Expose flows as tools
Nothing is exposed by default. List the flows you want inmcp.expose. Each becomes one tool with the same name as the flow id.
input schema tells the model what to send, and the server rejects calls that break it before the flow runs. Without an input schema, the tool accepts any object. Tool names may contain letters, digits, _, - and ., up to 64 characters, so an exposed flow id must fit that.
The tool result holds the flow’s output node as structured content:
errors such as "fetch-history: HTTP 503", so the model can decide whether to retry.
Run the server
mcp.transport:
The HTTP transport requires
mcp.auth.tokens unless mcp.host is 127.0.0.1, localhost or ::1. The server refuses to start otherwise. It also refuses to start when mcp.expose is empty or names an unknown flow.
Connect a client
- Claude Code
- Claude Desktop
Call other MCP servers
Themcp node calls a tool on another MCP server, so a flow can reach systems that already publish MCP tools. Declare each server once under mcpServers, then refer to it by id. Milford connects to remote servers over Streamable HTTP. It does not start local stdio servers.
arguments are templated like other node configs. The result’s output is the tool’s text, and data is its structured content, or the text parsed as JSON when it is JSON. A tool that reports an error fails the node, and retry and timeoutMs on the node apply as usual. The connection is opened on first use and dropped after an error, so the next call reconnects.
Let a decision pick the tool
Thetool can be a template, so a decision node can choose which tool runs. The node then needs an allow list, and Milford refuses to call any tool outside it. Loading the flow fails when a templated tool has no allow list.
Limits
- Tools only. Milford does not expose MCP resources or prompts, and the
mcpnode calls tools only. - Runs use the shared
run.timeoutMsandrun.maxConcurrentRunslimits. Calls over the cap get an error result. - Authentication is static bearer tokens. Put the server behind a gateway for OIDC or mutual TLS.
- MCP calls have no idempotency key.