AllFlyghts MCP Server
README.md
# AllFlyghts MCP Server
TypeScript MCP server for the AllFlyghts public API.
This repository is a standalone Node.js project. It exposes AllFlyghts data through MCP tools while keeping the public API key on the server side.
## Using AllFlyghts via the hosted MCP server
Most users don't need to install or run this code. AllFlyghts runs a managed
MCP server.
Visit for more info: https://www.allflyghts.com/developers/mcp
Full docs: https://www.allflyghts.com/mcp
To use it, configure your MCP client (Claude Desktop, Cursor, etc.) to
connect to this endpoint with your AllFlyghts API token in the `Authorization`
header:
Authorization: Bearer <your-token>
Get your token at https://www.allflyghts.com/access/sign-in
This repository contains the source code of that hosted server, made
public for transparency. You can also run it locally if you want — instructions below.
## Tools
- `search_locations`
- `get_city`
- `search_flights`
## Requirements
- Node.js 20+
- An AllFlyghts public API base URL
- An AllFlyghts public API key, provided either directly by environment variable or through Azure Key Vault
## Environment
Required:
- `ALLFLYGHTS_PUBLIC_API_BASE_URL`
Choose one API key source:
- `ALLFLYGHTS_PUBLIC_API_KEY`
- `PUBLIC_API_KEY_VAULT_URL` together with `MCP_PUBLIC_API_KEY_SECRET_NAME`
Optional:
- `MCP_AUTH_TOKEN`
- `MCP_AUTH_TOKEN_SECRET_NAME`
- `MCP_SERVER_NAME`
- `MCP_SERVER_VERSION`
- `MCP_TRANSPORT`
- `PORT`
- `MCP_ALLOWED_ORIGINS`
If `MCP_AUTH_TOKEN` or `MCP_AUTH_TOKEN_SECRET_NAME` is configured for HTTP mode, callers must send:
```text
Authorization: Bearer <token>
```
## Install
```bash
npm install
```
## Run
Stdio mode:
```bash
npm run dev:stdio
```
HTTP mode:
```bash
npm run dev:http
```
Production builds:
```bash
npm run build
```
Then start either transport from `dist/`:
```bash
npm run start:stdio
npm run start:http
```
## Notes
- Streamable HTTP creates a fresh MCP server and transport per request.
- Secrets are resolved from Azure Key Vault when configured, with direct environment variables as a fallback.
- Do not commit real API keys, auth tokens, or other secrets to this repository.
This server cannot be deployed
Maintenance
ActivityInactive
ResponsivenessNo issues