{"id":40950756,"url":"https://github.com/txn2/mcp-data-platform","last_synced_at":"2026-07-26T19:01:05.835Z","repository":{"id":333772383,"uuid":"1137195822","full_name":"txn2/mcp-data-platform","owner":"txn2","description":"A semantic data platform MCP server that composes multiple data tools with bidirectional cross-injection - tool responses automatically include critical context from other services.","archived":false,"fork":false,"pushed_at":"2026-05-30T19:55:39.000Z","size":11615,"stargazers_count":6,"open_issues_count":8,"forks_count":1,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-05-30T21:20:07.533Z","etag":null,"topics":["data-analysis","data-lake","data-warehouse","golang","golang-library","mcp","mcp-server"],"latest_commit_sha":null,"homepage":"http://mcp-data-platform.txn2.com/","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/txn2.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":"SECURITY.md","support":"docs/support/troubleshooting.md","governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null},"funding":{"github":["cjimti"]}},"created_at":"2026-01-19T03:40:44.000Z","updated_at":"2026-05-30T19:54:49.000Z","dependencies_parsed_at":"2026-05-16T01:04:41.507Z","dependency_job_id":null,"html_url":"https://github.com/txn2/mcp-data-platform","commit_stats":null,"previous_names":["txn2/mcp-data-platform"],"tags_count":210,"template":false,"template_full_name":null,"purl":"pkg:github/txn2/mcp-data-platform","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/txn2%2Fmcp-data-platform","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/txn2%2Fmcp-data-platform/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/txn2%2Fmcp-data-platform/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/txn2%2Fmcp-data-platform/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/txn2","download_url":"https://codeload.github.com/txn2/mcp-data-platform/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/txn2%2Fmcp-data-platform/sbom","scorecard":{"id":1242065,"data":{"date":"2026-01-21T19:11:12Z","repo":{"name":"github.com/txn2/mcp-data-platform","commit":"f72d635ce3ecdd36a65b112f3dcce37e727b2a98"},"scorecard":{"version":"v5.3.0","commit":"c22063e786c11f9dd714d777a687ff7c4599b600"},"score":7.9,"checks":[{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#security-policy"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yml:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#dependency-update-tool"}},{"name":"Maintained","score":0,"reason":"project was created within the last 90 days. Please review its contents carefully","details":["Warn: Repository was created within the last 90 days."],"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#maintained"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#binary-artifacts"}},{"name":"Token-Permissions","score":10,"reason":"GitHub workflow tokens follow principle of least privilege","details":["Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:16","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:37","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:73","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:94","Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:19","Info: topLevel permissions set to 'read-all': .github/workflows/ci.yml:9","Info: topLevel permissions set to 'read-all': .github/workflows/codeql.yml:11","Info: topLevel 'contents' permission set to 'read': .github/workflows/docs.yml:14","Info: found token with 'none' permissions: .github/workflows/release.yml:1","Info: topLevel permissions set to 'read-all': .github/workflows/scorecard.yml:10","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#token-permissions"}},{"name":"Code-Review","score":0,"reason":"Found 0/27 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#code-review"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#dangerous-workflow"}},{"name":"Pinned-Dependencies","score":9,"reason":"dependency not pinned by hash detected -- score normalized to 9","details":["Warn: pipCommand not pinned by hash: .github/workflows/docs.yml:36","Info:  