Tableau Public Authoring MCP
Tableau Public Authoring MCP
一个 MCP 服务器,它根据声明式规范创作 Tableau 工作簿,通过在已安装的 Tableau Public 应用程序中打开它们来验证,并通过 Tableau 自己的可见桌面工作流发布。
这是现有读取器 MCP(
tableau-public)的对应物,后者检查已发布的内容。读取器无法创建或发布任何内容。此服务器无法浏览公开个人资料。请同时保留两者。
它生成什么
下面的每张截图都是此服务器根据 JSON 规范生成的工作簿,然后在 Tableau Public 2026.2.0 中打开并拍摄的。没有任何内容是手工创作的,截图拍摄前也没有在 Tableau 中进行过任何操作。数据是 tests/fixtures/data/ 中的合成 12 行测试夹具。
仪表板 - 两个生成的工作表平铺在一个容器中,固定 1200×800 画布,标题已渲染:

符号地图 - 从列名检测出 latitude/longitude,并标记为 Tableau 的 [Geographical] 语义角色,这正是让标记背后出现真实背景地图的原因。每个站点一个标记,按维度着色并按度量调整大小:

条形图 - 按维度着色,绘制了标记标签,已应用画布适配:

地图背后的规范就是全部输入:
{
"name": "Site Map",
"template": "map",
"data_source": "sites",
"detail": ["Site Name"],
"color": "Status",
"size": { "field": "Annual Sessions", "aggregation": "Sum" },
"title": "Candidate sites"
}Related MCP server: mcp-tableau
它能做什么
读取器 MCP( | 此服务器( | |
搜索 / 检查公开个人资料 | ✅ | ❌ |
下载并解包 | ✅ | 仅检查 |
创建工作簿 | ❌ | ✅ |
在 Tableau Public 中打开它 | ❌ | ✅ |
发布到你的账户 | ❌ | ✅(可见界面) |
已验证的能力
以下所有内容都通过生成工作簿并在 macOS 上的 Tableau Public 2026.2.0 中打开它得到确认,而不仅仅是生成 XML。
支持
CSV 数据源,自动物化为
.hyper提取字段类型推断:字符串、整数、实数、布尔值、日期、日期时间
工作表模板:
bar、line、text_table、heatmap、scatter、circle、map(全部七个已在 Tableau Public 2026.2.0 中通过截图验证,并在每次实时运行时由tests/live/test_render_templates.py重新检查)地理角色:按名称检测纬度和经度列,这正是让
map模板背后出现真实背景地图的原因仪表板:标题、固定或自动画布、工作表平铺在一个容器中
计算字段(Tableau 公式语法)
分类筛选器,渲染为交互式筛选器卡片
编码:color、size、label、tooltip 和 detail -
detail提高详细级别,因此散点图按站点绘制一个标记,而不是按颜色值绘制一个标记画布适配:
standard、fit_width、fit_height、entire_view工作表标题和副标题
.twbx打包,内含字节确定性的.twb
v0.1 中不支持 - 参见 docs/architecture/CAPABILITY_BOUNDARY.md
故事、参数、LOD 表达式、联接/自定义 SQL、实时连接
集、组、层次结构、表计算、参考线
填充/等值区域地图、自定义区域、地图图层、空间文件
仪表板筛选器卡片、图例、操作、浮动区域、设备布局
两个需要仔细阅读的声明
.twbx不是字节可重现的。 其中的.twb是 - 相同的规范,相同的字节。归档文件不是,因为嵌入的.hyper由 Tableau 的 Hyper 引擎写入,并带有非确定性的内部状态。请对.twb进行 diff,绝不要对包摘要进行 diff。参见docs/LIMITATIONS.md§1。独立的
