[{"data":1,"prerenderedAt":39},["ShallowReactive",2],{"$f3f0b99pcpnl32":3},{"href":4,"title":5,"description":6,"kind":7,"mark":8,"planned":9,"contributors":10,"provenance":8,"html":11,"headings":12},"\u002Fdocs\u002Ftools\u002Fmetabase","Metabase","Questions, dashboards and queries, through the MCP server built into your own Metabase, connected with OAuth.","integrates",null,false,[],"\u003Ch2 id=\"what-a-member-can-do\">What a member can do\u003C\u002Fh2>\n\u003Cp>With Metabase connected, a member can search and read what your Metabase holds (collections, dashboards,\nquestions, models, metrics, databases and tables), build and run queries, and create or change questions,\ndashboards and collections. It sees only what its Metabase user may see.\u003C\u002Fp>\n\u003Cp>Each task names the Metabase tools it may call. \u003Ccode>metabase\u003C\u002Fcode> on a task means every tool your Metabase's server\noffers; a single tool is named after the prefix, \u003Ccode>metabase.&lt;tool&gt;\u003C\u002Fcode>, as the server names it. A tool the task does\nnot name is refused, whatever the connection allows. If your Metabase does not answer when a run starts, the run\ncarries on rather than failing, and its log records \u003Ccode>tool.not_offered\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Ch2 id=\"who-connects-it\">Who connects it\u003C\u002Fh2>\n\u003Cp>Metabase's MCP server signs clients in with Metabase's own OAuth, so a Metabase connection acts as \u003Cstrong>the Metabase\nuser who approved it\u003C\u002Fstrong> when it was connected, with that user's permissions. Every question it saves and every\nquery it runs is that user's.\u003C\u002Fp>\n\u003Cp>A connection can sit on the enterprise, a team, a member, a role or a task, and the one further down replaces the\none above: task, then role, then member, then team, then enterprise. Connect a member's own while Metabase is\nsigned in as the member's own Metabase user, and what it creates is under its own name, limited to its own\ngroups' permissions. Connect it while signed in as yourself, and it can do everything you can.\u003C\u002Fp>\n\u003Cp>A connection on anything but a task also reaches the \u003Ca href=\"\u002Fdocs\u002Fwork\u002Fchat\">chat\u003C\u002Fa> of every member it covers.\u003C\u002Fp>\n\u003Ch2 id=\"what-waits-for-you\">What waits for you\u003C\u002Fh2>\n\u003Cp>In a run, nothing in Metabase waits for you unless the task declares a gate on it. Metabase's write tools create\nand change questions, dashboards and collections, and run SQL with your database connection's own rights: gate the\nones you want to approve first, or leave them off the task. See \u003Ca href=\"\u002Fdocs\u002Fcontrol\u002Fgates\">Gates and tool scopes\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>In a chat, a Metabase tool that Metabase does not mark as read-only asks you before it runs, unless you chose\n\u003Cstrong>Always allow\u003C\u002Fstrong> for that member and tool.\u003C\u002Fp>\n\u003Ch2 id=\"setup\">Setup\u003C\u002Fh2>\n\u003Ch3 id=\"turn-on-metabases-mcp-server\">Turn on Metabase's MCP server\u003C\u002Fh3>\n\u003Cp>In Metabase, as an admin:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\u003Cstrong>Admin → AI:\u003C\u002Fstrong> turn AI features on. The MCP server needs them.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin → AI → MCP:\u003C\u002Fstrong> turn the MCP server on. If there is no \u003Cstrong>MCP\u003C\u002Fstrong> section, your version of Metabase has no\nMCP server: upgrade it first.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Zero Human OS reaches your Metabase over the internet, so it needs a public address, served over HTTPS, and its\n\u003Cstrong>Site URL\u003C\u002Fstrong> setting has to be that address: signing in with OAuth depends on it.\u003C\u002Fp>\n\u003Ch3 id=\"connect-it\">Connect it\u003C\u002Fh3>\n\u003Cp>Work in one browser window throughout: Metabase returns to the portal in the window you started from.\u003C\u002Fp>\n\u003Col>\n\u003Cli>In the portal, on the member's page → \u003Cstrong>Tools\u003C\u002Fstrong> (or \u003Cstrong>Tools\u003C\u002Fstrong>, for another layer), choose \u003Cstrong>Add tool\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Kind:\u003C\u002Fstrong> MCP. \u003Cstrong>Tool type:\u003C\u002Fstrong> \u003Ccode>metabase\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>MCP server URL:\u003C\u002Fstrong> your Metabase's address followed by \u003Ccode>\u002Fapi\u002Fmetabase-mcp\u003C\u002Fcode>, such as\n\u003Ccode>https:\u002F\u002Fmetabase.example.com\u002Fapi\u002Fmetabase-mcp\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Auth:\u003C\u002Fstrong> OAuth. Leave the client ID, client secret and scopes blank: Metabase registers Zero Human OS as a\nclient by itself.