Market Coverage / Hospitable Hub
Product & Tech

Hospitable's MCP server can now lock and unlock doors on a plain English request

PMS News Desk

PMS News Desk

September 28, 2026 · 3 min read

Hospitable has added smart device control to its MCP server. An AI assistant connected to a Hospitable account can now check a lock's battery level, read a thermostat, and lock or unlock a door when asked.

The tools cover any smart lock or thermostat already connected to a property in Hospitable, and work from any MCP-compatible client, including Claude, Cursor and ChatGPT Desktop.

What the three tools do

get-property-devices returns every smart lock and thermostat attached to a property with live status: battery percentage, online or offline state, locked or unlocked state, current temperature, and HVAC mode and setpoints. You can filter by device type and see any known device errors.

lock-smartlock and unlock-smartlock do what their names suggest. Both wait for confirmation from the lock provider before returning the new device state, so the answer tells you the lock actually changed rather than that the request was sent. Hospitable names Schlage, Yale and August among the supported brands, all reached through Seam.

The tools require the Smart Devices entitlement on the account, the same one that governs smart devices in the Hospitable app. If the MCP server is already connected, the tools appear automatically with no setup step. If not, the setup guide sits under Settings, then Integrations, then MCP.

Hospitable's own examples lean on the reporting side. Asking which properties have locks under 50% battery before a run of check-ins. Or combining device status with reservation data to list the next five arrivals where a lock is offline or below 30% battery. Those questions used to mean a spreadsheet or a click through every property.

The part worth pausing on

Hospitable flags the risk itself, in unusually plain terms. "Unlocking a door is a real-world security action. Treat it like handing someone your keys." It advises naming the property precisely, because "unlock the villa" is ambiguous in a way that "unlock the front door at Key West Villa" is not.

That warning is doing a lot of work. The guardrail here is prompt discipline, not a check inside the tool. The changelog describes no approval step before an unlock, no read-only mode for the device tools, and no way to separate a manager who should be able to open a door from a cleaner or an assistant who should not. Anyone who can reach the connected AI client can, in principle, open a door.

For a manager running one account with one person at the keyboard, that is a small surface. For a team that has handed an AI client to several staff, or wired one into an automation, it is worth working through before switching the entitlement on.

Where this fits

This is not a one-off. Hospitable has widened what its MCP server reaches steadily through 2026: owner statements and transactions in August, priority alerts including low battery warnings, calendar notes, and owner records before that. Locks are the first tools that act on the physical property rather than on records.

Operators weighing up AI access to their PMS should note the direction of travel. The question is moving from what an assistant can read to what it can do, and door access is a clear line. Worth deciding deliberately who holds that key.

Source: Hospitable Changelog