Apache Doris
About
MCP Server For [Apache Doris](https://doris.apache.org/), an MPP-based real-time data warehouse.
Details
- License
- MIT license
Explore
MCP Protocol Implementation: Provides standard MCP interfaces, supporting tool calls, resource management, and prompt interactions.
Streamable HTTP Communication: Unified HTTP endpoint supporting both request/response and streaming communication for optimal performance and reliability.
Stdio Communication: Standard input/output mode for direct integration with MCP clients like Cursor.
Enterprise-Grade Architecture: Modular design with comprehensive functionality:
Tools Manager: Centralized tool registration and routing with unified interfaces (doris_mcp_server/tools/tools_manager.py)
Enhanced Monitoring Tools Module: Advanced memory tracking, metrics collection, and flexible BE node discovery with modular, extensible design
Query Information Tools: Enhanced SQL explain and profiling with configurable content truncation, file export for LLM attachments, and advanced query analytics
Resources Manager: Resource management and metadata exposure (doris_mcp_server/tools/resources_manager.py)
Prompts Manager: Intelligent prompt templates for data analysis (doris_mcp_server/tools/prompts_manager.py)
Advanced Database Features:
Query Execution: High-performance SQL execution with advanced caching and optimization, enhanced connection stability and automatic retry mechanisms (doris_mcp_server/utils/query_executor.py)
Security Management: Comprehensive SQL security validation with configurable blocked keywords, SQL injection protection, data masking, and unified security configuration management (doris_mcp_server/utils/security.py)
Metadata Extraction: Comprehensive database metadata with catalog federation support (doris_mcp_server/utils/schema_extractor.py)
Performance Analysis: Advanced column analysis, performance monitoring, and data analysis tools (doris_mcp_server/utils/analysis_tools.py)
Catalog Federation Support: Full support for multi-catalog environments (internal Doris tables and external data sources like Hive, MySQL, etc.)
Enterprise Security: Comprehensive security framework with authentication, authorization, SQL injection protection, and data masking capabilities with environment variable configuration support
Web-Based Token Management: Secure localhost-only interface for complete token lifecycle management with database binding, real-time statistics, and enterprise-grade access controls (doris_mcp_server/auth/token_handlers.py)
Unified Configuration Framework: Centralized configuration management through config.py with comprehensive validation, standardized parameter naming, and smart default database handling with automatic fallback to information_schema
Multi-Catalog Metadata Access: All metadata tools (get_db_list, get_db_table_list, get_table_schema, etc.) support an optional catalog_name parameter to query specific catalogs.
Cross-Catalog SQL Queries: Execute SQL queries that span multiple catalogs using three-part table naming.
Catalog Discovery: Use get_catalog_list to discover available catalogs and their types.
π Multi-Authentication System: Complete Token, JWT, and OAuth authentication with independent control switches
π Token-Bound Database Configuration: Revolutionary approach allowing tokens to carry their own database connection parameters
π Hot Reload Security: Zero-downtime security configuration updates with intelligent token revalidation
β‘ Immediate Validation: Real-time database and authentication validation at connection time
π‘οΈ Role-Based Authorization: Advanced RBAC with four-tier security classification
π« Enhanced SQL Security: Advanced SQL injection protection with improved pattern detection
π Intelligent Data Masking: Automatic sensitive data masking with user-based permissions
- π Security Analytics: Comprehensive audit trails and security monitoring
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
Apache DorisCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
Interaction with the Doris MCP Server requires an MCP Client. The client connects to the server's Streamable HTTP endpoint and sends requests according to the MCP specification to invoke the server's tools.
Main Interaction Flow:
1. Client Initialization: Send an initialize method call to /mcp (Streamable HTTP).
2. (Optional) Discover Tools: The client can call tools/list to get the list of supported tools, their descriptions, and parameter schemas.
3. Call Tool: The client sends a tools/call request, specifying the name and arguments.
Example: Get Table Schema
name: get_table_schema
arguments: Include table_name, db_name, catalog_name.
4. Handle Response:
Non-streaming: The client receives a response containing content or isError.
