EgyptAir MCP Server
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@EgyptAir MCP ServerWhat's the status of flight MS123?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
EgyptAir MCP Server
Overview
This project was developed as part of the Autonomous Agents – MCP Server Lab.
Our goal is to build a secure Model Context Protocol (MCP) server that allows an AI assistant to safely interact with EgyptAir's internal operational data without giving the language model direct access to the production database.
Instead of exposing SQL queries or shell commands, the server provides carefully designed business tools that perform validated and authorized operations.
The MCP server acts as a secure layer between the AI assistant and the database.
Architecture: LLM | ▼ MCP Client | ▼ EgyptAir MCP Server | ▼
Related MCP server: EMS MCP Server
SQLite Database
Company
EgyptAir is Egypt's national airline.
The company handles thousands of passenger bookings every day. Flight delays and cancellations often lead to customer compensation requests that must be reviewed by customer service employees and supervisors.
The objective of this project is to build an AI assistant that helps employees manage these operations safely through MCP.
Problem Statement
Without MCP, an LLM could generate arbitrary SQL queries directly against the production database, creating several risks:
Invalid SQL queries
Unauthorized data modification
Prompt injection attacks
Poor auditing
Difficult monitoring
Instead of giving the LLM direct database access, this project exposes controlled business operations through an MCP Server.
The server handles:
Authentication
Authorization
Validation
Business rules
Database operations
Project Structure
EgyptAir-MCP-Server/
│ ├── db/ │ ├── schema.sql │ ├── seed.sql │ ├── create_db.py │ ├── database.db │ ├── erd.mmd │ └── erd.png │ ├── mcp_server/ │ ├── app.py │ ├── server.py │ ├── database.py │ ├── config.py │ ├── authorization.py │ ├── validation.py │ ├── notifications.py │ └── tools/ │ ├── agent/ │ └── README.md
Database
SQLite was selected as the database engine because it is lightweight, portable, and easy to demonstrate during development.
The database contains the following entities:
Employees
Flights
Passengers
Bookings
CompensationRequests
Policies
Reports
The complete Entity Relationship Diagram is available inside:
db/erd.png
Current MCP Tools
Tool | Type | Purpose |
get_flight_status | Read | Retrieve flight status |
get_booking_details | Read | Retrieve booking information |
get_compensation_policy | Read | Read compensation policy |
submit_compensation_request | Write | Create a new compensation request |
approve_compensation | Write | Approve or reject compensation |
generate_disruption_report | Read | Generate disruption report |
draft_passenger_email | Read | Draft passenger email |
Tool Classification
Read Tools
Read tools only retrieve information and do not modify database state.
Examples:
get_flight_status
get_booking_details
get_compensation_policy
generate_disruption_report
draft_passenger_email
Write Tools
Write tools modify database information and require additional protection.
Examples:
submit_compensation_request
approve_compensation
Defensive Tool Design
Write tools are designed using secure business operations instead of exposing SQL queries to the LLM.
Security measures include:
Parameterized SQL queries
Server-side validation
Authorization checks
Business rule validation
Structured responses
The LLM only interacts with predefined MCP tools and never executes raw SQL commands.
Validation
Validation is performed independently from MCP input schemas.
Examples:
Verify booking exists
Verify flight is eligible for compensation
Verify requested amount is valid
Verify compensation request exists
Verify request is still pending before approval
Authorization
Only authorized employees can execute sensitive write operations.
Example:
Customer Service → Submit compensation requests
Supervisor / Manager → Approve compensation requests
Authorization is performed inside the MCP tool handler before any database modification.
Implemented Issue: Secure Compensation Approval Workflow
Issue
The approve_compensation tool was a high-risk write operation because it directly modified compensation requests.
The missing requirements were:
Human confirmation before approval
MCP notification after state changes
Protection against accidental database updates
Solution 1: MCP Elicitation
Problem
Before implementation, the approval process updated the database immediately after authorization checks.
This could allow accidental approval of compensation requests.
Implementation
MCP Elicitation was added before the database update.
The workflow became:
Manager | approve_compensation() | Authorization Check | Request Validation | MCP Elicitation | User Confirmation | Database Update
The server asks the user for confirmation:
Example:
Are you sure you want to approve this compensation request?
Request ID: 8
Amount: $350
If the user confirms:
Status becomes Approved
approved_by is stored
If the user rejects:
The operation is cancelled
No database modification occurs
This ensures sensitive operations require explicit human approval.
Solution 2: MCP tools/list_changed Notification
Problem
After changing compensation status, connected clients needed a way to know that the server state had changed.
Implementation
After successful compensation processing, the server sends:
notifications/tools/list_changed
This allows MCP clients to refresh their available information and stay synchronized with server changes.
Implemented Issue: MCP Progress Tracking
Problem
The generate_disruption_report tool performs multiple database operations and may take time.
Previously, the client had no information about the current execution state.
Solution
MCP progress notifications were added.
The report generation now provides updates:
10% Starting report generation
30% Counting delayed flights
60% Counting cancelled flights
90% Calculating statistics
100% Report completed
After reaching 100%, the server returns the final report:
Contains:
Delayed flights
Cancelled flights
Average delay
Affected passengers
This improves user experience during long-running operations.
LLM call (gemini)
MCP server is Ingerated with gemini agent and access to all listed tools The user type his messege to the agent then route it The Agent can connect to mcp either stio or http (sse) Agent files could be found in /agent folder: - agent.py - agnet_llm.py for http transport could be found in - transport.py To switch between stio / http switch the comment section in server.py
Current Progress
The following components have been completed:
Project planning
Company selection
Problem definition
Database schema
Seed data
SQLite database
ERD
MCP Server initialization
Database connection layer
Configuration module
Validation module
Authorization module
Initial MCP tools
Secure compensation approval workflow
MCP Elicitation
MCP tools/list_changed notification
MCP Progress Tracking
Capability Negotiation
Resources
Prompts
Sampling
Streamable HTTP Transport
Agent Integration
Final Demonstration
Technologies
Python
SQLite
FastMCP
Model Context Protocol (MCP)
LangChain (planned)
JSON Schema
Team
Marwan Ahmed
Ahmed Ashraf
Youssef Hatem
Note: This README represents the current development stage. Additional protocol features will be added as
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Flicense-qualityDmaintenanceA comprehensive airline booking operations server that enables users to search flights, create bookings, check-in, select seats, track flights, and manage loyalty programs through natural language interactions.Last updated1
- AlicenseAqualityCmaintenanceProvides LLM access to the Event Monitoring System (EMS) API for comprehensive flight data analytics and monitoring. It enables users to query flight records, retrieve time-series analytics, and explore aircraft assets or database hierarchies.Last updated10MIT
- AlicenseAqualityAmaintenanceEnables AI agents to plan trips by searching flights, accommodations, and activities, and managing itineraries collaboratively with role-based permissions.Last updated20211MIT
- Flicense-qualityCmaintenanceMCP server for AI agents to execute the complete NevioServiceCenter flight booking flow. It provides 10 tools for flight search, cart management, passenger details, seat selection, ancillaries, and booking confirmation with automatic JWT token management.Last updated
Related MCP Connectors
AI marketplace — flights, tours, activities, transport & more via MCP. No auth required.
Gateway between LLM agents and world data through eight tools and a bundled endpoint catalog.
Live flight prices and working booking links for AI agents and travel apps.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/MarwanELMahdi/EgyptAir-MCP-Server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server