Sidecar
REMOTE · SERVICE-MCP.SIDECARDATA.COM · SCANNED AUG 3
Cross-tool context for your data stack. Search, lineage, and impact across warehouse and BI tools.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security92
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server supports Client ID Metadata Documents, the current MCP client-registration mechanism. View diagnostics → Pass
Transport & Reachability0
- Transport blocked by authentication: the endpoint requires auth we don't have to verify streamable-http. See how to fix → View diagnostics → Unverified
Schema Quality & AI Usability0
- Schema blocked by authentication: the endpoint requires auth we don't have to read it. See how to fix → Unverified
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
- Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Capabilities0
- Capabilities blocked by authentication: the endpoint requires auth we don't have to read them. See how to fix → Unverified
Unverified: 5 categories
Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · service-mcp.sidecardata.com
claude mcp add --transport http com-sidecardata-sidecar https://service-mcp.sidecardata.com/sidecar/mcp
[mcp_servers.com-sidecardata-sidecar] url = "https://service-mcp.sidecardata.com/sidecar/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-sidecardata-sidecar": {
"type": "remote",
"url": "https://service-mcp.sidecardata.com/sidecar/mcp",
"enabled": true
}
}
} openclaw mcp add com-sidecardata-sidecar --url https://service-mcp.sidecardata.com/sidecar/mcp --transport streamable-http
mcp_servers:
com-sidecardata-sidecar:
url: "https://service-mcp.sidecardata.com/sidecar/mcp" {
"mcpServers": {
"com-sidecardata-sidecar": {
"type": "http",
"url": "https://service-mcp.sidecardata.com/sidecar/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 31 Jul 26 +14
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 29 Jul 26 −44
- Endpoint reachability: reachable → behind authorisation ▼ security
- Stability: 0.07 → unverified ▼ security
- Transport: pass → unverified ▼ security
- Authorization: unverified → pass ▲ security
- Capabilities: pass → unverified ▼ functional
- Schema quality: 100 → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 65
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://service-mcp.sidecardata.com/sidecar/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=sidecardata.com | CN=Amazon RSA 2048 M04,O=Amazon,C=US | 14 Jul 2026 | 27 Jan 2027 | RSA 2048 | SHA256-RSA | 31411bba51ed47e062ab1157c653b94 |
| SANs: sidecardata.com, *.sidecardata.com | ||||||
| CN=Amazon RSA 2048 M04,O=Amazon,C=US (CA) | CN=Amazon Root CA 1,O=Amazon,C=US | 23 Aug 2022 | 23 Aug 2030 | RSA 2048 | SHA256-RSA | 773124f2a952e3ed18a58bdb85d1bc0ce5f27 |
| CN=Amazon Root CA 1,O=Amazon,C=US (CA) | CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies\, Inc.,L=Scottsdale,ST=Arizona,C=US | 25 May 2015 | 31 Dec 2037 | RSA 2048 | SHA256-RSA | 67f944a2a27cdf3fac2ae2b01f908eeb9c4c6 |
DNSSEC insecure
Validation of service-mcp.sidecardata.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| sidecardata.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On connection |
| HTTP status | 401 |
WWW-Authenticate challenge Bearer resource_metadata="https://service-mcp.sidecardata.com/.well-known/oauth-protected-resource/sidecar/mcp"
Bearer resource_metadata="https://service-mcp.sidecardata.com/.well-known/oauth-protected-resource/sidecar/mcp" | Header | Value |
|---|---|
| www-authenticate | Bearer resource_metadata="https://service-mcp.sidecardata.com/.well-known/oauth-protected-resource/sidecar/mcp" |
Protected resource metadata
| Document | https://service-mcp.sidecardata.com/.well-known/oauth-protected-resource/sidecar/mcp |
|---|---|
| Retrieved | Yes |
| Resource | https://service-mcp.sidecardata.com/sidecar/mcp |
| Authorisation server | https://service-platform.sidecardata.com |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://service-mcp.sidecardata.com/sidecar/mcp | Auth required | 401 | |
| http (plaintext) | http://service-mcp.sidecardata.com/sidecar/mcp | HTTPS enforced |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
advanced_search ~333
Search for data assets using identifier matching, keyword search, semantic similarity, or hybrid fusion. Use 'identifier' mode (default) when you know the asset name or a pattern (supports * wildcards). Use 'keyword' when searching by domain terms or metadata keywords. Use 'semantic' for natural language queries about what the data represents. Use 'hybrid' to combine all approaches for the best recall. Returns a ranked list of matching assets with identifiers, types, and relevance scores.
