OpCon MFT Transfer job
Behavior-level reference for building and diagnosing OpCon MFT Transfer jobs.
The OpCon MFT Transfer job moves files between two endpoints configured on a single OpCon MFT agent. One job is one round trip: it downloads files from a source endpoint, optionally compresses, decompresses, encrypts, decrypts or renames them, and then uploads the result to a destination endpoint.
An OpCon MFT agent is a branded Robo-FTP installation that exposes an HTTPS REST API. Continuum reaches it through a relay, the same as a legacy LSAM machine — but it is not an LSAM, and the differences matter when you register one:
| Legacy LSAM machine | OpCon MFT agent | |
|---|---|---|
| Platform label | WINDOWS, UNIX, IBM_i, SQL | OpCon MFT |
| Reached over | The LSAM wire protocol | The agent's HTTPS REST API |
| Default port | 3100 (LSAM Port) | 41100 (HTTPS Port) |
| JORS Port | Optional, for job output retrieval | Not offered — there is no JORS listener |
| Credential on the agent record | — | An API Token |
| File-transfer (FT) role panel | Offered when editing | Not offered — an MFT agent is never an end of a SMAFT transfer |
OpCon MFT Transfer and SMAFT File Transfer are unrelated. A SMAFT job names two legacy LSAM machines and moves a file between them. An OpCon MFT Transfer job names one OpCon MFT agent and moves files between two endpoints defined on that agent. Neither job type can substitute for the other, and an MFT agent cannot take part in a SMAFT transfer.
Before you can build one
Three things have to be in place.
- A relay that supports OpCon MFT. The relay reports whether it can serve MFT agents, and Continuum refuses to register one under a relay that does not. The register dialog says Upgrade the relay to register MFT agents. — see Relays.
- A registered OpCon MFT agent. Agents → Legacy Agents & Groups, pick the relay, then add an agent with Platform set to OpCon MFT. See Registering the agent.
- Endpoints configured on the agent. Continuum does not create endpoints. It reads the list the agent already holds, so the source and destination endpoints must exist in the agent's own configuration first.
Registering the agent
The agent form changes when Platform is OpCon MFT:
| Field | Detail |
|---|---|
| Host | IP address or fully qualified domain name of the OpCon MFT agent. Host only — a pasted URL, a path, or a stray space is refused with Enter the host name or IP address only — no scheme, path or spaces. Set the port below. |
| HTTPS Port | Default 41100. Switching Platform to or from OpCon MFT swaps the port default, but only while the field still holds the other platform's default — a port you typed is never overwritten. |
| API Token | The agent's X-Auth-Token. Optional. Enter the token the agent already uses — for example the one a Classic installation uses — or leave it blank and reset it later. |
| Max Concurrent Jobs | As for any legacy agent. |
The API token is write-only. It is stored encrypted, it is never shown again, and no read ever returns it — the agent record reports only whether a token is stored. On an edit, leaving API Token blank keeps the stored token; typing a value replaces it.
Reset API token
Reset API token is on the agent's actions menu. It has Continuum mint a new token and store it, without ever displaying it. You confirm by typing the agent's name, the same as regenerating relay credentials.
Resetting invalidates the token for every other client using this agent, including a Classic OpCon installation. Anything else pointed at the same agent stops working until it is given the new token.
A reset can fail, and the message distinguishes what to do next:
| Message | What it means |
|---|---|
| The agent's first-token window has closed; enter the existing token or reset the deadline in the MFT Configurator. | The agent only accepts an unauthenticated first token for a limited period after installation, and that period has expired. |
| The agent rejected the stored API token. | The token Continuum holds is not the one the agent expects. Edit the agent, enter the token it currently uses, and try again. |
| The relay serving this agent must be upgraded before its API token can be reset. | The relay does not support OpCon MFT. |
| This agent is not an OpCon MFT agent. | The action was aimed at an agent of another platform. |
| The agent didn't answer in time. The token may still have been reset — refresh in a moment. | The reset may have succeeded. Do not assume it failed — refresh and check before resetting again. |
Which machine runs the job
The machine is picked in Agent Assignment, as it is for a Windows or UNIX LSAM job — not derived from the job's own fields the way a SMAFT transfer is. Only OpCon MFT agents are offered, because the job type requires that platform.
The picked machine also decides what the endpoint, encryption key and signing key pickers contain: each list is read from that agent, so choosing the machine is the first thing to do. Change the machine and those lists change with it.
Configuration reference
Identity and timing
| Field | Required | Detail |
|---|---|---|
| Group Name | No | The MFT job group the transfer runs under on the agent. Defaults to DEFAULT. Only letters, digits and underscores are kept — everything else is removed before use. |
| Timeout (minutes) | No | How long the source download may wait. Leave empty to use the agent's own default of 1 minute. |
Source
| Field | Required | Detail |
|---|---|---|
| Source Endpoint | Yes | The endpoint to download from, chosen from the list read from the agent. |
| Source File Filter | Yes | Which files to transfer, as a Robo-FTP mask — *.csv, or a*|b* for more than one pattern. |
| Source File Path | No | Folder on the source endpoint. Leave empty for the endpoint's root. |
| Retain Source Files | No | Off by default. On, the source files are left in place after being downloaded. Excludes Reprocess Files — see below. |
| Reprocess Files | No | Off by default. On, files are downloaded again even if they were transferred before. Excludes Retain Source Files — see below. |
| Archive Files | No | Off by default. On, the files each step processes are archived — every step except decompression. |
Destination
| Field | Required | Detail |
|---|---|---|
| Destination Endpoint | Yes | The endpoint to upload to, chosen from the list read from the agent. |
| Destination File Filter | Yes | Which of the files the earlier steps produced to upload. Defaults to * — everything. |
| Destination File Path | No | Folder on the destination endpoint. Leave empty for the endpoint's root. |
| Overwrite | No | What to do when a destination file already exists: True (the default) overwrites it, Append appends to it, False fails the upload. |
| Rename Files | No | Off by default. On, files are renamed before upload and both rename patterns become required. |
| Rename Search Pattern | When renaming | A Robo-FTP regular expression matched against each file name, such as ^(.*)$. |
| Rename Replace Pattern | When renaming | A Robo-FTP replace expression that builds the new name, such as "X_" + ${1}. |
Compression
| Field | Required | Detail |
|---|---|---|
| Compression Action | No | None (the default), Compress — pack the downloaded files into one archive — or Decompress — unpack downloaded archives. |
| Compression File Name | No | Name of the archive to create. Used only when the action is Compress. |
| Extract Filter | No | Which files to extract from each archive. Used only when the action is Decompress. |
| Compression Password | No | An OpCon MFT Compression Password connection, used to protect the archive being created or to open a protected one. Leave it empty for no password. |
The Compression Password is a connection, not a value typed into the job: it is stored encrypted and never shown again after saving. That means one password can be shared by many jobs and rotated in one place.
Encryption
Encryption is PGP, using keys that live on the agent. Continuum lists them; it does not hold them.
| Field | Required | Detail |
|---|---|---|
| Encryption Action | No | None (the default), Encrypt — PGP-encrypt before upload — or Decrypt — decrypt downloaded files. |
| Encryption File Filter | When encrypting or decrypting | Which files to encrypt or decrypt. |
| Encryption Key | When encrypting | The PGP key to encrypt with, chosen from the keys listed on the agent. |
| Signing Key | No | A private key to sign with, chosen from the signing keys listed on the agent. |
| Cipher | No | CAST5, AES (the default), AES192, IDEA, Blowfish, Twofish or 3DES. |
| ASCII Armor | No | Off by default. On, the encrypted output is written as ASCII-armored text instead of binary. |
| Reverse Order of Encryption/Compression | No | Off by default. See the order the steps run in. |
Signature Type is kept so a job migrated from Classic round-trips unchanged, but it is not sent to the agent — the agent signs with its own configured settings. Changing it changes nothing about the transfer.
The order the steps run in
Every job runs a download step first and an upload step last. What happens in between depends on the two actions and on Reverse Order of Encryption/Compression:
| Compression Action | Encryption Action | Reverse Order | Steps between download and upload |
|---|---|---|---|
| None | None | — | (none) |
| Compress | None | — | Compress |
| Decompress | None | — | Decompress |
| None | Encrypt | — | Encrypt |
| None | Decrypt | — | Decrypt |
| Compress | Encrypt | Off | Compress → Encrypt |
| Compress | Encrypt | On | Encrypt → Compress |
| Decompress | Decrypt | Off | Decrypt → Decompress |
| Decompress | Decrypt | On | Decompress → Decrypt |
| Compress | Decrypt | — | Compress only — the decrypt is dropped |
| Decompress | Encrypt | — | Decompress only — the encrypt is dropped |
If Rename Files is on, the rename step runs after all of these and immediately before the upload.
Compress + Decrypt and Decompress + Encrypt run only the compression step. The encryption step is discarded without a warning, at save time or at run time. This matches Classic exactly, so a migrated job behaves as it always did — but if you are building a new job and expect both to happen, the job will not tell you that one of them never ran.
The save-time rules still apply to the discarded step: a Compress + Decrypt job is refused without an Encryption File Filter, even though the decrypt never runs.
