Metabase
Integrates
Questions, dashboards and queries, through the MCP server built into your own Metabase, connected with OAuth.
What a member can do
With Metabase connected, a member can search and read what your Metabase holds (collections, dashboards, questions, models, metrics, databases and tables), build and run queries, and create or change questions, dashboards and collections. It sees only what its Metabase user may see.
Each task names the Metabase tools it may call. metabase on a task means every tool your Metabase's server
offers; a single tool is named after the prefix, metabase.<tool>, as the server names it. A tool the task does
not name is refused, whatever the connection allows. If your Metabase does not answer when a run starts, the run
carries on rather than failing, and its log records tool.not_offered.
Who connects it
Metabase's MCP server signs clients in with Metabase's own OAuth, so a Metabase connection acts as the Metabase user who approved it when it was connected, with that user's permissions. Every question it saves and every query it runs is that user's.
A connection can sit on the enterprise, a team, a member, a role or a task, and the one further down replaces the one above: task, then role, then member, then team, then enterprise. Connect a member's own while Metabase is signed in as the member's own Metabase user, and what it creates is under its own name, limited to its own groups' permissions. Connect it while signed in as yourself, and it can do everything you can.
A connection on anything but a task also reaches the chat of every member it covers.
What waits for you
In a run, nothing in Metabase waits for you unless the task declares a gate on it. Metabase's write tools create and change questions, dashboards and collections, and run SQL with your database connection's own rights: gate the ones you want to approve first, or leave them off the task. See Gates and tool scopes.
In a chat, a Metabase tool that Metabase does not mark as read-only asks you before it runs, unless you chose Always allow for that member and tool.
Setup
Turn on Metabase's MCP server
In Metabase, as an admin:
- Admin → AI: turn AI features on. The MCP server needs them.
- Admin → AI → MCP: turn the MCP server on. If there is no MCP section, your version of Metabase has no MCP server: upgrade it first.
Zero Human OS reaches your Metabase over the internet, so it needs a public address, served over HTTPS, and its Site URL setting has to be that address: signing in with OAuth depends on it.
Connect it
Work in one browser window throughout: Metabase returns to the portal in the window you started from.
- In the portal, on the member's page → Tools (or Tools, for another layer), choose Add tool.
- Kind: MCP. Tool type:
metabase. - MCP server URL: your Metabase's address followed by
/api/metabase-mcp, such ashttps://metabase.example.com/api/metabase-mcp. - Auth: OAuth. Leave the client ID, client secret and scopes blank: Metabase registers Zero Human OS as a client by itself.
- Choose Connect with OAuth. Sign in to Metabase as the user the member should act as, and approve.
- Name the tools on the task,
metabasefor all of them or each by name. - Check it. Run a task that searches your Metabase. The run page shows the call and what Metabase returned, and in Metabase, Admin → AI → MCP → Authorizations lists the connection.
Giving a member its own Metabase user
Invite the member's Zero Human address as a Metabase user, in the groups whose data it should reach. If your Metabase sends email, the invitation appears in the Inbox on its member page in the portal. Set the account up in a separate browser profile or a private window, where Metabase is not signed in as you, then connect the member's binding from that same window, signed in to the portal as yourself.
Troubleshooting
| What you see | Why | What to do |
|---|---|---|
| "Could not discover OAuth from that MCP URL" | The MCP server is off, or the URL is wrong | Turn it on under Admin → AI → MCP, and check the URL ends in /api/metabase-mcp |
| "OAuth did not complete" | You approved in a different browser or window, or Metabase's Site URL is not the address you connected to | Do the whole connection in one window, and set the Site URL to Metabase's public address |
| A question or query shows as you | The connection was approved while Metabase was signed in as you | Remove the binding and connect it again, signed in to Metabase as the member |
The run's log says tool.not_offered for a Metabase tool |
Your Metabase did not answer when the run started, or offers no tool by that name | Check it is reachable at its public address, then run it again |
tool_not_bound:metabase |
No Metabase connection reaches this run | Connect it at a layer the run reaches: its task, its member or the member's roles, its team, or the enterprise |
| Calls fail with an auth error after working | The authorisation was revoked in Metabase, or the user was deactivated | Remove the binding and connect it again |