Data Prism MCP Setup & Guide
io.github.AindriuB/data-prism · v0.3.1
Fail-closed privacy layer that pseudonymises enterprise API data for LLM agents and MCP clients.
Copy the install config on this page first, then verify docs and permissions upstream.
Overview
Fail-closed privacy layer that pseudonymises enterprise API data for LLM agents and MCP clients. Data Prism is a MCP Server listed from MCP Registry. Transports: streamable-http. This page includes an overview, setup tutorial, install commands, and use cases for Trae, Tongyi Lingma, Cursor, Claude Code, and VS Code.
Use cases
AgentHub Verified AvailabilityTested & Ready
Automated pipeline validated install commands, protocol & client compatibility
Copy by platform
Choose your platform
- Open or create .cursor/mcp.json in your project root
- Click Copy config and paste; merge only this mcpServers entry if others exist
- Replace <placeholders> in env with real secrets (see Environment variables below)
- Save, then Cmd+Shift+P → Reload Window
Pre-fill Environment Variables (Optional)
{
"mcpServers": {
"data-prism": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/aindriub/data-prism-server:0.3.1"
],
"env": {
"LOADER_PATH": "<LOADER_PATH>",
"DATAPRISM_SECURITY_JWT_ISSUER": "<DATAPRISM_SECURITY_JWT_ISSUER>",
"DATAPRISM_SECURITY_JWT_AUDIENCE": "<DATAPRISM_SECURITY_JWT_AUDIENCE>",
"DATAPRISM_SECURITY_JWT_JWK_SET_URI": "<DATAPRISM_SECURITY_JWT_JWK_SET_URI>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL": "<DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES": "<DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION": "<DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION>",
"DATAPRISM_SECURITY_POLICY_PURPOSES": "<DATAPRISM_SECURITY_POLICY_PURPOSES>",
"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR": "<DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR>",
"DATAPRISM_PRIVACY_PROFILE": "<DATAPRISM_PRIVACY_PROFILE>",
"DATAPRISM_PRIVACY_SCOPE_LIFETIME": "<DATAPRISM_PRIVACY_SCOPE_LIFETIME>",
"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID": "<DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID>",
"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE": "<DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE>",
"DATAPRISM_AUDIT_SINK": "<DATAPRISM_AUDIT_SINK>",
"DATAPRISM_AUDIT_WRITER_ID": "<DATAPRISM_AUDIT_WRITER_ID>",
"DATAPRISM_METRICS_SINK": "<DATAPRISM_METRICS_SINK>",
"DATAPRISM_HAZELCAST_TOPOLOGY": "<DATAPRISM_HAZELCAST_TOPOLOGY>",
"DATAPRISM_SOURCES_CUSTOMER_BASE_URL": "<DATAPRISM_SOURCES_CUSTOMER_BASE_URL>",
"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT": "<DATAPRISM_SOURCES_CUSTOMER_TIMEOUT>"
}
}
}
}Setup tutorial
- Open the Data Prism page and confirm this MCP Server (source: MCP Registry).
- Copy the Cursor, Claude Code, or VS Code snippet.
- Merge it into mcpServers and replace env placeholders with real secrets.
- Reload the window, then call the MCP tools from your agent chat.
Install commands
Install commands and setup steps are in the HTML so search engines and no-JS browsers can read them without running client JavaScript.
