| name | raw-app |
| description | MUST use when creating raw apps. |
Windmill Raw Apps โ CLI workflow
This guide covers raw apps from the terminal: scaffolding via wmill app new, the on-disk layout, and the file-based conventions the CLI uses to represent backend runnables and data table configuration. The platform shape (how a raw app behaves at runtime โ frontend bundling, runnable types, datatable SDK calls) is covered in the companion authoring guide.
Creating a Raw App
You โ the AI agent โ create the app yourself by running wmill app new with the right flags. Do NOT tell the user to "run wmill app new and follow the prompts" or wait for them to do it. The bare wmill app new is an interactive wizard that hangs waiting for stdin in any non-TTY context (which includes you). Always pass flags.
Step 1 โ Gather the three required values by asking the user
You need three things to run the command:
- summary โ a short description of the app
- path โ the windmill path, e.g.
f/folder/my_app or u/username/my_app
- framework โ one of
react19 (recommended), react18, svelte5, vue
If the user's request did not supply every one of these explicitly, ask. Do not guess values, do not invent paths, do not pick a framework on the user's behalf, do not "just use react19 because it's the default".
Use whichever interactive question facility your runtime provides โ a structured multi-choice tool if available, otherwise plain chat โ and group all missing fields into a single round-trip so the user answers them at once:
- For
framework โ multiple-choice with the four allowed values; mark react19 as (Recommended) and put it first.
- For
summary and path โ provide one or two example values as multiple-choice options (the user can pick "Other" to type a free-form answer).
Only proceed once you have concrete values for all three. If the user replies with something ambiguous, ask again rather than guessing.
Step 2 โ Run the command yourself
Once you have summary + path + framework, run it:
wmill app new \
--summary "Customer dashboard" \
--path f/sales/dashboard \
--framework react19
That's the minimum. The datatable wizard and the "Open in Claude Desktop?" prompt are skipped silently because passing any of --summary/--path/--framework puts the command in non-interactive mode.
Optional flags
Layer these in only when the user asked for them:
| Flag | When to add it |
|---|
--datatable <name> | The user wants this app wired to a specific Windmill datatable. Without it, the app is created with no datatable. |
--schema <name> | Together with --datatable. Creates the schema with CREATE SCHEMA IF NOT EXISTS if it doesn't already exist. |
--overwrite | The target directory already exists and the user said it's OK to replace. Without it, non-interactive mode aborts with an error so you don't clobber existing work. |
--no-open-in-desktop | Already implied in non-interactive mode; only needed if you're somehow running interactively. |
Step 3 โ Offer the visual preview
After wmill app new and any initial edits to App.tsx / index.tsx, offer to open the visual preview as a one-sentence next step (e.g. "Want me to open the visual preview?"). Don't auto-open โ opening the dev page has side effects (browser window, possibly a launch.json entry when an embedded preview tool is in play) the user should consent to.
For apps the preview command runs from the app folder (cd <app_path>__raw_app && wmill app dev โฆ); the preview skill picks the proxy vs direct branch based on whether the runtime exposes a tool that can embed a localhost URL. If the user already asked to see/preview/visualize the app in their original request, skip the offer and just invoke the skill.
Anti-patterns to avoid
- โ Running
wmill app new with no flags (the prompt will hang).
- โ Telling the user to "run
wmill app new and follow the prompts" โ that's a step backwards from what you can do directly.
- โ Inventing a path/summary/framework instead of asking the user.
- โ Defaulting to
react19 because the user didn't say โ even sensible defaults must be confirmed.
- โ Passing
--overwrite automatically when the directory exists โ confirm with the user first.
Interactive (only when a human is at the terminal)
wmill app new
This is the wizard. It only works when run by a human in a real terminal. Don't call it this way from an agent.
On-disk app layout
my_app__raw_app/
โโโ AGENTS.md # AI agent instructions (auto-generated)
โโโ DATATABLES.md # Database schemas (run 'wmill app generate-agents' to refresh)
โโโ raw_app.yaml # App configuration (summary, path, data settings)
โโโ index.tsx # Frontend entry point
โโโ App.tsx # Main React/Svelte/Vue component
โโโ index.css # Styles
โโโ package.json # Frontend dependencies
โโโ wmill.ts # Auto-generated backend type definitions (DO NOT EDIT)
โโโ backend/ # Backend runnables (server-side scripts)
โ โโโ <id>.<ext> # Code file (e.g., get_user.ts)
โ โโโ <id>.yaml # Optional: config for fields, or to reference existing scripts
โ โโโ <id>.lock # Lock file (run 'wmill generate-metadata' to create/update)
โโโ sql_to_apply/ # SQL migrations (dev only, not synced)
โโโ *.sql # SQL files to apply via dev server
Backend runnables on disk
Add a code file to the backend/ folder:
backend/<id>.<ext>
The runnable ID is the filename without extension. For example, get_user.ts creates a runnable with ID get_user.
