Title

StayWell, with Proof: a hotel where your agent's work is checked.

What we built

StayWell is a hotel booking experience with real room collections, live availability, demand-aware pricing, bookings, and a guest itinerary. A person can use it normally: choose dates, compare Garden Kings, Terrace Studios, River Suites, and Penthouse Residences, then make and manage a reservation — with a demo checkout, nothing real is charged.

Proof is the part of StayWell that helps when a reservation change matters. A guest can ask an agent: "Move my stay to Friday for two nights, under $300." The agent reads the live reservation and availability, compares options, and prepares a change. The guest approves it. StayWell then re-reads its own final state and checks whether the room, date, price, and every other condition actually match the request.

Why this is a strong fit for WebMCP

Hotels are full of consequential, changing details: dates, inventory, room types, cancellation rules, and prices. An agent can remove a lot of manual work, but a guest should never have to take its word that a booking changed correctly.

WebMCP gives an agent structured access to the same StayWell reservation the guest sees. It can read a reservation, search availability, quote a change, set conditions, stage a proposal, find recovery options, and verify after a change. The tool set changes with the live task: verify_result does not exist before a change is applied, and recovery tools appear only after a mismatch.

What agents cannot do is just as important: they have no approval, commit, exception-acceptance, or "mark complete" tool. Those are structurally absent. Approval belongs to the guest, and completion belongs to StayWell's deterministic checker.

What people and agents can do together that was not possible before

Before something like WebMCP, delegation was all-or-nothing: either you did the booking yourself, or you handed your session to an agent and hoped. StayWell shows a third thing: an agent that works on your behalf through a tool surface that is expressive enough to be useful and narrow enough to be safe. The agent can genuinely change your stay — and can never be the one to call it done, because the tools that finalize and verify are not on its menu. A guest and an agent can negotiate a real, priced change together, in one thread, with the site itself as referee.

The memorable moment

On the demo seed, the agent quotes $294. Competing demand lands between the quote and the guest's approval. When StayWell applies the change, the real total is $319. Instead of saying "done," Proof catches the mismatch, explains the failed price condition, and offers choices — and this time there is a way forward that breaks nothing: another room at $247 that still checks in Friday for two nights. The guest approves it; every condition now passes; the receipt is green. The whole arc — promise, caught difference, honest recovery, verified result — runs in under a minute, live, with no API keys and no video tricks. (A "Reset demo" control restores the canonical world on demand.)

How we implemented WebMCP

The site is a WebMCP server on document.modelContext: 13 tools registered natively when the browser supports it (ChatGPT's in-app browser, Chrome 149+ behind a flag), with a labelled polyfill fallback elsewhere — /agent-check shows which mode you are in and lets you exercise the tools yourself. Registration is derived from live task state, so tools genuinely appear and disappear as the task moves; the withheld set (approve, commit, mark-verified, edit-constraints) is enforced by a boundary test that fails the build if any WebMCP-reachable code path can reach a commit or approval route. The built-in chat agent is deliberately not privileged: it drives the same HTTP routes over the same cookies and meets the same 403s.

Results

The reproducible evaluation suite covers 59 deterministic scenarios: 0 false completions, 8/8 unauthorised approvals rejected, 8/8 agent commit attempts rejected, and 2/2 stale plans refused, alongside 208 passing unit and boundary tests. Run pnpm evals and pnpm test to reproduce.

Built with

Next.js App Router, React, TypeScript, Tailwind CSS, document.modelContext WebMCP, and an engine-agnostic verification domain. The repository is Apache-2.0 licensed.

Built With

Share this project:

Updates

Submission history