Agent skill

Amex Travel

by borski in borski/travel-hacking-toolkit

Search Amex travel portal for cash prices, MR points pricing, IAP discounts, and FHR/THC hotel benefits via Patchright.

MITAuto-check passed

Install Amex Travel

skills CLI
$ npx skills add borski/travel-hacking-toolkit --skill amex-travel -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borski/travel-hacking-toolkit amex-travel --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borski/travel-hacking-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/travel-hacking-toolkit/skills/amex-travel .claude/skills/amex-travel && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
amex-travel
GitHub stars
688
Token cost
~3.1k tokens
SKILL.md length
1,348 words
Files
5 (incl. scripts)
Skills in repo
46
Repo updated
First seen
Licence
MIT

At a glance

Search Amex travel portal for cash prices, MR points pricing, IAP discounts, and FHR/THC hotel benefits via Patchright.

  • Works in 3 steps: When the gate rejects the automated… → The user runs, locally, not in Docker → Subsequent runs — including Docker runs…
  • Comparing pay-with-points portal pricing to award alternatives
  • SKILL.md covers Prerequisites, When to Use, When NOT to Use and Usage, plus 9 more sections
  • Runs Python scripts from its folder; calls python3, docker and pip; needs AMEX_PASSWORD and AMEX_BAD_CREDENTIALS

What it does

Amex Travel is an agent skill from borski/travel-hacking-toolkit. Search Amex travel portal for cash prices, MR points pricing, IAP discounts, and FHR/THC hotel benefits via Patchright. Use when comparing pay-with-points portal pricing to award alternatives.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts (for example `scripts/refresh_login.py`, `scripts/search_flights.py` and `tests/test_search_flights.py`).

The repository describes itself as: AI-powered travel hacking and search with cash, points, miles, and award flights. Drop-in skills and MCP servers for Claude, Codex, and OpenCode. The licence is MIT.

When your agent uses it

  • Comparing pay-with-points portal pricing to award alternatives

Example prompts

  • “/amex-travel”

Requirements

  • Python 3
  • Docker

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. When the gate rejects the automated login (captcha or otherwise), the script prints AMEX_HUMAN_LOGIN_NEEDED to stdout (and writes…
  2. The user runs, locally, not in Docker
  3. Subsequent runs — including Docker runs mounting ~/.amex-travel-profiles — reuse the warm session and skip the gate.

What it can do on your machine

Read from SKILL.md and the folder at commit db82131. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • docker
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AMEX_PASSWORD
    • AMEX_BAD_CREDENTIALS

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Amex Travel loads about 3.1k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 1,348 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borski/travel-hacking-toolkit at commit db82131, republished under its MIT licence (© borski). 1,348 words, ~3,086 tokens.

Download SKILL.mdSave it as .claude/skills/amex-travel/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
amex-travel
description
Search Amex travel portal for cash prices, MR points pricing, IAP discounts, and FHR/THC hotel benefits via Patchright. Use when comparing pay-with-points portal pricing to award alternatives.
category
portals
summary
Amex MR portal for flights, hotels, IAP discounts, FHR/THC benefits. Requires Platinum.
api_key
None (requires Patchright)
docker_image
ghcr.io/borski/amex-travel

Search the American Express travel portal for flights and hotels via Patchright. Returns cash prices, MR points pricing, International Airline Program (IAP) discounts, and Fine Hotels & Resorts / The Hotel Collection benefits.

Requires Patchright (undetected Playwright fork). Amex blocks standard Playwright and agent-browser.

Must run headed (headless=False). Amex detects headless browsers. On macOS, a Chrome window briefly appears. For background operation, use Docker.

Prerequisites

bash
pip install patchright && patchright install chromium

Or use Docker (no local install needed):

bash
docker pull ghcr.io/borski/amex-travel:latest
# or build locally:
docker build -t amex-travel skills/amex-travel/

When to Use

  • Compare Amex portal MR pricing against cash and award prices
  • Find IAP (International Airline Program) discounted fares on Platinum
  • Find FHR and THC hotels with benefits ($100 credit, breakfast, upgrade)
  • Compare portal redemption value against transfer-to-airline value

When NOT to Use

  • Completing purchases. Find flights and hotels only. Do not book.
  • Non-Platinum cards. IAP fares and FHR benefits require the Platinum Card.

