Airflow APISAFE
⚡ Control Apache Airflow with natural language via MCP. Chat with your workflows using Claude, GPT, or any LLM — no REST API calls needed. Supports Airflow 2.x (43 tools) & 3.0+ (45+ tools).
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Revolutionary Open Source Tool for Managing Apache Airflow with Natural Language
[](https://opensource.org/licenses/MIT) [](https://www.buymeacoffee.com/call518)
[](https://github.com/call518/MCP-Airflow-API/actions/workflows/pypi-publish.yml)
Architecture & Internal (DeepWiki)
[](https://deepwiki.com/call518/MCP-Airflow-API)
📋 Overview
Have you ever wondered how amazing it would be if you could manage your Apache Airflow workflows using natural language instead of complex REST API calls or web interface manipulations? MCP-Airflow-API is the revolutionary open-source project that makes this goal a reality.
🎯 What is MCP-Airflow-API?
MCP-Airflow-API is an MCP server that leverages the Model Context Protocol (MCP) to transform Apache Airflow REST API operations into natural language tools. This project hides the complexity of API structures and enables intuitive management of Airflow clusters through natural language commands.
🆕 Multi-Version API Support (NEW!)
Now supports both Airflow API v1 (2.x) and v2 (3.0+) with dynamic version selection via environment variable:
- API v1: Full compatibility with Airflow 2.x clusters (43 tools) - [Documentation](https://airflow.apache.org/docs/apache-ai
a5ae58e73e04OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-airflow-api --env AIRFLOW_API_PASSWORD=${AIRFLOW_API_PASSWORD} --env REMOTE_AUTH_ENABLE=${REMOTE_AUTH_ENABLE} --env REMOTE_SECRET_KEY=${REMOTE_SECRET_KEY} -- uvx mcp-airflow-api{
"mcpServers": {
"mcp-airflow-api": {
"command": "uvx",
"args": [
"mcp-airflow-api"
],
"env": {
"AIRFLOW_API_PASSWORD": "${AIRFLOW_API_PASSWORD}",
"REMOTE_AUTH_ENABLE": "${REMOTE_AUTH_ENABLE}",
"REMOTE_SECRET_KEY": "${REMOTE_SECRET_KEY}"
}
}
}
}Exposed tools (56)
46 read · 9 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
all_dag_event_summary | read | [Tool Role]: Provides summary of event logs across all DAGs. |
all_dag_import_summary | write | [Tool Role]: Provides summary of import errors across all DAGs. |
create_connection | write | [Tool Role]: Creates a new connection. |
dag_calendar | write | [Tool Role]: Shows DAG schedule and execution calendar for a date range. |
dag_code | read | [Tool Role]: Retrieves the source code for the specified DAG. |
dag_graph | read | [Tool Role]: Retrieves task graph structure for the specified DAG. |
dag_run_duration | write | [Tool Role]: Analyzes DAG run durations and performance metrics. |
dag_task_duration | write | [Tool Role]: Analyzes task durations within a DAG run. |
delete_connection | destructive | [Tool Role]: Deletes a connection. |
failed_dags | read | [Tool Role]: Lists all recently failed DAG runs in the Airflow cluster. |
get_config | read | [Tool Role]: Retrieves Airflow configuration. |
get_config_section | read | [Tool Role]: Gets all options within a specific configuration section. |
get_connection | read | [Tool Role]: Gets details for a specific connection. |
get_dag | read | |
get_dags_detailed_batch | read | |
get_dataset | read | [Tool Role]: Gets details of a specific dataset (v1 API only - v2 uses Assets). |
get_dataset_events | read | [Tool Role]: Gets events for a specific dataset (v1 API only - v2 uses Assets). |
get_event_log | read | [Tool Role]: Retrieves a specific event log entry. |
get_health | read | [Tool Role]: Checks Airflow cluster health status. |
get_import_error | write | [Tool Role]: Retrieves a specific import error. |
get_pool | read | [Tool Role]: Gets details for a specific pool. |
get_prompt_template | read | |
get_provider | read | [Tool Role]: Gets details of a specific provider package. |
get_task_instance_details | read | [Tool Role]: Gets detailed information for a specific task instance. |
