About Langflow 1.12.1 — Visual Builder for AI Agents and Workflows
Langflow is a visual builder for AI agents and workflows. You drag components onto a canvas, wire them together, test the result in a playground, and then call it from your own code as an API or expose it to other AI tools as an MCP server. It is written in Python, released under the MIT licence, and very actively developed.
This page links to the 1.12.1 release on GitHub: the source archive of the tag and the two Python wheels attached to it. Bineret did not build Langflow and is not affiliated with it.
What it does
- Visual builder. Flows are built on a canvas from components for models, prompts, tools, vector stores, memory and data sources.
- Code when you need it. Every component’s Python source is open to edit, so you are not stuck when the built-in component does nearly what you want.
- Playground. Run a flow step by step and see what each component produced.
- Agents. Multi-agent orchestration with conversation management and retrieval.
- Deploy it. Each flow is callable as an API, can be exported as JSON for Python apps, and can be served as an MCP server so MCP clients can use flows as tools.
- Observability. Integrations with LangSmith, Langfuse and others, and in 1.12 export of application telemetry to any OTLP backend.
Know what you are downloading
Langflow’s own recommended install is not a download at all. It is a Python package, installed with uv pip install langflow. The files on this page are what the GitHub release carries:
- the source archive of the
v1.12.1tag, 134 MB and 10,262 files, which is what you want to read, audit or build from; langflow_base-1.12.1-py3-none-any.whl, 17.6 MB, the application itself;langflow-1.12.1-py3-none-any.whl, a 5.5 KB wheel that pulls in the rest.
The wheels still fetch their dependencies from PyPI when installed, so they are not an offline installer. For a desktop app with everything bundled, Langflow publishes Langflow Desktop for Windows and macOS on its own website, not in this GitHub release.
Requirements
Python 3.10 to 3.14, and uv is the package manager the project recommends. Once running, Langflow listens on http://127.0.0.1:7860. There is also an official Docker image, langflowai/langflow, on the same port. The models are separate: an API key for a hosted provider, or a local model server.
What 1.12 changed
1.12.0, released on 1 September 2026, is a large release. It adds role-based authorization and groundwork for single sign-on, and removes the admin page from the open-source build. Knowledge bases can use pgvector. Code-execution components can run inside an opt-in microVM sandbox. Telemetry can go to any OTLP backend, and the built-in Langflow Assistant got better at building flows. 1.12.1 followed on 8 September with bug fixes.
Treat it like a code runner, because it is one
Flows run Python, and editable components mean anyone who can edit a flow can run code on the machine hosting Langflow. Earlier versions also had serious vulnerabilities: CVE-2025-3248 let unauthenticated users execute code in Langflow before 1.3.0. Keep it updated, do not expose it to the internet without authentication in front of it, and read the project’s security policy and authentication settings before sharing an instance.
When to use something else
If you want to write agents in plain code, a visual builder adds a layer you may not need. If you want a chat app for a team rather than a workflow builder, LibreChat fits better. If a single person wants to chat with their own documents on a desktop, a document-chat app is less to set up than a flow.
Key capabilities
A canvas, with the code open
Build flows by connecting components for models, prompts, tools, memory and vector stores. When a component nearly fits, open its Python source and change it rather than working around it.
Flows become tools
A finished flow can be called as an API from your own code, exported as JSON for Python apps, or served as an MCP server so other AI clients can use it as a tool.
What 1.12 brought
Role-based authorization and single sign-on groundwork, pgvector for knowledge bases, an opt-in microVM sandbox for code-execution components, and telemetry export to any OTLP backend. It also removed the open-source admin page.
A code runner, so guard it
Flows run Python, so anyone who can edit one can run code on the host. Versions before 1.3.0 had an unauthenticated code-execution flaw, CVE-2025-3248. Keep it updated and never expose it without authentication.
Not really a download
The recommended install is uv pip install langflow. The release carries a 134 MB source archive and two wheels that still fetch dependencies from PyPI. Langflow Desktop, with everything bundled, comes from Langflow's website.
Questions & Answers
Is Langflow free?
Yes. It is MIT licensed, including commercial use. The model providers you connect bill you separately.
Which file do I need?
Probably none of them: uv pip install langflow is the recommended install. The source archive is for reading, auditing or building from source; the wheels install this exact version, but still download dependencies from PyPI.
Is there a desktop app?
Langflow Desktop for Windows and macOS bundles everything, so there is no Python to manage. Langflow distributes it from its own website, not from this GitHub release.
Can I call a flow from my own application?
Yes. Every flow is available as an API, can be exported as JSON for Python apps, and can be served as an MCP server so MCP clients can use it as a tool.
Can it use local models?
Yes, through components for local model servers, alongside the hosted providers. Check the component list in your version for the exact options.
Is it safe to put on a server?
Only with care. Flows run Python by design. Langflow before 1.3.0 had an unauthenticated remote code execution flaw, CVE-2025-3248. Stay on current releases, require authentication, and do not expose it publicly.
What happened to the admin page in 1.12?
1.12.0 removed the admin page from the open-source build, as part of the work adding role-based authorization and single sign-on foundations. If you relied on it, read the 1.12.0 release notes before upgrading.
Is Bineret connected to Langflow?
No. This page describes Langflow and links to files on the project's GitHub release.
Tutorials
Install with uv (the project's recommended route)
You need Python 3.10 to 3.14 and uv. From a fresh directory:
uv pip install langflow==1.12.1
uv run langflow run
Langflow starts at http://127.0.0.1:7860. Drop ==1.12.1 to get whatever is newest instead.
Install from the wheels on this page
Download both wheels into one folder, then install them together. Their dependencies still come from PyPI, so this needs an internet connection.
uv pip install ./langflow_base-1.12.1-py3-none-any.whl ./langflow-1.12.1-py3-none-any.whl
uv run langflow run
Run with Docker
docker run -p 7860:7860 langflowai/langflow:1.12.1
Then open http://localhost:7860. The README uses the latest tag; pinning the version keeps what you run matched to this page.
Run from the source archive
Unzip langflow-1.12.1.zip and, from the repository root:
make run_cli
DEVELOPMENT.md in the archive covers the full development setup.
Build your first flow
Start from a template or an empty flow, add a model component and paste in your provider's API key, connect a chat input and output, and open the Playground to try it. When it works, the API panel for the flow shows the request to call it from your own code.
Before you share an instance
Anyone who can edit a flow can run Python on the host. Set up authentication as described in Langflow's documentation, keep it behind a reverse proxy with TLS, and never leave an instance open to the internet.
Support
Where support comes from
Langflow is maintained by its core team and contributors. Start with the documentation, report bugs as GitHub issues, and follow the security policy for vulnerabilities rather than filing them publicly.
What Bineret covers
This page. If a download link is broken or something written here is wrong, tell us and we will fix it. We do not host, install or build flows for Langflow.
No warranty
The MIT licence provides the software as-is. Releases arrive often; read the notes before upgrading, since 1.12.0 alone changed authorization and removed a page from the open-source build.