Atlas / MCP servers / easecloudio / Metabase

MetabaseSAFE

mcp/easecloudio/metabase-3

A comprehensive MCP server for Metabase with 70+ tools.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
95 51r · 35w · 9d
Transport
stdio
License
MIT
Stars
82
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@easecloudio/mcp-metabase-server) [](https://opensource.org/licenses/MIT) [](https://www.typescriptlang.org/) [](https://github.com/easecloudio/mcp-metabase-server)

A Model Context Protocol (MCP) server for Metabase that gives AI assistants full access to your analytics platform — dashboards, cards, databases, tables, collections, and more.

Developed and maintained by [EaseCloud](https://easecloud.io) — cloud-native, AI-driven, and data infrastructure solutions.

Quick Start

export METABASE_URL=https://your-metabase-instance.com
export METABASE_API_KEY=your_metabase_api_key
npx @easecloudio/mcp-metabase-server

96 Tools Available

Supported Metabase Versions

  • Metabase v0.46.x and above (recommended: v0.48.x or later)
  • Metabase Cloud (fully supported)
  • Self-hosted instances (Docker, JAR, or cloud deployments)

Installation

npx (Recommended)

npx @easecloudio/mcp-metabase-server

Global install

npm install -g @easecloudio/mcp-metabase-server
mcp-metabase-server

Docker

docker build -t mcp-metabase-server .
docker run -it --rm \
-e METABASE_URL=https://your-metabase-instance.com \
-e METABASE_API_KEY=your_metabase_api_key \
mcp-metabase-server

Configuration

Authentication

API Key (preferred):

METABASE_URL=https://your-metabase-instance.com
METABASE_API
Read from source at commit 0fdf25a6631aOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-metabase-server --env METABASE_API_KEY=${METABASE_API_KEY} --env METABASE_PASSWORD=${METABASE_PASSWORD} -- npx -y @easecloudio/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-metabase-server": {
      "command": "npx",
      "args": [
        "-y",
        "@easecloudio/[email protected]"
      ],
      "env": {
        "METABASE_API_KEY": "${METABASE_API_KEY}",
        "METABASE_PASSWORD": "${METABASE_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (95)

