The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Metabase MCP listing page.
The headless, AI-augmented MCP server for Metabase — API-key auth that works for agents, CI, and VPN'd self-hosted instances, with AI insights, production security controls, and support for any Metabase version.
Metabase ships an official MCP server (v0.60+), and since v0.61/v0.62 it covers both read and write operations — creating and updating questions, dashboards, and collections, plus raw SQL execution. It's good, and if it fits your setup you should consider it.
This server exists for the setups it doesn't fit:
batch_execute (up to 20 parallel ops) and run_workflow (chained steps with output references) have no official equivalent.| Capability | @ai-1luvc0d3/metabase-mcp | Metabase Official (v63) |
|---|---|---|
| Read dashboards / cards / databases | ✅ | ✅ |
| Create & update questions, dashboards, collections | ✅ | ✅ (v61+) |
| Raw SQL execution | ✅ SELECT-only + guardrails | ✅ (v62+, needs native-query permission) |
| Delete cards & dashboards | ✅ | ❌ (archive-only, via update) |
| Add / remove cards on a dashboard | ✅ | ❌ |
| Batch execution (parallel multi-op in one call) | ✅ | ❌ |
| Workflow pipelines (chained steps with output references) | ✅ | ❌ |
| NLQ → SQL + explain / optimize / validate (LLM in the server) | ✅ | ❌ (relies on the AI client) |
| Automated insights & trend analysis | ✅ | ❌ |
| Inline interactive charts rendered in the AI client | ❌ | ✅ (v62+) |
| SQL injection guardrails | ✅ | permission-based |
| Tiered rate limiting (read / write / LLM) | ✅ | blanket 1,000 req/min per user |
| Per-operation audit logging with risk levels | ✅ | partial (Enterprise usage analytics; OAuth event log) |
| Server modes / per-tool allow & deny lists | ✅ | ❌ (instance-wide on/off + an execute_sql kill switch) |
| API-key auth over MCP (headless, CI, agents, VPN'd self-hosted) | ✅ | ❌ (MCP endpoint is OAuth browser flow only) |
| OAuth per-user permission scoping | ❌ (API key) | ✅ |
| Works on Metabase < v0.60 (no upgrade required) | ✅ | ❌ |
Use this if: you're running agents or CI that can't do an OAuth browser flow, your self-hosted Metabase isn't publicly reachable, you want AI-generated insights server-side, you need audit logs and rate limits, or you're on a Metabase version older than v0.60.
Use Metabase's official MCP if: you're on v62+, your instance is reachable for OAuth, and per-user permission scoping or inline interactive charts matter more to you than the above.
Several community Metabase MCP servers exist, some exposing far more of the raw REST API (90+ tools). This one makes a different trade: a curated tool surface with production controls. As of August 2026, it is the only Metabase MCP server — official or community — with SQL injection guardrails, tiered rate limiting, per-operation audit logging, and per-tool access control enforced inside batch and workflow calls. If you want maximum raw API coverage, one of the broad-CRUD servers may fit better; if an agent is going to touch your BI unattended, safety rails are the feature.
$stepName.path output references between steps, including write steps (e.g. create a card, then add it to a dashboard, in one call)format: "default"read (safe default), write, or full (with AI insights)metabase-mcp-*.mcpb from GitHub ReleasesSet environment variables or create a .env file (see .env.example):
| Variable | Required | Default | Description |
|---|---|---|---|
METABASE_URL | Yes | - | Your Metabase instance URL |
METABASE_API_KEY | Yes | - | Metabase API key |
MCP_MODE | No | read | Server mode: read, write, or full |
ANTHROPIC_API_KEY | No | - | Enables NLQ and insight tools |
METABASE_TIMEOUT | No | 30000 | Request timeout (ms) |
METABASE_MAX_ROWS | No | 10000 | Max rows returned per query |
LOG_LEVEL | No | info | Logging: debug, info, warn, error |
MCP_TOOLS_ALLOW | No | - | Comma-separated allowlist — only these tools are exposed |
MCP_TOOLS_DENY | No | - | Comma-separated denylist — these tools are never exposed (wins over allow) |
RATE_LIMIT_READ_PER_MINUTE | No | 120 | Read-tier rate limit |
RATE_LIMIT_WRITE_PER_MINUTE | No | 30 | Write-tier rate limit |
RATE_LIMIT_LLM_PER_MINUTE | No | 20 | LLM-tier rate limit |
RATE_LIMIT_REQUESTS_PER_MINUTE | No | - | Legacy: sets the read tier when RATE_LIMIT_READ_PER_MINUTE is unset |
Server modes give coarse control (read / write / full); MCP_TOOLS_ALLOW and MCP_TOOLS_DENY refine it per tool. Denied tools are not registered with the MCP client at all, and the same policy is enforced on operations nested inside batch_execute and run_workflow — a denied tool can't be reached through a batch or pipeline. Deny always wins over allow.
METABASE_API_KEYAdd to your Claude Desktop config (~/Library/Application Support/Claude/claude_desktop_config.json on macOS):
| Mode | Tools | Description |
|---|---|---|
read | 12 + NLQ | Read-only access, batch execution, and workflow pipelines |
write | 22 + NLQ | Adds create/update/delete for cards, dashboards, collections |
full | 30 | All tools including automated insights and trend analysis |
Read (always available)
list_dashboards, get_dashboard, list_cards, get_card, execute_card, list_databases, get_database_schema, execute_query, search_content, get_collections
Batch & Workflow (always available)
batch_execute, run_workflow
In write/full mode, both also accept the non-destructive write tools (create_card, update_card, create_dashboard, update_dashboard, add_card_to_dashboard, create_collection, move_to_collection). Delete/remove operations are never batchable — they must be explicit single tool calls.
