Otto Travel MCP server icon

Otto Travel

by Otto Travel

Productivity14 tools

Search and book real flights and hotels from your AI assistant. Two of its fourteen tools complete a purchase against a card you store with Otto in advance — the first connector in this catalogue that can commit a user's money to a third party.

Verified connector

Listed by Anthropic as a partner connector in its Connectors Directory.

Connection checked by Agentman on .

Anthropic states this reflects the level of review a connector received, not a security audit.

Connect Otto Travel via MCP

https://api.ottotheagent.com/mcp

Works in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.

Otto Travel Tools & Capabilities (14)

Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.

Limits

  • book_flight and book_hotel complete real purchases against a card stored with Otto. Otto documents a confirmation step before money moves; that step is conversational, not a separate tool call, and we did not test it. Your client's per-call approval prompt is the gate you control.
  • Otto's own connection guide advises clicking "Always allow" in Claude's permission prompt (MCP Connectors, fetched 2026-08-19). For a connector that can buy airline tickets, that advice removes your independent gate.
  • cancel_booking releases the reservation, not necessarily the money. Otto states refunds follow the underlying airline or hotel's fare rules and that it surfaces them before you commit. We give no travel or consumer-rights advice and assert nothing about what any airline or law requires.
  • Two OAuth scopes for fourteen tools. mcp:write covers booking and cancelling alike; no read-only grant is expressible over a surface that can spend.
  • No annotations could be read. The endpoint requires authentication, so we could not confirm whether Otto marks its booking tools destructiveHint or its search tools readOnlyHint. Treat all fourteen as unannotated for planning purposes.
  • The tool listing may be incomplete. Otto markets rental-car booking prominently and no car tool appears in the fourteen. We could not establish whether the listing is short or the feature is absent over MCP.
  • The documentation is a Google Doc with no version history, no last-modified date, and no stable revision to cite. It was readable on 2026-08-19 and could change or disappear without notice.
  • Otto's published pricing is inconsistent between its own pages. The connector documentation says free for the first year, then $10 a month; the product pages say free during early access with no subscription. Both were live on 2026-08-19. Check what you are actually agreeing to at sign-up.
  • Otto documents two capability gaps of its own on the change-and-cancel path: it does not argue fees with airlines, and it cannot make name changes on tickets, which it attributes to airline restriction. It states 95% of changes complete without a human agent.
  • The privacy policy could not be read as text. app.ottotheagent.com/privacy returned 200 but renders client-side; our fetch recovered only the page title. Otto's binding data commitments live there, not on the marketing pages cited above.

Frequently asked questions

Does the Otto Travel MCP server actually spend my money?

Yes. Otto books real, ticketed flights and real hotel rooms against a payment method you store with Otto in advance, and its documentation says so plainly. This is not a quote engine or a hold — the vendor describes an average of 7.9 minutes from first message to confirmed ticket. Two of the fourteen tools complete purchases, and airline fares are frequently non-refundable.

Is there a confirmation step before Otto books a flight?

Otto states there is one. Its documentation says every booking requires your explicit confirmation and that the assistant cannot spend without your approval. That gate is a conversational turn inside Otto's own flow, not a separate confirm tool in the MCP surface, so we could not verify its enforcement without booking. Keep your client's per-call approval prompt enabled as an independent second gate.

Whose payment method does Otto charge when an agent books?

Yours, stored with Otto in advance. Otto's documentation requires a completed traveler profile and a saved payment method at its web app before any booking will run, and describes card details as tokenized in a PCI-compliant vault. There is no redirect to a payment page and no per-booking card entry. The agent never sees a card number, only a stored token.

Can cancel_booking undo a flight Otto already bought?

It can cancel the reservation; it cannot decide what you get back. Otto states that changes follow the fare rules of the underlying airline or hotel, that it shows fare conditions and refund eligibility before you commit, and that it reports what is recoverable as credit or partial refund. The refund outcome belongs to the carrier, not to the tool.

What personal data does Otto need before it can book?

A completed traveler profile. Otto's documentation names your legal name, date of birth and contact information, plus a payment method, all supplied at its web app rather than through the connector. Loyalty numbers attach to reservations and can be added through chat. Searching works with an incomplete profile; booking does not. Otto states it does not sell traveler data.

How many tools does the Otto Travel MCP server expose?

Fourteen in Anthropic's directory snapshot, and we could not confirm that number live because the endpoint requires authentication. Otto's marketing describes rental-car booking as a first-class capability, but no car tool appears among the fourteen. Either the listing is incomplete or that feature is unavailable over MCP — we could not establish which without connecting an account.

Can I give Otto read-only access so it can search but not book?

No. Otto's OAuth metadata advertises exactly two scopes, one for reading and one for writing, and the write scope covers everything the connector can do — including booking and cancelling. There is no narrower grant that separates searching flights from buying one. A user who wants search-only behaviour has to enforce it at the client's approval prompt.

