Yardi Virtuoso
Query Yardi property data and file maintenance work orders from an AI agent. Anthropic lists 5 tools, three of them work-order shaped, but the same listing advertises portfolio analysis and invoice approval that no listed tool performs. OAuth sign-in, identity-only scopes.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Connect Yardi Virtuoso via MCP
https://mcp.virtuoso.ai/mcpWorks in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.
Yardi Virtuoso Tools & Capabilities (5)
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
Limits
- The tool listing does not cover the advertised product. Anthropic's own connector page describes portfolio NOI analysis, market benchmarking and an invoice approval queue. None of the five listed tools performs any of them. Five is a floor, and a risk assessment built on the verb census is measuring the listing rather than the connector.
- Yardi's documentation for this server is not publicly readable, so it publishes no tool list we could diff. The nominated documentation URL returns HTTP 401 and renders Intercom's
not-authorizedpage. This is the "no vendor enumeration" case, and it is not a case of us failing to find the page — the help centre's own payload declaresallContentRestrictedas true with an empty collection list, which is Intercom stating that the entire article set is private. - We could not read tool schemas or safety annotations. Cloudflare returned 403 to our anonymous
initializerequest before it reached the MCP server, so no parameter-level detail is published here. The directory's own probe of this endpoint recorded the same 403. - The OAuth scopes carry no capability information. Four standard OpenID Connect values, no application scope, and the identical list on two sibling servers that Anthropic records as having different permissions. Nothing at the grant separates reading a work order from creating one.
- What a work order write actually triggers is unresolved. We could not establish whether creating one dispatches a vendor or incurs a cost, or whether marking one complete releases an invoice. Yardi's product documentation is behind a Cloudflare challenge on every path we tried, including
robots.txt. We did not attempt to bypass it. - Whether resident data is reachable is unresolved. No listed tool names a person record, and the connector page never says resident, tenant or lease. But work orders attach to occupied units, and the advertised financial surface would sit beside resident ledgers if it exists. We did not authenticate, so we could not check.
- Yardi's privacy statement does not govern resident data. It excludes "Client Data" — resident and tenant information — from its scope entirely. The applicable terms are your own agreement with Yardi, not the public document.
virtuoso.aiyields nothing to a reader. Every path we requested, including an invented one, returned a byte-identical 1,893-byte single-page-app shell. All of them are HTTP 200, and none of them means anything.- Three Yardi connectors share this host and are easy to confuse. Yardi Virtuoso (5 tools, Read and write), Yardi Matrix (33 tools, Read) and Yardi Deal Manager (14 tools, community tier — not in this catalogue). They are separate listings with separate endpoints.
- No rate limits, plan gates or pricing are documented publicly. We found none, which is not the same as there being none.
Sources
- Anthropic connector page for Yardi Virtuoso, vendor-supplied description and the three example prompts (retrieved 2026-08-23). Server-rendered; text quoted from the page HTML. · retrieved 2026-08-23
- Anthropic Connectors Directory entry — , read from our directory snapshot dated 2026-08-16, which supplies the five tool names, the
Read and writepermissions value and the recorded 403 endpoint probe. · retrieved 2026-08-16 - Yardi Virtuoso MCP technical documentation guide (retrieved 2026-08-23). Returned HTTP 401; the page's embedded payload resolves to Intercom's
/not-authorizedroute. The.mdsuffix route returns the same not-authorized shell, so it is not a content route here. · retrieved 2026-08-23 - Virtuoso help centre landing page (retrieved 2026-08-23). HTTP 200; its embedded payload declares
allContentRestrictedtrue with no public collections. · retrieved 2026-08-23 - Yardi privacy statement, scope exclusion for Client Data (retrieved 2026-08-23) · retrieved 2026-08-23
- Live OAuth posture check: RFC 9728 metadata at
https://mcp.virtuoso.ai/.well-known/oauth-protected-resourceand authorization server metadata athttps://mcp.virtuoso.ai/.well-known/oauth-authorization-server(2026-08-23). An anonymousinitializeto the endpoint returned a Cloudflare 403 with nowww-authenticateheader, so the auth posture comes from the server's own descriptor rather than from a challenge. · retrieved 2026-08-23 - Sibling scope comparison: RFC 9728 metadata at
https://matrixmcp.virtuoso.ai/.well-known/oauth-protected-resourceandhttps://dmmcp.virtuoso.ai/.well-known/oauth-protected-resource(2026-08-23), both advertising the same four scopes. · retrieved 2026-08-23 - Yardi support — · Privacy — . The
yardi.comhost returned a Cloudflare managed challenge to every request we made, includingrobots.txt; we did not attempt to bypass it.
Use in Agentman
Connect once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.
Open in Agentman StudioServer Info
- Category
- Finance
- Developer
- Yardi Virtuoso
- Tools
- 5
- Domain
- mcp.virtuoso.ai
Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.