Data Prism MCP Server
by aindriubio.github.AindriuB/data-prismv0.5.0
Fail-closed privacy layer that pseudonymises enterprise API data for LLM agents and MCP clients.
context tax
queued
security
queued
cold start
queued
freshness
Active1d ago
Install Data Prism MCP server
No published package or hosted endpoint yet — see the repository README for build-from-source instructions.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| LOADER_PATH | yes | — | Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above) |
| DATAPRISM_SECURITY_JWT_ISSUER | yes | — | OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment |
| DATAPRISM_SECURITY_JWT_AUDIENCE | yes | — | Expected JWT audience claim for this deployment; required for every protected deployment |
| DATAPRISM_SECURITY_JWT_JWK_SET_URI | yes | — | HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both |
| DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI | — | — | Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both |
| DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL | yes | — | JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims |
| DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES | yes | — | JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims |
| DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION | yes | — | JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims |
| DATAPRISM_SECURITY_POLICY_PURPOSES | yes | — | Comma-separated list of permitted purposes; at least one is required |
| DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR | yes | — | Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 4.1.1), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required |
| DATAPRISM_PRIVACY_PROFILE | yes | — | Name of the reviewed privacy profile implementation to apply; required |
| DATAPRISM_PRIVACY_SCOPE_LIFETIME | yes | — | Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required |
| DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID | yes | — | Identifier of the pinned HMAC key used to derive synthetic identities; required |
| DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE | yes | — | Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value |
| DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE | — | — | Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both |
| DATAPRISM_AUDIT_SINK | yes | — | Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op |
| DATAPRISM_AUDIT_WRITER_ID | yes | — | Writer/instance identity recorded on every audit entry; required |
| DATAPRISM_AUDIT_FILE_PATH | — | — | Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise |
| DATAPRISM_METRICS_SINK | yes | — | Metrics sink binding, currently only micrometer; required in production, never the framework no-op |
| DATAPRISM_HAZELCAST_TOPOLOGY | yes | — | Cluster read-budget topology: embedded (shared across members that have joined one cluster; set cluster name and join mode) or single-node (enforced per process); required, never defaulted |
| DATAPRISM_HAZELCAST_CLUSTERNAME | — | — | Hazelcast cluster name; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded, never dev, refused if set with single-node |
| DATAPRISM_HAZELCAST_JOIN_MODE | — | — | How cluster members find each other: tcp-ip, kubernetes or none; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded (none is an explicit single member bound to 127.0.0.1), refused if set with single-node |
| DATAPRISM_HAZELCAST_JOIN_MEMBERS | — | — | Comma-separated member addresses (host or host:port); required when DATAPRISM_HAZELCAST_JOIN_MODE=tcp-ip, otherwise unused |
| DATAPRISM_HAZELCAST_MEMBER_PORT | — | — | Hazelcast member port, default 5701, never auto-incremented; must differ from the server, management and operator ports. Member traffic is unencrypted, so keep it on a private network. Optional |
| DATAPRISM_OPERATOR_ENABLED | — | — | Enables the operator surface; optional, off by default |
| DATAPRISM_OPERATOR_PORT | — | — | Port of the operator listener; required when DATAPRISM_OPERATOR_ENABLED=true, must differ from the server, management (OPERATOR_PORT_SHARED otherwise) and member ports, and has no fixed default (publish it explicitly) |
| DATAPRISM_OPERATOR_REQUIREDAUDIENCE | — | — | JWT audience an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true |
| DATAPRISM_OPERATOR_REQUIREDSCOPE | — | — | JWT scope an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true |
| DATAPRISM_SOURCES_CUSTOMER_BASE_URL | yes | — | Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required |
| DATAPRISM_SOURCES_CUSTOMER_TIMEOUT | yes | — | Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL |
Freshness
Active — last maintenance signal 1d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-10-08 · 1d ago · GitHub
Latest release
2026-10-08 · 2d ago · GitHub · v0.5.0
Package published
no data · npm/PyPI
Registry entry updated
2026-10-08 · 2d ago · official registry · v0.5.0
FAQ
›Does Data Prism require an API key?
Yes. It expects LOADER_PATH, DATAPRISM_SECURITY_JWT_ISSUER, DATAPRISM_SECURITY_JWT_AUDIENCE, DATAPRISM_SECURITY_JWT_JWK_SET_URI, DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL, DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES, DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION, DATAPRISM_SECURITY_POLICY_PURPOSES, DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR, DATAPRISM_PRIVACY_PROFILE, DATAPRISM_PRIVACY_SCOPE_LIFETIME, DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID, DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, DATAPRISM_AUDIT_SINK, DATAPRISM_AUDIT_WRITER_ID, DATAPRISM_METRICS_SINK, DATAPRISM_HAZELCAST_TOPOLOGY, DATAPRISM_SOURCES_CUSTOMER_BASE_URL, DATAPRISM_SOURCES_CUSTOMER_TIMEOUT.
›Can I use Data Prism as a remote (hosted) MCP server?
Yes. It is a hosted MCP server; connect to its URL with any client that supports remote MCP.
›Is Data Prism in the official MCP registry?
Yes, as io.github.AindriuB/data-prism.
Alternatives to Data Prism
Other ai & llm tools MCP servers.