---
bezeichner: "io.github.AindriuB/data-prism"
art: "mcp_server"
slug: "io-github-aindriub-data-prism"
paketkoordinate: "oci:ghcr.io/aindriub/data-prism-server:0.6.0"
status: "aktiv"
homepage: "https://aindriub.github.io/data-prism/"
erhebungsstand: "2026-10-10T01:17:01.464Z"
namensraum: "io.github.AindriuB"
registerseite: "https://tracevero.de/mcp/io-github-aindriub-data-prism"
abgerufen_am: "2026-10-10"
zugangsdaten_erforderlich: false
ausfuehrungsort: "entfernt"
dateisystem_pfadargument: false
quelloffen_einsehbar: true
roh_beschreibung: "Fail-closed privacy layer that pseudonymises enterprise API data for LLM agents and MCP clients."
version: "0.6.0"
roh_umgebungsvariablen: "LOADER_PATH, DATAPRISM_SECURITY_JWT_ISSUER, DATAPRISM_SECURITY_JWT_AUDIENCE, DATAPRISM_SECURITY_JWT_JWK_SET_URI, DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI, DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL, DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES, DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION, DATAPRISM_SECURITY_POLICY_PURPOSES, DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR, DATAPRISM_PRIVACY_PROFILE, DATAPRISM_PRIVACY_SCOPE_LIFETIME, DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID, DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE, DATAPRISM_AUDIT_SINK, DATAPRISM_AUDIT_WRITER_ID, DATAPRISM_AUDIT_FILE_PATH, DATAPRISM_METRICS_SINK, DATAPRISM_HAZELCAST_TOPOLOGY, DATAPRISM_HAZELCAST_CLUSTERNAME, DATAPRISM_HAZELCAST_JOIN_MODE, DATAPRISM_HAZELCAST_JOIN_MEMBERS, DATAPRISM_HAZELCAST_MEMBER_PORT, DATAPRISM_OPERATOR_ENABLED, DATAPRISM_OPERATOR_PORT, DATAPRISM_OPERATOR_REQUIREDAUDIENCE, DATAPRISM_OPERATOR_REQUIREDSCOPE, DATAPRISM_SOURCES_CUSTOMER_BASE_URL, DATAPRISM_SOURCES_CUSTOMER_TIMEOUT"
roh_geheime_pflichtvariablen: ""
roh_transportarten: "streamable-http"
roh_pfadargumente: ""
roh_repository_url: "https://github.com/AindriuB/data-prism"
roh_paketquellen: "oci"
roh_geheime_pflichtkopfzeilen: ""
roh_pfad_umgebungsvariablen: ""
roh_remote_adressen: ""
roh_remote_hosts: ""
roh_statusmeldung: ""
roh_veroeffentlicht_am: "2026-10-09"
roh_aktualisiert_am: "2026-10-09"
roh_schemafassung: "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json"
roh_bereitstellungsform: "paket"
roh_repository_quelle: "github"
roh_repository_unterordner: ""
roh_paketbezeichner: "ghcr.io/aindriub/data-prism-server:0.6.0"
roh_paketversionen: ""
roh_laufzeithinweise: "docker"
roh_umgebungsformate: ""
roh_umgebungsbeschreibungen: "DATAPRISM_AUDIT_FILE_PATH=Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise · DATAPRISM_AUDIT_SINK=Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op · DATAPRISM_AUDIT_WRITER_ID=Writer/instance identity recorded on every audit entry; required · DATAPRISM_HAZELCAST_CLUSTERNAME=Hazelcast cluster name; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded, never dev, refused if set with single-node · DATAPRISM_HAZELCAST_JOIN_MEMBERS=Comma-separated member addresses (host or host:port); required when DATAPRISM_HAZELCAST_JOIN_MODE=tcp-ip, otherwise unused · DATAPRISM_HAZELCAST_JOIN_MODE=How cluster members find each other: tcp-ip, kubernetes or none; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded (none is an explicit single member bound to 127.0.0.1), refused if set with single-node · DATAPRISM_HAZELCAST_MEMBER_PORT=Hazelcast member port, default 5701, never auto-incremented; must differ from the server, management and operator ports. Member traffic is unencrypted, so keep it on a private network. Optional · DATAPRISM_HAZELCAST_TOPOLOGY=Cluster read-budget topology: embedded (shared across members that have joined one cluster; set cluster name and join mode) or single-node (enforced per process); required, never defaulted · DATAPRISM_METRICS_SINK=Metrics sink binding, currently only micrometer; required in production, never the framework no-op · DATAPRISM_OPERATOR_ENABLED=Enables the operator surface; optional, off by default · DATAPRISM_OPERATOR_PORT=Port of the operator listener; required when DATAPRISM_OPERATOR_ENABLED=true, must differ from the server, management (OPERATOR_PORT_SHARED otherwise) and member ports, and has no fixed default (publish it explicitly) · DATAPRISM_OPERATOR_REQUIREDAUDIENCE=JWT audience