Metabase includes a built-in Model Context Protocol (MCP) server that lets AI clients connect directly to a Metabase instance. It uses the Streamable HTTP transport and builds on Metabase's Agent API to expose tools for searching, exploring, querying, and visualizing data — all scoped to the connecting user's permissions.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Storybook Dev Server is Vulnerable to WebSocket Hijacking
ajv has ReDoS when using `$data` option
PostCSS has XSS via Unescaped </style> in its CSS Stringify Output
webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins
process.env. You'll be asked to provide them before it can run.BACKEND_PORTCLIENT_PORTCROSS_VERSION_DEV_MODECYPRESS_ALL_FEATURES_TOKENCYPRESS_BROWSERCYPRESS_GUICYPRESS_MB_ALL_FEATURES_TOKENCYPRESS_RETRIESCYPRESS_VIDEOENABLE_NETWORK_THROTTLINGENTERPRISE_TOKENFAIL_FASTFE_HEALTHCHECK_URLGITHUB_RUN_ATTEMPTGREPHOST_APP_ENVIRONMENTJAR_PATHJDK_JAVA_OPTIONSMB_ALL_FEATURES_TOKENMB_CUSTOM_VIZ_PLUGIN_DEV_MODE_ENABLEDMB_DB_FILEMB_EDITIONMB_ENABLE_TEST_LOCALESMB_FRONTEND_DEV_PORTMB_INTERNAL_DO_NOT_USE_SAMPLE_DB_DIRMB_JETTY_HOSTMB_JETTY_PORTMB_RUN_MODEMB_SNOWPLOW_URLMETABASE_INSTANCE_URLMETABASE_JWT_SHARED_SECRETMETASTORE_DEV_SERVER_URLNEXT_PUBLIC_MB_PORTNG_APP_MB_PORTSAMPLE_APP_ENVIRONMENTSDK_FIXUP_VERBOSE_LOGSSHOPPY_DATADOG_APPLICATION_IDSHOPPY_DATADOG_CLIENT_TOKENSHOPPY_DATADOG_ENVSHOPPY_DATADOG_SITE[](https://m8ven.ai/mcp/metabase-metabase-146479)