Supported languages (extension-driven)
| Language | Extension | Example |
|---|
| TypeScript | .ts | myFunc.ts |
| TypeScript (Bun) | .bun.ts | myFunc.bun.ts |
| TypeScript (Deno) | .deno.ts | myFunc.deno.ts |
| Python | .py | myFunc.py |
| Go | .go | myFunc.go |
| Bash | .sh | myFunc.sh |
| PowerShell | .ps1 | myFunc.ps1 |
| PostgreSQL | .pg.sql | myFunc.pg.sql |
| MySQL | .my.sql | myFunc.my.sql |
| BigQuery | .bq.sql | myFunc.bq.sql |
| Snowflake | .sf.sql | myFunc.sf.sql |
| MS SQL | .ms.sql | myFunc.ms.sql |
| GraphQL | .gql | myFunc.gql |
| PHP | .php | myFunc.php |
| Rust | .rs | myFunc.rs |
| C# | .cs | myFunc.cs |
| Java | .java | myFunc.java |
After creating or editing a backend runnable โ especially when its imports or arguments changed โ its local lock and wmill-lock.yaml go stale. Offer to run wmill generate-metadata and run it once the user agrees (or automatically if the project's AGENTS.md opts into that) โ YOU run it, don't just name it and wait. It writes local files only (not a deploy), and keeping the lock current avoids noise in git-sync/CI:
wmill generate-metadata
After it runs, check the regenerated .lock diff and tell the user which dependency versions changed (e.g. requests 2.31.0 โ 2.32.0), so they can catch an unwanted bump before deploying.
Optional YAML configuration
Add a <id>.yaml file alongside the code to configure fields or static values:
backend/get_user.yaml:
type: inline
fields:
user_id:
type: static
value: "default_user"
Referencing existing scripts
To use an existing Windmill script instead of inline code:
backend/existing_script.yaml:
type: script
path: f/my_folder/existing_script
For flows:
type: flow
path: f/my_folder/my_flow
Data tables โ raw_app.yaml config
The data block in raw_app.yaml controls which tables the app can query.
data:
datatable: main
schema: app_schema
tables:
- main/users
- main/app_schema:items
Table reference formats:
<datatable> โ All tables in the datatable
<datatable>/<table> โ Specific table in public schema
<datatable>/<schema>:<table> โ Table in specific schema
SQL Migrations (sql_to_apply/)
The sql_to_apply/ folder is for creating/modifying database tables during development.
Workflow
- Create
.sql files in sql_to_apply/
- Run
wmill app dev โ the dev server watches this folder
- When SQL files change, a modal appears in the browser to confirm execution
- After creating tables, add them to
data.tables in raw_app.yaml
Example migration
sql_to_apply/001_create_users.sql:
CREATE TABLE IF NOT EXISTS users (
id SERIAL PRIMARY KEY,
email TEXT NOT NULL UNIQUE,
name TEXT,
created_at TIMESTAMP DEFAULT NOW()
);
After applying, add to raw_app.yaml:
data:
tables:
- main/users
Migration best practices
- Use idempotent SQL:
CREATE TABLE IF NOT EXISTS, etc.
- Number files:
001_, 002_ for ordering
- Always whitelist tables after creation
- This folder is NOT synced โ it's for local development only
CLI Commands
Two commands you run yourself, not the user:
wmill app new โ run it with flags, per the "Creating a Raw App" section above.
wmill generate-metadata โ (re)generates local lock files and refreshes wmill-lock.yaml content hashes; writes local files only (not a deploy). After adding or editing a runnable, offer it and run it on agreement โ or automatically if the project's AGENTS.md opts into that (see "After creating a runnable" above).
For the rest, tell the user which command fits their intent and let them run it โ these deploy to the workspace, overwrite local files, or launch a long-running server, so the user should consent each time:
| Command | Description |
|---|
wmill app dev | Start dev server with live reload (see the preview skill for the full open-the-app-in-the-IDE-pane procedure). |
wmill app generate-agents | Refresh AGENTS.md and DATATABLES.md |
wmill sync push | Deploy app to Windmill |
wmill sync pull | Pull latest from Windmill |
Windmill Raw Apps
Raw apps let you build custom frontends with React, Svelte, or Vue that connect to Windmill backend runnables and datatables.
App shape
A raw app has three logical parts:
- Frontend โ bundled with esbuild from
index.tsx as the entrypoint. Files include the entrypoint, components (App.tsx), styles, etc.
- Backend runnables โ server-side scripts the frontend calls, each addressed by a unique key.
- Data โ optional whitelisted datatables (managed PostgreSQL) that the backend runnables can query. The frontend never queries the database directly; backend runnables are the only bridge.
Frontend
Entrypoint
The entrypoint is index.tsx for React and index.ts for Svelte and Vue. It is both the bundling entrypoint (the bundler is esbuild) and the mount entrypoint: the preview executes the bundle against an empty <div id="root"> and auto-renders nothing, so the entrypoint must mount a top-level App itself. Keep the UI in App.tsx / App.svelte / App.vue and keep the entrypoint as the mount shim.
