DataCharter MCP Server
io.github.datacharter/datacharter
Local-first SQL workspace with contract-governed, PII-masked query access for AI agents.
What is the DataCharter MCP server?
DataCharter is a local SQL workspace that lets you query files and databases via DuckDB, governed by a charter.yaml contract. Agents get read-only, PII-masked access to exactly the columns and rows you authorize, with no data leaving your infrastructure.
DataCharter provides a secure, contract-based data exploration layer for AI agents. You define data access policies in charter.yaml (row filters, PII masking, aggregation rules), and agents see only what the contract permits. Works on your laptop as a web app or desktop client, or deploys to your company infrastructure via MCP with OAuth and audit logging.
How to install DataCharter
Copy-paste configuration for popular MCP clients.
Tools & capabilities
Tools this server exposes to the agent.
SQL Query Tool— Execute read-only SQL queries against federated data sources (files and databases) via DuckDBPII Masking— Automatically mask personally identifiable information in query results based on charter.yaml policiesRow Filtering— Apply row-level access controls defined in the contract to limit which records agents can seeAudit Logging— Hash-chained audit trail of all queries and access attempts with SIEM JSON/OTLP exportPolicy Enforcement— Plain-English policy rules including aggregates-only mode, canaries, and default-deny access control
Use cases
- Give AI agents read-only access to your database with automatic PII redaction for sensitive columns
- Define fine-grained data access policies (row filters, aggregation rules) in a git-tracked charter.yaml file
- Deploy a shared MCP data endpoint for your team with OAuth identity and audit logging
- Explore local CSV/Parquet files and databases through a web UI or desktop app without moving data
- Red-team your data governance policies to find access control gaps before production
DataCharter MCP server FAQ
DataCharter is a local-first SQL workspace that lets you query files and databases with AI agents, enforcing read-only access and PII masking via a charter.yaml contract. No data leaves your infrastructure.
Yes, DataCharter is open-source under Apache-2.0 with no paid edition. You can use it on your laptop or deploy it to your infrastructure.
Install via pip (pip install datacharter) for Python 3.11+, or use the desktop app (beta) for macOS or Windows. Run 'datacharter serve' to start the web UI.
DataCharter exposes an MCP endpoint. Configure your client to connect to the MCP server (localhost:8321 for local, or your deployed endpoint), and agents will access data through the charter.yaml policies.
For local use, no. For company/shared deployments, DataCharter supports OAuth 2.1 and identity-based access control defined in charter.yaml.
PII masking, row-level filters, plain-English policies, canaries, hash-chained audit logging, and a red-team tool to test your governance policies.
README (reference)
Source of truth, from the repository.
DataCharter
Query all your data locally. Hand agents exactly the columns you choose.
A local SQL workspace over files and databases, federated by DuckDB and
governed by charter.yaml. Agents get read-only, PII-masked access to what
the contract grants. Apache-2.0. No paid edition.
datacharter.dev · Docs · Desktop · GovBench · Deploy
Two ways in. Same kernel.
Laptop
Drop a file. Query it. Chart it. An agent sees ••• where PII lives.
uvx datacharter serve # demo workspace, http://127.0.0.1:8321
# or: datacharter init --from && datacharter serve
# or: datacharter init --template life && datacharter serve --local
No terminal: desktop app (beta). macOS (Apple Silicon) or Windows. Unsigned until Apple secrets exist.
brew install datacharter/tap/datacharter # macOS
pip install datacharter # Python 3.11+
The workspace is a directory: charter.yaml, queries/, guides/. Commit it.
Secrets stay out. Optional agent: SpaceXAI, Claude Code, Ollama (--local),
or any OpenAI-compatible endpoint.
Company
The same binary, on a shared MCP endpoint. Identities live in git, not on our servers. No rows leave your infrastructure.
datacharter mcp --http --host 0.0.0.0 # OAuth env required off loopback
helm install datacharter ./chart \
--set oauth.issuer=... --set oauth.audience=... --set oauth.jwksUri=...
datacharter govbench --json # cite corpus govbench-v1
- MCP Streamable HTTP (
POST /mcp) with optional OAuth 2.1 principals:andgrants:incharter.yaml(default-deny on HTTP)- Helm chart and OCI image
- Hash-chained audit plus SIEM JSON/OTLP
- GovBench: frozen 28-attack corpus, grade A-F
Wrap someone else's MCP server: datacharter mcp --guard "npx -y some-mcp-server".
What the contract enforces
PII default-deny, row filters, plain-English policies (aggregates only),
canaries, a flight recorder, datacharter redteam, access diff on PRs.
CLI reference: docs/cli.md. Security: docs/security.md.
Status: pre-release. V1 in development.
Privacy
Runs on your machine or in your cluster. No telemetry. No DataCharter-operated data plane. Privacy Policy.
License
Related MCP servers

io.github.datahogo/datahogo
Scan a project for security issues locally with the open-source Data Hogo engine.

io.github.datalattice/mcp-chainladder
Actuarial chain-ladder reserving: IBNR, Mack stochastic stats, and assumption diagnostics.
MCP server for dbatools — exposes SQL Server management commands as MCP tools

DataRaum
Pre-computed metadata context engine for AI-driven data analytics
Observes tasks and generates anonymized SOPs — task tracking and SOP review via MCP. Fully local.
View repository →MCP-first read-only discovery of your infra & SaaS landscape as MCP resources, tools and prompts.
View repository →