Sources

  • Otto in Claude, MCP documentation — https://docs.google.com/document/d/1qLCBH-k2XmXN739EFtiWY2ih_Sft756OPDoKnNLjOt8/edit (fetched 2026-08-19 via the document's plain-text export; the URL Anthropic's directory publishes as this connector's documentation. Source of the connection steps, the account and profile requirements, the traveler-profile fields, the stored-payment-method statement, the confirm-before-change statement, the pricing figures, and the troubleshooting guidance. This is a Google Doc with no version history — see the sourcing note above) · retrieved 2026-08-19
  • Otto, MCP Connectors — https://www.ottotheagent.com/mcpconnections (fetched 2026-08-19; source of the Claude and ChatGPT connection walkthroughs, the "Always allow" advice, and the generic MCP-client instructions naming the endpoint and transport) · retrieved 2026-08-19
  • Otto, How to Talk to Otto — https://www.ottotheagent.com/how-to-talk-to-otto (fetched 2026-08-19; source of the stored-payment-and-profile statement, the conversational booking and cancellation examples, the mid-conversation preference and loyalty-number examples, the company-policy and rate-cap references, and the rental-car request example) · retrieved 2026-08-19
  • Otto, Is Otto Safe? How Otto Handles Payments and Data — https://www.ottotheagent.com/product-marketing/is-otto-safe-how-otto-handles-payments-and-data (fetched 2026-08-19; source of the explicit-confirmation claim, the propose-approve-then-spend sequence, the PCI vault and tokenization statement, the data-use and no-sale statements, the deletion-on-request statement, and the Direct Travel handoff disclosure) · retrieved 2026-08-19
  • Otto, Book Flights by Chat — https://www.ottotheagent.com/product-marketing/book-flights-by-chat-under-8-minutes-start-to-confirmed (fetched 2026-08-19; source of the 7.9-minute mean and 6.9-minute median booking times, the measurement window, the real-ticketed-flights answer, and the GDS inventory statement) · retrieved 2026-08-19
  • Otto, Change or Cancel Any Booking in One Request — https://www.ottotheagent.com/product-marketing/change-or-cancel-any-booking-in-one-request (fetched 2026-08-19; source of the fare-rules-surfaced-before-commit statement, the confirm-then-execute sequence, the 95% figure, the non-refundable recoverability answer, and the two stated capability gaps) · retrieved 2026-08-19
  • Otto, Otto Works Inside Your AI Assistant — https://www.ottotheagent.com/product-marketing/otto-works-inside-your-ai-assistant (fetched 2026-08-19; source of the MCP-specific confirmation claim, the same-account statement, and the disruption-monitoring statement for bookings made through an assistant) · retrieved 2026-08-19
  • Otto, product overview — https://www.ottotheagent.com/product (fetched 2026-08-19; source of the 5.2-minute hotel booking average, the Spotnana inventory statement, the Direct Travel human-agent backing, and the rental-car capability that has no corresponding tool in the listing) · retrieved 2026-08-19
  • Live anonymous probe — 2026-08-19: a single anonymous POST to https://api.ottotheagent.com/mcp returned HTTP 401 with a www-authenticate Bearer challenge naming resource_metadata and scope="mcp:read". No credentials were supplied, no OAuth flow was begun, and no tool on this server was invoked at any point · retrieved 2026-08-19
  • Live RFC 9728 protected-resource descriptor — https://api.ottotheagent.com/.well-known/oauth-protected-resource (fetched 2026-08-19; the path-append form returns a byte-identical body, the path-insert form returns HTTP 401 rather than a 404). Source of the two named scopes and the resource identifier · retrieved 2026-08-19
  • Live RFC 8414 authorization-server metadata — https://api.ottotheagent.com/.well-known/oauth-authorization-server (fetched 2026-08-19; source of the issuer, the three grant types, the S256 challenge method, and the advertised registration endpoint) · retrieved 2026-08-19
  • www.ottotheagent.com/robots.txt (fetched 2026-08-19; allows all crawlers with three disallowed marketing paths, points at the site sitemap — which is how every Otto sub-URL above was located rather than guessed — and carries no Content-Signal line, so no use-side restriction is expressed. No llms.txt exists at the marketing domain, which returns a 404 page, and no documentation subdomain resolves) · retrieved 2026-08-19
  • Anthropic connector directory — https://claude.ai/directory/a758ddcc-4510-4774-b316-9ea13af188bc (snapshot 2026-08-16; source of the fourteen tool names, the "Read and write" permissions label, the partner tier, the streamable-HTTP transport, the client list, the author and support contacts, and an empty prompt list) · retrieved 2026-08-16
  • Otto privacy policy — https://app.ottotheagent.com/privacy (fetched 2026-08-19; returned HTTP 200 but renders client-side and yielded no readable policy text, so nothing on this page is sourced from it) · retrieved 2026-08-19

Use in Agentman

Connect once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.

Open in Agentman Studio

Server Info

Category
Productivity
Developer
Otto Travel
Tools
14
Domain
api.ottotheagent.com

Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.