\u003C\u002Fli>\n\u003Cli>Choose \u003Cstrong>Connect with OAuth\u003C\u002Fstrong>. Sign in to Metabase as the user the member should act as, and approve.\u003C\u002Fli>\n\u003Cli>Name the tools on the task, \u003Ccode>metabase\u003C\u002Fcode> for all of them or each by name.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Check it.\u003C\u002Fstrong> Run a task that searches your Metabase. The run page shows the call and what Metabase returned,\nand in Metabase, \u003Cstrong>Admin → AI → MCP → Authorizations\u003C\u002Fstrong> lists the connection.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3 id=\"giving-a-member-its-own-metabase-user\">Giving a member its own Metabase user\u003C\u002Fh3>\n\u003Cp>Invite the member's Zero Human address as a Metabase user, in the groups whose data it should reach. If your\nMetabase sends email, the invitation appears in the \u003Cstrong>Inbox\u003C\u002Fstrong> on its member page in the portal. Set the account up in a \u003Cstrong>separate browser\nprofile or a private window\u003C\u002Fstrong>, where Metabase is not signed in as you, then connect the member's binding from that\nsame window, signed in to the portal as yourself.\u003C\u002Fp>\n\u003Ch2 id=\"troubleshooting\">Troubleshooting\u003C\u002Fh2>\n\u003Cdiv class=\"prose__table\">\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>What you see\u003C\u002Fth>\n\u003Cth>Why\u003C\u002Fth>\n\u003Cth>What to do\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\n\u003Ctr>\n\u003Ctd>&quot;Could not discover OAuth from that MCP URL&quot;\u003C\u002Ftd>\n\u003Ctd>The MCP server is off, or the URL is wrong\u003C\u002Ftd>\n\u003Ctd>Turn it on under \u003Cstrong>Admin → AI → MCP\u003C\u002Fstrong>, and check the URL ends in \u003Ccode>\u002Fapi\u002Fmetabase-mcp\u003C\u002Fcode>\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>&quot;OAuth did not complete&quot;\u003C\u002Ftd>\n\u003Ctd>You approved in a different browser or window, or Metabase's \u003Cstrong>Site URL\u003C\u002Fstrong> is not the address you connected to\u003C\u002Ftd>\n\u003Ctd>Do the whole connection in one window, and set the Site URL to Metabase's public address\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>A question or query shows as you\u003C\u002Ftd>\n\u003Ctd>The connection was approved while Metabase was signed in as you\u003C\u002Ftd>\n\u003Ctd>Remove the binding and connect it again, signed in to Metabase as the member\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>The run's log says \u003Ccode>tool.not_offered\u003C\u002Fcode> for a Metabase tool\u003C\u002Ftd>\n\u003Ctd>Your Metabase did not answer when the run started, or offers no tool by that name\u003C\u002Ftd>\n\u003Ctd>Check it is reachable at its public address, then run it again\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Ccode>tool_not_bound:metabase\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>No Metabase connection reaches this run\u003C\u002Ftd>\n\u003Ctd>Connect it at a layer the run reaches: its task, its member or the member's roles, its team, or the enterprise\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Calls fail with an auth error after working\u003C\u002Ftd>\n\u003Ctd>The authorisation was revoked in Metabase, or the user was deactivated\u003C\u002Ftd>\n\u003Ctd>Remove the binding and connect it again\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\n\u003C\u002Ftable>\n\u003C\u002Fdiv>\n",[13,17,20,23,26,30,33,36],{"id":14,"text":15,"level":16,"planned":9},"what-a-member-can-do","What a member can do",2,{"id":18,"text":19,"level":16,"planned":9},"who-connects-it","Who connects it",{"id":21,"text":22,"level":16,"planned":9},"what-waits-for-you","What waits for you",{"id":24,"text":25,"level":16,"planned":9},"setup","Setup",{"id":27,"text":28,"level":29,"planned":9},"turn-on-metabases-mcp-server","Turn on Metabase's MCP server",3,{"id":31,"text":32,"level":29,"planned":9},"connect-it","Connect it",{"id":34,"text":35,"level":29,"planned":9},"giving-a-member-its-own-metabase-user","Giving a member its own Metabase user",{"id":37,"text":38,"level":16,"planned":9},"troubleshooting","Troubleshooting",1791124519803]