Claude Code (local)
- Install Claude Code CLI
- Copy the command below, replace <placeholders> with real env values, then run in terminal
- See Environment variables below if listed
claude mcp add data-prism --env LOADER_PATH=<LOADER_PATH> --env DATAPRISM_SECURITY_JWT_ISSUER=<DATAPRISM_SECURITY_JWT_ISSUER> --env DATAPRISM_SECURITY_JWT_AUDIENCE=<DATAPRISM_SECURITY_JWT_AUDIENCE> --env DATAPRISM_SECURITY_JWT_JWK_SET_URI=<DATAPRISM_SECURITY_JWT_JWK_SET_URI> --env DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL=<DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL> --env DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES=<DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES> --env DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION=<DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION> --env DATAPRISM_SECURITY_POLICY_PURPOSES=<DATAPRISM_SECURITY_POLICY_PURPOSES> --env DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR=<DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR> --env DATAPRISM_PRIVACY_PROFILE=<DATAPRISM_PRIVACY_PROFILE> --env DATAPRISM_PRIVACY_SCOPE_LIFETIME=<DATAPRISM_PRIVACY_SCOPE_LIFETIME> --env DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID=<DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID> --env DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE=<DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE> --env DATAPRISM_AUDIT_SINK=<DATAPRISM_AUDIT_SINK> --env DATAPRISM_AUDIT_WRITER_ID=<DATAPRISM_AUDIT_WRITER_ID> --env DATAPRISM_METRICS_SINK=<DATAPRISM_METRICS_SINK> --env DATAPRISM_HAZELCAST_TOPOLOGY=<DATAPRISM_HAZELCAST_TOPOLOGY> --env DATAPRISM_SOURCES_CUSTOMER_BASE_URL=<DATAPRISM_SOURCES_CUSTOMER_BASE_URL> --env DATAPRISM_SOURCES_CUSTOMER_TIMEOUT=<DATAPRISM_SOURCES_CUSTOMER_TIMEOUT> -- docker run -i --rm ghcr.io/aindriub/data-prism-server:0.3.1Cursor — .cursor/mcp.json (local)
- Open or create .cursor/mcp.json in your project root
- Click Copy config and paste; merge only this mcpServers entry if others exist
- Replace <placeholders> in env with real secrets (see Environment variables below)
- Save, then Cmd+Shift+P → Reload Window
{
"mcpServers": {
"data-prism": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/aindriub/data-prism-server:0.3.1"
],
"env": {
"LOADER_PATH": "<LOADER_PATH>",
"DATAPRISM_SECURITY_JWT_ISSUER": "<DATAPRISM_SECURITY_JWT_ISSUER>",
"DATAPRISM_SECURITY_JWT_AUDIENCE": "<DATAPRISM_SECURITY_JWT_AUDIENCE>",
"DATAPRISM_SECURITY_JWT_JWK_SET_URI": "<DATAPRISM_SECURITY_JWT_JWK_SET_URI>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL": "<DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES": "<DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION": "<DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION>",
"DATAPRISM_SECURITY_POLICY_PURPOSES": "<DATAPRISM_SECURITY_POLICY_PURPOSES>",
"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR": "<DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR>",
"DATAPRISM_PRIVACY_PROFILE": "<DATAPRISM_PRIVACY_PROFILE>",
"DATAPRISM_PRIVACY_SCOPE_LIFETIME": "<DATAPRISM_PRIVACY_SCOPE_LIFETIME>",
"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID": "<DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID>",
"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE": "<DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE>",
"DATAPRISM_AUDIT_SINK": "<DATAPRISM_AUDIT_SINK>",
"DATAPRISM_AUDIT_WRITER_ID": "<DATAPRISM_AUDIT_WRITER_ID>",
"DATAPRISM_METRICS_SINK": "<DATAPRISM_METRICS_SINK>",
"DATAPRISM_HAZELCAST_TOPOLOGY": "<DATAPRISM_HAZELCAST_TOPOLOGY>",
"DATAPRISM_SOURCES_CUSTOMER_BASE_URL": "<DATAPRISM_SOURCES_CUSTOMER_BASE_URL>",
"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT": "<DATAPRISM_SOURCES_CUSTOMER_TIMEOUT>"
}
}
}
}VS Code — .vscode/mcp.json (local)
- Install GitHub Copilot in VS Code with MCP support
- Open or create .vscode/mcp.json in your project root
