Write-enabled MCP server for Metabase with 28 tools covering read, write, and AI-driven insights operations.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
When Vitest UI server is listening, arbitrary file can be read and executed
process.env. You'll be asked to provide them before it can run.ALLOWED_SQL_PATTERNSANTHROPIC_API_KEY— No - Enables NLQ and insight toolsAUDIT_LOG_FILE— This extension does not retain any data. Audit logs (if enabled via ) are written to your local filesystem only, with owner-only permissions (0600)BLOCKED_SQL_PATTERNSLLM_DAILY_TOKEN_LIMITLLM_FALLBACK_MODELLLM_MODELLLM_MONTHLY_TOKEN_LIMITLLM_RETRY_ATTEMPTSLLM_RETRY_DELAY_MSLLM_TIMEOUT_MSLOG_LEVEL— No info Logging: debug, info, warn, errorMCP_AUTH_TOKENMCP_CORS_ORIGINMCP_HTTP_HOSTMCP_HTTP_PORTMCP_MODE— No read Server mode: read, write, or fullMCP_TOOLS_ALLOW— No - Comma-separated allowlist — only these tools are exposedMCP_TOOLS_DENY— No - Comma-separated denylist — these tools are never exposed (wins over allow)MCP_TRANSPORTMETABASE_API_KEY— Yes - Metabase API keyMETABASE_MAX_ROWS— No 10000 Max rows returned per queryMETABASE_TIMEOUT— No 30000 Request timeout (ms)METABASE_URL— Yes - Your Metabase instance URLRATE_LIMIT_LLM_PER_MINUTE— No 20 LLM-tier rate limitRATE_LIMIT_READ_PER_MINUTE— No 120 Read-tier rate limitRATE_LIMIT_REQUESTS_PER_MINUTE— No - Legacy: sets the read tier when RATE_LIMIT_READ_PER_MINUTE is unsetRATE_LIMIT_WRITE_PER_MINUTE— No 30 Write-tier rate limit[](https://m8ven.ai/mcp/ai-1luvc0d3-metabase-mcp-vfisv7)