-
-
Pointifly: an AI agent that plans your whole year of points and pays with Visa. Demo: 3,000 fewer points, +$970 in flights, $970 less cash.
-
Every Visa call, visible as it happens: the FX API, the optimizer picks the best Visa card, and Visa points earned from transaction..
-
Connect once with Plaid: 3 Visa cards found. Pointifly picks the best one for each cash trip.
-
The agent greets you as soon as your cards are connected. You're in control from the start: Autonomous payments is one switch.
-
Four flights and four balances. Speech recognition misheard "Sapphire Preferred", and the agent still got the Chase balance right.
-
The plan: 93,000 points for $3,919 of flights, Pointifly saves $970. New York over the agent's $1000 limit so doesn't. autopay
-
Same trips, same points. Trip by trip spends 68,000 miles on New York at 3.6¢; Pointifly saves them for Shanghai business at 5.2¢.
-
Where every point goes: Amex to ANA for Shanghai and San Francisco, Chase to Aeroplan for Mumbai, and 86,862 points kept for later.
-
Guardrails at work: the agent can't pay over $1,000 per-payment limit. Paid with one tap, on your best Visa, through Cybersource.
✈️ The receipt
Our real travel year: two international students, four flights, the same points in both columns.
| Booking trip by trip | Pointifly | ||
|---|---|---|---|
| Points spent | 96,000 | 93,000 | 3,000 fewer |
| Flights covered by points | $2,949 | $3,919 | +$970 |
| Cash out of pocket | $3,430 | $2,460 | $970 less |
Same wallet. Same trips. Planned as a year.
Booking one flight at a time spends 68,000 miles on the first long-haul flight (Delhi → New York, 3.6¢ a mile), and then there aren't enough left for Shanghai in business. Pointifly pays for New York on Visa instead and saves those miles for Shanghai, where each one is worth 5.2¢.
Live Google Flights fares, official transfer ratios and award charts. Cash includes $29 of award fees.
🧪 Try it in 30 seconds
- Tap Connect with Plaid, then Continue.
- The agent greets you. Allow the microphone and say (or type) this:
I have 90,000 Amex points, 50,000 Chase Sapphire Preferred points, 35,000 United miles and nothing in Capital One. Delhi to New York in business on December 3, 2026. New York to San Francisco in economy on November 12, 2026. New York to Shanghai in business on January 12, 2027. New Delhi to Mumbai in business on February 2, 2027.
Watch for:
- Gold Visa labels as the agent uses Visa's FX Rates API and picks your best Visa card
- The receipt above, rebuilt live, with the plan card on screen
- A guardrail at work: New York costs $2,431, over the agent's $1,000 per-payment limit, so it won't pay on its own. Raise the limit under See full breakdown, say "pay it", and it pays through Cybersource.
No mic, or a loud room? Just type it into the box under the circle, or use **Manual mode.
💡 Inspiration
We're two international students from India. Flying home isn't a spontaneous trip for us: we plan every flight at least six months ahead, and we split our points across Amex, Chase and United to get there.
And we still did it wrong. We booked one flight at a time, so whichever flight came first got the points, even when a flight three months later was worth twice as much per point. Award tools answer "what's the best deal on this flight?" Nobody was answering "what's the best way to spend a whole year of points?"
At the Visa workshop, one line stuck with us: make AI-driven commerce more useful, trusted and inclusive. So we built the travel agent we wanted: one you can just talk to, that plans the whole year, and that can be trusted to pay with your Visa within limits you set.
✈️ What it does
Pointifly turns buying a year of flights from searching and browsing into a conversation with an AI agent that plans, decides and pays.
- Talk. Connect your cards, then tell the agent your balances and trips in one sentence, by voice or by typing. It asks only for what's missing.
- Plan. It finds live fares, explains how your points transfer to airlines, and optimizes the whole year at once. Then it puts the result side by side with booking trip by trip, so you see exactly what you gain.
- Pay. For the trips that are better paid in cash, it picks the Visa card that earns the most, asks you once, and pays through Visa's Cybersource gateway, within spending limits you control.
Every stage of the shopping journey in Visa's challenge, covered by one agent:
| Stage | What Pointifly does |
|---|---|
| Discovery | Finds the cheapest live fare for every trip on Google Flights |
| Decision-making | Decides for each trip: points (which program, which transfers) or cash |
| Personalization | Uses your cards, your balances and your travel dates |
| Loyalty & rewards | Gets the most out of your points across the whole year and earns more on every cash trip |
| Checkout & payments | The agent pays with your best Visa card through Cybersource, after one confirmation |
| Post-purchase | A live audit log shows every payment, paid or blocked, and why |
💳 How Visa powers Pointifly
Visa is in the loop at every point where money is involved. You can see it happen: a gold Visa label appears each time the agent calls a Visa service.
