Tableau Public Authoring MCP
It authors, validates, and publishes Tableau Public workbooks from a JSON spec, plus provides read-only inspection and status tools.
Author workbooks from a declarative spec: CSV sources become Hyper extracts; field types are inferred; seven worksheet templates are supported (bar, line, text_table, heatmap, scatter, circle, map); encodings include color, size, label, tooltip, and detail; calculated fields, categorical filters, dashboards, titles/subtitles, and fit modes are generated; output is a deterministic
.twband packaged.twbx.Dry-run validation:
validate_workbook_specchecks an authoring spec without writing files.Open and validate in Tableau Public: open a generated
.twb/.twbx, detect error dialogs, and capture screenshot proof of rendered content.Publish to Tableau Public: uses the visible desktop workflow with required confirmation, profile name, overwrite control, dry-run mode, and resulting URL verification.
Inspect and monitor: list workbook templates, inspect local
.twbxarchives, check Tableau Public installation/version/window state, and verify published URLs are live.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Tableau Public Authoring MCPauthor a dashboard with two worksheets from my data.csv"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Tableau Public Authoring MCP
An MCP server that authors Tableau workbooks from a declarative spec, validates them by opening them in the installed Tableau Public application, and publishes through Tableau's own visible desktop workflow.
This is the counterpart to the existing reader MCP (
tableau-public), which inspects already-published content. The reader cannot create or publish anything. This server cannot browse public profiles. Keep both installed.
What it produces
Every screenshot below is a workbook generated from a JSON spec by this server,
then opened in Tableau Public 2026.2.0 and photographed. Nothing was authored by
hand, and nothing was touched in Tableau before the screenshot was taken. The
data is the synthetic 12-row fixture in tests/fixtures/data/.
A dashboard - two generated worksheets tiled in one container, fixed 1200×800 canvas, title rendered:

A symbol map - latitude/longitude detected from the column names and
tagged with Tableau's [Geographical] semantic role, which is what puts a real
background map behind the marks. One mark per site, coloured by a dimension and
sized by a measure:

A bar chart - colour by dimension, mark labels drawn, canvas fit applied:

The spec behind the map is the whole input:
{
"name": "Site Map",
"template": "map",
"data_source": "sites",
"detail": ["Site Name"],
"color": "Status",
"size": { "field": "Annual Sessions", "aggregation": "Sum" },
"title": "Candidate sites"
}Related MCP server: mcp-tableau
What it does
Reader MCP ( | This server ( | |
Search / inspect public profiles | ✅ | ❌ |
Download & unpack | ✅ | inspect only |
Create a workbook | ❌ | ✅ |
Open it in Tableau Public | ❌ | ✅ |
Publish to your account | ❌ | ✅ (visible UI) |
Verified capabilities
Everything below was confirmed by generating a workbook and opening it in Tableau Public 2026.2.0 on macOS, not merely by producing XML.
Supported
CSV data sources, automatically materialised into
.hyperextractsField type inference: string, integer, real, boolean, date, datetime
Worksheet templates:
bar,line,text_table,heatmap,scatter,circle,map(all seven screenshot-verified in Tableau Public 2026.2.0, and re-checked on every live run bytests/live/test_render_templates.py)Geographic roles: latitude/longitude columns detected by name, which is what puts a real background map behind the
maptemplateDashboards: title, fixed or automatic canvas, worksheets tiled in one container
Calculated fields (Tableau formula syntax)
Categorical filters, rendered as interactive filter cards
Encodings: color, size, label, tooltip, and detail -
detailraises the level of detail, so a scatter draws one mark per site instead of one per colour valueCanvas fit:
standard,fit_width,fit_height,entire_viewWorksheet titles and subtitles
.twbxpackaging, with a byte-deterministic.twbinside
Not supported in v0.1 - see docs/architecture/CAPABILITY_BOUNDARY.md
Stories, parameters, LOD expressions, joins/custom SQL, live connections
Sets, groups, hierarchies, table calculations, reference lines
Filled/choropleth maps, custom territories, map layers, spatial files
Dashboard filter cards, legends, actions, floating zones, device layouts
Two claims to read carefully
The
.twbxis not byte-reproducible. The.twbinside it is - identical spec, identical bytes. The archive is not, because the embedded.hyperis written by Tableau's Hyper engine and carries non-deterministic internal state. Diff the.twb, never the package digest. Seedocs/LIMITATIONS.md§1.A standalone
.twbis only usable next to its data directory.output.package_twbx: falsewrites<name>.twbplus a<name>.data/directory holding each source's.hyperand CSV, and the.twbresolves its data relative to itself - so keep the two together, or move them together. A packaged build produces the same layout underData/, matching what is inside the archive. Paths are always relative by necessity, not by preference: an absolute path would embed a home directory, andbuild_workbookrefuses to emit machine-identifying data (seedocs/architecture/THREAT_MODEL.md, T6).
