Data Prism
Runs onlineNo credentials listedRepository declared by sourceUpdated 2026-10-09
io.github.AindriuB/data-prism · Registry status: active
At a glance
Fail-closed privacy layer that pseudonymises enterprise API data for LLM agents and MCP clients.
Vendor's own description, untranslated and unverified
- Execution location
- Runs onlineMCP-Register · 2026-09-18
- Required secrets declared
- No credentials listedMCP-Register · 2026-09-18
- Declared version and change
0.6.0· Source-reported change date 2026-10-09MCP-Register · 2026-10-10- Repository as declared
- github.com/AindriuB/data-prismMCP-Register · 2026-09-18
- Configuration
- can be built from the disclosed start template
Inspect connection paths and prerequisites
Related categories
- MCP servers without declared required secrets35,800
- Remotely executed MCP servers24,811
- MCP servers with a repository URL30,107
- MCP servers over streamable-http only23,554
- MCP servers as a container only702
- Remote MCP servers with a repository URL13,955
6 of 7 categories. All categories in the segment catalogue
Page last changed:
Sources and collection
- Runs
- Runs online
- Credentials
- No credentials listed
- Registry record changed
- 2026-10-09
- Setup
- Template available
- Registry name
io.github.AindriuB/data-prism- Package coordinate
oci:ghcr.io/aindriub/data-prism-server:0.6.0- Declared version
0.6.0- Source-reported listing date
- 2026-10-09
- Source-reported change date
- 2026-10-09
- First seen by tracevero
- 2026-09-18
- Vendor's website
- https://aindriub.github.io/data-prism/
Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin. What the confidence levels mean
Measured values
| Required secrets declared | No credentials listed no Original data – Required secret variables (raw): confirmed absent Original data – Required secret headers (raw): confirmed absent Source: MCP-Register · collected on 2026-09-18 · derived |
|---|---|
| Execution location | Runs online remote Original data – Transports (raw): streamable-http Source: MCP-Register · collected on 2026-09-18 · derived |
| Path argument present | no Original data – Path arguments (raw): confirmed absent Original data – Path environment variables (raw): confirmed absent Source: MCP-Register · collected on 2026-09-18 · derived |
| Repository URL listed | Repository declared by source yes Original data – Repository (raw): https://github.com/AindriuB/data-prism Source: MCP-Register · collected on 2026-09-18 · derived |
| Declared version | 0.6.0 Source: MCP-Register · collected on 2026-10-10 · self-declared |
What is measured is what a manifest declares, not what a piece of software does. This registry fetches no repository URL, no endpoint and no package index; nothing here is verified. Which value comes from which source, and by which rule it was formed, is set out in the Methodology.
Source data25
Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin.
| Description (raw) | Fail-closed privacy layer that pseudonymises enterprise API data for LLM agents and MCP clients. Source: MCP-Register · collected on 2026-09-25 · self-declared |
|---|---|
| Environment variables (raw) | LOADER_PATH, DATAPRISM_SECURITY_JWT_ISSUER, DATAPRISM_SECURITY_JWT_AUDIENCE, DATAPRISM_SECURITY_JWT_JWK_SET_URI, DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI, DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL, DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES, DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION, DATAPRISM_SECURITY_POLICY_PURPOSES, DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR, DATAPRISM_PRIVACY_PROFILE, DATAPRISM_PRIVACY_SCOPE_LIFETIME, DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID, DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE, DATAPRISM_AUDIT_SINK, DATAPRISM_AUDIT_WRITER_ID, DATAPRISM_AUDIT_FILE_PATH, DATAPRISM_METRICS_SINK, DATAPRISM_HAZELCAST_TOPOLOGY, DATAPRISM_HAZELCAST_CLUSTERNAME, DATAPRISM_HAZELCAST_JOIN_MODE, DATAPRISM_HAZELCAST_JOIN_MEMBERS, DATAPRISM_HAZELCAST_MEMBER_PORT, DATAPRISM_OPERATOR_ENABLED, DATAPRISM_OPERATOR_PORT, DATAPRISM_OPERATOR_REQUIREDAUDIENCE, DATAPRISM_OPERATOR_REQUIREDSCOPE, DATAPRISM_SOURCES_CUSTOMER_BASE_URL, DATAPRISM_SOURCES_CUSTOMER_TIMEOUT Source: MCP-Register · collected on 2026-10-08 · self-declared |
| Required secret variables (raw) | confirmed absent Source: MCP-Register · collected on 2026-09-18 · self-declared |
| Transports (raw) | streamable-http Source: MCP-Register · collected on 2026-09-18 · self-declared |
| Path arguments (raw) | confirmed absent Source: MCP-Register · collected on 2026-09-18 · self-declared |
| Repository (raw) | https://github.com/AindriuB/data-prism Source: MCP-Register · collected on 2026-09-18 · self-declared |
| Package registries (raw) | oci Source: MCP-Register · collected on 2026-09-18 · self-declared |
| Required secret headers (raw) | confirmed absent Source: MCP-Register · collected on 2026-09-18 · self-declared |
| Path environment variables (raw) | confirmed absent Source: MCP-Register · collected on 2026-09-18 · self-declared |
| Remote URLs (raw) | confirmed absent Source: MCP-Register · collected on 2026-09-18 · self-declared |
| Remote hosts (raw) | confirmed absent Source: MCP-Register · collected on 2026-09-18 · self-declared |
