Skip to main content

OPC UA Client and Server

Using the FlowFuse Certified Node for OPC UA, connect to any OPC UA server as a client, or host your own server on self-hosted FlowFuse. Bridge structured, secured industrial data to Modbus, EtherNet/IP, MQTT, historians, and the cloud, all from one canvas.

Industrial engineer building an OPC UA flow with FlowFuse on a laptop

What is OPC UA?

OPC UA (OPC Unified Architecture) is the modern, platform-independent standard for exchanging data between industrial equipment, applications, and enterprise systems. Where a protocol like Modbus moves raw register values, OPC UA exposes a structured information model, an address space of typed objects and relationships, with security built into the spec rather than bolted on.

FlowFuse connects to OPC UA through a dedicated Certified Node, then bridges that data to Modbus, EtherNet/IP, MQTT, or a historian without a separate gateway. If you're integrating directly with PLC hardware across multiple protocols, the FlowFuse PLC integration covers that broader case.

What is an OPC UA Client?

An OPC UA client is the application that connects to a server to browse, read, write, and subscribe to data. That source might be a PLC, a historian, or any other software exposing its own OPC UA server.

FlowFuse acts as a client on any deployment, cloud or self-hosted, connecting to any third-party OPC UA server without restriction.

What is an OPC UA Server?

An OPC UA server exposes data as a browsable information model that other applications connect to. It's the source side of the relationship: a PLC, historian, or gateway that other software queries.

FlowFuse can host its own OPC UA server, exposing a curated information model built from any connected data source, in the same runtime as its client.

Backed by a FlowFuse Certified Node

FlowFuse connects to OPC UA through a FlowFuse Certified Node built on node-opcua and maintained by Sterfive, the team behind that open-source stack. Certified Nodes are vetted for quality, security, and ongoing support, unlike community packages, which can go unmaintained without warning.

One node handles both directions: connect to third-party OPC UA servers as a client, or host your own server on self-hosted FlowFuse (not available on FlowFuse Cloud). Both sides share a single certificate store, so a trust decision made for one applies to the other. The node ships through the FlowFuse Edge Certified Nodes catalogue, contact us to enable it for your instance.

OPC UA is one protocol. FlowFuse bridges all of them.

Real plants are never one protocol. OPC UA on the new line, Modbus on the legacy skid, EtherNet/IP on the Allen-Bradley cell, a camera feed nobody's touched since commissioning. FlowFuse runs them all together, so bridging data between them is a wire between nodes rather than a separate integration project.

Modbus

TCP, UDP, and Serial (RTU/ASCII), running right next to your OPC UA connections. Read and write coils and registers, or simulate a server for testing.

Modbus Certified Node

EtherNet/IP (CIP)

Native Rockwell and Allen-Bradley connectivity: ControlLogix, CompactLogix, Micro800, SLC500, and other CIP-capable devices, normalized into the same data model as your OPC UA connection.

CIP Suite Certified Node

RTSP Video

Turn factory-floor camera feeds into images your flow can act on. Join a frame with the OPC UA values read at that instant, so a quality event is recorded with both the picture and the process conditions behind it.

RTSP Certified Node

Siemens S7

Direct S7comm connectivity to S7-300, S7-400, S7-1200, and S7-1500 PLCs, for the many Siemens deployments that predate an OPC UA server.

Siemens S7 integration guide

MQTT

Publish OPC UA, Modbus, or S7 data to any MQTT broker, normalized into a Unified Namespace topic hierarchy on the way.

Bridging OPC UA to MQTT

5,000+ Community Nodes

Beyond the certified set: PROFINET, BACnet, DNP3, IEC 61850, Mitsubishi MC Protocol, Omron FINS, Beckhoff TwinCAT ADS, and more, wired in beside your OPC UA flow.

Browse the node library

Modbus, EtherNet/IP, and RTSP ship as FlowFuse Certified Nodes through the FlowFuse Edge catalogue. Everything else is a free, open-source community node or built into core Node-RED.

Built for enterprise OPC UA deployments

FlowFuse is SOC 2 Type I and Type II certified, with role-based access control, single sign-on, audit logging, and air-gapped, self-hosted deployment options, for teams running OPC UA clients and servers across regulated or security-sensitive plants.

Review our security and compliance details

SOC 2 Type II

Single Sign-On

Audit Logs

Role-Based Access Control

Air-Gapped / Self-Hosted Deployment

What you can build with OPC UA + FlowFuse

Historical Data Logging

Subscribe to OPC UA nodes and write timestamped values into InfluxDB or TimescaleDB, for a durable history that outlives the server's own buffer.

OPC UA to InfluxDB guide

OPC UA Client Dashboards

Browse an address space, read and write values, subscribe to alarms, then wire the results straight into a live operator dashboard. No separate client, no separate HMI license.

Build an OPC UA client dashboard

Bridging OPC UA to MQTT / UNS

Pull structured data out of an OPC UA server and republish it to any MQTT broker, normalized into a Unified Namespace topic hierarchy on the way.

Bridging OPC UA to MQTT

Agentic AI on OPC UA Data

Let an AI agent query the information model directly, correlating live values, alarms, and history to surface a root cause instead of a manual address-space search.

Agentic AI reads OPC UA servers

Migrating Off Kepware

Connect to an existing KepServerEX server as a client today, no rip-and-replace. Retire it on your own timeline by hosting an equivalent server on self-hosted FlowFuse.

Connect to a Kepware OPC server

Hosting Your Own OPC UA Server

Model your own address space and expose it as a standards-compliant server, so any SCADA, historian, or other client can browse and subscribe to it. Requires self-hosted FlowFuse.

Deploy a basic OPC UA server

From OPC UA to insight, step by step

Step 1

Connect or Build

Browse and connect to an existing OPC UA server as a client. On self-hosted FlowFuse, model your own address space and expose it as a server, from the same canvas.

Step 2

Secure the Session

Set Security Policy to SignAndEncrypt, then add the client certificate to the server's trusted list so the secure handshake succeeds.

Step 3

Bridge Other Protocols

Wire in Modbus, EtherNet/IP, or Siemens S7 nodes alongside OPC UA on the same canvas, for the plants that aren't running OPC UA end to end.

Step 4

Visualize, Route & Scale

Wire the results into a live dashboard, forward data to MQTT, a time-series database, or a cloud platform. Then push the flow to one edge device or a thousand with one click.

Frequently asked questions

Ready to build an OPC UA client or server the right way?

No per-tag licensing. No Security Policy left at None. Connect to any OPC UA server, host your own, and bridge both to Modbus, MQTT, or a historian without extra middleware. See it live, or start free.