Skip to content
Last updated

Go Windmill integration

Go Windmill is an AI-powered performance management platform for performance reviews, one-on-one meetings, pulse surveys, and feedback.

Agen.co connects to Go Windmill through Go Windmill's own hosted MCP server as an Official connector. Each user signs in with their own Go Windmill account, and every action runs with that account's existing permissions. There is no OAuth client ID or secret to copy, but Go Windmill must allow Agen.co's callback URLs before you can connect.

Not the Windmill workflow platform

Go Windmill (gowindmill.com) is a different product from Windmill (windmill.dev), the open-source workflow engine. Each has its own connector in the Agen.co catalog — pick the one that matches the product you use.


Prerequisites

  • A Go Windmill account for each person whose agents will use the connector.
  • Go Windmill must trust Agen.co's callback URLs. Go Windmill only accepts loopback and trusted third-party redirect URLs, and only Go Windmill can add yours — see the steps below.

What you see until the callback URLs are trusted

Go Windmill must trust both callback URLs, and each one fails differently:

  • If the Callback URL is not trusted, Connect fails straight away with an error and no Go Windmill tab opens. Behind the error, Go Windmill rejects the registration with invalid_redirect_uri — "only loopback redirect URIs and trusted third party URIs are allowed".
  • If only the Gateway callback URL is missing, Connect and Add still succeed. The failure appears later: the first tool call from a user fails, because the MCP gateway registers its own client with the gateway callback URL and Go Windmill rejects that registration.

The callback URLs are specific to your Agen.co environment, so you request this once per environment.

Get the callback URLs from Agen.co

  1. In the Agen.co portal, go to Connectors → My connectors and click Add connector.
  2. In the Select connector drawer, search for Go Windmill and select it. The Add Go Windmill panel opens.
  3. Copy both read-only URLs shown in the panel:
    • Callback URL — completes the initial OAuth handshake between Agen.co and Go Windmill.
    • Gateway callback URL — used by the Agen.co MCP gateway for per-user authorization at runtime.

Ask Go Windmill to trust the callback URLs

Contact Go Windmill support, send both URLs, and ask for them to be added as trusted redirect URLs for the Go Windmill MCP server. Wait for Go Windmill's confirmation before you continue.

Connect Go Windmill in Agen.co

Return to the Add Go Windmill panel (reopen it if you closed it) and fill in the field:

FieldRequiredDescription
Instance SlugYesNamespaces this instance — it prefixes each imported tool as slug__tool, so several instances of the same MCP can coexist. Prefilled with gowindmill. Use lowercase kebab-case. You can change it later from the connector's settings.
Callback URL—Read-only. Send it to Go Windmill to trust (see above).
Gateway callback URL—Read-only. Send it to Go Windmill to trust as well (see above) — the MCP gateway uses it for per-user authorization at runtime.
  1. Click Connect. Go Windmill opens in a new tab, and the panel shows Waiting for authorization — complete it in the opened tab…
  2. Sign in to Go Windmill and approve access.
  3. Back in Agen.co, the panel switches to Select the tools to import from Go Windmill. Every tool is toggled on; turn off any you don't want to import, then click Add.

The connector is created and its tools imported only when you click Add. If you close the panel before that, nothing is saved, even if the Go Windmill tab reported success.

What it covers

Everything runs through the signed-in user's Go Windmill account: if the user cannot see something in Go Windmill, agents cannot reach it either. According to Go Windmill's MCP documentation (checked 2026-10-07):

AreaWhat it covers
Employees and org chartRead employees and the org chart, and update supported employee information
One-on-onesRead meeting series, agendas, and notes; create, update, and manage meetings
Pulse surveysRead results; create, test, send, and manage surveys
Performance reviewsRead cycles, reviews, and context. Submitting reviews is not available
Feedback and shoutoutsRead your feedback; create, edit, and delete your own feedback; give shoutouts
Workspace membersView members and invite new ones. Removing members is not supported
Private notesRead and write your own notes only

Feedback request tools require the Feedback page to be enabled in Go Windmill. Go Windmill does not publish a tool list and keeps it behind sign-in, so the areas above are unverified; the tool selection screen after Connect shows exactly what your account serves.

Enabling the Go Windmill connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.

Additional resources