Shortlist Pass for AI agents

Read a real local business — its menu, upcoming stops and events, and pickup availability — over MCP or plain JSON. Read-only. No key needed.

MCP server

https://app.shortlistpass.com/mcp

Streamable HTTP (MCP spec 2025-03-26), no authentication. Add it to any MCP client as a remote server. Four tools:

ToolWhat it returns
search_businesses(town?, category?, query?)Same as /search.
get_business(subdomain)Same as /businesses/{subdomain}.
get_menu(subdomain)Same as /businesses/{subdomain}/menu.
get_upcoming_events(subdomain)Same as /businesses/{subdomain}/events, pickup slots included.

JSON API

https://app.shortlistpass.com/api/agent/v1
EndpointWhat it returns
GET /businesses/{subdomain}Name, type, description, town, phone, website, page URL, hours (fixed locations), whether ordering is open and the order page URL.
GET /businesses/{subdomain}/menuActive public menu items: name, description, price, category, tags, sold-out flag, image URL.
GET /businesses/{subdomain}/eventsUpcoming events and stops: ISO start/end with offset, location, whether pre-orders are open, and the pickup slots still available with remaining capacity.
GET /search?town=&category=&q=Find businesses. town is a slug like myrtle-beach, category a key like food_truck, q free text. Never returns demos.

Example:

curl https://app.shortlistpass.com/api/agent/v1/businesses/nitos/menu
curl "https://app.shortlistpass.com/api/agent/v1/search?town=myrtle-beach&q=empanadas"

Ordering

When ordering_open is true, every result carries an order_url and the note “To order, send the customer to this link.” Orders are placed by the customer on the business’s own page. Nothing in this API or the MCP server places an order or writes anything.

What you will never see

Customer, order, owner, payment and internal fields are not part of any response — every response is built from an explicit allow-list of public fields. Demo pages return 404. Test, cancelled, draft and private events are omitted.

Limits and freshness

60 requests a minute per IP. Responses are cached for up to a minute, so an owner’s change shows within that. Times are ISO 8601 with the business’s own UTC offset; the timezone field names the zone.

Discovery

Listed on the official MCP Registry as com.shortlistpass/local-businesses (registry entry).

Every business host serves /llms.txt (for example nitos.shortlistpass.com/llms.txt) naming these endpoints, and app.shortlistpass.com/llms.txt describes the platform. A crawlable list of businesses is at https://app.shortlistpass.com/directory/myrtle-beach.