Repository navigation
Releases: alexechoi/avios-cli
Release list
avios-cli v0.6.0 — MCP server for AI agents
Your Avios accounts, and British Airways reward availability, available to Claude
and any other MCP client.
uv tool install 'avios-cli[mcp]'
avios login ba # sessions come from the CLI
claude mcp add avios -- avios-mcpAdded
MCP server (avios-mcp) — six read-only tools over stdio: list_accounts,
get_balance, get_transactions, get_pending_transactions, whoami,
search_reward_flights. Closes #45.
Sessions come from avios login, so the server never performs a login itself —
that stays a deliberate human action in a terminal.
The safeguards are the interesting part:
- Read-only. Nothing books, spends, or mutates a session.
- No credentials in output. Every tool returns an explicit response model
rather than a raw API payload, so cookies, API keys andwhoami's id token
cannot leak through a field nobody thought about. - Reward search is batched and rate-limited. British Airways blocks by IP
address, so an agent exploring "what about March? what about via LGW?" could
lock you out of the site. A whole return trip goes through one batched,
single-browser-session search; the server enforces a cooldown between searches;
and a block is reported as terminal and explicitly not retryable. - MCP is an optional extra, so a plain CLI install does not pull in the SDK's
web stack. Runningavios-mcpwithout it prints the install command rather than
a traceback.
Built against MCP Python SDK 2.x.
Full changelog: https://github.com/alexechoi/avios-cli/blob/main/CHANGELOG.md
avios-cli v0.5.0 — BA reward search fixed + Avios prices
British Airways replaced the reward-flight finder with a new Next.js app, which
broke reward search. This release follows the new protocol, cuts the request
volume that was getting IPs blocked, and picks up the Avios pricing the new
searcher exposes.
uvx avios-cli flights LON HKG --date 2027-01-06Fixed
- Reward search returned nothing. Each day's flights moved one level deeper
(departureJourneys.<date>.journeys[].flights[]instead of
departureJourneys.<date>.flights[]), so every day parsed as empty. - Business always reported 0 seats. BA's availability rows use cabin code
J;
we only looked forC. Both are now recognised. - Fewer requests, far less chance of being blocked. Every leg used to launch
its own Chrome, navigate to the finder and drive the search form — that
page-load traffic is what earns an IP a site-wide 403 from Akamai. A search now
warms one navigation and issues in-pagefetch()calls for everything after it,
paced. A two-leg return trip costs one navigation and two fetches. - Akamai denials are told apart from an expired session: you get "wait a few
minutes and switch network" instead of being sent to log in again, and the
remaining legs are abandoned rather than hammering a blocked endpoint. - The request contract is reproduced byte for byte against a live capture,
including bothnext-router-state-treevariants. The default user-agent claimed
Chrome/126 while thesec-ch-uaclient hints claimed 148 — a disagreement that
is itself a bot signal — and now matches.
Added
-
Avios prices. Searching an exact
--dateshows the Avios cost per cabin for
your party, in both the CLI and the TUI. Calendar (month) searches stay
seats-only, which keeps them to one request per leg.│ BA0031 │ LHR→HKG │ 18:55 │ 15:50 │ 12h 55m │ 9 · 38,500 │ 7 · 55,000 │ — │ — │ no │ -
Exact-date searches re-read that date the way clicking a day does, so seat
counts are fresh rather than served from the month cache. -
Seats that only sell against a BA companion voucher are marked
†instead of
being counted as general availability. -
Dates beyond BA's rolling booking horizon are recognised and no longer render as
"no reward seats"; an out-of-range month now reports the window BA actually
offers. -
AviosClient.search_reward_legs()searches every leg of a trip over one browser
session and reports failures per leg.
Breaking
avios flights --json reports days as journeys[].flights[], following the
upstream shape, and includes the price attached to each cabin.
Full changelog: https://github.com/alexechoi/avios-cli/blob/main/CHANGELOG.md
avios-cli v0.4.3 — login works with plain uvx
uvx avios-cli login now works out of the box — no more uvx --from 'avios-cli[login]' ….
- Browser-assisted login (Playwright + browser-cookie3) moved into the base package, so
uvx avios-cli login,login iberia,login finnairall work with no extra flags. - If you have no system Chrome, login now downloads Chromium automatically on first use (~150 MB, one-time).
- The
loginextra is kept as a no-op alias, soavios-cli[login]still resolves.
uvx avios-cli login iberia
uvx avios-cli balanceavios-cli v0.4.2 — live BA reward search
Fixed
- BA login now waits for the reward-flight finder’s separate Auth0 session and second login prompt.
- Reward searches drive the website’s real form through a background Chrome window, avoiding Akamai’s rejection of plain HTTP and headless result requests.
- Chrome owns and refreshes anti-bot cookies; only application-session cookies may seed an empty profile.
- Rapid consecutive searches retry one transient Next.js shell response.
- Passenger searches now enforce BA’s nine-traveller limit.
Verified
- 125 tests plus Ruff and mypy
- CI on Python 3.10–3.13 and GitGuardian
- live month, exact-date, two-adult return, and JSON reward searches
avios-cli v0.4.1 — Finnair fix
Fixes Finnair balance/transactions failing with 403 immediately after login.
- #28: login was capturing the wrong
x-api-key(fromgetgauth, which uses a different key than the loyalty balance/transactions endpoints). It now captures from a loyalty API request, so calls use the key those endpoints accept. - #29: a
403 Forbiddenis no longer mislabelled "session expired"; the message names the real cause.
If you logged into Finnair on 0.4.0, just uvx --from 'avios-cli[login]' avios login finnair again on 0.4.1 (or your existing session may already work).
avios-cli v0.3.0 — multi-account
Multiple Avios accounts, one per programme, with combined views.
Highlights
- Multiple accounts:
avios login [ba|iberia|aerlingus|finnair],avios logout [programme], and a newavios accountsroster. - Combined views:
balancesums all accounts into a combined total;transactions/pendingmerge across accounts with a Programme column;--account/-afilters to one. - Finnair Plus via CAS/OAuth (token-backed), alongside the cookie-based BA/Iberia/Aer Lingus programmes.
- Multi-account TUI: combined balance header + Programme column, loaded concurrently.
- Per-programme session storage (
~/.config/avios/accounts/<programme>.json), migrated from the old singlestate.json.
Install: uvx avios-cli · log in: uvx --from 'avios-cli[login]' avios login
Full notes: see CHANGELOG.
avios-cli v0.2.1
What's Changed
- PR17: friendly message for expired-session timeouts (v0.2.1) by @alexechoi in #21
Full Changelog: v0.2.0...v0.2.1
avios-cli v0.2.0 — transactions
What's Changed
- PR16: unlock transactions/overview via x-avios-opco header (v0.2.0) by @alexechoi in #20
Full Changelog: v0.1.6...v0.2.0
avios-cli v0.1.6
What's Changed
- PR15: balance/whoami use endpoints that actually authenticate (v0.1.6) by @alexechoi in #19
Full Changelog: v0.1.5...v0.1.6
avios-cli v0.1.5
What's Changed
- PR14: --from-browser scans all Chrome profiles + verifies auth (v0.1.5) by @alexechoi in #18
Full Changelog: v0.1.4...v0.1.5