Usage

bash
# Local (opens a Chrome window briefly)
python3 scripts/search_flights.py --origin SFO --dest CDG --depart 2026-08-11

# Round-trip business
python3 scripts/search_flights.py --origin SFO --dest CDG --depart 2026-08-11 --return 2026-09-02 --cabin business

# JSON output
python3 scripts/search_flights.py --origin SFO --dest CDG --depart 2026-08-11 --json

# Docker
docker run --rm \
    -v ~/.amex-travel-profiles:/profiles \
    -e AMEX_USERNAME -e AMEX_PASSWORD \
    amex-travel script /app/search_flights.py \
    --origin SFO --dest CDG --depart 2026-08-11 --cabin business --json
bash
# Local
python3 scripts/search_flights.py --hotel --dest "Oslo" --checkin 2026-08-13 --checkout 2026-08-15

# Docker
docker run --rm \
    -v ~/.amex-travel-profiles:/profiles \
    -e AMEX_USERNAME -e AMEX_PASSWORD \
    amex-travel script /app/search_flights.py \
    --hotel --dest "Oslo" --checkin 2026-08-13 --checkout 2026-08-15 --json
Record Mode (API Discovery)

Capture network traffic during a manual search:

bash
python3 scripts/search_flights.py --record
Offline Debug (Hotels)

Save and re-parse hotel results without re-running the browser:

bash
# Save page HTML after hotel search
python3 scripts/search_flights.py --hotel --dest "Paris" --checkin 2026-08-11 --checkout 2026-08-15 --save-html /tmp/amex-hotels.json

# Re-parse locally (instant, no browser)
python3 scripts/search_flights.py --parse-html /tmp/amex-hotels.json

2FA Flow

Amex uses email OTP for 2FA. After first login with "Add This Device", subsequent runs skip 2FA from the same profile.

How it works: When 2FA is triggered, the script prints 2FA_CODE_NEEDED to stdout and 2FA REQUIRED to stderr, then polls for the code. It will wait up to 2 minutes.

For agents: When you see 2FA_CODE_NEEDED in the script output, ask the user for the verification code Amex just emailed them. Once they provide it, write it to the code file:

bash
echo "123456" > /tmp/amex-2fa-code.txt

The script picks up the file automatically and continues login.

Command hook (optional, for full automation): Set AMEX_2FA_COMMAND to a command that blocks until it has the code, then prints it to stdout. The script runs this instead of polling the file.

After first login with "Add This Device", 2FA is skipped on repeat runs from the same profile.

Known Limitation: travel-portal login captcha (May 2026)

As of Amex's May 2026 overhaul, submitting a flight search redirects through a separate travel-portal login gate (/account/travel/login) — even when already signed in to americanexpress.com — protected by a risk-based captcha layer. The script fills and submits the gate automatically, and the outcome depends on how Amex scores the session that run:

  • Sometimes it passes — the automated re-auth is accepted and results load end to end (verified live July 2026: full Docker run returned 50 parsed flights).
  • Sometimes it's silently swallowed — fields hold the correct values after submit, the form's own #loginSubmit was clicked, no error renders, captcha markers sit in the DOM, and the page never advances. Also verified live, same day, same credentials, same container.

The travel session is also short-lived (next-auth token, ~1 hour), so warm sessions expire quickly and the gate re-appears often. On gate failure the script prints a Gate diag: line (field/button/alert state) so breakage is diagnosable from logs, then exits promptly instead of waiting out the results timeout. Hotel search may be affected similarly.

The wall only exists on fresh logins. With a warm saved session (valid cookies + trusted device), the gate passes automatically and searches work end to end. So the recovery is a one-time human step, not a dead end:

  1. When the gate rejects the automated login (captcha or otherwise), the script prints AMEX_HUMAN_LOGIN_NEEDED to stdout (and writes HUMAN_LOGIN_NEEDED to /tmp/amex-2fa-status.txt). For agents: stop retrying and tell the user to run the refresh script. (A separate sentinel, AMEX_BAD_CREDENTIALS, means the credential env vars contained an unresolved secret-manager reference instead of real values — fix the credential injection, not the login.)

