Skip to main content

AI Assistant & MCP Server

Seatsurfing Cloud

The AI Assistant and the MCP server are part of the Cloud Features and are available for Seatsurfing Cloud organizations.

Seatsurfing offers two independent AI features:

  • AI Assistant: a chat in the booking UI that lets your users find, book and cancel spaces in plain language.
  • MCP server: direct access for your organization's own AI tools (such as Claude, ChatGPT or Copilot) via the Model Context Protocol.

Both features are managed by organization admins on the Cloud Features page in the Admin UI. They can be switched on and off independently of each other.

FeatureDefaultSetting
AI AssistantOnAI assistant
MCP serverOffAccess for your own AI tools (MCP)

AI Assistant​

The AI Assistant appears as Assistant in the navigation of the booking UI and opens a chat panel. Users can, for example:

  • Find free spaces ("Is there a desk with a monitor free tomorrow morning?")
  • Book a space
  • List their bookings
  • Cancel a booking
  • See where their buddies (colleagues they follow) are booked and book a seat near them

The assistant acts on behalf of the signed-in user and can do exactly what this user can do in the booking UI, and nothing else. All booking rules and permissions apply. It only answers questions about bookings and about where buddies are booked, and declines everything else. Booking for other people, looking up bookings of people who are not buddies and managing buddies are out of scope.

Confirmation of changes​

The assistant never books or cancels on its own. Every booking and cancellation is shown as a card with the details, which the user has to confirm or decline. Only a confirmation runs the action, and only once.

Language​

The assistant replies in the language selected in the app (English or German; other languages get English), regardless of the language the user writes in.

Data protection​

  • The assistant uses a language model in Azure AI Foundry, deployed in Germany West Central (Standard, regional deployment).
  • To answer a request, the message text and the data needed for it, such as matching spaces and bookings, are processed by Azure. When users ask about buddies, the names and booked seats of those buddies are processed as well.
  • Users see a privacy and AI notice in the chat panel.
  • Conversations are stored on the server only, and are deleted 24 hours after their last message, or when the user or the organization is deleted.

If this doesn't fit your organization's requirements, switch the assistant off (see below).

Switching the assistant on or off​

  1. Open the Admin UI and go to Cloud Features.
  2. Toggle AI assistant.

When switched off, the Assistant item disappears from the booking UI, and the organization's existing conversations are deleted. The MCP server is not affected.

MCP server​

The MCP server lets AI tools that support MCP find and book spaces on behalf of a user. It is switched off by default.

Enabling​

  1. Open the Admin UI and go to Cloud Features.
  2. Toggle Access for your own AI tools (MCP).
  3. Copy the server URL shown on the page, for example https://acme.seatsurfing.app/cloud-features/mcp.

While the switch is off, the MCP endpoint and all related sign-in endpoints are unavailable for your organization. Switching it off again immediately disconnects all AI tools: connected clients, grants and tokens of your organization are deleted.

The AI Assistant does not depend on this switch. It keeps working when direct access is off, and direct access keeps working when the assistant is off.

Connecting an AI tool​

  1. Add a custom MCP server / connector in your AI tool, using the server URL from the Cloud Features page (transport: Streamable HTTP).
  2. The tool registers itself and opens a Seatsurfing consent page in the browser.
  3. Sign in to Seatsurfing if necessary (password, passkey or your organization's identity provider), and allow access.

Each user connects with their own account. Users can only access and change what they could access in the booking UI itself.

Available tools​

ToolDescriptionPermission
search_spacesFind available spacesspaces:read
create_bookingBook a spacebookings:write
cancel_bookingCancel a bookingbookings:write
list_my_bookingsList the user's bookingsbookings:read
list_buddiesList the user's buddiesbuddies:read
get_buddy_locationsShow where buddies are bookedbuddies:read
search_spaces_near_buddiesFind free spaces near buddiesbuddies:read

The permission (OAuth scope) is granted by the user on the consent page.

Security​

  • Authentication uses OAuth 2.1 with PKCE. Seatsurfing never sees or stores the credentials of your AI tool's provider, and the consent page uses the user's regular Seatsurfing login.
  • Access tokens are bound to your organization and to the MCP server URL, and are only accepted by the MCP server. Regular Seatsurfing session tokens don't work there, and vice versa.
  • Every tool call runs as the user who granted access, so all booking rules and permissions apply.
  • Note that data returned by the tools (such as spaces, bookings and buddies' locations) is passed on to the AI tool you connect, and is processed under that provider's terms.

Self-hosted​

The AI Assistant and MCP server are part of the Seatsurfing Cloud Features and are not included in self-hosted installations.