Two constraints that shape everything
Tableau Public has no publishing API. The REST API covers Server/Cloud only, so publishing is driven through the real UI. Tableau documents the command as
Server > Tableau Public > Save to Tableau Public, but that is the Desktop Professional path: in the Public edition (2026.2.0) the Server menu holds onlyRun Optimizer...and the command lives on the File menu. It is invoked with a real Command+Shift+S key event, with the File menu as a fallback - seedocs/PUBLISHING_WORKFLOW.md.Tableau Public rejects non-extract data sources (
Error Code: 3C242D89). Every CSV is therefore converted to a Hyper extract at build time.
Install
uv tool install git+https://github.com/andyyaro/tableau-public-authoring-mcp
tableau-public-authoring doctorNo clone, no virtualenv, no paths to edit. doctor checks everything the server
needs and prints exactly what to fix - run it before registering, because
every prerequisite below fails silently at runtime rather than raising:
[PASS] platform macOS
[PASS] python 3.13.14 at ~/.local/share/uv/tools/…/bin/python
[PASS] mcp sdk importable
[PASS] tableauhyperapi importable
[PASS] quartz (pyobjc) importable
[PASS] tableau public 2026.2.0 at /Applications/Tableau Public.app
[PASS] accessibility granted to this process
[PASS] screen recording capture succeededMissing | What you would actually see |
Quartz | Tableau appears to have no windows open; publishing says "no document window matching …" |
Screen Recording | validation screenshots come back blank, with no error |
Accessibility | keystrokes and clicks go nowhere |
tableauhyperapi | no workbook can be built at all |
macOS permissions are granted per executable, so grant them to the
interpreter doctor prints - not to Tableau, and not to your terminal if you
register a different one. Details in docs/MACOS_PERMISSIONS.md.
Requirements: macOS with Tableau Public installed (developed against 2026.2.0,
Apple silicon), Python ≥ 3.10, and uv.
Register with Claude Code
claude mcp add --transport stdio --scope user tableau-public-authoring \
-- tableau-public-authoringThat is the whole command - uv tool install puts the executable on your PATH
at a stable location, so there is no absolute path to substitute and it survives
upgrades. Registering does not affect any other MCP server; verify with
claude mcp list. Restart Claude Code before the tools appear.
git clone https://github.com/andyyaro/tableau-public-authoring-mcp
cd tableau-public-authoring-mcp
uv venv && uv sync && uv pip install -e .
uv run tableau-public-authoring doctorRegister that build by pointing at its interpreter explicitly:
claude mcp add --transport stdio --scope user tableau-public-authoring \
-- /absolute/path/to/.venv/bin/python -m tableau_public_authoring.serverAvoid uvx --from … for the registered server: it runs from a
content-hashed cache path that changes whenever a dependency changes, and the
macOS permission grants are tied to that path - so the server would quietly lose
Accessibility and Screen Recording on the next upgrade. It is fine for one-off
use such as uvx --from … tableau-public-authoring doctor.
