MetabaseSAFE
A comprehensive MCP server for Metabase with 70+ tools.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@easecloudio/mcp-metabase-server) [](https://opensource.org/licenses/MIT) [](https://www.typescriptlang.org/) [](https://github.com/easecloudio/mcp-metabase-server)
A Model Context Protocol (MCP) server for Metabase that gives AI assistants full access to your analytics platform — dashboards, cards, databases, tables, collections, and more.
Developed and maintained by [EaseCloud](https://easecloud.io) — cloud-native, AI-driven, and data infrastructure solutions.
Quick Start
export METABASE_URL=https://your-metabase-instance.com export METABASE_API_KEY=your_metabase_api_key npx @easecloudio/mcp-metabase-server
96 Tools Available
Supported Metabase Versions
- Metabase v0.46.x and above (recommended: v0.48.x or later)
- Metabase Cloud (fully supported)
- Self-hosted instances (Docker, JAR, or cloud deployments)
Installation
npx (Recommended)
npx @easecloudio/mcp-metabase-server
Global install
npm install -g @easecloudio/mcp-metabase-server mcp-metabase-server
Docker
docker build -t mcp-metabase-server . docker run -it --rm \ -e METABASE_URL=https://your-metabase-instance.com \ -e METABASE_API_KEY=your_metabase_api_key \ mcp-metabase-server
Configuration
Authentication
API Key (preferred):
METABASE_URL=https://your-metabase-instance.com METABASE_API
0fdf25a6631aOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-metabase-server --env METABASE_API_KEY=${METABASE_API_KEY} --env METABASE_PASSWORD=${METABASE_PASSWORD} -- npx -y @easecloudio/[email protected]{
"mcpServers": {
"mcp-metabase-server": {
"command": "npx",
"args": [
"-y",
"@easecloudio/[email protected]"
],
"env": {
"METABASE_API_KEY": "${METABASE_API_KEY}",
"METABASE_PASSWORD": "${METABASE_PASSWORD}"
}
}
}
}Exposed tools (95)
51 read · 35 write · 9 destructive. Blast radius: 9 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_card_to_dashboard | write | Add a card to a dashboard with positioning |
add_sample_database | write | Add the built-in Metabase sample database (H2) with demo data for testing |
add_text_block | write | Add a text or heading block to a dashboard |
append_csv_to_table | read | Append new rows to a table from CSV content (for Metabase-managed tables) |
check_database_health | read | Check the connection health of a database |
copy_card | read | Duplicate an existing card/question |
copy_dashboard | read | Duplicate a dashboard with all its cards |
create_card | write | Create a new Metabase question (card) |
create_card_public_link | write | Create a public sharing link for a card/question. Returns the UUID for the public URL. |
create_collection | write | Create a new Metabase collection |
create_dashboard | write | Create a new Metabase dashboard |
create_dashboard_public_link | write | Create a public sharing link for a dashboard. Returns the UUID for the public URL. |
create_database_connection | write | Create a new database connection |
create_permission_group | write | Create a new permission group |
create_user | write | Create a new Metabase user |
delete_card | destructive | Delete a Metabase question (card) |
delete_card_public_link | destructive | Remove the public sharing link for a card/question |
delete_collection | destructive | Delete a collection and all its contents |
delete_dashboard | destructive | Delete a Metabase dashboard |
delete_dashboard_public_link | destructive | Remove the public sharing link for a dashboard |
delete_database | destructive | Permanently remove a database connection from Metabase |
discard_table_field_values | read | Discard cached field values for a table |
execute_card | write | Execute a Metabase question/card and get results |
execute_dashboard_card | write | Execute a specific card on a dashboard and return results |
execute_pivot_card_query | write | Execute a card query and return results formatted as a pivot table |
execute_query | write | Execute a SQL query against a Metabase database |
export_card_result | read | Export a card |
favorite_dashboard | read | Mark a dashboard as a favourite |
get_card | read | Get a single Metabase question/card by ID with full details including the SQL query (dataset_query). Returns MBQL 5 by default. |
get_card_dashboards | read | List all dashboards that contain a specific card |
get_card_param_remapping | read | Get how a card parameter |
get_card_param_values | read | Get available values for a card parameter (for populating filter dropdowns) |
get_card_query_metadata | read | Get query metadata for a card including column types and display names |
get_card_series | read | Get time series data or related card suggestions for a card |
get_card_table_fks | read | Get foreign key relationships for a card |
get_card_table_query_metadata | read | Get query metadata (fields, types) for a card |
get_collection | read | Get details of a specific collection |
get_collection_items | read | List items (cards, dashboards, sub-collections) inside a collection |
get_dashboard | read | Get a specific dashboard by ID with full details |
get_dashboard_cards | read | Get all cards in a dashboard |
get_dashboard_queries | read | Extract all card queries from a dashboard with their resolved database IDs and SQL. Useful for auditing what data a dashboard queries. |
get_dashboard_related | read | Get related content suggestions for a dashboard |
get_dashboard_revisions | read | Get revision history for a dashboard (audit trail) |
get_database | read | Get detailed information about a specific database connection |
get_database_metadata | read | Get full metadata for a database including all tables and fields with their IDs. This is the authoritative source for field IDs needed in MBQL queries. |
get_database_schema | read | Get the schema information for a database |
get_database_sync_status | write | Get database schema sync status |
get_database_tables | read | Get all tables in a database |
get_field_id | read | Look up the Metabase field ID for a column by table ID and column name. Essential for building MBQL queries. |
get_schema_cache | read | Get cached database schema (tables + field IDs) for a Metabase database. |
get_table | read | Get metadata for a specific table by ID |
get_table_data | read | Get a sample data preview from a table |
get_table_fks | read | Get all foreign key relationships for a table |
get_table_metadata | read | Get full query metadata for a table including all fields with their IDs, types, and semantic types. Use this to get field IDs needed for MBQL queries. |
get_table_related | read | Find tables and entities related to this table through foreign key relationships |
list_cards | read | List all questions/cards in Metabase |
list_collections | read | List all collections in Metabase |
list_dashboards | read | List all dashboards in Metabase |
list_database_schemas | read | List all schemas within a database |
list_databases | read | List all databases in Metabase |
list_embeddable_cards | write | List all cards that are set up for embedding |
list_embeddable_dashboards | write | List all dashboards that are set up for embedding |
list_permission_groups | read | List all permission groups |
list_public_cards | read | List all cards that have public sharing links enabled |
list_public_dashboards | read | List all dashboards that have public sharing links enabled |
list_tables | read | List all tables across all databases in Metabase |
list_users | read | List all users in Metabase |
move_cards | write | Move one or more cards to a different collection |
move_cards_to_collection | write | Move all cards matching a filter to a specific collection |
move_to_collection | write | Move a card or dashboard to a different collection |
refresh_schema_cache | destructive | Force-refresh the local schema cache for one or all databases. |
remove_card_from_dashboard | destructive | Remove a card from a dashboard |
reorder_table_fields | write | Change the display order of fields in a table |
replace_table_csv | read | Replace all data in a table with new CSV content (for Metabase-managed tables) |
rescan_table_field_values | read | Rescan field values for a table (updates filter dropdowns) |
revert_dashboard | read | Revert a dashboard to a previous revision |
save_dashboard | write | Save a complete dashboard object including nested cards and settings |
save_dashboard_to_collection | write | Move a dashboard into a specific collection |
search_card_param_values | read | Search and filter available values for a card parameter |
search_content | read | Search across all Metabase content |
search_dashboards | read | Search dashboards by name or description |
sync_database_schema | write | Sync database schema metadata |
sync_table_schema | write | Trigger a schema sync for a specific table |
test_database_connection | read | Test a database connection |
unfavorite_dashboard | destructive | Remove a dashboard from favourites |
update_card | write | Update an existing Metabase question (card) |
update_collection | write | Update a collection |
update_dashboard | write | Update an existing Metabase dashboard |
update_dashboard_card | write | Update card position, size, and settings on a dashboard |
update_dashboard_cards | write | Bulk-replace all cards on a dashboard. WARNING: replaces the entire card layout. |
update_dashcard | write | Update a specific dashcard |
update_database | write | Update a database connection |
update_table | write | Update table metadata (display name, description, visibility) |
update_tables | write | Bulk-update multiple tables with the same configuration (e.g. hide all at once) |
validate_database | read | Validate a database connection before saving |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
delete_card, delete_card_public_link, delete_collection, delete_dashboard, delete_dashboard_public_link, delete_database, refresh_schema_cache, remove_card_from_dashboard, unfavorite_dashboard
@modelcontextprotocol/sdk, abort-controller, axios, @types/node, typescript
A **Model Context Protocol (MCP) server for Metabase** that gives AI assistants full access to your analytics platform — dashboards, cards, databases, tables, collections, and more.
Gates applied: no_behavioural_pass.
0fdf25a6631afull audit observations/trust-audit/mcp-server/easecloudio__metabase-3.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 0fdf25a6631a | SAFE | B | 89 | first audit |
Questions
What is the Metabase MCP server?
A comprehensive MCP server for Metabase with 70+ tools.
What tools does Metabase expose?
95 in total: 51 read-only, 35 that write, and 9 that can delete or overwrite (delete_card, delete_card_public_link, delete_collection, delete_dashboard, delete_dashboard_public_link). Every one is listed on this page with its risk.
Is Metabase safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 9 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Metabase need?
It reads METABASE_API_KEY and METABASE_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Metabase run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @easecloudio/mcp-metabase-server at 1.3.0.
How current is this page?
The grade is for one exact copy of the source (0fdf25a6631a), read on 2026-10-07. The repository is watched and re-audited when it changes.