Streaming: The client receives a series of progress notifications, followed by a final response.
pip install doris-mcp-server
pip install doris-mcp-server==0.6.0
> π‘ Command Compatibility: After installation, both doris-mcp-server commands are available for backward compatibility. You can use either command interchangeably.
doris-mcp-server \
--transport http \
--host 0.0.0.0 \
--port 3000 \
--db-host 127.0.0.1 \
--db-port 9030 \
--db-user root \
--db-password your_password
ENABLE_HTTP_TOKEN_MANAGEMENT=true
ENABLE_TOKEN_AUTH=true
TOKEN_MANAGEMENT_ADMIN_TOKEN=your_secure_admin_token
TOKEN_MANAGEMENT_ALLOWED_IPS=127.0.0.1,::1
doris-mcp-server --help
Instead of command-line arguments, you can use environment variables:
bash
export DORIS_HOST="127.0.0.1"
export DORIS_PORT="9030"
export DORIS_USER="root"
export DORIS_PASSWORD="your_password"
For developers who want to build from source:
pip install -r requirements.txt
Copy the .env.example file to .env and modify the settings according to your environment:
cp .env.example .env
Key Environment Variables:
Database Connection:
DORIS_HOST: Database hostname (default: localhost)
DORIS_PORT: Database port (default: 9030)
DORIS_USER: Database username (default: root)
DORIS_PASSWORD: Database password
DORIS_DATABASE: Default database name (default: information_schema)
DORIS_MIN_CONNECTIONS: Minimum connection pool size (default: 5)
DORIS_MAX_CONNECTIONS: Maximum connection pool size (default: 20)
DORIS_BE_HOSTS: BE nodes for monitoring (comma-separated, optional - auto-discovery via SHOW BACKENDS if empty)
DORIS_BE_WEBSERVER_PORT: BE webserver port for monitoring tools (default: 8040)
FE_ARROW_FLIGHT_SQL_PORT: Frontend Arrow Flight SQL port for ADBC (New in v0.5.0)
BE_ARROW_FLIGHT_SQL_PORT: Backend Arrow Flight SQL port for ADBC (New in v0.5.0)
Authentication Configuration (Enhanced in v0.6.0):
ENABLE_TOKEN_AUTH: Enable token-based authentication (default: false)
ENABLE_JWT_AUTH: Enable JWT authentication (default: false)
ENABLE_OAUTH_AUTH: Enable OAuth authentication (default: false)
ENABLE_DORIS_OAUTH_AUTH: Enable Doris-backed OAuth authentication (default: false)
DORIS_OAUTH_BASE_URL: Public base URL used by Doris-backed OAuth discovery and token endpoints
TOKEN_FILE_PATH: Path to tokens.json file for token management (default: tokens.json)
TOKEN_HOT_RELOAD: Enable hot reloading of token configuration (default: true)
DEFAULT_ADMIN_TOKEN: Default admin token (customizable via env)
DEFAULT_ANALYST_TOKEN: Default analyst token (customizable via env)
DEFAULT_READONLY_TOKEN: Default readonly token (customizable via env)
Legacy Security Configuration:
AUTH_TYPE: Legacy authentication type (token/basic/oauth, deprecated - use individual switches)
TOKEN_SECRET: Legacy token secret key (use token-based auth instead)
ENABLE_SECURITY_CHECK: Enable/disable SQL security validation (default: true)
BLOCKED_KEYWORDS: Comma-separated list of blocked SQL keywords
ENABLE_MASKING: Enable data masking (default: true)
MAX_RESULT_ROWS: Maximum result rows (default: 10000)
ADBC Configuration (New in v0.5.0):
ADBC_DEFAULT_MAX_ROWS: Default maximum rows for ADBC queries (default: 100000)
ADBC_DEFAULT_TIMEOUT: Default ADBC query timeout in seconds (default: 60)
ADBC_DEFAULT_RETURN_FORMAT: Default return format - arrow/pandas/dict (default: arrow)
ADBC_CONNECTION_TIMEOUT: ADBC connection timeout in seconds (default: 30)
ADBC_ENABLED: Enable/disable ADBC tools (default: true)
Performance Configuration:
ENABLE_QUERY_CACHE: Enable query caching (default: true)
CACHE_TTL: Cache time-to-live in seconds (default: 300)
MAX_CONCURRENT_QUERIES: Maximum concurrent queries (default: 50)
MAX_RESPONSE_CONTENT_SIZE: Maximum response content size for LLM compatibility (default: 4096, New in v0.4.0)
Enhanced Logging Configuration (Improved in v0.5.0):
LOG_LEVEL: Log level (DEBUG/INFO/WARNING/ERROR, default: INFO)
LOG_FILE_PATH: Log file path (automatically organized by level)
ENABLE_AUDIT: Enable audit logging (default: true)
ENABLE_LOG_CLEANUP: Enable automatic log cleanup (default: true, Enhanced in v0.5.0)
LOG_MAX_AGE_DAYS: Maximum age of log files in days (default: 30, Enhanced in v0.5.0)
LOG_CLEANUP_INTERVAL_HOURS: Log cleanup check interval in hours (default: 24, Enhanced in v0.5.0)
New Features in v0.5.0:
Level-based File Separation: Automatic separation into debug.log, info.log, warning.log, error.log, critical.log
Timestamped Format: Enhanced formatting with millisecond precision and proper alignment
Background Cleanup Scheduler: Automatic cleanup with configurable retention policies
Audit Trail: Dedicated audit.log with separate retention management
Performance Optimized: Minimal overhead async logging with rotation support
If you want to run only Doris MCP Server in docker:
cd doris-mcp-server
docker build -t doris-mcp-server .
docker run -d -p <port>:<port> -v /your-host/doris-mcp-server/.env:/app/.env --name <your-mcp-server-name> -it doris-mcp-server:latest
Service Endpoints:
Streamable HTTP: http://<host>:<port>/mcp (Primary MCP endpoint - supports GET, POST, DELETE, OPTIONS)
Health Check: http://<host>:<port>/health
> Note: The server uses Streamable HTTP for web-based communication, providing unified request/response and streaming capabilities.
The Doris MCP Server includes a comprehensive enterprise-grade security framework with advanced authentication, authorization, SQL security validation, and data masking capabilities enhanced in v0.6.0.
Configure the new authentication system with granular control:
ENABLE_TOKEN_AUTH=true # Enable token-based authentication
ENABLE_JWT_AUTH=false # Enable JWT authentication
ENABLE_OAUTH_AUTH=false # Enable OAuth authentication
DEFAULT_ADMIN_TOKEN=doris_admin_token_123456
DEFAULT_ANALYST_TOKEN=doris_analyst_token_123456
DEFAULT_READONLY_TOKEN=doris_readonly_token_123456
Doris-backed OAuth is a separate OAuth mode where Doris itself is the authorization backend. The MCP client discovers this server's OAuth metadata, the user signs in with a Doris username and password, the server validates those credentials by creating a per-user Doris connection pool, and issued doa_ access tokens route tool calls through that Doris user's pool. MCP scopes control which MCP operations can be called; Doris RBAC controls which catalogs, databases, tables, and metadata the user can see.
This mode is not the same as external OAuth/OIDC. ENABLE_DORIS_OAUTH_AUTH=true conflicts with ENABLE_OAUTH_AUTH=true, OAUTH_ENABLED=true, and legacy AUTH_TYPE=oauth; startup fails fast if both modes are configured. A standard MCP agent enters one MCP URL and should discover exactly one OAuth behavior for that URL, so the existing /auth/* external OAuth login flow is not used in Doris-backed OAuth mode.
The following example is for local development on a single worker:
bashTRANSPORT=http
WORKERS=1
DORIS_HOST=localhost
DORIS_PORT=9030
DORIS_USER=root
DORIS_PASSWORD=<service-account-password>
DORIS_DATABASE=information_schema
ENABLE_DORIS_OAUTH_AUTH=true
DORIS_OAUTH_BASE_URL=http://localhost:3000
ENABLE_OAUTH_AUTH=false
DORIS_OAUTH_DB_TOOLS_ENABLED=true
DORIS_OAUTH_DB_TOOL_ALLOWLIST=get_db_list,get_db_table_list,get_table_schema,get_table_comment,get_table_column_comments,get_table_indexes,get_catalog_list
DORIS_OAUTH_QUERY_TOOLS_ENABLED=true
DORIS_OAUTH_EXPLAIN_TOOLS_ENABLED=true
get_db_list
* `get_db_table_list`
get_table_schema
* `get_table_comment`
get_table_column_comments
* `get_table_indexes`
get_catalog_list
For normal MCP OAuth flows, clients do not need to pass a long `--scopes` list. If the OAuth request omits
exec_query
Execute SQL query and return results.
get_db_table_list
Get list of all table names in specified database.
get_table_comment
Get table comment information.
get_table_indexes
Get index information for specified table.
get_recent_audit_logs
Get audit log records for recent period.
get_sql_explain
Get SQL execution plan with configurable content truncation and file export for LLM analysis.
get_sql_profile
Get SQL execution profile with content management and file export for LLM optimization workflows.
get_table_data_size
Get table data size information via FE HTTP API.
get_monitoring_metrics_info
Get Doris monitoring metrics definitions and descriptions.
get_monitoring_metrics_data
Get actual Doris monitoring metrics data from nodes with flexible BE discovery.
get_realtime_memory_stats
Get real-time memory statistics via BE Memory Tracker with auto/manual BE discovery.
get_historical_memory_stats
Get historical memory statistics via BE Bvar interface with flexible BE configuration.
analyze_data_quality
Comprehensive data quality analysis combining completeness and distribution analysis.
trace_column_lineage
End-to-end column lineage tracking through SQL analysis and dependency mapping.
monitor_data_freshness
Real-time data staleness monitoring with configurable freshness thresholds.
analyze_data_access_patterns
User behavior analysis and security anomaly detection with access pattern monitoring.
analyze_data_flow_dependencies
Data flow impact analysis and dependency mapping between tables and views.
analyze_slow_queries_topn
Performance bottleneck identification with top-N slow query analysis and patterns.
analyze_resource_growth_curves
Capacity planning with resource growth analysis and trend forecasting.
exec_adbc_query
High-performance SQL execution using ADBC (Arrow Flight SQL) protocol.
get_adbc_connection_info
ADBC connection diagnostics and status monitoring for Arrow Flight SQL.
The following table lists the main tools currently available for invocation via an MCP client:
| Tool Name | Description | Parameters |
|-----------------------------|--------------------------------------------------------------|--------------------------------------------------------------|
| exec_query | Execute SQL query and return results. | sql (string, Required), db_name (string, Optional), catalog_name (string, Optional), max_rows (integer, Optional), timeout (integer, Optional) |
| get_table_schema | Get detailed table structure information. | table_name (string, Required), db_name (string, Optional), catalog_name (string, Optional) |
| get_db_table_list | Get list of all table names in specified database. | db_name (string, Optional), catalog_name (string, Optional) |
| get_db_list | Get list of all database names. | catalog_name (string, Optional) |
| get_table_comment | Get table comment information. | table_name (string, Required), db_name (string, Optional), catalog_name (string, Optional) |
| get_table_column_comments | Get comment information for all columns in table. | table_name (string, Required), db_name (string, Optional), catalog_name (string, Optional) |
| get_table_indexes | Get index information for specified table. | table_name (string, Required), db_name (string, Optional), catalog_name (string, Optional) |
| get_recent_audit_logs | Get audit log records for recent period. | days (integer, Optional), limit (integer, Optional) |
| get_catalog_list | Get list of all catalog names. | random_string (string, Required) |
| get_sql_explain | Get SQL execution plan with configurable content truncation and file export for LLM analysis. | sql (string, Required), verbose (boolean, Optional), db_name (string, Optional), catalog_name (string, Optional) |
| get_sql_profile | Get SQL execution profile with content management and file export for LLM optimization workflows. | sql (string, Required), db_name (string, Optional), catalog_name (string, Optional), timeout (integer, Optional) |
| get_table_data_size | Get table data size information via FE HTTP API. | db_name (string, Optional), table_name (string, Optional), single_replica (boolean, Optional) |
| get_monitoring_metrics_info | Get Doris monitoring metrics definitions and descriptions. | role (string, Optional), monitor_type (string, Optional), priority (string, Optional) |
| get_monitoring_metrics_data | Get actual Doris monitoring metrics data from nodes with flexible BE discovery. | role (string, Optional), monitor_type (string, Optional), priority (string, Optional) |
| get_realtime_memory_stats | Get real-time memory statistics via BE Memory Tracker with auto/manual BE discovery. | tracker_type (string, Optional), include_details (boolean, Optional) |
| get_historical_memory_stats | Get historical memory statistics via BE Bvar interface with flexible BE configuration. | tracker_names (array, Optional), time_range (string, Optional) |
| analyze_data_quality | Comprehensive data quality analysis combining completeness and distribution analysis. | table_name (string, Required), analysis_scope (string, Optional), sample_size (integer, Optional), business_rules (array, Optional) |
| trace_column_lineage | End-to-end column lineage tracking through SQL analysis and dependency mapping. | target_columns (array, Required), analysis_depth (integer, Optional), include_transformations (boolean, Optional) |
| monitor_data_freshness | Real-time data staleness monitoring with configurable freshness thresholds. | table_names (array, Optional), freshness_threshold_hours (integer, Optional), include_update_patterns (boolean, Optional) |
| analyze_data_access_patterns | User behavior analysis and security anomaly detection with access pattern monitoring. | days (integer, Optional), include_system_users (boolean, Optional), min_query_threshold (integer, Optional) |
| analyze_data_flow_dependencies | Data flow impact analysis and dependency mapping between tables and views. | target_table (string, Optional), analysis_depth (integer, Optional), include_views (boolean, Optional) |
| analyze_slow_queries_topn | Performance bottleneck identification with top-N slow query analysis and patterns. | days (integer, Optional), top_n (integer, Optional), min_execution_time_ms (integer, Optional), include_patterns (boolean, Optional) |
| analyze_resource_growth_curves | Capacity planning with resource growth analysis and trend forecasting. | days (integer, Optional), resource_types (array, Optional), include_predictions (boolean, Optional) |
| exec_adbc_query | High-performance SQL execution using ADBC (Arrow Flight SQL) protocol. | sql (string, Required), max_rows (integer, Optional), timeout (integer, Optional), return_format (string, Optional) |
| get_adbc_connection_info | ADBC connection diagnostics and status monitoring for Arrow Flight SQL. | No parameters required |
Note: All metadata tools support catalog federation for multi-catalog environments. Enhanced monitoring tools provide comprehensive memory tracking and metrics collection capabilities. New in v0.5.0: 7 advanced analytics tools for enterprise data governance and 2 ADBC tools for high-performance data transfer with 3-10x performance improvements for large datasets.
Doris-backed OAuth note: The table above describes global server capabilities. Doris-backed OAuth uses configuration gates for its operation surface. MCP resources are available with resource metadata caching disabled. Reviewed metadata tools are callable when DORIS_OAUTH_DB_TOOLS_ENABLED=true; exec_query and get_sql_explain are callable when their Doris OAuth query/explain gates are enabled. These MySQL-channel operations run through the logged-in Doris user pool, so Doris RBAC is the final data authorization backend. Prompts, ADBC, FE HTTP profile/monitoring, audit/governance, and performance analytics remain closed until they have per-user routing or an explicit service-account/admin design.
DORIS_OAUTH_DB_TOOLS_ENABLED=true opens the reviewed metadata bucket. The reviewed tools are:
get_db_list
get_db_table_list
get_table_schema
get_table_comment
get_table_column_comments
get_table_indexes
-
get_catalog_list
For normal MCP OAuth flows, clients do not need to pass a long
--scopes list. If the OAuth request omitsClaude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"apache doris": {
"doris-mcp": {
"command": "uv",
"args": [
"--project",
"/path/to/your/doris-mcp-server",
"run",
"doris-mcp-server"
],
"env": {
"DB_HOST": "FE_HOST",
"DB_PORT": "9030",
"DB_USER": "root",
"DB_PASSWORD": ""
}
},
"doris-http": {
"url": "http://127.0.0.1:3000/mcp"
}
}
}
}
McpServers
{
"doris-mcp": {
"command": "uv",
"args": [
"--project",
"/path/to/your/doris-mcp-server",
"run",
"doris-mcp-server"
],
"env": {
"DB_HOST": "FE_HOST",
"DB_PORT": "9030",
"DB_USER": "root",
"DB_PASSWORD": ""
}
},
"doris-http": {
"url": "http://127.0.0.1:3000/mcp"
}
}
Doris MCP Server
Doris MCP (Model Context Protocol) Server is a backend service built with Python and FastAPI. It implements the MCP, allowing clients to interact with it through defined "Tools". It's primarily designed to connect to Apache Doris databases, potentially leveraging Large Language Models (LLMs) for tasks like converting natural language queries to SQL (NL2SQL), executing queries, and performing metadata management and analysis.