| Name | Type | Req | Description |
|---|---|---|---|
| asset_type | — | — | Filter to a specific asset type. snake_case, e.g. snowflake_table, dbt_model. |
| importance | — | — | Filter to a specific importance level: 'high', 'medium', or 'low'. |
| limit | integer | — | Maximum number of results (1-50). |
| mode | string | — | Search mode. 'identifier' (default): exact/wildcard match on asset_identifier. 'keyword': full-text search over indexed keywords. 'semantic': vector similarity search. 'hybrid': fuses identifier + ke… |
| query | string | yes | Search query. For identifier mode: asset name or wildcard pattern (e.g. 'fct_orders', 'stg_*', 'analytics.*customers'). For keyword/semantic/hybrid: natural language query (e.g. 'revenue metrics', 'u… |
| tags | — | — | Filter to assets with any of these tags (OR semantics). |
| tool_type | — | — | Filter to a specific tool. UPPERCASE, e.g. SNOWFLAKE, DBT_CLOUD, BIGQUERY. |
Structured output declared, but exposes no named fields.
No examples provided.
calculate_downstream_impact ~167
Find everything downstream of a data asset — tables, dashboards, and reports that would break or be affected if this asset changes. Call this automatically after the user modifies any SQL file, dbt model, or source definition, or whenever they ask 'what depends on X?' or 'what breaks if I change Y?' Returns a breakdown of affected assets by tool type and a full list of downstream nodes.
| Name | Type | Req | Description |
|---|---|---|---|
| asset_identifier | string | yes | Asset name or Sidecar asset identifier to analyze (e.g., 'fct_reviews' or 'model.jaffle_shop.fct_reviews'). |
| max_depth | integer | — | Downstream depth to traverse for impact analysis. |
| tool_type | — | — | Optional tool/source hint (e.g., DBT_CLOUD, SNOWFLAKE). |
Structured output declared, but exposes no named fields.
No examples provided.
describe_asset ~275
Fetch detailed information about a data asset by its identifier. Resolves the asset, then fetches the requested sections in parallel. Use this after advanced_search or resolve_asset_id to get deeper information about a specific asset. Sections: - overview: asset description, importance, owner, metadata - columns: full column schema with types and descriptions - tests: dbt test coverage (only for assets with a dbt parent) - context_counts: cheap count of linked tickets and Slack threads - tickets: full Jira/Linear ticket content - slack: full Slack thread content (truncated to first 5 messages per thread)
| Name | Type | Req | Description |
|---|---|---|---|
| asset_identifier | string | yes | Asset name or Sidecar asset identifier (e.g. 'fct_orders' or 'model.jaffle_shop.fct_orders'). |
| include | array | yes | Which sections to fetch. One or more of: 'overview' (description, importance, owner), 'columns' (schema), 'tests' (dbt test coverage), 'context_counts' (ticket/slack counts), 'tickets' (full ticket c… |
| tool_type | — | — | Optional tool/source hint to disambiguate (e.g. SNOWFLAKE, DBT_CLOUD). |
Structured output declared, but exposes no named fields.
No examples provided.
get_catalog_overview ~145
Get a summary of everything available in this customer's Sidecar catalog. Returns the connected tools (e.g. SNOWFLAKE, DBT_CLOUD, LOOKER), asset type breakdown with counts, all available tag names, and a customer-provided company summary describing the company's domain and data landscape (if set). Call this at the start of any open-ended exploration (e.g. 'what data do we have?', 'show me all Snowflake tables'), or when a search returns no results and you need to understand what's actually in the catalog before trying again. Use the customer_summary field (when present) to understand the business context behind the data.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
get_column_lineage ~195
Trace column-level lineage — which upstream columns feed into a column and which downstream columns consume it. Use this when the user asks 'where does this column come from?', 'what columns feed into X.col?', or needs to understand column-level data flow. Returns the target column, upstream columns (with levels), and downstream columns (with levels).
| Name | Type | Req | Description |
|---|---|---|---|
| asset_identifier | string | yes | Asset name or Sidecar asset identifier (e.g., 'fct_orders' or 'model.jaffle_shop.fct_orders'). |
| column_name | string | yes | The column name to trace lineage for (case-insensitive). |
| downstream_depth | integer | — | Levels of downstream column lineage to include. |
| tool_type | — | — | Optional tool/source hint (e.g., DBT_CLOUD, SNOWFLAKE) to disambiguate when multiple assets share the same identifier. |
| upstream_depth | integer | — | Levels of upstream column lineage to include. |
Structured output declared, but exposes no named fields.
