{"_id":"@databasin/mcp-client","_rev":"3-f76aeffb99f5496909f241045aaabab2","name":"@databasin/mcp-client","dist-tags":{"latest":"0.2.0","next":"0.2.0-beta.1"},"versions":{"0.1.0":{"name":"@databasin/mcp-client","version":"0.1.0","keywords":["databasin","mcp","model-context-protocol","stdio"],"license":"UNLICENSED","_id":"@databasin/mcp-client@0.1.0","maintainers":[{"name":"itlackey","email":"itlackey@outlook.com"}],"homepage":"https://databasin.cloud","bugs":{"url":"https://github.com/Databasin-AI/mcp-client/issues"},"bin":{"databasin-mcp":"dist/cli.js"},"dist":{"shasum":"15549c00d7ee7dfa3588a6115d2b3cd406648e5a","tarball":"https://registry.npmjs.org/@databasin/mcp-client/-/mcp-client-0.1.0.tgz","fileCount":54,"integrity":"sha512-GarjzUmJV0BrhwPOk8LdQ7rhOHq291VJ0YFz/op+QlwNOdbLT6zWrmkSc9RiZ9vHPvnW1IwNgD4J7UF68YBTcw==","signatures":[{"sig":"MEUCIQDCb9CgvDTIqP9ryDbDad5BveWsNQedG3C/GDOdqmg6MAIgV9nvRGpnMa0YhiUZF9GlIlsTDvT324sUfOgGhT0dSII=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":127882},"type":"module","engines":{"node":">=22.14.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"1769e5fa959c90063d83e2317f8d852f0971abf1","scripts":{"test":"vitest run","build":"npm run clean && tsc -p tsconfig.json","clean":"node scripts/clean.mjs","verify":"npm run typecheck && npm run build && npm run test","prepack":"npm run verify","typecheck":"tsc -p tsconfig.json --noEmit","test:stdio":"npm run build && vitest run tests/stdio.e2e.test.ts"},"_npmUser":{"name":"itlackey","email":"itlackey@outlook.com"},"repository":{"url":"git+https://github.com/Databasin-AI/mcp-client.git","type":"git"},"_npmVersion":"11.16.0","description":"Local stdio MCP server for DataBasin with Microsoft Entra sign-in.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"4.2.0","@azure/msal-node":"5.5.0","@azure/msal-node-extensions":"5.3.5","@modelcontextprotocol/server":"2.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"4.1.10","typescript":"5.9.3","@types/node":"22.19.7","@modelcontextprotocol/client":"2.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-client_0.1.0_1786773393948_0.912526847794477","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-beta.1":{"name":"@databasin/mcp-client","version":"0.2.0-beta.1","keywords":["databasin","mcp","model-context-protocol","stdio"],"license":"UNLICENSED","_id":"@databasin/mcp-client@0.2.0-beta.1","maintainers":[{"name":"itlackey","email":"itlackey@outlook.com"}],"homepage":"https://databasin.cloud","bugs":{"url":"https://github.com/Databasin-AI/mcp-client/issues"},"bin":{"databasin-mcp":"dist/cli.js"},"dist":{"shasum":"3767ef8d6d24f24439940bcb28407f349c4babc9","tarball":"https://registry.npmjs.org/@databasin/mcp-client/-/mcp-client-0.2.0-beta.1.tgz","fileCount":86,"integrity":"sha512-T3ugTDhL1T8Ze8hwTAEFM0KvwPakP48/FpfSX/oRsssrvBSAFjo8TJ4uXCa5Ce/qjEt+N7e49IwhKPwK8PERHQ==","signatures":[{"sig":"MEUCIBolCsALnPLSv3c1OLRmEn3Jtsvr7NvEubHb5eFuijb/AiEAoDmWTZyK7a6qB6arJVC9lBawgE3EZrFpKJq4dafm7to=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":265362},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":"^22.20.0 || ^24.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"ec9dd14a781b9ebdc0d7d440dcc234da54efdaaf","scripts":{"test":"vitest run --exclude tests/stdio.e2e.test.ts","build":"npm run clean && tsc -p tsconfig.json","clean":"node scripts/clean.mjs","verify":"npm run typecheck && npm test && npm run test:stdio","prepack":"npm run build","typecheck":"tsc -p tsconfig.json --noEmit","qualify:np":"node scripts/qualify-packed-np.mjs","test:stdio":"npm run build && vitest run tests/stdio.e2e.test.ts","verify:package":"node scripts/verify-package.