Data and analytics

The Metabase connector.

Search, run and read saved questions. Connect once with your own key. Every agent your team runs reads the same 6 tools under one permission model.

How access is governed

6

Read tools

Open by default. They run when called, and every call is logged with the endpoint, tool and capability.

0

Write tools

Metabase exposes no write tools. Nothing it does mutates external state.

0

Destructive tools

Metabase defines no destructive tools. Nothing here deletes data.

Defaults come from the capability on each tool definition, and an admin can tighten or open any tool individually. The endpoint's capability ceiling can only tighten that policy. An endpoint scoped to read never surfaces a write tool.

Every Metabase tool

6 tools, named as the agent sees them.

  • search_cardsread

    Search saved questions, models, and dashboards by name. Start here when the user names a report in words rather than by id — the `id` of each result feeds run_card_query (for cards/models) or get_dashboard (for dashboards).

  • run_card_queryread

    Run a saved question (card or model) and return its result rows as objects keyed by column name. Get the card_id from search_cards. Results are capped — check `truncated` and `total_rows` in the response before drawing conclusions from a large report.

  • list_dashboardsread

    List the dashboards on this Metabase instance with their id, name, and collection. Use the id with get_dashboard to see which cards a dashboard is built from.

  • get_dashboardread

    Get one dashboard with the cards placed on it. Each card carries a card_id you can then run through run_card_query to get the underlying numbers.

  • list_databasesread

    List the databases Metabase is connected to, with id, name, and engine. The id feeds list_tables when you need to know what data actually exists before hunting for a question.

  • list_tablesread

    List the tables in one database, with their schema and row-count estimate. Use the database_id from list_databases. Use this to check whether the data the user is asking about is even modelled in Metabase.

Use it from any agent

The same Metabase tools reach Claude Code, Cursor, Claude Desktop or your own agent through one MCP endpoint. The endpoint is scoped to a group, the token is issued per group and revocable from the dashboard, and an allowed-tool list and capability ceiling limit what it exposes. Reads run. Gated writes refuse unless an admin opens them. Destructive tools remain unavailable over MCP.

.mcp.json · works for Cursor and Claude Desktop too
{
  "mcpServers": {
    "growth": {
      "type": "http",
      "url": "https://app.notara.ai/mcp/g/acme/growth",
      "headers": {
        "Authorization": "Bearer ntr_mcp_xxxxxxxxxxxxxxxxxxxx"
      }
    }
  }
}

The URL and token are placeholders. Real endpoints are issued per group from the dashboard.

Setup

  1. 01

    Create a Metabase API Key in your Metabase account (where to find it). The key is yours: Notara stores it encrypted and never sees a bill.

  2. 02

    Paste it into the Notara dashboard. Credentials can be scoped to the workspace or to one person.

  3. 03

    The tools appear with their capability defaults already set. Tighten or open any of them per tool, then invite the agent to a channel or issue an MCP token.

Connect Metabase once. Use it everywhere.

Use Notara directly, or bring us the workflow that needs to be redesigned and built.