Airflow MCP server — DAG list, runs, task instances, log tails, trigger and clear over the Airflow REST API
Strong tool naming and comprehensive schema coverage. Most tools have clear, actionable descriptions that follow the verb_noun convention (list_, get_, trigger_, clear_). Schemas are well-typed with descriptions and constraints (min/max, defaults, enums where appropriate). However, output schemas are not explicitly documented in the code, forcing inference from implementation. Error handling is present but generic. Some descriptions exceed optimal length (200+ chars). Security is well-gated (AIRFLOW_ALLOW_WRITE for destructive ops), but no explicit permission annotations in tool definitions. The server correctly exposes per-tool descriptions inline and uses Zod for runtime validation.
Clear specific task instances in an Airflow DAG run (re-run them); supports include_upstream / include_downstream. Write-gated by AIRFLOW_ALLOW_WRITE.
Get one Airflow 3.x asset by numeric id, including producing tasks and consuming DAGs and the asset's extra metadata blob.
List task instances for a specific Airflow DAG run with state, try_number, duration
Fetch the tail (last N kB) of an Airflow task instance log for a specific try_number
List Airflow 3.x asset materialization events (newest first by default). Each event names the source DAG/task/run plus any downstream DAG runs the materialization triggered. Filterable by assetId, sourceDagId, sourceRunId, sourceTaskId, and a timestamp window — pair with dbt-mcp lineage to trace cross-tool data flow.
Output schemas not explicitly documented in tool definitions. Code shows .shape extraction but no explicit return type documentation for agents to plan downstream calls.
Tool annotations (readOnlyHint, destructiveHint) are inferred dynamically via inferToolAnnotations() but never explicitly shown in registration. This prevents clients from knowing at registration time which tools are destructive (e.g. airflow-trigger-dag, airflow-clear-task) vs read-only.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 73 | 2026-07-28+ | v2 |
List Airflow 3.x assets (replaces the legacy 'dataset' concept) with optional URI substring filter and DAG-id filter. Returns producing tasks + consuming DAGs per asset — the cross-DAG lineage answer to 'who writes this, who reads this?'
List Airflow connections (connection_id / conn_type / host / schema / login / port) — diagnose which external targets DAGs talk to. Passwords are never returned by the API.
List non-fatal DAG warnings (e.g. references to a non-existent pool, duplicate task ids) optionally filtered by dagId or warningType. Newest first.
List Airflow DAGs (active by default) with optional tag filter and dag_id substring search
List the Airflow event-log audit trail (newest first): DAG run / task state changes, config edits, etc. Filterable by dagId, taskId, runId, event.
List DAG files that failed to parse (import errors) with filename, timestamp, and stack trace — the first thing to check when a DAG is 'missing' from list-dags. Newest first.
List Airflow pools with slot utilization (slots / occupied / running / queued / open) — diagnose why tasks are stuck queued due to pool capacity.
List recent runs of one Airflow DAG, optionally filtered by state, ordered newest first
List Airflow Variable keys + descriptions (values omitted to avoid leaking secrets) — see what configuration knobs exist.
Trigger a new Airflow DAG run with optional conf payload and note. Write-gated by AIRFLOW_ALLOW_WRITE.
Aggregated DAG health: success-rate over the last N runs + count breakdown (succeeded/failed/queued) + average duration + last-failed-run id + (optional) failing task instances. Replaces the airflow-list-runs + airflow-get-task-instances combo for 'is this DAG healthy right now?'.
Discover available Airflow MCP tools by natural language query.
Error handling delegates to wrapToolHandler but no explicit error recovery guidance in tool descriptions. LLMs cannot know whether a 'DAG not found' error is user-fixable or fatal.
search-tools description is generic ('Discover available...') and does not explain it uses natural language matching or that it should be called first to find the right tool. This reduces its discovery utility.
airflow-list-asset-events description mentions 'pair with dbt-mcp lineage', a cross-tool dependency that may not always be available. No graceful degradation documented if dbt-mcp is absent.