tableau-graphql-mcp
Enables querying Tableau lineage through the Metadata API via MCP, supporting impact analysis, where-used lookups, and content search. Provides read-only tools for answering natural-language questions about workbooks, datasources, fields, and dependencies.
README
<!-- mcp-name: io.github.tdries/tableau-graphql-mcp -->
<p align="center"> <img src="docs/images/banner.png" alt="tableau-graphql-mcp" width="880"> </p>
<h1 align="center">tableau-graphql-mcp</h1>
<p align="center"><em>Ask any Tableau lineage question, in any MCP client, through the Tableau Metadata API.</em></p>
<p align="center"> <a href="https://github.com/tdries/tableau-graphQL-mcp/actions/workflows/ci.yml"><img src="https://github.com/tdries/tableau-graphQL-mcp/actions/workflows/ci.yml/badge.svg" alt="CI"></a> <a href="https://github.com/tdries/tableau-graphQL-mcp/actions/workflows/codeql.yml"><img src="https://github.com/tdries/tableau-graphQL-mcp/actions/workflows/codeql.yml/badge.svg" alt="CodeQL"></a> <a href="https://github.com/astral-sh/ruff"><img src="https://img.shields.io/endpoint?url=https://raw.githubusercontent.com/astral-sh/ruff/main/assets/badge/v2.json" alt="Ruff"></a> <a href="https://pypi.org/project/tableau-graphql-mcp/"><img src="https://img.shields.io/pypi/v/tableau-graphql-mcp.svg" alt="PyPI"></a> <img src="https://img.shields.io/pypi/pyversions/tableau-graphql-mcp.svg" alt="Python versions"> <img src="https://img.shields.io/badge/MCP-compatible-8A2BE2.svg" alt="MCP compatible"> <a href="LICENSE"><img src="https://img.shields.io/badge/license-MIT-00696E.svg" alt="MIT License"></a> <img src="https://img.shields.io/badge/Tableau-Server%20%2B%20Cloud-006EFF.svg" alt="Server + Cloud"> <img src="https://img.shields.io/badge/deps-just%20mcp-64FA8C.svg" alt="Minimal dependencies"> </p>
<p align="center"> <a href="cursor://anysphere.cursor-deeplink/mcp/install?name=tableau-graphql&config=eyJjb21tYW5kIjogInV2eCIsICJhcmdzIjogWyJ0YWJsZWF1LWdyYXBocWwtbWNwIl19"><img src="https://img.shields.io/badge/Add%20to-Cursor-0098FF.svg" alt="Add to Cursor"></a> </p>
<p align="center"> <img src="docs/images/demo.gif" alt="Asking lineage questions in Claude" width="760"> </p>
tableau-graphql-mcp turns your Tableau site's Metadata API into a set of MCP tools, so an AI assistant (Claude, Cursor, Cline, and others) can answer lineage questions in plain language:
- "If I drop the column
SALES, which workbooks break?" - "What tables does the Sales Overview workbook depend on?"
- "Which calculated fields reference
Profit, and on which dashboards?" - "Who should I notify before changing the
DIM_CUSTOMERtable?"
It ships seven curated tools: a universal GraphQL passthrough, live schema introspection, an embedded library of correct query templates, a robust where_used resolver, a multi-hop impact_analysis, a substring content search, and a connection probe. Together they let the model answer any lineage question, not just a fixed menu.
Why it's different
- Any question, done right.
graphql_queryruns any read-only GraphQL;introspect_schemaand a built-in cheat-sheet plus 28 worked examples keep the model's queries correct. - True impact analysis (multi-hop).
impact_analysisfollows the whole dependency chain (a calc built on a calc built on a column is included) and returns the full blast radius plus the de-duplicated owners to notify, not just direct references. - Works everywhere. Tableau Server and Cloud. The REST API version and the GraphQL endpoint (
/api/metadata/graphql, with a/relationship-service-war/graphqlfallback) are auto-detected. - Robust lineage without Catalog.
where_usedresolves workbooks via core lineage (referencedByFields -> sheets -> workbook), so it works even when the Data Management add-on'sdownstreamWorkbooksis empty. - No silent truncation.
graphql_queryflagspartial_resultswhen a query hits the node limit, andsearch_contentreportsscanned/totalcoverage, so a truncated answer is never mistaken for a complete one. - Tiny and safe. Read-only, stdio-only (no inbound port), secrets from env only, and no dependencies beyond the MCP SDK (stdlib
urllibfor HTTP).
