Wren AI MCP server

Give your agents an analyst, not a database password.

Connect Claude, ChatGPT, Claude Code or your own agent to one MCP endpoint. Agents hand data questions to Wren AI and get back governed SQL, results and charts from 20+ databases, under each user's permissions.

  • OAuth sign-in, no API keys
  • Row- and column-level security per user
  • One endpoint, 20+ sources
claude code, wrenai
OAuth

$ claude mcp add --transport http wrenai \ https://cloud.getwren.ai/api/mcp

✓ signed in, 2 projects exposed

toollist_projects

sales-analytics, finance-core

toolask

{ projectId: "sales-analytics", question: "Net revenue by region last quarter?" }

SELECT region, SUM(net_revenue) AS net_revenue
FROM sales_performance
WHERE fiscal_quarter = '2026-Q3'
GROUP BY region

4 rows. North America leads at $4.2M; APAC is down 6% quarter over quarter.

metric: net_revenuerule: fiscal calendarrow policy: region

toolgenerate_chart

Vega chart spec, bar chart by region

Illustrative session on a sample project.

Trusted by data teams worldwide, with 17,841 GitHub stars

The tool surface

Eight tools. One context layer behind every call.

Agents can delegate the whole question, or drive each step themselves. Either way, every call resolves through the same definitions, joins and access rules your team uses in Wren AI.

Discover

See what it can query

Start a session by finding the projects this user can reach and how their data is shaped.

  • list_projects

    Lists the projects exposed to MCP that this user is a member of.

  • get_project_metadata

    Returns the tables and columns of one project.

Delegate

Hand off the whole question

Treat Wren AI as a sub-agent: it plans the query, runs governed SQL and answers in plain language.

  • ask

    End-to-end question answering from live data.

  • respond_clarification

    Replies when Wren AI asks which metric or period you meant.

  • generate_summary

    Turns query results into a plain-language summary.

Compose

Drive each step yourself

For agents that want control: generate the SQL, review it, run it and chart the result.

  • generate_sql

    Turns a question into SQL against your context layer.

  • run_sql

    Executes SQL under the signed-in user's permissions.

  • generate_chart

    Returns a Vega chart spec for the result.

Every tool except list_projects takes a projectId, so one connection can work across every project the user is allowed to query.

Why it matters

A connection is not context.

Most database MCP servers hand an agent a schema and a set of credentials. The agent then guesses what the columns mean on every question. Wren AI puts a context layer between the agent and your data, so answers agree no matter which agent asked.

DimensionAgent on a database MCP serverAgent on Wren AI MCP
Business definitionsInferred from table and column namesResolved from your context layer, versioned in git
JoinsChosen by the model on each questionDeclared once and reused by every agent
SourcesOne server and one connection per database20+ sources through one endpoint
CredentialsDatabase credentials in the agent's configOAuth with each user's Wren AI account
AccessWhatever the connection's role can seeRow- and column-level security per user, enforced on the server
Revoking accessRotate the database passwordSwitch off a project or the MCP connection, effective immediately
Every answerRows back from a queryThe SQL that ran, results, a chart spec and a summary

The same context layer also serves Wren AI's own GenBI agent, Slack and embedded analytics, so a definition changed once is used everywhere.

How it works

From exposed project to governed answer.

An admin decides what agents can reach. Everyone else signs in with their own account.

  1. 1. Expose

    Choose what agents can reach

    In Settings, an admin turns on MCP for the organization and marks which projects are exposed. Projects stay private until you expose them, and switching one off cuts access immediately.

    cloud.getwren.ai/settings/mcp

    MCP

    Choose which projects AI agents can reach.

    Enable MCP for this organization

    Turning this off cuts every connection immediately.

    ProjectExposed
    sales-analyticsSnowflake, 42 models
    finance-coreBigQuery, 18 models
    hr-privatePostgres, 9 models

    Users only reach exposed projects they are members of.

  2. 2. Connect

    Add one endpoint to your client

    Add the endpoint as a custom connector in Claude or ChatGPT, or with one command in Claude Code. Each person signs in with OAuth, so no key or database password is stored in the client.

    Add custom connector

    Name

    WrenAI

    Remote MCP server URL

    https://cloud.getwren.ai/api/mcp

    You will sign in with your Wren AI account. No API key or database password is stored.

    CancelAdd
    Signed in with OAuth, 2 exposed projects available
  3. 3. Call

    Let the agent ask

    The agent calls ask for a full answer, or composes generate_sql, run_sql and generate_chart itself. Wren AI resolves the context layer, applies the user's access rules and returns the SQL with every result.

    ClaudeWrenAI

    Which regions missed target in Q3?

    wrenai: list_projects, ask

    Two regions missed target: APAC closed at 91% and LATAM at 96%. North America and EMEA beat it.

    SELECT region, SUM(net_revenue) / SUM(target) AS attainment
    FROM sales_performance
    WHERE fiscal_quarter = '2026-Q3'
    GROUP BY region
    project: sales-analyticsmetric: net_revenuerow policy applied

    And bookings?

    wrenai: ask

    Wren AI needs one detail before it answers: gross or net bookings? Your choice goes back through respond_clarification.

    Gross bookingsNet bookings

One context layer

Build your own agent on the definitions everyone else uses.

The MCP server is the same context layer behind every surface Wren AI answers in. An agent you build gets the same numbers your team sees in ChatGPT, Claude and Slack.

Running the open-source Wren Engine? It includes its own MCP server you can self-host.

FAQ

The Wren AI MCP server, answered.

It is a remote MCP endpoint, https://cloud.getwren.ai/api/mcp, that lets an AI agent hand data questions to Wren AI. The agent calls tools like ask or generate_sql, and Wren AI answers from live data through your context layer, so every caller works from the same business definitions.

Setup is documented for Claude (web and desktop), ChatGPT and Claude Code. The server speaks the open Model Context Protocol over HTTP with OAuth, so your own agents and other MCP clients that support remote servers can use the same endpoint. See the MCP setup guide.

Each person signs in with their own Wren AI account over OAuth. There is no API key to paste into a config file, and database credentials never leave Wren AI. Each connection is bound to one organization, and an admin can switch off a project or the whole MCP connection at any time, which cuts access immediately.

Row- and column-level security is enforced on the server for the user who signed in, and the client cannot override it. Agents only reach projects an admin has exposed to MCP and the user is a member of. Because permissions follow the account, each person should connect with their own account rather than a shared one.

A database MCP server gives an agent a connection and a schema, so the model guesses what columns mean and how tables join on every question. Wren AI gives the agent your context layer instead: metrics, relationships and business rules defined once in MDL and versioned in git. One endpoint covers 20+ data sources, and every answer comes back with the SQL that ran.

Use ask to delegate the whole question: Wren AI plans the query, runs it and answers, and may ask a clarifying question you reply to with respond_clarification. Use generate_sql, run_sql and generate_chart when your agent wants to control each step. Both paths resolve through the same context layer.

The hosted MCP server is available on the Enterprise Cloud plan and above. If you run the open-source Wren Engine, it ships its own MCP server you can host yourself; see the Wren Engine quickstart.

Try it

Give your agents your business definitions.

Expose a project, add one endpoint, and let your agents ask. Or see it on your own data with our team.