Upgrading
uv tool upgrade tableau-public-authoring
tableau-public-authoring doctorBuild a workbook
{
"spec_version": "0.1",
"workbook": { "name": "EV Charging Readiness", "description": "Generated" },
"data_sources": [{ "id": "sites", "type": "csv", "path": "/abs/path/sites.csv" }],
"calculated_fields": [{
"name": "Readiness Band", "data_source": "sites", "datatype": "string",
"formula": "IF [Readiness Score] >= 70 THEN \"High\" ELSE \"Low\" END"
}],
"worksheets": [{
"name": "Readiness by Site", "template": "bar", "data_source": "sites",
"rows": ["Site Name"],
"columns": [{ "field": "Readiness Score", "aggregation": "Sum" }],
"color": "Readiness Band",
"filters": ["Status"],
"title": "EV Charging Readiness by Site"
}],
"output": { "directory": "/abs/path/output", "package_twbx": true }
}Paths may be relative to a single base_dir instead of absolute - and a relative
path is confined to that directory, which an absolute path is not. See
docs/AUTHORING_SPEC.md.
Then: validate_workbook_spec (dry run) → build_workbook →
validate_in_tableau_public → publish_to_tableau_public.
Full schema: schemas/workbook-spec-v0.1.json and docs/AUTHORING_SPEC.md.
Why things are the way they are
Most of this codebase's shape is a response to something Tableau actually did.
docs/LIMITATIONS.md lists the constraints; docs/history/CHANGE_HISTORY.md
keeps the release write-ups, which record the failure each fix was responding to
and what proved it fixed. docs/fixtures/ holds the forensic analysis of a real
published workbook that the compiler was reverse-engineered from.
Publishing
publish_to_tableau_public is marked destructive and requires both
confirm_publish: true and profile (your Tableau Public profile name);
overwrite defaults to false. profile is required because without it the
server cannot check whether a workbook of that name is already live, and Tableau
Public replaces a same-named workbook irreversibly, with no version history.
It drives the visible command and never reads, types, or stores credentials - it uses your existing signed-in desktop session. If Tableau needs a sign-in, the tool stops and tells you to sign in manually. Publication is irreversible and world-visible.
Use dry_run: true to see exactly what would happen first.
Tests
uv run pytest # unit + integration (no Tableau needed)
uv run pytest -m live # requires Tableau Public installed
uv run ruff check . && uv run ruff format --check .live and publish tests are excluded from normal runs and must never run in CI.
Security
No credentials are stored anywhere. XML is generated through ElementTree
(never string concatenation), archives are ZIP-slip guarded, paths are
traversal-checked, and generated workbooks are scanned for machine-identifying
data before packaging. See docs/SECURITY.md and
docs/architecture/THREAT_MODEL.md.
Rollback
claude mcp remove --scope user tableau-public-authoringThis leaves all other MCP servers untouched.
Uninstalling
claude mcp remove tableau-public-authoring -s user
claude mcp list # your other servers should still be listed
rm -rf <this repo>/output # generated workbooks are inert local filesAnything already published must be deleted by you from your Tableau Public
profile in the browser. This server has no delete capability, by design:
publication is irreversible from its side, which is why it requires
confirm_publish and refuses a name collision unless you pass overwrite.
License
MIT - see LICENSE.
Available Tools
10 toolsbuild_workbookA
PRIMARY TOOL. Compile a specification into a .twb and packaged .twbx with Hyper extracts (required by Tableau Public). Writes files to the spec's output.directory. The .twb is byte-deterministic for an identical spec; the .twbx digest is not, because the embedded Hyper extract carries non-deterministic state.
