Business Box Start free

AI assistants and MCP

A remote MCP server is coming. Until then, an API key and the OpenAPI document get you most of the way.

In shortThe hosted MCP endpoint is not live yet — it needs OAuth 2.1, which is the next milestone. Today you can give a local MCP client an API key, or point any assistant that reads OpenAPI at /openapi.json.

Where this stands#

Being honest about it, because a documentation page that describes something unbuilt wastes your afternoon: there is no hosted MCP server yet.

The AI assistant directories — Claude's connectors, ChatGPT apps, the MCP registry — accept only OAuth 2.1 with PKCE, dynamic client registration and discovery metadata. That is deliberately not something to bolt on: an assistant acting on your bookings needs consent you can see and revoke, not a pasted key. It is the next milestone, and the changelog will say when it ships.

Some of the groundwork is already live. Every 401 from this API carries the discovery pointer an MCP client looks for:

WWW-Authenticate: Bearer resource_metadata="https://api.marubox.jp/.well-known/oauth-protected-resource"

That URL does not answer yet. When it does, nothing else about the API changes.

What works today#

A local MCP server you run#

If you are comfortable writing a small MCP server, the API is a good target: bearer auth, 12 operations and a full OpenAPI document. Run it on your own machine with your own API key in its environment, and any MCP client — Claude Desktop, Claude Code, Cursor — can use it.

Keep the key in the server's environment, never in a config file you might share, and give it read-only access unless you genuinely want an assistant cancelling appointments.

Assistants that read OpenAPI#

Anything that can be pointed at an OpenAPI document can call this API directly:

https://api.marubox.jp/v1/openapi.json

Every operation has an operationId and a description written to be read by a person or a model, which is what these tools use to decide what to call.

A word about care#

An assistant with a read-write key can cancel a real customer's appointment, and the customer will be emailed about it. Before you connect one:

  • Prefer a read-only key. Most of what people want — "what's my week look like", "when is my next appointment" — needs nothing more.
  • Give it its own key, so you can revoke that one thing without touching your other integrations.
  • Remember that cancellation emails the customer and cannot be silenced through the API. That is on purpose.

Common questions

Can I add Business Box to Claude or ChatGPT today?

Not through the directories — those require OAuth 2.1, which is not built yet. You can run a local MCP server with your own API key, or point any assistant that reads OpenAPI at the document.

When will the hosted MCP server be available?

It is the next milestone after the REST API, but no date is being promised here. The changelog is where it will be announced.

Will the REST API change when MCP arrives?

No. MCP is an additional way in, not a replacement, and v1 changes additively only.

Last reviewed 28 September 2026.