Quickstart
You need uv (curl -LsSf https://astral.sh/uv/install.sh | sh) and a Tableau Personal Access Token.
Claude Code, one line:
claude mcp add tableau-graphql \
-e TABLEAU_SERVER=https://10ax.online.tableau.com \
-e TABLEAU_SITE_CONTENT_URL=YourSite \
-e TABLEAU_PAT_NAME=my-token \
-e TABLEAU_PAT_SECRET=the-full-secret \
-- uvx tableau-graphql-mcp
That's all. uvx fetches the package from PyPI and runs it in an isolated environment; nothing to clone or install (and no git required). Then ask Claude a lineage question.
Configuration
All configuration is via environment variables (set them in your client's env block, never on the command line).
| Env var | Required | Default | Description |
|---|---|---|---|
TABLEAU_SERVER |
yes | n/a | https://tableau.company.com (Server) or https://<pod>.online.tableau.com (Cloud). |
TABLEAU_SITE_CONTENT_URL |
no | "" |
Site slug (the part after /#/site/). Empty = Default site (Server only); Cloud always has one. |
TABLEAU_PAT_NAME |
yes¹ | n/a | Personal Access Token name. |
TABLEAU_PAT_SECRET |
yes¹ | n/a | PAT secret: the whole string, do not split on :. |
TABLEAU_TIMEOUT |
no | 60 |
Per-request timeout (seconds). |
TABLEAU_API_VERSION |
no | auto | REST API version; else read from /api/serverinfo. |
TABLEAU_METADATA_PATH |
no | auto | Override the GraphQL path; else auto-detected. |
TABLEAU_AUTH_TOKEN |
no | n/a | Advanced: a pre-obtained X-Tableau-Auth token (SSO tenants where PATs are disabled). |
TABLEAU_COOKIE |
no | n/a | Advanced: a browser session cookie (SSO fallback). |
¹ Provide a PAT (TABLEAU_PAT_NAME + TABLEAU_PAT_SECRET) or an advanced TABLEAU_AUTH_TOKEN / TABLEAU_COOKIE.
<details> <summary><b>Claude Desktop</b></summary>
Edit claude_desktop_config.json (macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\):
{
"mcpServers": {
"tableau-graphql": {
"command": "uvx",
"args": ["tableau-graphql-mcp"],
"env": {
"TABLEAU_SERVER": "https://10ax.online.tableau.com",
"TABLEAU_SITE_CONTENT_URL": "YourSite",
"TABLEAU_PAT_NAME": "my-token",
"TABLEAU_PAT_SECRET": "the-full-secret"
}
}
}
}
Fully quit and reopen Claude Desktop, then check the tools menu. </details>
<details> <summary><b>Cursor</b> · <b>Cline</b> · <b>Windsurf</b></summary>
Every client uses the same mcpServers schema shown above. Add the same block to:
- Cursor:
~/.cursor/mcp.json(global) or.cursor/mcp.json(project). - Cline: the MCP Servers panel, then Configure, into
cline_mcp_settings.json. - Windsurf:
~/.codeium/windsurf/mcp_config.json.
On Windows, if uvx isn't found by the GUI app, use its absolute path (e.g. %USERPROFILE%\.local\bin\uvx.exe).
</details>
Tools
| Tool | What it does | Key args |
|---|---|---|
graphql_query |
Run any read-only Metadata API GraphQL query. The general tool for any lineage question. | query, variables |
introspect_schema |
Live schema introspection: list entry points, or a type's exact fields. | type_name |
lineage_examples |
A schema cheat-sheet plus 28 curated question-to-GraphQL templates (8 categories). | category |
where_used |
Which workbooks/datasources use given column / field / table names (robust one-hop core-lineage resolution). | names |
impact_analysis |
Full transitive multi-hop blast radius of a column/field/table: every dependent field, plus affected sheets, dashboards, workbooks, and owners to notify. | name |
search_content |
Find content whose name contains a term (case-insensitive substring), across workbooks, datasources, tables (and optionally fields/columns), with coverage numbers. | term, types |
server_info |
Connected server, site, versions, endpoint, auth, and whether Catalog lineage is available. | none |
All tools are read-only. The Metadata API has no mutations.