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:32d187dc-98ce-4a00-a7a0-cb268f72aee5"}},"repository":{"url":"git+https://github.com/Databasin-AI/mcp-client.git","type":"git"},"_npmVersion":"12.0.2","description":"Local stdio MCP server for DataBasin with Microsoft Entra sign-in.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"zod":"4.2.0","@azure/msal-node":"5.5.0","@azure/msal-node-extensions":"5.3.5","@modelcontextprotocol/server":"2.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"vitest":"4.1.10","typescript":"5.9.3","@types/node":"24.13.3","@modelcontextprotocol/client":"2.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-client_0.2.0-beta.1_1787946557251_0.8239036527785013","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"_id":"@databasin/mcp-client@0.2.0","bin":{"databasin-mcp":"dist/cli.js"},"bugs":{"url":"https://github.com/Databasin-AI/mcp-client/issues"},"dist":{"shasum":"7f4fdc24b43c6616cc4a739faa4486934cd1aa71","tarball":"https://registry.npmjs.org/@databasin/mcp-client/-/mcp-client-0.2.0.tgz","fileCount":74,"integrity":"sha512-doMIoXbLwSgVvEv/BgVLdXrX00MrBhMVo5p5+P6pnbEwF03cl28fddnFo2OBZp1fPPoFeyKvKSYrfwcN291n0A==","signatures":[{"sig":"MEUCIQDieWbTSVamjLz1P1Wp8WfIXm4yj9zVKR3x7L3o8iQw4QIgUTrEjM9RkXsbC1KApwhSHV6RBav95CjufCtFXkQEW6I=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQC34hw/aOEwsctvTLcXVMGZOYJ3Eo4CnJeq1lFFKyHrLwIhAJ4DSIQf79tRYGxqhAlcDUQw7w8HgIWVFzNmmYu6IsqO"}],"unpackedSize":144852},"main":"./dist/index.js","name":"@databasin/mcp-client","type":"module","types":"./dist/index.d.ts","engines":{"node":"^22.20.0 || ^24.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"f3315532408c5932afacffdd9930e0928178341f","license":"UNLICENSED","scripts":{"test":"vitest run --exclude tests/stdio.e2e.test.ts","build":"npm run clean && tsc -p tsconfig.json","clean":"node scripts/clean.mjs","verify":"npm run typecheck && npm test && npm run test:stdio","prepack":"npm run build","typecheck":"tsc -p tsconfig.json --noEmit","qualify:np":"node scripts/qualify-packed-np.mjs","test:stdio":"npm run build && vitest run tests/stdio.e2e.test.ts","verify:package":"node scripts/verify-package.mjs","qualify:package":"node scripts/qualify-packed.mjs"},"version":"0.2.0","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:32d187dc-98ce-4a00-a7a0-cb268f72aee5"}},"homepage":"https://databasin.cloud","keywords":["databasin","mcp","model-context-protocol","stdio"],"repository":{"url":"git+https://github.com/Databasin-AI/mcp-client.git","type":"git"},"_npmVersion":"12.1.0","description":"Local stdio MCP server for DataBasin with Microsoft Entra sign-in.","directories":{},"maintainers":[{"name":"itlackey","email":"itlackey@outlook.com"}],"_nodeVersion":"24.21.0","dependencies":{"zod":"4.2.0","@azure/msal-node":"5.5.0","@azure/msal-node-extensions":"5.3.5","@modelcontextprotocol/client":"2.0.0","@modelcontextprotocol/server":"2.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"4.1.10","typescript":"5.9.3","@types/node":"24.13.3"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-client_0.2.0_1790314163539_0.33948354688825155"}}},"time":{"created":"2026-08-15T05:56:33.750Z","modified":"2026-09-25T05:29:23.820Z","0.1.0":"2026-08-15T05:56:34.118Z","0.2.0-beta.1":"2026-08-28T19:49:17.430Z","0.2.0":"2026-09-25T05:29:23.632Z"},"bugs":{"url":"https://github.com/Databasin-AI/mcp-client/issues"},"license":"UNLICENSED","homepage":"https://databasin.cloud","keywords":["databasin","mcp","model-context-protocol","stdio"],"repository":{"url":"git+https://github.com/Databasin-AI/mcp-client.git","type":"git"},"description":"Local stdio MCP server for DataBasin with Microsoft Entra sign-in.","maintainers":[{"name":"itlackey","email":"itlackey@outlook.com"}],"readme":"# DataBasin MCP Client\n\nLocal stdio MCP proxy for DataBasin. It keeps Microsoft Entra credentials in the OS-protected MSAL cache and connects to DataBasin's true Streamable HTTP MCP endpoint with the official MCP SDK.