  2. The user runs, locally, not in Docker:

    bash
    python3 scripts/refresh_login.py

    A real Chrome window opens on the travel portal. They log in themselves (password, captcha, email code, "Add This Device"), and the script saves the refreshed cookies/profile automatically, printing AMEX_SESSION_REFRESHED when done.

  3. Subsequent runs — including Docker runs mounting ~/.amex-travel-profiles — reuse the warm session and skip the gate.

To keep the session from going stale, run any cheap search (or refresh_login.py, which exits as soon as it sees a logged-in page) every week or two. Prefer a residential IP; datacenter and hotel IPs draw extra Akamai scrutiny.

How It Works

Flight Search Architecture
  1. Auth: Cookie injection from saved profile. Falls back to fresh login with email 2FA.
  2. Form filling: DOM-based search form automation (airport autocomplete, calendar picker, cabin selector)
  3. Login gate: After form submission, Amex redirects through a login interstitial. Script handles re-authentication automatically (risk-based; see Known Limitation).
  4. Data extraction (new UI, May 2026+): Results land on travel.americanexpress.com/en-us/book/flights/search-results, a Next.js app with no usable window.appData (__NEXT_DATA__ is config only). The script parses the DOM's [data-testid="offer-card-wrapper"] cards — airline, times, airports, duration, stops, cash, points, was/now discounts all carry dedicated data-testids.
  5. Data extraction (legacy fallback): If no offer cards appear, the script falls back to the old window.appData Redux-store extraction (627KB JSON blob).
  6. IAP detection: Cards carrying the private-fare-banner-PEP* banner with a "was $X now it's $Y" cash discount are IAP (Platinum Member Airfares), typically 10-15% off front-of-cabin international. Alaska "Insider Fares" (points-only discounts) are flagged separately via insider_fare/points_discount.
Show full SKILL.md (512 more words)Show less
Hotel Search Architecture
  1. Form filling: Same DOM-based approach as flights
  2. Login gate: Handled automatically
  3. Data extraction: Hotels render as a Next.js app with NO window.appData. Script parses the DOM using data-testid="hotel-offer-card" elements.
  4. FHR/THC detection: Identified via data-testid="offer-banner" text ("Fine Hotels and Resorts" or "The Hotel Collection")
  5. Benefits extraction: FHR/THC cards show benefits (breakfast, credit, upgrade) as data-testid="offer-amenities-item" elements
Data Structure

Flight results (from window.appData.flightSearch.itineraries[]):

  • pricing_information[] with fare_type = PEP (IAP) or PUB (public)
  • total_price.cents (cash), total_price_in_points (MR points = 1 cent per point)
  • segment.legs[] with carrier, times, duration, cabin, equipment, amenities
  • segment.seats_left, is_refundable, cancellation_policy

Hotel results (from DOM parsing):

  • Hotel name, stars, city, distance
  • TripAdvisor rating and review count
  • Per-night price and total price
  • MR points cost
  • FHR/THC membership with specific benefits
  • Standard amenities (wifi, breakfast, parking)

International Airline Program (IAP)

Platinum Card benefit. Lower fares on premium cabin seats for international flights on select airlines. Shows as a separate PEP fare type alongside PUB (public fare).

  • Typically 10-15% savings on business/first class
  • Not available on all routes or airlines
  • Only visible when logged in with a Platinum Card

Output Format

Always use markdown tables.

Flights
#AirlineRouteStopsDurationCashIAP CashPointsSeats
1TurkishSFO-IST-CDG120h 10m$5,044$4,381438,1133
Hotels
#HotelProgramStarsPer NightTotalPointsBenefits
1Hotel ContinentalFHR5$471$94294,200Breakfast, $100 credit, upgrade, 4pm checkout
After Tables
  • Flag IAP savings (show % discount)
  • Note FHR/THC benefits and how they offset the rate
  • Calculate effective CPP for MR redemptions (1 point = 1 cent at Amex portal)
  • Compare against transfer-to-airline value
  • Mention the $600/yr Platinum hotel credit ($300 per half-year, shared between FHR and THC)

Cabin Codes

CLI ValueAmex CodeDescription
economyECONOMYStandard economy
premiumPREMIUM_ECONOMYPremium economy
businessBUSINESSBusiness class
firstFIRSTFirst class

