nifi-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| NIFI_AUTH | No | Authentication method: oidc, jwt or bearer | oidc |
| NIFI_API_URL | Yes | NiFi /nifi-api URL or UI origin, e.g. https://nifi.example.com/nifi-api | |
| NIFI_PASSWORD | No | jwt mode: password | |
| NIFI_READONLY | No | true blocks every create, update, delete and schedule | false |
| NIFI_USERNAME | No | jwt mode: user for POST /nifi-api/access/token | |
| NIFI_CA_BUNDLE | No | Extra CA bundle, added to the default trust store | |
| NIFI_CLIENT_ID | No | RevisionDTO.clientId for optimistic locking | nifi-mcp |
| NIFI_OIDC_SCOPE | No | OIDC scope | openid profile |
| NIFI_TLS_VERIFY | No | Prefer NIFI_CA_BUNDLE over turning this off | true |
| NIFI_BEARER_TOKEN | No | bearer mode: a pre-minted token | |
| NIFI_OIDC_PASSWORD | No | OIDC password | |
| NIFI_OIDC_USERNAME | No | OIDC user | |
| NIFI_OIDC_CLIENT_ID | No | OIDC client id | |
| NIFI_OIDC_TOKEN_URL | No | OIDC token endpoint for the password grant | |
| NIFI_TIMEOUT_SECONDS | No | HTTP timeout | 30 |
| NIFI_OIDC_CLIENT_SECRET | No | OIDC client secret | |
| NIFI_DISCONNECTED_NODE_ACK | No | Acknowledge disconnected cluster nodes on mutations | true |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| nifi_aboutA | NiFi version, build, and whether this is 2.x. Call first on a new session. |
| nifi_current_userA | Who the configured credentials authenticate as, plus anonymous/permissions flags. |
| nifi_get_flowC | Compact outline of a process group: child groups, processors, connections, ports. |
| nifi_searchB | Search processors, groups, and other components by name or id. |
| nifi_list_processor_typesA | List installed processor types. Filter by class-name substring, then call nifi_get_processor_definition. |
| nifi_get_processor_definitionC | Property descriptors, relationships, and supported scheduling for one processor type. |
| nifi_get_processorC | One processor: state, validation errors, properties (secrets redacted). |
| nifi_list_controller_service_typesB | List installed controller-service types. Filter by class-name substring. |
| nifi_list_controller_servicesB | Controller services visible to a process group (includes inherited). |
| nifi_get_healthC | Running/stopped/invalid counts, queued connections, and processors with validation errors. |
| nifi_get_bulletinsA | Recent NiFi bulletins (errors/warnings). Use after a flow misbehaves. after_id is a bulletin id cursor, not a time: pass the largest id from the last call for newer ones. |
| nifi_list_queueB | Sample FlowFiles sitting on a connection. Connection must not be empty-delete-blocked. |
| nifi_create_process_groupA | Create an empty process group. Build every new flow inside one of these, not on root. Omit x/y to take the next free 424x288 cell below the other groups. An x/y that would overlap another card is shifted down clear of it, and the result says so in warnings. |
| nifi_create_processorA | Add a processor to a process group. Prefer nifi_apply_flow_spec for a whole graph. Omit x/y to take the first free 512x240 cell that clears every card already in the group. An x/y that would overlap another card is shifted down clear of it, and the result says so. |
| nifi_update_processorA | Change processor properties, name, schedule or position. Sends only the fields you set. Property, name and schedule changes need the processor STOPPED; a position-only move does not. A move that would overlap another card is shifted down clear of it, and the result says so. |
| nifi_set_run_statusB | Set one processor to RUNNING, STOPPED, DISABLED, or RUN_ONCE. |
| nifi_create_connectionA | Connect a source to a destination. Processor sources need relationships; port sources take none. Wiring child groups: connect an OUTPUT_PORT (source_group_id = its group) to an INPUT_PORT (destination_group_id = its group) with parent_id = the group that contains both children. |
| nifi_update_connectionA | Change a connection's name, queue backpressure or FlowFile expiration. Sends only the fields you set. Works on a running flow: NiFi only checks component state when a connection's destination changes. |
| nifi_create_controller_serviceC | Create a controller service in a process group and optionally enable it. |
| nifi_get_controller_serviceA | One controller service: state, validation errors and properties (secrets redacted). |
| nifi_update_controller_serviceA | Change a controller service's properties or name in place. Sends only the fields you set. NiFi only updates a DISABLED service: disable it with nifi_set_controller_service_state (stop referencing processors first), update, then enable it again. Processor references stay valid. |
| nifi_set_controller_service_stateA | Enable or disable a controller service. Referencing processors must be stopped to disable. |
| nifi_schedule_process_groupB | Bulk RUNNING or STOPPED for every authorized processor in a process group. |
| nifi_delete_componentA | Delete a stopped processor, empty connection, disabled service, stopped input or output port with no connections, empty process group, or parameter context. A parameter context can only be deleted once no process group is bound to it. The result confirms the id, kind and the revision NiFi deleted; it does not repeat the deleted entity. |
| nifi_export_flowB | Download a process group as a versioned flow snapshot (same JSON the UI exports). A property, run schedule or network interface NiFi reports invalid in the live group is masked in the component it is invalid on, as on every other read. |
