Metabase MCP Server (thangnm93/metabase-mcp-server) is an MCP server listed on the M8ven Trust Index. It scores 42 out of 100, grade D. It declares 87 tools. No publisher has claimed this listing.
Provides AI assistants with full access to Metabase analytics platform, enabling dashboard and card management, database queries, and schema operations through natural language.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
thangnm93
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
get_collection_itemsRetrieve all items (cards, dashboards) within a Metabase collection - use this to explore collection contents, organize analytical assets, or understand content structure
move_to_collectionMove a Metabase card or dashboard to a different collection - use this to reorganize content, implement governance policies, or clean up analytical assets
search_contentSearch across all Metabase content including cards, dashboards, collections, and models - use this to find specific content, discover assets, or explore analytical resources
list_collectionsRetrieve all Metabase collections for organizing analytical content - use this to understand content structure, find collections, or explore organizational hierarchy
create_collectionCreate a new Metabase collection for organizing analytical content - use this to establish organizational containers for cards, dashboards, and reports
update_collectionUpdate collection properties including name, description, and organization - use this to maintain metadata, reorganize hierarchies, or update structure
delete_collectionPermanently delete a Metabase collection - use with caution as this affects contained content and cannot be undone
list_usersRetrieve all Metabase users with their roles and permissions - use this to understand user access, manage permissions, or audit accounts
get_metabase_playground_linkGenerate a Metabase playground link for interactive query exploration - allows users to see results and experiment with data in a user-friendly interface
list_cardsRetrieve all Metabase cards with optional filtering by source type (e.g., 'models') or model relationships - use this to discover available cards, find specific cards by type, or get an overview of all analytical content
get_cardGet complete metadata and configuration for a specific Metabase card including query definition, visualization settings, collection location, and permissions - use this when you need to examine or understand how a particular card is built
create_cardCreate a new Metabase card with custom query, visualization type, and settings - use this to programmatically build new analytical cards, dashboards charts, or data exploration queries
update_cardModify an existing Metabase card's name, description, query definition, visualization type, or settings - use this to fix broken cards, change chart types, update queries, or move cards between collections
delete_cardRemove a Metabase card either by archiving (soft delete, preserves history) or permanent deletion - use this to clean up unused cards, remove broken cards, or organize analytical content
execute_cardRun a Metabase card query and return the actual data results - use this to get current data from existing cards, refresh analytical insights, or programmatically access query results for further processing
export_card_resultExecute a Metabase card and export the results in a specific format (CSV, Excel, JSON, etc.) - use this to download data for external analysis, create reports for stakeholders, or integrate query results with other systems
copy_cardCreate a duplicate copy of an existing Metabase card with identical query and settings - use this to create variations of existing cards, build templates for similar analyses, or backup important queries before modifications
get_card_dashboardsFind all dashboards that include a specific Metabase card - use this to understand where a card is being used, track dependencies before making changes, or find related analytical content
list_embeddable_cardsRetrieve all Metabase cards configured for embedding in external applications (requires admin privileges) - use this to audit embedded content, manage external integrations, or review public-facing analytics
create_card_public_linkGenerate a publicly accessible URL for a Metabase card that can be viewed without authentication (requires admin privileges) - use this to share analytical insights with external stakeholders, create public reports, or embed charts in websites
delete_card_public_linkRemove public access to a Metabase card by deleting its public URL (requires admin privileges) - use this to revoke external access to sensitive data, clean up unused public links, or update security permissions
list_public_cardsRetrieve all Metabase cards that have public URLs enabled (requires admin privileges) - use this to audit publicly accessible content, review security settings, or manage external data sharing
move_cardsRelocate multiple Metabase cards to a different collection or dashboard for better organization - use this to reorganize analytical content, group related cards, or clean up workspace structure
move_cards_to_collectionBulk transfer multiple Metabase cards to a specific collection for organizational purposes - use this to categorize cards by team, project, or topic, or to implement content governance policies