Environment Variables

VariableRequiredDescription
AMEX_USERNAMEYesAmex online account username
AMEX_PASSWORDYesAmex online account password
AMEX_PROFILENoBrowser profile directory (default: ~/.amex-travel-profiles/default)
AMEX_2FA_COMMANDNoCommand that blocks until email code is ready, prints to stdout

Troubleshooting

  • Login gate after search: Normal. Amex always redirects through a login interstitial after form submission. The script handles this automatically.
  • No appData found (flights): The page may not have fully loaded. Script waits for the Redux store to populate. Check if login succeeded.
  • Empty hotel results: Hotels use DOM parsing, not appData. If the DOM structure changed, the data-testid selectors may need updating.
  • Calendar picker fails: Amex uses div[role="button"] for calendar days (not <button>). The script uses class patterns automation-date-picker-month-{year}-{month} to find the right month container.
  • 2FA code rejected: Amex codes expire quickly. Make sure the code is fresh (not an old one from a previous login).

Limitations

  • Headed mode required. Amex detects headless. Docker+xvfb is the workaround.
  • ~45 seconds per search. Login + form fill + login gate + results load.
  • Hotel results via DOM only. No API interception available for hotels (Next.js app with empty __NEXT_DATA__). Parser depends on data-testid attributes.
  • Device trust helps. After "Add This Device" on first login, 2FA is skipped for that profile. Keep profiles persistent via Docker volume mounts.

© borski, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts) in plugins/travel-hacking-toolkit/skills/amex-travel of borski/travel-hacking-toolkit.

  • SKILL.md
  • Dockerfile
  • scripts/refresh_login.py
  • scripts/search_flights.py
  • tests/test_search_flights.py

Open the folder on GitHubat commit db82131

Compare with similar skills

Amex Travel next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Amex Travel compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Amex Travel this skillborski/travel-hacking-toolkit688—~3.1kAutomated safety check: PassMIT
Pricingsickn33/agentic-awesome-skills47k1 repos~1.9kAutomated safety check: PassMIT
Pricing Strategyphuryn/pm-skills27k—~913Automated safety check: PassMIT
Pricing Strategyalirezarezvani/claude-skills28k1 repos~3.5kAutomated safety check: PassMIT
Pricing Strategistalirezarezvani/claude-skills28k—~2.3kAutomated safety check: PassMIT
SaaS Pricing Strategistsickn33/agentic-awesome-skills47k1 repos~1.5kAutomated safety check: PassMIT

Similar skills

  • Pricing

    sickn33/agentic-awesome-skills

    When the user wants help with pricing decisions, packaging, or monetization strategy.

    47k GitHub starsUsed in 1 repo~1.9k tokens
    Sales & SupportAuto-check passed
  • Pricing Strategy

    phuryn/pm-skills

    Analyze and design pricing strategies including pricing models, competitive pricing analysis, willingness-to-pay estimation, and price elasticity.

    27k GitHub stars~913 tokensUpdated yesterday
    Sales & SupportAuto-check passed
  • Pricing Strategy

    alirezarezvani/claude-skills

    Design, optimize, and communicate SaaS pricing — tier structure, value metrics, pricing pages, and price increase strategy.

    28k GitHub starsUsed in 1 repo~3.5k tokens
    Sales & SupportAuto-check passed
  • Pricing Strategist

    alirezarezvani/claude-skills

    A skill your agent uses when designing or revisiting product pricing — selecting a pricing model (subscription seat-based, usage-based, value-based, freemium, or hybrid), running Van Westendorp…

    28k GitHub stars~2.3k tokensUpdated 1 mo ago
    Sales & SupportAuto-check passed
  • SaaS Pricing Strategist

    sickn33/agentic-awesome-skills

    Design, optimize, and test pricing strategies for SaaS products using data-driven frameworks, competitive analysis, and psychological pricing principles.

    47k GitHub starsUsed in 1 repo~1.5k tokens
    Marketing & SEOAuto-check passed
  • Add Model Price

    langfuse/langfuse

    A skill your agent uses when editing worker/src/constants/default-model-prices.json, packages/shared/src/server/llm/types.ts, pricing tiers, tokenizer IDs, or matchPattern regexes for OpenAI…

    36k GitHub stars~1.2k tokensUpdated today
    AI & LLM EngineeringAuto-check passed

More from borski/travel-hacking-toolkit

All 46 skills in this repo
  • Chase Travel

    borski/travel-hacking-toolkit

    Search Chase UR travel portal via Patchright for cash prices, points pricing, Points Boost offers, and Chase Edit hotel benefits.