| nifi_import_flowC | Import a versioned flow snapshot as a new child process group. Omit x/y to take the next free process group cell; an x/y on another card is shifted clear of it. |
| nifi_replace_flowA | Overwrite an existing process group with a flow snapshot. Destructive. Prefer a sandbox PG. |
| nifi_apply_flow_specA | Create a complete flow from a declarative spec: process group, services, processors, ports, connections. Property values starting with @ (processor or controller_service properties) are resolved to a controller service created earlier in the same spec. Services are enabled in spec order. JSON booleans and numbers become NiFi text (true -> "true", 10 -> "10"); null unsets a property. auto_terminated and relationships take a list or a single name. Connections refer to components by name. Prefer this over many create_* calls. Every result, ok or error, has outcome (applied, not_applied or unknown: the failing request's) and lists created[] (kind, id, ref, outcome; services carry their state). ref is the item's place in the spec (process_group, objects[2], connections[0]). An ok result adds each item's name and name_map; an error names items by ref only, and never repeats a value from the spec. An error, or a build whose flow view could not be read, adds a hint saying how to roll back or inspect exactly what this call created. cause "spec" means the spec was refused before NiFi was asked (a missing name or type, an unknown connection end or @service, or an unknown key at the top level or in process_group): nothing was created. Top-level keys: process_group, objects, connections, parent_process_group_id, layout. process_group keys: name, comments, parameter_context_id, inherit_parameter_context, x, y, position. A request with no definite answer (a timeout, a 5xx, a lost connection) is in created[] with outcome "unknown": NiFi may have applied it, and the hint says what the server's read-back found. Check again before retrying. Only created[] items with an id are ever named for deletion. |
| nifi_layout_process_groupC | Lay processors out top-down, forks sideways, and stack child process groups top-down. Processors: 240px rows (tallest card + label + 32px). At a fork the main branch continues down and the others sit on the fork's row, 672px out; a fork of leaves spreads one row down, 512px apart. Joins return to the fork's axis; every card is centred on its axis by its own width. A self-loop sits outside its card's side with its label on the outer stretch. The second of two connections between one pair, a retry line back up, and any line or label that would cross a card or another label are routed: out of the source's side (else its top or bottom), along a free lane between card columns, into the target's side (else its top or bottom), never along another line. Child process groups: 288px rows, 424px columns, one per row in flow order, upstream above downstream. |
| nifi_empty_queueA | Drop every FlowFile on a connection. Data loss. Required before deleting a non-empty connection. |
| nifi_list_parameter_contextsA | List parameter contexts. Sensitive parameter values are redacted. |
| nifi_get_parameter_contextA | One parameter context: parameters (sensitive values redacted) and bound process groups. |
| nifi_create_parameter_contextB | Create a parameter context with parameters. Bind it to a group with nifi_bind_parameter_context. |
| nifi_update_parameter_contextA | Add, change, or remove parameters. NiFi restarts referencing components itself. A name cannot be in both parameters and remove. To change whether an existing parameter is sensitive, remove it in one call and add it back with the new flag and value in the next. |
| nifi_bind_parameter_contextA | Bind a parameter context to a process group so #{name} references resolve. null unbinds. NiFi does not inherit contexts, so by default this is the UI's "Apply recursively": one request with processGroupUpdateStrategy=ALL_DESCENDANTS binds the group and every descendant, replacing any context a descendant had. NiFi checks every group before changing any, so an error means no group was rebound. apply_recursively=false binds only this group. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| nifi_flow_builder | How to go from a natural-language pipeline request to a running NiFi 2 flow. |
| nifi_debug_flow | Debug a broken or stalled process group. |
| nifi_best_practices | NiFi 2 flow-building practices for this MCP. |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 35 tools
Most tools have distinct resource/action pairs, and descriptions clarify overlaps such as apply_flow_spec versus granular create_* calls. However, create/import/replace/apply_flow_spec and schedule_process_group versus set_run_status could still create confusion in edge cases.
All tools share the nifi_ prefix and snake_case, and the vast majority follow a verb_noun pattern. Minor deviations like nifi_about and nifi_current_user keep it from being perfectly uniform, but the convention is highly predictable.
35 tools is heavy for this surface, with many granular list/get/create/update tools that could be consolidated through apply_flow_spec or grouped by resource. While NiFi is genuinely complex, the count exceeds a comfortable selection range for an agent.
The surface covers most core flow lifecycle operations: process groups, processors, connections, controller services, parameter contexts, health, queues, and import/export/apply. Notable gaps remain around dedicated create/update port tools (though apply_flow_spec can create ports) and user/group policy management.