.twb只能在其数据目录旁边使用。output.package_twbx: false会写入<name>.twb以及一个<name>.data/目录,其中包含每个数据源的.hyper和 CSV,而.twb相对于自身解析其数据 - 因此请将两者放在一起,或一起移动。打包构建会在Data/下生成相同的布局,与归档内的布局一致。路径总是出于必要而相对,而非出于偏好:绝对路径会嵌入主目录,而build_workbook拒绝输出可识别机器的数据(参见docs/architecture/THREAT_MODEL.md,T6)。
影响一切的两个约束
Tableau Public 没有发布 API。 REST API 仅涵盖 Server/Cloud,因此发布是通过真实 UI 驱动的。Tableau 将命令记录为
Server > Tableau Public > Save to Tableau Public,但那是 Desktop Professional 的路径:在 Public 版本(2026.2.0)中,Server 菜单只包含Run Optimizer...,而该命令位于 File 菜单上。它通过真实的 Command+Shift+S 按键事件调用,并以 File 菜单作为后备 - 参见docs/PUBLISHING_WORKFLOW.md。Tableau Public 拒绝非提取数据源(
Error Code: 3C242D89)。因此,每个 CSV 在构建时都会转换为 Hyper 提取。
安装
uv tool install git+https://github.com/andyyaro/tableau-public-authoring-mcp
tableau-public-authoring doctor无需克隆,无需 virtualenv,无需编辑路径。doctor 会检查服务器所需的一切,并准确打印需要修复的内容 - 请在注册之前运行它,因为下面的每个先决条件在运行时都会静默失败,而不是抛出错误:
[PASS] platform macOS
[PASS] python 3.13.14 at ~/.local/share/uv/tools/…/bin/python
[PASS] mcp sdk importable
[PASS] tableauhyperapi importable
[PASS] quartz (pyobjc) importable
[PASS] tableau public 2026.2.0 at /Applications/Tableau Public.app
[PASS] accessibility granted to this process
[PASS] screen recording capture succeeded缺失项 | 你实际会看到什么 |
Quartz | Tableau 似乎没有打开任何窗口;发布时提示“no document window matching …” |
屏幕录制 | 验证截图返回空白,且没有错误 |
辅助功能 | 按键和点击没有任何效果 |
tableauhyperapi | 根本无法构建任何工作簿 |
macOS 权限是按可执行文件授予的,因此请授予 doctor 打印的解释器 - 而不是 Tableau,如果你注册了不同的终端,也不是你的终端。详细信息见 docs/MACOS_PERMISSIONS.md。
要求:安装了 Tableau Public 的 macOS(针对 2026.2.0、Apple silicon 开发),Python ≥ 3.10,以及 uv。
使用 Claude Code 注册
claude mcp add --transport stdio --scope user tableau-public-authoring \
-- tableau-public-authoring这就是完整的命令 - uv tool install 会将可执行文件放在 PATH 上的一个稳定位置,因此无需替换绝对路径,并且它在升级后仍然有效。注册不会影响任何其他 MCP 服务器;使用 claude mcp list 验证。在工具出现之前重启 Claude Code。
git clone https://github.com/andyyaro/tableau-public-authoring-mcp
cd tableau-public-authoring-mcp
uv venv && uv sync && uv pip install -e .