- Click Copy config and paste; merge only this mcpServers entry if others exist
- Replace <placeholders> in env with real secrets
- Save and Developer: Reload Window
{
"mcpServers": {
"data-prism": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/aindriub/data-prism-server:0.3.1"
],
"env": {
"LOADER_PATH": "<LOADER_PATH>",
"DATAPRISM_SECURITY_JWT_ISSUER": "<DATAPRISM_SECURITY_JWT_ISSUER>",
"DATAPRISM_SECURITY_JWT_AUDIENCE": "<DATAPRISM_SECURITY_JWT_AUDIENCE>",
"DATAPRISM_SECURITY_JWT_JWK_SET_URI": "<DATAPRISM_SECURITY_JWT_JWK_SET_URI>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL": "<DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES": "<DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION": "<DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION>",
"DATAPRISM_SECURITY_POLICY_PURPOSES": "<DATAPRISM_SECURITY_POLICY_PURPOSES>",
"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR": "<DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR>",
"DATAPRISM_PRIVACY_PROFILE": "<DATAPRISM_PRIVACY_PROFILE>",
"DATAPRISM_PRIVACY_SCOPE_LIFETIME": "<DATAPRISM_PRIVACY_SCOPE_LIFETIME>",
"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID": "<DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID>",
"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE": "<DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE>",
"DATAPRISM_AUDIT_SINK": "<DATAPRISM_AUDIT_SINK>",
"DATAPRISM_AUDIT_WRITER_ID": "<DATAPRISM_AUDIT_WRITER_ID>",
"DATAPRISM_METRICS_SINK": "<DATAPRISM_METRICS_SINK>",
"DATAPRISM_HAZELCAST_TOPOLOGY": "<DATAPRISM_HAZELCAST_TOPOLOGY>",
"DATAPRISM_SOURCES_CUSTOMER_BASE_URL": "<DATAPRISM_SOURCES_CUSTOMER_BASE_URL>",
"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT": "<DATAPRISM_SOURCES_CUSTOMER_TIMEOUT>"
}
}
}
}Claude Desktop — claude_desktop_config.json (local)
- Open Claude Desktop claude_desktop_config.json (see remote guide for paths)
- Click Copy config and merge under mcpServers
- Replace <placeholders> in env with real secrets
- Fully quit and restart Claude Desktop
{
"mcpServers": {
"data-prism": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/aindriub/data-prism-server:0.3.1"
],
"env": {
"LOADER_PATH": "<LOADER_PATH>",
"DATAPRISM_SECURITY_JWT_ISSUER": "<DATAPRISM_SECURITY_JWT_ISSUER>",
"DATAPRISM_SECURITY_JWT_AUDIENCE": "<DATAPRISM_SECURITY_JWT_AUDIENCE>",
"DATAPRISM_SECURITY_JWT_JWK_SET_URI": "<DATAPRISM_SECURITY_JWT_JWK_SET_URI>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL": "<DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES": "<DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION": "<DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION>",
"DATAPRISM_SECURITY_POLICY_PURPOSES": "<DATAPRISM_SECURITY_POLICY_PURPOSES>",
"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR": "<DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR>",
"DATAPRISM_PRIVACY_PROFILE": "<DATAPRISM_PRIVACY_PROFILE>",
"DATAPRISM_PRIVACY_SCOPE_LIFETIME": "<DATAPRISM_PRIVACY_SCOPE_LIFETIME>",
"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID": "<DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID>",
"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE": "<DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE>",
"DATAPRISM_AUDIT_SINK": "<DATAPRISM_AUDIT_SINK>",
"DATAPRISM_AUDIT_WRITER_ID": "<DATAPRISM_AUDIT_WRITER_ID>",
"DATAPRISM_METRICS_SINK": "<DATAPRISM_METRICS_SINK>",
"DATAPRISM_HAZELCAST_TOPOLOGY": "<DATAPRISM_HAZELCAST_TOPOLOGY>",
"DATAPRISM_SOURCES_CUSTOMER_BASE_URL": "<DATAPRISM_SOURCES_CUSTOMER_BASE_URL>",
"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT": "<DATAPRISM_SOURCES_CUSTOMER_TIMEOUT>"
}
}
}
}Trae — .trae/mcp.json (local)
- Trae → Settings → MCP, or edit .trae/mcp.json / global mcp.json
- Click Copy config and merge mcpServers
- Replace <placeholders> in env with real secrets
- Save and reload Trae
{
"mcpServers": {
