{"_id":"@argo-mcp/mcp-argo-workflows","_rev":"13-84a3f68ac5f98e967b5310acd3904a3d","name":"@argo-mcp/mcp-argo-workflows","dist-tags":{"latest":"1.2.0"},"versions":{"0.1.4":{"name":"@argo-mcp/mcp-argo-workflows","version":"0.1.4","_id":"@argo-mcp/mcp-argo-workflows@0.1.4","maintainers":[{"name":"odinn1984","email":"levan@sleep-coding.com"}],"homepage":"https://github.com/odinn1984/argo-mcp#readme","bugs":{"url":"https://github.com/odinn1984/argo-mcp/issues"},"bin":{"mcp-argo-workflows":"dist/index.mjs"},"dist":{"shasum":"fe63edc033bf6d2a64408a16e204b73b1652897b","tarball":"https://registry.npmjs.org/@argo-mcp/mcp-argo-workflows/-/mcp-argo-workflows-0.1.4.tgz","fileCount":5,"integrity":"sha512-SAoD+RFSBgCccT+TAjw04YJyO45W53b88Y+3VBSUbDzxMFd/HnfRTIScrLhQEnsWvx3hVxzhg7uJY0AZGjvniQ==","signatures":[{"sig":"MEUCIQC0ByY9KmgoYEiMiB1O3sJOMfr8ZVJFFn/PcLW2sbIalQIgdlf8F4vQdyyxkq7nYSr6ViitkLnss5Ld298rjuP99uY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":3213827},"main":"dist/index.mjs","type":"module","types":"dist/index.d.mts","engines":{"node":">=24"},"gitHead":"a9f943869046f4404180caf8b4e62ec681f92dac","scripts":{"dev":"tsdown --watch","lint":"eslint src test-integration test-auth --max-warnings 0","test":"bun test src","build":"tsdown && chmod +x dist/index.mjs","clean":"rm -rf dist *.tsbuildinfo","start":"bun src/index.ts","test:auth":"bun test test-auth","start:prod":"node dist/index.mjs","type-check":"tsc --noEmit -p tsconfig.app.json && tsc --noEmit -p tsconfig.spec.json","test:integration":"bun test test-integration","test:integration:sso-rbac":"bun test test-integration/auth-sso-rbac.it.spec.ts","test:integration:sso-client":"bun test test-integration/auth-sso-client.it.spec.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:0337d8e2-e539-4411-8548-a3156d7413d9"}},"repository":{"url":"git+https://github.com/odinn1984/argo-mcp.git","type":"git","directory":"apps/mcp-argo-workflows"},"_npmVersion":"11.15.0","description":"MCP server for Argo Workflows","directories":{},"_nodeVersion":"24.15.0","dependencies":{"zod":"^4.0.0","pino":"^9.0.0","citty":"^0.1.6","undici":"^8.3.0","pino-pretty":"^11.0.0","openid-client":"^6.8.4","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-argo-workflows_0.1.4_1779734976089_0.07733342540497978","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"@argo-mcp/mcp-argo-workflows","version":"1.0.0","_id":"@argo-mcp/mcp-argo-workflows@1.0.0","maintainers":[{"name":"odinn1984","email":"levan@sleep-coding.com"}],"homepage":"https://github.com/odinn1984/argo-mcp#readme","bugs":{"url":"https://github.com/odinn1984/argo-mcp/issues"},"bin":{"mcp-argo-workflows":"dist/index.mjs"},"dist":{"shasum":"900cd6c771822d86b053896024d99c593b46356a","tarball":"https://registry.npmjs.org/@argo-mcp/mcp-argo-workflows/-/mcp-argo-workflows-1.0.0.tgz","fileCount":5,"integrity":"sha512-o0782alRsQ3u9C9dwWscFgDuBRzmSS5+0TR887ob0r85wf4WGaQXMomWvt2C+vHdWwGhSobVpw4LX6pV+/p4Ug==","signatures":[{"sig":"MEQCIHmDMYt4RpnRXX0Ji6kebKlYyzcLg2taL2tMJD3o+pgGAiA3R2r5BRYCzglgzosMe8Id/r9ozjclB8lDJ5RW6ps8vw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":3102014},"main":"dist/index.mjs","type":"module","types":"dist/index.d.mts","engines":{"node":">=24"},"gitHead":"07cf5e8caf4979e37f05dbbf22971e906bdf6c72","scripts":{"dev":"tsdown --watch","lint":"eslint src test-integration test-auth --max-warnings 0","test":"bun test src","build":"tsdown && chmod +x dist/index.mjs","clean":"rm -rf dist *.tsbuildinfo","start":"bun src/index.ts","test:auth":"bun test test-auth","start:prod":"node dist/index.mjs","type-check":"tsc --noEmit -p tsconfig.app.json && tsc --noEmit -p tsconfig.spec.json","test:integration":"bun test test-integration"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:0337d8e2-e539-4411-8548-a3156d7413d9"}},"repository":{"url":"git+https://github.com/odinn1984/argo-mcp.git","type":"git","directory":"apps/mcp-argo-workflows"},"_npmVersion":"11.15.0","description":"MCP server for Argo