New · Open source

AKKO open-sources its Trino MCP server.

A governed MCP server for Trino under the Apache 2.0 licence: every call from an AI agent carries the identity of the person, the engine decides. Code, tests and replayable proofs are on GitHub, the package on PyPI.

See the code on GitHubRead the documentation

$ pip install akko-mcp-trino
Successfully installed akko-mcp-trino-0.3.0

Star on GitHubPyPI · The article

IDENTITY PROVIDERKeycloak, any OIDCtoken of the personMCP HOSTS AND MODELSClaude CodeCursorMistralLangGraphany MCP hostakko-mcp-trinoApache 2.0 · MCP serveridentity verified (JWT)read only, on the SQL treequotas and revocationaudit, never the tokenTrinounder the identity of the personSOURCESPostgreSQLHive IcebergSnowflakeBigQueryOraOracleSQLSQL ServerMySQLMongoDBKafkaClickHouseDelta Lakethrough the Trino connectors,row filters and column masks applyjetonSQL

Built on the technologies you know

  • Trino
  • Apache Iceberg
  • OpenMetadata
  • Apache Airflow
  • Apache Spark
  • Apache Superset
  • JupyterHub
  • MLflow
  • Keycloak
  • Open Policy Agent
  • Kubernetes
  • OpenShift
  • PostgreSQL
  • OpenSearch
  • Ollama
  • vLLM

Federation

Start by federating, without moving your data.

Your data stays in PostgreSQL, Hive or Iceberg. AKKO exposes it through a single Trino engine: one SQL query, several sources, one result. Only the requested rows travel.

Every query runs under the identity of the signed-in person. Row and column rules apply at query time, across every source, and every execution is logged.

The catalogue fills up as you federate: NORA suggests descriptions and flags what is missing. When a source deserves a copy, Iceberg and Airflow take over, on your team's decision.

WITH COPYPostgreSQL · customersHive · salesIceberg · logsETLCopied warehouseyesterdayDashboardThree copies to maintain.Rights copied by hand.Yesterday's data.WITHOUT COPY, WITH AKKOIN PLACE, WITH YOUPostgreSQL · customersHive · salesIceberg · logsSELECTFROM pg.clients JOIN hive.ventesSQL engineTrino, under the identity of the personNotebook, BIor ADENNo copy.Rights applied by the engine, on every query.The data at the moment of the question.

What AKKO installs on your side

Nine layers, one cockpit, one identity.

Each layer is an open component you know, installed and wired by AKKO, replaceable by what you already have. The cockpit brings them together; the identity of the signed-in person runs through all of them.

Identity and access

One identity, from the directory to the engine. Row filters and column masks per group.

ComponentsKeycloak, LDAP or your Active Directory, OPA or Ranger

Cockpit AKKO, accès aux données : politiques par catalogue et par groupe

Sovereignty

Sovereignty, in concrete terms.

Built in France
AKKO is a French company. The platform is developed in France.
Hosted with you
The platform, the default AI models, the indexes and the logs run in your cluster. No data passes through AKKO.
Identity end to end
Your directory remains the source of accounts and groups; data rights are expressed per group and apply down to the query, including the assistant's answers.
Reversibility
Open formats (Iceberg, Parquet), an OpenMetadata catalogue, a Trino engine: your data and metadata can be read back with tools you do not buy from AKKO.

Deployment

AKKO installs with you, wherever your Kubernetes is.

One Helm chart, one values file per environment, the same result everywhere. The targets below are the ones we have installed and tested; we do not list others.

helm install akkoDATA CENTREYour serversbare metal or virtualisedSOVEREIGN CLOUDThe host of your choicein your accountEXISTING KUBERNETESYour cluster, your operatorsk3s in demonstration; OpenShift under validationNO INTERNET ACCESSIsolated networkembedded images and chartsSAME CHART · SAME IMAGES · SAME IDENTITY

Ecosystem

What AKKO connects to.

AKKO installs on what exists and federates it: a Kerberised Hadoop cluster with Ranger and Knox, an ODP or OKDP distribution, a corporate directory, databases and lakes in place, sovereign models running on your side.

Where it runs

  • Kubernetes
  • OpenShift
  • OVHcloud
  • Scaleway
  • Any managed Kubernetes

Existing Hadoop estates

  • Cloudera
  • Kerberos
  • Apache Ranger
  • Apache Knox
  • Hive Metastore
  • ODP (Clemlab)
  • OKDP (TOSIT)

Data sources

  • PostgreSQL
  • Apache Iceberg
  • Apache Hive
  • MinIO / S3
  • MySQL
  • Oracle
  • ClickHouse
  • MongoDB
  • Cassandra
  • Elasticsearch
  • Kafka
  • Delta Lake

Identity

  • Keycloak
  • LDAP
  • Active Directory
  • Kerberos
  • Open Policy Agent
  • Apache Ranger

Models

  • Mistral
  • Ollama
  • vLLM
  • Qwen
  • Any OpenAI-compatible endpoint

Catalogue and observability

  • OpenMetadata
  • OpenSearch
  • Prometheus

Sovereign AI

Connect your federated sources with Trino, query them with Mistral.