    688 GitHub stars~2.8k tokensUpdated 6 days ago
    Auto-check passed
  • Deutsche Bahn

    borski/travel-hacking-toolkit

    Deutsche Bahn train schedules, journey planning, and departures across Germany and into neighboring countries (Austria, Switzerland, Netherlands, France, Belgium).

    688 GitHub stars~1.5k tokensUpdated 6 days ago
    Auto-check passed
  • Sutochno

    borski/travel-hacking-toolkit

    Search Sutochno.ru (СУТОЧНО.РУ), a Russian short-term apartment-rental platform where you book directly from owners and pay in rubles (Mir card / bank transfer).

    688 GitHub stars~2.1k tokensUpdated 6 days ago
    Auto-check passed
  • Ticketsatwork

    borski/travel-hacking-toolkit

    Search TicketsAtWork (EBG corporate perks) for hotels, theme park tickets, attractions, and rental cars via Patchright.

    688 GitHub stars~4.2k tokensUpdated 6 days ago
    Auto-check passed
  • Vrbo

    borski/travel-hacking-toolkit

    Search VRBO (Vrbo / Expedia Group) vacation rentals including entire homes, condos, and cabins via Patchright browser automation.

    688 GitHub stars~1.7k tokensUpdated 6 days ago
    Auto-check passed
  • American Airlines

    borski/travel-hacking-toolkit

    Check American Airlines AAdvantage balance, elite status, and loyalty points via Patchright.

    688 GitHub stars~1.3k tokensUpdated 6 days ago
    Auto-check passed

Questions about Amex Travel

What does Amex Travel do?

Search Amex travel portal for cash prices, MR points pricing, IAP discounts, and FHR/THC hotel benefits via Patchright. Amex Travel is an agent skill from borski/travel-hacking-toolkit. Search Amex travel portal for cash prices, MR points pricing, IAP discounts, and FHR/THC hotel benefits via Patchright.

When should I use Amex Travel?

Amex Travel fits situations like: comparing pay-with-points portal pricing to award alternatives.

How do I install Amex Travel in Claude Code?

Run `npx skills add borski/travel-hacking-toolkit --skill amex-travel -a claude-code`. Or copy the skill folder (plugins/travel-hacking-toolkit/skills/amex-travel in borski/travel-hacking-toolkit) into .claude/skills/amex-travel in your project. Claude Code loads it when a task matches its description.

How do I install Amex Travel in Codex?

Run `npx skills add borski/travel-hacking-toolkit --skill amex-travel -a codex`. Or copy the skill folder (plugins/travel-hacking-toolkit/skills/amex-travel in borski/travel-hacking-toolkit) into .agents/skills/amex-travel in your project. Codex loads it when a task matches its description.

Can I use Amex Travel in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borski/travel-hacking-toolkit --skill amex-travel -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/amex-travel, .gemini/skills/amex-travel, .github/skills/amex-travel and .opencode/skills/amex-travel in your project.

What does Amex Travel need to run?

Going by SKILL.md and its folder, Amex Travel needs Python for the scripts in its folder, the command-line tools its instructions call (python3, docker and pip) and credentials named AMEX_PASSWORD and AMEX_BAD_CREDENTIALS. Our summary lists: Python 3; Docker.

Does Amex Travel access the network?

SKILL.md contains no URLs. Its commands use docker and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Amex Travel safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Amex Travel use?

Amex Travel is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Amex Travel use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Amex Travel?

Skills that share tags, products or a category with Amex Travel: Pricing (sickn33/agentic-awesome-skills, 47k stars), Pricing Strategy (phuryn/pm-skills, 27k stars), Pricing Strategy (alirezarezvani/claude-skills, 28k stars) and Pricing Strategist (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Amex Travel?

borski (a GitHub user) maintains it in borski/travel-hacking-toolkit, which has 688 GitHub stars. The repository holds 46 skills in this directory. The repository was last updated on October 5, 2026.

Source: borski/travel-hacking-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.