Windmill HR MCP server icon

Windmill HR

by Windmill HR

HIPAA CompliantSOC2 ReadyISO 27001 Ready
Productivity64 tools

Query performance review cycles, feedback, 1:1s and pulse surveys from an AI assistant. 64 tools over employee and personnel data, OAuth sign-in, and every call scoped to the signed-in user's Windmill permissions.

Verified connector

Listed by Anthropic as a partner connector in its Connectors Directory.

Connection checked by Agentman on .

Anthropic states this reflects the level of review a connector received, not a security audit.

Connect Windmill HR via MCP

https://mcp.gowindmill.com/mcp

Works in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.

Use in Agentman

Connect Windmill HR once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.

Open in Agentman Studio

Windmill HR Tools & Capabilities (64)

employees_count
employees_groups_load
employees_query
employees_update
feedback_create
feedback_delete
feedback_edit
feedback_load_visibility_setting
feedback_query
feedback_requests_cancel
feedback_requests_create
feedback_requests_query
feedback_shoutouts_load_config
help_center_page_load
help_center_search
load_resources
members_count
members_invite
members_query
ona_collaborators_top_query
one-on-one-events_next
one-on-one-events_query
one-on-ones_calendar_query
one-on-ones_create
one-on-ones_event_confirm
one-on-ones_event_remove
one-on-ones_notes_load
one-on-ones_notes_update
one-on-ones_query
one-on-ones_series_remove
performance-reviews_cycle_admin_todo_status_query
performance-reviews_cycles_load
performance-reviews_cycles_query
performance-reviews_employees_query
performance-reviews_manager_review_context_load
performance-reviews_my_todos_load
performance-reviews_reviews_query
private_notes_count
private_notes_create
private_notes_delete
private_notes_load
private_notes_query
private_notes_update
pulse_answers_load
pulse_answers_save
pulse_create
pulse_employee_runs_count
pulse_employee_runs_query
pulse_employees_query
pulse_owner_add
pulse_owner_remove
pulse_owner_update
pulse_query
pulse_runs_query
pulse_send_now
pulse_send_nudge
pulse_test
pulse_update
query_resources
stats_employee_data_counts
stats_metadata
stats_query
weekly_recaps_query
whoami

Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.

Limits

  • Performance reviews cannot be written. Windmill records drafting, submitting and nudging on reviews as unavailable through the public MCP. Seven review tools all read.
  • Members cannot be removed. members_invite adds a person; Windmill states removing a member is not available through the public MCP.
  • Private notes reach only your own. Windmill's MCP matrix states you can access only your own private notes through the connector.
  • No application OAuth scope. offline_access is the only advertised scope, so there is no read-only connection to approve. Access is limited by your Windmill account instead.
  • No consent-screen narrowing, and no admin kill switch documented. Windmill's documentation describes revoking a connector as a way to end a session, but publishes no per-tool or per-family admin control over what a connected user's assistant can call.
  • Data leaves Windmill on every answer. Windmill states data returned passes through the connected AI tool's model so it can generate a response, and advises using tools that meet your company's privacy and security requirements.
  • The connection does not expire. There is no scheduled re-authentication; the refresh token rotates indefinitely until the server is removed, the connector revoked, or the session invalidated by an admin.
  • Seats are billed on provisioning, not usage. Windmill's standard plan includes 10 free seats and charges $10 per additional seat per month; an invited member counts even if they never log in, and archiving mid-cycle produces no refund.
  • Organizational Health has no partial view. The collaboration graph behind ona_collaborators_top_query is documented as available only to Workspace Admins and Data Analysts, with no manager-limited version of the report.
  • History starts when you connect. Windmill states reviews and 1:1s collect data on a go-forward basis from when a system was connected, so the connector cannot reach what predates the integration.
  • Retention is engagement-linked. Windmill retains customer data for the life of the engagement and offers deletion on request after it ends; it publishes no fixed retention window.
  • We could not read tool schemas or safety annotations. The endpoint is OAuth-gated. Tool names come from Anthropic's directory; every behaviour claim comes from Windmill's documentation.

Frequently asked questions

No. Windmill states the MCP server acts as the signed-in user, so role-based access, org-chart scoping, connected-source permissions and feature privacy rules all apply. Its documented example is an Engineering manager being refused People Team review results. Review visibility stays with the management chain and cycle admins.