No examples provided.
get_context_repo ~27
Return the clean OSI semantic contract currently deployed to this MCP token's Context Garage surface.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
get_knowledge_base_file_content ~89
Fetch the full text content of a file from the customer's knowledge base. Use this after calling list_knowledge_base_files to get file IDs. Works with any file in the knowledge base — playbooks, metric definitions, nuances, or captured context summaries.
| Name | Type | Req | Description |
|---|---|---|---|
| file_id | string | yes | UUID of the knowledge base file to retrieve. Get file IDs from list_knowledge_base_files. |
Structured output declared, but exposes no named fields.
No examples provided.
inspect_lineage_details ~157
Trace the full data lineage for an asset — both upstream sources and downstream consumers. Use this when the user asks 'where does this data come from?', 'what feeds into X?', or needs the raw lineage graph. For pure downstream impact (blast radius), prefer `calculate_downstream_impact` instead.
| Name | Type | Req | Description |
|---|---|---|---|
| asset_identifier | string | yes | Asset name or Sidecar asset identifier to trace (e.g., 'fct_reviews' or 'model.jaffle_shop.fct_reviews'). |
| downstream_depth | integer | — | Levels of downstream lineage to include. |
| tool_type | — | — | Optional tool/source hint (e.g., DBT_CLOUD, DBT_CORE). |
| upstream_depth | integer | — | Levels of upstream lineage to include. |
Structured output declared, but exposes no named fields.
No examples provided.
list_knowledge_base_files ~126
List all files in the customer's knowledge base. The knowledge base contains company-specific reference material — playbooks, metric definitions, business nuances, and conventions — uploaded by the customer's team. Returns file names, paths, types, and IDs. Pass a file ID to `get_knowledge_base_file_content` to read its content. Use the optional folder_path parameter to narrow results to a specific folder.
| Name | Type | Req | Description |
|---|---|---|---|
| folder_path | — | — | Optional folder path to filter results (e.g. '/Playbooks', '/Metrics and Drivers'). When omitted, returns all files across the entire knowledge base. |
Structured output declared, but exposes no named fields.
No examples provided.
resolve_asset_id ~423
Look up any data asset by name across the full catalog (dbt, Snowflake, BigQuery, Looker, etc.). Returns the asset's columns, description, owner, tags, and its **Sidecar asset identifier** (`asset_identifier` field) — the fully-qualified internal name used by lineage and impact tools (e.g. `model.jaffle_shop.fct_orders`, `PROD_DB.ANALYTICS.FCT_ORDERS`). When a single asset is resolved, the response also includes a `context_summary` with counts of linked tickets (Jira/Linear) and Slack threads. If those counts are non-zero and relevant to the user's question, follow up with `describe_asset` using include=['tickets'] or include=['slack'] to fetch the actual content. Call this first whenever the user refers to a specific table, model, view, or dashboard.
| Name | Type | Req | Description |
|---|---|---|---|
| asset_name | string | yes | Name or query for the asset to look up. Plain name ('fct_reviews'), wildcard ('fct_*'), or filters inline ('fct_reviews tool_type:SNOWFLAKE', 'tag:finance'). Filter keys: tool_type (UPPERCASE, e.g. S… |
| asset_type | — | — | Narrow to a specific asset type. snake_case, e.g. snowflake_table, dbt_model, dbt_source, looker_dashboard. Call get_catalog_overview to see all asset types present for this customer. |
| tool_type | — | — | Narrow to a specific tool. UPPERCASE, e.g. SNOWFLAKE, DBT_CLOUD, DBT_CORE, BIGQUERY, LOOKER, METABASE, FIVETRAN, POWER_BI, REDSHIFT. Call get_catalog_overview to see which tools are connected for thi… |
Structured output declared, but exposes no named fields.
No examples provided.