PluginBench
MCP Server
Active
Apache-2.0

DataCharter MCP Server

io.github.datacharter/datacharter

Local-first SQL workspace with contract-governed, PII-masked query access for AI agents.

What is the DataCharter MCP server?

DataCharter is a local SQL workspace that lets you query files and databases via DuckDB, governed by a charter.yaml contract. Agents get read-only, PII-masked access to exactly the columns and rows you authorize, with no data leaving your infrastructure.

DataCharter provides a secure, contract-based data exploration layer for AI agents. You define data access policies in charter.yaml (row filters, PII masking, aggregation rules), and agents see only what the contract permits. Works on your laptop as a web app or desktop client, or deploys to your company infrastructure via MCP with OAuth and audit logging.

How to install DataCharter

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "datacharter": {
      "command": "uvx",
      "args": [
        "datacharter",
        "mcp",
        "workspace"
      ]
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • SQL Query Tool — Execute read-only SQL queries against federated data sources (files and databases) via DuckDB
  • PII Masking — Automatically mask personally identifiable information in query results based on charter.yaml policies
  • Row Filtering — Apply row-level access controls defined in the contract to limit which records agents can see
  • Audit Logging — Hash-chained audit trail of all queries and access attempts with SIEM JSON/OTLP export
  • Policy Enforcement — Plain-English policy rules including aggregates-only mode, canaries, and default-deny access control

Use cases

  • Give AI agents read-only access to your database with automatic PII redaction for sensitive columns
  • Define fine-grained data access policies (row filters, aggregation rules) in a git-tracked charter.yaml file
  • Deploy a shared MCP data endpoint for your team with OAuth identity and audit logging
  • Explore local CSV/Parquet files and databases through a web UI or desktop app without moving data
  • Red-team your data governance policies to find access control gaps before production

DataCharter MCP server FAQ

What is DataCharter?

DataCharter is a local-first SQL workspace that lets you query files and databases with AI agents, enforcing read-only access and PII masking via a charter.yaml contract. No data leaves your infrastructure.

Is DataCharter free?

Yes, DataCharter is open-source under Apache-2.0 with no paid edition. You can use it on your laptop or deploy it to your infrastructure.

How do I install DataCharter?

Install via pip (pip install datacharter) for Python 3.11+, or use the desktop app (beta) for macOS or Windows. Run 'datacharter serve' to start the web UI.

How do I use DataCharter with Claude or Cursor?

DataCharter exposes an MCP endpoint. Configure your client to connect to the MCP server (localhost:8321 for local, or your deployed endpoint), and agents will access data through the charter.yaml policies.

Does DataCharter require authentication?

For local use, no. For company/shared deployments, DataCharter supports OAuth 2.1 and identity-based access control defined in charter.yaml.

What security features does DataCharter provide?

PII masking, row-level filters, plain-English policies, canaries, hash-chained audit logging, and a red-team tool to test your governance policies.

README (reference)

Source of truth, from the repository.

DataCharter

Query all your data locally. Hand agents exactly the columns you choose.

A local SQL workspace over files and databases, federated by DuckDB and governed by charter.yaml. Agents get read-only, PII-masked access to what the contract grants. Apache-2.0. No paid edition.

<!-- mcp-name: io.github.datacharter/datacharter -->

PyPI Python License: Apache-2.0

datacharter.dev · Docs · Desktop · GovBench · Deploy

Two ways in. Same kernel.

Laptop

Drop a file. Query it. Chart it. An agent sees ••• where PII lives.

uvx datacharter serve          # demo workspace, http://127.0.0.1:8321
# or: datacharter init --from && datacharter serve
# or: datacharter init --template life && datacharter serve --local

No terminal: desktop app (beta). macOS (Apple Silicon) or Windows. Unsigned until Apple secrets exist.

brew install datacharter/tap/datacharter   # macOS
pip install datacharter                    # Python 3.11+

The workspace is a directory: charter.yaml, queries/, guides/. Commit it. Secrets stay out. Optional agent: SpaceXAI, Claude Code, Ollama (--local), or any OpenAI-compatible endpoint.

Company

The same binary, on a shared MCP endpoint. Identities live in git, not on our servers. No rows leave your infrastructure.

datacharter mcp --http --host 0.0.0.0   # OAuth env required off loopback
helm install datacharter ./chart \
  --set oauth.issuer=... --set oauth.audience=... --set oauth.jwksUri=...
datacharter govbench --json             # cite corpus govbench-v1
  • MCP Streamable HTTP (POST /mcp) with optional OAuth 2.1
  • principals: and grants: in charter.yaml (default-deny on HTTP)
  • Helm chart and OCI image
  • Hash-chained audit plus SIEM JSON/OTLP
  • GovBench: frozen 28-attack corpus, grade A-F

Wrap someone else's MCP server: datacharter mcp --guard "npx -y some-mcp-server".

What the contract enforces

PII default-deny, row filters, plain-English policies (aggregates only), canaries, a flight recorder, datacharter redteam, access diff on PRs. CLI reference: docs/cli.md. Security: docs/security.md.

Status: pre-release. V1 in development.

Privacy

Runs on your machine or in your cluster. No telemetry. No DataCharter-operated data plane. Privacy Policy.

License

Apache-2.0

Related MCP servers

Scan a project for security issues locally with the open-source Data Hogo engine.

0
TypeScript
AGPL-3.0
View repository →

Actuarial chain-ladder reserving: IBNR, Mack stochastic stats, and assumption diagnostics.

0
Python
View repository →

MCP server for dbatools — exposes SQL Server management commands as MCP tools

4
TypeScript
MIT
View repository →
DADataRaum logo

DataRaum

Active

Pre-computed metadata context engine for AI-driven data analytics

3
Python
Apache-2.0
View repository →

Observes tasks and generates anonymized SOPs — task tracking and SOP review via MCP. Fully local.

View repository →

MCP-first read-only discovery of your infra & SaaS landscape as MCP resources, tools and prompts.

View repository →