Write (write/full modes)
create_card, update_card, delete_card, create_dashboard, update_dashboard, delete_dashboard, add_card_to_dashboard, remove_card_from_dashboard, create_collection, move_to_collection
NLQ (requires ANTHROPIC_API_KEY)
nlq_to_sql, explain_sql, optimize_sql, validate_sql
Insights (full mode + ANTHROPIC_API_KEY)
ask_data, generate_insights, compare_metrics, trend_analysis
You: What dashboards do we have related to customer retention?
Claude uses search_content to find retention-related dashboards, then get_dashboard to summarize the key metrics. You see a ranked list with the most relevant results.
You: Run the "Monthly Active Users" card for the last 90 days
Claude calls list_cards to locate the card, then execute_card with the appropriate time filter. Results come back as a table you can ask follow-up questions about ("what was the biggest dip and when?").
You: Show me the top 10 products by revenue last quarter from the sales database
Claude calls list_databases to find the sales database, get_database_schema to inspect the relevant tables, then generates and runs a SELECT query via execute_query. The query is validated against the SQL guardrails (no DROP/DELETE/UNION, single statement only) before execution. Audit log entry is written with the query and row count.
You: DROP TABLE users
Request is blocked. Claude surfaces: "Blocked SQL pattern detected: DROP — this operation is not allowed." The block is logged as a high-risk audit event.
You: Which support agents closed the most tickets this week, and how does that compare to last week?
Claude uses nlq_to_sql with the database schema as context to generate a comparative SQL query. You can ask it to explain_sql in plain English before running, or optimize_sql to suggest performance improvements — all before hitting your database.
You: Save the MAU trend query we just ran as a card called "MAU — Last 90 Days" in the Growth collection
Claude calls get_collections to find "Growth", then create_card with your validated SQL. The card now lives in your Metabase library and can be re-executed by name in future conversations via execute_card — no LLM tokens spent on re-generating the query.
You: Get me the details for dashboards 1, 3, and 7, plus the schema for the sales database
Claude uses batch_execute to run all four operations in parallel in a single call:
One tool call instead of four. Results come back with per-operation success/failure, so partial failures don't block the rest.
You: Find dashboards about revenue, get the first one's cards, and run the top card
Claude uses run_workflow to chain the steps with output references:
Each step can reference results from previous steps using $stepName.path[index].field syntax. One round trip instead of three back-and-forth exchanges.
In write/full mode, pipelines can also build content:
You: Save this query as a card and put it on a new "Growth" dashboard
Write steps go through the same guardrails as the standalone write tools: write-tier rate limiting, SQL validation, and per-operation audit logging. Destructive operations (deletes/removes) are not allowed in pipelines.
You: Run last quarter's revenue query and tell me what's interesting
Claude uses execute_query to run the query, then generate_insights which asks the Claude API to identify trends, outliers, and recommendations. You get a structured summary: headline number, 3-5 bullet points, and suggested follow-up questions.
Note on data privacy:
generate_insights,ask_data,compare_metrics, andtrend_analysissend query result rows to the Anthropic API for analysis. See Data Privacy Note for details.
This server is designed for production use with multiple layers of protection:
SELECT and WITH queries are allowed by default. DDL/DML statements (DROP, DELETE, INSERT, etc.) are blocked. Injection patterns (UNION, comments, multi-statement, file ops, time-based attacks) are detected and rejected.RATE_LIMIT_*_PER_MINUTE.MCP_TOOLS_ALLOW / MCP_TOOLS_DENY restrict which tools are exposed, enforced at registration and inside batch_execute / run_workflow.When using NLQ or insight tools (ask_data, generate_insights, etc.), query result data is sent to the Anthropic API for analysis. If your queries return sensitive data (PII, financial records, etc.), that data will be processed by Claude. Consider this when enabling NLQ features on databases containing sensitive information.
What this extension collects:
What this extension transmits:
Data retention:
AUDIT_LOG_FILE) are written to your local filesystem only, with owner-only permissions (0600)Third-party privacy policies:
Reporting security issues: See SECURITY.md for responsible disclosure.
METABASE_URL is correct and reachable (test: curl $METABASE_URL/api/health)METABASE_API_KEY is valid (regenerate in Metabase Admin > Settings > API Keys if needed)SELECT and WITH queries are allowed by defaultSELECT, patterns like UNION SELECT, SQL comments (--, /* */), xp_cmdshell, INTO OUTFILE, etc. are blockedINSERT, UPDATE, DELETE), you must run in write or full mode AND the SQL must still pass guardrails (it won't — by design)RATE_LIMIT_REQUESTS_PER_MINUTE env varANTHROPIC_API_KEY — verify it's setsk- and has remaining creditsMCP_MODE=full~/Library/Logs/Claude/mcp*.log on macOSnode --version is >= 20This project is young and your input shapes where it goes next — especially now that Metabase has shipped its own official MCP. A minute of your time helps a lot:
MCP_MODE, and reproduction steps.See CONTRIBUTING.md for more details.