No. Windmill's MCP documentation records performance reviews as read-only over the connector: cycles, participants, reviews, todos and manager-review context can be read, and nothing can be changed. Drafting reviews, submitting them and sending performance-review nudges are all listed as unavailable through the public MCP.

No. Windmill's visibility rules state the subject of a piece of feedback never reads it, regardless of role. Peer and upward feedback about you stay hidden permanently; a manager review reaches you only when your manager shares it. Windmill records that cycle admins get no exception.

Only you. Windmill documents private notes as visible solely to their author and never shared with the people they are about. The MCP page repeats the boundary for the connector, listing private notes as an area where you can access only your own. Six tools read and write that personal set.

Never on a schedule. Windmill states an MCP connection has no time-based expiry, because the OAuth refresh token rotates silently in the background. You re-authenticate only if you remove and re-add the server, revoke the connector, or an admin signs you out. Dashboard logins expire after about seven days.

Yes. Windmill's documentation states each person adds the connector and authenticates with their own Windmill account, and that MCP access uses your individual account. There is no workspace-wide install that connects colleagues on your behalf, so each person's connection carries only their own permissions.

Sources

  • Windmill MCP documentation — https://help.gowindmill.com/features/mcp (retrieved 2026-09-08). Endpoint, per-client setup, the read/change/limits matrix, authentication and permissions, and seven vendor FAQs. · retrieved 2026-09-08
  • Windmill permissions and access — https://help.gowindmill.com/permissions-and-access (retrieved 2026-09-08). Five roles and their capability matrix, org-chart scope, access delegation and its limits, 1:1 auditability, connected-system permissions. · retrieved 2026-09-08
  • Windmill performance review visibility — https://help.gowindmill.com/features/performance-reviews/visibility (retrieved 2026-09-08). The subject-cannot-read rule, cycle admin scoping, calibration access, sharing behaviour. · retrieved 2026-09-08
  • Windmill feedback — https://help.gowindmill.com/features/continuous-feedback (retrieved 2026-09-08). Feedback types, default visibility, and the giver's inability to choose an audience. · retrieved 2026-09-08
  • Windmill private notes — https://help.gowindmill.com/features/private-notes (retrieved 2026-09-08). Author-only visibility and the writing-aid boundary in review drafting. · retrieved 2026-09-08
  • Windmill data privacy and collection — https://help.gowindmill.com/security/data-privacy (retrieved 2026-09-08). HRIS fields collected and explicitly not collected, admin visibility, historical data, retention. · retrieved 2026-09-08
  • Windmill Organizational Health — https://help.gowindmill.com/features/analytics/organizational-health (retrieved 2026-09-08). ONA report access limited to Workspace Admins and Data Analysts. · retrieved 2026-09-08
  • Windmill pricing — https://help.gowindmill.com/getting-started/pricing (retrieved 2026-09-08). Free-seat allowance, $10 per seat per month, provisioning-based billing. · retrieved 2026-09-08
  • Windmill documentation index — https://help.gowindmill.com/llms.txt (retrieved 2026-09-08). The machine-readable page map that resolved the directory's bare help-centre URL to the MCP page. · retrieved 2026-09-08
  • Live OAuth probe of https://mcp.gowindmill.com/mcp — 2026-09-08. Anonymous initialize and tools/list both returned HTTP 401 with a WWW-Authenticate: Bearer challenge; the RFC 9728 protected-resource descriptor and the authorization-server metadata at api.gowindmill.com both returned HTTP 200. No tool was called and no credential was supplied. · retrieved 2026-09-08
  • Anthropic connector directory snapshot — https://claude.ai/directory/9af5c0c8-b270-4457-851e-196b591e43b1 (snapshot dated 2026-09-08). The 64 tool names, partner tier, endpoint, transport, categories. · retrieved 2026-09-08
  • help.gowindmill.com/robots.txt (retrieved 2026-09-08) carries a Content-Signal line setting ai-train=yes, search=yes and ai-input=yes, and gowindmill.com/robots.txt carries the same three values — synthesis of this publisher's content is expressly permitted. · retrieved 2026-09-08

Server Info

Category
Productivity
Developer
Windmill HR
Tools
64
Domain
mcp.gowindmill.com

Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.

Ready to connect Windmill HR?

Connect Windmill HR once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.