Workflows","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^4.0.0","pino":"^9.0.0","citty":"^0.1.6","undici":"^8.3.0","pino-pretty":"^11.0.0","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-argo-workflows_1.0.0_1779826443303_0.5325060725699062","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@argo-mcp/mcp-argo-workflows","version":"1.0.1","_id":"@argo-mcp/mcp-argo-workflows@1.0.1","maintainers":[{"name":"odinn1984","email":"levan@sleep-coding.com"}],"homepage":"https://github.com/odinn1984/argo-mcp#readme","bugs":{"url":"https://github.com/odinn1984/argo-mcp/issues"},"bin":{"mcp-argo-workflows":"dist/index.mjs"},"dist":{"shasum":"8190292faa1eb3e16362314d242c9a4452449e47","tarball":"https://registry.npmjs.org/@argo-mcp/mcp-argo-workflows/-/mcp-argo-workflows-1.0.1.tgz","fileCount":5,"integrity":"sha512-EOCpUgvnMhN5dVNNcSEYpeMX6XVt/apNHwtvV/soQrKWsJJBbMhgzm3t8cSTsrmr91rr3XeMQd5NZgIR+NU0KQ==","signatures":[{"sig":"MEYCIQCFppT49LF7fXXXIYBcacrgJh11yuFAwrmludTe2BK9PQIhANLoz6WH1FVIsNEBiEb1slDugVxOSZim9zpWDMu7kb/L","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":3102014},"main":"dist/index.mjs","type":"module","types":"dist/index.d.mts","engines":{"node":">=24"},"gitHead":"687e228629f02f65030bae58e9d0788efd9189b5","scripts":{"dev":"tsdown --watch","lint":"eslint src test-integration test-auth --max-warnings 0","test":"bun test src","build":"tsdown && chmod +x dist/index.mjs","clean":"rm -rf dist *.tsbuildinfo","start":"bun src/index.ts","test:auth":"bun test test-auth","start:prod":"node dist/index.mjs","type-check":"tsc --noEmit -p tsconfig.app.json && tsc --noEmit -p tsconfig.spec.json","test:integration":"bun test test-integration"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:0337d8e2-e539-4411-8548-a3156d7413d9"}},"repository":{"url":"git+https://github.com/odinn1984/argo-mcp.git","type":"git","directory":"apps/mcp-argo-workflows"},"_npmVersion":"11.15.0","description":"MCP server for Argo Workflows","directories":{},"_nodeVersion":"24.15.0","dependencies":{"zod":"^4.0.0","pino":"^9.0.0","citty":"^0.1.6","undici":"^8.3.0","pino-pretty":"^11.0.0","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-argo-workflows_1.0.1_1779828204212_0.29916188024020296","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@argo-mcp/mcp-argo-workflows","version":"1.1.0","_id":"@argo-mcp/mcp-argo-workflows@1.1.0","maintainers":[{"name":"odinn1984","email":"levan@sleep-coding.com"}],"homepage":"https://github.com/odinn1984/argo-mcp#readme","bugs":{"url":"https://github.com/odinn1984/argo-mcp/issues"},"bin":{"mcp-argo-workflows":"dist/index.mjs"},"dist":{"shasum":"94fefe6c34447f316a3d153e7016120643391bdc","tarball":"https://registry.npmjs.org/@argo-mcp/mcp-argo-workflows/-/mcp-argo-workflows-1.1.0.tgz","fileCount":5,"integrity":"sha512-0OHaAo3LltYwDj0AmDPIuVoN56hsopKohODzeFG94VwFLspJSxBoGVZLzzzNGWYVdcJ2Th4kPs1h0L18CZ4o1A==","signatures":[{"sig":"MEYCIQCbKk9lRbtS1mCI0JC4Nfopa7PsZXeNywKSp2Tftit1awIhAN5V6eC8Z3s9bQkw/JwPEVsMK4Pqe8YzQp/JaYAN96mH","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":3117762},"main":"dist/index.mjs","type":"module","types":"dist/index.d.mts","engines":{"node":">=24"},"gitHead":"d4185594b08b998a555f47460e2f862f60d13ad4","scripts":{"dev":"tsdown --watch","lint":"eslint src test-integration test-auth --max-warnings 0","test":"bun test src","build":"tsdown && chmod +x dist/index.mjs","clean":"rm -rf dist *.tsbuildinfo","start":"bun src/index.ts","test:auth":"bun test test-auth","start:prod":"node dist/index.mjs","type-check":"tsc --noEmit -p tsconfig.app.json && tsc --noEmit -p tsconfig.spec.json","test:integration":"bun test test-integration"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:0337d8e2-e539-4411-8548-a3156d7413d9"}},"repository":{"url":"git+https://github.com/odinn1984/argo-mcp.git","type":"git","directory":"apps/mcp-argo-workflows"},"_npmVersion":"11.15.0","description":"MCP server for Argo Workflows","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^4.0.0","pino":"^9.0.0","citty":"^0.1.6","undici":"^8.3.0","pino-pretty":"^11.0.0","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-argo-workflows_1.1.0_1779873710454_0.4795295953524239","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@argo-mcp/mcp-argo-workflows","version":"1.2.0","description":"MCP server for Argo Workflows","type":"module","main":"dist/index.mjs","types":"dist/index.d.mts","bin":{"mcp-argo-workflows":"dist/index.mjs"},"repository":{"type":"git","url":"git+https://github.com/odinn1984/argo-mcp.git","directory":"apps/mcp-argo-workflows"},"scripts":{"build":"tsdown && chmod +x dist/index.mjs","dev":"tsdown --watch","start":"bun src/index.ts","start:prod":"node dist/index.mjs","lint":"eslint src test-integration test-auth --max-warnings 0","type-check":"tsc --noEmit -p tsconfig.app.json && tsc --noEmit -p tsconfig.spec.json","test":"bun test src","test:integration":"bun test test-integration","test:auth":"bun test test-auth","clean":"rm -rf dist *.tsbuildinfo"},"dependencies":{"@modelcontextprotocol/sdk":"^1.0.0","citty":"^0.1.6","pino":"^9.0.0","pino-pretty":"^11.0.0","undici":"^8.3.0","zod":"^4.0.0"},"engines":{"node":">=24"},"gitHead":"46c346c0941a1769e345e9f129f62b04d723a9d9","_id":"@argo-mcp/mcp-argo-workflows@1.2.0","bugs":{"url":"https://github.com/odinn1984/argo-mcp/issues"},"homepage":"https://github.com/odinn1984/argo-mcp#readme","_nodeVersion":"24.16.