Skip to content

Connect DataHub

Connecting DataHub gives the agents the metadata your organization has already curated: entity search across your DataHub instance, lineage traversal, ownership and glossary context, all feeding catalog, quality, and incident work. This connector is metadata-read focused — see Supported operations for the honest scope. Until verified, DataHub stays in 🟡 Evaluation on sample data.

  • Data Workers installed and registered with your coding agent (install guide)
  • A running DataHub instance and its GMS endpoint URL
  • Permission to generate an access token in DataHub

Step 1 — Create a least-privilege credential

Section titled “Step 1 — Create a least-privilege credential”

Generate a read-scoped access token for the GMS API — in DataHub, create a dedicated service user (not a personal account), give it read privileges on the entities in scope, and issue the token under that user. Read access is all this connector needs; don’t issue an admin token (least-privilege guidance).

Checkpoint: a token exists for a service user whose DataHub privileges are read-only.

Set these in the shell your coding agent launches from, then restart the coding agent so the MCP server picks them up. The token stays on your machine; nothing is sent to Data Workers.

Terminal window
export DATAHUB_GMS_URL="<https://datahub-gms.yourco.internal>"
export DATAHUB_TOKEN="<token>"

Checkpoint: the variables are visible in the environment your coding agent starts from.

Setting a credential is not the same as a working connection. Ask:

Test the connection to my DataHub catalog.

The agent makes a real call to your GMS endpoint. DataHub shows 🟢 Connected only after that live test passes; a failure reports 🔴 with the reason. Full model: Verify your setup.

Checkpoint: DataHub reports 🟢 Connected.

OperationStatus
Discovery (entities, schemas, lineage, metadata read)Supported
Catalog control-plane writesNot supported
RBAC (role-based access enforcement)Not supported
Policy attachment and enforcementNot supported
Credential vending (scoped, time-bound tokens)Not supported

Straight answer: DataHub is a metadata-read connector today. Control-plane operations route to connectors that support them (for example your warehouse connector), and calling one here returns a clear error naming those connectors — never a pretend success.

SymptomLikely causeFix
Still answering from sample dataVariables set in a different shell, or agent not restartedSet them in the shell your coding agent launches from, restart it
🔴 with an auth errorToken expired, or issued for a user without read privilegesRe-issue the token for the read-scoped service user
🔴 with a network/timeout errorHost can’t reach the GMS URL (internal network, VPN)Run the agents from a host with network access to DataHub
Entities missing from answersService user can’t see those entities in DataHubExtend the service user’s read privileges to the missing scope