Prefect MCP

Live

OAUTH 2.1

WORKFLOW ORCHESTRATION

Automation

Prefect MCP gives your agent read access to workflow orchestration: flows, deployments, flow and task runs, run logs, work pools, automations, and events.

  • Per-user credentials: each call uses the actual user's token, never a shared bot.
  • Encrypted per-tenant vault: AES-256, resolved at request time, never in LLM context.
  • Scoped before every call: pre-call scope check, 90-day SIEM-exportable audit chain.
Prefect MCP
agent · Acme Q3
Run
Why did last night's nightly-etl flow run fail?
S
prefectmcp_get_flow_run_logs
88ms
DevOps agent
The nightly-etl run failed in the load_warehouse task after 3 retries. The last log line shows a connection timeout at 02:14 UTC.
Sources: 1 flow run, 214 log lines
prefectmcp
1 flow run
18:29
Message Claude...

Tools your workflow orchestration agent reaches for on Prefect, scoped per user.

CALL ANY TOOL
15 read-only tools for workflow orchestration: inspect flows, deployments, flow and task runs, logs, work pools, automations, and events, plus Prefect docs search.
prefectmcp_docs_get_release_notes
Docs get release notes
Get authoritative, structured release notes for a Prefect OSS release. Accepts "latest" or an exact version and returns the release title, date, Markdown notes, and source URL.
Parameters
Name
Type
Required
Description
version
string
Optional
'latest' for the latest stable Prefect OSS release, or an exact version such as '3.7.8'. Default: `latest`.
prefectmcp_docs_search_prefect
Docs search prefect
prefectmcp_get_automations
Get automations
prefectmcp_get_dashboard
Get dashboard
prefectmcp_get_deployments
Get deployments
prefectmcp_get_flow_run_logs
Get flow run logs
prefectmcp_get_flow_runs
Get flow runs
prefectmcp_get_flows
Get flows
prefectmcp_get_identity
Get identity
prefectmcp_get_object_schema
Get object schema
prefectmcp_get_task_runs
Get task runs
prefectmcp_get_work_pools
Get work pools
prefectmcp_list_authorized_workspaces
List authorized workspaces
prefectmcp_orientation
Orientation
prefectmcp_read_events
Read events
Build your Agent
Same auth pattern across LangChain, OpenAI, Anthropic, and Google ADK.
Python · LlamaIndex
import { ScalekitClient } from "@scalekit-sdk/node";
import { createReactAgent } from "@langchain/langgraph/prebuilt";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);

// Prefect MCP tools scoped to this user
const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["prefectmcp"], toolNames: [
    "prefectmcp_get_flow_runs",
    "prefectmcp_get_flow_run_logs",
    "prefectmcp_get_deployments"] },
  pageSize: 100,
});

const agent = createReactAgent({ llm, tools });
await agent.invoke({ messages: [{ role: "user", content: "Why did last night's nightly-etl flow run fail?" }] });
import OpenAI from "openai";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
const openai = new OpenAI();

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["prefectmcp"] }, pageSize: 100,
});

const res = await openai.chat.completions.create({
  model: "gpt-5",
  messages: [{ role: "user", content: "Why did last night's nightly-etl flow run fail?" }],
  tools,
});

// Execute the tool call with the user's vaulted Prefect token
await sk.tools.executeTool(res.choices[0].message.tool_calls[0], "user_123");
import Anthropic from "@anthropic-ai/sdk";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
const anthropic = new Anthropic();

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["prefectmcp"] }, pageSize: 100,
});

const msg = await anthropic.messages.create({
  model: "claude-sonnet-5",
  max_tokens: 1024,
  messages: [{ role: "user", content: "Why did last night's nightly-etl flow run fail?" }],
  tools,
});

// Tool call runs with the user's vaulted Prefect token
await sk.tools.executeTool(msg.content, "user_123");
import { Agent } from "@google/adk/agents";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["prefectmcp"] }, pageSize: 100,
});

const agent = new Agent({
  name: "devops_agent",
  model: "gemini-2.5-pro",
  instruction: "Prefect MCP tools scoped to this user",
  tools,
});