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-R760tusT575eqdw75RHGL5C/xsNQcC2QDi15EJLSGQT8hCFblkxN5Cs2pJxEykrodm+/Ln/+n9EJdiS/cNCw5g==","shasum":"c153abfd1af357cfdd66caa7210c6ece77415eb9","tarball":"https://registry.npmjs.org/@argo-mcp/mcp-argo-workflows/-/mcp-argo-workflows-1.2.0.tgz","fileCount":5,"unpackedSize":3125038,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIG3GBytDVOdQ1A6mqppYMfdqEWaw9zjnQKLBh8A8jzA7AiEAsmc084sWPmZuezlt8ggQLBzgFMlNWqgeRAv0fyjxiKQ="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:0337d8e2-e539-4411-8548-a3156d7413d9"}},"directories":{},"maintainers":[{"name":"odinn1984","email":"levan@sleep-coding.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-argo-workflows_1.2.0_1780352459248_0.3314057754854227"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-25T17:54:50.373Z","modified":"2026-06-01T22:20:59.903Z","0.1.3":"2026-05-25T17:54:50.761Z","0.1.4-git-2af953f.0":"2026-05-25T18:13:57.154Z","0.1.4-git-1b3352e.0":"2026-05-25T18:15:30.997Z","0.1.4-git-329beda.0":"2026-05-25T18:24:53.428Z","0.1.4":"2026-05-25T18:49:36.292Z","1.0.0":"2026-05-26T20:14:03.543Z","1.0.1":"2026-05-26T20:43:24.386Z","1.1.0":"2026-05-27T09:21:50.668Z","1.2.0":"2026-06-01T22:20:59.429Z"},"bugs":{"url":"https://github.com/odinn1984/argo-mcp/issues"},"homepage":"https://github.com/odinn1984/argo-mcp#readme","repository":{"type":"git","url":"git+https://github.com/odinn1984/argo-mcp.git","directory":"apps/mcp-argo-workflows"},"description":"MCP server for Argo Workflows","maintainers":[{"name":"odinn1984","email":"levan@sleep-coding.com"}],"readme":"# Argo Workflows MCP\n\nAn [MCP](https://modelcontextprotocol.io) server that exposes [Argo Workflows](https://argoproj.github.io/workflows/)\noperations as tools. It connects to an Argo Workflows API server and lets MCP clients list, inspect, submit, and manage\nworkflows, archived workflows, artifacts, Argo Events EventSources, and Sensors.\n\n## Table of contents\n\n- [Overview](#overview)\n- [Quick start](#quick-start)\n- [Launching the server](#launching-the-server)\n  - [Run modes](#run-modes)\n    - [Dev (no build) via `just`](#dev-no-build-via-just)\n    - [Built binary](#built-binary)\n    - [HTTP with TLS](#http-with-tls)\n  - [Auth modes](#auth-modes)\n    - [`bearer` — static token from the environment](#bearer--static-token-from-the-environment)\n    - [`bearer-file` — token read from a file each request](#bearer-file--token-read-from-a-file-each-request)\n    - [`k8s-service-account` — in-cluster service-account token](#k8s-service-account--in-cluster-service-account-token)\n    - [`none` — no authentication](#none--no-authentication)\n- [CLI flags](#cli-flags)\n- [Environment variables](#environment-variables)\n- [Registering with an MCP client](#registering-with-an-mcp-client)\n- [Tool reference](#tool-reference)\n- [Troubleshooting](#troubleshooting)\n  - [`missing Argo Workflows server URL`](#missing-argo-workflows-server-url)\n  - [`auth mode \"bearer\" requires a token`](#auth-mode-bearer-requires-a-token)\n  - [`auth mode \"bearer-file\" requires a token file`](#auth-mode-bearer-file-requires-a-token-file)\n  - [`401 Unauthorized` from every tool](#401-unauthorized-from-every-tool)\n  - [`x509: certificate signed by unknown authority`](#x509-certificate-signed-by-unknown-authority)\n\n## Overview\n\nThe server speaks the MCP protocol over a streamable HTTP transport by default, or over stdio when launched with\n`--stdio` (for embedding directly in an MCP client). On start-up it builds a typed Argo Workflows client from the\nsupplied CLI flags / environment variables, registers the full tool set (~38 tools), and serves requests until it\nreceives `SIGINT` or `SIGTERM`.\n\nAuthentication mirrors the way the upstream `argo` CLI authenticates: a static or rotating bearer token, a projected\nKubernetes service-account token, or no credentials at all. SSO is an Argo UI concern and is **not** supported here;\nif your MCP client needs SSO it must mint a bearer token externally and pass it via one of the bearer modes below.\n\n## Quick start\n\nRun against a local Argo Workflows server with no auth (development only):\n\n```sh\njust run-workflows --argo-server-url http://localhost:2746 --argo-auth-mode none\n```\n\nThen register it with your MCP client (see [Registering with an MCP client](#registering-with-an-mcp-client)).