\n\nProduction is the default. The non-production profile is selected with `--environment np`.\n\n## Version 0.2.0 production release\n\nVersion `0.2.0` replaces the legacy REST adapter with a true MCP proxy for the deployed production server, including support tickets and notifications. Upgrade clients pinned to `0.1.0` or `0.2.0-beta.1`; those versions do not implement this transport. Production is the default:\n\n```bash\nnpx -y @databasin/mcp-client@0.2.0 doctor\nnpx -y @databasin/mcp-client@0.2.0 login\n```\n\nThe client requires Node.js 22.20+ or Node.js 24 and an available OS-protected credential store. `doctor` reports the selected fixed profile, runtime support, credential-store availability, and sign-in state; it never prints account identity, tokens, or credentials.\n\nFor non-production, use the same stable package with the NP profile:\n\n| Host | NP setup |\n| --- | --- |\n| Codex | `codex mcp add databasin-np -- npx -y @databasin/mcp-client@0.2.0 --environment np` |\n| Claude Code | `claude mcp add --transport stdio --scope user databasin-np -- npx -y @databasin/mcp-client@0.2.0 --environment np` |\n| Claude Desktop / Cursor-compatible config | Use the `mcpServers` JSON below |\n| VS Code | Use the `servers` JSON below in user or workspace `mcp.json` |\n| OpenCode v2 | Use the `mcp.servers` JSON below in `opencode.jsonc` |\n\nClaude Desktop and other hosts that accept the common `mcpServers` shape:\n\n```json\n{\n  \"mcpServers\": {\n    \"databasin-np\": {\n      \"type\": \"stdio\",\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@databasin/mcp-client@0.2.0\", \"--environment\", \"np\"]\n    }\n  }\n}\n```\n\nVS Code `mcp.json`:\n\n```json\n{\n  \"servers\": {\n    \"databasinNp\": {\n      \"type\": \"stdio\",\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@databasin/mcp-client@0.2.0\", \"--environment\", \"np\"]\n    }\n  }\n}\n```\n\nOpenCode v2 `opencode.jsonc`:\n\n```jsonc\n{\n  \"$schema\": \"https://opencode.ai/config.json\",\n  \"mcp\": {\n    \"servers\": {\n      \"databasin-np\": {\n        \"type\": \"local\",\n        \"command\": [\"npx\", \"-y\", \"@databasin/mcp-client@0.2.0\", \"--environment\", \"np\"]\n      }\n    }\n  }\n}\n```\n\nOn native Windows, a host that cannot launch `npx` directly should use `cmd` with arguments beginning `[/c, npx, ...]` (JSON string form: `[\"/c\", \"npx\", ...]`). Restart the host after changing its MCP configuration so it refreshes the server-owned tool inventory.\n\nThe only remote MCP endpoints are:\n\n- Production: `https://databasin.cloud/mcp`\n- NP: `https://databasin-ui-np.grayriver-813df174.centralus.azurecontainerapps.io/mcp`\n\nThe downstream connection pins MCP `2026-07-28` and has no REST or legacy-protocol fallback. Tool discovery and listing are public protocol operations. The client obtains a local access token only for `tools/call`, adds it as a bearer credential to that request, and rejects HTTP redirects so credentials cannot cross origins.\n\n## Install and connect\n\n```bash\nnpx -y @databasin/mcp-client\n```\n\nThe client requires an OS credential store. On Linux, an available and unlocked\nSecret Service/libsecret keyring is required; headless environments must provide\none explicitly. The client fails closed rather than falling back to a plaintext\ntoken cache.\n\nCodex:\n\n```bash\ncodex mcp add databasin -- npx -y @databasin/mcp-client\n```\n\nClaude Code:\n\n```bash\nclaude mcp add --transport stdio --scope user databasin -- npx -y @databasin/mcp-client\n```\n\nTo use non-production:\n\n```bash\nnpx -y @databasin/mcp-client --environment np\n```\n\nThe assistant can call `databasin_login` and give you the short-lived Microsoft device URL and code. Enter credentials only on Microsoft’s page. The client never sends credentials or tokens through MCP tool output.