Example prompts
Once connected, try:
- "Use server_info to confirm what you're connected to."
- "Search for anything with 'revenue' in the name."
- "Which workbooks use the columns SALES, PROFIT and DISCOUNT? Group by owner."
- "Show me the field-to-source-column map for the 'Sales Overview' workbook."
- "List every calculated field in that workbook with its formula."
- "Which published datasources feed workbooks in the Analytics project, and which are uncertified?"
- "Run impact_analysis on the 'Profit Ratio' field: every dependent sheet, dashboard, workbook, and owner to notify."
- "What is the blast radius of dropping the DIM_CUSTOMER table: workbooks, sheets, and owners to notify?"
Architecture
<p align="center"><img src="docs/images/architecture.svg" alt="Architecture" width="900"></p>
The server speaks MCP over stdio to the client and HTTPS to Tableau: it signs in with your PAT to get an X-Tableau-Auth token (auto-refreshed on expiry), auto-detects the REST API version and the GraphQL endpoint, then forwards queries to the Metadata API. Nothing is stored; every answer is live.
Security
- Read-only, enforced. Only GraphQL queries: no writes, no shell.
graphql_queryrejectsmutation/subscriptionoperations, and the Metadata API is query-only regardless. - Local and stdio-only. No inbound network port is opened.
- Secrets from env only. Never passed as tool arguments, never logged, never returned in output.
- Least privilege. The PAT inherits your Tableau permissions; the API only returns content you can see.
- Pin a version in production:
uvx tableau-graphql-mcp==0.1.0.
See SECURITY.md.
Troubleshooting
| Symptom | Fix |
|---|---|
| Server doesn't appear | Fully quit and relaunch the client; check the config path and JSON validity. |
spawn uvx ENOENT |
Install uv, or use the absolute path to uvx. |
| Sign-in fails (401) | Check the PAT name/secret and TABLEAU_SITE_CONTENT_URL. On SSO tenants PATs may be disabled; use TABLEAU_AUTH_TOKEN/TABLEAU_COOKIE. |
| "Could not reach the Metadata API" | On Tableau Server, an admin must enable it: tsm maintenance metadata-services enable. On Cloud it is always on. |
Empty downstreamWorkbooks |
Expected without the Data Management add-on; use the where_used tool, which resolves via core lineage. |
Inspect the server directly with the MCP Inspector:
npx @modelcontextprotocol/inspector uvx tableau-graphql-mcp
Development
git clone https://github.com/tdries/tableau-graphQL-mcp && cd tableau-graphQL-mcp
uv sync --all-extras
uv run tableau-graphql-mcp # run from source
uv run pytest --cov=tableau_graphql_mcp # tests + coverage (offline; no Tableau needed)
uv run ruff check . # lint
uv run ruff format --check . # format
The same three gates (lint, format, tests with a 85% coverage floor) run in CI across Linux/macOS/Windows and Python 3.10 to 3.13. Coverage is reported to Codecov and the code is scanned by CodeQL on every push.
The same gates run in CI (Linux/macOS/Windows, Python 3.10 to 3.13): ruff check,
ruff format --check, mypy --strict, and pytest with a coverage floor. The package
ships a PEP 561 py.typed marker, so importing it gives your type checker full types.
Contributions welcome: see CONTRIBUTING.md and the Code of Conduct.
Roadmap
Shipped: published on PyPI and listed on the official MCP registry. Next:
- [ ] Optional Data Management path: richer
downstreamWorkbookswhen Catalog is present - [ ] More curated query templates in
lineage_examples - [ ] Optional response caching for repeated introspection within a session
Ideas and votes welcome in Discussions.
License
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。