Lagaam MCP Server
by lagaam-aiio.github.lagaam-ai/lagaamv0.2.4
Stops an agent's Trino or Pinot query before it runs if it costs too much or reads outside its grant
context tax
queued
security
queued
cold start
queued
freshness
Active6d ago
Install Lagaam MCP server
Install in Claude Code
claude mcp add lagaam -e LAGAAM_ALLOWED_TABLES='<lagaam-allowed-tables>' -e PINOT_PASSWORD='<pinot-password>' -- uvx lagaamInstall in Cursor
{
"mcpServers": {
"lagaam": {
"command": "uvx",
"args": [
"lagaam"
],
"env": {
"LAGAAM_ALLOWED_TABLES": "<lagaam-allowed-tables>",
"PINOT_PASSWORD": "<pinot-password>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"lagaam": {
"command": "uvx",
"args": [
"lagaam"
],
"env": {
"LAGAAM_ALLOWED_TABLES": "<lagaam-allowed-tables>",
"PINOT_PASSWORD": "<pinot-password>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"lagaam": {
"type": "stdio",
"command": "uvx",
"args": [
"lagaam"
],
"env": {
"LAGAAM_ALLOWED_TABLES": "<lagaam-allowed-tables>",
"PINOT_PASSWORD": "<pinot-password>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"lagaam": {
"command": "uvx",
"args": [
"lagaam"
],
"env": {
"LAGAAM_ALLOWED_TABLES": "<lagaam-allowed-tables>",
"PINOT_PASSWORD": "<pinot-password>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| LAGAAM_ALLOWED_TABLES | yes | — | Comma list of catalog.schema.table grants; the server will not start without it |
| LAGAAM_ALLOW_ALL_TABLES | — | — | true to run with no grant at all: an explicit opt-out, off by default |
| LAGAAM_ENGINE | — | — | Which adapter to run |
| TRINO_HOST | — | — | Trino coordinator host |
| TRINO_PORT | — | — | Trino coordinator port |
| TRINO_USER | — | — | Trino user |
| PINOT_CONTROLLER_URL | — | — | Pinot controller URL |
| PINOT_BROKER_URL | — | — | Pinot broker URL |
| PINOT_USER | — | — | Pinot user; unset means no auth |
| PINOT_PASSWORD | — | yes | Pinot password; unset means no auth |
| LAGAAM_AGENT_NAME | — | — | Identity stamped on the audit trail |
| LAGAAM_MAX_SCAN_BYTES | — | — | Scan-bytes budget per query, checked before it runs (default 50 GiB) |
| LAGAAM_MAX_ROWS | — | — | Scanned-row estimate budget per query; unset means ungated |
| LAGAAM_MAX_INTERMEDIATE_ROWS | — | — | Rows the engine would build at its widest step, not rows returned, so a LIMIT doesn't lower it |
| LAGAAM_MAX_RETURNED_ROWS | — | — | Rows returned to the agent per query, capped at 100000; a bigger LIMIT in the query is lowered to it |
| LAGAAM_QUERY_TIMEOUT | — | — | Wall-clock seconds per query |
| LAGAAM_METADATA_TTL | — | — | Metadata cache TTL, seconds |
| LAGAAM_AUDIT_LOG | — | — | Audit JSONL file path; unset means stderr |
Freshness
Active — last maintenance signal 6d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-10-04 · 6d ago · GitHub
Latest release
2026-09-29 · 11d ago · GitHub · v0.2.4
Package published
no data · npm/PyPI
Registry entry updated
2026-09-29 · 11d ago · official registry · v0.2.4
FAQ
›How do I install the Lagaam MCP server in Claude Code?
Run: claude mcp add lagaam -e LAGAAM_ALLOWED_TABLES='<lagaam-allowed-tables>' -e PINOT_PASSWORD='<pinot-password>' -- uvx lagaam. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Lagaam require an API key?
Yes. It expects LAGAAM_ALLOWED_TABLES, PINOT_PASSWORD, of which 1 is a secret.
›Can I use Lagaam as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Lagaam in the official MCP registry?
Yes, as io.github.lagaam-ai/lagaam.