\n\nThe rest of this README walks through the run modes (how the server is invoked) and the auth modes (how it\nauthenticates to the Argo server). Pick one from each section and combine the flags.\n\n## Launching the server\n\nYou need three things to launch:\n\n1. **Server URL** — `--argo-server-url` or `ARGO_SERVER_URL`. Point at the Argo Workflows API server\n   (e.g. `https://argo.example.com`). For a port-forwarded local server use `http://localhost:2746`.\n2. **Run mode** — how the process itself is started: dev recipe, built binary, or HTTP-with-TLS. See\n   [Run modes](#run-modes).\n3. **Auth mode** — `--argo-auth-mode` or `ARGO_AUTH_MODE`. One of `bearer`, `bearer-file`, `k8s-service-account`, or\n   `none`. Defaults to `k8s-service-account` when `KUBERNETES_SERVICE_HOST` is set (in-cluster), otherwise `none`. See\n   [Auth modes](#auth-modes).\n\nEvery example below combines a run-mode invocation with one auth mode's flags. Swap the auth flags for any other mode\nfrom the [Auth modes](#auth-modes) section.\n\n### Run modes\n\n#### Dev (no build) via `just`\n\nRuns the TypeScript entry point with Bun. Best for local development against a real Argo server.\n\n```sh\nARGO_TOKEN=\"<token>\" just run-workflows \\\n  --argo-server-url https://argo.example.com \\\n  --argo-auth-mode bearer\n```\n\nAll flags after `run-workflows` are forwarded to the server. Override the listener with `--host` / `--port`:\n\n```sh\njust run-workflows \\\n  --host 127.0.0.1 \\\n  --port 9001 \\\n  --argo-server-url https://argo.example.com \\\n  --argo-auth-mode none\n```\n\n#### Built binary\n\nAfter building, the package exposes a `mcp-argo-workflows` bin (declared in\n`apps/mcp-argo-workflows/package.json#bin`). Inside this repo, invoke the built artifact directly with `node`:\n\n```sh\njust filter mcp-argo-workflows\nnode apps/mcp-argo-workflows/dist/index.mjs \\\n  --argo-server-url https://argo.example.com \\\n  --argo-auth-mode k8s-service-account\n```\n\nAfter installing the package globally (or in a container that puts the bin on `PATH`), the same invocation becomes:\n\n```sh\nmcp-argo-workflows \\\n  --argo-server-url https://argo.example.com \\\n  --argo-auth-mode k8s-service-account\n```\n\nThis is the form to use inside a container or Pod.\n\n#### Published package\n\nThe server is published to two registries under different scopes — same code, pick whichever fits:\n\n| Registry        | Scope        | Package                         | Stable (`@latest`) | Prerelease (`@alpha`) | Auth                           |\n| --------------- | ------------ | ------------------------------- | :----------------: | :-------------------: | ------------------------------ |\n| npm (npmjs.org) | `@argo-mcp`  | `@argo-mcp/mcp-argo-workflows`  | ✓                  | —                     | none — public                  |\n| GitHub Packages | `@odinn1984` | `@odinn1984/mcp-argo-workflows` | ✓                  | ✓                     | GitHub token (`read:packages`) |\n\nFor stable releases, use whichever fits (npmjs is easier). Alpha builds are only on GitHub Packages.\n\nInternal workspace dependencies are bundled — no repo checkout or build required either way.\n\n##### From npmjs (recommended for stable)\n\nNo `.npmrc` config needed:\n\n```sh\nnpx -y @argo-mcp/mcp-argo-workflows \\\n  --argo-server-url https://argo.example.com \\\n  --argo-auth-mode k8s-service-account\n```\n\n##### From GitHub Packages\n\nGitHub Packages requires authentication even for reads. Point the `@odinn1984` scope at the GitHub registry\nand supply a token with `read:packages` in `~/.npmrc`:\n\n```ini\n@odinn1984:registry=https://npm.pkg.github.com\n//npm.pkg.github.com/:_authToken=${GITHUB_TOKEN}\n```\n\nThen run it with `npx`:\n\n```sh\nnpx -y @odinn1984/mcp-argo-workflows \\\n  --argo-server-url https://argo.example.com \\\n  --argo-auth-mode k8s-service-account\n```\n\n##### Dist-tags\n\n- `@latest` — stable releases cut from Conventional Commits on `main`. Published to **both** registries.\n- `@alpha` — preview builds, published on every feature-branch / PR push as `<x.y.z>-git<short-sha>`.\n  Published to **GitHub Packages only**.\n\nPin a version (e.g. `@argo-mcp/mcp-argo-workflows@0.1.0`) when embedding the server in an MCP client config so\nupgrades stay explicit.