The visa desk, inside the tool your agents already have.
Your support desk, your agent portal, your CRM. One mount puts the whole flow in the record your agent already has open: travelers, documents, cost, margin, payment. They sign in to your portal, not to ours.
// token minted by your server, never in the page source const sv = SimpleVisa.desk(token); sv.mount('#visa', { view: 'order', display: 'panel', brand: 'farebound', context: { ticket: '48219', booking: 'GGU-88214' }, onOrderPlaced: (order) => crm.logActivity(order.reference, order.total) });
Here it is, in a portal like yours.
A Zendesk-style support desk, panel mode, the order view. Everything inside the dashed outline is rendered by us; the chrome around it is a mock of the tool your agents live in. The record prefills the whole party. The agent types nothing twice.
sv.mount('#visa', { view: 'order', display: 'panel', brand: 'farebound', context: { ticket: '48219', booking: 'GGU-88214' }, token // role: agent · scopes: desk.read desk.write desk.pay.* });
A publishable key cannot open this. Wholesale is on the screen.
Traveler elements mount with a key that is safe in page source, because a traveler only ever sees their own price. The desk shows what you pay us, your margin, your wallet and other people's orders. So it mounts with a session your server asks for, on behalf of an agent it has already authenticated.
Your portal authenticates the agent
However you do it today: SSO, LDAP, your own session. We never see a password and never issue one. No agent has a SimpleVisa account to forget.
Your server asks us for a session
One call with your secret key, carrying who the agent is, which team, which scopes and what they are allowed to spend. Valid 30 minutes, refreshed silently.
The mount inherits all of it
The embed renders exactly what those scopes allow. Every order it files is stamped with that agent, that team and your record reference, in your console and in the audit log.
const { token } = await simplevisa.deskSessions.create({ agent: { id: 'u_8823', name: 'Ellie Marsh', email: 'ellie.marsh@farebound.co.uk' }, team: 'support-london', role: 'agent', scopes: ['desk.read', 'desk.write', 'desk.pay.wallet'], limits: { perOrder: 25000, perDay: 150000 }, brand: 'farebound', ttl: 1800 });
Agent desktops on Citrix, GDS windows and locked-down CRMs often cannot load a library. The same session mints a URL, desk.simplevisa.com/s/<token>, that you open in an iframe, a pop-out or a browser tab. Same embed, same scopes, no JavaScript of ours in your page.
Traveler-facing and agent-facing are not the same product.
The embed is free. The control room is the add-on.
We make money when your agents file. So mounting the desk costs nothing and your wholesale rate is unchanged. What is chargeable is the layer a large operation needs around it: directory identity, spend limits, approvals and an exportable audit trail.
See Desk rates on the pricing pageWhat we deliberately did not charge for
No per-seat fee: agent turnover is high and a seat count makes portals ration access to the tool that earns you money. No mount fee, no volume tier on the embed, and no premium for the signed-URL route. The margin stays in the application fee.
Ten things a desk embed has to survive.
A traveler embed only has to be pretty and fast. An agent embed sits in the middle of a phone call, a shared screen, a payroll and an audit. This is the list we design against.
The agent is on a call
The whole flow is keyboard-reachable and the common path is under 40 seconds: the record prefills the trip, tab moves through documents, Enter files. Nothing waits on a page load the caller can hear.
The screen is being shared
Cost and margin are on screen by default because the agent needs them. One keystroke, or a screen-share flag from your portal, replaces every figure with dots until they press it again.
The session expires mid-call
Tokens live 30 minutes and refresh silently from your server. A draft survives the refresh, the tab crash and the transfer to a colleague. An agent never meets a login wall with a customer on the line.
The desktop cannot take a script tag
Citrix, GDS windows, locked-down CRMs: the same session mints a signed URL you open in an iframe or a pop-out. No library, no npm, no change-control ticket.
Security owns the frame
You allowlist us in your CSP, we allowlist your origins in the console. Both directions are a settings field. The embed asks for no cookies and no storage in your origin.
Agents leave on a Friday
Access follows your directory. Disable the account and the next session mint fails. There is no SimpleVisa password to go and revoke, and no shared login being passed around a team.
Someone has to answer for the money
Every order carries the agent, the team and your record reference. Per-agent and per-day spend limits, approvals above a threshold, and an audit log you can export or stream: who priced what, when, from which portal.
The traveler should sometimes pay
Payment link handover keeps your price and your margin but moves the card away from the agent. Nothing sensitive is read out, nothing lands in the call recording, and the order is only filed once the money is in.
Things get cancelled
An agent can cancel and refund inside the embed until the application reaches the government; after that it becomes a support case with a clear reason on screen. Refunds return to the original method, wallet included.
Passport data must not land in your CRM
Scans, passport numbers and cards are entered in our frame and posted to us. Your portal receives the reference, the status, the amount and the documents it is allowed to show. Your DPA gets shorter.
Mount options
Events and webhooks
Desk orders filed from an embed land in the same Desk screen as the ones your agents file in our console: same list, same wallet, same commission report, with the host portal and record reference on each row. Mounts and their scopes are managed under Desk · agents and settings.
See the partner console →Mint a test session today.
Mint a test session, mount it in a staging portal, file against test data. Switch the key when your security review is done.