Rules
Refused when you save
These are checked when the workflow is saved, when it is deployed, and when an automation bundle is imported.
| Refused when | Message |
|---|---|
| No Source Endpoint | a Source Endpoint is required |
| No Source File Filter | a Source File Filter is required |
| No Destination Endpoint | a Destination Endpoint is required |
| Destination File Filter was cleared | a Destination File Filter is required (leave it unset to use the default *) |
| Retain Source Files and Reprocess Files are both on | Reprocess Files cannot be on while Retain Source Files is on — OpCon MFT refuses the combination, because the retained files would be downloaded again on every run |
| Rename Files is on and either pattern is empty | a Rename Search Pattern is required when Rename Files is on / a Rename Replace Pattern is required when Rename Files is on |
| Encryption Action is Encrypt and the filter or key is empty | an Encryption File Filter is required when Encryption Action is 'Encrypt' / an Encryption Key is required when Encryption Action is 'Encrypt' |
| Encryption Action is Decrypt and the filter is empty | an Encryption File Filter is required when Encryption Action is 'Decrypt' |
| Group Name contains no letter, digit or underscore | the Group Name must contain at least one letter, digit or underscore (A–Z, a–z, 0–9, _), or be left blank to use DEFAULT |
| The job name contains no letter, digit or underscore | the job name must contain at least one letter, digit or underscore (A–Z, a–z, 0–9, _) to be used as the OpCon MFT job name |
The two name rules exist because the agent's REST path is built from the stripped group and job names. A name that strips to nothing could never run — in Classic either — so it is refused at save rather than failing every dispatch.
Each one makes sense alone. Together they mean leave the files where they are and download files you have already taken — so every run would transfer the whole folder again, for ever. OpCon MFT refuses that pair outright, so the job could never run at all.
It is refused at save now, naming Reprocess Files. Earlier builds had no guard, so the job saved cleanly and then failed on every single dispatch with nothing explaining why. (Classic prevented it by hiding Reprocess while Retain was on, rather than by a rule.) If you have a job in this state, turn one of the two off and save.
Clearing a field is not the same as never setting it. Destination File Filter is the one
place this is visible: a job that never touched the field uses the default * and saves, while a
job whose field was filled in and then emptied is refused.
Exit criteria
The job's exit code is the MFT run's Result, where 0 means success. Exit criteria work exactly
as they do on the legacy LSAM job types: up to 20
conditions, each an operator and a whole number, with Range taking a second value and matching
inclusively at both ends. Exit Criteria Result decides what a match means — Fail (the
default) or Finish OK.
Two things are specific to this job type:
- Continuum evaluates the criteria, not the agent. The MFT agent never sees them.
- A job that fails to start has no exit code, so no criterion applies to it. It fails on the dispatch error instead.
Outcomes
The job log Continuum stores for the run is the MFT job log: a header naming the run, then a Job
Step Information block per step in the order the agent ran them. Timestamps are the agent's local
time, so a log reads the same regardless of where the relay runs. A very long log is truncated, and
the log ends with ... (truncated) when it is.
If the log cannot be fetched after the run finishes, the run is still reported — the job's outcome is never lost to a failed log fetch — and the log text is the fetch error instead.
A restart resumes the previous run
This is the one behavior that is likely to surprise you.
When an OpCon MFT job fails, Continuum remembers the agent's run id and the machine it ran on. If you then restart, force start, or let a failure retry run the job again on the same machine, the agent resumes that run rather than starting a new one — files already transferred are not transferred again. This is deliberate, and matches Classic.
It does not resume in these cases, each of which starts a completely fresh run:
- The next run targets a different machine.
- The job runs again as part of a recurrence — a new cycle is always a new run.
- The previous run succeeded, or was marked Finished OK or Fixed.
If you have fixed something on the agent and want the transfer to start over rather than pick up where it stopped, run it on a fresh instance rather than restarting the failed one.
Troubleshooting
| Symptom | Likely cause | What to do |
|---|---|---|
| Registering the agent fails with Upgrade the relay to register MFT agents. | The relay serving it does not support OpCon MFT | Upgrade the relay — see Relays |
| The Source Endpoint or Destination Endpoint list is empty | No machine is picked yet, or the agent holds no endpoints | Pick the machine in Agent Assignment first; then check the endpoints in the agent's own configuration |
| The Encryption Key list is empty | The agent lists no PGP encryption keys | Add the key on the agent; Continuum only lists what the agent holds |
| The job was saved but the encryption step never happened | The job pairs Compress with Decrypt, or Decompress with Encrypt | One of the two is dropped by design — see the order the steps run in |
| Everything looks right and the job fails immediately | The agent rejects the stored API token | Edit the agent and enter the token it currently uses, or Reset API token |
| A restarted job transferred nothing | It resumed the failed run, which had already transferred those files | Expected — see A restart resumes the previous run |
| The archive cannot be opened, or a protected archive is not read | The Compression Password connection is empty or holds the wrong password | An empty Compression Password means no password; check the connection |
Contact support when
- The agent is reachable and its token is accepted, but every run fails with an agent-side error the job log does not explain.
- Reset API token reports the first-token window has closed and the MFT Configurator does not offer a way to reset the deadline.