Connect to the data.world MCP server
All clients connect to the same hosted endpoint over HTTPS: https://api.data.world/mcp
The server is fully hosted by data.world and you do not install or self-host any component. Authentication uses your existing data.world account and completes in your browser.
Authorization methods
There are generally three ways to obtain a token to authorize against the MCP server:
OAuth (recommended): Authenticate directly through your browser with your data.world account.
Public API token: Use a token from your data.world Settings page.
Service account token: Use a token issued for service account authentication.
The data.world MCP server complies with authorization behaviors detailed in the MCP specification.
How MCP permissions work
MCP permissions operate in two layers to ensure security and compliance with your organization's access controls:
Layer 1 - MCP server permissions: When you authorize the MCP server, you grant it specific capabilities (such as "can edit"). This defines the scope of operations the token can request.
Layer 2 - App-level authorization: Even with an edit permission token, the MCP server respects all your app-level access controls (like collection-level permissions, role-based restrictions, and data governance rules). If you don't have access to a specific collection or resource in data.world, the MCP server cannot access it either.
Both layers must pass for any action to succeed. The MCP server is fully constrained by your authenticated user's permissions—it cannot perform actions beyond what you're authorized to do in data.world.
Session and authorization validity
When using OAuth authentication, your authorization stays valid for 30 days, after which you sign in again. Within that window, individual sessions time out after 30 minutes of inactivity and after 12 hours maximum. No action is required when a session times out; the next request re-establishes one until your 30-day authorization expires.
Setting up the MCP server
To add the MCP server to your AI client:
In your AI client, find the option to add a custom connector.
In the connection details, provide the data.world MCP endpoint: https://api.data.world/mcp
Your AI client should redirect you to data.world to begin authorization.
Review the consent screen. It names the specific AI tool requesting access; it is not a blanket approval.
Approve the request. data.world returns control to your AI client.
Your client receives a scoped token for MCP operations and begins working with your catalog on your behalf.