TDB Enterprise¶
The Data-Bridge is a self-hosted, auditable API layer that turns your databases into secure REST and MCP endpoints — governed, queryable, and AI-ready.
Register a data source once. Query it from REST, SQL, or any MCP-compatible AI tool. Every query is logged.
Install it First query in 5 minutes Why TDB
Evaluating rather than deploying?
The free community edition runs one CSV source in a single Docker command, with the same read-only enforcement and the same audit log. It is the fastest way to answer "does this work for us?" — start at Community Edition, or compare the two at Editions.
Your data is already scattered across PostgreSQL, MySQL, SQL Server, Snowflake, and CSV files — and every team now wants AI agents to query it. TDB makes that existing, multi-source data safely accessible on your own infrastructure, without moving it into a single cloud warehouse or routing it through a SaaS copilot, and with a tamper-evident audit log you own.
Features¶
-
Connectors
PostgreSQL, MySQL, SQL Server and Snowflake. Database-wide or single-table registration per source, and multiple simultaneous registered sources.
-
Auth & API
Static API keys plus DB-managed keys (create / rotate / revoke), role-based access control (read / readwrite / admin), JWT, OAuth 2.1 with PKCE on MCP, per-API-key rate limiting and CORS configuration.
-
Query & MCP
A REST query endpoint (SELECT only) and seven MCP tools —
query_source,schema_source,preview_source,filter_source,aggregate_source,list_views,run_view. YAML-defined named views with typed parameters, prompt-injection filtering on input and output, per-key tool allow-lists, and auto schema detection. -
Audit & compliance
An NDJSON audit log on every query, signed and hash-chained so tampering is detectable, with integrity verification via
GET /v1/audit/verifyand incremental export to Splunk HEC or S3. -
Observability
Prometheus metrics at
GET /metrics, schema caching with a configurable TTL, and a health check atGET /health. -
Read-only, enforced
TDB never modifies your data. Every connector enforces read-only at the connection or session level — not merely by validating the SQL — and refusals are written to the audit log too.
How it works¶
Postgres · MySQL · SQL Server · Snowflake
│
│ read-only connection (per connector)
▼
┌────────────────────────────────────────────┐
│ TDB Enterprise │
│ │
│ POST /v1/sources ← register source │
│ POST /v1/query ← SQL SELECT │
│ POST /v1/mcp ← MCP tool calls │
│ GET /v1/views ← YAML-defined views │
│ GET /metrics ← Prometheus │
│ │
│ Every query → hash-chained audit log │
│ RBAC enforced per key (read/readwrite/ │
│ admin); tool allow-lists per MCP key │
└────────────────────────────────────────────┘
│
│ Authorization: Bearer <token>
▼
Your app / Claude Desktop / Cursor
Quick links¶
-
Get running
Installation
Quickstart — first query in 5 minutes
Community edition (free, CSV)
Connect an IDE or AI tool -
Connect a source
-
Govern it
Authentication overview
Role-based access control
Audit log & tamper verification
Credentials at rest -
Operate it
YAML named views
Prometheus metrics
Splunk HEC integration
All environment variables
Interactive API docs¶
When TDB is running, the full OpenAPI reference is available at:
- Swagger UI —
http://localhost:8000/docs - ReDoc —
http://localhost:8000/redoc - OpenAPI JSON —
http://localhost:8000/openapi.json