Metabase for AI agents

Metabase is an open source business intelligence tool teams use to query data, build charts, and share dashboards without writing raw SQL each time. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

AnalyticsAPI keyMCP + RESTmetabase.com
AUDIT LOG · METABASEPOLICY: acme-support
09:41:07 · claude · u_8f2read
metabase.list_tables
List Tables✓ allowed · 212ms
09:41:08 · claude · u_8f2read
metabase.get_action
Get Action✓ allowed · 164ms
09:41:09 · claude · u_8f2write
metabase.create_bookmark
Create Bookmark✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
metabase.delete_card
Delete Card✕ blocked · policy: deny
EVERY METABASE CALL, ON THE RECORD
01 · USE CASES

What agents do in Metabase.

01

Run a saved query

Run an existing card's query to pull current numbers for a report, read-only.

02

Save a dashboard to a collection

Save a built dashboard into the right collection so a team can find it.

03

Approve before deleting a dashboard

Require approval before deleting a dashboard, since teams may depend on it for reporting.

02 · ACTIONS

194 Metabase actions, graded by risk.

Every Metabase action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

97

Look things up. Allowed by default.

  • metabase.get_action
    Get Action
  • metabase.list_tables
    List Tables
  • metabase.get_api_card
    Get API Card
  • metabase.get_api_alert
    Get All Alerts
  • metabase.get_api_pulse
    Get All Pulses
  • metabase.get_table_fks
    Get Table Foreign Keys
  • metabase.get_api_action
    Get all Metabase actions
  • metabase.get_api_search
    Search Metabase objects
  • metabase.get_table_data
    Get Table Data
  • metabase.list_databases
    List Databases
  • metabase.get_api_card_id
    Get Card by ID
  • metabase.get_api_segment
    Get All Segments
  • metabase.get_api_user_id
    Get User by ID
  • metabase.get_card_series
    Get Card Series
  • metabase.get_table_by_id
    Get Table By ID
  • metabase.get_api_bookmark
    Get User Bookmarks
+ 81 MORE

write

83

Create and change things. Allow, or ask the user first.

  • metabase.post_api_card
    Create Card
  • metabase.post_api_pulse
    Create Pulse
  • metabase.create_bookmark
    Create Bookmark
  • metabase.post_api_dataset
    Execute Dataset Query
  • metabase.update_dashboard
    Update Dashboard
  • metabase.post_api_glossary
    Create Glossary Entry
  • metabase.post_api_timeline
    Create Timeline
  • metabase.create_card_query1
    Run Card Query
  • metabase.post_api_dashboard
    Create Dashboard
  • metabase.create_field_values
    Update Field Values
  • metabase.post_api_cards_move
    Bulk Move Cards
  • metabase.post_api_collection
    Create Collection
  • metabase.post_api_model_index
    Create Model Index
  • metabase.post_dashboard_query
    Execute Dashboard Card Query
  • metabase.create_dashboard_copy
    Copy Dashboard
  • metabase.post_api_card_id_copy
    Copy Card
+ 67 MORE

destructive

14

Delete, cancel or archive. Ask first, or deny outright.

  • metabase.delete_card
    Delete Card
  • metabase.delete_bookmark
    Delete Bookmark
  • metabase.delete_glossary
    Delete Glossary Entry
  • metabase.delete_api_cache
    Delete API Cache
  • metabase.delete_dashboard
    Delete Dashboard
  • metabase.delete_model_index
    Delete Model Index
  • metabase.delete_timeline_event
    Delete Timeline Event
  • metabase.delete_api_timeline_id
    Delete Timeline
  • metabase.delete_field_dimension
    Delete Field Dimension
  • metabase.delete_api_action_action_id
    Delete Action
  • metabase.delete_user_key_value_namespace_key
    Delete User Key-Value Pair
  • metabase.delete_ee_audit_app_user_subscriptions
    Delete User Subscriptions
  • metabase.get_api_session_password_reset_token_valid
    Validate Password Reset Token
  • metabase.post_api_ee_remote_sync_current_task_cancel
    Cancel Current Remote Sync Task
03 · HOW IT WORKS

Metabase in three steps.

  1. 01Your users connect MetabaseThey add their Metabase api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create Bookmark” can wait for the user, and “delete Card” can be denied outright.
  3. 03Any agent can actYour agent calls Metabase through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('metabase', {
  read: 'allow',
  write: 'ask',        // create_bookmark
  destructive: 'deny',  // delete_card
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Metabase connects.

Users add their Metabase api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same Metabase connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Metabase from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Metabase and Arc0, answered.

Q01

Can I use Metabase with Claude, ChatGPT or Cursor?

Yes. Connect Metabase to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Metabase actions you allow.

Q02

How do users connect Metabase?

Users add their Metabase api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which Metabase actions can my agent take?

194 in total: 97 read, 83 write and 14 destructive, such as “create Bookmark”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Metabase?

Yes. Actions like “delete Card” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Metabase too?

Yes. The same Metabase connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Metabase into your agent.

Your users connect Metabase once, under your brand. Your agent gets 194 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan