Lagaam
Stop your agent's query from taking down a shared Trino or Pinot cluster. Lagaam is an MCP server that sits between your AI agents and your lakehouse (Trino and Apache Pinot). Every query is schema-grounded, priced before it runs, checked against a budget, and audited. Over budget, it is refused before it runs — and the rejection tells the agent exactly how to fix its SQL.
Run it
Against the Trino you already have:
TRINO_HOST=trino.internal LAGAAM_ALLOWED_TABLES=hive.sales.orders uvx lagaam
Wire it into any MCP client (Claude Code, Claude Desktop, or your own agent):
{
"mcpServers": {
"lagaam": {
"command": "uvx",
"args": ["lagaam"],
"env": {
"TRINO_HOST": "localhost",
"LAGAAM_MAX_SCAN_BYTES": "5368709120",
"LAGAAM_ALLOWED_TABLES": "hive.sales.orders,hive.sales.customers"
}
}
}
}
The agent gets three tools — list_catalogs, describe_table,
query_data — and cannot reach the engine any other way.
Configure it
| Env var | Meaning | Default |
|---|---|---|
LAGAAM_ALLOWED_TABLES |
Comma list of catalog.schema.table grants |
required |
TRINO_HOST / TRINO_PORT / TRINO_USER |
Trino coordinator | localhost / 8080 / lagaam |
LAGAAM_ENGINE |
pinot to run the native Pinot adapter |
trino |
PINOT_CONTROLLER_URL / PINOT_BROKER_URL |
Pinot controller and broker | http://localhost:9000 / http://localhost:8000 |
LAGAAM_MAX_SCAN_BYTES |
Scan-bytes budget per query, pre-execution | 50 GiB |
The server will not start without LAGAAM_ALLOWED_TABLES. An agent that
can reach every table in every catalog is the thing this exists to prevent, so
that has to be asked for — set LAGAAM_ALLOW_ALL_TABLES=true if you mean it.
Every budget and setting: Configuration.
Full docs: github.com/lagaam-ai/lagaam
Release files for lagaam 0.2.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| lagaam-0.2.4.tar.gz | 107.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| lagaam-0.2.4-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 233.5 kB
Release files / lagaam-0.2.4.tar.gz
| Download URL | lagaam-0.2.4.tar.gz |
|---|---|
| Size | 107.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
4f2952325ba89fc91680fdd6dabe538b7737f45511d489f7ef3149e3152c17eb
|
|
BLAKE2b-256 checksum How to use checksums |
d2cba099a09fd4a43abc0a8c552fa06f248633b3bd55785d9336ae4853c6b04e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.
Transparency logRelease files / lagaam-0.2.4-py3-none-any.whl
| Download URL | lagaam-0.2.4-py3-none-any.whl |
|---|---|
| Size | 126.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
da6f49176b1de0893100f1b13402f0736f2feb58847f23a6f635dee4f8923201
|
|
BLAKE2b-256 checksum How to use checksums |
2cc75150accd86dba29407194c66ad34bc97ee4a87eea9006cf17333541ed536
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.
Transparency log