uv run tableau-public-authoring doctor通过显式指向其解释器来注册该构建:
claude mcp add --transport stdio --scope user tableau-public-authoring \
-- /absolute/path/to/.venv/bin/python -m tableau_public_authoring.server避免对已注册的服务器使用 uvx --from …:它从内容哈希缓存路径运行,该路径在依赖项发生变化时就会改变,而 macOS 权限授予与该路径绑定 - 因此服务器会在下次升级时悄悄失去辅助功能和屏幕录制权限。对于一次性使用(例如 uvx --from … tableau-public-authoring doctor)是可以的。
升级
uv tool upgrade tableau-public-authoring
tableau-public-authoring doctor构建工作簿
{
"spec_version": "0.1",
"workbook": { "name": "EV Charging Readiness", "description": "Generated" },
"data_sources": [{ "id": "sites", "type": "csv", "path": "/abs/path/sites.csv" }],
"calculated_fields": [{
"name": "Readiness Band", "data_source": "sites", "datatype": "string",
"formula": "IF [Readiness Score] >= 70 THEN \"High\" ELSE \"Low\" END"
}],
"worksheets": [{
"name": "Readiness by Site", "template": "bar", "data_source": "sites",
"rows": ["Site Name"],
"columns": [{ "field": "Readiness Score", "aggregation": "Sum" }],
"color": "Readiness Band",
"filters": ["Status"],
"title": "EV Charging Readiness by Site"
}],
"output": { "directory": "/abs/path/output", "package_twbx": true }
}路径可以是相对于单个 base_dir 的,而不是绝对路径 - 相对路径被限制在该目录内,而绝对路径则不然。参见 docs/AUTHORING_SPEC.md。
然后:validate_workbook_spec(试运行)→ build_workbook → validate_in_tableau_public → publish_to_tableau_public。
完整模式:schemas/workbook-spec-v0.1.json 和 docs/AUTHORING_SPEC.md。
为什么事情会是这样
这个代码库的大部分形态都是对 Tableau 实际行为的回应。docs/LIMITATIONS.md 列出了这些约束;docs/history/CHANGE_HISTORY.md 保留了发布说明,其中记录了每个修复所应对的失败以及证明其已修复的内容。docs/fixtures/ 保存了对一个真实已发布工作簿的取证分析,编译器正是从该工作簿逆向工程而来。
发布
publish_to_tableau_public 被标记为破坏性操作,并且需要 confirm_publish: true 和 profile(你的 Tableau Public 个人资料名称);overwrite 默认为 false。profile 是必需的,因为没有它,服务器无法检查同名工作簿是否已经在线,而 Tableau Public 会不可逆地替换同名工作簿,且没有版本历史。
它驱动可见命令,并且从不读取、输入或存储凭据 - 它使用你现有的已登录桌面会话。如果 Tableau 需要登录,该工具会停止并告诉你手动登录。发布是不可逆的,并且对全世界可见。
使用 dry_run: true 先查看确切会发生什么。
测试
uv run pytest # unit + integration (no Tableau needed)
uv run pytest -m live # requires Tableau Public installed
uv run ruff check . && uv run ruff format --check .live 和 publish 测试被排除在正常运行之外,并且绝不能在 CI 中运行。
安全
任何地方都不存储凭据。XML 通过 ElementTree 生成(绝不使用字符串拼接),归档受到 ZIP-slip 防护,路径经过遍历检查,生成的工作簿在打包前会扫描可识别机器的数据。参见 docs/SECURITY.md 和 docs/architecture/THREAT_MODEL.md。
回滚
claude mcp remove --scope user tableau-public-authoring这不会影响所有其他 MCP 服务器。
卸载
claude mcp remove tableau-public-authoring -s user
claude mcp list # your other servers should still be listed
rm -rf <this repo>/output # generated workbooks are inert local files任何已经发布的内容都必须由你在浏览器中从你的 Tableau Public 个人资料中删除。此服务器没有删除功能,这是设计使然:发布从它这一侧是不可逆的,这就是为什么它要求 confirm_publish,并且除非你传递 overwrite,否则会拒绝名称冲突。
许可证
MIT - 参见 LICENSE。
Available Tools
10 toolsbuild_workbookA
PRIMARY TOOL. Compile a specification into a .twb and packaged .twbx with Hyper extracts (required by Tableau Public). Writes files to the spec's output.directory. The .twb is byte-deterministic for an identical spec; the .twbx digest is not, because the embedded Hyper extract carries non-deterministic state.