an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true · DATAPRISM_OPERATOR_REQUIREDSCOPE=JWT scope an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true · DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE=Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value · DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID=Identifier of the pinned HMAC key used to derive synthetic identities; required · DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE=Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both · DATAPRISM_PRIVACY_PROFILE=Name of the reviewed privacy profile implementation to apply; required · DATAPRISM_PRIVACY_SCOPE_LIFETIME=Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required · DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR=Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 4.1.1), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required · DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION=JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims · DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL=JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims · DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES=JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims · DATAPRISM_SECURITY_JWT_AUDIENCE=Expected JWT audience claim for this deployment; required for every protected deployment · DATAPRISM_SECURITY_JWT_ISSUER=OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment · DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI=Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both · DATAPRISM_SECURITY_JWT_JWK_SET_URI=HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both · DATAPRISM_SECURITY_POLICY_PURPOSES=Comma-separated list of permitted purposes; at least one is required · DATAPRISM_SOURCES_CUSTOMER_BASE_URL=Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required · DATAPRISM_SOURCES_CUSTOMER_TIMEOUT=Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL · LOADER_PATH=Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above)"
roh_symbolformate: ""
roh_verbindungswege: "{\"packages\":[{\"registryType\":\"oci\",\"identifier\":\"ghcr.io/aindriub/data-prism-server:0.6.0\",\"runtimeHint\":\"docker\",\"transport\":\"streamable-http\",\"environment\":[{\"name\":\"LOADER_PATH\",\"description\":\"Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above)\",\"required\":true,\"secret\":false},{\"name\":\"DATAPRISM_SECURITY_JWT_ISSUER\",\"description\":\"OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment\",\"required\":true,\"secret\":false},{\"name\":\"DATAPRISM_SECURITY_JWT_AUDIENCE\",\"description\":\"Expected JWT audience claim for this deployment; required for every protected deployment\",\"required\":true,\"secret\":false},{\"name\":\"DATAPRISM_SECURITY_JWT_JWK_SET_URI\",\"description\":\"HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both\",\"required\":true,\"secret\":false},{\"name\":\"DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI\",\"description\":\"Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both\",\"required\":false,\"secret\":false},{\"name\":\"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL\",\"description\":\"JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims\",\"required\":true,\"secret\":false},{\"name\":\"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES\",\"description\":\"JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims\",\"required\":true,\"secret\":false},{\"name\":\"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION\",\"description\":\"JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims\",\"required\":true,\"secret\":false},{\"name\":\"DATAPRISM_SECURITY_POLICY_PURPOSES\",\"description\":\"Comma-separated list of permitted purposes; at least one is required\",\"required\":true,\"secret\":false},{\"name\":\"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR\",\"description\":\"Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 4.1.1), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required\",\"required\":true,\"secret\":false},{\"name\":\"DATAPRISM_PRIVACY_PROFILE\",\"description\":\"Name of the reviewed privacy profile implementation to