doris-mcp-server

MCP.Pizza Chef: apache

Apache's own read-only bridge to a Doris data warehouse, version 1.0 groups fifty-five abilities into eight areas: browsing catalogs and tables, running and explaining queries, checking cluster health, tracing where data came from, and text or similarity search. It cannot change or delete anything, and your existing Doris permissions still decide what is visible. This is aimed at teams that already run Doris. You install it with pip and point it at your own cluster.

Data

Use This MCP server To

Ask a question about our warehouse data in plain English See which tables exist without opening a query tool Find out why a query is running slowly Check whether a table's data is up to date Trace where a number in a report came from

README

Apache Doris MCP Server

English | 简体中文

Apache Doris MCP Server exposes read-only Apache Doris capabilities to MCP Hosts and AI agents over MCP 2026-07-28. Version 1.0 replaces a large flat tool surface with eight stable domains and fifty-five progressively disclosed child capabilities, while keeping runtime availability, authorization, input schemas, output schemas, and failure behavior explicit.

Release status

The package version is 1.0.0. MCP 2026-07-28 protocol compatibility on master is Generally Available (GA) on Streamable HTTP and stdio. This GA statement is scoped to protocol compatibility; the Python package classifier remains Beta, and the documented deployment limits still apply.

Before upgrading, read the 1.0 release notes, the 1.0 migration guide, and the generated 8-domain/55-child registry. The detailed release record is Issue #189.

Architecture at a glance

MCP Host
  -> stdio or Streamable HTTP
  -> transport security and authentication
  -> MCP protocol validation and authorization
  -> stable domain discovery
  -> route-aware Doris capability detection
  -> exact child dispatch and read-only runtime
  -> request-specific Doris route and RBAC
  -> bounded, schema-validated result

The default hierarchical mode exposes these domains:

Domain Children Responsibility
doris_catalog 5 catalogs, databases, tables, table context, size
doris_query 7 query, explain, profile, diagnosis, slow queries, explicit ADBC
doris_cluster 11 nodes, tasks, metrics, memory, cache, compaction, workloads
doris_pipeline 5 ingestion, materialized views, freshness, dependencies
doris_search 4 text/vector/hybrid search, analyzers, indexes, diagnosis
doris_governance 8 quality, storage, lineage, audit, UDFs, auth mapping
doris_lakehouse 3 external catalogs, lakehouse tables, Variant
doris_semantic 12 optional Apache Ossie grounding and MetricFlow consumption

Call a domain with {} to discover its authorized children and exact schemas. Call the same domain again with child_tool, arguments, and the returned manifest_version. Hosts that cannot use progressive disclosure may set MCP_TOOL_EXPOSURE_MODE=flat before startup; this exposes the same 55 children under collision-free formal names and does not restore pre-1.0 aliases.

See Architecture, Request lifecycle, and Tool domains.

doris-mcp-server FAQ

Is this still maintained?
Yes. It is an Apache project, updated in early August 2026, and now at a 1.0 release.
Can it change or delete our data?
No. Version 1.0 is read-only by design, and your existing Doris permissions still apply on top of that.
Can I use this to answer a question about our sales table?
Yes, if that table lives in Doris and your account is allowed to see it.
Do I need a key?
Not a key as such. You supply a Doris username and password, and a login is required for anything beyond your own machine.
How hard is setup?
It expects someone comfortable with Python and your cluster's connection details, so plan on a technical person doing it.