| Name | Required | Description | Default |
|---|---|---|---|
| spec | Yes | Declarative description of a Tableau workbook to generate. Unknown properties are rejected everywhere. Generated from tableau_public_authoring.models.spec.spec_json_schema(); edit that function, never this file. Structural validation only - the server additionally checks cross-references, field existence and encoding compatibility, so a valid document here can still be rejected. | |
| overwrite | No | Replace files in the output directory that this server did not generate. Rebuilding the same workbook does not require it. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description must carry the full burden. It discloses that files are written to the spec's output directory and notes the determinism of .twb versus .twbx. However, it lacks details on authorization, overwrite behavior, error conditions, or prerequisites beyond the schema.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is three sentences, front-loaded with 'PRIMARY TOOL', and every sentence provides essential information (purpose, output location, determinism). No superfluous content.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the complexity of the input schema and the absence of an output schema and annotations, the description is minimal. It does not explain return values, error handling, the build process, or prerequisites, leaving the agent with potential gaps for correct invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100% with detailed descriptions for both parameters (spec and overwrite) and all nested properties. The tool description does not add additional meaning beyond what the schema already provides, so baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states it is the 'PRIMARY TOOL' and specifies the action 'Compile a specification into .twb and .twbx with Hyper extracts'. It distinguishes itself from sibling tools like validation, inspection, and publishing by its primary build role.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description labels the tool as 'PRIMARY' but does not provide explicit guidance on when to use it versus alternatives like validate_workbook_spec or inspect_local_workbook. No when-not-to or exclusions are mentioned.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_authoring_capabilitiesA
Report what this server can and cannot author, the detected Tableau Public installation, and the macOS permission state. Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Read-only behavior is mentioned, which is transparent given no annotations. However, the description does not elaborate on potential nuances like data freshness or permission requirements, leaving some ambiguity.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Single sentence with no fluff, front-loaded with purpose. Every word contributes meaning.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Adequate for a simple info tool, but lacks details on output format or the meaning of 'capabilities'. Given no output schema, more detail would improve completeness.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema has zero parameters with 100% coverage, so description adds value by explaining the output categories. Baseline of 4 is appropriate as it compensates for lack of output schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Description clearly states the tool reports three specific categories: authoring capabilities, Tableau Public installation, and macOS permission state. Verb 'report' and resource are specific and distinct from sibling tools which focus on workbook operations.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No explicit guidance on when to use this tool vs alternatives like 'get_tableau_public_app_status'. The read-only nature is noted but not contextualized relative to sibling tools.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_tableau_public_app_statusA
Report Tableau Public installation, version, running state, open windows and Accessibility permission. Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries full responsibility. It explicitly states 'Read-only' and enumerates five specific aspects reported. It does not discuss prerequisites or error conditions, but for a status tool, this is sufficient.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence with front-loaded content. Every word adds value: 'Report', the list of items, and 'Read-only'. No redundancy or filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no output schema, the description lists the reported items without specifying return format. This is adequate for an agent to understand what will be provided. Slightly incomplete as it doesn't mention failure modes or format, but acceptable for a status tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
There are no parameters, so schema coverage is 100% trivially. The description does not need to add parameter info. According to calibration, 0 parameters merits a baseline of 4.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb 'report' and specific resources: installation, version, running state, open windows, and Accessibility permission. It distinguishes from siblings by focusing on status information rather than authoring or publishing.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description includes 'Read-only' which implies safe usage without side effects. While it does not explicitly list when to use vs alternatives, the context is clear among sibling tools. Slightly lacking explicit when-not or alternative references.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
inspect_local_workbookA
Safely inspect a local .twbx archive's contents. Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
| path | Yes | Absolute .twbx path |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description states safety and read-only nature but omits exactly what 'contents' means (e.g., file list vs metadata) and error behavior. Adequate but minimal.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences front-load the purpose and behavior, with zero waste. Ideal conciseness for a simple tool.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
No output schema exists, yet the description does not explain the return format or data. For a read-only inspection tool, the output is a critical missing piece.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema covers 100% of parameters with clear description ('Absolute .twbx path'). The tool description adds no extra parameter meaning beyond the schema, so baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly identifies the resource (local .twbx archive) and action (inspect contents), with 'Read-only' distinguishing it from mutation tools like build_workbook or publish_to_tableau_public.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
'Safely inspect' and 'Read-only' imply usage for examining archives without modification. No explicit alternatives or exclusions, but the context from siblings makes the intended use clear.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_workbook_templatesA
List supported worksheet templates and their required shelves. Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Only states 'Read-only' as behavioral info. No annotations exist, so description should disclose more (e.g., if requires auth, any side effects). Minimal for a no-annotation tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Single sentence, no waste. Essential info is front-loaded. Efficient for a simple list tool.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Describes output sufficiently for a parameterless list tool. Lacks mention of how output can be used with sibling tools (e.g., building a workbook), but given simplicity, adequate.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
No parameters, so schema coverage is 100%. Description adds context about return values (required shelves), which enhances understanding beyond the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States exact action (list) and resource (supported worksheet templates) with output details (required shelves). Clearly distinguishes from sibling tools that validate, build, or publish.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance on when to use or alternatives. With siblings like get_authoring_capabilities and validate_workbook_spec, the description provides no context for selection.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
open_in_tableau_publicA
Open a generated workbook in Tableau Public and wait for its window. Returns the load error verbatim if Tableau rejects the file.
