Skip to content

Connect OpenMetadata

Connecting OpenMetadata gives the agents your curated metadata: asset search across your OpenMetadata instance, lineage, ownership, glossary, and tags, all feeding catalog, quality, and incident work. This connector is metadata-read focused — see Supported operations for the honest scope. Until verified, OpenMetadata stays in 🟡 Evaluation on sample data.

  • Data Workers installed and registered with your coding agent (install guide)
  • A running OpenMetadata instance and its server URL
  • Permission to create a bot and issue a JWT in OpenMetadata

Step 1 — Create a least-privilege credential

Section titled “Step 1 — Create a least-privilege credential”

In OpenMetadata, create a dedicated bot (not a personal account) with a read-scoped role covering the assets you want visible, and issue a JWT for it. Read access is all this connector needs; don’t reuse the ingestion bot or an admin token (least-privilege guidance).

Checkpoint: a JWT exists for a bot whose OpenMetadata role is read-only.

Set these in the shell your coding agent launches from, then restart the coding agent so the MCP server picks them up. The token stays on your machine; nothing is sent to Data Workers.

Terminal window
export OPENMETADATA_HOST="<https://openmetadata.yourco.internal>"
export OPENMETADATA_JWT_TOKEN="<jwt>"

Checkpoint: the variables are visible in the environment your coding agent starts from.

Setting a credential is not the same as a working connection. Ask:

Test the connection to my OpenMetadata catalog.

The agent makes a real call to your instance. OpenMetadata shows 🟢 Connected only after that live test passes; a failure reports 🔴 with the reason. Full model: Verify your setup.

Checkpoint: OpenMetadata reports 🟢 Connected.

OperationStatus
Discovery (assets, schemas, lineage, metadata read)Supported
Catalog control-plane writesNot supported
RBAC (role-based access enforcement)Not supported
Policy attachment and enforcementNot supported
Credential vending (scoped, time-bound tokens)Not supported

Straight answer: OpenMetadata is a metadata-read connector today. Control-plane operations route to connectors that support them (for example your warehouse connector), and calling one here returns a clear error naming those connectors — never a pretend success.

SymptomLikely causeFix
Still answering from sample dataVariables set in a different shell, or agent not restartedSet them in the shell your coding agent launches from, restart it
🔴 with an auth errorJWT expired or revokedRe-issue the bot’s JWT and update OPENMETADATA_JWT_TOKEN
🔴 with a network/timeout errorHost can’t reach the server URL (internal network, VPN)Run the agents from a host with network access to OpenMetadata
Assets missing from answersBot’s role doesn’t cover those assetsExtend the bot’s read-scoped role to the missing assets