apply; required\",\"required\":true,\"secret\":false},{\"name\":\"DATAPRISM_PRIVACY_SCOPE_LIFETIME\",\"description\":\"Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required\",\"required\":true,\"secret\":false},{\"name\":\"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID\",\"description\":\"Identifier of the pinned HMAC key used to derive synthetic identities; required\",\"required\":true,\"secret\":false},{\"name\":\"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE\",\"description\":\"Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value\",\"required\":true,\"secret\":false},{\"name\":\"DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE\",\"description\":\"Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both\",\"required\":false,\"secret\":false},{\"name\":\"DATAPRISM_AUDIT_SINK\",\"description\":\"Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op\",\"required\":true,\"secret\":false},{\"name\":\"DATAPRISM_AUDIT_WRITER_ID\",\"description\":\"Writer/instance identity recorded on every audit entry; required\",\"required\":true,\"secret\":false},{\"name\":\"DATAPRISM_AUDIT_FILE_PATH\",\"description\":\"Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise\",\"required\":false,\"secret\":false},{\"name\":\"DATAPRISM_METRICS_SINK\",\"description\":\"Metrics sink binding, currently only micrometer; required in production, never the framework no-op\",\"required\":true,\"secret\":false},{\"name\":\"DATAPRISM_HAZELCAST_TOPOLOGY\",\"description\":\"Cluster read-budget topology: embedded (shared across members that have joined one cluster; set cluster name and join mode) or single-node (enforced per process); required, never defaulted\",\"required\":true,\"secret\":false},{\"name\":\"DATAPRISM_HAZELCAST_CLUSTERNAME\",\"description\":\"Hazelcast cluster name; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded, never dev, refused if set with single-node\",\"required\":false,\"secret\":false},{\"name\":\"DATAPRISM_HAZELCAST_JOIN_MODE\",\"description\":\"How cluster members find each other: tcp-ip, kubernetes or none; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded (none is an explicit single member bound to 127.0.0.1), refused if set with single-node\",\"required\":false,\"secret\":false},{\"name\":\"DATAPRISM_HAZELCAST_JOIN_MEMBERS\",\"description\":\"Comma-separated member addresses (host or host:port); required when DATAPRISM_HAZELCAST_JOIN_MODE=tcp-ip, otherwise unused\",\"required\":false,\"secret\":false},{\"name\":\"DATAPRISM_HAZELCAST_MEMBER_PORT\",\"description\":\"Hazelcast member port, default 5701, never auto-incremented; must differ from the server, management and operator ports. Member traffic is unencrypted, so keep it on a private network. Optional\",\"required\":false,\"secret\":false},{\"name\":\"DATAPRISM_OPERATOR_ENABLED\",\"description\":\"Enables the operator surface; optional, off by default\",\"required\":false,\"secret\":false},{\"name\":\"DATAPRISM_OPERATOR_PORT\",\"description\":\"Port of the operator listener; required when DATAPRISM_OPERATOR_ENABLED=true, must differ from the server, management (OPERATOR_PORT_SHARED otherwise) and member ports, and has no fixed default (publish it explicitly)\",\"required\":false,\"secret\":false},{\"name\":\"DATAPRISM_OPERATOR_REQUIREDAUDIENCE\",\"description\":\"JWT audience an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true\",\"required\":false,\"secret\":false},{\"name\":\"DATAPRISM_OPERATOR_REQUIREDSCOPE\",\"description\":\"JWT scope an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true\",\"required\":false,\"secret\":false},{\"name\":\"DATAPRISM_SOURCES_CUSTOMER_BASE_URL\",\"description\":\"Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required\",\"required\":true,\"secret\":false},{\"name\":\"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT\",\"description\":\"Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL\",\"required\":true,\"secret\":false}],\"additional_arguments_declared\":true}],\"remotes\":[]}"
---

# Data Prism

## Gemessene Werte

| Merkmal | Wert | Quelle | Erhoben am | Vertrauensgrad | Rohangabe |
| --- | --- | --- | --- | --- | --- |
| Pflicht-Geheimnisse deklariert | false | MCP-Register | 2026-09-18T01:17:01.510Z | abgeleitet | roh_geheime_pflichtvariablen: ; roh_geheime_pflichtkopfzeilen: |
