Technical note: Ordina's MCP servers

How Ordina's two Model Context Protocol servers work, their endpoints, authentication, tools, and how to connect a client or build on them.

Ordina speaks the Model Context Protocol (MCP), the open standard AI assistants use to call tools. There are two servers: a public one for customers' assistants and a private one for business owners.

  1. ClientClaude, ChatGPT or your own agent.
  2. MCP over HTTPJSON-RPC 2.0 with POST.
  3. OrdinaTools run against live data.
  4. The businessBookings and orders land in the dashboard.

The two servers

Customer server Owner server
Endpoint https://www.useordina.com/api/mcp https://www.useordina.com/api/mcp/owner
Who uses it Any assistant acting for a customer The business owner's own assistant
Auth None OAuth 2.1 bearer token
Scope Public directory, one business at a time by handle The owner's own business only, from the token
Plan Works for every listed business Owner on Pro or Business; checked on every request

Transport

Both use MCP's Streamable HTTP transport, stateless: send one JSON-RPC 2.0 message or a batch with POST and get JSON back. GET answers 405 because the servers never open a server-to-client stream. Supported protocol versions: 2025-06-18, 2025-03-26 and 2024-11-05. CORS is open, so browser-based clients work.

POST https://www.useordina.com/api/mcp
Content-Type: application/json

{"jsonrpc":"2.0","id":1,"method":"tools/call",
 "params":{"name":"get_business","arguments":{"handle":"ordina"}}}

Customer tools

Tool What it does
search_businesses Search the public directory by name, service or city; returns handles
get_business Details, hours, services with prices, policies, products, and which services can be booked directly
check_availability Real open times for one service over the next two weeks, in the business's timezone
book_appointment Books a service; needs the customer's name and phone with country code
place_order Orders products
get_store_checkout_link A link to the business's Shopify or WooCommerce checkout with items in the cart
get_booking_link The business's booking page
check_order_status Status of an order

Bookings from assistants are marked AI assistant in the business's Messages. Calls are rate limited per IP, with a tighter limit on real bookings.

Owner server: authentication

The owner server follows the MCP authorization spec, so clients like Claude connect with no configuration beyond the URL:

  1. A request without a token gets 401 with a WWW-Authenticate header pointing to the protected-resource metadata (RFC 9728) at /.well-known/oauth-protected-resource.
  2. The client reads the authorization-server metadata at /.well-known/oauth-authorization-server.
  3. It registers itself with dynamic client registration (RFC 7591) at /api/oauth/register.
  4. It sends the owner to /oauth/authorize with PKCE (S256), which is required. The owner signs in and approves; scope is business.
  5. It exchanges the code at /api/oauth/token (authorization_code), and later refreshes with refresh_token. Tokens can be revoked at /api/oauth/revoke.
  6. Every call carries Authorization: Bearer and the access token. The business comes from the token alone.

The plan and account are checked on every request, so a lapsed or suspended business stops working at once. Owners can see and revoke connections under Integration, AI assistants, Settings.

Owner tools

They are the same tools the dashboard Secretary uses, bound to the owner's business: get_my_business, list_appointments, list_orders, list_payments, get_revenue, rank_customers, get_customer_summary, get_customer_insight, list_services, list_categories, update_service, hide_service, unhide_service, add_service, delete_service, create_category, update_faq, draft_email, invite_team_member, update_appointment_status, reschedule_appointment, cancel_appointment, mark_no_show, update_order_status, cancel_order, block_time, list_blocked_time, unblock_time, list_team, and photo tools (list_service_photos, add_service_photo, get_photo_upload_link, remove_service_photo).

Irreversible actions are confirmed in code, not in the prompt. Adding or deleting an item, emailing someone and inviting staff return a proposal instead of acting. Nothing happens until the client calls confirm_action with that proposal after the owner says yes.

Implementing a client

  • Claude: Settings, Connectors, Add custom connector, and the URL above. The OAuth flow runs by itself.
  • Your own agent: use any MCP client library with the Streamable HTTP transport. For the owner server, implement the OAuth flow above, or use a library that does. Call initialize, then tools/list to read the current tool schemas; do not hard-code them, they grow.
  • Customer server only? No auth: POST JSON-RPC and go. Start with search_businesses or get_business with a known handle.

For plain REST access to your own data without MCP, see API keys.

Did this answer it?If not, write to help@useordina.com with your handle, or contact us. A person replies.
Contact us