"data-prism": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/aindriub/data-prism-server:0.3.1"
],
"env": {
"LOADER_PATH": "<LOADER_PATH>",
"DATAPRISM_SECURITY_JWT_ISSUER": "<DATAPRISM_SECURITY_JWT_ISSUER>",
"DATAPRISM_SECURITY_JWT_AUDIENCE": "<DATAPRISM_SECURITY_JWT_AUDIENCE>",
"DATAPRISM_SECURITY_JWT_JWK_SET_URI": "<DATAPRISM_SECURITY_JWT_JWK_SET_URI>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL": "<DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES": "<DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION": "<DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION>",
"DATAPRISM_SECURITY_POLICY_PURPOSES": "<DATAPRISM_SECURITY_POLICY_PURPOSES>",
"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR": "<DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR>",
"DATAPRISM_PRIVACY_PROFILE": "<DATAPRISM_PRIVACY_PROFILE>",
"DATAPRISM_PRIVACY_SCOPE_LIFETIME": "<DATAPRISM_PRIVACY_SCOPE_LIFETIME>",
"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID": "<DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID>",
"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE": "<DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE>",
"DATAPRISM_AUDIT_SINK": "<DATAPRISM_AUDIT_SINK>",
"DATAPRISM_AUDIT_WRITER_ID": "<DATAPRISM_AUDIT_WRITER_ID>",
"DATAPRISM_METRICS_SINK": "<DATAPRISM_METRICS_SINK>",
"DATAPRISM_HAZELCAST_TOPOLOGY": "<DATAPRISM_HAZELCAST_TOPOLOGY>",
"DATAPRISM_SOURCES_CUSTOMER_BASE_URL": "<DATAPRISM_SOURCES_CUSTOMER_BASE_URL>",
"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT": "<DATAPRISM_SOURCES_CUSTOMER_TIMEOUT>"
}
}
}
}Cherry Studio — MCP settings (local)
- Cherry Studio → Settings → MCP Servers → Add (STDIO)
- Or import JSON: click Copy config and merge mcpServers
- Replace <placeholders> in env; ensure Node.js / uv (npx, uvx) are installed
- Enable the server and check tools load
{
"mcpServers": {
"data-prism": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/aindriub/data-prism-server:0.3.1"
],
"env": {
"LOADER_PATH": "<LOADER_PATH>",
"DATAPRISM_SECURITY_JWT_ISSUER": "<DATAPRISM_SECURITY_JWT_ISSUER>",
"DATAPRISM_SECURITY_JWT_AUDIENCE": "<DATAPRISM_SECURITY_JWT_AUDIENCE>",
"DATAPRISM_SECURITY_JWT_JWK_SET_URI": "<DATAPRISM_SECURITY_JWT_JWK_SET_URI>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL": "<DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES": "<DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION": "<DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION>",
"DATAPRISM_SECURITY_POLICY_PURPOSES": "<DATAPRISM_SECURITY_POLICY_PURPOSES>",
"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR": "<DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR>",
"DATAPRISM_PRIVACY_PROFILE": "<DATAPRISM_PRIVACY_PROFILE>",
"DATAPRISM_PRIVACY_SCOPE_LIFETIME": "<DATAPRISM_PRIVACY_SCOPE_LIFETIME>",
"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID": "<DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID>",
"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE": "<DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE>",
"DATAPRISM_AUDIT_SINK": "<DATAPRISM_AUDIT_SINK>",
"DATAPRISM_AUDIT_WRITER_ID": "<DATAPRISM_AUDIT_WRITER_ID>",
"DATAPRISM_METRICS_SINK": "<DATAPRISM_METRICS_SINK>",
"DATAPRISM_HAZELCAST_TOPOLOGY": "<DATAPRISM_HAZELCAST_TOPOLOGY>",
"DATAPRISM_SOURCES_CUSTOMER_BASE_URL": "<DATAPRISM_SOURCES_CUSTOMER_BASE_URL>",
"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT": "<DATAPRISM_SOURCES_CUSTOMER_TIMEOUT>"
}
}
}
}Tongyi Lingma — MCP config (local)
- Lingma Settings → MCP → + → STDIO or config file
- Click Copy config and merge mcpServers
- Replace <placeholders> in env; need Node.js 18+ (npx) or uv (uvx)
- Confirm connected before using tools in agent chat
{
"mcpServers": {
"data-prism": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/aindriub/data-prism-server:0.3.1"
],
"env": {
"LOADER_PATH": "<LOADER_PATH>",
"DATAPRISM_SECURITY_JWT_ISSUER": "<DATAPRISM_SECURITY_JWT_ISSUER>",
