PluginBench
MCP Server

Data Prism MCP Server

io.github.AindriuB/data-prism

What is the Data Prism MCP server?

Fail-closed privacy layer that pseudonymises enterprise API data for LLM agents and MCP clients.

How to install Data Prism

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • LOADER_PATH
    required

    Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above)

  • DATAPRISM_SECURITY_JWT_ISSUER
    required

    OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment

  • DATAPRISM_SECURITY_JWT_AUDIENCE
    required

    Expected JWT audience claim for this deployment; required for every protected deployment

  • DATAPRISM_SECURITY_JWT_JWK_SET_URI
    required

    HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both

  • DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI

    Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both

  • DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL
    required

    JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims

  • DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES
    required

    JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims

  • DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION
    required

    JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims

  • DATAPRISM_SECURITY_POLICY_PURPOSES
    required

    Comma-separated list of permitted purposes; at least one is required

  • DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR
    required

    Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 3.5.16), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required

  • DATAPRISM_PRIVACY_PROFILE
    required

    Name of the reviewed privacy profile implementation to apply; required

  • DATAPRISM_PRIVACY_SCOPE_LIFETIME
    required

    Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required

  • DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID
    required

    Identifier of the pinned HMAC key used to derive synthetic identities; required

  • DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE
    required

    Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value

  • DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE

    Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both

  • DATAPRISM_AUDIT_SINK
    required

    Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op

  • DATAPRISM_AUDIT_WRITER_ID
    required

    Writer/instance identity recorded on every audit entry; required

  • DATAPRISM_AUDIT_FILE_PATH

    Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise

  • DATAPRISM_METRICS_SINK
    required

    Metrics sink binding, currently only micrometer; required in production, never the framework no-op

  • DATAPRISM_HAZELCAST_TOPOLOGY
    required

    Cluster read-budget topology: embedded (shared across the cluster) or single-node (enforced per process); required, never defaulted

  • DATAPRISM_SOURCES_CUSTOMER_BASE_URL
    required

    Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required

  • DATAPRISM_SOURCES_CUSTOMER_TIMEOUT
    required

    Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "data-prism": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/aindriub/data-prism-server:0.3.1",
        "-v",
        "{adapter_jar_host_path}:/app/adapters/{adapter_jar_name}",
        "-v",
        "{config_host_path}:/app/config/application.yaml"
      ],
      "env": {
        "LOADER_PATH": "<YOUR_LOADER_PATH>",
        "DATAPRISM_SECURITY_JWT_ISSUER": "<YOUR_DATAPRISM_SECURITY_JWT_ISSUER>",
        "DATAPRISM_SECURITY_JWT_AUDIENCE": "<YOUR_DATAPRISM_SECURITY_JWT_AUDIENCE>",
        "DATAPRISM_SECURITY_JWT_JWK_SET_URI": "<YOUR_DATAPRISM_SECURITY_JWT_JWK_SET_URI>",
        "DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI": "<YOUR_DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI>",
        "DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL": "<YOUR_DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL>",
        "DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES": "<YOUR_DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES>",
        "DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION": "<YOUR_DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION>",
        "DATAPRISM_SECURITY_POLICY_PURPOSES": "<YOUR_DATAPRISM_SECURITY_POLICY_PURPOSES>",
        "DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR": "<YOUR_DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR>",
        "DATAPRISM_PRIVACY_PROFILE": "<YOUR_DATAPRISM_PRIVACY_PROFILE>",
        "DATAPRISM_PRIVACY_SCOPE_LIFETIME": "<YOUR_DATAPRISM_PRIVACY_SCOPE_LIFETIME>",
        "DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID": "<YOUR_DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID>",
        "DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE": "<YOUR_DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE>",
        "DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE": "<YOUR_DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE>",
        "DATAPRISM_AUDIT_SINK": "<YOUR_DATAPRISM_AUDIT_SINK>",
        "DATAPRISM_AUDIT_WRITER_ID": "<YOUR_DATAPRISM_AUDIT_WRITER_ID>",
        "DATAPRISM_AUDIT_FILE_PATH": "<YOUR_DATAPRISM_AUDIT_FILE_PATH>",
        "DATAPRISM_METRICS_SINK": "<YOUR_DATAPRISM_METRICS_SINK>",
        "DATAPRISM_HAZELCAST_TOPOLOGY": "<YOUR_DATAPRISM_HAZELCAST_TOPOLOGY>",
        "DATAPRISM_SOURCES_CUSTOMER_BASE_URL": "<YOUR_DATAPRISM_SOURCES_CUSTOMER_BASE_URL>",
        "DATAPRISM_SOURCES_CUSTOMER_TIMEOUT": "<YOUR_DATAPRISM_SOURCES_CUSTOMER_TIMEOUT>"
      }
    }
  }
}

Related MCP servers

8 EU accounting (x402 USDC on Base): reconcile, VAT, invoicing. Free health.

LLM caching proxy (x402 USDC on Base) - exact + semantic cache. Free health.

4 web-search tiers (x402 USDC on Base) - simple/medium/deep/cached. Free health.

22 utility tools (x402 USDC on Base): currency, PDF, image, GDPR. Free health.

AVAvalanche AVAX MCP logo

Search and retrieve Avalanche blockchain documentation for building on AVAX.

0
JavaScript
MIT
View repository →