\n\n#### HTTP with TLS\n\nThe default transport is HTTP on port `8081`. To serve over HTTPS, supply both `--tls-cert` and `--tls-key`\n(passing only one is an error):\n\n```sh\njust run-workflows \\\n  --tls-cert ./certs/server.crt \\\n  --tls-key  ./certs/server.key \\\n  --argo-server-url https://argo.example.com \\\n  --argo-auth-mode bearer-file \\\n  --argo-token-file ~/.argo/token\n```\n\n#### stdio\n\nPass `--stdio` to speak MCP over the process' stdin/stdout instead of HTTP — the transport an MCP client uses when it\nlaunches the server as a child process. `--host`, `--port`, and `--tls-*` are ignored in this mode; the `--argo-*`\nconnection flags still apply. All diagnostics go to stderr so they never corrupt the protocol stream.\n\n```sh\njust run-workflows --stdio \\\n  --argo-server-url https://argo.example.com \\\n  --argo-auth-mode bearer-file \\\n  --argo-token-file ~/.argo/token\n```\n\n### Auth modes\n\nPick one and slot its flags into any of the run-mode commands above.\n\n| Mode                  | Credential source                                                                                                                        |\n| --------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- |\n| `bearer`              | Static bearer token from the `ARGO_TOKEN` environment variable.                                                                          |\n| `bearer-file`         | Bearer token read from `--argo-token-file` (re-read on each request).                                                                    |\n| `k8s-service-account` | Kubernetes service-account token; default path `/var/run/secrets/kubernetes.io/serviceaccount/token`, override with `--argo-token-file`. |\n| `none`                | No authentication (anonymous access).                                                                                                    |\n\n#### `bearer` — static token from the environment\n\nUse when you have a long-lived service-account token or a freshly minted token and want to pass it directly.\n\n**How to get the token**\n\n- From the Argo CLI (mints a token for the current kubeconfig user):\n\n  ```sh\n  argo auth token\n  ```\n\n  The first line of stdout (after the `Bearer` prefix) is the token. Strip the `Bearer` prefix and the trailing\n  space when setting `ARGO_TOKEN`.\n\n- From a Kubernetes service-account in the `argo` namespace (Argo ≥ 3.4 with client-side token generation):\n\n  ```sh\n  kubectl -n argo create token argo-server --duration=24h\n  ```\n\n- From a long-lived service-account Secret (Kubernetes ≤ 1.23 style, or a manually-created `kubernetes.io/service-account-token` Secret):\n\n  ```sh\n  kubectl -n argo get secret <sa-secret-name> -o jsonpath='{.data.token}' | base64 -d\n  ```\n\n**Auth flags**\n\n```sh\n--argo-auth-mode bearer\n```\n\nThe token is read from the `ARGO_TOKEN` environment variable at boot:\n\n```sh\nexport ARGO_TOKEN=\"<token>\"\n```\n\n> **Note:** `ARGO_TOKEN` is an environment variable, not a CLI flag, so the token never appears in the host's\n> process list. It is read once at boot and fixed until restart — for a rotating token use\n> [`bearer-file`](#bearer-file--token-read-from-a-file-each-request).\n\n#### `bearer-file` — token read from a file each request\n\nUse when the token rotates on disk (sidecar refresher, `kubectl create token` cron, etc.). The file is re-read on every\noutbound request, so rotation is picked up without restarting the server.\n\n**How to get the token file**\n\n- Write any of the bearer-token sources above to a file:\n\n  ```sh\n  kubectl -n argo create token argo-server --duration=24h > ~/.argo/token\n  chmod 600 ~/.argo/token\n  ```\n\n- Or have your token refresher write to that path on a schedule. The file must contain just the raw token (no\n  `Bearer` prefix or surrounding whitespace; trailing whitespace is trimmed on read).\n\n**Auth flags**\n\n```sh\n--argo-auth-mode bearer-file --argo-token-file ~/.argo/token\n```\n\n#### `k8s-service-account` — in-cluster service-account token\n\nUse when the MCP server runs inside the same Kubernetes cluster as Argo Workflows (e.g. as a Pod). The container's\nprojected service-account token is read from disk and sent as a bearer token.\n\n**How to get the token**\n\nNothing to do — the kubelet projects the token onto the Pod's filesystem. The default path is:\n\n```text\n/var/run/secrets/kubernetes.io/serviceaccount/token\n```\n\nFor this to work, the Pod's `ServiceAccount` needs RBAC permissions against the Argo API server (typically a\n`RoleBinding` to a Role with `workflows`, `workflowtemplates`, etc. verbs).