# AI Assistant (MCP) (/docs/plugins/ai-assistant)



The &#x2A;*AI Assistant (MCP)** plugin lets an AI assistant you already use — Claude Desktop, Cursor, a voice agent, or any other client that speaks the Model Context Protocol — read your Resytech data and answer questions in plain English.

Access is **read-only**. An assistant connected this way can look things up but never creates, changes, or cancels a booking, touches pricing, or alters a setting.

This is a **feature** plugin — there are no credentials for *you* to enter. You create a token and paste it into your assistant.

Setup [#setup]

1. Open **Plugins → Browse Plugins** and click **Install** on &#x2A;*AI Assistant (MCP)**.
2. On the setup page, click **Create Token**. Choose the locations it may read and tick only the permissions the assistant needs. The token is shown once — copy it straight away.
3. Configure your assistant to talk to `https://mcp.resytech.com` with the token in the `Authorization: Bearer` header.
4. Click **Enable**. A token can only read a location while the plugin is enabled there, so enable it at each location the token covers.

Client-by-client configuration, the full list of tools, and the permission model are in the [AI Assistants (MCP) guide](/docs/integrations/mcp-server).

Permissions [#permissions]

| Permission                    | What it unlocks                                                                                                                                                    |
| ----------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Activities & availability** | Listing activities and checking open time slots. No customer data.                                                                                                 |
| **Bookings**                  | Searching and reading bookings. Customer name, email, and phone are redacted unless the next permission is granted.                                                |
| **Customer details**          | Reveals customer contact details on booking results.                                                                                                               |
| **Business analytics**        | Aggregate questions: channel mix, group size, lead time, booking hour, add-on attach, departure load, year-over-year. Numbers only. &#x2A;*For your own AI only.** |

<Callout type="warn">
  Create one token per audience. A token you give to a third party, such as a phone agent that helps callers find their booking, should have only Activities and, if needed, Bookings. **Business analytics** reveals your revenue and performance and must never be granted on a token that leaves your hands.
</Callout>

Only administrators can create, disable, or revoke tokens.

Disabling and removing [#disabling-and-removing]

* **Disable** cuts every token's access to this location immediately. Tokens are kept, so enabling again restores access without re-issuing anything.
* **Remove** uninstalls the plugin at this location. Tokens are company-wide and survive removal; they simply cannot read this location until the plugin is installed and enabled again.