| Registry status message (raw) | confirmed absent Source: MCP-Register · collected on 2026-09-18 · self-declared |
| First listed in the registry (raw) | 2026-10-09 Source: MCP-Register · collected on 2026-10-10 · self-declared |
| Last changed in the registry (raw) | 2026-10-09 Source: MCP-Register · collected on 2026-10-10 · self-declared |
| Schema version of the raw record (raw) | https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json Source: MCP-Register · collected on 2026-09-18 · self-declared |
| Delivery form (raw) | package Source: MCP-Register · collected on 2026-09-18 · self-declared |
| Repository platform (raw) | github Source: MCP-Register · collected on 2026-09-18 · self-declared |
| Repository subfolder (raw) | confirmed absent Source: MCP-Register · collected on 2026-09-18 · self-declared |
| Package identifiers (raw) | ghcr.io/aindriub/data-prism-server:0.6.0 Source: MCP-Register · collected on 2026-10-10 · self-declared |
| Package versions (raw) | confirmed absent Source: MCP-Register · collected on 2026-09-18 · self-declared |
| Runtime hints (raw) | docker Source: MCP-Register · collected on 2026-09-18 · self-declared |
| Environment variable formats (raw) | confirmed absent Source: MCP-Register · collected on 2026-09-18 · self-declared |
| Environment variable descriptions (raw) | DATAPRISM_AUDIT_FILE_PATH=Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise · DATAPRISM_AUDIT_SINK=Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op · DATAPRISM_AUDIT_WRITER_ID=Writer/instance identity recorded on every audit entry; required · DATAPRISM_HAZELCAST_CLUSTERNAME=Hazelcast cluster name; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded, never dev, refused if set with single-node · DATAPRISM_HAZELCAST_JOIN_MEMBERS=Comma-separated member addresses (host or host:port); required when DATAPRISM_HAZELCAST_JOIN_MODE=tcp-ip, otherwise unused · DATAPRISM_HAZELCAST_JOIN_MODE=How cluster members find each other: tcp-ip, kubernetes or none; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded (none is an explicit single member bound to 127.0.0.1), refused if set with single-node · DATAPRISM_HAZELCAST_MEMBER_PORT=Hazelcast member port, default 5701, never auto-incremented; must differ from the server, management and operator ports. Member traffic is unencrypted, so keep it on a private network. Optional · DATAPRISM_HAZELCAST_TOPOLOGY=Cluster read-budget topology: embedded (shared across members that have joined one cluster; set cluster name and join mode) or single-node (enforced per process); required, never defaulted · DATAPRISM_METRICS_SINK=Metrics sink binding, currently only micrometer; required in production, never the framework no-op · DATAPRISM_OPERATOR_ENABLED=Enables the operator surface; optional, off by default · DATAPRISM_OPERATOR_PORT=Port of the operator listener; required when DATAPRISM_OPERATOR_ENABLED=true, must differ from the server, management (OPERATOR_PORT_SHARED otherwise) and member ports, and has no fixed default (publish it explicitly) · DATAPRISM_OPERATOR_REQUIREDAUDIENCE=JWT audience an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true · DATAPRISM_OPERATOR_REQUIREDSCOPE=JWT scope an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true · DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE=Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value · DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID=Identifier of the pinned HMAC key used to derive synthetic identities; required · DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE=Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both · DATAPRISM_PRIVACY_PROFILE=Name of the reviewed privacy profile implementation to apply; required · DATAPRISM_PRIVACY_SCOPE_LIFETIME=Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required · DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR=Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 4.1.1), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required · DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION=JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims · DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL=JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims · DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES=JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims · DATAPRISM_SECURITY_JWT_AUDIENCE=Expected JWT audience claim for this deployment; required for every protected deployment · DATAPRISM_SECURITY_JWT_ISSUER=OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment · DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI=Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both · DATAPRISM_SECURITY_JWT_JWK_SET_URI=HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both · DATAPRISM_SECURITY_POLICY_PURPOSES=Comma-separated list of permitted purposes; at least one is required · DATAPRISM_SOURCES_CUSTOMER_BASE_URL=Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required · DATAPRISM_SOURCES_CUSTOMER_TIMEOUT=Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL · LOADER_PATH=Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above) Source: MCP-Register · collected on 2026-10-09 · self-declared |
| Icon formats (raw) | confirmed absent Source: MCP-Register · collected on 2026-09-18 · self-declared |
