Skip to content

TDB Enterprise

The Data-Bridge is a self-hosted, auditable API layer that turns your databases into secure REST and MCP endpoints — governed, queryable, and AI-ready.

Register a data source once. Query it from REST, SQL, or any MCP-compatible AI tool. Every query is logged.

Install it First query in 5 minutes Why TDB

Evaluating rather than deploying?

The free community edition runs one CSV source in a single Docker command, with the same read-only enforcement and the same audit log. It is the fastest way to answer "does this work for us?" — start at Community Edition, or compare the two at Editions.

Your data is already scattered across PostgreSQL, MySQL, SQL Server, Snowflake, and CSV files — and every team now wants AI agents to query it. TDB makes that existing, multi-source data safely accessible on your own infrastructure, without moving it into a single cloud warehouse or routing it through a SaaS copilot, and with a tamper-evident audit log you own.


Features

  • Connectors


    PostgreSQL, MySQL, SQL Server and Snowflake. Database-wide or single-table registration per source, and multiple simultaneous registered sources.

    All connectors

  • Auth & API


    Static API keys plus DB-managed keys (create / rotate / revoke), role-based access control (read / readwrite / admin), JWT, OAuth 2.1 with PKCE on MCP, per-API-key rate limiting and CORS configuration.

    Authentication

  • Query & MCP


    A REST query endpoint (SELECT only) and seven MCP tools — query_source, schema_source, preview_source, filter_source, aggregate_source, list_views, run_view. YAML-defined named views with typed parameters, prompt-injection filtering on input and output, per-key tool allow-lists, and auto schema detection.

    Query API

  • Audit & compliance


    An NDJSON audit log on every query, signed and hash-chained so tampering is detectable, with integrity verification via GET /v1/audit/verify and incremental export to Splunk HEC or S3.

    Audit log

  • Observability


    Prometheus metrics at GET /metrics, schema caching with a configurable TTL, and a health check at GET /health.

    Metrics

  • Read-only, enforced


    TDB never modifies your data. Every connector enforces read-only at the connection or session level — not merely by validating the SQL — and refusals are written to the audit log too.

    RBAC


How it works

Postgres · MySQL · SQL Server · Snowflake
      │
      │  read-only connection (per connector)
      ▼
 ┌────────────────────────────────────────────┐
 │              TDB Enterprise                │
 │                                            │
 │  POST /v1/sources     ← register source    │
 │  POST /v1/query       ← SQL SELECT         │
 │  POST /v1/mcp         ← MCP tool calls     │
 │  GET  /v1/views       ← YAML-defined views │
 │  GET  /metrics        ← Prometheus         │
 │                                            │
 │  Every query → hash-chained audit log      │
 │  RBAC enforced per key (read/readwrite/    │
 │  admin); tool allow-lists per MCP key      │
 └────────────────────────────────────────────┘
      │
      │  Authorization: Bearer <token>
      ▼
 Your app / Claude Desktop / Cursor


Interactive API docs

When TDB is running, the full OpenAPI reference is available at:

  • Swagger UI — http://localhost:8000/docs
  • ReDoc — http://localhost:8000/redoc
  • OpenAPI JSON — http://localhost:8000/openapi.json