51 read · 35 write · 9 destructive. Blast radius: 9 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_card_to_dashboardwriteAdd a card to a dashboard with positioning
add_sample_databasewriteAdd the built-in Metabase sample database (H2) with demo data for testing
add_text_blockwriteAdd a text or heading block to a dashboard
append_csv_to_tablereadAppend new rows to a table from CSV content (for Metabase-managed tables)
check_database_healthreadCheck the connection health of a database
copy_cardreadDuplicate an existing card/question
copy_dashboardreadDuplicate a dashboard with all its cards
create_cardwriteCreate a new Metabase question (card)
create_card_public_linkwriteCreate a public sharing link for a card/question. Returns the UUID for the public URL.
create_collectionwriteCreate a new Metabase collection
create_dashboardwriteCreate a new Metabase dashboard
create_dashboard_public_linkwriteCreate a public sharing link for a dashboard. Returns the UUID for the public URL.
create_database_connectionwriteCreate a new database connection
create_permission_groupwriteCreate a new permission group
create_userwriteCreate a new Metabase user
delete_carddestructiveDelete a Metabase question (card)
delete_card_public_linkdestructiveRemove the public sharing link for a card/question
delete_collectiondestructiveDelete a collection and all its contents
delete_dashboarddestructiveDelete a Metabase dashboard
delete_dashboard_public_linkdestructiveRemove the public sharing link for a dashboard
delete_databasedestructivePermanently remove a database connection from Metabase
discard_table_field_valuesreadDiscard cached field values for a table
execute_cardwriteExecute a Metabase question/card and get results
execute_dashboard_cardwriteExecute a specific card on a dashboard and return results
execute_pivot_card_querywriteExecute a card query and return results formatted as a pivot table
execute_querywriteExecute a SQL query against a Metabase database
export_card_resultreadExport a card
favorite_dashboardreadMark a dashboard as a favourite
get_cardreadGet a single Metabase question/card by ID with full details including the SQL query (dataset_query). Returns MBQL 5 by default.
get_card_dashboardsreadList all dashboards that contain a specific card
get_card_param_remappingreadGet how a card parameter
get_card_param_valuesreadGet available values for a card parameter (for populating filter dropdowns)
get_card_query_metadatareadGet query metadata for a card including column types and display names
get_card_seriesreadGet time series data or related card suggestions for a card
get_card_table_fksreadGet foreign key relationships for a card
get_card_table_query_metadatareadGet query metadata (fields, types) for a card
get_collectionreadGet details of a specific collection
get_collection_itemsreadList items (cards, dashboards, sub-collections) inside a collection
get_dashboardreadGet a specific dashboard by ID with full details
get_dashboard_cardsreadGet all cards in a dashboard
get_dashboard_queriesreadExtract all card queries from a dashboard with their resolved database IDs and SQL. Useful for auditing what data a dashboard queries.
get_dashboard_relatedreadGet related content suggestions for a dashboard
get_dashboard_revisionsreadGet revision history for a dashboard (audit trail)
get_databasereadGet detailed information about a specific database connection
get_database_metadatareadGet full metadata for a database including all tables and fields with their IDs. This is the authoritative source for field IDs needed in MBQL queries.
get_database_schemareadGet the schema information for a database
get_database_sync_statuswriteGet database schema sync status
get_database_tablesreadGet all tables in a database
get_field_idreadLook up the Metabase field ID for a column by table ID and column name. Essential for building MBQL queries.
get_schema_cachereadGet cached database schema (tables + field IDs) for a Metabase database.
get_tablereadGet metadata for a specific table by ID
get_table_datareadGet a sample data preview from a table
get_table_fksreadGet all foreign key relationships for a table
get_table_metadatareadGet full query metadata for a table including all fields with their IDs, types, and semantic types. Use this to get field IDs needed for MBQL queries.
get_table_relatedreadFind tables and entities related to this table through foreign key relationships
list_cardsreadList all questions/cards in Metabase
list_collectionsreadList all collections in Metabase
list_dashboardsreadList all dashboards in Metabase
list_database_schemasreadList all schemas within a database
list_databasesreadList all databases in Metabase
list_embeddable_cardswriteList all cards that are set up for embedding
list_embeddable_dashboardswriteList all dashboards that are set up for embedding
list_permission_groupsreadList all permission groups
list_public_cardsreadList all cards that have public sharing links enabled
list_public_dashboardsreadList all dashboards that have public sharing links enabled
list_tablesreadList all tables across all databases in Metabase
list_usersreadList all users in Metabase
move_cardswriteMove one or more cards to a different collection
move_cards_to_collectionwriteMove all cards matching a filter to a specific collection
move_to_collectionwriteMove a card or dashboard to a different collection
refresh_schema_cachedestructiveForce-refresh the local schema cache for one or all databases.
remove_card_from_dashboarddestructiveRemove a card from a dashboard
reorder_table_fieldswriteChange the display order of fields in a table
replace_table_csvreadReplace all data in a table with new CSV content (for Metabase-managed tables)
rescan_table_field_valuesreadRescan field values for a table (updates filter dropdowns)
revert_dashboardreadRevert a dashboard to a previous revision
save_dashboardwriteSave a complete dashboard object including nested cards and settings
save_dashboard_to_collectionwriteMove a dashboard into a specific collection
search_card_param_valuesreadSearch and filter available values for a card parameter
search_contentreadSearch across all Metabase content
search_dashboardsreadSearch dashboards by name or description
sync_database_schemawriteSync database schema metadata
sync_table_schemawriteTrigger a schema sync for a specific table
test_database_connectionreadTest a database connection
unfavorite_dashboarddestructiveRemove a dashboard from favourites
update_cardwriteUpdate an existing Metabase question (card)
update_collectionwriteUpdate a collection
update_dashboardwriteUpdate an existing Metabase dashboard
update_dashboard_cardwriteUpdate card position, size, and settings on a dashboard
update_dashboard_cardswriteBulk-replace all cards on a dashboard. WARNING: replaces the entire card layout.
update_dashcardwriteUpdate a specific dashcard
update_databasewriteUpdate a database connection
update_tablewriteUpdate table metadata (display name, description, visibility)
update_tableswriteBulk-update multiple tables with the same configuration (e.g. hide all at once)
validate_databasereadValidate a database connection before saving
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_card, delete_card_public_link, delete_collection, delete_dashboard, delete_dashboard_public_link, delete_database, refresh_schema_cache, remove_card_from_dashboard, unfavorite_dashboard
Why it matters. 9 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, abort-controller, axios, @types/node, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:8
A **Model Context Protocol (MCP) server for Metabase** that gives AI assistants full access to your analytics platform — dashboards, cards, databases, tables, collections, and more.

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 0fdf25a6631afull audit observations/trust-audit/mcp-server/easecloudio__metabase-3.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-070fdf25a6631aSAFEB89first audit
06

Questions

What is the Metabase MCP server?

A comprehensive MCP server for Metabase with 70+ tools.

What tools does Metabase expose?

95 in total: 51 read-only, 35 that write, and 9 that can delete or overwrite (delete_card, delete_card_public_link, delete_collection, delete_dashboard, delete_dashboard_public_link). Every one is listed on this page with its risk.

Is Metabase safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 9 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Metabase need?

It reads METABASE_API_KEY and METABASE_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Metabase run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @easecloudio/mcp-metabase-server at 1.3.0.

How current is this page?

The grade is for one exact copy of the source (0fdf25a6631a), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement