kestra-io/mcp-server-python
Workflow & Automation · tested 2026-09-27 · by the Hlido desk, not the vendor
In short: A credible, well-documented MCP server that exposes Kestra's workflow orchestration to agent clients like Claude, Cursor and VS Code — genuinely agent-first, though Hlido's capture landed on the parent blog rather than the repo, leaving repo-health signals unverified.
5 PASS · 5 FAIL of 10 public-surface claims
Quick answer
kestra-io/mcp-server-python scores 74/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-09-27). STEADY (74) because this is a coherent, well-documented MCP server from a credible open-source orchestration vendor, with a clear agent-consumption path (container image + MCP client configs for Claude/Cursor/VS Code + O
The Kestra Python MCP server is exactly the kind of surface an agent ecosystem wants: it wraps Kestra — a mature, open-source declarative orchestration platform — behind the Model Context Protocol so an assistant like Claude Desktop, Cursor, Windsurf or VS Code can drive flows and executions directly. The documentation is a real strength: it ships as a pinned container image (ghcr.io/kestra-io/mcp-server-python), gives copy-paste MCP client configs, and cleanly separates an open-source auth path (username/password) from an Enterprise one (API token), with environment-variable controls for disabling tools and setting log level. That is a coherent, agent-consumable design from a vendor with a serious platform behind it. The honest gaps are on Hlido's side as much as the product's: our automated pass captured the Kestra AI Agents blog rather than the repository itself, so we could not independently verify the license file, release cadence, test/CI presence, maintenance recency or community traction for this specific repo — and we did not run it against a live Kestra instance. It is also not a standalone tool: it is only useful to teams already operating Kestra, and the OSS example embeds plaintext admin credentials, which deployers should replace with the token path. As a documented, vendor-backed MCP bridge it reads as a solid building block; a hands-on run against a live instance would be needed to confirm the tools behave as described and to lift it above medium confidence.
Why STEADY
STEADY (74) because this is a coherent, well-documented MCP server from a credible open-source orchestration vendor, with a clear agent-consumption path (container image + MCP client configs for Claude/Cursor/VS Code + OSS and Enterprise auth modes). It is not rated higher for two reasons: Hlido's capture resolved to the Kestra AI Agents blog rather than the MCP server's repository, so license, releases, CI, maintenance recency and star count for this specific repo were not independently verified; and this is a public/repo-surface review with no hands-on behavioral run against a live Kestra instance (medium confidence). A confirmed repo-health pass plus a behavioral run would likely move it into the upper STEADY range.
Public-surface checklist
- PASS Repo reachable (required) — kestra-io/mcp-server-python referenced as the canonical product surface; README content captured via scout-enrich preanalysis.
- PASS Readme present (required) — README documents Docker distribution and MCP client configuration (OSS and EE); captured markdown preview well over 500 chars.
- PASS Install documented (required) — Docker run command plus MCP settings JSON for Cursor/Claude/VS Code documented for both OSS (username/password) and EE (API token) users.
- PASS Agent consumable — Model Context Protocol server; ghcr.io/kestra-io/mcp-server-python image; mcpServers config blocks for Cursor, Claude and VS Code.
- PASS Active 12mo (required) — Kestra AI Agents (which lists MCP clients as a current tool) last updated Sept 2025; © 2026 Kestra Technologies. NOTE: repo-specific push date was not captured; platform-level activity is the basis here.
- FAIL License present (required) — License file not visible in captured evidence — the capture landed on the Kestra AI Agents blog, not the repo page. Not independently verified for this repo.
- FAIL Releases present — Not captured; the container image is pinned to :latest in the README, but tagged repo releases were not verified.
- FAIL Community traction — Star count for this repo not captured (preanalysis gh_stars is null). The 27,793 stars on the blog belong to the main kestra-io/kestra platform repo, not the MCP server, and are not credited here.
- FAIL Ci or tests — Not captured; repo page was not crawled in this run.
- FAIL Recent commit 90d — Repo push date not captured; not independently verified for this repository.
What we saw
1 screenshot captured by the Hlido engine during the reviewed run (run-4fb8482b0478e9bc-kestra-io). Our own captures — not vendor marketing material.
What it does well
- Genuinely agent-first: a Model Context Protocol server that exposes Kestra orchestration directly to MCP clients (Claude, Cursor, Windsurf, VS Code)
- Container-first distribution with a pinned image (ghcr.io/kestra-io/mcp-server-python) that avoids local Python/dependency management
- Copy-paste MCP client configuration is documented for both open-source and Enterprise Edition users
- Clean auth separation — OSS username/password vs Enterprise API-token config — with env-var controls for disabling tools and log level
- Backed by Kestra, an established open-source declarative-orchestration platform with Enterprise and Cloud editions
What it fails at
- Only useful to teams already running Kestra — it is a bridge to a backend, not a standalone tool
- The documented OSS config example embeds plaintext admin username/password; deployers must harden this with the token path
- Repo-health signals (license file, tagged releases, CI, push recency, star count) were not captured for this specific repository
- No live/browsable demo of the MCP tools; behaviour is asserted by the README, not independently exercised here
- Requires Docker plus a reachable Kestra instance (KESTRA_BASE_URL), so setup is heavier than a hosted agent tool
Best for
- Teams already operating Kestra who want to drive flows and executions from an MCP-capable assistant
- Builders wiring Claude Desktop, Cursor, Windsurf or VS Code to a workflow-orchestration backend
- Platform/data engineers who prefer a pinned container image over managing a Python environment
- Enterprise Kestra users who need token-scoped, tool-restricted MCP access
Not recommended for
- Anyone not already running or planning to run a Kestra instance
- Users wanting a zero-infrastructure, hosted agent tool with no Docker or backend to operate
- Buyers who need a live pre-adoption demo of the exact tool behaviour before integrating
- Deployments that cannot securely manage MCP-client credentials and API tokens
Related agents
Agent relevance
API MCP
An MCP client (Claude Desktop, Cursor, Windsurf, VS Code) runs the container image ghcr.io/kestra-io/mcp-server-python via a stdio Docker command, pointed at a Kestra instance (KESTRA_BASE_URL / tenant) and authenticated with either OSS username-password or an Enterprise API token. The agent then invokes Kestra orchestration through the exposed MCP tools; specific tools can be disabled via KESTRA_MCP_DISABLED_TOOLS. Requires a reachable Kestra backend and Docker.
Agent-friendly score: 8/10
Score over time
The longitudinal record — every point is the score as published on that date. Raw series.
Evidence
- You can run the MCP Server in a Docker container (image ghcr.io/kestra-io/mcp-server-python:latest) — source (2026-09-27) verified
- MCP client configuration is documented for Cursor, Claude and VS Code ("Paste the following configuration into your MCP settings") — source (2026-09-27) verified
- Separate configurations for open-source users (username/password) and Enterprise Edition users (KESTRA_API_TOKEN), with env-var controls for disabled tools and log level — source (2026-09-27) verified
- Backed by Kestra, an established open-source declarative orchestration platform with Enterprise and Cloud editions — source (2026-09-27) verified
- Repository health signals for this specific MCP server repo (license file, tagged releases, CI, push recency, star/fork counts) — source (2026-09-27)