| Ausführungsort | entfernt | MCP-Register | 2026-09-18T01:17:01.510Z | abgeleitet | roh_transportarten: streamable-http |
| Pfadargument vorhanden | false | MCP-Register | 2026-09-18T01:17:01.510Z | abgeleitet | roh_pfadargumente: ; roh_pfad_umgebungsvariablen: |
| Repository-Adresse geführt | true | MCP-Register | 2026-09-18T01:17:01.510Z | abgeleitet | roh_repository_url: https://github.com/AindriuB/data-prism |
| Beschreibung (Rohangabe) | Fail-closed privacy layer that pseudonymises enterprise API data for LLM agents and MCP clients. | MCP-Register | 2026-09-25T01:17:01.872Z | selbstauskunft |  |
| Deklarierte Version | 0.6.0 | MCP-Register | 2026-10-10T01:17:01.464Z | selbstauskunft |  |
| Umgebungsvariablen (Rohangabe) | LOADER_PATH, DATAPRISM_SECURITY_JWT_ISSUER, DATAPRISM_SECURITY_JWT_AUDIENCE, DATAPRISM_SECURITY_JWT_JWK_SET_URI, DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI, DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL, DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES, DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION, DATAPRISM_SECURITY_POLICY_PURPOSES, DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR, DATAPRISM_PRIVACY_PROFILE, DATAPRISM_PRIVACY_SCOPE_LIFETIME, DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID, DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE, DATAPRISM_AUDIT_SINK, DATAPRISM_AUDIT_WRITER_ID, DATAPRISM_AUDIT_FILE_PATH, DATAPRISM_METRICS_SINK, DATAPRISM_HAZELCAST_TOPOLOGY, DATAPRISM_HAZELCAST_CLUSTERNAME, DATAPRISM_HAZELCAST_JOIN_MODE, DATAPRISM_HAZELCAST_JOIN_MEMBERS, DATAPRISM_HAZELCAST_MEMBER_PORT, DATAPRISM_OPERATOR_ENABLED, DATAPRISM_OPERATOR_PORT, DATAPRISM_OPERATOR_REQUIREDAUDIENCE, DATAPRISM_OPERATOR_REQUIREDSCOPE, DATAPRISM_SOURCES_CUSTOMER_BASE_URL, DATAPRISM_SOURCES_CUSTOMER_TIMEOUT | MCP-Register | 2026-10-08T01:17:01.893Z | selbstauskunft |  |
| Geheime Pflichtvariablen (Rohangabe) |  | MCP-Register | 2026-09-18T01:17:01.510Z | selbstauskunft |  |
| Transportarten (Rohangabe) | streamable-http | MCP-Register | 2026-09-18T01:17:01.510Z | selbstauskunft |  |
| Pfadargumente (Rohangabe) |  | MCP-Register | 2026-09-18T01:17:01.510Z | selbstauskunft |  |
| Repository (Rohangabe) | https://github.com/AindriuB/data-prism | MCP-Register | 2026-09-18T01:17:01.510Z | selbstauskunft |  |
| Paketquellen (Rohangabe) | oci | MCP-Register | 2026-09-18T01:17:01.510Z | selbstauskunft |  |
| Geheime Pflichtkopfzeilen (Rohangabe) |  | MCP-Register | 2026-09-18T01:17:01.510Z | selbstauskunft |  |
| Pfad-Umgebungsvariablen (Rohangabe) |  | MCP-Register | 2026-09-18T01:17:01.510Z | selbstauskunft |  |
| Remote-Adressen (Rohangabe) |  | MCP-Register | 2026-09-18T01:17:01.510Z | selbstauskunft |  |
| Remote-Hosts (Rohangabe) |  | MCP-Register | 2026-09-18T01:17:01.510Z | selbstauskunft |  |
| Statusmeldung des Registers (Rohangabe) |  | MCP-Register | 2026-09-18T01:17:01.510Z | selbstauskunft |  |
| Im Register eingetragen am (Rohangabe) | 2026-10-09 | MCP-Register | 2026-10-10T01:17:01.464Z | selbstauskunft |  |
| Im Register geändert am (Rohangabe) | 2026-10-09 | MCP-Register | 2026-10-10T01:17:01.464Z | selbstauskunft |  |
| Schemafassung des Rohsatzes (Rohangabe) | https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json | MCP-Register | 2026-09-18T01:17:01.510Z | selbstauskunft |  |
| Bereitstellungsform (Rohangabe) | paket | MCP-Register | 2026-09-18T01:17:01.510Z | selbstauskunft |  |
| Repository-Plattform (Rohangabe) | github | MCP-Register | 2026-09-18T01:17:01.510Z | selbstauskunft |  |
| Repository-Unterordner (Rohangabe) |  | MCP-Register | 2026-09-18T01:17:01.510Z | selbstauskunft |  |
| Paketbezeichner (Rohangabe) | ghcr.io/aindriub/data-prism-server:0.6.0 | MCP-Register | 2026-10-10T01:17:01.464Z | selbstauskunft |  |
| Paketversionen (Rohangabe) |  | MCP-Register | 2026-09-18T01:17:01.510Z | selbstauskunft |  |
| Laufzeithinweise (Rohangabe) | docker | MCP-Register | 2026-09-18T01:17:01.510Z | selbstauskunft |  |
| Formate der Umgebungsvariablen (Rohangabe) |  | MCP-Register | 2026-09-18T01:17:01.510Z | selbstauskunft |  |