await agent.run("Why did last night's nightly-etl flow run fail?");
Try these prompts
Copy any prompt into your agent. Each maps directly to a Prefect MCP tool. Click to copy, paste into your agent, done.
Runs and failures
Copy the prompt
Copied
List failed flow runs from the last 24 hours.
Copy the prompt
Copied
Show the logs for this flow run.
Copy the prompt
Copied
Which task runs in this flow run are still pending?
Deployments and infrastructure
Copy the prompt
Copied
List the deployments for this flow.
Copy the prompt
Copied
List the work pools in this workspace.
Copy the prompt
Copied
Give me a dashboard overview of this Prefect instance.
Events and docs
Copy the prompt
Copied
Read the events from the last hour.
Copy the prompt
Copied
List the automations configured in this workspace.
Copy the prompt
Copied
Search the Prefect docs for how retries work.
SEE HOW AUTH WORKS
Each user signs in to Prefect once; Scalekit stores and refreshes their tokens. Tokens stay vaulted, every call is scope checked, and every action is logged.
1
Authorize
Your user connects
Prefect MCP
once. We tie it to their identity and the meetings they approved — no shared bot account, no org-wide access
Who:
user ‘A’
when:
Once per user
access:
Limited to user
2
Store
Their
Prefect MCP
token lives in a vault scoped to them. User A's meetings are never reachable by an agent acting for user B, even on the same connection
vault:
encrypted
scope:
per-user
tokens:
auto-refreshed
3
Resolve
When your agent calls a
Prefect MCP
tool, we fetch the right token server-side. It never touches your agent, never appears in the LLM context, never shows up in your logs
speed:
~40ms
check:
before every call
seen by:
nobody
4
Audit
Every
Prefect MCP
tool call is logged — who triggered it, which meeting was fetched, what came back. 90 days of history, tied to the user who authorized it
history:
90 days
export:
SIEM-ready
logged:
every call
Test other agents
See the same per-user auth pattern across other developer and monitoring connectors.
Engineering Teams
DevOps assistant agent
Polls GitHub for failing checks and stale PRs, opens Linear issues for the ones that need work, and posts a daily digest to Slack. It acts as the engineer, not a shared service account.
Engineering Teams
Engineering standup agent
Pulls commits from GitHub and GitLab, tracks issue movement in Jira, and posts a per-engineer standup brief to Slack. Each engineer's activity is read on their own delegated OAuth.
Engineering Teams
Slack triage
Polls Slack for new messages, classifies bugs and support requests with a LangGraph router, files GitHub issues or Zendesk tickets, and confirms in the thread.
Engineering Teams
Auto release notes agent
Reads merged GitHub PRs, groups them into structured release notes, publishes the page to Notion, and announces the release in Slack. Every call runs on the engineer's own delegated OAuth.
Test other agents
See the same per-user auth pattern across other developer and monitoring connectors.
ENGINEERING
DevOps assistant agent
Poll GitHub for failing checks and stale pull requests, open Linear issues for the ones that need work, and digest to Slack.
ENGINEERING
Engineering standup agent
Pull commits from GitHub and GitLab, track Jira issue movement, and post a per-engineer standup brief to Slack.
ENGINEERING
Slack triage agent
Classify new Slack messages as bugs or support requests, file the GitHub issue or Zendesk ticket, and reply in the thread.
ENGINEERING
Auto-release notes agent
Group merged GitHub PRs into structured release notes, publish the page to Notion, and announce the release in Slack.
Why Scalekit
Secure your agent's access. Connectors ship in minutes
01.
Shared tokens break per-user analytics
A shared Prefect token looks fine in a demo. In production every run and log read looks like one service account, and you cannot tell which user triggered it. Scalekit resolves the credential of the actual user who triggered the agent, never a shared bot.
// shared token
audit → bot_service_account

// scalekit
audit → user_abc ✓
02.
Authentication is not authorization
03.
Multi-tenancy is architectural
04.
Prefect today. Ten connectors tomorrow.
“Our agents act across Salesforce, Gong, Google Drive, and more, on behalf of every customer. Scalekit behind the scenes meant we can keep adding tools without ever rebuilding how credentials or tool calling work.”
Venu Madhav Kattagoni
Head of Engineering / Von
FAQs
Frequently Asked Questions
Does the agent access Prefect as the user or as a shared key?
As the user. Each user signs in to Prefect once, and Scalekit stores and refreshes their tokens. Audit logs attribute every run and log read to that user, not a shared service account.
Where is the Prefect OAuth token stored?
In Scalekit's managed AES-256 token vault, namespaced per tenant. Refresh is automatic. Revocation is a single dashboard action. Credentials never appear in prompts, logs, or LLM context.
Can I limit what the agent does in Prefect?
Yes. Filter by tool name in listScopedTools to expose only what you want. Scalekit also enforces scope checks before every API call.
What happens when a user revokes Prefect access?
The connection is invalidated on the next tool call. Subsequent requests for that user fail closed with a clear error. Other users in the tenant remain unaffected. The event is logged for audit.
Can the agent trigger or change Prefect runs?
No. All 15 Prefect MCP tools are read-only: flows, deployments, flow and task runs, logs, work pools, automations, events, and Prefect docs. Access covers only the Prefect Cloud workspaces the user selected during OAuth consent.
Start in your coding agent
Up and running in one command
Install the Scalekit skill in your editor of choice. Connector, auth, tools, prompt, all wired up
Claude Code REPL
/plugin marketplace add scalekit-inc/claude-code-authstack
/plugin install agentkit@scalekit-auth-stack
Cursor Code REPL
# ~/.cursor/mcp.json
{
""mcpServers"": {
""prefectmcp"": {
""url"": ""https://mcp.scalekit.com/prefectmcp"",
""headers"": { ""Authorization"": ""Bearer $SCALEKIT_TOKEN"" }
}
}
}
Codex Code REPL
# ~/.codex/config.toml
[mcp_servers.prefectmcp]
url = ""https://mcp.scalekit.com/prefectmcp""
auth_env = ""SCALEKIT_TOKEN""
Copilot Code REPL
# .vscode/mcp.json
{
""servers"": {
""prefectmcp"": {
""url"": ""https://mcp.scalekit.com/prefectmcp"",
""type"": ""http""
}
}
}