"DATAPRISM_SECURITY_JWT_AUDIENCE": "<DATAPRISM_SECURITY_JWT_AUDIENCE>",
"DATAPRISM_SECURITY_JWT_JWK_SET_URI": "<DATAPRISM_SECURITY_JWT_JWK_SET_URI>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL": "<DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES": "<DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION": "<DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION>",
"DATAPRISM_SECURITY_POLICY_PURPOSES": "<DATAPRISM_SECURITY_POLICY_PURPOSES>",
"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR": "<DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR>",
"DATAPRISM_PRIVACY_PROFILE": "<DATAPRISM_PRIVACY_PROFILE>",
"DATAPRISM_PRIVACY_SCOPE_LIFETIME": "<DATAPRISM_PRIVACY_SCOPE_LIFETIME>",
"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID": "<DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID>",
"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE": "<DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE>",
"DATAPRISM_AUDIT_SINK": "<DATAPRISM_AUDIT_SINK>",
"DATAPRISM_AUDIT_WRITER_ID": "<DATAPRISM_AUDIT_WRITER_ID>",
"DATAPRISM_METRICS_SINK": "<DATAPRISM_METRICS_SINK>",
"DATAPRISM_HAZELCAST_TOPOLOGY": "<DATAPRISM_HAZELCAST_TOPOLOGY>",
"DATAPRISM_SOURCES_CUSTOMER_BASE_URL": "<DATAPRISM_SOURCES_CUSTOMER_BASE_URL>",
"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT": "<DATAPRISM_SOURCES_CUSTOMER_TIMEOUT>"
}
}
}
}Windsurf — mcp_config.json (local)
- Edit ~/.codeium/windsurf/mcp_config.json
- Click Copy config and merge mcpServers (stdio same as Cursor)
- Replace <placeholders> in env, save, refresh Cascade
{
"mcpServers": {
"data-prism": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/aindriub/data-prism-server:0.3.1"
],
"env": {
"LOADER_PATH": "<LOADER_PATH>",
"DATAPRISM_SECURITY_JWT_ISSUER": "<DATAPRISM_SECURITY_JWT_ISSUER>",
"DATAPRISM_SECURITY_JWT_AUDIENCE": "<DATAPRISM_SECURITY_JWT_AUDIENCE>",
"DATAPRISM_SECURITY_JWT_JWK_SET_URI": "<DATAPRISM_SECURITY_JWT_JWK_SET_URI>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL": "<DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES": "<DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION": "<DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION>",
"DATAPRISM_SECURITY_POLICY_PURPOSES": "<DATAPRISM_SECURITY_POLICY_PURPOSES>",
"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR": "<DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR>",
"DATAPRISM_PRIVACY_PROFILE": "<DATAPRISM_PRIVACY_PROFILE>",
"DATAPRISM_PRIVACY_SCOPE_LIFETIME": "<DATAPRISM_PRIVACY_SCOPE_LIFETIME>",
"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID": "<DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID>",
"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE": "<DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE>",
"DATAPRISM_AUDIT_SINK": "<DATAPRISM_AUDIT_SINK>",
"DATAPRISM_AUDIT_WRITER_ID": "<DATAPRISM_AUDIT_WRITER_ID>",
"DATAPRISM_METRICS_SINK": "<DATAPRISM_METRICS_SINK>",
"DATAPRISM_HAZELCAST_TOPOLOGY": "<DATAPRISM_HAZELCAST_TOPOLOGY>",
"DATAPRISM_SOURCES_CUSTOMER_BASE_URL": "<DATAPRISM_SOURCES_CUSTOMER_BASE_URL>",
"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT": "<DATAPRISM_SOURCES_CUSTOMER_TIMEOUT>"
}
}
}
}Cline — MCP Servers (local)
- Cline panel → Settings → MCP Servers
- Click Copy config and merge
- Replace <placeholders> in env, then save
{
"mcpServers": {
"data-prism": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/aindriub/data-prism-server:0.3.1"
],
"env": {
"LOADER_PATH": "<LOADER_PATH>",
"DATAPRISM_SECURITY_JWT_ISSUER": "<DATAPRISM_SECURITY_JWT_ISSUER>",
"DATAPRISM_SECURITY_JWT_AUDIENCE": "<DATAPRISM_SECURITY_JWT_AUDIENCE>",
"DATAPRISM_SECURITY_JWT_JWK_SET_URI": "<DATAPRISM_SECURITY_JWT_JWK_SET_URI>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL": "<DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES": "<DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION": "<DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION>",