| Name | Required | Description | Default |
|---|---|---|---|
| spec | Yes | Declarative description of a Tableau workbook to generate. Unknown properties are rejected everywhere. Generated from tableau_public_authoring.models.spec.spec_json_schema(); edit that function, never this file. Structural validation only - the server additionally checks cross-references, field existence and encoding compatibility, so a valid document here can still be rejected. | |
| overwrite | No | Replace files in the output directory that this server did not generate. Rebuilding the same workbook does not require it. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description must carry the full burden. It discloses that files are written to the spec's output directory and notes the determinism of .twb versus .twbx. However, it lacks details on authorization, overwrite behavior, error conditions, or prerequisites beyond the schema.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is three sentences, front-loaded with 'PRIMARY TOOL', and every sentence provides essential information (purpose, output location, determinism). No superfluous content.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the complexity of the input schema and the absence of an output schema and annotations, the description is minimal. It does not explain return values, error handling, the build process, or prerequisites, leaving the agent with potential gaps for correct invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100% with detailed descriptions for both parameters (spec and overwrite) and all nested properties. The tool description does not add additional meaning beyond what the schema already provides, so baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states it is the 'PRIMARY TOOL' and specifies the action 'Compile a specification into .twb and .twbx with Hyper extracts'. It distinguishes itself from sibling tools like validation, inspection, and publishing by its primary build role.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description labels the tool as 'PRIMARY' but does not provide explicit guidance on when to use it versus alternatives like validate_workbook_spec or inspect_local_workbook. No when-not-to or exclusions are mentioned.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_authoring_capabilitiesA
Report what this server can and cannot author, the detected Tableau Public installation, and the macOS permission state. Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Read-only behavior is mentioned, which is transparent given no annotations. However, the description does not elaborate on potential nuances like data freshness or permission requirements, leaving some ambiguity.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Single sentence with no fluff, front-loaded with purpose. Every word contributes meaning.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Adequate for a simple info tool, but lacks details on output format or the meaning of 'capabilities'. Given no output schema, more detail would improve completeness.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema has zero parameters with 100% coverage, so description adds value by explaining the output categories. Baseline of 4 is appropriate as it compensates for lack of output schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Description clearly states the tool reports three specific categories: authoring capabilities, Tableau Public installation, and macOS permission state. Verb 'report' and resource are specific and distinct from sibling tools which focus on workbook operations.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No explicit guidance on when to use this tool vs alternatives like 'get_tableau_public_app_status'. The read-only nature is noted but not contextualized relative to sibling tools.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_tableau_public_app_statusA
Report Tableau Public installation, version, running state, open windows and Accessibility permission. Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries full responsibility. It explicitly states 'Read-only' and enumerates five specific aspects reported. It does not discuss prerequisites or error conditions, but for a status tool, this is sufficient.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence with front-loaded content. Every word adds value: 'Report', the list of items, and 'Read-only'. No redundancy or filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no output schema, the description lists the reported items without specifying return format. This is adequate for an agent to understand what will be provided. Slightly incomplete as it doesn't mention failure modes or format, but acceptable for a status tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
There are no parameters, so schema coverage is 100% trivially. The description does not need to add parameter info. According to calibration, 0 parameters merits a baseline of 4.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb 'report' and specific resources: installation, version, running state, open windows, and Accessibility permission. It distinguishes from siblings by focusing on status information rather than authoring or publishing.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description includes 'Read-only' which implies safe usage without side effects. While it does not explicitly list when to use vs alternatives, the context is clear among sibling tools. Slightly lacking explicit when-not or alternative references.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
inspect_local_workbookA
Safely inspect a local .twbx archive's contents. Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
| path | Yes | Absolute .twbx path |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description states safety and read-only nature but omits exactly what 'contents' means (e.g., file list vs metadata) and error behavior. Adequate but minimal.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences front-load the purpose and behavior, with zero waste. Ideal conciseness for a simple tool.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
No output schema exists, yet the description does not explain the return format or data. For a read-only inspection tool, the output is a critical missing piece.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema covers 100% of parameters with clear description ('Absolute .twbx path'). The tool description adds no extra parameter meaning beyond the schema, so baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly identifies the resource (local .twbx archive) and action (inspect contents), with 'Read-only' distinguishing it from mutation tools like build_workbook or publish_to_tableau_public.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
'Safely inspect' and 'Read-only' imply usage for examining archives without modification. No explicit alternatives or exclusions, but the context from siblings makes the intended use clear.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_workbook_templatesA
List supported worksheet templates and their required shelves. Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Only states 'Read-only' as behavioral info. No annotations exist, so description should disclose more (e.g., if requires auth, any side effects). Minimal for a no-annotation tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Single sentence, no waste. Essential info is front-loaded. Efficient for a simple list tool.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Describes output sufficiently for a parameterless list tool. Lacks mention of how output can be used with sibling tools (e.g., building a workbook), but given simplicity, adequate.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
No parameters, so schema coverage is 100%. Description adds context about return values (required shelves), which enhances understanding beyond the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States exact action (list) and resource (supported worksheet templates) with output details (required shelves). Clearly distinguishes from sibling tools that validate, build, or publish.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance on when to use or alternatives. With siblings like get_authoring_capabilities and validate_workbook_spec, the description provides no context for selection.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
open_in_tableau_publicA
Open a generated workbook in Tableau Public and wait for its window. Returns the load error verbatim if Tableau rejects the file.