get_task_instance_extra_links | read | [Tool Role]: Gets extra links for a task instance. |
get_task_instance_logs | read | [Tool Role]: Retrieves logs for a specific task instance. |
get_user | read | [Tool Role]: Gets details of a specific user (v1 API only). |
get_variable | read | [Tool Role]: Gets the value of a specific variable. |
get_version | read | [Tool Role]: Gets Airflow version information. |
get_xcom_entry | read | [Tool Role]: Gets a specific XCom entry. |
list_asset_events | read | |
list_assets | read | |
list_config_sections | read | [Tool Role]: Lists all configuration sections with summary. |
list_connections | read | [Tool Role]: Lists all connections in Airflow. |
list_dags | read | |
list_dataset_events | read | [Tool Role]: Lists dataset events for data lineage tracking (v1 API only - v2 uses Assets). |
list_datasets | read | [Tool Role]: Lists all datasets in the Airflow system (v1 API only - v2 uses Assets). |
list_event_logs | read | [Tool Role]: Lists event logs from Airflow. |
list_import_errors | write | [Tool Role]: Lists import errors in Airflow. |
list_permissions | read | [Tool Role]: Lists all permissions available in the Airflow system (v1 API only). |
list_plugins | read | [Tool Role]: Lists all installed plugins in the Airflow system. |
list_pools | read | [Tool Role]: Lists all pools in Airflow. |
list_providers | read | [Tool Role]: Lists all provider packages installed in the Airflow system. |
list_roles | read | [Tool Role]: Lists all roles in the Airflow system (v1 API only). |
list_task_instances_all | read | [Tool Role]: Lists task instances with comprehensive filtering options. |
list_task_instances_batch | read | [Tool Role]: Lists task instances in batch with date and state filtering. |
list_tasks | read | [Tool Role]: Lists all tasks within the specified DAG. |
list_users | read | [Tool Role]: Lists all users in the Airflow system (v1 API only). |
list_variables | read | [Tool Role]: Lists all variables in Airflow. |
list_xcom_entries | read | [Tool Role]: Lists XCom entries for a specific task instance. |
pause_dag | read | [Tool Role]: Pauses the specified Airflow DAG (prevents scheduling new runs). |
running_dags | read | [Tool Role]: Lists all currently running DAG runs in the Airflow cluster. |
search_config_options | read | [Tool Role]: Searches for configuration options matching a term. |
trigger_dag | write | [Tool Role]: Triggers a new DAG run for a specified Airflow DAG. |
unpause_dag | read | [Tool Role]: Unpauses the specified Airflow DAG (allows scheduling new runs). |
update_connection | write | [Tool Role]: Updates an existing connection. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- UNDECLARED (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
delete_connection
.env.template
.pre-commit-config.yaml
Gates applied: no_behavioural_pass.
a5ae58e73e04full audit observations/trust-audit/mcp-server/call518__airflow-api.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | a5ae58e73e04 | SAFE | B | 89 | first audit |
Questions
What is the Airflow API MCP server?
⚡ Control Apache Airflow with natural language via MCP. Chat with your workflows using Claude, GPT, or any LLM — no REST API calls needed. Supports Airflow 2.x (43 tools) & 3.0+ (45+ tools).
What tools does Airflow API expose?
56 in total: 46 read-only, 9 that write, and 1 that can delete or overwrite (delete_connection). Every one is listed on this page with its risk.
Is Airflow API safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Airflow API need?
It reads AIRFLOW_API_PASSWORD, REMOTE_AUTH_ENABLE and REMOTE_SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Airflow API run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mcp-airflow-api.
How current is this page?
The grade is for one exact copy of the source (a5ae58e73e04), read on 2026-10-08. The repository is watched and re-audited when it changes.