"DATAPRISM_SECURITY_POLICY_PURPOSES": "<DATAPRISM_SECURITY_POLICY_PURPOSES>",
"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR": "<DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR>",
"DATAPRISM_PRIVACY_PROFILE": "<DATAPRISM_PRIVACY_PROFILE>",
"DATAPRISM_PRIVACY_SCOPE_LIFETIME": "<DATAPRISM_PRIVACY_SCOPE_LIFETIME>",
"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID": "<DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID>",
"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE": "<DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE>",
"DATAPRISM_AUDIT_SINK": "<DATAPRISM_AUDIT_SINK>",
"DATAPRISM_AUDIT_WRITER_ID": "<DATAPRISM_AUDIT_WRITER_ID>",
"DATAPRISM_METRICS_SINK": "<DATAPRISM_METRICS_SINK>",
"DATAPRISM_HAZELCAST_TOPOLOGY": "<DATAPRISM_HAZELCAST_TOPOLOGY>",
"DATAPRISM_SOURCES_CUSTOMER_BASE_URL": "<DATAPRISM_SOURCES_CUSTOMER_BASE_URL>",
"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT": "<DATAPRISM_SOURCES_CUSTOMER_TIMEOUT>"
}
}
}
}WorkBuddy — .workbuddy/mcp.json (local)
- Edit ~/.workbuddy/mcp.json (user) or project .workbuddy/mcp.json
- Or Plugins → MCP Servers → Configure MCP and paste the JSON below
- Replace <placeholders> in env; on Windows prefer absolute paths for command/scripts
- Save, restart WorkBuddy, confirm connector status is green
{
"mcpServers": {
"data-prism": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/aindriub/data-prism-server:0.3.1"
],
"env": {
"LOADER_PATH": "<LOADER_PATH>",
"DATAPRISM_SECURITY_JWT_ISSUER": "<DATAPRISM_SECURITY_JWT_ISSUER>",
"DATAPRISM_SECURITY_JWT_AUDIENCE": "<DATAPRISM_SECURITY_JWT_AUDIENCE>",
"DATAPRISM_SECURITY_JWT_JWK_SET_URI": "<DATAPRISM_SECURITY_JWT_JWK_SET_URI>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL": "<DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES": "<DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES>",
"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION": "<DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION>",
"DATAPRISM_SECURITY_POLICY_PURPOSES": "<DATAPRISM_SECURITY_POLICY_PURPOSES>",
"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR": "<DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR>",
"DATAPRISM_PRIVACY_PROFILE": "<DATAPRISM_PRIVACY_PROFILE>",
"DATAPRISM_PRIVACY_SCOPE_LIFETIME": "<DATAPRISM_PRIVACY_SCOPE_LIFETIME>",
"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID": "<DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID>",
"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE": "<DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE>",
"DATAPRISM_AUDIT_SINK": "<DATAPRISM_AUDIT_SINK>",
"DATAPRISM_AUDIT_WRITER_ID": "<DATAPRISM_AUDIT_WRITER_ID>",
"DATAPRISM_METRICS_SINK": "<DATAPRISM_METRICS_SINK>",
"DATAPRISM_HAZELCAST_TOPOLOGY": "<DATAPRISM_HAZELCAST_TOPOLOGY>",
"DATAPRISM_SOURCES_CUSTOMER_BASE_URL": "<DATAPRISM_SOURCES_CUSTOMER_BASE_URL>",
"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT": "<DATAPRISM_SOURCES_CUSTOMER_TIMEOUT>"
}
}
}
}Troubleshooting & Common ErrorsFAQ
Common connection errors and verified fixes for Data Prism
Getting 'connection closed' or exit code 1 in Cursor / Claude Code for Data Prism?
Usually caused by missing runtime paths or IDE environment inheritance. Fix steps: 1. Verify Node.js 18+ (npx) or Python 3.10+ (uvx) is installed; 2. Run 'which npx' or 'which uvx' in terminal, and replace 'command' with absolute path; 3. Reload or restart the client window after modifying config.
# Check binary path in terminal: which npx node -v
Getting 'spawn npx ENOENT' or 'command not found'?
The editor background process does not inherit your full terminal PATH. Solution: Globally install the package, or set the absolute binary path (e.g. C:\Program Files\nodejs\npx.cmd on Windows, or /usr/local/bin/npx on macOS).
Missing required environment variable or authentication failure?
