# search_hotels

Search live hotel availability for a destination and date range. Returns a price-sorted list of hotels (JSON in the text), each with a ref and its cheapest bookable room's supplierRoomId. To book: pass a room's supplierRoomId + the hotel ref to get_checkout_quote then create_checkout. For a hotel's other rooms (or a hotel not in the list), call get_rooms. Narrow with keywords (a hotel name, area, or amenities).

Agent View of the PolicyLayer registry record for `search_hotels`. HTML page: https://policylayer.com/tools/com-getmyhotels-getmyhotels/search-hotels

## Facts

- Tool: `search_hotels`
- Server: GetMyHotels (`https://mcp.getmyhotels.com`) — https://policylayer.com/tools/com-getmyhotels-getmyhotels.md
- Homepage: https://github.com/fenilsonani/gmh
- Risk category: Read (Low risk)
- Registry record: grade F, identity unverified
- Server auth posture: open
- Server rate-limited: no
- Parameters: 9 (3 required)
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `rooms` | integer | no | Rooms (1-6). Default 1. |
| `adults` | integer | no | Adults (1-10). Default 2. |
| `checkIn` | string | yes | Check-in date, ISO 8601 (YYYY-MM-DD). |
| `checkOut` | string | yes | Check-out date, ISO 8601 (YYYY-MM-DD). Must be after check-in. |
| `children` | integer | no | Children (0-6). Default 0. |
| `keywords` | string | no | Optional free-text preferences, e.g. 'beachfront pool spa'. |
| `destination` | string | yes | City, region, or place to search (e.g. 'Paris', 'Goa', 'Lower Manhattan'). |
| `childrenAges` | array | no | Age of each child at check-in. Length should equal `children`. |
| `guestNationality` | string | no | ISO 3166-1 alpha-2 guest nationality (e.g. 'US', 'GB'). Affects supplier pricing. |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "search_hotels",
    "arguments": {
      "checkIn": "<checkIn>",
      "checkOut": "<checkOut>",
      "destination": "<destination>"
    }
  }
}
```

## Why search_hotels is rated Low

search_hotels is a read-only operation that retrieves and queries hotel availability and pricing data. While it returns information used to facilitate bookings downstream, the tool itself performs no side effects—it does not create, modify, delete, or charge. The description explicitly indicates it searches and returns results without state changes. This is a standard read operation with low severity.

From the tool's own definition: "Tool description states it 'Search[es] live hotel availability' and 'Returns a price-sorted list of hotels'. The function performs a search query with no modification of data, no execution of arbitrary operations, and no financial transactions."

Risk signals: Accepts file system path (destination)

## Use case

AI agents call search_hotels to retrieve information from GetMyHotels without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches GetMyHotels:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "search_hotels": {}
  }
}
```

## Other tools on GetMyHotels (17)

- `cancel_booking` — Destructive — https://policylayer.com/tools/com-getmyhotels-getmyhotels/cancel-booking.md
- `create_checkout` — Financial — https://policylayer.com/tools/com-getmyhotels-getmyhotels/create-checkout.md
- `create_one_click_checkout` — Financial — https://policylayer.com/tools/com-getmyhotels-getmyhotels/create-one-click-checkout.md
- `fetch` — Read — https://policylayer.com/tools/com-getmyhotels-getmyhotels/fetch.md
- `get_booking` — Read — https://policylayer.com/tools/com-getmyhotels-getmyhotels/get-booking.md
- `get_checkout_quote` — Read — https://policylayer.com/tools/com-getmyhotels-getmyhotels/get-checkout-quote.md
- `get_hotel_details` — Read — https://policylayer.com/tools/com-getmyhotels-getmyhotels/get-hotel-details.md
- `get_my_booking` — Read — https://policylayer.com/tools/com-getmyhotels-getmyhotels/get-my-booking.md
- `get_rooms` — Read — https://policylayer.com/tools/com-getmyhotels-getmyhotels/get-rooms.md
- `list_my_bookings` — Read — https://policylayer.com/tools/com-getmyhotels-getmyhotels/list-my-bookings.md
- `list_payment_methods` — Read — https://policylayer.com/tools/com-getmyhotels-getmyhotels/list-payment-methods.md
- `list_trips` — Read — https://policylayer.com/tools/com-getmyhotels-getmyhotels/list-trips.md
- `search` — Read — https://policylayer.com/tools/com-getmyhotels-getmyhotels/search.md
- `add_trip_item` — Write — https://policylayer.com/tools/com-getmyhotels-getmyhotels/add-trip-item.md
- `modify_booking` — Write — https://policylayer.com/tools/com-getmyhotels-getmyhotels/modify-booking.md
- `request_booking_action_code` — Write — https://policylayer.com/tools/com-getmyhotels-getmyhotels/request-booking-action-code.md
- `save_trip` — Write — https://policylayer.com/tools/com-getmyhotels-getmyhotels/save-trip.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=com-getmyhotels-getmyhotels · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/com-getmyhotels-getmyhotels
