Connect DataHub
Connecting DataHub gives the agents the metadata your organization has already curated: entity search across your DataHub instance, lineage traversal, ownership and glossary context, all feeding catalog, quality, and incident work. This connector is metadata-read focused — see Supported operations for the honest scope. Until verified, DataHub stays in 🟡 Evaluation on sample data.
Prerequisites
Section titled “Prerequisites”- Data Workers installed and registered with your coding agent (install guide)
- A running DataHub instance and its GMS endpoint URL
- Permission to generate an access token in DataHub
Step 1 — Create a least-privilege credential
Section titled “Step 1 — Create a least-privilege credential”Generate a read-scoped access token for the GMS API — in DataHub, create a dedicated service user (not a personal account), give it read privileges on the entities in scope, and issue the token under that user. Read access is all this connector needs; don’t issue an admin token (least-privilege guidance).
Checkpoint: a token exists for a service user whose DataHub privileges are read-only.
Step 2 — Set the environment variables
Section titled “Step 2 — Set the environment variables”Set these in the shell your coding agent launches from, then restart the coding agent so the MCP server picks them up. The token stays on your machine; nothing is sent to Data Workers.
export DATAHUB_GMS_URL="<https://datahub-gms.yourco.internal>"export DATAHUB_TOKEN="<token>"Checkpoint: the variables are visible in the environment your coding agent starts from.
Step 3 — Verify
Section titled “Step 3 — Verify”Setting a credential is not the same as a working connection. Ask:
Test the connection to my DataHub catalog.
The agent makes a real call to your GMS endpoint. DataHub shows 🟢 Connected only after that live test passes; a failure reports 🔴 with the reason. Full model: Verify your setup.
Checkpoint: DataHub reports 🟢 Connected.
Supported operations
Section titled “Supported operations”| Operation | Status |
|---|---|
| Discovery (entities, schemas, lineage, metadata read) | Supported |
| Catalog control-plane writes | Not supported |
| RBAC (role-based access enforcement) | Not supported |
| Policy attachment and enforcement | Not supported |
| Credential vending (scoped, time-bound tokens) | Not supported |
Straight answer: DataHub is a metadata-read connector today. Control-plane operations route to connectors that support them (for example your warehouse connector), and calling one here returns a clear error naming those connectors — never a pretend success.
Troubleshooting
Section titled “Troubleshooting”| Symptom | Likely cause | Fix |
|---|---|---|
| Still answering from sample data | Variables set in a different shell, or agent not restarted | Set them in the shell your coding agent launches from, restart it |
| 🔴 with an auth error | Token expired, or issued for a user without read privileges | Re-issue the token for the read-scoped service user |
| 🔴 with a network/timeout error | Host can’t reach the GMS URL (internal network, VPN) | Run the agents from a host with network access to DataHub |
| Entities missing from answers | Service user can’t see those entities in DataHub | Extend the service user’s read privileges to the missing scope |