DevelopersRead only

list_open_slots

API reference — one of the tools an AI assistant can call on an Avrosh account.

What it does

The appointment times still open for one bookable type on one date, already accounting for existing bookings, buffers and the business's own opening hours. Use this before offering a customer a time - never infer availability from a booking list, which cannot see hours or buffers. `configured: false` means the business has not set opening hours for that type: that is 'no hours are set up', NOT 'fully booked', and the two must never be reported as the same thing. Times come back as instants; render them in the business's timezone (get_business.timezone).

This is the exact text the model reads before deciding to call.

Parameters

business_idstringrequired

The id returned by list_businesses.

bookable_type_idstringrequired

From list_bookable_types.

datestringrequired

The day to look at, YYYY-MM-DD, in the business timezone.

team_member_idstringoptional

Optional. Only slots for this one team member, when the business books people rather than spaces.

Request

curl -X POST https://us.avrosh.com/mcp \
  -H "Authorization: Bearer $AVROSH_KEY" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"list_open_slots","arguments":{"business_id":"926135ac-487d-4367-8bad-25397d0d4b87","bookable_type_id":"rt_haircut","date":"2026-08-20"}}}'

Response

The result arrives as an MCP content block; the JSON below is what the text field parses to.

{
  "configured": true,
  "reason": null,
  "slots": [
    {
      "startAt": "2026-08-20T02:00:00.000Z",
      "endAt": "2026-08-20T02:45:00.000Z",
      "label": "10:00",
      "freeUnits": 2
    },
    {
      "startAt": "2026-08-20T03:00:00.000Z",
      "endAt": "2026-08-20T03:45:00.000Z",
      "label": "11:00",
      "freeUnits": 1
    }
  ]
}

Connecting

Paste the URL into your assistant and log in. Avrosh implements OAuth 2.1, so an MCP client discovers the authorisation server, registers itself, and opens a browser asking you to sign in here. That is the whole setup: nothing to copy, no key to keep, and nothing to rotate later.

https://us.avrosh.com/mcp

For something with no browser to log in with — a cron job, a script, an automation platform — there is a second door: a bearer key made in the dashboard under Docs, shown once because only its hash is stored, and revocable at any time.

curl https://us.avrosh.com/mcp \
  -H "Authorization: Bearer $AVROSH_KEY"

Either way the boundary is the same one: an assistant reaches every business on the account it signed in to, and no others. There are no scopes to configure and nothing to switch on — what bounds it is whose account it is, enforced in the database rather than by a permission anybody sets.