\n\nDevice login output is restricted to the HTTPS `microsoft.com/devicelogin` endpoint (with an optional trailing slash, canonicalized away). Interactive CLI login is restricted to the configured tenant’s exact `login.microsoftonline.com/<tenant>/oauth2/v2.0/authorize` path and client ID. Credential-bearing URLs, redirects to other hosts, other schemes, ports, fragments, and unexpected paths fail closed before a URL is opened or returned. Raw MSAL device codes, polling intervals/handles, and provider messages are discarded immediately; only the validated verification URL, human-entered user code, and expiry are retained.\n\nBefore using an MSAL access token, the client fail-closes on its tenant, issuer, audience, delegated scope, timing, authority, account, and expiry metadata. JWT payload decoding here is local defense-in-depth, not signature verification; the DataBasin API remains the cryptographic validation and authorization boundary.\n\n## Tools\n\nThe production server currently exposes twenty product tools, plus this client's two local authentication helpers (twenty-two total). Product tools are discovered dynamically from the remote DataBasin MCP server and mirrored over local stdio. Their names, descriptions, annotations, input/output schemas, and timeout metadata are server-owned; this package does not keep a second product-tool contract. The current server catalog is:\n\n- `databasin_get_capabilities` — fetch the server-owned capability allowlist.\n- `databasin_get_context` — fetch authorized project and connector metadata.\n- `databasin_search` — bounded authorized metadata search.\n- `databasin_get_schema` — bounded non-secret schema metadata.\n- `databasin_run_agent` — run the fixed `metadata_readonly` profile for an explicit institution and optional project/connector scope.\n- `databasin_get_agent_run` — read an authorized run status/result.\n- `databasin_cancel_agent_run` — request cancellation and report the server’s truthful state.\n- `databasin_run_query` — execute a single read-only `SELECT`/`WITH` statement against an authorized connector and return up to `maxRows` rows.\n- `databasin_get_query_status` — read an authorized query's status, and its columns/rows/error once terminal.\n- `databasin_cancel_query` — request cancellation and report the server’s truthful state.\n- `databasin_run_assistant` — run the read-only DataBasin assistant (a server-side Claude Code agent) that browses metadata and runs DataBasin skills over multiple steps to answer a natural-language request.\n\nSupport tools are also discovered: `databasin_get_support_context`, `databasin_list_support_tickets`, `databasin_get_support_ticket`, `databasin_create_support_ticket`, `databasin_add_support_ticket_message`, `databasin_update_support_ticket`, `databasin_list_support_notifications`, `databasin_mark_support_notification_read`, and `databasin_mark_all_support_notifications_read`. Support operations include writes; follow their server-owned schemas and annotations. Ticket/message data includes authorized email fields, and optional values may be null.\n\nThe other two tools, `databasin_auth_status` and `databasin_login`, are client-local authentication helpers. They interact only with the local MSAL credential manager and Microsoft sign-in; they are not part of the remote product catalog.\n\nNo organization configuration is required. Unscoped `databasin_get_context` and `databasin_search` discover metadata only across organizations the signed-in user is authorized to access. A project-scoped search must include its `institutionId`; account discovery is not a wildcard and never broadens server-side authorization.