| Name | Required | Description | Default |
|---|---|---|---|
| path | Yes | Absolute .twb or .twbx path | |
| timeout_s | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description does well to disclose key behaviors: it waits for the window and returns error verbatim. However, it does not explicitly state whether the tool modifies the workbook or the Tableau environment, though 'open' implies read-only. The waiting behavior is clearly mentioned.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences with no wasted words. It front-loads the main action and immediately provides additional context about waiting and error handling.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool with 2 parameters and no output schema, the description covers the essential behavior: opening a workbook, waiting for the window, and returning errors. It is slightly ambiguous about what happens on success (presumably returns nothing or success indicator), but overall adequate.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The description adds no additional meaning to the parameters beyond what the input schema provides. The path parameter is already described as 'Absolute .twb or .twbx path' in the schema, and timeout_s has default/min/max bounds. The description's mention of 'Open a generated workbook' implicitly references the path but does not enhance parameter understanding.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action ('open'), the resource ('generated workbook in Tableau Public'), and the specific behavior ('wait for its window', 'returns load error verbatim'). It distinguishes from sibling tools like 'publish_to_tableau_public' or 'validate_in_tableau_public' by focusing on opening and waiting.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies the tool is for opening a generated workbook, but lacks explicit guidance on when to use it versus alternatives like 'validate_in_tableau_public' or 'publish_to_tableau_public'. No when-not or exclusions provided.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
publish_to_tableau_publicA
DESTRUCTIVE / PUBLIC. Publish an open workbook to the user's Tableau Public account through the visible Server > Tableau Public > Save to Tableau Public workflow. Publication is irreversible and world-visible. Requires confirm_publish=true. Never reads credentials; pauses for manual sign-in if required.
| Name | Required | Description | Default |
|---|---|---|---|
| dry_run | No | Report what would happen without publishing. | |
| profile | Yes | Your Tableau Public profile name. Required to resolve and verify the resulting public URL after publication. | |
| overwrite | No | Allow overwriting an existing workbook of the same name. | |
| set_title | No | Type public_name into the dialog's Workbook Title field. If false, Tableau's pre-filled title (from the file name) is kept. | |
| public_name | Yes | Name for the published workbook (must be unique) | |
| workbook_path | No | Absolute path to the .twbx being published. Optional but recommended: it lets a minimized workbook be raised reliably with `open -a` instead of a coordinate click. | |
| screenshot_dir | No | ||
| confirm_publish | Yes | Must be true. Guards against accidental publication. | |
| workbook_window | Yes | The open workbook's exact name (its window title without the 'Tableau Public - ' prefix). Matched exactly, not as a substring, because publishing is irreversible: a substring match would let 'Q3_Sales' publish 'Q3_Sales_Draft'. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden. It explicitly labels the action as 'DESTRUCTIVE / PUBLIC,' states 'Publication is irreversible and world-visible,' highlights the guard (confirm_publish=true), and discloses manual sign-in behavior. This is comprehensive, though it could mention error handling or failure modes.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences: the first focuses on purpose and danger, the second on key details (irreversibility, guard, credential handling). No waste, front-loaded with the most critical information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a destructive 9-parameter tool with no output schema, the description covers the essential aspects: irreversible publication, required guard, credential handling, and exact window name matching. It could mention return behavior or failure scenarios, but it is sufficiently complete for safe usage.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 89%, so the schema already documents most parameters. The description adds little beyond what's in the schema (e.g., reiterates confirm_publish must be true and workbook_window exact matching). Baseline 3 is appropriate as it does not need to compensate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description starts with 'DESTRUCTIVE / PUBLIC. Publish an open workbook to the user's Tableau Public account...' and clearly distinguishes the tool from siblings like validate_workbook_spec or verify_published_workbook. The verb 'Publish' and resource 'open workbook to Tableau Public' are precise.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description states 'Requires confirm_publish=true' and 'Never reads credentials; pauses for manual sign-in if required,' providing clear usage context. However, it does not explicitly state when not to use the tool or suggest alternatives among the sibling tools.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
