Langflow

Platform · Last verified 2026-09-30

TL;DR

Langflow is an MIT-licensed visual builder for agent and RAG flows, maintained by the Langflow project on GitHub. Flows are made of Python components, and an Agent component can call other agents as tools. Each flow can be served over REST, MCP or A2A. It suits Python teams that want to prototype visually and still edit code.

Key facts

Langflow key facts. Data as of 2026-09-30.
Type Platform
Languages / SDKs Python, TypeScript
License MIT
Pricing model Open source, free
Orchestration pattern Supervisor
GitHub stars 155,389 (as of 2026-09-30)
GitHub forks 10,150
Last push 2026-09-30
Latest release v1.12.4
Repository langflow-ai/langflow
Website www.langflow.org
Documentation docs.langflow.org
Last verified 2026-09-30

Key features

  • The Agent component combines a chosen model, custom instructions and tools; any component switched to Tool Mode, including other agents and MCP servers, can be wired to its Tools port. (source)
  • Multi-agent flows are built by setting a second Agent component to Tool Mode and attaching it as a tool of the primary agent, with an editable tool name and description. (source)
  • Every project can be served as an MCP server whose tools are the project's flows, over streamable HTTP with SSE as a fallback; the MCP Tools component lets agents call external MCP servers. (source)
  • With LANGFLOW_A2A_ENABLED=true, an agent-type flow can be published as an A2A agent with an agent card and JSON-RPC endpoint, and the A2A Agent component calls remote A2A agents from inside a flow. (source)
  • The beta Workflow API runs flows in sync, stream or background mode, and stream mode can emit AG-UI events instead of Langflow's own event format. (source)
  • Human-in-the-loop gates pause a run at a checkpoint and resume after approval, either through a Human Input component with branches or a per-tool Requires approval switch. (source)
  • A Langflow MCP Client settings entry configures coding agents such as Claude Code to build and run flows through the lfx-mcp server. (source)
  • Flows can be packaged and published to IBM watsonx Orchestrate as tools for wxO agents, behind a feature flag. (source)

Architecture and orchestration pattern

Pattern: Supervisor

Langflow is a Python server with a web editor. A flow is a directed graph of components (inputs, models, prompts, tools, vector stores, outputs), each a Python class that can be edited in place. The server runs the graph when a flow is called from the Playground, the v1 /run endpoint, the beta v2 Workflow API, webhooks, MCP or A2A.

Agent behaviour lives in the Agent component, which runs a tool-calling loop over whatever is connected to its Tools port. Multi-agent designs follow an agent-as-tool pattern: a secondary Agent in Tool Mode becomes one of the primary agent's tools, so the primary agent decides when to delegate. Flows can also call other flows or remote agents through MCP Tools and the A2A Agent component.

State is kept in a database, SQLite by default (tied to the virtual environment for pip installs) or external PostgreSQL via LANGFLOW_DATABASE_URL. Agents have chat memory on by default: messages are grouped by session_id and a configurable number of recent messages is fed back each turn; the Message History component adds filtering and external stores such as Mem0. HITL pauses write a checkpoint so a resumed run does not repeat finished steps.

Human in the loop

Two documented mechanisms. A Human Input component placed in a flow pauses the run, creates a checkpoint and exposes one output branch per configured user action (for example Approve continues and Reject sends a draft back for revision). Alternatively, Requires approval can be switched on for individual tools in the Agent component's tools menu; the run pauses when the agent tries that tool until someone picks Approve or Reject in the Playground, and the decision is saved in chat history so a reloaded session shows it as resolved. In both cases the run resumes from the checkpoint without re-running completed steps.

Harnesses it can drive

Protocols

MCP, A2A and AG-UI support for Langflow. See the full matrix.
ProtocolSupportNote
MCP Yes evidence
checked 2026-09-30
Server and client: projects are served as MCP servers over streamable HTTP with SSE fallback, and the MCP Tools component connects agents to external MCP servers (JSON config, start command or HTTP/SSE URL).
A2A Yes evidence
checked 2026-09-30
Server and client: agent-type flows can be published with an agent card and JSON-RPC endpoint, and the A2A Agent component calls remote agents; off by default (LANGFLOW_A2A_ENABLED=true) and the card advertises protocolVersion 0.3.0.
AG-UI Yes evidence
checked 2026-09-30
Event output only: the Workflow API's stream mode emits AG-UI events when stream_protocol is agui, from an adapter in Langflow's own repository; the Workflow API is labelled Beta, and the AG-UI README still lists Langflow as a community integration in progress.

