bank, and tax fields — never exposed via MCP)

Key rules: boutique Stays (Boutique1Boutique6 room types) and standard Stays are validated separately — always call getRoomTypeOptions first. Package price tiers are locked to 7/14/21/30 nights and don't all need to be set — a subset (e.g. 1-week-only) is valid. advertisingEndpoint only applies to Advertising-business-model Stays. Personal, bank, and tax details are permanently excluded from every tool.

Setup

1. Prerequisites

  • Node.js 20+
  • Access to a Nomad Stays SQL Server database (hosted on Coolify/Hetzner)

2. Install

git clone https://github.com/nomadstays/nomadstays-mcp-server.git
cd nomadstays-mcp-server
npm install

3. Configure

cp .env.example .env
# Edit .env and set your NOMADSTAYS_DB_CONNECTION string

4. Build

npm run build

5. Run (stdio mode — for Claude Desktop / local MCP clients)

node build/index.js

6. Run (HTTP mode — for hosted / remote deployments)

PORT=8080 node build/index.js

HTTP endpoints:

  • POST /mcp — MCP Streamable HTTP transport
  • GET /health — Health check
  • GET /api/mcp/stats/daily — Daily usage stats
  • GET /api/mcp/stats/tools — Per-tool usage stats

Claude Desktop configuration

Copy claude_desktop_config.example.json, update the path and connection string, then merge into your claude_desktop_config.json:

{
  "mcpServers": {
    "nomadstays": {
      "command": "node",
      "args": ["/path/to/nomadstays-mcp-server/build/index.js"],
      "env": {
        "NOMADSTAYS_DB_CONNECTION": "Server=tcp:..."
      }
    }
  }
}

Deploy

The production Nomad Stays deployment runs its MCP servers as Docker containers on Coolify (self-hosted on Hetzner) rather than Azure App Service. This repo doesn't include a Dockerfile of its own — containerize it with a standard Node.js build (Node 20+, npm run build, run dist/index.js) and deploy to any Docker-capable host, setting NOMADSTAYS_DB_CONNECTION (and PORT/HTTP_PORT for HTTP mode) as environment variables on the target platform.

Tech stack

Reviews

No reviews yet

Be the first to review this server!