DorisBLOCK
Apache Doris MCP Server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 简体中文
Apache Doris MCP Server exposes read-only Apache Doris capabilities to MCP Hosts and AI agents over MCP 2026-07-28. Version 1.0 replaces a large flat tool surface with eight stable domains and fifty-five progressively disclosed child capabilities, while keeping runtime availability, authorization, input schemas, output schemas, and failure behavior explicit.
Release status
The package version is 1.0.0. MCP 2026-07-28 protocol compatibility on master is Generally Available (GA) on Streamable HTTP and stdio. This GA statement is scoped to protocol compatibility; the Python package classifier remains Beta, and the documented deployment limits still apply.
Before upgrading, read the 1.0 release notes, the 1.0 migration guide, and the generated 8-domain/55-child registry. The detailed release record is Issue #189.
Architecture at a glance
MCP Host -> stdio or Streamable HTTP -> transport security and authentication -> MCP protocol validation and authorization -> stabl
4f1936516936OBSERVED · 2026-10-03Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add doris-mcp-server --env ALLOW_UNAUTHENTICATED_NON_LOOPBACK=${ALLOW_UNAUTHENTICATED_NON_LOOPBACK} --env AUTH_TYPE=${AUTH_TYPE} --env BLOCKED_KEYWORDS=${BLOCKED_KEYWORDS} --env DEFAULT_TOKEN_EXPIRY_HOURS=${DEFAULT_TOKEN_EXPIRY_HOURS} -- uvx doris-mcp-server{
"mcpServers": {
"doris-mcp-server": {
"command": "uvx",
"args": [
"doris-mcp-server"
],
"env": {
"ALLOW_UNAUTHENTICATED_NON_LOOPBACK": "${ALLOW_UNAUTHENTICATED_NON_LOOPBACK}",
"AUTH_TYPE": "${AUTH_TYPE}",
"BLOCKED_KEYWORDS": "${BLOCKED_KEYWORDS}",
"DEFAULT_TOKEN_EXPIRY_HOURS": "${DEFAULT_TOKEN_EXPIRY_HOURS}"
}
}
}
}Exposed tools (33)
32 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze_columns | read | |
analyze_data_access_patterns | read | |
analyze_data_flow_dependencies | read | |
analyze_resource_growth_curves | read | |
analyze_slow_queries_topn | read | |
analyze_table_storage | read | |
array_output | read | Exercise non-object 2026-07-28 structured content. |
bad_output | read | Exercise server output-schema enforcement. |
echo | read | Verify process recovery after schema errors. |
exec_query | write | |
fail | read | Return a model-readable tool error. |
foxtrot | read | new item invalidates the snapshot |
get_adbc_connection_info | read | |
get_catalog_list | read | |
get_db_list | read | |
get_db_table_list | read | |
get_memory_stats | read | |
get_monitoring_metrics | read | |
get_recent_audit_logs | read | |
get_sql_explain | read | |
get_sql_profile | read | |
get_table_basic_info | read | |
get_table_column_comments | read | |
get_table_comment | read | |
get_table_data_size | read | |
get_table_indexes | read | |
get_table_schema | read | |
monitor_data_freshness | read | |
schema_guard | read | Exercise full JSON Schema 2020-12 input validation. |
select_rows | read | Select rows by identifier or name. |
test_missing_capability | read | Exercise the required-client-capability boundary. |
trace_column_lineage | read | |
unclassified_tool | read | Unclassified |
Trust audit
BLOCKgrade D · trust 62/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (14 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (24)
"metadata.google.internal",
ipaddress.ip_address("169.254.169.254"),self.logger.debug(f"Using provided auth_context with token: {bool(hasattr(auth_context, 'token') and auth_context.token)}")# curl -X POST http://127.0.0.1:3000/token/create
# curl -H "Authorization: Bearer $TOKEN_MANAGEMENT_ADMIN_TOKEN" http://127.0.0.1:3000/token/stats
http://127.0.0.1:3000/live || exit 1
secret = "must-not-echo-schema-secret"
secret = "stdio-secret-sec-016"
secret = "must-not-echo-stdio-schema-secret"
secret = "test-shared-state-handle-secret-value"
secret = "pagination-shared-state-handle-secret-value"
.asf.yaml
.licenserc.yaml
return yaml.load(WORKFLOW_PATH.read_text(encoding="utf-8"), Loader=yaml.BaseLoader)
fe_http_host="169.254.169.254",
assert fe_result["node_info"]["host"] == "169.254.169.254"
assert fe_result["node_info"]["host"] == "169.254.169.254"
--url http://127.0.0.1:39124/mcp \
- MCP: `POST http://127.0.0.1:3000/mcp`
decoded = base64.b64decode(
bandit, mypy, pandas-stubs, pytest, pytest-asyncio, pytest-cov, pytest-mock, pytest-xdist
mcp, aiomysql, PyMySQL, adbc-driver-manager, adbc-driver-flightsql, pyarrow, asyncio-mqtt, aiofiles
allowlist. Doris administrative, export, load, plugin, credential, backup,
- Read credentials from environment variables or a secret manager. Never place
Gates applied: no_behavioural_pass.
4f1936516936full audit observations/trust-audit/mcp-server/apache__doris-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-03 | 4f1936516936 | BLOCK | D | 62 | first audit |
Questions
What is the Doris MCP server?
Apache Doris MCP Server
What tools does Doris expose?
33 in total: 32 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Doris safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (62/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Doris need?
It reads ALLOW_UNAUTHENTICATED_NON_LOOPBACK, AUTH_TYPE, BLOCKED_KEYWORDS, DEFAULT_TOKEN_EXPIRY_HOURS, DORIS_OAUTH_ALLOW_INSECURE_HTTP, DORIS_OAUTH_BASE_URL, DORIS_OAUTH_CHILD_TOOLS_ENABLED, DORIS_OAUTH_CLIENTS_FILE, DORIS_OAUTH_DB_TOOLS_ENABLED, DORIS_OAUTH_DYNAMIC_CLIENT_REGISTRATION_MODE, DORIS_OAUTH_EXPLAIN_TOOLS_ENABLED and DORIS_OAUTH_LOGIN_PAGE_TITLE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Doris run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as doris-mcp-server.
How current is this page?
The grade is for one exact copy of the source (4f1936516936), read on 2026-10-03. The repository is watched and re-audited when it changes.