π What's New in v0.6.0
- π Enterprise Authentication System: Revolutionary token-bound database configuration with comprehensive Token, JWT, and OAuth authentication support, enabling secure multi-tenant access with granular control switches and enterprise-grade security defaults
- β‘ Immediate Database Validation: Real-time database configuration validation at connection time, eliminating query-time blocking and providing instant feedback for invalid configurations - achieving 100% elimination of late-stage connection failures
- π Hot Reload Configuration Management: Zero-downtime configuration updates with intelligent hot reloading of tokens.json, automatic token revalidation, and comprehensive error handling with rollback mechanisms
- ποΈ Advanced Connection Architecture: Session caching and connection pool optimization with 60% reduction in connection overhead, intelligent pool recreation, and automatic resource management
- π Multi-Worker Scalability: True horizontal scaling with stateless multi-worker architecture, efficient load distribution, and enterprise-grade concurrent processing capabilities
- π Enhanced Security Framework: Comprehensive access control and SQL security validation with immediate validation, role-based permissions, and enhanced injection detection patterns
- π οΈ Unified Configuration System: Streamlined configuration management with proper command-line precedence, Docker compatibility improvements, and cross-platform deployment support
- π Token Management Dashboard: Complete token lifecycle management with creation, revocation, statistics, and comprehensive audit trails for enterprise token governance
- π Web-Based Management Interface: Secure localhost-only token administration with intuitive dashboard, database binding configuration, real-time operations, and enterprise-grade access controls
> π Major Milestone: v0.6.0 establishes the platform as a production-ready enterprise authentication and database management system with zero-downtime operations (hot reload + immediate validation + multi-worker scaling), advanced security controls, and comprehensive token-bound database configuration - representing a fundamental advancement in enterprise data platform capabilities.
What's Also Included from v0.5.1
- π₯ Critical at_eof Connection Fix: Complete elimination of connection pool errors with intelligent health monitoring and self-healing recovery
- π§ Enterprise Logging System: Level-based file separation with automatic cleanup and millisecond precision timestamps
- π Advanced Data Analytics Suite: 7 enterprise-grade data governance tools including quality analysis, lineage tracking, and performance monitoring
- πββοΈ High-Performance ADBC Integration: Apache Arrow Flight SQL support with 3-10x performance improvements for large datasets
- βοΈ Enhanced Configuration Management: Complete ADBC configuration system with intelligent parameter validation
Core Features
MCP Protocol Implementation: Provides standard MCP interfaces, supporting tool calls, resource management, and prompt interactions.
Streamable HTTP Communication: Unified HTTP endpoint supporting both request/response and streaming communication for optimal performance and reliability.
Stdio Communication: Standard input/output mode for direct integration with MCP clients like Cursor.
Enterprise-Grade Architecture: Modular design with comprehensive functionality:
Tools Manager: Centralized tool registration and routing with unified interfaces (doris_mcp_server/tools/tools_manager.py)
Enhanced Monitoring Tools Module: Advanced memory tracking, metrics collection, and flexible BE node discovery with modular, extensible design
Query Information Tools: Enhanced SQL explain and profiling with configurable content truncation, file export for LLM attachments, and advanced query analytics
Resources Manager: Resource management and metadata exposure (doris_mcp_server/tools/resources_manager.py)
Prompts Manager: Intelligent prompt templates for data analysis (doris_mcp_server/tools/prompts_manager.py)
Advanced Database Features:
Query Execution: High-performance SQL execution with advanced caching and optimization, enhanced connection stability and automatic retry mechanisms (doris_mcp_server/utils/query_executor.py)
Security Management: Comprehensive SQL security validation with configurable blocked keywords, SQL injection protection, data masking, and unified security configuration management (doris_mcp_server/utils/security.py)
Metadata Extraction: Comprehensive database metadata with catalog federation support (doris_mcp_server/utils/schema_extractor.py)
Performance Analysis: Advanced column analysis, performance monitoring, and data analysis tools (doris_mcp_server/utils/analysis_tools.py)
Catalog Federation Support: Full support for multi-catalog environments (internal Doris tables and external data sources like Hive, MySQL, etc.)
Enterprise Security: Comprehensive security framework with authentication, authorization, SQL injection protection, and data masking capabilities with environment variable configuration support
Web-Based Token Management: Secure localhost-only interface for complete token lifecycle management with database binding, real-time statistics, and enterprise-grade access controls (doris_mcp_server/auth/token_handlers.py)
Unified Configuration Framework: Centralized configuration management through config.py with comprehensive validation, standardized parameter naming, and smart default database handling with automatic fallback to information_schema
System Requirements
Python: 3.12+
Database: Apache Doris connection details (Host, Port, User, Password, Database)
π Quick Start
Installation from PyPI
```bash
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



