
Security News
6 AppSec CTOs Debate Open Source Supply Chain Security at Black Hat
Socket CTO Ahmad Nassri joins AppSec leaders at Black Hat to discuss active malware, package manager risks, and software supply chain defense.
@furlpay/travel-mcp
Advanced tools
FurlPay Travels — an MCP server composing Travala's Travel MCP (search) with FurlPay payment rails (x402/USDC on Base or single-use MCC-locked Visa VCN). Captures the 10% cbBTC developer rebate. Zero runtime dependencies.
The payment & orchestration layer for agentic travel. This MCP server composes Travala's Travel MCP (search 2.2M+ hotels + flights) with FurlPay's payment rails (pay), so an AI agent can search, budget-check, pay, and book travel autonomously.
Two payment routes, chosen per booking:
Clone-and-run: with no keys, search and payment simulate end-to-end (no network) so you can drive the whole loop offline. Zero runtime dependencies.
Maintained by FurlPay · MIT licensed.
{
"mcpServers": {
"furlpay-travels": {
"command": "npx",
"args": ["-y", "@furlpay/travel-mcp"],
"env": {
"FURLPAY_API_KEY": "fp_live_sk_...", // omit for demo mode
"TRAVALA_API_KEY": "...", // omit for demo inventory
"DUFFEL_API_KEY": "duffel_test_...", // live flight offers (free test token, duffel.com)
"FURLPAY_DEVELOPER_WALLET": "0xYourWallet" // receives the 7% cbBTC split
}
}
}
}
| Tool | What it does |
|---|---|
travel_search_stays | Search Travala hotels for a city + date range |
travel_search_flights | Search flights for a route + date |
travel_set_agent_budget | Cap an agent's USDC travel spend |
travel_authorize_booking | Pay a booking — x402/USDC (Travala) or single-use MCC-locked Visa VCN (legacy) |
travel_confirm_booking | Confirm after passkey step-up |
travel_cancel_booking | Cancel & void the authorization |
travel_list_rebates | Accumulated 10% cbBTC rebates (7% dev / 3% treasury) |
Visa's Trusted Agent Protocol went
production-live in July 2026: agent-initiated payments carry cryptographic proof of
agent identity and user consent. This server supports the same model via
@furlpay/agent-trust — configure a
MandateVerifier and every travel_authorize_booking call must present a
mandateToken: an agent-signed intent under a user-signed spend mandate
(budget cap, MCC allowlist, expiry, single-use, replay-safe).
import { TravelClient } from "@furlpay/travel-mcp";
import { AgentTrust, generateKeypair, issueMandate, createBookingToken } from "@furlpay/agent-trust";
const trust = new AgentTrust();
trust.registerUser(user.publicKeyPem);
trust.registerAgent(agent.publicKeyPem);
const travel = new TravelClient({ trust }); // bookings now REQUIRE a valid mandateToken
const mandate = issueMandate({ /* user signs: $500 cap, MCC 7011+4511, 7-day expiry */ });
const mandateToken = createBookingToken({ mandate, /* agent signs THIS exact intent */
intent: { amountUsd: 320, source: "legacy", mcc: "7011" } });
const booking = await travel.authorizeBooking({ amountUsd: 320, source: "legacy", mandateToken });
// booking.trust = { agentKeyId, mandateId, remainingUsd }
The verifier checks the full chain — user signed the mandate, mandate names this agent, agent signed this exact amount/mcc/source, constraints hold, nonce never seen — before any x402 proof or virtual card is issued. Without a verifier configured, behavior is unchanged (back-compat).
import { TravelClient, MCC } from "@furlpay/travel-mcp";
const travel = new TravelClient({ developerWallet: "0xDev" });
const stays = await travel.searchStays({
city: "London", checkIn: "2026-08-01", checkOut: "2026-08-04", maxNightlyUsd: 200,
});
travel.setAgentBudget("agent_1", 1000);
// Crypto-native route → x402/USDC on Base + 10% cbBTC rebate
const booking = await travel.authorizeBooking({
amountUsd: stays[0].totalUsd, source: "travala", agentId: "agent_1", reference: stays[0].quoteId,
});
// booking.authorization.x402 · booking.rebate.developerUsd
// Legacy merchant route → single-use MCC-locked Visa VCN
const legacy = await travel.authorizeBooking({ amountUsd: 130, source: "legacy", mcc: MCC.LODGING });
// legacy.authorization.card = { last4, mccWhitelist, singleUse, limitUsd }
travel.listRebates(); // { developerTotalUsd, treasuryTotalUsd, accruals }
Set DUFFEL_API_KEY and travel_search_flights returns live real-time
offers — NDC + GDS + LCC content from 300+ airlines via
Duffel, cheapest first. Free test tokens
(duffel_test_…) work out of the box against Duffel's sandbox inventory.
Any Duffel failure falls back to Travala/demo, so the agent loop never breaks.
Why Duffel in mid-2026: Amadeus Self-Service shuts down July 17 2026, Kiwi's Tequila is closed to new partners, and Expedia/Booking gate API access behind commercial review — Duffel is the one top-1% supplier a developer can start on today with no contract.
| Route | Rail | Why |
|---|---|---|
travala | x402 → gasless USDC on Base, ~$0.01/booking | The rail Travala's protocol accepts directly; earns the cbBTC rebate |
legacy | Single-use Visa VCN, MCC-locked (7011 lodging, 4511 airlines, 7512 car rental) | Reaches Web2 travel merchants Travala doesn't cover; card can only spend on travel, up to the booking total |
FurlPay's value here is the layer Travala doesn't provide: agent spend budgets, multi-token funding, VCN issuing for legacy merchants, and rebate accounting.
npm run example # full search → pay → book → rebate flow, demo mode
npm start # run the MCP server on stdio
npm test # tsc build + node --test (demo mode, no network)
The suite pins the contract: deterministic search, the x402 route's proof + exact 10%/(7/3) rebate math, the legacy route's single-use MCC-locked VCN, budget enforcement, the confirm/cancel lifecycle, rebate aggregation (excluding cancellations), and well-formed MCP tools.
This server orchestrates Travala search and FurlPay payments — it does not custody funds or settle on-chain itself; x402 settlement and card issuing happen in the FurlPay API, and inventory/fulfilment in Travala. Point it at your own accounts and it books on your behalf. Issuing travel cards and handling refunds carries money-transmission/merchant-compliance obligations — wire in FurlPay's compliance engine before going live.
MIT
FAQs
FurlPay Travels — an MCP server composing Travala's Travel MCP (search) with FurlPay payment rails (x402/USDC on Base or single-use MCC-locked Visa VCN). Captures the 10% cbBTC developer rebate. Zero runtime dependencies.
The npm package @furlpay/travel-mcp receives a total of 11 weekly downloads. As such, @furlpay/travel-mcp popularity was classified as not popular.
We found that @furlpay/travel-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri joins AppSec leaders at Black Hat to discuss active malware, package manager risks, and software supply chain defense.

Research
/Security News
Thirteen malicious Packagist themes expose visitors on unpatched iPhones to a WebKit-to-kernel exploit chain that steals device data and wallet seeds.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.