What is the Data Prism MCP server?
Fail-closed privacy layer that pseudonymises enterprise API data for LLM agents and MCP clients.
How to install Data Prism
Copy-paste configuration for popular MCP clients.
LOADER_PATHrequiredDirectory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above)
DATAPRISM_SECURITY_JWT_ISSUERrequiredOAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment
DATAPRISM_SECURITY_JWT_AUDIENCErequiredExpected JWT audience claim for this deployment; required for every protected deployment
DATAPRISM_SECURITY_JWT_JWK_SET_URIrequiredHTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both
DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URIAlternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both
DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPALrequiredJWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims
DATAPRISM_SECURITY_CALLER_CLAIMS_ROLESrequiredJWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims
DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATIONrequiredJWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims
DATAPRISM_SECURITY_POLICY_PURPOSESrequiredComma-separated list of permitted purposes; at least one is required
DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATORrequiredExample only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 3.5.16), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required
DATAPRISM_PRIVACY_PROFILErequiredName of the reviewed privacy profile implementation to apply; required
DATAPRISM_PRIVACY_SCOPE_LIFETIMErequiredPositive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required
DATAPRISM_PRIVACY_HMAC_KEY_KEY_IDrequiredIdentifier of the pinned HMAC key used to derive synthetic identities; required
DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLErequiredName of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value
DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCEReference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both
DATAPRISM_AUDIT_SINKrequiredAudit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op
DATAPRISM_AUDIT_WRITER_IDrequiredWriter/instance identity recorded on every audit entry; required
DATAPRISM_AUDIT_FILE_PATHPath to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise
DATAPRISM_METRICS_SINKrequiredMetrics sink binding, currently only micrometer; required in production, never the framework no-op
DATAPRISM_HAZELCAST_TOPOLOGYrequiredCluster read-budget topology: embedded (shared across the cluster) or single-node (enforced per process); required, never defaulted
DATAPRISM_SOURCES_CUSTOMER_BASE_URLrequiredExample only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required
DATAPRISM_SOURCES_CUSTOMER_TIMEOUTrequiredExample only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL
Related MCP servers
8 EU accounting (x402 USDC on Base): reconcile, VAT, invoicing. Free health.
LLM caching proxy (x402 USDC on Base) - exact + semantic cache. Free health.
4 web-search tiers (x402 USDC on Base) - simple/medium/deep/cached. Free health.
22 utility tools (x402 USDC on Base): currency, PDF, image, GDPR. Free health.

Avalanche AVAX MCP
Search and retrieve Avalanche blockchain documentation for building on AVAX.
