Back to Browse

Dev Allflyghts MCP Server

Developer ToolsModerate5.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Geo-based flight search MCP server. Find more flights between any two places on earth

About

Geo-based flight search MCP server. Find more flights between any two places on earth

Remote endpoints: streamable-http: https://mcp.allflyghts.com/mcp

Security Report

5.2
Moderate5.2Moderate Risk

This is a well-structured MCP server with proper authentication, secure credential handling, and appropriate permissions for its purpose. The server uses environment variables and Azure Key Vault for secrets, implements Bearer token authentication for HTTP mode, and follows good security practices. Minor code quality observations exist but do not materially impact security. Supply chain analysis found 4 known vulnerabilities in dependencies (0 critical, 3 high severity).

7 files analyzed · 8 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

azure_keyvault_read

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

AllFlyghts MCP Server

TypeScript MCP server for the AllFlyghts public API.

This repository is a standalone Node.js project. It exposes AllFlyghts data through MCP tools while keeping the public API key on the server side.

Using AllFlyghts via the hosted MCP server

Most users don't need to install or run this code. AllFlyghts runs a managed MCP server.

Visit for more info: https://www.allflyghts.com/developers/mcp Full docs: https://www.allflyghts.com/mcp

To use it, configure your MCP client (Claude Desktop, Cursor, etc.) to connect to this endpoint with your AllFlyghts API token in the Authorization header:

Authorization: Bearer <your-token>

Get your token at https://www.allflyghts.com/access/sign-in

This repository contains the source code of that hosted server, made public for transparency. You can also run it locally if you want — instructions below.

Tools

  • search_locations
  • get_city
  • search_flights

Requirements

  • Node.js 20+
  • An AllFlyghts public API base URL
  • An AllFlyghts public API key, provided either directly by environment variable or through Azure Key Vault

Environment

Required:

  • ALLFLYGHTS_PUBLIC_API_BASE_URL

Choose one API key source:

  • ALLFLYGHTS_PUBLIC_API_KEY
  • PUBLIC_API_KEY_VAULT_URL together with MCP_PUBLIC_API_KEY_SECRET_NAME

Optional:

  • MCP_AUTH_TOKEN
  • MCP_AUTH_TOKEN_SECRET_NAME
  • MCP_SERVER_NAME
  • MCP_SERVER_VERSION
  • MCP_TRANSPORT
  • PORT
  • MCP_ALLOWED_ORIGINS

If MCP_AUTH_TOKEN or MCP_AUTH_TOKEN_SECRET_NAME is configured for HTTP mode, callers must send:

Authorization: Bearer <token>

Install

npm install

Run

Stdio mode:

npm run dev:stdio

HTTP mode:

npm run dev:http

Production builds:

npm run build

Then start either transport from dist/:

npm run start:stdio
npm run start:http

Notes

  • Streamable HTTP creates a fresh MCP server and transport per request.
  • Secrets are resolved from Azure Key Vault when configured, with direct environment variables as a fallback.
  • Do not commit real API keys, auth tokens, or other secrets to this repository.

Reviews

No reviews yet

Be the first to review this server!