Aleph
Query live FP&A data, build reports and update dashboards from your AI assistant.
Query a governed semantic layer over Snowflake, BigQuery or Databricks in plain language, read-only SQL.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Jedify MCP server connects a governed semantic layer over your data warehouse to Claude, ChatGPT and any MCP-compatible agent. Jedify sits between an agent and Snowflake, BigQuery or Databricks, mapping business terms — revenue, churn, a metric definition — onto warehouse tables, so an agent asks in plain language rather than SQL. Sign-in is OAuth or an API key.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
?mode= or a proxy flag. A tool census of the listed endpoint does not describe an installation that connected with a different string.https://be.jedify.com/.well-known/oauth-protected-resource/mcp declares scopes_supported as anis_authless: true and auth_posture: "no_auth". The listed endpoint returned HTTP 401 with a WWW-Authenticate: Bearer challenge to an anonymous request on 2026-08-23. Jedify requires a login.ask_an_agent, list_agents and create_share_link appear in Anthropic's listing and in none of Jedify's three tool references. We cannot describe what ask_an_agent reaches, and it is dispatcher-shaped by name.tools/list response and cannot report readOnlyHint or destructiveHint for any tool. The read/write split above is our classification of names against Jedify's descriptions./mcp/message initializes without authentication. A single anonymous initialize returned HTTP 200 with the server's full instruction block on 2026-08-23, while the listed /mcp path returned 401. Only the handshake is open — we did not attempt any tool call, and tool access remains credentialed on Jedify's documented account.credit, balance, usage, quota or billing verb. Warehouse query cost is real — Jedify's own Athena page notes per-TB-scanned billing — and nothing in the surface reports it.Sixteen in Anthropic's listing, but 25 in Jedify's documentation. Jedify's MCP server runs three modes — Asker, Editor and Builder — and its docs state the mode changes which tools your client sees. The directory lists Asker only. Editor adds six semantic-layer editing tools and Builder adds six function-management tools, and a URL parameter selects the mode.
Not in the default Asker mode, and only as a proposal in Editor mode. Jedify documents that Editor mode never changes your semantic layer directly — sl_commit_edits stages a changeset as review-pending sessions and a human approves before anything applies. Asker mode's only write is create_share_link. No mode writes to your warehouse.
Yes, read-only SELECT statements. The run_sql_query tool is in Anthropic's listing and Jedify's Asker reference describes it as a read-only SQL SELECT against the data source. The server's own instructions state that only SELECT is allowed, that INSERT, UPDATE, DELETE, DROP, ALTER and CREATE are barred, and that queries must be single-line.
None that narrow anything. Jedify's RFC 9728 resource descriptor declares scopes_supported as an empty array, and its authorization server advertises only email, profile and phone — all OpenID identity claims. Checked live on 2026-08-23. So the consent screen offers no way to grant asking a question without also granting read-only SQL.
Yes, despite Anthropic's directory recording it as authless. The directory entry sets is_authless to true and auth_posture to no_auth, but an anonymous request to the listed endpoint returned HTTP 401 with a Bearer challenge on 2026-08-23. Jedify documents browser sign-in for desktop clients and an API key for hosted agents.
Whatever your warehouse holds, filtered by your permissions. Jedify connects to Snowflake, BigQuery, Databricks, Redshift and AWS Athena, and its authentication page states access is scoped to the signed-in user's or key's permissions. For Snowflake, Jedify forwards the end-user identity so native row access policies filter rows per user.
Because it uses one API key for all viewers. Jedify warns that a published app uses one API key for everyone who opens it, so every viewer sees data at that key's permission level rather than their own. Jedify's guidance for sensitive data such as HR or finance is to pick a key whose access matches what all viewers should see.
Because you are in Asker mode, which is the default. Jedify's troubleshooting page states that Builder mode requires the --builder flag in the proxy args, and that an API key carries its own mode. When using a key, Jedify's documented fix is to set the server URL to https://be.jedify.com/mcp/message?mode=builder, which takes precedence over the key's mode.
?mode= parameter (retrieved 2026-08-23) · retrieved 2026-08-23llms.txt and llms-full.txt — · (retrieved 2026-08-23). docs.jedify.com/robots.txt carries Content-Signal: ai-train=yes, search=yes, ai-input=yes, expressly permitting this synthesis. · retrieved 2026-08-23@jedify/mcp-auth 1.1.1 (retrieved 2026-08-23) · retrieved 2026-08-23https://be.jedify.com/mcp returned 401 with a Bearer challenge; RFC 9728 metadata at https://be.jedify.com/.well-known/oauth-protected-resource/mcp; authorization server metadata at https://be.jedify.com/.well-known/oauth-authorization-server (2026-08-23) · retrieved 2026-08-23Connect Jedify Production once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.