React (index.tsx):
import React from 'react'
import { createRoot } from 'react-dom/client'
import App from './App'
createRoot(document.getElementById('root')!).render(<App />)
Svelte (index.ts): mount(App, { target: document.getElementById('root')! }). Vue (index.ts): createApp(App).mount('#root').
Never replace the entrypoint with a bare component (export default function App() { ... } and no mount call). A component that is defined but never mounted renders a blank screen with no error thrown โ it never executes, so nothing reaches the console or the error overlay. If an app renders blank, check that the entrypoint still mounts App into #root.
Always begin every React file (.tsx/.jsx) that uses JSX with import React from 'react'. esbuild uses the classic JSX transform, so React must be in scope wherever JSX appears โ a missing import compiles fine but throws React is not defined at runtime, leaving a blank screen.
Generated bindings (wmill.d.ts / wmill.ts)
The frontend imports a generated module that mirrors the backend runnables. Never write to it directly โ it gets regenerated whenever backend runnables change. Modifying it by hand will be overwritten.
Calling backend runnables
Import the generated bindings and call the runnable like a function:
import { backend } from './wmill';
const user = await backend.get_user({ user_id: '123' });
The frontend cannot reach datatables, workspace items, or external services on its own โ it goes through backend.<key>(args) for everything server-side.
Keeping data out of recorded demos
An app can be demoed by recording a session: every interaction becomes a step carrying a snapshot of the page, replayed publicly or on the Hub. Password inputs are masked automatically. Mark anything else that must not appear with data-wm-no-record โ the whole marked subtree is dropped from every snapshot, along with its values and the step's own metadata:
<label data-wm-no-record>
Customer SSN <input value={ssn} onChange={onSsn} />
</label>
Apply it to customer data, internal notes and anything else a viewer of the demo should not see. It costs nothing when the app is never recorded.
Backend runnables
Each runnable has a unique key (used to call it from the frontend) and one of four types:
| Type | What it is |
|---|
inline | Custom code stored on the app itself. Most common for app-specific logic. |
script | Reference to an existing workspace script by path. |
flow | Reference to an existing workspace flow by path. |
hubscript | Reference to a hub script by path. |
Inline runnables
Inline runnables carry their own source code. For file-based raw apps, the runnable language is determined by the backend file extension. The script must expose a main function as its entrypoint.
TypeScript example (backend/get_user.ts):
import * as wmill from 'windmill-client';
export async function main(user_id: string) {
const sql = wmill.datatable();
const user = await sql`SELECT * FROM users WHERE id = ${user_id}`.fetchOne();
return user;
}
Python example (backend/get_user.py):
import wmill
def main(user_id: str):
db = wmill.datatable()
user = db.query('SELECT * FROM users WHERE id = $1', user_id).fetch_one()
return user
Path runnables (script / flow / hubscript)
When type is script, flow, or hubscript, the runnable just stores a path to an existing workspace or hub item โ no inline code. The referenced item's input/output schema becomes the runnable's surface.
Static inputs
staticInputs is an optional Record<string, any> for arguments not overridable from the frontend. Useful with path runnables to pre-fill some args while leaving the rest to the frontend caller.
Data Tables
Data tables are PostgreSQL databases managed by Windmill. Backend runnables query them via the wmill client; the frontend never queries them directly.
Critical rules
- Whitelisted tables only: a runnable can only query tables listed in the app's
data.tables config. Tables not in this list are not accessible.
- Add tables before using: queries against unlisted tables fail at runtime. When you introduce a new table, register it in
data.tables first.
- Use the configured datatable/schema: the app's
data config sets the default datatable and schema; reference them consistently across runnables.
Querying in TypeScript (Bun/Deno)
import * as wmill from 'windmill-client';
export async function main(user_id: string) {
const sql = wmill.datatable();
const user = await sql`SELECT * FROM users WHERE id = ${user_id}`.fetchOne();
const users = await sql`SELECT * FROM users WHERE active = ${true}`.fetch();
await sql`INSERT INTO users (name, email) VALUES (${name}, ${email})`;
await sql`UPDATE users SET name = ${newName} WHERE id = ${user_id}`;
return user;
}
Querying in Python
import wmill
def main(user_id: str):
db = wmill.datatable()
user = db.query('SELECT * FROM users WHERE id = $1', user_id).fetch_one()
users = db.query('SELECT * FROM users WHERE active = $1', True).fetch()
db.query('INSERT INTO users (name, email) VALUES ($1, $2)', name, email)
db.query('UPDATE users SET name = $1 WHERE id = $2', new_name, user_id)
return user
Best Practices
- Check existing tables before creating new ones โ reuse beats schema growth.
- Use parameterized queries โ never concatenate user input into SQL.
- Keep runnables focused โ one function per runnable; small surface area.
- Use descriptive keys โ
get_user, not a.
- Always whitelist tables โ adding a runnable that queries a new table requires the table to be in
data.tables first.
- Mark sensitive UI with
data-wm-no-record โ it is what keeps that data out of a recorded demo; passwords are handled for you.