| Name | Required | Description | Default |
|---|---|---|---|
| path | Yes | Absolute .twb or .twbx path | |
| timeout_s | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description does well to disclose key behaviors: it waits for the window and returns error verbatim. However, it does not explicitly state whether the tool modifies the workbook or the Tableau environment, though 'open' implies read-only. The waiting behavior is clearly mentioned.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences with no wasted words. It front-loads the main action and immediately provides additional context about waiting and error handling.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool with 2 parameters and no output schema, the description covers the essential behavior: opening a workbook, waiting for the window, and returning errors. It is slightly ambiguous about what happens on success (presumably returns nothing or success indicator), but overall adequate.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The description adds no additional meaning to the parameters beyond what the input schema provides. The path parameter is already described as 'Absolute .twb or .twbx path' in the schema, and timeout_s has default/min/max bounds. The description's mention of 'Open a generated workbook' implicitly references the path but does not enhance parameter understanding.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action ('open'), the resource ('generated workbook in Tableau Public'), and the specific behavior ('wait for its window', 'returns load error verbatim'). It distinguishes from sibling tools like 'publish_to_tableau_public' or 'validate_in_tableau_public' by focusing on opening and waiting.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies the tool is for opening a generated workbook, but lacks explicit guidance on when to use it versus alternatives like 'validate_in_tableau_public' or 'publish_to_tableau_public'. No when-not or exclusions provided.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
publish_to_tableau_publicA
DESTRUCTIVE / PUBLIC. Publish an open workbook to the user's Tableau Public account through the visible Server > Tableau Public > Save to Tableau Public workflow. Publication is irreversible and world-visible. Requires confirm_publish=true. Never reads credentials; pauses for manual sign-in if required.
| Name | Required | Description | Default |
|---|---|---|---|
| dry_run | No | Report what would happen without publishing. | |
| profile | Yes | Your Tableau Public profile name. Required to resolve and verify the resulting public URL after publication. | |
| overwrite | No | Allow overwriting an existing workbook of the same name. | |
| set_title | No | Type public_name into the dialog's Workbook Title field. If false, Tableau's pre-filled title (from the file name) is kept. | |
| public_name | Yes | Name for the published workbook (must be unique) | |
| workbook_path | No | Absolute path to the .twbx being published. Optional but recommended: it lets a minimized workbook be raised reliably with `open -a` instead of a coordinate click. | |
| screenshot_dir | No | ||
| confirm_publish | Yes | Must be true. Guards against accidental publication. | |
| workbook_window | Yes | The open workbook's exact name (its window title without the 'Tableau Public - ' prefix). Matched exactly, not as a substring, because publishing is irreversible: a substring match would let 'Q3_Sales' publish 'Q3_Sales_Draft'. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden. It explicitly labels the action as 'DESTRUCTIVE / PUBLIC,' states 'Publication is irreversible and world-visible,' highlights the guard (confirm_publish=true), and discloses manual sign-in behavior. This is comprehensive, though it could mention error handling or failure modes.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences: the first focuses on purpose and danger, the second on key details (irreversibility, guard, credential handling). No waste, front-loaded with the most critical information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a destructive 9-parameter tool with no output schema, the description covers the essential aspects: irreversible publication, required guard, credential handling, and exact window name matching. It could mention return behavior or failure scenarios, but it is sufficiently complete for safe usage.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 89%, so the schema already documents most parameters. The description adds little beyond what's in the schema (e.g., reiterates confirm_publish must be true and workbook_window exact matching). Baseline 3 is appropriate as it does not need to compensate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description starts with 'DESTRUCTIVE / PUBLIC. Publish an open workbook to the user's Tableau Public account...' and clearly distinguishes the tool from siblings like validate_workbook_spec or verify_published_workbook. The verb 'Publish' and resource 'open workbook to Tableau Public' are precise.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description states 'Requires confirm_publish=true' and 'Never reads credentials; pauses for manual sign-in if required,' providing clear usage context. However, it does not explicitly state when not to use the tool or suggest alternatives among the sibling tools.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
