What is an AI assistant with MCP
MCP connects an external AI assistant to Luma Concierge. The owner and manager can ask questions about hotel operations and receive answers based on current system data. This is a separate connection for the team; the guest does not need it to use the app.
The server is read-only. The AI can suggest an action plan, but assigning assignees, changing statuses, messaging guests, and payment operations are performed in the Luma interface.
What data is available
| Tool | What the AI receives | Example question |
|---|---|---|
get_operational_overview |
Number of open requests by status, overdue requests, and active stays | "Prepare a brief summary for the start of the shift" |
list_open_requests |
Latest open requests: number, title, status, priority, assignee, and dates | "Show new requests and suggest an order of handling" |
list_active_stays |
Active stays: room and check-in and check-out dates | "Which check-outs are upcoming among active stays?" |
list_service_catalog |
Active services, prices, currency, payment method, availability time, and booking rules | "Which services are available and how much do they cost?" |
Lists return up to 20 records by default; the limit parameter sets from 1 to 50. There is no pagination: a list of 50 records does not guarantee the completeness of the report. Requests are sorted from newest to oldest, stays by check-out time. For the full count, use the summary.
For requests there is a status filter: new, accepted, in_progress, waiting_guest, ready. Completed and cancelled requests are not included in the open list. The catalog returns names and descriptions in English; the assistant can translate the answer. The price is stored in price_minor: for IDR it is the displayed amount, for other supported currencies it is hundredths of the currency.
How to connect
- Log in to the owner's dashboard, open "AI and MCP" in the management menu. Enter a connection name and click "Create token". Copy the issued token: it is shown only on this page after creation. The manager receives the token from the hotel owner.
- In the settings of a compatible AI client, add a remote MCP server with HTTP support and an authorization header.
- Specify the address
https://lalo.craabchee.com/mcpandBearerauthorization with the issued token. The client must send the headerAuthorization: Bearer <MCP_TOKEN>with every request. Here<MCP_TOKEN>is a placeholder, not a real key. - Save the connection and check that the client sees the four tools from the table above.
- Request the hotel summary. Compare the result with the current dashboard data and check the
generated_attime.
The protocol 2025-11-25, JSON-RPC 2.0, and JSON responses to POST requests are supported. A GET/SSE stream is not provided. OAuth login is not implemented: a client that strictly requires OAuth will not be able to connect this way. The specific field names depend on the AI client.
Example prompts for the team
Owner: "Get the current summary via MCP. Show open requests by status, the number of overdue and active stays. Suggest three priorities for the team. Specify the data time and sampling limitations."
Manager: "Get up to 50 new requests via list_open_requests with status: new. Group by priority, flag requests without an assignee, and suggest an order of handling. Do not change anything."
Preparing for check-outs: "Get up to 50 active stays. Highlight the nearest check-outs with room numbers and times. Do not identify guests and indicate if the list is limited."
Catalog: "Get active services. Explain prices and advance booking rules in simple language. Do not promise availability on a specific date: MCP does not return remaining slots."
Instructions for the AI assistant
These instructions can be saved in your assistant's settings:
Use the Luma MCP tools to get current data. Separate facts from the server response from recommendations. Specify the summary time and list limitations. Do not invent missing data and do not identify guests by room numbers and dates. MCP is read-only. To change a request, make a payment, or send a message, suggest that the manager perform the action in Luma. If data is unavailable, state so directly.
Connection management and privacy
Each token is tied to one hotel. MCP does not return guest names and contacts, PIN codes, request descriptions, internal notes, or payment data. However, room numbers, request titles, and names of assigned staff are available to the assistant — choose an AI client that your team trusts.
Store the token in secure connection settings. Do not paste it into messages, the address bar, screenshots, or shared documents. Issue a separate token for each client. If access is lost or an employee changes, the owner must open "AI and MCP" in the dashboard and click "Revoke" for the corresponding connection.
If the connection does not work
- 401: the token is missing, incorrect, or revoked; also check the hotel's activity and subscription access with the administrator.
- 403: the Origin of the browser client is not allowed. The administrator must check the allowed origins settings; do not disable the check.
- 405: the client is using GET. The connection must work via POST with JSON responses.
- 429: the request limit has been exceeded. Wait and retry the request; the route is limited to 60 requests per minute.
- Empty list: there may be no matching data. Check the status, stay dates, and filter; do not replace missing data with assumptions.
- OAuth required: the current integration uses a Bearer token; choose a compatible client.
The owner's dashboard displays the connection name, creation date, last use, and status. To disconnect the AI client, click "Revoke". Revocation terminates access via this token; to reconnect, create a new one. Tokens of other hotels are not accessible, and the manager cannot issue or revoke tokens.