Duffel MCP

Search flights, hold and pay for bookings, and manage orders through Duffel from your AI assistant.

  1. Sign in and connect Duffel

    On the account page, sign in with an allowed email. Open Duffel → Developers → Access tokens, create a read-write token, then paste it into your connection. Start with a duffel_test_ token: test mode returns synthetic Duffel Airways flights and never charges anything. Use a Duffel token; do not paste an MCP token here. The service encrypts the saved token.

    Set the currency and the per-order maximum your assistant may spend, then tick Allow booking only when you want it to hold, pay for and cancel orders. A live token (duffel_live_) additionally needs Allow live booking before any real ticket can be issued; live orders are charged to your pre-funded Duffel balance. An optional daily cap limits live spend per UTC day.

    Add a traveler profile for each person the assistant may book (name, date of birth, contact details, optional passport). Your assistant only ever sees a label and an id for each profile.

  2. Create a personal MCP token

    In the account page’s MCP tokens section, create a named token, choose read-only or read/write and an expiry, then copy it immediately. It is shown only once. Read-only tokens can search flights and view orders; read/write tokens can also hold, pay and cancel within your connection’s limits. Revoke it from the account page if it is exposed or no longer needed.

  3. Configure your MCP client

    Add a remote server using Streamable HTTP at:

    https://duffel-mcp.sherwoodcallaway.com/mcp

    Set bearer-token authentication with your personal MCP token. Claude Code:

    claude mcp add --transport http duffel https://duffel-mcp.sherwoodcallaway.com/mcp --header "Authorization: Bearer <YOUR_PERSONAL_MCP_TOKEN>"

    For clients using JSON server configuration:

    {
      "mcpServers": {
        "duffel": {
          "url": "https://duffel-mcp.sherwoodcallaway.com/mcp",
          "headers": { "Authorization": "Bearer <YOUR_PERSONAL_MCP_TOKEN>" }
        }
      }
    }

    Replace the placeholder on your device; never include a real token in a URL, shared configuration, or chat. This service uses bearer tokens. OAuth-only clients cannot connect. MCP Gateway is optional.

  4. Verify and manage access

    Reload the tools in your client. Call search for getAccount, then execute it; confirm the mode and limits are what you set. Try searchPlaces and searchFlights, then getOffer on a result. Booking is a handshake: holdOrder reserves without charging, and payOrder requires the exact current total as confirmedTotal, so your assistant must show you the price first.

    • 401 Unauthorized: check the endpoint and bearer header; create a replacement if the MCP token expired or was revoked.
    • Duffel authorization error: check that the Duffel token is active and read-write. Save a replacement in your connection.
    • Booking refused: enable booking (and live booking for a live token) on your connection, raise the per-order maximum, and use a read/write MCP token.
    • Offer no longer available: offers expire within minutes; search again and re-price with getOffer.

    Disconnect the Duffel connection and revoke MCP tokens from the account page to stop access. You can also revoke the access token directly in Duffel.