AI KestraFlow

AI KestraFlow

Certified

Execute Kestra flows from an agent

Triggers Kestra flows as tools, either predefined (kestra_flow_<namespace>_<flowId>) or generic (kestra_flow with namespace/flowId provided by the prompt). A description is mandatory from the flow or the tool description; inputs, labels, and schedule provided by the LLM override tool defaults. Labels are not inherited unless inheritLabels=true, while the correlationId is inherited when none is supplied.

yaml
type: io.kestra.plugin.ai.tool.KestraFlow

Call a Kestra flow as a tool, explicitly defining the flow ID and namespace in the tool definition

yaml
id: agent_calling_flows_explicitly
namespace: company.ai

inputs:
  - id: use_case
    type: SELECT
    description: Your Orchestration Use Case
    defaults: Hello World
    values:
      - Business Automation
      - Business Processes
      - Data Engineering Pipeline
      - Data Warehouse and Analytics
      - Infrastructure Automation
      - Microservices and APIs
      - Hello World

tasks:
  - id: agent
    type: io.kestra.plugin.ai.agent.AIAgent
    prompt: Execute a flow that best matches the {{ inputs.use_case }} use case selected by the user
    provider:
      type: io.kestra.plugin.ai.provider.GoogleGemini
      modelName: gemini-3.5-flash-lite
      apiKey: "{{ secret('GEMINI_API_KEY') }}"
    tools:
      - type: io.kestra.plugin.ai.tool.KestraFlow
        namespace: tutorial
        flowId: business-automation
        description: Business Automation
        auth:
          apiToken: "{{ secret('KESTRA_API_TOKEN') }}"

      - type: io.kestra.plugin.ai.tool.KestraFlow
        namespace: tutorial
        flowId: business-processes
        description: Business Processes
        auth:
          apiToken: "{{ secret('KESTRA_API_TOKEN') }}"

      - type: io.kestra.plugin.ai.tool.KestraFlow
        namespace: tutorial
        flowId: data-engineering-pipeline
        description: Data Engineering Pipeline
        auth:
          apiToken: "{{ secret('KESTRA_API_TOKEN') }}"

      - type: io.kestra.plugin.ai.tool.KestraFlow
        namespace: tutorial
        flowId: dwh-and-analytics
        description: Data Warehouse and Analytics
        auth:
          apiToken: "{{ secret('KESTRA_API_TOKEN') }}"

      - type: io.kestra.plugin.ai.tool.KestraFlow
        namespace: tutorial
        flowId: file-processing
        description: File Processing
        auth:
          apiToken: "{{ secret('KESTRA_API_TOKEN') }}"

      - type: io.kestra.plugin.ai.tool.KestraFlow
        namespace: tutorial
        flowId: hello-world
        description: Hello World
        auth:
          apiToken: "{{ secret('KESTRA_API_TOKEN') }}"

      - type: io.kestra.plugin.ai.tool.KestraFlow
        namespace: tutorial
        flowId: infrastructure-automation
        description: Infrastructure Automation
        auth:
          apiToken: "{{ secret('KESTRA_API_TOKEN') }}"

      - type: io.kestra.plugin.ai.tool.KestraFlow
        namespace: tutorial
        flowId: microservices-and-apis
        description: Microservices and APIs
        auth:
          apiToken: "{{ secret('KESTRA_API_TOKEN') }}"

Call a Kestra flow as a tool, implicitly passing the flow ID and namespace in the prompt

yaml
id: agent_calling_flows_implicitly
namespace: company.ai

inputs:
  - id: use_case
    type: SELECT
    description: Your Orchestration Use Case
    defaults: Hello World
    values:
      - Business Automation
      - Business Processes
      - Data Engineering Pipeline
      - Data Warehouse and Analytics
      - Infrastructure Automation
      - Microservices and APIs
      - Hello World

tasks:
  - id: agent
    type: io.kestra.plugin.ai.agent.AIAgent
    prompt: |
      Execute a flow that best matches the {{ inputs.use_case }} use case selected by the user. Use the following mapping of use cases to flow IDs:
      - Business Automation: business-automation
      - Business Processes: business-processes
      - Data Engineering Pipeline: data-engineering-pipeline
      - Data Warehouse and Analytics: dwh-and-analytics
      - Infrastructure Automation: infrastructure-automation
      - Microservices and APIs: microservices-and-apis
      - Hello World: hello-world
      Remember that all those flows are in the tutorial namespace.
    provider:
      type: io.kestra.plugin.ai.provider.GoogleGemini
      modelName: gemini-3.5-flash-lite
      apiKey: "{{ secret('GEMINI_API_KEY') }}"
    tools:
      - type: io.kestra.plugin.ai.tool.KestraFlow
        auth:
          apiToken: "{{ secret('KESTRA_API_TOKEN') }}"