- Cybersource Payments API (REST). The agent's checkout. It pays each cash trip at the plan's amount, with the plan's Visa card, through Cybersource's official SDK (Sandbox). Both the agent and your own Pay with Visa button go through the same server-side payment path.
- Visa Foreign Exchange Rates API. Shows each international trip in the local currency. Connected with two-way SSL (the client certificates Visa requires), fetched at most once per currency pair per day, and clearly labelled as Sandbox sample rates.
- Visa Merchant Offers Resource Center. Brings in real Visa travel benefits, and only for cards that qualify: Visa Infinite perks show up only when you hold a Visa Infinite card.
- Visa card rewards, built into the optimizer. For every cash trip, the optimizer picks the Visa card that earns the most points on that fare, from issuers' official earn rates, and counts those points toward later trips once they post.
🛡️ Why you can trust an agent with your Visa
Visa's challenge asks for secure and trusted payments. Our rule: the agent can ask, but only the server decides.
- You're in control. An Autonomous payments switch (on by default) plus per-payment and total spending limits. Turn it off and the agent can plan and explain, but only you can pay.
- One approval before money moves. The agent asks once. Every step before that (reading your trips, planning) is free and can be undone, so it runs without interruptions.
- The agent can't change the amount or the card. It names a trip; the amount and the Visa card come from the server's own copy of the plan. Requests carrying extra fields like
amountorcardare rejected. - No double charges, no runaway loops. One payment per trip, and a cap on payment attempts per minute.
- Every attempt is recorded. Paid, blocked or skipped, each one shows in an audit log with the reason.
- Card data stays out of the AI. Plaid returns only card names and the last four digits; the agent never sees a card number, and neither does anything we store. Payments are made server-side through Cybersource. Tokenized credentials are next (see What's next).
- Tested against attacks. 141 automated tests, including a suite that sends SQL-injection strings, prompt-injection phrasing and tampered payment requests at every payment endpoint and confirms nothing reaches the payment gateway. There's no SQL database to inject into, and every input is validated before it's used.
🌍 Useful, trusted, inclusive: built for Visa's goal
Visa asked for commerce that's intuitive, personalized and frictionless, with secure and trusted payments. Here's how Pointifly answers each part with something that runs in the demo.
Useful: it solves a real, expensive problem. Points are a year-long budget, but every tool treats them as a coupon for one flight. On our own travel year, planning the year instead saved 3,000 points and $970 in cash (see the receipt at the top). That's money back in a student's pocket, not a vanity metric.
Seamless: one sentence, from "where am I flying?" to paid. No forms, no spreadsheets, no award-chart research. The agent greets you about a second after the page opens, fills in the plan from what you say, optimizes and pays. The only thing it asks you to approve is the payment.
Inclusive: built for travellers who cross borders. We built it as international students, for anyone flying home:
- Any of about 4,500 airports worldwide, including trips that don't start at home (Delhi → Mumbai, New York → Shanghai)
- Local prices in pounds, euros, rupees, yen and yuan, converted with the Visa Foreign Exchange Rates API
- Speak or type, whichever you can: noisy room, no microphone, or English as a second language
- Plain-language answers: ask "why cash for New York?" and the agent explains it in one sentence
Trusted: the agent is flexible, the money isn't. Every payment passes the server's guardrails (your switch, your limits, a fixed amount and card, an audit log), and those guardrails are tested against injection attacks. See Why you can trust an agent with your Visa above.
🎙️ Tying it all together: an ElevenLabs agent that acts, not just talks
The ElevenLabs agent is the single interface to everything above. The key design decision: AI where flexibility helps, math where money is at stake. The agent understands you, explains the plan and runs the steps; the numbers come from a deterministic optimizer, never from the model's guess.
It acts through tools, not just words. Five client tools connect the agent to the real system:
fill_trip_plan: turns your sentence into trips and balances (Gemini, then checked against real airports and dates)describe_programs: the official transfer ratios for your cardsrun_optimizer: calls the whole-year optimizer (the math below)explain_trip: why a trip is points or cash, in one sentencepay_cash_leg: asks the server to pay; the server decides whether it may
It answers from verified sources (RAG). A knowledge base of four documents (official transfer ratios, the Aeroplan and ANA award charts, Visa card earn rates, and how Pointifly decides) grounds every answer. It holds public reference data only, never user data.