\n\nThe client does not expose arbitrary SQL, shell commands, connector credentials, arbitrary URLs, or arbitrary headers. The remote server validates product inputs, authorization, output safety, query policy, and response bounds. `databasin_run_query` accepts only a single read-only `SELECT`/`WITH` statement under that server-owned contract. Every product success is the MCP result returned by the server, including its structured `{ \"data\": T, \"correlationId\": \"...\" }` payload.\n\n`databasin_run_agent` accepts the scope and execution fields advertised in its discovered schema and always uses the server-owned `metadata_readonly` profile. The remote MCP tool owns run creation, bounded polling, cancellation on MCP abort, authorization rechecks, and any idempotency behavior; the local proxy performs one `tools/call` and forwards its cancellation signal.\n\nAgent status, result, and cancellation responses include the complete server-authorized scope. A canonical run contains `runId`, the three scope IDs (nullable where optional), `profile`, `status`, bounded `result`/`error`, and `createdAt`/`updatedAt`. Cancellation reports the state returned by the server and does not imply completion before the server says `cancelled`.\n\n`databasin_run_query` accepts the bounded connector, SQL, and row-limit fields in the discovered schema. The remote MCP tool owns its bounded polling and timeout behavior. Status and cancellation remain explicit tools for follow-up. A canonical query result contains `queryId`, `connectorId`, `status`, bounded `columns`/`data`/`rowCount`, `truncated`, and `error`.\n\n`databasin_run_assistant` remains the server's bounded, read-only assistant operation. It is metadata-and-skills only; use `databasin_run_query` for SQL. The server advertises the accepted input and output schemas plus the call timeout in MCP metadata, and the client mirrors them without local copies. This transport change does not replace or modify the server's existing Claude Agent SDK runtime.\n\n## CLI fallback\n\n```bash\nnpx -y @databasin/mcp-client login\nnpx -y @databasin/mcp-client status\nnpx -y @databasin/mcp-client logout\nnpx -y @databasin/mcp-client login --environment np\nnpx -y @databasin/mcp-client doctor --environment np\n```\n\nEnvironment aliases `production` and `staging`/`test` are accepted for `prod` and `np` respectively.\n\n## Development\n\n```bash\nnpm ci\nnpm run verify\nnpm audit --omit=dev --audit-level=high\nnpm run verify:package\n```\n\n`npm run verify` runs the TypeScript check, unit tests, build, and stdio child-process E2E. CI runs those checks on Node 22 and 24 across Linux, macOS, and Windows, audits production dependencies, and verifies the exact package allowlist with `npm pack --dry-run --json`.\n\nRelease qualification uses an exact local tarball, never a mutable dist-tag. After `npm pack`, an authorized tester with an existing production session can run the read-only qualification:\n\n```bash\nDATABASIN_MCP_TARBALL=./databasin-mcp-client-0.2.0.tgz npm run qualify:package\n```\n\nSet `DATABASIN_MCP_QUALIFY_ENVIRONMENT=np` to qualify against NP instead. This check installs the exact artifact in a temporary directory, starts its stdio executable, checks local sign-in and the twenty-two-tool inventory, and calls only context/search/support read operations. It never creates agent jobs, executes SQL, or changes support data, and does not print credentials or business content. The old `qualify:np` script remains only for historical beta lifecycle qualification.\n\nRelease approval still requires proof of the Entra registration, tenant, issuer, audience, delegated scope, and wrong-claim rejection behavior for each environment.\n","readmeFilename":"README.md"}