Limit an agent to explicitly allowed flows

yaml
id: agent_calling_allowed_flows
namespace: company.ai

tasks:
  - id: agent
    type: io.kestra.plugin.ai.agent.AIAgent
    prompt: Execute the hello-world flow in the tutorial namespace.
    provider:
      type: io.kestra.plugin.ai.provider.GoogleGemini
      modelName: gemini-3.5-flash-lite
      apiKey: "{{ secret('GEMINI_API_KEY') }}"
    tools:
      - type: io.kestra.plugin.ai.tool.KestraFlow
        allowedFlows:
          - namespace: tutorial
            flowId: hello-world
        auth:
          apiToken: "{{ secret('KESTRA_API_TOKEN') }}"
Properties

Allowed flows

Allowlist of exact namespace and flow ID pairs the tool may execute. Not set by default, meaning no restriction. When set, it must be non-empty and every entry must resolve to a non-blank namespace and flow ID; the permitted pairs are exposed to the model and any selection outside the list is rejected before the API is called. The restriction applies even when namespace and flowId are predefined on the tool.

Definitions
flowId*string

Allowed flow ID

Identifier of a flow the tool is permitted to execute. No default: this property is required on each allowlist entry.

namespace*string

Allowed flow namespace

Namespace of a flow the tool is permitted to execute. No default: this property is required on each allowlist entry.

API authentication

Credentials used to call the Kestra API: either an API token or HTTP Basic username/password, never both. Not set by default, in which case credentials are taken from Kestra's own configuration.

Definitions
apiTokenstring

API token

Bearer token authenticating calls to the Kestra API. Store it as a Kestra secret rather than inline. Mutually exclusive with username/password.

autobooleanstring
Defaulttrue

Auto-retrieve credentials

If true, missing credentials are taken from Kestra's own configuration when available. Defaults to true. Set it to false, with no credentials, to call a Kestra API that requires no authentication.

passwordstring

HTTP Basic password

Password paired with username for HTTP Basic authentication. Store it as a Kestra secret rather than inline. Mutually exclusive with apiToken.

usernamestring

HTTP Basic username

User authenticating against the Kestra API with HTTP Basic. Must be paired with password and is mutually exclusive with apiToken.

Tool description

Natural-language summary of what the called flow does, which the LLM uses to decide whether to call it. Not set by default: the target flow's own description is used, so this property is only needed when that flow has none, or when the flow is chosen dynamically through allowedFlows.

Flow ID

Identifier of the flow to execute. Not set by default, in which case the LLM chooses the flow, constrained by allowedFlows when it is configured.

Defaultfalse

Inherit labels from the calling execution

If true, the triggered execution inherits all labels from the agent's own execution. Defaults to false. Any label the LLM supplies still takes precedence.

Flow execution inputs

Input values passed to the triggered execution. Any input the LLM supplies overrides the value defined here. Not set by default.

Kestra API endpoint

Base URL used for calls to the Kestra API. Not set by default, in which case {{ kestra.url }} is rendered from configuration, falling back to http://localhost: 8080.

Flow execution labels

Labels added to the triggered execution. Any label the LLM supplies overrides the value defined here. Not set by default.

Flow namespace

Namespace of the flow to execute. Not set by default, in which case the LLM chooses the namespace, constrained by allowedFlows when it is configured.

Flow revision

Specific revision of the flow to execute. Not set by default, in which case the latest revision runs.

Scheduled execution date

Date and time at which the execution should start, rather than immediately. Not set by default (immediate execution). A scheduleDate supplied by the LLM overrides this value.

Target tenant

Tenant the API calls are made against. Defaults to the tenant of the current execution.