Skip to main content

Apache Doris MCP Server

English | 简体中文

Apache Doris MCP Server exposes read-only Apache Doris capabilities to MCP Hosts and AI agents over MCP 2026-07-28. Version 1.0 replaces a large flat tool surface with eight stable domains and fifty-five progressively disclosed child capabilities, while keeping runtime availability, authorization, input schemas, output schemas, and failure behavior explicit.

Release status

The package version is 1.0.0. MCP 2026-07-28 protocol compatibility on master is Generally Available (GA) on Streamable HTTP and stdio. This GA statement is scoped to protocol compatibility; the Python package classifier remains Beta, and the documented deployment limits still apply.

Before upgrading, read the 1.0 release notes, the 1.0 migration guide, and the generated 8-domain/55-child registry. The detailed release record is Issue #189.

Architecture at a glance

MCP Host
  -> stdio or Streamable HTTP
  -> transport security and authentication
  -> MCP protocol validation and authorization
  -> stable domain discovery
  -> route-aware Doris capability detection
  -> exact child dispatch and read-only runtime
  -> request-specific Doris route and RBAC
  -> bounded, schema-validated result

The default hierarchical mode exposes these domains:

Domain Children Responsibility
doris_catalog 5 catalogs, databases, tables, table context, size
doris_query 7 query, explain, profile, diagnosis, slow queries, explicit ADBC
doris_cluster 11 nodes, tasks, metrics, memory, cache, compaction, workloads
doris_pipeline 5 ingestion, materialized views, freshness, dependencies
doris_search 4 text/vector/hybrid search, analyzers, indexes, diagnosis
doris_governance 8 quality, storage, lineage, audit, UDFs, auth mapping
doris_lakehouse 3 external catalogs, lakehouse tables, Variant
doris_semantic 12 optional Apache Ossie grounding and MetricFlow consumption

Call a domain with {} to discover its authorized children and exact schemas. Call the same domain again with child_tool, arguments, and the returned manifest_version. Hosts that cannot use progressive disclosure may set MCP_TOOL_EXPOSURE_MODE=flat before startup; this exposes the same 55 children under collision-free formal names and does not restore pre-1.0 aliases.

See Architecture, Request lifecycle, and Tool domains.

Quick start

Requirements:

  • Python 3.12 or later;
  • Apache Doris 2.0.0 or later;
  • network access to the Doris FE MySQL endpoint, normally port 9030.

Install the pinned release:

pip install doris-mcp-server==1.0.0

doris-mcp-server starts the Server. doris-mcp-client is a separate client; the two commands are not interchangeable.

Configure a Doris route:

export DORIS_HOST=127.0.0.1
export DORIS_PORT=9030
export DORIS_USER=root
export DORIS_PASSWORD='replace-me'
export DORIS_DATABASE=information_schema

Start Streamable HTTP on loopback:

doris-mcp-server \
  --transport http \
  --host 127.0.0.1 \
  --port 3000

Endpoints:

  • MCP: POST http://127.0.0.1:3000/mcp
  • liveness: GET http://127.0.0.1:3000/live
  • Doris-backed readiness: GET http://127.0.0.1:3000/ready

Or run stdio for a local Host:

doris-mcp-server --transport stdio

See the complete Quick start and Host integration guide.

Security boundary

  • The built-in 1.0 catalog is read-only; doris_admin is reserved and not registered.
  • Static tokens, JWT, external OAuth/OIDC, and Doris-backed OAuth are supported under mutually validated configuration boundaries.
  • Domain discovery and child execution use exact authorization identifiers.
  • Doris RBAC remains the final authority for visible objects and data.
  • SQL shape, identifiers, parameters, timeout, rows, bytes, and result schemas are bounded before data leaves the Server.
  • Secrets and backend errors are redacted from public results and logs.
  • Non-loopback HTTP requires authentication unless an explicit dangerous development override is enabled.

Read the Security and permission model and the Doris fine-grained access guide.

Reliability boundary

The Server uses deterministic manifests and errors, signed expiring cursors, route-aware capability snapshots, bounded stale fallback, request-specific connection routing, multi-FE failover, liveness/readiness separation, output Schema validation, and sanitized trace propagation. Unsupported or misconfigured capabilities remain discoverable with callable=false and fail closed when called.

Current limits include process-local Doris-backed OAuth, explicit-only ADBC that is disabled by default and fail-closed on token-bound routes, optional read-only Ossie grounding, an optional MetricFlow compiler sidecar whose SQL must execute through the bounded MCP query runtime, and best-effort native lineage delivery. See Reliability and limits.

Documentation

The root README is intentionally an entry point. The bilingual documentation system is indexed at:

Primary guides:

Development

git clone https://github.com/apache/doris-mcp-server.git
cd doris-mcp-server
uv sync --group dev
uv run pytest

Generated artifacts must remain synchronized:

uv run python generate_tool_catalog.py --check
uv lock --check

See Contributing and verification.

License

Apache License 2.0. See LICENSE.txt and NOTICE.

Metadata

Release files for doris-mcp-server 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for doris-mcp-server 1.0.0
File Size Uploaded
doris_mcp_server-1.0.0.tar.gz 632.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for doris-mcp-server 1.0.0
File Interpreter ABI Platform
doris_mcp_server-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 1.2 MB

Release files / doris_mcp_server-1.0.0.tar.gz

Download URL doris_mcp_server-1.0.0.tar.gz
Size 632.5 kB
Tags Source
SHA-256 checksum
How to use checksums
c8a4369cc223bd81c35578ad664dd3b3ea3c32620bedc8457f1e1db3a07e93aa
BLAKE2b-256 checksum
How to use checksums
d9af7618449ec500fe530b92cb11b82c10768a525e129e0daaad705e2847e392
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.12.9

Release files / doris_mcp_server-1.0.0-py3-none-any.whl

Download URL doris_mcp_server-1.0.0-py3-none-any.whl
Size 588.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
4c8e7084ab0b9e1afcfb7fb125ed20a20867c8169e342239702689a5c7d072db
BLAKE2b-256 checksum
How to use checksums
2422fc0160c6c2274ba3679575c8ce4f24ff42b4907614bf7e0e55c404c47597
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.12.9

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

0.6.1

2 release files

0.6.0

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.2

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page