Guardrails in the agent, and in the server behind it:
- Told never to ask for card numbers, passwords or security codes, and to take every number about the plan from the tools
- Told to ignore any instruction that tries to change amounts, cards, limits or the autopay setting, and to report blocked payments exactly as they happened
- Kept up to date live: flip Autonomous payments or change a limit and the agent is told immediately, mid-conversation
- And if the model gets it wrong anyway, the server still enforces every rule (see Why you can trust an agent with your Visa)
Built for real people in real rooms:
- Greets you on its own in about a second (the session is prepared while you connect your cards)
- Tuned for noisy places: other people's voices can't cut it off mid-sentence; turn-taking is patient; recognition knows words like Aeroplan, Heathrow and premium economy
- Says its name right: a pronunciation dictionary makes the voice say "Point-ih-fly"
- Never blocks you: no microphone, or no permission? It switches to typing in 5 seconds, and you can type at any time
- Private by design: the API key stays on our server, the browser gets a 15-minute signed link, and your balances and cards never live on ElevenLabs; the agent sees only short summaries
🛠️ How we built it
The flow
You (voice or text)
▼
ElevenLabs agent ◀── knowledge base (RAG): official ratios · award charts · Visa earn rates
▼ client tools
Gemini ──▶ trips & balances, checked against ~4,500 airports and real dates
▼
Google Flights (SerpApi) + Visa FX Rates API ──▶ live fares, local currencies
▼
OR-Tools CP-SAT optimizer ──▶ best whole-year plan (and the trip-by-trip plan to compare)
▼
Server-side guardrails ──▶ your switch · your limits · amount & card fixed · audit log
▼
Cybersource Payments API ──▶ paid with your best Visa card
Stack:FastAPI (Python) · React + TypeScript (Vite) · OR-Tools CP-SAT · ElevenLabs Agents · Gemini · Plaid · deployed on Vultr (Ubuntu, Caddy HTTPS).
The Optimizer: Behind the Scenes
Every trip has a few ways to pay, and every point can move along a few paths:
your points ──transfer (official ratio, 1,000-point blocks)──▶ airline miles ──▶ award seat
│ (worth the cash fare it replaces)
└── or keep them: each point you keep is worth 1¢; an award has to beat that
cash trip ──best Visa card──▶ earns points (posting in 30 days) ──▶ funds later trips
We turned that into an integer program. For every trip \(t\), payment option \(o\) (cash, or an award in program \(p_o\)), holding \(h\) and Visa card \(k\):
$$\max\;\sum_{t,o}\big(V_o - F_o\big)\,y_{t,o}\;-\;\sum_{h,t,o}\rho_h\,x_{h,t,o}\;+\;\sum_{t,k}\rho_{k}\,E_{t,k}\,z_{t,k}$$
subject to
$$\sum_o y_{t,o} = 1 \qquad \text{(one way to pay per trip)}$$
$$\sum_h r_{h,p_o}\,x_{h,t,o} \;\ge\; P_o\,y_{t,o} \qquad \text{(transferred points cover the award)}$$
$$x_{h,t,o} \in b_h\,\mathbb{Z}_{\ge 0} \qquad \text{(transfers move in official blocks)}$$
$$\sum_{t' \le t}\sum_o x_{h,t',o} \;\le\; B_h + \text{earned}_h(t) \qquad \text{(never overdrawn on any date)}$$
- \(y_{t,o}\): trip \(t\) is paid with option \(o\); \(x_{h,t,o}\): points moved out of holding \(h\); \(z_{t,k}\): Visa card \(k\) pays cash trip \(t\)
- \(V_o\): the cash fare an award replaces; \(F_o\): its taxes and fees; \(P_o\): its price in miles; \(r_{h,p}\): the official transfer ratio; \(b_h\): the transfer block size; \(B_h\): your balance
- \(\rho_h\): what a point is worth if you keep it (1¢), so an award only wins if it beats saving the points
- \(E_{t,k}\): points card \(k\) earns on trip \(t\)'s fare, usable 30 days later
How it ties to the goal. The objective is travel value you actually gain: award value, minus fees, minus the value of the points you give up, plus the points your Visa cards earn back. Cash is neutral: you pay the fare and get the fare.
A fair comparison. "Booking trip by trip" is the same model run one trip at a time in date order. The only difference is scope, so the gap in the receipt comes entirely from planning the year together.