validate_in_tableau_publicC
Layer 3+4 validation: open the workbook in Tableau Public, detect error dialogs, and capture a screenshot proving rendered content.
| Name | Required | Description | Default |
|---|---|---|---|
| path | Yes | ||
| settle_s | No | ||
| screenshot_dir | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries full burden. It states it opens the workbook and detects error dialogs, but fails to disclose behavioral aspects such as whether the tool modifies the workbook, whether it requires user interaction, how long it takes, or what happens to the screenshot after capture. The lack of side-effect clarity (e.g., destructive hint) is a significant gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, front-loaded sentence that efficiently conveys the main purpose. However, it sacrifices necessary detail for brevity, leaving parameter semantics and usage unspecified.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool has 3 parameters, no output schema, and no annotations, the description is incomplete. It does not explain 'Layer 3+4', what constitutes an error dialog, or how the screenshot is returned. The agent would need external context to use it correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, and the description does not explain any of the three parameters (path, settle_s, screenshot_dir). The term 'settle_s' is ambiguous (likely a delay), and 'screenshot_dir' is not described. Without any clarification, the agent cannot correctly provide values.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the specific purpose: 'Layer 3+4 validation: open the workbook in Tableau Public, detect error dialogs, and capture a screenshot proving rendered content.' It uses a specific verb (validate) and resource (workbook in Tableau Public), and distinguishes from related siblings like 'open_in_tableau_public' and 'verify_published_workbook' by defining its unique validation layer.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is provided on when to use this tool versus alternatives. The description does not mention prerequisites, when not to use it, or how it differs from sibling validation tools like 'validate_workbook_spec' or 'verify_published_workbook'.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
validate_workbook_specA
Validate an authoring specification without writing any files (dry run). Returns actionable errors. Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
| spec | Yes | Declarative description of a Tableau workbook to generate. Unknown properties are rejected everywhere. Generated from tableau_public_authoring.models.spec.spec_json_schema(); edit that function, never this file. Structural validation only - the server additionally checks cross-references, field existence and encoding compatibility, so a valid document here can still be rejected. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the burden and discloses key behaviors: no files written (dry run) and read-only. It also mentions returning actionable errors. This is sufficient for a validation tool, though it omits details on rate limits or performance.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences with zero waste. First sentence states the verb and resource; second adds key behavioral traits. Ideal conciseness.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Adequate for a simple tool, but lacks detail on output format of 'actionable errors' and prerequisites (e.g., valid JSON schema). Could be more complete given the complex spec parameter.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% with embedded descriptions for the single parameter 'spec'. The tool description adds only the dry-run context, not parameter-specific meaning, so baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool validates an authoring specification as a dry run, being read-only. It distinguishes from the build tool but does not explicitly differentiate from the sibling 'validate_in_tableau_public', which may also validate.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies use as a pre-build check (dry run) but provides no explicit guidance on when to use this versus alternatives like 'validate_in_tableau_public' or when not to use it.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
verify_published_workbookB
