Metabase for AI agents
Metabase is an open source business intelligence tool teams use to query data, build charts, and share dashboards without writing raw SQL each time. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Metabase.
Run a saved query
Run an existing card's query to pull current numbers for a report, read-only.
Save a dashboard to a collection
Save a built dashboard into the right collection so a team can find it.
Approve before deleting a dashboard
Require approval before deleting a dashboard, since teams may depend on it for reporting.
194 Metabase actions, graded by risk.
Every Metabase action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
97Look things up. Allowed by default.
- metabase.get_actionGet Action
- metabase.list_tablesList Tables
- metabase.get_api_cardGet API Card
- metabase.get_api_alertGet All Alerts
- metabase.get_api_pulseGet All Pulses
- metabase.get_table_fksGet Table Foreign Keys
- metabase.get_api_actionGet all Metabase actions
- metabase.get_api_searchSearch Metabase objects
- metabase.get_table_dataGet Table Data
- metabase.list_databasesList Databases
- metabase.get_api_card_idGet Card by ID
- metabase.get_api_segmentGet All Segments
- metabase.get_api_user_idGet User by ID
- metabase.get_card_seriesGet Card Series
- metabase.get_table_by_idGet Table By ID
- metabase.get_api_bookmarkGet User Bookmarks
write
83Create and change things. Allow, or ask the user first.
- metabase.post_api_cardCreate Card
- metabase.post_api_pulseCreate Pulse
- metabase.create_bookmarkCreate Bookmark
- metabase.post_api_datasetExecute Dataset Query
- metabase.update_dashboardUpdate Dashboard
- metabase.post_api_glossaryCreate Glossary Entry
- metabase.post_api_timelineCreate Timeline
- metabase.create_card_query1Run Card Query
- metabase.post_api_dashboardCreate Dashboard
- metabase.create_field_valuesUpdate Field Values
- metabase.post_api_cards_moveBulk Move Cards
- metabase.post_api_collectionCreate Collection
- metabase.post_api_model_indexCreate Model Index
- metabase.post_dashboard_queryExecute Dashboard Card Query
- metabase.create_dashboard_copyCopy Dashboard
- metabase.post_api_card_id_copyCopy Card
destructive
14Delete, cancel or archive. Ask first, or deny outright.
- metabase.delete_cardDelete Card
- metabase.delete_bookmarkDelete Bookmark
- metabase.delete_glossaryDelete Glossary Entry
- metabase.delete_api_cacheDelete API Cache
- metabase.delete_dashboardDelete Dashboard
- metabase.delete_model_indexDelete Model Index
- metabase.delete_timeline_eventDelete Timeline Event
- metabase.delete_api_timeline_idDelete Timeline
- metabase.delete_field_dimensionDelete Field Dimension
- metabase.delete_api_action_action_idDelete Action
- metabase.delete_user_key_value_namespace_keyDelete User Key-Value Pair
- metabase.delete_ee_audit_app_user_subscriptionsDelete User Subscriptions
- metabase.get_api_session_password_reset_token_validValidate Password Reset Token
- metabase.post_api_ee_remote_sync_current_task_cancelCancel Current Remote Sync Task
Metabase in three steps.
- 01Your users connect MetabaseThey add their Metabase api key on Arc0 Connect, under your brand. It goes straight into the vault.
- 02You set the rulesReads run, writes like “create Bookmark” can wait for the user, and “delete Card” can be denied outright.
- 03Any agent can actYour agent calls Metabase through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('metabase', { read: 'allow', write: 'ask', // create_bookmark destructive: 'deny', // delete_card }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Metabase connects.
Users add their Metabase api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
The same Metabase connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Metabase from any agent.
Metabase and Arc0, answered.
Can I use Metabase with Claude, ChatGPT or Cursor?
Yes. Connect Metabase to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Metabase actions you allow.
How do users connect Metabase?
Users add their Metabase api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
Which Metabase actions can my agent take?
194 in total: 97 read, 83 write and 14 destructive, such as “create Bookmark”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Metabase?
Yes. Actions like “delete Card” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Metabase too?
Yes. The same Metabase connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Metabase into your agent.
Your users connect Metabase once, under your brand. Your agent gets 194 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan