PluginBench
MCP Server
Active
MIT

fabric-dw MCP Server

io.github.sdebruyn/fabric-dw-mcp

MCP server for administering, querying, and optimizing Microsoft Fabric Data Warehouses and SQL Analytics Endpoints.

What is the fabric-dw MCP server?

The fabric-dw MCP server exposes Microsoft Fabric Data Warehouse and SQL Analytics Endpoint operations as tools for AI assistants. It provides capabilities for querying, performance monitoring, optimization, governance, and data management through a Model Context Protocol interface, with optional read-only and destructive-operation restrictions.

fabric-dw lets you manage Microsoft Fabric Data Warehouses and SQL Analytics Endpoints from Claude, Cursor, or other MCP clients. Execute queries, monitor long-running operations, optimize performance, manage permissions (including row-level and column-level security), export snapshots, and scaffold dbt projects—all without leaving your AI agent or terminal.

How to install fabric-dw

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • FABRIC_AUTH

    Azure credential source: 'default' (DefaultAzureCredential chain), 'sp' (service principal, needs AZURE_TENANT_ID/AZURE_CLIENT_ID/AZURE_CLIENT_SECRET), or 'interactive' (browser sign-in).

  • FABRIC_MCP_READONLY

    Set to 1 to restrict execute_sql to SELECT/WITH statements and block all mutating tools.

  • FABRIC_MCP_ALLOW_DESTRUCTIVE

    Set to 1 to enable permanently-destructive tools (delete_*, clear_table, restore_warehouse_in_place). Disabled by default.

  • FABRIC_MCP_WORKSPACES

    Comma-separated workspace names or GUIDs the server may touch. Unset allows all workspaces.

  • FABRIC_MCP_ALLOW_REMOTE

    Set to 1 to allow the HTTP transport to bind on a non-loopback address. Always front with an authenticating reverse proxy.

  • FABRIC_LOG_LEVEL

    Log level for the MCP server (DEBUG, INFO, WARNING, ERROR, CRITICAL).

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "fabric-dw-mcp": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/sdebruyn/fabric-dw:2026.9.0"
      ],
      "env": {
        "FABRIC_AUTH": "<YOUR_FABRIC_AUTH>",
        "FABRIC_MCP_READONLY": "<YOUR_FABRIC_MCP_READONLY>",
        "FABRIC_MCP_ALLOW_DESTRUCTIVE": "<YOUR_FABRIC_MCP_ALLOW_DESTRUCTIVE>",
        "FABRIC_MCP_WORKSPACES": "<YOUR_FABRIC_MCP_WORKSPACES>",
        "FABRIC_MCP_ALLOW_REMOTE": "<YOUR_FABRIC_MCP_ALLOW_REMOTE>",
        "FABRIC_LOG_LEVEL": "<YOUR_FABRIC_LOG_LEVEL>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • execute_sql — Execute SQL queries against a warehouse or SQL Analytics Endpoint
  • sql_plan — Capture and visualize estimated execution plans as SVG
  • queries_running — View currently running queries
  • queries_long_running — Find long-running queries from a specified time window
  • queries_kill — Terminate a runaway query session by ID
  • queries_frequent — Identify most-repeated queries over a time period
  • statistics_show — Inspect table statistics with histograms and terminal bar charts
  • tables_cluster_by — Re-cluster a table on a new key with transactional CTAS-swap
  • tables_read — Browse table data at a point in time
  • tables_export — Export point-in-time snapshots to Parquet
  • tables_load — Load local Parquet files and auto-create tables from schema
  • permissions_grant — Grant SELECT or other permissions on specific tables
  • permissions_cls — Manage column-level security by denying access to sensitive columns
  • permissions_rls — Create row-level security policies to filter rows by user attributes
  • dbt_init — Scaffold a full dbt-fabric project wired to the warehouse
  • workspaces — List and manage Fabric workspaces
  • warehouses — List and manage Data Warehouses
  • schemas — Inspect and manage database schemas
  • tables — Manage tables including creation, deletion, and metadata
  • views — Manage views

Use cases

  • Execute ad-hoc SQL queries and capture execution plans without SSMS or Windows
  • Monitor and kill long-running queries to prevent warehouse bottlenecks
  • Optimize table performance by re-clustering on new keys and inspecting statistics
  • Implement fine-grained access control with column-level and row-level security policies
  • Export point-in-time snapshots for compliance, testing, or disaster recovery
  • Scaffold and manage dbt projects for Fabric Data Warehouses with AI assistance

fabric-dw MCP server FAQ

What is fabric-dw?

fabric-dw is an MCP server that exposes Microsoft Fabric Data Warehouse and SQL Analytics Endpoint operations as tools for AI assistants like Claude. It supports querying, performance monitoring, optimization, governance, and data management.

Is fabric-dw free?

Yes, fabric-dw is open-source under the MIT license. You only pay for Microsoft Fabric compute and storage.

How do I install it in Claude Desktop or Cursor?

Add the MCP server to your client config using `uvx --from fabric-dw fabric-dw-mcp`, or install via the plugin marketplace with `/plugin install fabric-dw@fabric-dw`. Set `FABRIC_AUTH` environment variable for authentication.

What authentication methods does it support?

fabric-dw uses Azure Identity's DefaultAzureCredential, which supports environment variables, Workload/Managed Identity, Azure CLI, Azure Developer CLI, Azure PowerShell, and interactive browser login. You can also configure service principal auth via `FABRIC_AUTH=sp`.

Can I restrict what the MCP server can do?

Yes. Set `FABRIC_MCP_READONLY=1` to block all mutating operations, `FABRIC_MCP_ALLOW_DESTRUCTIVE=1` to enable destructive tools (disabled by default), and `FABRIC_MCP_WORKSPACES` to limit which workspaces the server can access.

Does it work in Docker?

Yes. The Docker image at `ghcr.io/sdebruyn/fabric-dw` runs the MCP server by default, or you can override the entrypoint to run the CLI. Pass Azure credentials via environment variables.

README (reference)

Source of truth, from the repository.

<p align="center"> <a href="https://fdw.debruyn.dev"> <img src="https://raw.githubusercontent.com/sdebruyn/fabric-dw-mcp-cli/main/docs/assets/logo.svg" alt="fabric-dw logo" width="200" /> </a> </p> <h1 align="center">fabric-dw</h1> <p align="center"> <a href="https://fdw.debruyn.dev"><img src="https://img.shields.io/badge/docs-fdw.debruyn.dev-blue" alt="Documentation"></a> <a href="https://github.com/sdebruyn/fabric-dw-mcp-cli/actions/workflows/ci.yml"><img src="https://github.com/sdebruyn/fabric-dw-mcp-cli/actions/workflows/ci.yml/badge.svg" alt="CI"></a> <a href="https://codecov.io/gh/sdebruyn/fabric-dw-mcp-cli"><img src="https://codecov.io/gh/sdebruyn/fabric-dw-mcp-cli/graph/badge.svg" alt="codecov"></a> <a href="https://pypi.org/project/fabric-dw/"><img src="https://img.shields.io/pypi/v/fabric-dw" alt="PyPI version"></a> <a href="https://pypi.org/project/fabric-dw/"><img src="https://img.shields.io/pypi/pyversions/fabric-dw" alt="Python versions"></a> <a href="LICENSE"><img src="https://img.shields.io/github/license/sdebruyn/fabric-dw-mcp-cli" alt="License"></a> </p>

Python CLI and MCP server for Microsoft Fabric Data Warehouses and SQL Analytics Endpoints: administer, query, optimize, and secure them from your terminal or your AI agent.

Full documentation: fdw.debruyn.dev

📣 Just announced! Read the story behind fabric-dw in the announcement blog post.

Description

fabric-dw provides two interfaces for managing Microsoft Fabric Data Warehouses and SQL Analytics Endpoints:

  • CLI: a command-line tool for common DW administration tasks.
  • MCP server: a Model Context Protocol server that exposes DW operations as tools for AI assistants.

Authentication is configured via the FABRIC_AUTH environment variable. The default (FABRIC_AUTH=default) uses azure-identity DefaultAzureCredential, which walks environment variables, Workload/Managed Identity, Azure CLI, Azure Developer CLI, Azure PowerShell, and interactive browser in order. Any of these will satisfy it. See the Authentication docs for the full chain, all supported sources, and debugging tips.

Installation

pip install fabric-dw
# or run without installing:
uvx fabric-dw --help
# or install persistently on PATH:
uv tool install fabric-dw

After installation, the fdw command is a short alias for fabric-dw; both invoke the same entry point. See the Install docs for MCP server setup, upgrading, and prerelease builds.

Quick Start

CLI

The workspace is a global root option -w / --workspace placed before the command group. Set a default once with fdw config set workspace <NAME> and omit -w on every subsequent call. Workspace resolution order: (1) -w flag, (2) FABRIC_DW_DEFAULT_WORKSPACE env var, (3) configured default.

# Run without installing; install to get the fdw alias
uvx fabric-dw --help

# Set a default workspace once; all subsequent commands pick it up
fdw config set workspace SalesWS
# -- Run and explain SQL --

# Execute a query against a warehouse
fdw sql exec SalesWH -q "SELECT TOP 10 * FROM dbo.orders ORDER BY order_date DESC"

# Capture an estimated execution plan as SVG -- no SSMS or Windows needed
fdw sql plan SalesWH -f query.sql --format svg -o plan.svg

# -- Performance mission-control --

# See what is running right now
fdw queries running SalesWH

# Long-running queries from the past hour
fdw queries long-running SalesWH --ago 1h

# Kill a runaway session by ID
fdw queries kill SalesWH 55

# Most-repeated queries over the past 24 hours
fdw queries frequent SalesWH --ago 24h

# -- Optimize --

# Inspect a statistics histogram with inline terminal bar charts
fdw statistics show SalesWH dbo.orders st_order_date --histogram

# Re-cluster a table on a new key (transactional CTAS-swap, auto-rollback on failure)
fdw tables cluster-by SalesWH dbo.orders --cluster-by customer_id

# -- Time travel + export --

# Browse the table as it looked 2 hours ago
fdw tables read SalesWH dbo.orders --ago 2h

# Export a point-in-time snapshot to Parquet
fdw tables export SalesWH dbo.orders --output snapshot.parquet --ago 2h

# -- Governance --

# Grant SELECT on a specific table
fdw permissions sql grant SalesWH SELECT --to analyst@company.com --object dbo.orders

# Deny access to sensitive columns (column-level security)
fdw permissions cls deny SalesWH SELECT --to contractor@company.com \
    --object dbo.orders --columns salary,bonus

# Create a row-level security policy (filter rows by SalesRep)
fdw permissions rls create SalesWH rls.SalesFilter \
    --filter "rls.fn_sales_filter(SalesRep)" --on dbo.orders

# -- Load + scaffold --

# Load a local Parquet file and auto-create the table from its schema
fdw tables load SalesWH dbo.orders --file orders.parquet --create

# Scaffold a full dbt-fabric project wired to the warehouse
fdw dbt init SalesWH ./my-dbt-project --project-name sales_dw --with-sources

MCP Server

Add to your MCP client configuration (e.g. Claude Desktop, VS Code):

{
  "mcpServers": {
    "fabric-dw": {
      "command": "uvx",
      "args": ["--from", "fabric-dw", "fabric-dw-mcp"]
    }
  }
}

The MCP server exposes all CLI operations as MCP tools (workspaces, warehouses, SQL endpoints, schemas, tables, views, queries, snapshots, restore points, audit, statistics, permissions, sql-pools). Bundled Claude Code agent skills (query-optimizer, warehouse-performance, dbt-setup) are included for deeper AI-assisted analysis. Set FABRIC_AUTH in the environment if you need a non-default auth mode.

Both the skills and the MCP server install in one command via the fabric-dw plugin marketplace, for Claude Code and GitHub Copilot CLI alike: /plugin marketplace add sdebruyn/fabric-dw-mcp-cli then /plugin install fabric-dw@fabric-dw. See the Agent Skills docs for details.

Run in Docker

The Docker image's default ENTRYPOINT is the MCP server (fabric-dw-mcp). Use it as-is with your MCP client, or override the entrypoint to run the CLI instead.

docker pull ghcr.io/sdebruyn/fabric-dw:latest

# Run the MCP server (default entrypoint, connect via stdio from your MCP client):
docker run --rm -i \
  -e AZURE_CLIENT_ID=… \
  -e AZURE_TENANT_ID=… \
  -e AZURE_CLIENT_SECRET=… \
  -e FABRIC_AUTH=sp \
  ghcr.io/sdebruyn/fabric-dw

# Run the CLI instead (override the entrypoint):
docker run --rm \
  --entrypoint fabric-dw \
  -e AZURE_CLIENT_ID=… \
  -e AZURE_TENANT_ID=… \
  -e AZURE_CLIENT_SECRET=… \
  -e FABRIC_AUTH=sp \
  ghcr.io/sdebruyn/fabric-dw --help

Dev images (built from every main merge): ghcr.io/sdebruyn/fabric-dw:main or :<version>.dev<N>.

Package page: ghcr.io/sdebruyn/fabric-dw

Security environment variables

VariableDefaultDescription
FABRIC_MCP_READONLYunsetSet to 1 to restrict execute_sql to SELECT/WITH and block all mutating tools.
FABRIC_MCP_ALLOW_DESTRUCTIVEunsetSet to 1 to enable permanently-destructive tools (delete_*, clear_table, restore_warehouse_in_place). Disabled by default.
FABRIC_MCP_WORKSPACESunsetComma-separated workspace names or GUIDs the server may touch. Unset = all workspaces allowed.
FABRIC_MCP_ALLOW_REMOTEunsetSet to 1 to allow the HTTP transport (--transport http) to bind on a non-loopback address. A warning is logged; ensure an authenticating reverse proxy with TLS fronts the endpoint, and pass --allowed-host so Host validation stays on. See Hosting the MCP server.

HTTP transport

The MCP server can be started in HTTP mode for remote clients:

fabric-dw-mcp --transport http [--host 127.0.0.1] [--port 8000]

It binds to loopback by default, where Host and Origin validation is handled for you. Binding anywhere else requires FABRIC_MCP_ALLOW_REMOTE=1 and --allowed-host, and the endpoint has no built-in authentication or TLS, so always front it with an authenticating reverse proxy. See Hosting the MCP server for that setup.

Develop in a container

Open the repo in GitHub Codespaces or VS Code's Remote-Containers extension. The devcontainer pre-installs Python 3.14, uv, Azure CLI, and the GitHub CLI.

Open in GitHub Codespaces

Contributing

See CONTRIBUTING.md for dev setup, branch flow, and how to run tests locally.

📖 Docs: fdw.debruyn.dev (or run uv run --only-group docs zensical serve locally).

Security

Please report vulnerabilities privately. See SECURITY.md.

Code of Conduct

This project follows the Contributor Covenant 2.1.

License

MIT. Copyright (c) 2026 Sam Debruyn

Related MCP servers

Nationwide Korea: bus stops in 138 cities, 30-year climate normals, tourism (KR/EN).

0
JavaScript
MIT
View repository →

Korea tide times (42 stations) plus fishing, mudflat, beach, surf and scuba forecasts.

0
JavaScript
MIT
View repository →
PRPromptlint MCP logo

Promptlint MCP

Maintained

Static linter for AI prompts: contradictions, redundancy, ambiguity, and fluff.

1
JavaScript
MIT
View repository →

Publish content to the web by emailing POST@abovo.co. No API key, no signup. SMTP is the API.

0
TypeScript
MIT
View repository →

AI sports betting picks, odds, injuries & line movement. 1,353+ picks, 59.6% win rate.

5
Python
MIT
View repository →

Trading card prices: daily TCGplayer market, history since 2024, sold comps, PSA 10 floors. 6 games.