Data Prism requires environment variables (LOADER_PATH、DATAPRISM_SECURITY_JWT_ISSUER、DATAPRISM_SECURITY_JWT_AUDIENCE、DATAPRISM_SECURITY_JWT_JWK_SET_URI、DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL、DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES、DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION、DATAPRISM_SECURITY_POLICY_PURPOSES、DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR、DATAPRISM_PRIVACY_PROFILE、DATAPRISM_PRIVACY_SCOPE_LIFETIME、DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID、DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE、DATAPRISM_AUDIT_SINK、DATAPRISM_AUDIT_WRITER_ID、DATAPRISM_METRICS_SINK、DATAPRISM_HAZELCAST_TOPOLOGY、DATAPRISM_SOURCES_CUSTOMER_BASE_URL、DATAPRISM_SOURCES_CUSTOMER_TIMEOUT). Ensure you have added valid keys under the 'env' object in your config file without trailing whitespace.
// .cursor/mcp.json 或 claude_desktop_config.json
{
"env": {
"LOADER_PATH": "your_actual_key_here"
}
}Tool Mock Playground
SandboxData Prism Tool Interface Simulation · Preview tool schema & outputs without local runtime
{
"target": "Data Prism",
"action": "execute",
"options": {
"mode": "standard",
"timeoutMs": 5000
}
}Click 'Run Mock' above
to preview the raw response returned to the LLM
Decision Guide: Why & When to Use
Assess suitability before installing to save trial-and-error time
- PR review
- Changelog generation
- Cross-repo issue search
- Replacing human security audit
- Unauthorized repo access
Data Prism + Scenario Prompt → Complete Agent Automation
MCP hands-on: install to visible results
Follow the full lab (expected UI/output + contrast checks). After installing this item, verify with the tutorial prompts.
Related resources
GlobalGov — Government Contracts, Tenders & Procurement
v1.0.8
io.globalgov/mcp
Find government contracts, tenders and RFPs you can still bid on, in 193 countries. Free, no key.
Fillo
v0.10.0
io.github.jacobfunch/usefillo
Fillo MCP server — provision, scaffold, publish, and query forms from your coding agent.
securityscorecard-mcp
v2.0.0
io.github.CallMarcus/securityscorecard-mcp
Community-built, comprehensive MCP server for the SecurityScorecard API (unofficial).
taxapp.nz
v1.0.0
nz.taxapp/taxapp
Your taxapp.nz income, expenses, rental properties and NZ tax figures, and adding new records.
AgentsJunction
v0.1.1
io.github.JakubTrousil/agentsjunction
Discover MCP servers and A2A agents; verify, message, post, follow, react, and receive webhooks.
WebZum - Websites for Small & Local Businesses
v1.4.0
io.github.suprraz/webzum
Describe a local business, verify the owner email: SEO site, hosting, chatbot, Google Ads.
Often paired with
API Gateway
v1.2.25
io.clawhub.byungkyu/api-gateway
Call third-party APIs through the Maton gateway, which injects the credential for an app the user has already connected. Use this skill when the user names a connected app and a concrete action in it - read a mailbox, query a CRM, file an issue, update a spreadsheet, etc.
v1.2.6
io.clawhub.byungkyu/linkedin-api
LinkedIn API integration with managed OAuth. Share posts, manage profile, and access LinkedIn features. Use this skill when users want to share content on LinkedIn, get profile/organization information, or interact with LinkedIn's platform.
WhatsApp Business
v1.2.8
io.clawhub.byungkyu/whatsapp-business
WhatsApp Business API integration with managed OAuth. Send messages, manage templates, and handle conversations. Use this skill when users want to interact with WhatsApp Business. For other third party apps, use the api-gateway skill (https://clawhub.ai/byungkyu/api-gateway).
Salesforce
v1.2.7
io.clawhub.byungkyu/salesforce-api
Salesforce CRM API integration with managed OAuth. Install only if you need Salesforce CRM administration. Connect with the narrowest Salesforce permissions available, prefer sandbox orgs for destructive or batch work, verify the intended connection ID before each request, etc.
Keep exploring AgentHub
Most people compare similar tools or check scenario guides before installing—start here.
Listing badge: put AgentHub on your site
Copy either snippet into your project homepage, docs, or GitHub README. The badge is a hotlinked SVG — nothing to host — and it links back to this page so visitors can find the install steps.