execute_pivot_card_queryRun a Metabase card with pivot table formatting to cross-tabulate data with rows and columns - use this to create summary tables, analyze data relationships, or generate matrix-style reports from existing cards
get_card_param_valuesRetrieve all available values for a specific parameter in a Metabase card - use this to populate dropdown filters, validate parameter inputs, or understand what data options are available for interactive cards
search_card_param_valuesSearch and filter available parameter values for a Metabase card using a text query - use this to find specific parameter options in large datasets, help users locate filter values, or implement autocomplete functionality
get_card_param_remappingRetrieve how parameter values are remapped or transformed for display in a Metabase card - use this to understand data transformations, debug parameter issues, or see how raw values are presented to users
get_card_query_metadataRetrieve structural metadata about a Metabase card's underlying query including column types, field information, and data schema - use this to understand card structure, validate data types, or build dynamic interfaces
get_card_seriesRetrieve time series data or related card suggestions for a Metabase card - use this to get chronological data trends, find similar cards, or discover related analytical content for dashboard building
list_dashboardsRetrieve all Metabase dashboards - use this to discover available dashboards, get an overview of analytical content, or find specific dashboards
get_dashboardRetrieve detailed information about a specific Metabase dashboard including cards, layout, and settings - use this to examine dashboard structure or get configuration details
get_dashboard_cardsRetrieve all cards within a specific Metabase dashboard - use this to analyze dashboard content, understand data sources, or examine card configurations
get_dashboard_relatedRetrieve entities related to a Metabase dashboard - use this to discover related content, find similar analytical views, or understand dashboard relationships
get_dashboard_revisionsRetrieve revision history for a Metabase dashboard - use this to track dashboard evolution, review past changes, or restore previous versions
list_embeddable_dashboardsRetrieve all Metabase dashboards configured for embedding (requires superuser) - use this to audit embedded content or manage external integrations
list_public_dashboardsRetrieve all Metabase dashboards with public URLs enabled (requires superuser) - use this to audit publicly accessible content or review security settings
create_dashboardCreate a new Metabase dashboard - use this to build new analytical views, organize related cards, or establish monitoring interfaces
create_public_linkGenerate publicly accessible URL for a dashboard (requires superuser) - use this for external reporting, client dashboards, or public data sharing
copy_dashboardCreate a copy of an existing dashboard with all cards and layout - use this to create templates, backups, or variations of analytical views
add_card_to_dashboardAdd an existing card to a dashboard with optional parameter mappings - use this to build comprehensive dashboards by combining multiple visualizations
add_text_blockAdd a text block or heading to a dashboard - use this for explanatory text, titles, or instructions
favorite_dashboardMark a dashboard as favorite for quick access - use this to bookmark frequently accessed analytical views
revert_dashboardRestore a dashboard to a specific previous revision - use this to undo changes, restore deleted content, or return to known good configuration
save_dashboardSave a complete dashboard object with nested data - use this for bulk operations or complex dashboard structures
save_dashboard_to_collectionSave a dashboard object directly into a specific collection - use this for organized dashboard creation or bulk imports
update_dashboardUpdate dashboard properties including name, description, parameters, and settings - use this to maintain metadata, reorganize content, or configure sharing
update_dashboard_cards⚠️ DANGER: REPLACES ALL dashboard cards - any cards not in the array will be DELETED. To update a single card, first get_dashboard to fetch ALL cards, then include ALL of them with your modifications. This affects ALL tabs.
delete_dashboardDelete or archive a dashboard (soft or hard delete) - use with caution as permanent deletion cannot be undone
delete_public_linkRemove public URL access for a dashboard (requires superuser) - use this to revoke external access for security or privacy reasons
remove_cards_from_dashboardRemove specific dashcards from a dashboard by their dashcard IDs (not card_id) - use this to clean up dashboards or reorganize content
unfavorite_dashboardRemove a dashboard from the user's favorites list - use this to clean up bookmarked dashboards
execute_dashboard_cardExecute a specific card from a dashboard and retrieve fresh data - use this to get current results from dashboard components or test card functionality
search_dashboardsSearch dashboards by name or description text - use this to find specific dashboards or discover related analytical content
update_dashcardUpdate a specific dashcard's properties without affecting other cards - use for parameter_mappings, visualization_settings, position, or size changes. Much safer than update_dashboard_cards.
