MCP server for ALTR data security: databases, tags, policies, classification, access, audits
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β we're steadily working through the catalog.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
ALTR provides tag-based data masking, access governance, and classification for Snowflake, Databricks, and OLTP databases. This MCP server enables AI assistants (Claude, Cursor, and other MCP clients) to manage data security on the ALTR platform, covering database connections, tag masking, policies, classification, access management, audits, telemetry, and sidecar configuration.
New to ALTR? See the ALTR documentation for an overview of the platform, concepts, and supported data sources.
All tools return structured {success, data, error} responses and can run over stdio, SSE, or streamable-http transports.
Install from PyPI:
Or run directly with uvx (no install required):
uvxis part of the uv Python package manager. Install it withpip install uvor see the uv installation guide.
Set the three required environment variables (see Getting Credentials for where to find each in the ALTR console):
Wire it into your AI client β see Setup for Claude Desktop, Claude Code, Cursor, VS Code, and Windsurf. The same three env vars go into the client's env block.
Verify by asking your AI assistant to run a read-only tool:
get_databasesget_tagsget_rolesIf these return data, your setup is working.
You need three values from the ALTR platform to configure this server. See Manage API keys for the full reference.
| Credential | Where to find it |
|---|---|
ORG_ID | In the ALTR console: Settings > Preferences > Organization β copy the value from "ALTR Organization ID" |
MAPI_KEY | In the ALTR console: Settings > Preferences > API > Add New β give it a description, then copy the key |
MAPI_SECRET | Shown once when you create the API key above β copy and store it securely |
Set the following environment variables before starting the server:
| Variable | Required | Description |
|---|---|---|
ORG_ID | Yes | ALTR organization ID |
MAPI_KEY | Yes | ALTR management API key |
MAPI_SECRET | Yes | ALTR management API secret |
MCP_TRANSPORT | No | Transport protocol: stdio (default), sse, or streamable-http |
MCP_HOST | No | Bind address for HTTP transports (default: 0.0.0.0) |
MCP_PORT | No | Port for HTTP transports (default: 8000) |
RESTRICTED_TOOLS | No | Comma-separated tool names to hide from clients |
LOG_FORMAT | No | Log output format: console (default) or json |
LOG_LEVEL | No | Log level (default: INFO) |
MAX_RETRIES | No | Attempts per API call before giving up (default: 3, minimum 1) |
DISABLE_RETRY | No | Set true to disable retries entirely (default: false) |
REQUEST_TIMEOUT | No | Per-request timeout in seconds (default: 30) |
MAX_RETRY_AFTER | No | Ceiling in seconds on a server-sent Retry-After (default: 60) |
MAX_RETRIES counts total attempts, not retries on top of the first, so 1
disables retrying without disabling the retry path. Backoff is exponential with
jitter; a Retry-After response header overrides it, clamped to
MAX_RETRY_AFTER so a server cannot park a call indefinitely.
Every ALTR service endpoint can be pointed elsewhere, which is useful against a non-production ALTR environment. All are optional β leave them unset in normal use.
The seven per-service endpoints are derived from your ORG_ID as
https://<ORG_ID>.<service>.live.altr.com, four of them with a version path
segment appended. An override replaces the whole value, so it must include that
path segment where the default has one β see the table.
| Variable | Default |
|---|---|
ALTR_API_BASE_URL | https://api.live.altr.com |
ALTR_ALTRNET_BASE_URL | https://altrnet.live.altr.com |
ALTR_CLASSIFICATION_BASE_URL | https://<ORG_ID>.classification.live.altr.com |
ALTR_SC_CONTROL_BASE_URL | https://<ORG_ID>.sc-control.live.altr.com |
ALTR_SERVICE_USER_BASE_URL | https://<ORG_ID>.service-user.live.altr.com |
ALTR_AUDIT_REPORT_BASE_URL | https://<ORG_ID>.audit-report.live.altr.com/v1 |
ALTR_VAULT_BASE_URL | https://<ORG_ID>.vault.live.altr.com/api/v2 |
ALTR_CRITICAL_BASE_URL | https://<ORG_ID>.critical.live.altr.com/v2 |
ALTR_KMA_BASE_URL | https://<ORG_ID>.kma.live.altr.com/v1 |
Use RESTRICTED_TOOLS to hide specific tools from MCP clients. Restricted tools are removed from the tool list and blocked if called directly.
Names must match the registered tool name exactly. An entry that matches nothing restricts nothing, and is logged as a warning the first time a client lists tools. Note that 11 tools were renamed from delete_* to disconnect_* in 0.4.0.
For example, to give a team read-only access without any destructive operations:
Or in the Claude Desktop config:
This is an operator-level safety net β it prevents accidental or unwanted tool usage but is not a substitute for proper API key permissions.
Add the following to your claude_desktop_config.json (Settings > Developer > Edit Config):
This writes the config to .mcp.json which can be committed to share with your team.
Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project-scoped):
Open User Settings JSON (Ctrl+Shift+P β "Preferences: Open User Settings (JSON)") and add:
Add to ~/.codeium/windsurf/mcp_config.json:
To run from a local clone instead of the published PyPI package:
Claude Code:
Claude Desktop:
This section is for building a standalone CLI binary from the MCP server. If you just want to use the server with Claude Desktop or Claude Code, skip to Tools.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/altr-mcp-server)<a href="https://allmcps.com/mcp/altr-mcp-server"><img src="https://allmcps.com/api/badge/altr-mcp-server?style=directory" alt="Altr MCP Server on AllMCPs" /></a>