| Beschreibungen der Umgebungsvariablen (Rohangabe) | DATAPRISM_AUDIT_FILE_PATH=Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise · DATAPRISM_AUDIT_SINK=Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op · DATAPRISM_AUDIT_WRITER_ID=Writer/instance identity recorded on every audit entry; required · DATAPRISM_HAZELCAST_CLUSTERNAME=Hazelcast cluster name; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded, never dev, refused if set with single-node · DATAPRISM_HAZELCAST_JOIN_MEMBERS=Comma-separated member addresses (host or host:port); required when DATAPRISM_HAZELCAST_JOIN_MODE=tcp-ip, otherwise unused · DATAPRISM_HAZELCAST_JOIN_MODE=How cluster members find each other: tcp-ip, kubernetes or none; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded (none is an explicit single member bound to 127.0.0.1), refused if set with single-node · DATAPRISM_HAZELCAST_MEMBER_PORT=Hazelcast member port, default 5701, never auto-incremented; must differ from the server, management and operator ports. Member traffic is unencrypted, so keep it on a private network. Optional · DATAPRISM_HAZELCAST_TOPOLOGY=Cluster read-budget topology: embedded (shared across members that have joined one cluster; set cluster name and join mode) or single-node (enforced per process); required, never defaulted · DATAPRISM_METRICS_SINK=Metrics sink binding, currently only micrometer; required in production, never the framework no-op · DATAPRISM_OPERATOR_ENABLED=Enables the operator surface; optional, off by default · DATAPRISM_OPERATOR_PORT=Port of the operator listener; required when DATAPRISM_OPERATOR_ENABLED=true, must differ from the server, management (OPERATOR_PORT_SHARED otherwise) and member ports, and has no fixed default (publish it explicitly) · DATAPRISM_OPERATOR_REQUIREDAUDIENCE=JWT audience an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true · DATAPRISM_OPERATOR_REQUIREDSCOPE=JWT scope an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true · DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE=Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value · DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID=Identifier of the pinned HMAC key used to derive synthetic identities; required · DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE=Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both · DATAPRISM_PRIVACY_PROFILE=Name of the reviewed privacy profile implementation to apply; required · DATAPRISM_PRIVACY_SCOPE_LIFETIME=Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required · DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR=Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 4.1.1), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required · DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION=JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims · DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL=JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims · DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES=JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims · DATAPRISM_SECURITY_JWT_AUDIENCE=Expected JWT audience claim for this deployment; required for every protected deployment · DATAPRISM_SECURITY_JWT_ISSUER=OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment · DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI=Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both · DATAPRISM_SECURITY_JWT_JWK_SET_URI=HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both · DATAPRISM_SECURITY_POLICY_PURPOSES=Comma-separated list of permitted purposes; at least one is required · DATAPRISM_SOURCES_CUSTOMER_BASE_URL=Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required · DATAPRISM_SOURCES_CUSTOMER_TIMEOUT=Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL · LOADER_PATH=Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above) | MCP-Register | 2026-10-09T01:17:01.645Z | selbstauskunft |  |
| Symbolformate (Rohangabe) |  | MCP-Register | 2026-09-18T01:17:01.510Z | selbstauskunft |  |