| Connection paths (source structure) | {"packages":[{"registryType":"oci","identifier":"ghcr.io/aindriub/data-prism-server:0.6.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"LOADER_PATH","description":"Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above)","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER","description":"OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_AUDIENCE","description":"Expected JWT audience claim for this deployment; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_JWK_SET_URI","description":"HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI","description":"Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both","required":false,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL","description":"JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES","description":"JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION","description":"JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_POLICY_PURPOSES","description":"Comma-separated list of permitted purposes; at least one is required","required":true,"secret":false},{"name":"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR","description":"Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 4.1.1), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_PROFILE","description":"Name of the reviewed privacy profile implementation to apply; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_SCOPE_LIFETIME","description":"Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID","description":"Identifier of the pinned HMAC key used to derive synthetic identities; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE","description":"Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE","description":"Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both","required":false,"secret":false},{"name":"DATAPRISM_AUDIT_SINK","description":"Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_WRITER_ID","description":"Writer/instance identity recorded on every audit entry; required","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_FILE_PATH","description":"Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise","required":false,"secret":false},{"name":"DATAPRISM_METRICS_SINK","description":"Metrics sink binding, currently only micrometer; required in production, never the framework no-op","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_TOPOLOGY","description":"Cluster read-budget topology: embedded (shared across members that have joined one cluster; set cluster name and join mode) or single-node (enforced per process); required, never defaulted","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_CLUSTERNAME","description":"Hazelcast cluster name; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded, never dev, refused if set with single-node","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_JOIN_MODE","description":"How cluster members find each other: tcp-ip, kubernetes or none; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded (none is an explicit single member bound to 127.0.0.1), refused if set with single-node","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_JOIN_MEMBERS","description":"Comma-separated member addresses (host or host:port); required when DATAPRISM_HAZELCAST_JOIN_MODE=tcp-ip, otherwise unused","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_MEMBER_PORT","description":"Hazelcast member port, default 5701, never auto-incremented; must differ from the server, management and operator ports. Member traffic is unencrypted, so keep it on a private network. Optional","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_ENABLED","description":"Enables the operator surface; optional, off by default","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_PORT","description":"Port of the operator listener; required when DATAPRISM_OPERATOR_ENABLED=true, must differ from the server, management (OPERATOR_PORT_SHARED otherwise) and member ports, and has no fixed default (publish it explicitly)","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_REQUIREDAUDIENCE","description":"JWT audience an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_REQUIREDSCOPE","description":"JWT scope an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true","required":false,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_BASE_URL","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL","required":true,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} Source: MCP-Register · collected on 2026-10-10 · self-declared |
Embed this badge
Paste this line into a README of your own. The badge states how many values the registry holds for the entry and when it last looked, and it links back to this page.
[](https://tracevero.com/mcp/io-github-aindriub-data-prism)
The image is drawn again on every request, so it always reports the current state while the pasted line stays as it is. It carries no rating and no traffic light – only the two measured figures.
Changes
| 2026-10-10 | Declared version: 0.5.0 → 0.6.0 |
|---|---|
| 2026-10-10 | Last changed in the registry (raw): 2026-10-08 → 2026-10-09 |
| 2026-10-10 | First listed in the registry (raw): 2026-10-08 → 2026-10-09 |
These are the 3 most recent changes to this entry. Full history
tracevero · https://tracevero.com/mcp/io-github-aindriub-data-prism