\n\n**Auth flags (default token path)**\n\n```sh\n--argo-auth-mode k8s-service-account\n```\n\n**Auth flags with a custom token path** (e.g. a non-default projected volume, or a token mounted from a `kubectl create\ntoken` cron):\n\n```sh\n--argo-auth-mode k8s-service-account --argo-token-file /var/run/argo/token\n```\n\nWhen `KUBERNETES_SERVICE_HOST` is set you can omit `--argo-auth-mode` entirely — the server defaults to\n`k8s-service-account` in-cluster.\n\n#### `none` — no authentication\n\nUse only against an Argo server that has authentication disabled (`--auth-mode=server` on the Argo server, or a local\ndev cluster). No credential is sent.\n\n**Auth flags**\n\n```sh\n--argo-auth-mode none\n```\n\n## CLI flags\n\n| Flag                              | Type    | Default   | Description                                                                                                          |\n| --------------------------------- | ------- | --------- | -------------------------------------------------------------------------------------------------------------------- |\n| `--stdio`                         | boolean | `false`   | Speak MCP over stdio instead of HTTP (for embedding in an MCP client); ignores `--host`/`--port`/`--tls-*`.          |\n| `--host`                          | string  | `0.0.0.0` | Bind address (HTTP transport only).                                                                                 |\n| `--port`                          | string  | `8081`    | TCP port (HTTP transport only).                                                                                     |\n| `--tls-cert`                      | string  | —         | Path to a PEM-encoded TLS certificate (requires `--tls-key`).                                                        |\n| `--tls-key`                       | string  | —         | Path to a PEM-encoded TLS private key (requires `--tls-cert`).                                                       |\n| `--argo-server-url`               | string  | —         | Argo Workflows server URL (e.g. `https://argo.example.com`).                                                         |\n| `--argo-auth-mode`                | string  | see note  | Auth mode: `bearer`, `bearer-file`, `k8s-service-account`, or `none`. Defaults to `k8s-service-account` in-cluster, otherwise `none`. |\n| `--argo-token-file`               | string  | —         | Path to a token file (required for `bearer-file`; overrides the default path for `k8s-service-account`).             |\n| `--argo-default-namespace`        | string  | `argo`    | Default Kubernetes namespace used when a tool call omits one.                                                        |\n| `--argo-insecure-skip-tls-verify` | boolean | `false`   | Skip TLS verification for outbound Argo requests (debug only). Scoped to the Argo client — other connections still verify TLS. |\n\n## Environment variables\n\nThe `--argo-*` connection flags fall back to environment variables when the flag is absent. A flag always wins over its\nenvironment variable.\n\n| Variable                        | Equivalent flag                                                  |\n| ------------------------------- | ---------------------------------------------------------------- |\n| `ARGO_SERVER_URL`               | `--argo-server-url`                                              |\n| `ARGO_AUTH_MODE`                | `--argo-auth-mode`                                               |\n| `ARGO_TOKEN`                    | _(environment only — `bearer` mode has no token flag)_           |\n| `ARGO_TOKEN_FILE`               | `--argo-token-file`                                              |\n| `ARGO_DEFAULT_NAMESPACE`        | `--argo-default-namespace`                                       |\n| `ARGO_INSECURE_SKIP_TLS_VERIFY` | `--argo-insecure-skip-tls-verify` (set to `1`, `true`, or `yes`) |\n\n## Registering with an MCP client\n\nPoint the URL at whatever host and port the server is bound to. Any MCP client that supports the streamable HTTP\ntransport can connect the same way. With the Claude Code CLI:\n\n```sh\nclaude mcp add --transport http argo-workflows http://localhost:8081\n```\n\nTo have the client launch the server itself, register the `--stdio` command instead:\n\n```sh\nclaude mcp add argo-workflows -- \\\n  mcp-argo-workflows --stdio --argo-server-url https://argo.example.com --argo-auth-mode none\n```\n\n## Tool reference\n\nEach tool is annotated as read-only or destructive. Read-only tools have no side effects on the Argo server.\nDestructive tools mutate or delete cluster state and may be irreversible.