ADEN puts the question to a model and runs the SQL on the federated engine, under the identity of the person. The model is the one you choose: Mistral, Qwen or DeepSeek running in your cluster with Ollama or vLLM, or the API of Mistral AI, a French company. Every answer comes with its chart, its SQL, its steps and the name of the model that produced it.

  1. PostgreSQL · Hive · Iceberg
  2. Trino
  3. ADEN
  4. Mistral · Qwen · DeepSeek
ADEN, choix du modèle
The choice of model, per question or automatic.
ADEN, réponse de mistral-small avec graphique et SQL
An answer from mistral-small: chart, interpretation, executed SQL.
ADEN, les étapes de la réponse
The nine steps of the answer, from resolved rights to the confidence score.

Governed AI

The same question, two accounts, two answers.

ADEN turns a question into SQL and runs it under the identity of the person asking. That person's row filters and column masks apply, as they do for a dashboard or a notebook. Below, the same question asked by an analyst and by an administrator.

ADEN, carol_analyst
carol_analyst sees masked emails and only the scope she is allowed: “1 column masked”.
ADEN, alice_admin
alice_admin sees the emails in clear: “no column masked”. Same question, same SQL, same engine.
ADEN, steps of an answer
Every answer shows its steps: access rights resolved, tables allowed by the policy, generated SQL, confidence score. The reasoning can be exported.

External agents

Cursor, Claude Code or a Mistral agent on your data, under the same rules.

An agent wired with a technical account reads everything; the only guardrail left is the prompt. The akko-mcp-trino brick carries the person's token down to Trino, refuses any write, applies quotas and revocation, and logs every call without ever keeping the token. It installs on its own, on the Trino you already have, with your directory.

tests/proofs/akko-mcp-trino-live-proof.sh
== 3. Verifications depuis le pod ==-- RFC 9728OK    metadonnees sans jeton200OK    authorization_servers = emetteurhttps://keycloak…/realms/akkoOK    401 porte resource_metadataTrue-- double identiteOK    sans cle agent : refus nomme401/agent_key_missingOK    cle inconnue : refus nommeagent_key_unknownOK    cle ok, sans jeton401/unauthenticatedOK    jeton forge401-- deux comptes, deux reponses (core_postgres.clients.customers)OK    alice : emails en clairTrue (6 lignes)OK    carol : emails masquesTrue (3 lignes)OK    carol : pays["FR"]-- quotasOK    429 une fois la fenetre pleineTrueOK    Retry-After + raisonrate_limited/N-- revocationOK    jeton deconnecte refuse401/revoked-- jointure d'audit (journal du pod)OK    ligne d'audit aliceexecute_query alice_admin cursor True TrueOK    jamais le jeton dans l'audit0== PREUVE OK ==  21/21

The proofs are published with the code: eight replayable scenarios against a real cluster, from the nominal case to adversarial ones, including a Mistral agent and Claude Code as host.

  • 21/21 functional
  • 35/35 adversarial
  • 10/10 Mistral agent
  • 7/7 real host
  • 8/8 JWT passthrough
  • 26/26 context and catalogue

260 tests, 100% line and branch coverage.

The proofs in detail

Open source

Discover our open source bricks.

akko-mcp-trino is published today under the Apache 2.0 licence, on PyPI and GitHub. akko-lab will be open-sourced soon. The AKKO platform is distributed under an enterprise licence. The building blocks it relies on (Trino, Iceberg, OpenMetadata, Airflow, Spark, Superset, JupyterHub, MLflow) are open source projects that we do not fork.

0.3.0 · Apache 2.0

akko-mcp-trino

Governed MCP server for Trino: end-to-end identity, read only, quotas, audit, catalogue context.

PyPI · image · Python 3.12 and 3.13
Open source soon

akko-lab

The platform lab: notebooks, code environments and models, with data access governed like everything else.

Planned

Identity broker

Token exchange between providers (RFC 8693) to carry identity across several directories and engines.

Planned

Policy sync

A classification set in the catalogue becomes a policy in Ranger, and a refusal in the engine.

Who it is for

Three situations where AKKO gets installed.

A complete platform, on your side

You start from an ageing Hadoop distribution or from nothing, and you want a whole data and AI platform on your Kubernetes, including without Internet access, with your directory. The platform

An AI that answers under your rules

You already have governed data and you want a model to answer on it without ever reading what is forbidden, with an audit receipt per question and models running on your side by default. ADEN and NORA

External agents on an existing Trino

You have a governed Trino, on ODP, Cloudera or Kubernetes, and you are asked for Cursor, Claude Code or an in-house agent on top of it. The answer fits in one command and is checked with another. akko-mcp-trino

Blog

What we learn while building AKKO.

Let us talk about your infrastructure.

A technical conversation about your Kubernetes, your directory, your engines and your rules. Or install a brick and tell us what is missing.

Request a demonstration The source code

contact@akko-ai.com