Best for

  • Python teams that want to sketch agent and RAG flows visually and then edit component code.
  • Running a local or self-hosted agent builder from pip, Docker or the Desktop app under an MIT license. (shortlist)
  • Publishing one flow as a REST endpoint, an MCP tool and an A2A agent at the same time.
  • Letting Claude Code create and run flows on a Langflow server through the lfx-mcp configuration. (shortlist)
  • A research-style agent that delegates harder sub-questions to a second agent attached as a tool.

Not for

  • Exposing a server to untrusted users without hardening and prompt patching; several critical security advisories were published in 2026.
  • Teams that want an agent SDK without running a separate web server and database.
  • Clients that need a stable streaming contract today; the Workflow API that carries AG-UI output is still in Beta.

Quickstart

uv pip install langflow

Install not yet verified by this site. What this means

# Setup: uv venv lf && source lf/bin/activate && uv pip install langflow
#        uv run langflow run   # editor at http://127.0.0.1:7860
# In the editor: Chat Input -> Agent -> Chat Output, plus a second Agent in
# Tool Mode wired to the first Agent's Tools port. Copy the flow ID and an API key.
import os
import requests

url = "http://localhost:7860/api/v1/run/FLOW_ID"
payload = {
    "input_type": "chat",
    "output_type": "chat",
    "input_value": "Compare MCP and A2A in three bullet points.",
    "session_id": "demo-user-1",  # chat memory is grouped by session
}
headers = {"x-api-key": os.environ["LANGFLOW_API_KEY"]}
resp = requests.post(url, json=payload, headers=headers, timeout=120)
resp.raise_for_status()
print(resp.json())

Common pitfalls

  • Needs Python 3.10 to 3.14 and uv; minimum 2 CPU cores and 2 GB RAM (4 GB recommended). Startup can take a few minutes.
  • langflow includes provider extensions; langflow-base installs the same app without them, and both use the langflow command.
  • With a pip install, the default SQLite database lives inside the virtual environment, so it is not shared between environments; back it up before upgrading, or set LANGFLOW_DATABASE_URL for PostgreSQL.
  • A2A is off until LANGFLOW_A2A_ENABLED=true, and only flows saved as agent-type (Chat Input plus Chat Output) can be published; workflow-type flows return 404.
  • The v2 Workflow API (including AG-UI streaming) is in Beta and may change.
  • Keep the server patched: a 2026 advisory describes authenticated remote code execution through the MCP stdio transport, fixed in 1.9.0.

Official quickstart

Pros

  • A published flow can be called by any A2A client, and messages that share a contextId share one chat session. (source)
  • Agent-as-tool delegation needs no custom code: set a second Agent to Tool Mode and connect it. (source)
  • Per-tool approval pauses only the risky tool call, and the decision is stored in chat history. (source)
  • MIT license with pip, Docker and desktop installs for Windows and macOS. (source)
  • Chat memory works out of the box and can move to PostgreSQL or an external memory store. (source)

Cons

  • The repository's security page lists several critical and high-severity advisories published in 2026, so self-hosted servers need prompt upgrades. (source)
  • One 2026 advisory describes authenticated remote code execution through the MCP stdio transport in 1.8.3, fixed in 1.9.0. (source)
  • A2A is disabled by default and the published agent card advertises protocolVersion 0.3.0. (source)
  • The v2 Workflow API, which carries AG-UI streaming, is labelled Beta and its endpoints and responses may change. (source)
  • The default SQLite database is tied to the virtual environment for pip installs and is not shared between environments. (source)

Alternatives

FAQ

Does Langflow support MCP?

Yes, as both server and client. Each project can be served as an MCP server whose tools are its flows, and the MCP Tools component lets agents call external MCP servers.

Does Langflow support A2A and AG-UI?

Yes. Agent-type flows can be published as A2A agents and remote A2A agents can be called with the A2A Agent component, once LANGFLOW_A2A_ENABLED is set. The beta Workflow API can stream AG-UI events.

Is Langflow free?

The code is MIT-licensed and free to self-host. No official pricing page was found; the website offers sign-up for a free cloud account.

How do multiple agents work in Langflow?

A primary Agent component gets other agents as tools: switch the second Agent to Tool Mode and connect it to the primary agent's Tools port. The primary agent then decides when to call it.

What languages does Langflow use?

Langflow and its components are written in Python and can be customized in Python. A separate TypeScript client package is documented for calling the Langflow API.

Sources

Something wrong or out of date, or do you maintain Langflow and want this page removed? Report a correction or request removal.