<a href="https://myagenthub.cn/p/io.github.AindriuB/data-prism" title="Listed on AgentHub: Data Prism" target="_blank" rel="noopener">
<img src="https://myagenthub.cn/badge/io.github.AindriuB/data-prism?lang=en" alt="Listed on AgentHub: Data Prism" height="20" style="border:0"/>
</a>[](https://myagenthub.cn/p/io.github.AindriuB/data-prism)Badges are generated on the fly from /badge/<package-id>, so name and listing changes propagate automatically. Keep the link target unchanged — it is what counts as the referral.
Unified Manifest
{
"id": "io.github.AindriuB/data-prism",
"type": "mcp-server",
"version": "0.3.1",
"displayName": "Data Prism",
"description": "Fail-closed privacy layer that pseudonymises enterprise API data for LLM agents and MCP clients.",
"repository": {
"url": "https://github.com/AindriuB/data-prism",
"source": "github"
},
"homepage": "https://aindriub.github.io/data-prism/",
"distribution": {
"packages": [
{
"registryType": "oci",
"identifier": "ghcr.io/aindriub/data-prism-server:0.3.1",
"runtimeHint": "docker",
"transport": "streamable-http",
"environmentVariables": [
{
"name": "LOADER_PATH",
"description": "Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above)",
"isRequired": true
},
{
"name": "DATAPRISM_SECURITY_JWT_ISSUER",
"description": "OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment",
"isRequired": true
},
{
"name": "DATAPRISM_SECURITY_JWT_AUDIENCE",
"description": "Expected JWT audience claim for this deployment; required for every protected deployment",
"isRequired": true
},
{
"name": "DATAPRISM_SECURITY_JWT_JWK_SET_URI",
"description": "HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both",
"isRequired": true
},
{
"name": "DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI",
"description": "Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both"
},
{
"name": "DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL",
"description": "JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims",
"isRequired": true
},
{
"name": "DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES",
"description": "JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims",
"isRequired": true
},
{
"name": "DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION",
"description": "JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims",
"isRequired": true
},
{
"name": "DATAPRISM_SECURITY_POLICY_PURPOSES",
"description": "Comma-separated list of permitted purposes; at least one is required",
"isRequired": true
},
{
"name": "DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR",
"description": "Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 3.5.16), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required",
"isRequired": true
},
{
"name": "DATAPRISM_PRIVACY_PROFILE",
"description": "Name of the reviewed privacy profile implementation to apply; required",
"isRequired": true
},
{
"name": "DATAPRISM_PRIVACY_SCOPE_LIFETIME",
"description": "Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required",
"isRequired": true
},
{
"name": "DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID",
"description": "Identifier of the pinned HMAC key used to derive synthetic identities; required",
"isRequired": true
},
{
"name": "DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE",
"description": "Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value",
"isRequired": true
},
{
"name": "DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE",
"description": "Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both"
},
{
"name": "DATAPRISM_AUDIT_SINK",
"description": "Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op",
"isRequired": true
},
{
"name": "DATAPRISM_AUDIT_WRITER_ID",
"description": "Writer/instance identity recorded on every audit entry; required",
"isRequired": true
},
{
"name": "DATAPRISM_AUDIT_FILE_PATH",
"description": "Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise"
},
{
"name": "DATAPRISM_METRICS_SINK",
"description": "Metrics sink binding, currently only micrometer; required in production, never the framework no-op",
"isRequired": true
},
{
"name": "DATAPRISM_HAZELCAST_TOPOLOGY",
"description": "Cluster read-budget topology: embedded (shared across the cluster) or single-node (enforced per process); required, never defaulted",
"isRequired": true
},
{
"name": "DATAPRISM_SOURCES_CUSTOMER_BASE_URL",
"description": "Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required",
"isRequired": true
},
{
"name": "DATAPRISM_SOURCES_CUSTOMER_TIMEOUT",
"description": "Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL",
"isRequired": true
}
]
}
],
"remotes": []
},
"dependencies": [],
"installTargets": [
"claude-code",
"claude-desktop",
"cursor",
"vscode",
"trae",
"cherry-studio",
"lingma",
"windsurf",
"cline",
"workbuddy"
],
"keywords": [],
"provenance": {
"origin": "official-mcp-registry",
"originalId": "io.github.AindriuB/data-prism",
"originalUrl": "https://registry.modelcontextprotocol.io/v0.1/servers/io.github.AindriuB%2Fdata-prism/versions/latest",
"isOfficial": true,
"status": "active"
}
}