Shortlist Pass for AI agents
Read a real local business — its menu, upcoming stops and events, and pickup availability — over MCP or plain JSON. Read-only. No key needed.
MCP server
https://app.shortlistpass.com/mcp
Streamable HTTP (MCP spec 2025-03-26), no authentication. Add it to any MCP client as a remote server. Four tools:
| Tool | What it returns |
|---|---|
search_businesses(town?, category?, query?) | Same as /search. |
get_business(subdomain) | Same as /businesses/{subdomain}. |
get_menu(subdomain) | Same as /businesses/{subdomain}/menu. |
get_upcoming_events(subdomain) | Same as /businesses/{subdomain}/events, pickup slots included. |
JSON API
https://app.shortlistpass.com/api/agent/v1
| Endpoint | What it returns |
|---|---|
GET /businesses/{subdomain} | Name, type, description, town, phone, website, page URL, hours (fixed locations), whether ordering is open and the order page URL. |
GET /businesses/{subdomain}/menu | Active public menu items: name, description, price, category, tags, sold-out flag, image URL. |
GET /businesses/{subdomain}/events | Upcoming events and stops: ISO start/end with offset, location, whether pre-orders are open, and the pickup slots still available with remaining capacity. |
GET /search?town=&category=&q= | Find businesses. town is a slug like myrtle-beach, category a key like food_truck, q free text. Never returns demos. |
Example:
curl https://app.shortlistpass.com/api/agent/v1/businesses/nitos/menu curl "https://app.shortlistpass.com/api/agent/v1/search?town=myrtle-beach&q=empanadas"
Ordering
When ordering_open is true, every result carries an order_url and the note “To order, send the customer to this link.” Orders are placed by the customer on the business’s own page. Nothing in this API or the MCP server places an order or writes anything.
What you will never see
Customer, order, owner, payment and internal fields are not part of any response — every response is built from an explicit allow-list of public fields. Demo pages return 404. Test, cancelled, draft and private events are omitted.
Limits and freshness
60 requests a minute per IP. Responses are cached for up to a minute, so an owner’s change shows within that. Times are ISO 8601 with the business’s own UTC offset; the timezone field names the zone.
Discovery
Listed on the official MCP Registry as com.shortlistpass/local-businesses (registry entry).
Every business host serves /llms.txt (for example nitos.shortlistpass.com/llms.txt) naming these endpoints, and app.shortlistpass.com/llms.txt describes the platform. A crawlable list of businesses is at https://app.shortlistpass.com/directory/myrtle-beach.