Layer 5 validation: load a public Tableau URL and confirm it responds. Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
| url | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
States it is read-only, which is crucial for safety. However, with no annotations provided, the description should disclose more behavioral traits such as error handling, timeout behavior, or what constitutes a successful response. The current description is minimal.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is extremely concise, using a single sentence. It is front-loaded with 'Layer 5 validation', which may be jargon, but overall the structure is efficient. Could be slightly improved by moving the important 'read-only' claim earlier.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's simplicity (one parameter, no output schema), the description covers the basic action but lacks completeness. It does not explain what 'confirms it responds' means (e.g., HTTP status 200) nor how the output signals success or failure. Also fails to differentiate from siblings.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The only parameter 'url' receives minimal additional meaning: it is described as a 'public Tableau URL'. With 0% schema description coverage, this is insufficient. The description should specify expected format (e.g., must start with 'https://public.tableau.com'), but does not.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool loads a public Tableau URL and confirms a response. It identifies the resource (public Tableau URL) and action (verify). However, it does not explicitly differentiate from sibling tools like validate_in_tableau_public, which may perform similar checks, and the jargon 'Layer 5 validation' is not explained.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Implies usage for verifying a published workbook is accessible, but provides no guidance on when to use this tool over alternatives (e.g., validate_in_tableau_public). No exclusions or prerequisites are mentioned, leaving the agent to infer context.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
10 tool updates
v0.1.0- First observed
build_workbook - First observed
get_authoring_capabilities - First observed
get_tableau_public_app_status - First observed
inspect_local_workbook - First observed
list_workbook_templates - First observed
open_in_tableau_public - First observed
publish_to_tableau_public - First observed
validate_in_tableau_public - First observed
validate_workbook_spec - First observed
verify_published_workbook
TDQS
Each tool has a clearly distinct purpose: capabilities, templates, validation, building, inspection, app status, opening, in-app validation, publishing, and verification. No two tools overlap in function, and descriptions clearly differentiate them.
All tool names follow a consistent verb_noun pattern using snake_case (e.g., get_authoring_capabilities, build_workbook, publish_to_tableau_public). No mixing of conventions, and verbs clearly indicate the action.
Ten tools is well-scoped for the domain of authoring and publishing Tableau Public workbooks. Each tool serves a necessary step in the workflow, from capability reporting to verification.
The tool set covers the full authoring and publishing lifecycle: capabilities, templates, dry-run validation, building, local inspection, app status, opening, in-app validation, publishing, and web verification. No obvious gaps for the stated purpose.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Generate Tableau .twb/.twbx workbooks: 47 tools for charts, dashboards, rules, CSV pipelines.
Formula-backed WorkPaper tools for workbook readback, input edits, and JSON persistence.
Excel analytics: inspect, query (JSON rows), charts, and JSON-to-xlsx workbook writing.
Validate, build, and publish the resume you keep as YAML in your own GitHub repository.
Related MCP Servers
- FlicenseNot gradedqualityNot gradedmaintenanceEnables discovery, querying, and exporting of Tableau Cloud dashboards and data sources. Supports searching workbooks, filtering data, and exporting views as PDF, PNG, PowerPoint, CSV, or JSON.-
- FlicenseAqualityBmaintenanceMCP server that automates the publishing and validation of Tableau workbooks and data sources on Tableau Server or Tableau Cloud, enabling an AI agent to discover, build, validate, and publish content without human intervention.10-
- FlicenseNot gradedqualityBmaintenanceBuilds importable RUCKUS One Data Studio dashboards from a declarative spec, enabling users to create valid dashboards without learning Superset internals or guessing field names.2-
- AlicenseNot gradedqualityCmaintenanceAudits local Tableau workbooks for unused assets, duplicate worksheets, and dashboard weight, providing cleanup reports and health summaries.MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/andyyaro/tableau-public-authoring-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server