Set up DataHub MCP Server

Make DataHub metadata available safely in an MCP client using OAuth or a minimally privileged token.

Published on 18.09.2026

The DataHub MCP Server makes metadata from your DataHub catalog available to an MCP-capable AI client. Start with a clear objective: find data assets, understand columns, review dashboard and metric context, or assess change impact through lineage. The server is not a direct database connector. It returns catalog context; SQL execution belongs only in a separate, explicitly approved database workflow.

Define visibility before connecting

First determine which DataHub entities the agent truly needs to see. Table and column names, PII tags, ownership, glossary terms, query history, documents, and lineage can already be sensitive. Create a dedicated DataHub user or service account for the agent with minimal rights. For a service account, a Default View can, according to the official documentation, scope search to particular domains, platforms, or assets. Test that restriction with a search for a known asset before allowing the account to expose production metadata to an AI client.

Connect DataHub Cloud with OAuth

For an interactive client, the official universal endpoint https://mcp.datahub.com/mcp is the recommended starting point. On first connection, the client asks for your DataHub domain and then guides you through OAuth login. The login can use the SSO configuration of your tenant. The token belongs to the signed-in user and compatible clients manage refresh automatically. Never place tokens in a URL, prompt, or shared configuration file; the source accepts tokens in the Authorization header and warns about URL logs, browser history, and Referer headers.

Use local stdio for one person

For DataHub Core or a local single-user setup, install uv and set DATAHUB_GMS_URL and DATAHUB_GMS_TOKEN only in a secure local environment. Then run uvx mcp-server-datahub and add that stdio command to the client configuration. The server can also read ~/.datahubenv, created through datahub init. After starting, test with a low-risk search for a known non-sensitive asset and check that the agent receives only expected metadata.

Operate shared HTTP safely

For a team, use the separate HTTP entry point and configure only DATAHUB_GMS_URL. Never set a global DATAHUB_GMS_TOKEN on a shared server: the official server intentionally refuses that startup so every request uses the person's own bearer token and permissions and audit identity do not collapse into one account. Enable METADATA_SERVICE_AUTH_ENABLED=true in DataHub, enforce TLS at an ingress or reverse proxy, and apply rate limiting. The health endpoint is intentionally unauthenticated but returns only process status.

Start read-only; deliberately enable changes

Discovery and inspection tools read catalog state. Keep mutation tools disabled while the use case is search, analysis, or research. Only TOOLS_IS_MUTATION_ENABLED=true enables changes to tags, terms, owners, domains, descriptions, or structured properties. Plan a separate approval, limited account, and proposal or review process for this. An AI agent can misinterpret instructions; independently confirm every business-relevant change outside the chat.

Control the model path and operation

The MCP server returns results to the connected client. Review that client's model provider, telemetry, logging, retention, and data residency. A local server installation does not automatically mean that returned metadata stays local. Use short task-specific queries, limit visibility before search, and keep tokens out of shell history, screenshots, and support tickets. This keeps DataHub MCP a catalog and research tool rather than an unrestricted data path.

Published on 18.09.2026

Categories

Frequently asked questions

Does DataHub MCP replace database access?

No. It searches and explains DataHub metadata. An agent can draft SQL, but access to table rows or SQL execution requires a separate authorized database path.

Which login is appropriate for DataHub Cloud?

For interactive clients, the official documentation recommends OAuth through the universal MCP endpoint. For unattended workflows, use a minimally privileged service account with its own Default View.

When may I enable mutation tools?

Only when the workflow truly needs to change metadata, permissions were intentionally granted, and a review or approval process exists. Keep them disabled for discovery.