get_dashboard_queriesExtract all queries from a dashboard with IDs resolved to actual table/column names - use this to understand dashboard data sources, audit queries, or plan migrations
audit_dashboard_filtersAnalyze dashboard filter connections to find unconnected or misconfigured cards - use this to diagnose filter issues and ensure all cards are properly connected
list_databasesRetrieve all database connections in Metabase - use this to discover available data sources, check connection status, or get an overview of connected databases
get_databaseRetrieve detailed information about a specific Metabase database including connection details and schema - use this to examine database properties or troubleshoot connections
create_databaseAdd a new database connection to Metabase - use this to connect new data sources, establish analytical pipelines, or expand data access
update_databaseUpdate database configuration including name, connection details, and sync settings - use this to maintain connections, update credentials, or modify sync behavior
delete_databasePermanently remove a database from Metabase - use with caution as this will break dependent content and cannot be undone
validate_databaseTest database connection parameters before creating - use this to verify credentials, connectivity, and accessibility
add_sample_databaseAdd the built-in Metabase sample database with demo data - use this for testing, learning, or exploring Metabase features
check_database_healthPerform health check on database connection - use this to diagnose issues, monitor status, or troubleshoot sync problems
get_database_metadataRetrieve comprehensive database metadata including tables, fields, and relationships - use this to understand structure or build dynamic queries
list_database_schemasRetrieve all schema names in a database - use this to explore database organization or navigate multi-schema databases
get_database_schemaRetrieve detailed information about a specific schema including tables and objects - use this to explore schema contents or understand organization
execute_queryExecute a native SQL query against a Metabase database - use this for custom data analysis, complex queries, or extracting specific data not available through existing cards
sync_database_schemaInitiate schema sync to update Metabase metadata cache - use this after database changes to recognize new tables, columns, or relationships
list_tablesRetrieve all Metabase tables with optional ID filtering - use this to discover available tables, explore database schema, or get metadata about specific tables
update_tablesBulk update multiple Metabase tables with same configuration - use this to apply consistent settings, update metadata, or modify table properties efficiently
get_tableRetrieve comprehensive table information including schema, fields, and metadata - use this to understand structure, explore fields, or get configuration details
update_tableUpdate table configuration including display name, description, and field settings - use this to customize presentation, update metadata, or configure data model
get_table_fksRetrieve foreign key relationships for a table - use this to understand data connections, build joins, or explore table dependencies
get_table_query_metadataRetrieve query-optimized table metadata for building dynamic queries - use this when constructing queries or building query interfaces
get_table_relatedFind tables and entities related through relationships or schemas - use this to discover connected data, find related content, or understand context
get_card_table_fksRetrieve foreign keys for a card's virtual table - use this to understand relationships in card-based queries or saved question tables
get_card_table_query_metadataRetrieve query metadata for a card's virtual table - use this to build queries on top of saved questions or treat cards as queryable tables
append_csv_to_tableAdd new rows from CSV content to existing table - use this for incremental data loading, updates, or importing additional records
discard_table_field_valuesClear cached field values to force fresh data loading - use this when table data has changed or cached values are stale
reorder_table_fieldsChange display order of table fields for better organization - use this to arrange fields logically, group columns, or improve presentation
replace_table_csvCompletely replace table data with new CSV content - use this for full data refreshes, model updates, or complete table replacements
rescan_table_field_valuesTrigger rescan to refresh field values cache with current data - use this to update dropdown options, statistics, or filter values
sync_table_schemaInitiate schema sync for specific table to update metadata - use this when table structure has changed and needs recognition
get_table_dataRetrieve sample data from table for preview and analysis - use this to examine content, verify quality, or understand data patterns
get_field_idLook up a field's ID and metadata by table and column name - essential for building parameter mappings. Returns field_id, base_type, and other metadata needed for filter connections.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
Axios: Header Injection via Prototype Pollution
METABASE_API_KEY1. Set METABASE_URL andMETABASE_PASSWORD2. Set METABASE_URL, METABASE_USERNAME,METABASE_URL1. Set and METABASE_API_KEYMETABASE_USERNAME2. Set METABASE_URL, , METABASE_PASSWORDTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
87/87 tools missing one or more hints — get_collection_items (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); move_to_collection (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); search_content (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +84 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tests exist
No test files found
Add tests that exercise each declared tool.
Secrets never reach shell commands
1 secret value passed to a subprocess as an argument — no shell is invoked, so there is nothing to inject into
Never pass secrets through shell commands. Use library APIs that accept credentials as arguments.
Production dependencies are patched
0 critical, 12 high severity in production deps — @modelcontextprotocol/sdk@0.6.1 (high), axios@1.13.2 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dependency freshness
1/6 production deps stale: abort-controller@2023-07-12 (3.1y)
Domain consistency
npm scope @cognitionai doesn't match GitHub owner thangnm93
Use the same org name across GitHub, npm, and your homepage so users can verify the publisher.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/thangnm93/metabase-mcp-server)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check