Token导航 LogoToken导航TokenDH.com
开发规范external-servicegithub未标认证来源可访问许可证需确认审计提醒

visa-best-practices签证最佳实践

Agent Skill

visa-best-practices 用于处理 GitHub 仓库、Issue、Pull Request 和代码协作信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要围绕仓库状态、代码变更或协作事项进行整理时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

380

周安装

16

GitHub Stars

25

下载量

133
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:visa-best-practices(签证最佳实践)
来源仓库:https://github.com/visa/ai
仓库路径:skills/visa-best-practices
安装命令:
npx skills add https://github.com/visa/ai --skill visa-best-practices
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/visa/ai --skill visa-best-practices

简介

用于处理 GitHub 仓库、Issue、Pull Request 和代码协作信息。

  • 适合围绕仓库状态、代码变更或协作事项进行整理。
  • 可结合来源仓库和原始 README 核验具体用法。
  • 安装前建议确认权限范围和维护状态。visa-best-practices 属于开发规范类 Skill,可作为该场景下的辅助能力补充。
  • 注意是否会触发命令执行或文件读写。

SKILL.md

Visa Developer Platform Integration Guide

Code Examples & Starter Kit

Fetch https://sandbox.mcp.visa.com/mcp/doc/llms.txt for all code examples, implementation references, and direct links to source code. This covers MCP client integration, direct API client, VDP connectivity, authentication implementations, VIC tools/workflows, and payload builders.

Official Documentation

Authentication

VDP supports two authentication methods. See the official guides and llms.txt for implementation code.

  • X-Pay Token: HMAC-SHA256 based. Preferred for most integrations. See X-Pay Token Guide.
  • Two-Way SSL (Mutual TLS): Certificate-based mutual authentication. See Two-Way SSL Guide.

Key gotcha — Resource path differs for VIC APIs:

Product TypeResource Path for X-Pay Token
Standard APIsFull path after domain (e.g., /vdp/helloworld)
VIC APIsPath excluding context prefix (e.g., /vic/v1/... becomes /v1/...)

Message Level Encryption (MLE)

MLE provides end-to-end payload encryption using JWE. See the Encryption Guide and llms.txt for implementation code.

  • Check each API's enforcement level (Mandatory / Optional / Not Applicable) in the API docs or VDP Dashboard.
  • MLE requires two certificate pairs: Visa's server key (for encrypting requests) and your client key (for encrypting responses).

Key gotchas:

  • Include keyId as an HTTP header in all MLE-enabled API calls
  • Up to 3 active Key-IDs per project (for rotation)
  • Key-ID changes when certificates are renewed — update your config accordingly
  • CSR must include the Key-ID as the UID field

Environments

EnvironmentB2B URLB2C URL
Sandboxhttps://sandbox.api.visa.com/https://sandbox.webapi.visa.com/
Certificationhttps://cert.api.visa.com/-
Productionhttps://api.visa.com/-

Credential Management Best Practices

  • Monitor certificate expiration dates in VDP Dashboard — renew before expiry
  • New certificates require new Key-IDs for MLE
  • Maintain 2-3 active credential sets for seamless rotation
  • Always test credential rotation in Sandbox/Certification before Production
  • Revoke old credentials only after successful migration

Project-Specific Guides

Visa Intelligent Commerce (VIC)

For VIC integration (card enrollment, purchase instructions, payment credentials, agent commerce workflows), see:

references/visa-intelligent-commerce.md

Machine Payments Protocol (MPP)

For MPP card charge integration (HTTP 402 payment challenges, encrypted network token credentials, Client Enabler interface, receipts), see:

references/machine-payments-protocol.md

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

36.18%
按下载量换算48

Claude

32.62%
按下载量换算43

Cursor

19.59%
按下载量换算26

Gemini CLI

8.93%
按下载量换算12

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

可疑

权限和风险

external-service

该 Skill 可能调用第三方服务、云服务或外部模型 API,使用前需要确认账号、额度、数据发送范围和服务条款。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills