AI agents (MCP)

MCP Server for AI Agents

The Sky Schedule MCP server lets AI agents like Claude, Cursor, and Grok read and update your flight school's schedule, flights, aircraft, CRM, and reports.

llms.txt

The Sky Schedule MCP server lets an AI agent work in your flight school's account through the Model Context Protocol (MCP). Connect Claude, Cursor, Grok, or another MCP client with your school's API key, and the agent can look up the schedule, book and cancel flights, log Hobbs after a flight, attach a fuel receipt to a reservation, email a CRM lead, or run a report.

https://app.skyschedule.io/api/mcp

Sky Schedule hosts the server. There is nothing to install or run on your side. To connect a client, follow MCP setup.

What an agent can do with the MCP server

The server has 34 tools: 20 that read and 14 that write. A few things you can ask an agent once it's connected:

  • "What's on the schedule for N12345 tomorrow?"
  • "Book Alex in N12345 Saturday 9 to 11 with Sam for dual training."
  • "Complete reservation 1042 with Hobbs 2451.3 to 2452.6."
  • "Which aircraft have open grounding squawks?"
  • "Log a $142 fuel reimbursement on this morning's flight in N67890 and attach the receipt."
  • "Draft invoices for yesterday's completed flights."
  • "Post in the general Team Chat channel that the runway is closed until noon."

The MCP tools reference lists every tool with its inputs. Unlike the REST API, MCP can read aircraft records and CRM leads, and it can write.

Authentication

The MCP server uses the same school API key as the REST API, sent on every request in either header:

Authorization: Bearer ss_live_YOUR_API_KEY
X-SkySchedule-API-Key: ss_live_YOUR_API_KEY

There is no OAuth sign-in. The server publishes protected resource metadata that tells clients to use a bearer token in a header, with no authorization server:

curl -s https://app.skyschedule.io/.well-known/oauth-protected-resource
{
  "resource": "https://app.skyschedule.io/api/mcp",
  "bearer_methods_supported": ["header"],
  "resource_documentation": "https://app.skyschedule.io/developer/mcp"
}

The same document is also served at /.well-known/oauth-protected-resource/api/mcp.

A few requests work without a key so that clients can check the address while you set up a connector:

  • A GET to the server address with no session returns {"status":"ok","name":"sky-schedule","version":"2.0.0"}.
  • The MCP initialize and ping messages are answered.

Anything else without a key gets 401 and the header WWW-Authenticate: Bearer realm="Sky Schedule MCP".

Limits

LimitAmountWhat counts
MCP requests1,000 per school per UTC dayEvery request to the MCP server that passes the key check, including listing tools and starting a session, not only tool calls.
Write tool calls200 per school per UTC dayCalls to any of the 14 write tools, whether they succeed or fail. run_report counts as a write.
List size100 records per callThe limit input on list tools, default 50.

Both counters reset at 00:00 UTC and are separate from the REST API's 100 requests per day.

  • Over the request limit, the server answers 429 with {"error":"MCP daily rate limit exceeded."}.
  • Over the write limit, the tool call returns an error with the text MCP write limit reached (200/day UTC). Try again tomorrow or use read tools. Read tools keep working.

MCP responses carry X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset headers for the 1,000 per day counter, and every tool result repeats them under meta.rateLimit.

Audit log

Sky Schedule records every tool call in an audit log: the tool name, a short summary of the inputs, whether it succeeded, the error message if it failed, and which key made the call. The summary keeps the log small and avoids storing personal data in bulk:

  • Text inputs longer than 120 characters are cut short.
  • File contents sent as base64, and any input named like a password or secret, are replaced with [redacted].
  • Nested objects are replaced with a placeholder.

Who the agent acts as

Tools act for the school as a whole, not as a particular staff member, and every tool is limited to the school that owns the key. Some writes are labeled so staff can tell them apart in the app:

  • Cancellations from cancel_reservation are recorded as made by "Connected agent".
  • Team Chat messages from send_team_chat_message are posted as "Sky Schedule MCP".
  • Draft invoices from draft_invoice_for_flight are created under the admin who generated the current key.

Write tools can change real records: void_reservation permanently removes a reservation, and send_crm_lead_email sends a real email from your school. Most MCP clients let you require approval before a tool runs. Turn that on for write tools, at least until you trust how the agent uses them.

Tool results

Every tool returns a single text block containing JSON. Successful results put the records under data (or return the fields of the new record) and add meta:

{
  "data": [
    {
      "id": "bbbbbbbb-bbbb-4bbb-8bbb-bbbbbbbbbbbb",
      "tailNumber": "N12345",
      "model": "Cessna 172S Skyhawk",
      "type": "Single Engine",
      "status": "Available",
      "currentHobbs": 2452.6,
      "currentTach": 1981.5,
      "totalHours": 8123.4,
      "hourlyRate": 165
    }
  ],
  "meta": {
    "count": 1,
    "pageSize": 1,
    "rateLimit": { "limit": 1000, "remaining": 962, "reset": "2026-10-09T00:00:00.000Z" }
  }
}

When a tool fails, the result has isError: true and the text explains why, for example {"error": "That time slot overlaps another reservation on this aircraft."}. Agents read these messages and can usually correct the call themselves.

Calling the server without an MCP client

Most people only use the server through an MCP client. If you're building your own, the server speaks MCP over Streamable HTTP and doesn't keep sessions, so each JSON-RPC message can be sent on its own with a POST:

curl -s https://app.skyschedule.io/api/mcp \
  -H "Authorization: Bearer $SKYSCHEDULE_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"list_aircraft","arguments":{"limit":1}}}'

The reply comes back as a server-sent event whose data is the JSON-RPC response. The tool's JSON is a string inside result.content[0].text. Only the Streamable HTTP endpoint at /api/mcp is available; there is no separate SSE endpoint.

The REST API remains the simpler choice for scheduled reports and exports. See the Sky Schedule API overview to compare the two.