22 out of  22 GitHub-owned GitHubAction dependencies pinned","Info:  10 out of  10 third-party GitHubAction dependencies pinned","Info:   0 out of   1 pipCommand dependencies pinned","Info:   1 out of   1 containerImage dependencies pinned","Info:   1 out of   1 goCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#pinned-dependencies"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#license"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#cii-best-practices"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#packaging"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#vulnerabilities"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":8,"reason":"branch protection is not maximal on development and all release branches","details":["Info: 'allow deletion' disabled on branch 'main'","Info: 'force pushes' disabled on branch 'main'","Warn: 'branch protection settings apply to administrators' is disabled on branch 'main'","Info: 'stale review dismissal' is required to merge on branch 'main'","Warn: required approving review count is 1 on branch 'main'","Warn: codeowners review is not required on branch 'main'","Info: 'last push approval' is required to merge on branch 'main'","Info: 'up-to-date branches' is required to merge on branch 'main'","Info: status check found to merge onto on branch 'main'","Info: PRs are required in order to make changes on branch 'main'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#branch-protection"}},{"name":"SAST","score":10,"reason":"SAST tool is run on all commits","details":["Info: SAST configuration detected: CodeQL","Info: all commits (5) are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#sast"}},{"name":"Fuzzing","score":10,"reason":"project is fuzzed","details":["Info: GoBuiltInFuzzer integration found: pkg/auth/fuzz_test.go:11","Info: GoBuiltInFuzzer integration found: pkg/auth/fuzz_test.go:42","Info: GoBuiltInFuzzer integration found: pkg/auth/fuzz_test.go:76","Info: GoBuiltInFuzzer integration found: pkg/auth/fuzz_test.go:101","Info: GoBuiltInFuzzer integration found: pkg/middleware/fuzz_test.go:10","Info: GoBuiltInFuzzer integration found: pkg/middleware/fuzz_test.go:32","Info: GoBuiltInFuzzer integration found: pkg/middleware/fuzz_test.go:49","Info: GoBuiltInFuzzer integration found: pkg/oauth/fuzz_test.go:58","Info: GoBuiltInFuzzer integration found: pkg/oauth/fuzz_test.go:101","Info: GoBuiltInFuzzer integration found: pkg/oauth/fuzz_test.go:122","Info: GoBuiltInFuzzer integration found: pkg/platform/fuzz_test.go:10","Info: GoBuiltInFuzzer integration found: pkg/platform/fuzz_test.go:78","Info: GoBuiltInFuzzer integration found: pkg/platform/fuzz_test.go:96"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#fuzzing"}},{"name":"Contributors","score":10,"reason":"project has 4 contributing companies or organizations","details":["Info: found contributions from: DeasilCognitive, apk8s, deasilworks, txn2"],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#contributors"}},{"name":"CI-Tests","score":10,"reason":"5 out of 5 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#ci-tests"}}]},"last_synced_at":"2026-01-21T19:37:39.785Z","repository_id":333772383,"created_at":"2026-01-21T19:37:39.785Z","updated_at":"2026-01-21T19:37:39.785Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":33717419,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-05-31T02:00:06.040Z","response_time":95,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["data-analysis","data-lake","data-warehouse","golang","golang-library","mcp","mcp-server"],"created_at":"2026-01-22T05:11:57.646Z","updated_at":"2026-07-26T19:01:05.794Z","avatar_url":"https://github.com/txn2.png","language":"Go","funding_links":["https://github.com/sponsors/cjimti"],"categories":[],"sub_categories":[],"readme":"[![txn2/mcp-data-platform](docs/images/MCP-data-platform-logo-banner.svg)](https://mcp-data-platform.txn2.com)\n\n[![GitHub license](https://img.shields.io/github/license/txn2/mcp-data-platform.svg)](https://github.com/txn2/mcp-data-platform/blob/main/LICENSE)\n[![Go