\n\n### Info\n\n| Tool               | Description                                                                                            | Kind      |\n| ------------------ | ------------------------------------------------------------------------------------------------------ | --------- |\n| `get_argo_info`    | Return the Argo Workflows server-level info (executor image, default executor, links, navColor, etc.). | Read-only |\n| `get_argo_version` | Return the Argo Workflows server version (semantic version, git commit, build date, Go version).      | Read-only |\n| `get_user_info`    | Return the authenticated user identity as seen by the Argo server (issuer, subject, groups, email).   | Read-only |\n\n### Workflow read\n\n| Tool                | Description                                                                                     | Kind      |\n| ------------------- | ----------------------------------------------------------------------------------------------- | --------- |\n| `list_workflows`    | List workflows in a namespace with optional label/field selectors and pagination.               | Read-only |\n| `get_workflow`      | Fetch a single workflow by name (full `Workflow` resource: spec + status).                      | Read-only |\n| `get_workflow_logs` | Stream-drain workflow logs across one or all pods into a single text payload (capped at ~64KB). | Read-only |\n| `get_pod_logs`      | Stream-drain logs for a single pod inside a workflow into one text payload (capped at ~64KB).   | Read-only |\n\n### Workflow lifecycle\n\n| Tool                | Description                                                                                            | Kind      |\n| ------------------- | ------------------------------------------------------------------------------------------------------ | --------- |\n| `submit_workflow`   | Submit a workflow from a referenced template (WorkflowTemplate, ClusterWorkflowTemplate, CronWorkflow). | Mutating  |\n| `lint_workflow`     | Lint a workflow manifest server-side without creating it.                                              | Read-only |\n| `suspend_workflow`  | Suspend a running workflow at the next step boundary (reversible via `resume_workflow`).               | Mutating  |\n| `resume_workflow`   | Resume a previously suspended workflow.                                                                | Mutating  |\n| `resubmit_workflow` | Resubmit a workflow as a new run; the original workflow is left untouched.                             | Mutating  |\n| `set_workflow`      | Set node-level fields on a workflow: phase, message, or output parameters.                             | Mutating  |\n\n### Workflow destructive\n\n| Tool                 | Description                                                                                     | Kind        |\n| -------------------- | ----------------------------------------------------------------------------------------------- | ----------- |\n| `retry_workflow`     | Retry a failed or errored workflow; failed pods are deleted and the run restarts. Irreversible. | Destructive |\n| `stop_workflow`      | Gracefully stop a running workflow via the exit handler, leaving it in a terminal state.        | Destructive |\n| `terminate_workflow` | Hard-kill a workflow; every pod is deleted immediately without running exit handlers.           | Destructive |\n| `delete_workflow`    | Permanently delete a workflow resource from the cluster; history and outputs are lost.          | Destructive |\n\n### Artifacts\n\n| Tool                           | Description                                                                           | Kind      |\n| ------------------------------ | ------------------------------------------------------------------------------------- | --------- |\n| `get_workflow_output_artifact` | Stream a workflow output artifact to a local file; returns `{ path, bytes, sha256 }`. | Read-only |\n| `get_workflow_input_artifact`  | Stream a workflow input artifact to a local file; returns `{ path, bytes, sha256 }`.  | Read-only |\n\nThe artifact tools are read-only against the Argo server; the local-disk write is caller-directed via `destinationPath`.\n\n### Archived workflow read\n\n| Tool                                  | Description                                                                                       | Kind      |\n| ------------------------------------- | ------------------------------------------------------------------------------------------------- | --------- |\n| `list_archived_workflows`             | List archived (persisted) workflows with namespace, selector, started-at, and pagination filters. | Read-only |\n| `get_archived_workflow`               | Fetch a single archived workflow by UID.                                                          | Read-only |\n| `list_archived_workflow_label_keys`   | List all label keys present on archived workflows.                                                | Read-only |\n| `list_archived_workflow_label_values` | List all values for a given label key across archived workflows.                                  | Read-only |\n\n### Archived workflow mutating\n\n| Tool                         | Description                                                                                  | Kind        |\n| ---------------------------- | -------------------------------------------------------------------------------------------- | ----------- |\n| `delete_archived_workflow`   | Delete an archived workflow record by UID; the original live workflow is not affected.       | Destructive |\n| `retry_archived_workflow`    | Retry an archived workflow by UID; pods for failed/errored nodes are deleted and re-created. | Destructive |\n| `resubmit_archived_workflow` | Resubmit an archived workflow by UID as a fresh workflow; the archive record is untouched.   | Mutating    |\n\n### Event sources\n\n| Tool                    | Description                                                                            | Kind        |\n| ----------------------- | -------------------------------------------------------------------------------------- | ----------- |\n| `list_event_sources`    | List Argo Events EventSources in a namespace.                                          | Read-only   |\n| `get_event_source`      | Get a single Argo Events EventSource by name.                                          | Read-only   |\n| `create_event_source`   | Create a new Argo Events EventSource in a namespace.                                   | Mutating    |\n| `update_event_source`   | Update an existing Argo Events EventSource; the request replaces the spec.             | Mutating    |\n| `delete_event_source`   | Delete an Argo Events EventSource by name; downstream consumers stop receiving events. | Destructive |\n| `get_event_source_logs` | Drain Argo Events EventSource logs into a single text payload (bounded at ~64KB).      | Read-only   |\n\n### Sensors\n\n| Tool              | Description                                                                                        | Kind        |\n| ----------------- | -------------------------------------------------------------------------------------------------- | ----------- |\n| `list_sensors`    | List Argo Events Sensors in a namespace.                                                           | Read-only   |\n| `get_sensor`      | Get a single Argo Events Sensor by name.                                                           | Read-only   |\n| `create_sensor`   | Create an Argo Events Sensor.                                                                      | Mutating    |\n| `update_sensor`   | Update an existing Argo Events Sensor by name.                                                     | Mutating    |\n| `delete_sensor`   | Delete an Argo Events Sensor by name; in-flight triggers tied to it are removed.                   | Destructive |\n| `get_sensor_logs` | Drain Argo Events Sensor logs into a single text payload (bounded; truncation marker on overflow). | Read-only   |\n\n## Troubleshooting\n\n### `missing Argo Workflows server URL`\n\nPass `--argo-server-url` or set `ARGO_SERVER_URL`.\n\n### `auth mode \"bearer\" requires a token`\n\nSet the `ARGO_TOKEN` environment variable. See [`bearer`](#bearer--static-token-from-the-environment) for how to mint one.\n\n### `auth mode \"bearer-file\" requires a token file`\n\nPass `--argo-token-file` or set `ARGO_TOKEN_FILE`. See\n[`bearer-file`](#bearer-file--token-read-from-a-file-each-request) for how to populate the file.\n\n### `401 Unauthorized` from every tool\n\nThe bearer token expired or has no RBAC permissions. In `bearer-file` mode, refresh the token (re-run\n`argo auth token`) and overwrite the token file — no server restart needed. In `bearer` mode, restart the server with\na fresh `ARGO_TOKEN`.\n\n### `x509: certificate signed by unknown authority`\n\nThe Argo server is using a private CA. For local development you can set `--argo-insecure-skip-tls-verify` (debug only —\ndisables TLS verification for the Argo client). In production, mount the CA bundle into the host's trust store instead.\n","readmeFilename":"README.md"}