validate_in_tableau_publicC
Layer 3+4 validation: open the workbook in Tableau Public, detect error dialogs, and capture a screenshot proving rendered content.
| Name | Required | Description | Default |
|---|---|---|---|
| path | Yes | ||
| settle_s | No | ||
| screenshot_dir | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries full burden. It states it opens the workbook and detects error dialogs, but fails to disclose behavioral aspects such as whether the tool modifies the workbook, whether it requires user interaction, how long it takes, or what happens to the screenshot after capture. The lack of side-effect clarity (e.g., destructive hint) is a significant gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, front-loaded sentence that efficiently conveys the main purpose. However, it sacrifices necessary detail for brevity, leaving parameter semantics and usage unspecified.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool has 3 parameters, no output schema, and no annotations, the description is incomplete. It does not explain 'Layer 3+4', what constitutes an error dialog, or how the screenshot is returned. The agent would need external context to use it correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, and the description does not explain any of the three parameters (path, settle_s, screenshot_dir). The term 'settle_s' is ambiguous (likely a delay), and 'screenshot_dir' is not described. Without any clarification, the agent cannot correctly provide values.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the specific purpose: 'Layer 3+4 validation: open the workbook in Tableau Public, detect error dialogs, and capture a screenshot proving rendered content.' It uses a specific verb (validate) and resource (workbook in Tableau Public), and distinguishes from related siblings like 'open_in_tableau_public' and 'verify_published_workbook' by defining its unique validation layer.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is provided on when to use this tool versus alternatives. The description does not mention prerequisites, when not to use it, or how it differs from sibling validation tools like 'validate_workbook_spec' or 'verify_published_workbook'.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
validate_workbook_specA
Validate an authoring specification without writing any files (dry run). Returns actionable errors. Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
| spec | Yes | Declarative description of a Tableau workbook to generate. Unknown properties are rejected everywhere. Generated from tableau_public_authoring.models.spec.spec_json_schema(); edit that function, never this file. Structural validation only - the server additionally checks cross-references, field existence and encoding compatibility, so a valid document here can still be rejected. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the burden and discloses key behaviors: no files written (dry run) and read-only. It also mentions returning actionable errors. This is sufficient for a validation tool, though it omits details on rate limits or performance.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences with zero waste. First sentence states the verb and resource; second adds key behavioral traits. Ideal conciseness.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Adequate for a simple tool, but lacks detail on output format of 'actionable errors' and prerequisites (e.g., valid JSON schema). Could be more complete given the complex spec parameter.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% with embedded descriptions for the single parameter 'spec'. The tool description adds only the dry-run context, not parameter-specific meaning, so baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool validates an authoring specification as a dry run, being read-only. It distinguishes from the build tool but does not explicitly differentiate from the sibling 'validate_in_tableau_public', which may also validate.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies use as a pre-build check (dry run) but provides no explicit guidance on when to use this versus alternatives like 'validate_in_tableau_public' or when not to use it.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
verify_published_workbookB