Reference](https://pkg.go.dev/badge/github.com/txn2/mcp-data-platform.svg)](https://pkg.go.dev/github.com/txn2/mcp-data-platform)\n[![MCP](https://img.shields.io/badge/MCP-Model_Context_Protocol-blue)](https://modelcontextprotocol.io)\n[![Release](https://img.shields.io/github/v/release/txn2/mcp-data-platform)](https://github.com/txn2/mcp-data-platform/releases/latest)\n[![CI](https://github.com/txn2/mcp-data-platform/actions/workflows/ci.yml/badge.svg)](https://github.com/txn2/mcp-data-platform/actions/workflows/ci.yml)\n[![CodeQL](https://github.com/txn2/mcp-data-platform/actions/workflows/codeql.yml/badge.svg)](https://github.com/txn2/mcp-data-platform/actions/workflows/codeql.yml)\n[![codecov](https://codecov.io/gh/txn2/mcp-data-platform/graph/badge.svg)](https://codecov.io/gh/txn2/mcp-data-platform)\n[![OpenSSF Best Practices](https://www.bestpractices.dev/projects/13548/badge)](https://www.bestpractices.dev/projects/13548)\n[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/txn2/mcp-data-platform/badge)](https://scorecard.dev/viewer/?uri=github.com/txn2/mcp-data-platform)\n[![Signed by Cosign](https://img.shields.io/badge/artifacts-signed_by_cosign-blue?logo=sigstore\u0026logoColor=white)](https://github.com/sigstore/cosign)\n[![Docker](https://img.shields.io/badge/ghcr.io-txn2%2Fmcp--data--platform-blue?logo=docker)](https://github.com/txn2/mcp-data-platform/pkgs/container/mcp-data-platform)\n[![DOI](https://zenodo.org/badge/DOI/10.5281/zenodo.21438044.svg)](https://doi.org/10.5281/zenodo.21438044)\n\n**[Documentation](https://mcp-data-platform.txn2.com/)** | **[Installation](https://mcp-data-platform.txn2.com/server/installation/)** | **[Quick Start](#quick-start)** | **[Go Library](https://mcp-data-platform.txn2.com/library/overview/)**\n\n**Your AI assistant can run SQL. But it doesn't know that `cust_id` contains PII, that the table was deprecated last month, or who to ask when something breaks.**\n\nmcp-data-platform fixes that. It is a single MCP server that connects AI assistants to your data infrastructure and enriches every response with business context from your semantic layer: query a table and get its meaning, owners, quality scores, and deprecation warnings in the same call.\n\nIt is a platform, not just a bridge. The same endpoint gives agents persistent memory and a governed path to write knowledge back to the catalog, proxies third-party MCP servers and REST APIs through one authentication, persona, and audit pipeline, and ships a web portal where AI-generated assets are saved, organized into collections, and shared with teammates.\n\nCross-enrichment is what [DataHub](https://datahubproject.io/) is for: point the platform at it as the semantic layer, then add [Trino](https://trino.io/) for SQL and [S3](https://aws.amazon.com/s3/) for object storage when you're ready. [Learn why this stack.](https://mcp-data-platform.txn2.com/concepts/components/)\n\nNo data warehouse and no catalog? The gateways, knowledge layer, memory, portal, and `search`/`fetch` are database-backed and run without DataHub or Trino, on PostgreSQL alone. See [Deployment Shapes](https://mcp-data-platform.txn2.com/server/deployment-shapes/) for what each shape gives you.\n\n---\n\n## Why\n\nAI assistants are powerful at querying data, but they work blind. When an agent asks \"What's in the orders table?\", it gets column names and types. It doesn't know that `customer_id` is PII, that the table is deprecated in favor of `orders_v2`, that the quality score dropped last week, or who to contact when something looks wrong.\n\n```\n# Without mcp-data-platform\n─────────────────────────────────────────────────────────────────────\nUser:      \"Describe the orders table\"\nAI:        Queries Trino → gets columns and types\nUser:      \"Who owns this data?\"\nAI:        Queries DataHub → finds owners\nUser:      \"Is this table still active?\"\nAI:        Queries DataHub again → finds deprecation status\nUser:      \"What does customer_id actually mean?