Exact, not a guess. Google's OR-Tools CP-SAT solver rules out options that provably can't beat the best plan found, and proves the result is optimal. On our own travel year it found and proved the best plan in 21 milliseconds (with a 10-second safety cap). Ties are broken toward the plan with the fewest transfers.
📚 Where the data comes from
| Data | Source | Status |
|---|---|---|
| Cash fares | Google Flights (via SerpApi) | Live; saved after the first search |
| Transfer ratios | Amex, Chase, Capital One official pages | Official, verified Sep 26, 2026 |
| Award prices | Aeroplan and ANA official award charts | Official; seat availability not checked |
| Card earn rates | Issuers' official card pages | Official |
| Airports | OurAirports | Open data |
| Currency conversion | Visa Foreign Exchange Rates API | Visa Sandbox (sample rates, labelled in the app) |
| Card benefits | Visa Merchant Offers Resource Center | Visa Sandbox |
| Payments | Cybersource Payments API | Sandbox, no money moves |
| Linked cards | Plaid | Sandbox institutions |
| Trip parsing · voice | Gemini · ElevenLabs Agents | Live |
We never invent a price. Where a program doesn't publish an award chart, we don't guess one.
🧗 Challenges we ran into
- Visa's two-way SSL. The FX Rates API won't talk to you without client certificates. Getting the certificate, private key and credentials working (and then working again on our live server) took real debugging.
- A payment gateway that said no. Our Cybersource Sandbox account has no card processor enabled yet, so every payment returned a server error. We proved our code on Cybersource's public test merchant, then built a fallback so the demo completes while the audit log records the gateway's real reply.
- "New York" isn't an airport. The AI turned "New York" into the city code NYC, and three of our own trips silently disappeared. We now map city codes to their main airport and tell the parser to use real airport codes.
- Voice in a loud hall. Other people's voices kept cutting the agent off mid-sentence. We turned off interruptions, made turn-taking patient, and added recognition keywords for program and airport names.
- An agent that sat on "Starting…". An unanswered microphone prompt could stall it forever. Now the agent switches to typing after 5 seconds, and its session is prepared while you connect your cards.
- Staying honest about prices. Most loyalty programs don't publish award charts. Instead of guessing, we price awards only from Aeroplan's and ANA's official charts, and say so.
- Free-tier limits. With 250 flight searches a month, we saved every fare after its first search, reused identical searches, capped searches per day, and ran our tests with the network blocked.
🏆 Accomplishments that we're proud of
- It wins on our own travel year: 3,000 fewer points, $970 more in flights covered by points, $970 less cash. Better on all three at once.
- An AI agent that goes from one sentence to a Visa payment, end to end, live over HTTPS.
- Guardrails you can test: 141 automated tests, including SQL-injection, prompt-injection and tampered-payment attacks that never reach the payment gateway.
- Math you can check: the whole-year plan is proven optimal in 21 milliseconds, against a trip-by-trip baseline built from the same model.
- Four Visa services in one flow: Cybersource, the FX Rates API, Merchant Offers, and Visa card rewards built into the optimizer, each shown on screen as it's used.
- A voice agent that feels finished: it greets you in about a second, says its own name right, handles noisy rooms, and switches to typing when the microphone isn't available.
- Real demand: we pitched Pointifly to people around the hackathon, and 6 of them gave us their name and email to try it.
📖 What we learned
- Plan the year, not the flight. The biggest gains come from which trip gets the points, not from finding a slightly cheaper award.
- Let AI talk and math decide. The agent handles language and flow; a deterministic optimizer handles the money. That split is what makes it trustworthy.
- Trust belongs in the server, not the prompt. A prompt can be talked around; server-side limits, fixed amounts and an audit log can't.
- Honesty builds trust. Labelling Sandbox data and refusing to invent prices made the product more credible, not less.
- Voice UX is in the details: startup time, background noise, a mic prompt nobody answers, and even how the product says its own name.
🚀 What's next for Pointifly
- Visa Intelligent Commerce: pay with tokenized agent credentials instead of a card on file
- Trusted Agent Protocol: have Pointifly's agent cryptographically verified by merchants at checkout
- Payment passkeys: confirm agent payments with Face ID or a fingerprint instead of a spoken "yes"
- Points + cash: use leftover points for part of a fare and pay the rest with Visa
- More of the real world: more award charts, live seat availability, round trips, and real card linking through Plaid in production
- Beyond HackGT: we're applying to Create-X to keep building Pointifly as a startup
Log in or sign up for Devpost to join the conversation.