Airsup MCP Server
by tadeus123
README.md
# Airsup ChatGPT App
A zero-dependency remote MCP server that lets ChatGPT discover and communicate with AI agents hosted directly on official websites.
The website remains the registry. Airsup does not maintain a central directory.
## Tools
### `discover_website_agent`
Starts from the official website and checks:
- HTTP `Link` headers
- normal homepage links and image-link metadata
- `/.well-known/agent-card.json`
- `/.well-known/agent.json`
- `/llms.txt`
- `/agent/status.json`
It returns the agent identity, capabilities, discovery sources, and conversational endpoint.
### `talk_to_website_agent`
- Discovers the website agent automatically.
- Sends a GET request with `message` and optional `contextId`.
- Falls back to JSON POST when GET is unsupported.
- Returns `contextId` for continued conversations.
- Separates a tentatively agreed meeting from a real booking.
A remote agent saying “confirmed” is not enough. The tool reports `actionEvidence.status: "confirmed"` only when the response includes structured evidence such as:
- `eventId`
- `reservationId`
- `invitationSent: true`
## Architecture
```text
ChatGPT
-> Airsup MCP app
-> official website
-> website discovery metadata
-> website-owned agent endpoint
```
## Run
Node.js 20 or newer is required. There are no npm dependencies.
```bash
npm run check
npm test
npm start
```
Endpoints:
```text
http://localhost:3000/mcp
http://localhost:3000/health
```
## Test MCP manually
Initialize:
```bash
curl -s http://localhost:3000/mcp \
-H 'content-type: application/json' \
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"test","version":"1"}}}'
```
List tools:
```bash
curl -s http://localhost:3000/mcp \
-H 'content-type: application/json' \
-d '{"jsonrpc":"2.0","id":2,"method":"tools/list","params":{}}'
```
Discover Supi:
```bash
curl -s http://localhost:3000/mcp \
-H 'content-type: application/json' \
-d '{"jsonrpc":"2.0","id":3,"method":"tools/call","params":{"name":"discover_website_agent","arguments":{"site":"tademehl.com"}}}'
```
## Connect to ChatGPT
1. Deploy this server to a stable public HTTPS endpoint.
2. Where Developer Mode is available, create a custom ChatGPT app using:
```text
https://YOUR-DOMAIN.example/mcp
```
3. Scan tools and add the app to the conversation.
4. Test:
```text
Find Supi on tademehl.com and negotiate a meeting in three messages. Reuse the returned contextId. Do not call it booked unless the remote agent returns completion evidence.
```
## Deployment
The included Dockerfile can run on Render, Railway, Fly.io, Cloud Run, App Runner, or another container host.
```bash
docker build -t airsup-chatgpt-app .
docker run --rm -p 3000:3000 airsup-chatgpt-app
```
A `render.yaml` is included.
## Security
- HTTPS-only outbound requests by default.
- Blocks localhost, private, loopback, link-local, reserved, and documentation IP ranges.
- Rejects domains resolving to restricted addresses.
- Requires discovered agent endpoints to remain on the official website origin.
- Limits redirects, response size, request duration, and MCP request size.
- Validates incoming browser `Origin` headers against `ALLOWED_ORIGINS`.
- Does not accept arbitrary outbound headers, cookies, credentials, or tokens.
For a public high-scale service, route outbound traffic through an egress proxy that pins DNS for the full connection. The included DNS validation materially reduces SSRF exposure but does not eliminate every possible DNS-rebinding race.
## Important limitation
This version implements the minimal stateless JSON form of MCP Streamable HTTP directly, without the MCP SDK. That avoids dependency installation and is easy to audit. Before public directory submission, run it through the current MCP Inspector and ChatGPT Developer Mode, then migrate to or validate against the current official MCP SDK release if the protocol surface changes.
The next product version should add native A2A transport support for websites that expose only a formal A2A interface rather than a simple chat URL.
This server cannot be deployed
Maintenance
ActivitySlowing
ResponsivenessNo issues