\"\nAI:        Queries DataHub again → finds column descriptions\n─────────────────────────────────────────────────────────────────────\n4 round trips. Context scattered across conversations. Easy to miss warnings.\n```\n\n```\n# With mcp-data-platform\n─────────────────────────────────────────────────────────────────────\nUser:      \"Describe the orders table\"\nAI:        Gets everything in one response:\n           → Schema: columns and types\n           → ⚠️ DEPRECATED: Use orders_v2 instead\n           → Owners: Data Platform Team\n           → Tags: pii, financial\n           → Quality Score: 87%\n           → Column meanings and business definitions\n─────────────────────────────────────────────────────────────────────\n1 call. Complete context. Warnings front and center.\n```\n\n## How It Works\n\n```mermaid\nsequenceDiagram\n    participant AI as AI Assistant\n    participant P as mcp-data-platform\n    participant T as Trino\n    participant D as DataHub\n\n    AI-\u003e\u003eP: trino_describe_table \"orders\"\n    P-\u003e\u003eT: DESCRIBE orders\n    T--\u003e\u003eP: columns, types\n    P-\u003e\u003eD: Get semantic context\n    D--\u003e\u003eP: description, owners, tags, quality, deprecation\n    P--\u003e\u003eAI: Schema + Full Business Context\n```\n\nThe platform intercepts tool responses at the protocol level and enriches them with context from the other services. This **cross-enrichment** is bidirectional:\n\n- **Trino → DataHub**: query results include owners, tags, glossary terms, deprecation warnings, quality scores\n- **DataHub → Trino**: search results include query availability and sample SQL\n- **S3 ↔ DataHub**: object listings include matching dataset metadata, and dataset searches show storage availability\n\n## Does it work? Measured effectiveness\n\nThe knowledge layer is not just a design claim; it is benchmarked. On knowledge-trap questions, the ones an agent answers plausibly but wrongly without business context, connecting the agent to the platform's semantic knowledge layer lifts accuracy from **42.7% (raw data tools) to 98.7%**, a **+56-point** gain (95% CI +44 to +67). On plain lookups and arithmetic, where no business context is needed, the platform and bare tools are statistically tied, so the gain is specific to knowledge-gated questions, not a blanket accuracy boost.\n\nThis is an **arm-vs-arm** result on a single pinned model (same model, same tasks, only the platform configuration changes). It measures the **knowledge layer** specifically, that is cross-enrichment, `search`, and the memory/`apply_knowledge` lifecycle, not the whole platform. Every number is recomputed from committed raw data by a notebook that needs no API key. See the full, citable [Benchmark Report](https://mcp-data-platform.txn2.com/reference/benchmark-report/) (four-arm ablation, cold-start learning curve, lifecycle scorecard, threats to validity) and the [operator manual](bench/README.md).\n\n## Features\n\nEach feature links to its full documentation.\n\n### Semantic data access\n\n| Feature | Description |\n|---------|-------------|\n| [Cross-enrichment](https://mcp-data-platform.txn2.com/cross-enrichment/overview/) | Business context added to every tool response automatically, with session dedup to save tokens |\n| [Lineage inheritance](https://mcp-data-platform.txn2.com/cross-enrichment/lineage/) | Column descriptions inherited from upstream datasets via DataHub lineage |\n| [Universal search](https://mcp-data-platform.txn2.com/knowledge/overview/) | One `search` tool fans a query across the catalog, knowledge pages, memory, insights, assets, prompts, and APIs; `fetch` dereferences any result |\n| [Workflow gating](https://mcp-data-platform.txn2.com/reference/middleware/) | Session-aware guidance that steers agents to discovery before SQL, with escalating warnings |\n| [Tools](https://mcp-data-platform.txn2.com/server/tools/) | Full tool reference for Trino, DataHub, S3, knowledge, memory, portal, and gateway toolkits |\n\n### Knowledge and memory\n\n| Feature | Description |\n|---------|-------------|\n| [Memory