Layer 5 validation: load a public Tableau URL and confirm it responds. Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
| url | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
States it is read-only, which is crucial for safety. However, with no annotations provided, the description should disclose more behavioral traits such as error handling, timeout behavior, or what constitutes a successful response. The current description is minimal.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is extremely concise, using a single sentence. It is front-loaded with 'Layer 5 validation', which may be jargon, but overall the structure is efficient. Could be slightly improved by moving the important 'read-only' claim earlier.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's simplicity (one parameter, no output schema), the description covers the basic action but lacks completeness. It does not explain what 'confirms it responds' means (e.g., HTTP status 200) nor how the output signals success or failure. Also fails to differentiate from siblings.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The only parameter 'url' receives minimal additional meaning: it is described as a 'public Tableau URL'. With 0% schema description coverage, this is insufficient. The description should specify expected format (e.g., must start with 'https://public.tableau.com'), but does not.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool loads a public Tableau URL and confirms a response. It identifies the resource (public Tableau URL) and action (verify). However, it does not explicitly differentiate from sibling tools like validate_in_tableau_public, which may perform similar checks, and the jargon 'Layer 5 validation' is not explained.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Implies usage for verifying a published workbook is accessible, but provides no guidance on when to use this tool over alternatives (e.g., validate_in_tableau_public). No exclusions or prerequisites are mentioned, leaving the agent to infer context.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
10 tool updates
v0.1.0- First observed
build_workbook - First observed
get_authoring_capabilities - First observed
get_tableau_public_app_status - First observed
inspect_local_workbook - First observed
list_workbook_templates - First observed
open_in_tableau_public - First observed
publish_to_tableau_public - First observed
validate_in_tableau_public - First observed
validate_workbook_spec - First observed
verify_published_workbook
TDQS
Each tool has a clearly distinct purpose: capabilities, templates, validation, building, inspection, app status, opening, in-app validation, publishing, and verification. No two tools overlap in function, and descriptions clearly differentiate them.
All tool names follow a consistent verb_noun pattern using snake_case (e.g., get_authoring_capabilities, build_workbook, publish_to_tableau_public). No mixing of conventions, and verbs clearly indicate the action.
Ten tools is well-scoped for the domain of authoring and publishing Tableau Public workbooks. Each tool serves a necessary step in the workflow, from capability reporting to verification.
The tool set covers the full authoring and publishing lifecycle: capabilities, templates, dry-run validation, building, local inspection, app status, opening, in-app validation, publishing, and web verification. No obvious gaps for the stated purpose.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Generate Tableau .twb/.twbx workbooks: 47 tools for charts, dashboards, rules, CSV pipelines.
Formula-backed WorkPaper tools for workbook readback, input edits, and JSON persistence.
Excel analytics: inspect, query (JSON rows), charts, and JSON-to-xlsx workbook writing.
Validate, build, and publish the resume you keep as YAML in your own GitHub repository.
Related MCP Servers
- FlicenseNot gradedqualityNot gradedmaintenanceEnables discovery, querying, and exporting of Tableau Cloud dashboards and data sources. Supports searching workbooks, filtering data, and exporting views as PDF, PNG, PowerPoint, CSV, or JSON.-
- FlicenseAqualityBmaintenanceMCP server that automates the publishing and validation of Tableau workbooks and data sources on Tableau Server or Tableau Cloud, enabling an AI agent to discover, build, validate, and publish content without human intervention.10-
- FlicenseNot gradedqualityBmaintenanceBuilds importable RUCKUS One Data Studio dashboards from a declarative spec, enabling users to create valid dashboards without learning Superset internals or guessing field names.2-
- AlicenseNot gradedqualityCmaintenanceAudits local Tableau workbooks for unused assets, duplicate worksheets, and dashboard weight, providing cleanup reports and health summaries.MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/andyyaro/tableau-public-authoring-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server