| Verbindungswege (Quellstruktur) | {"packages":[{"registryType":"oci","identifier":"ghcr.io/aindriub/data-prism-server:0.6.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"LOADER_PATH","description":"Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above)","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER","description":"OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_AUDIENCE","description":"Expected JWT audience claim for this deployment; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_JWK_SET_URI","description":"HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI","description":"Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both","required":false,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL","description":"JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES","description":"JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION","description":"JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_POLICY_PURPOSES","description":"Comma-separated list of permitted purposes; at least one is required","required":true,"secret":false},{"name":"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR","description":"Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 4.1.1), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_PROFILE","description":"Name of the reviewed privacy profile implementation to apply; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_SCOPE_LIFETIME","description":"Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID","description":"Identifier of the pinned HMAC key used to derive synthetic identities; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE","description":"Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE","description":"Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both","required":false,"secret":false},{"name":"DATAPRISM_AUDIT_SINK","description":"Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_WRITER_ID","description":"Writer/instance identity recorded on every audit entry; required","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_FILE_PATH","description":"Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise","required":false,"secret":false},{"name":"DATAPRISM_METRICS_SINK","description":"Metrics sink binding, currently only micrometer; required in production, never the framework no-op","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_TOPOLOGY","description":"Cluster read-budget topology: embedded (shared across members that have joined one cluster; set cluster name and join mode) or single-node (enforced per process); required, never defaulted","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_CLUSTERNAME","description":"Hazelcast cluster name; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded, never dev, refused if set with single-node","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_JOIN_MODE","description":"How cluster members find each other: tcp-ip, kubernetes or none; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded (none is an explicit single member bound to 127.0.0.1), refused if set with single-node","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_JOIN_MEMBERS","description":"Comma-separated member addresses (host or host:port); required when DATAPRISM_HAZELCAST_JOIN_MODE=tcp-ip, otherwise unused","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_MEMBER_PORT","description":"Hazelcast member port, default 5701, never auto-incremented; must differ from the server, management and operator ports. Member traffic is unencrypted, so keep it on a private network. Optional","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_ENABLED","description":"Enables the operator surface; optional, off by default","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_PORT","description":"Port of the operator listener; required when DATAPRISM_OPERATOR_ENABLED=true, must differ from the server, management (OPERATOR_PORT_SHARED otherwise) and member ports, and has no fixed default (publish it explicitly)","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_REQUIREDAUDIENCE","description":"JWT audience an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_REQUIREDSCOPE","description":"JWT scope an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true","required":false,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_BASE_URL","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL","required":true,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} | MCP-Register | 2026-10-10T01:17:01.464Z | selbstauskunft |  |

## Verweise

- Namensraum: [[namensraum/io-github-aindriub|io.github.AindriuB]]

---

- Registerseite: <https://tracevero.de/mcp/io-github-aindriub-data-prism>
- Abgerufen am: 2026-10-10