layer](https://mcp-data-platform.txn2.com/memory/overview/) | Persistent agent memory across sessions, PostgreSQL + pgvector, hybrid semantic/lexical recall |\n| [Knowledge capture](https://mcp-data-platform.txn2.com/knowledge/overview/) | Agents record domain insights during sessions; approved knowledge is written back to DataHub or canonical knowledge pages |\n| [Governance workflow](https://mcp-data-platform.txn2.com/knowledge/governance/) | Human-in-the-loop review, approve/reject, changeset tracking, and rollback for every applied change |\n| [Managed resources](https://mcp-data-platform.txn2.com/server/portal-user/#resources) | Human-uploaded reference files (playbooks, samples, templates) served to agents as MCP resources |\n\n### Gateways and extensibility\n\n| Feature | Description |\n|---------|-------------|\n| [MCP gateway](https://mcp-data-platform.txn2.com/server/gateway/) | Re-expose any third-party MCP server through the platform's auth, persona, and audit pipeline |\n| [API gateway](https://mcp-data-platform.txn2.com/server/api-gateway/) | Proxy REST/HTTP APIs (Salesforce, Google, GitHub, Stripe) with four tools instead of one tool per endpoint |\n| [API catalogs](https://mcp-data-platform.txn2.com/server/api-catalogs/) | Versioned OpenAPI bundles shared across connections, with semantic endpoint ranking |\n| [REST invoke shim](https://mcp-data-platform.txn2.com/server/api-gateway/#rest-gateway-for-non-mcp-clients) | Call gateway endpoints from NiFi, Airflow, or `curl` under the same auth and audit pipeline |\n| [Self-configuration](https://mcp-data-platform.txn2.com/server/self-configuration/) | Admins manage personas, connections, and prompts by asking the agent instead of clicking |\n| [MCP Apps](https://mcp-data-platform.txn2.com/mcpapps/overview/) | Interactive UI panels rendered inline in the MCP host |\n| [Go library](https://mcp-data-platform.txn2.com/library/overview/) | Import the platform as a library: custom toolkits, providers, and middleware |\n\n### Security and operations\n\n| Feature | Description |\n|---------|-------------|\n| [Authentication](https://mcp-data-platform.txn2.com/auth/overview/) | Fail-closed model: OIDC (Keycloak, Auth0, Okta, Azure AD) and API keys for service accounts |\n| [OAuth 2.1 server](https://mcp-data-platform.txn2.com/auth/oauth-server/) | Built-in authorization server with PKCE and Dynamic Client Registration; Claude signs in through your IdP |\n| [Outbound OAuth](https://mcp-data-platform.txn2.com/auth/oauth-gateway/) | OAuth to upstream MCPs and APIs with encrypted refresh tokens that survive restarts |\n| [Personas](https://mcp-data-platform.txn2.com/personas/overview/) | Role-mapped allow/deny tool and connection filtering, default-deny |\n| [Audit logging](https://mcp-data-platform.txn2.com/server/audit/) | Every tool call logged to PostgreSQL with identity, persona, sanitized parameters, and timing |\n| [Observability](https://mcp-data-platform.txn2.com/server/observability/) | Prometheus metrics and optional OpenTelemetry distributed tracing |\n| [Session externalization](https://mcp-data-platform.txn2.com/server/session-externalization/) | PostgreSQL-backed sessions for zero-downtime restarts, horizontal scaling, and live tool-inventory updates |\n| [Explicit session handles](https://mcp-data-platform.txn2.com/server/configuration/#explicit-session-handles) | `platform_info` mints a `session_id` the agent threads on every call, making orientation unskippable and readying the platform for the sessionless MCP 2026-07-28 protocol |\n| [Multi-provider](https://mcp-data-platform.txn2.com/server/multi-provider/) | Multiple instances of each service behind one endpoint, with isolated failure domains |\n| [Operating modes](https://mcp-data-platform.txn2.com/server/operating-modes/) | Standalone (no database) or file + database with hot-reloaded config overrides |\n| [Deployment shapes](https://mcp-data-platform.txn2.com/server/deployment-shapes/) | Which backends you need: the semantic stack for cross-enrichment, PostgreSQL alone for the gateways and knowledge layer, or both |\n| [Email notifications](https://mcp-data-platform.txn2.com/server/notifications/) | Branded emails for shares and feedback: admin-configured SMTP, per-user preferences (immediate, daily digest, or off), durable queue with retries |\n\n## The Portal\n\nA built-in web portal serves both operators and end users. Enable with `portal.enabled: true`.\n\n**For operators**: dashboards with activity timelines and performance percentiles, a searchable audit log, an interactive tool explorer with per-persona visibility and inline test runs, knowledge insight governance, connection and persona management, API keys, and indexing health. See the [Admin Portal guide](https://mcp-data-platform.txn2.com/server/admin-portal/).\n\n![Admin Dashboard](docs/images/screenshots/light/admin-admin-dashboard-light.webp)\n\n**For users**: AI-generated assets (reports, charts, documents) are saved from any session with the `save_asset` tool, organized into shareable [collections](https://mcp-data-platform.txn2.com/server/portal-user/#collections), and shared with teammates or through public links. A [prompt library](https://mcp-data-platform.txn2.com/server/portal-user/#prompts), [feedback threads](https://mcp-data-platform.txn2.com/server/portal-user/#feedback) on any asset, and personal knowledge and activity views round out the [User Portal](https://mcp-data-platform.txn2.com/server/portal-user/).\n\n![Collections](docs/images/screenshots/light/user-collection-view-light.webp)\n\n## Quick Start\n\nInstall (see [all methods](https://mcp-data-platform.txn2.com/server/installation/): Homebrew, Docker, source):\n\n```bash\ngo install github.com/txn2/mcp-data-platform/cmd/mcp-data-platform@latest\n```\n\nCreate a minimal configuration. This one wires the semantic layer, which is what cross-enrichment needs; `${VAR}` references are expanded from the environment:\n\n```yaml\n# platform.yaml\nserver:\n  name: mcp-data-platform\n  transport: stdio\n\nsemantic:\n  provider: datahub\n  instance: primary\n\ntoolkits:\n  datahub:\n    enabled: true\n    instances:\n      primary:\n        url: \"${DATAHUB_URL}\"\n        token: \"${DATAHUB_TOKEN}\"\n    default: primary\n```\n\nWire it to Claude Code:\n\n```bash\nclaude mcp add data-platform \\\n  -e DATAHUB_URL=https://datahub.example.com/api/graphql \\\n  -e DATAHUB_TOKEN=$TOKEN \\\n  -- mcp-data-platform --config platform.yaml\n```\n\nStarting without a warehouse or catalog? Swap the `semantic:` and `toolkits:` blocks above for a database and the API toolkit, and the gateways, knowledge layer, memory, portal, and `search`/`fetch` come up on PostgreSQL alone:\n\n```yaml\n# platform.yaml\nserver:\n  name: mcp-data-platform\n  transport: http\n  address: \":8080\"\n\ndatabase:\n  dsn: \"${DATABASE_URL}\"\n\n# API connections are authored in the admin portal, not in YAML.\ntoolkits:\n  api:\n    enabled: true\n```\n\n[Deployment Shapes](https://mcp-data-platform.txn2.com/server/deployment-shapes/) covers the full configuration, what each shape includes, and what it leaves out.\n\nFor a hosted deployment, run `--transport http` and enable the built-in OAuth 2.1 server so Claude and other MCP clients sign in through your identity provider. See [Configuration](https://mcp-data-platform.txn2.com/server/configuration/), [Deployment](https://mcp-data-platform.txn2.com/server/deployment/) (Docker Compose, Kubernetes), and the [OAuth 2.1 Server guide](https://mcp-data-platform.txn2.com/auth/oauth-server/).\n\n## Security\n\nThe platform implements a **fail-closed** security model: missing or invalid credentials deny access, never bypass. Personas are default-deny, Trino and S3 support enforced read-only mode, and metadata is sanitized against prompt injection. See the [Auth Overview](https://mcp-data-platform.txn2.com/auth/overview/) and [MCP Defense: A Case Study in AI Security](https://imti.co/mcp-defense/) for the architecture rationale.\n\n| Transport | Authentication | TLS |\n|-----------|----------------|-----|\n| **stdio** | Not required (local execution) | N/A |\n| **HTTP** | Required (Bearer token or API key) | Strongly recommended |\n\n## Ecosystem\n\nmcp-data-platform is the orchestration layer for a suite of open-source MCP servers that also run standalone:\n\n- [txn2/mcp-datahub](https://github.com/txn2/mcp-datahub/): DataHub metadata: search, lineage, glossary, domains, tags, ownership\n- [txn2/mcp-trino](https://github.com/txn2/mcp-trino/): Trino distributed SQL with configurable timeouts and row limits\n- [txn2/mcp-s3](https://github.com/txn2/mcp-s3/): S3 object storage: buckets, prefixes, objects, presigned URLs\n\nSee [Ecosystem](https://mcp-data-platform.txn2.com/ecosystem/) for how they compose.\n\n## Documentation\n\nFull documentation lives at [mcp-data-platform.txn2.com](https://mcp-data-platform.txn2.com/).\n\n- [Server Guide](https://mcp-data-platform.txn2.com/server/overview/): architecture, configuration, deployment\n- [Cross-Enrichment](https://mcp-data-platform.txn2.com/cross-enrichment/overview/): how automatic enrichment works\n- [Authentication](https://mcp-data-platform.txn2.com/auth/overview/): OIDC, API keys, OAuth 2.1\n- [Knowledge Capture](https://mcp-data-platform.txn2.com/knowledge/overview/) and [Memory](https://mcp-data-platform.txn2.com/memory/overview/): the agent knowledge loop\n- [Go Library](https://mcp-data-platform.txn2.com/library/overview/): build custom MCP servers ([API stability policy](https://mcp-data-platform.txn2.com/library/stability/))\n- [Tools API Reference](https://mcp-data-platform.txn2.com/reference/tools-api/): complete tool specifications\n- [Examples Gallery](https://mcp-data-platform.txn2.com/examples/): real-world configurations\n- [Troubleshooting](https://mcp-data-platform.txn2.com/support/troubleshooting/): common issues and debugging\n\n## Development\n\n```bash\ngo build -o mcp-data-platform ./cmd/mcp-data-platform   # build\ngo test -race ./...                                     # tests\nmake verify                                             # full CI-equivalent suite\nmake osv                                                # osv-scanner, informational (mirrors OpenSSF Scorecard)\n```\n\n`make verify` runs `govulncheck`, which does reachability analysis and reports only vulnerabilities your code actually calls. `make osv` runs [osv-scanner](https://github.com/google/osv-scanner) the way [OpenSSF Scorecard](https://securityscorecards.dev/) does, flagging every vulnerable package in the dependency graph regardless of reachability. It is informational and not part of `verify`; suppressions for non-reachable and test-only findings are documented with justification and expiry in [`osv-scanner.toml`](osv-scanner.toml).\n\nThe React admin portal lives under [`ui/`](ui/README.md). Its CI job runs\n`npm run lint`, which enforces per-function complexity budgets that mirror the\nGo gates (`complexity \u003c= 10` ≈ `gocyclo \u003c= 10`, `cognitive-complexity \u003c= 15` ≈\n`gocognit \u003c= 15`) plus an import-cycle rule. See [`ui/README.md`](ui/README.md)\nfor the thresholds and the ratchet baseline.\n\nTwo measurement harnesses live outside `make verify` (each is its own Go\nmodule): [`test/load`](test/load/README.md) measures throughput and resource\nlimits (\"how much\"), and [`bench/`](bench/README.md) measures agent\neffectiveness — arm-ablated accuracy and efficiency with audit-derived metrics\n(\"how well\"). Run them via `make load-*` and `make bench-*` targets.\n\nContributions for bug fixes, tests, and documentation are welcome. Please run `make verify` (formatting, race-detected tests, coverage, linting, security scanning) before opening a pull request.\n\n## License\n\n[Apache License 2.0](LICENSE)\n\n---\n\nOpen source by [Craig Johnston](https://imti.co/about/), sponsored by [Deasil Works, Inc.](https://deasil.works/) and [Plexara](https://plexara.io)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftxn2%2Fmcp-data-platform","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftxn2%2Fmcp-data-platform","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftxn2%2Fmcp-data-platform/lists"}