Server data from the Official MCP Registry
MCP server for LINDAS — the Swiss administration's linked-data SPARQL knowledge graph (cube.link)
MCP server for LINDAS — the Swiss administration's linked-data SPARQL knowledge graph (cube.link)
Valid MCP server (0 strong, 4 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry. Trust signals: trusted author (40/41 approved).
6 files analyzed · 1 issue found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
This plugin requests these system permissions. Most are normal for its category.
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-malkreide-lindas-mcp": {
"args": [
"lindas-mcp"
],
"command": "uvx"
}
}
}From the project's GitHub README.
Part of the Swiss Public Data MCP Portfolio — a collection of open-source MCP servers connecting AI agents to Swiss public and open data. This is a private project. It is not affiliated with, endorsed by, or operated on behalf of any employer or public authority.
MCP server for LINDAS — the linked-data knowledge graph of the Swiss administration.
LINDAS (Linked Data Service) is the Swiss Confederation's SPARQL knowledge graph, run by the Federal Archives. Instead of tables, it publishes data as RDF triples: around 2000 statistical data cubes (cube.link) from federal offices, plus the geo-linked data that powers visualize.admin.ch.
Mnemonic: «I14Y is the library catalogue, LINDAS is the library itself.» i14y-mcp tells you a dataset exists. LINDAS holds the data and lets you query across all of it at once.
This server wraps LINDAS in guarded tools rather than exposing raw SPARQL, because the store rewards precise queries and times out on broad ones.
«Which forest-fire danger level currently applies, who publishes it, and under which licence?»
search_cubes(query="waldbrand")
→ «Waldbrandgefahr» — BAFU, published
get_cube_structure(cube_uri=...)
→ dimensions: Warnregion (key), Gefahrenstufe (measure)
→ licence: fedlex.data.admin.ch/eli/cc/1984/... (a Fedlex URI!)
query_cube_observations(cube_uri=...)
→ Warnregion: "Dorneck / Thierstein (SO)", Gefahrenstufe: "grosse Gefahr"
The codes come back as labels — «grosse Gefahr», not 4. And the licence is a
Fedlex URI you can resolve with fedlex-mcp.
LINDAS cubes are self-describing but coded. Reading them well means two steps, which this server enforces:
get_cube_structure reads the cube's SHACL shape: its
dimensions (filterable axes), its measures (the numbers), and which
dimensions carry code lists.query_cube_observations reads the observations and
resolves coded values to human labels using the structure from step 1.Mnemonic: «LINDAS speaks in postcodes, not place names.» An observation says region
1805; the server turns that into «Alpennordhang» for you.
┌──────────────────────────────┐
│ MCP Host (Claude) │
└───────────────┬──────────────┘
│ stdio | streamable-http
┌───────────────▼──────────────┐
│ lindas-mcp │
│ ┌────────────────────────┐ │
│ │ server.py (7 tools) │ │ talks only to cube.py
│ ├────────────────────────┤ │
│ │ lindas/cube.py │ │ ← vocabulary guardrail,
│ │ │ │ two-phase access,
│ │ │ │ code→label resolution
│ ├────────────────────────┤ │
│ │ lindas/queries.py │ │ SPARQL templates,
│ │ │ │ all anchored on a class
│ ├────────────────────────┤ │
│ │ lindas/client.py │ │ raw SPARQL over HTTP,
│ │ │ │ knows nothing of cubes
│ └────────────────────────┘ │
└───────────────┬──────────────┘
│ HTTPS, no auth
┌───────────────▼──────────────┐
│ lindas.admin.ch/query │
│ SPARQL 1.1 · ~2000 cubes │
└──────────────────────────────┘
The lindas/ package is deliberately layered so it can be lifted into other
LINDAS-backed servers unchanged. client.py knows only HTTP and SPARQL;
cube.py knows the cube.link vocabulary; the tools know only cube.py. Raw
SPARQL never reaches the agent except through the guarded run_sparql escape
hatch.
Architecture A (live SPARQL only), with a strict vocabulary guardrail.
Verified live on 2026-07-21:
SELECT *, COUNT(*) over the whole store) time out at
60–90 s; the same question anchored on ?x a cube:Cube answers in ~2 s.Consequences, baked into the tools:
run_sparql is capped at 500 rows and 30 s and marked as advanced.Full probe report: docs/probe-lindas.md.
| Tool | Purpose |
|---|---|
search_cubes | Find cubes by topic. Entry point. Deduplicates versions. |
get_cube_structure | Phase 1: dimensions, measures, licence. |
query_cube_observations | Phase 2: data points with codes resolved to labels. |
list_publishers | Federal bodies publishing cubes, with counts. |
resolve_municipality | Name ↔ URI ↔ BFS number — the portfolio join key. |
run_sparql | Advanced escape hatch. Capped, guarded. |
api_status | Reachability check with cube count. |
All tools are annotated readOnlyHint: true.
uvx lindas-mcp
{
"mcpServers": {
"lindas": {
"command": "uvx",
"args": ["lindas-mcp"]
}
}
}
LINDAS_MCP_TRANSPORT=sse PORT=8000 lindas-mcp
LINDAS_MCP_TRANSPORT accepts stdio (default), sse or streamable-http.
The SSE / streamable-http transport binds to HOST, default 127.0.0.1;
set HOST=0.0.0.0 explicitly to expose it (only behind a reverse proxy). For a
hosted HTTP deployment, set ALLOWED_ORIGINS to a comma-separated list of
browser origins (default *), and LOG_LEVEL to tune the JSON stderr logs.
docker compose up --build # binds 0.0.0.0 inside the container, publishes :8000
The image runs as a non-root user, read-only, with resource limits and a
TCP health check (see Dockerfile and compose.yaml).
LINDAS is a connector layer, and two of its identifiers make it composable with the rest of the portfolio:
| Key | Where | Joins to |
|---|---|---|
| BFS commune number | resolve_municipality → bfs_number | swiss-statistics-mcp, zurich-opendata-mcp |
| Fedlex URI | cube licence field | fedlex-mcp |
The Fedlex link is the quiet surprise: many cubes declare their licence as a
legal-basis URI (fedlex.data.admin.ch/eli/cc/...), so you can go from a data
point straight to the law that governs it.
Verified live on 2026-07-21.
run_sparql warns about it and caps runtime.resolve_labels=False to skip it.query_cube_observations reads the first N observations. Analytical slicing
belongs in run_sparql.dcterms:license, frequently
a Fedlex URI rather than a plain name. Always surface the licence field.search_cubes deduplicates by stripping
the version suffix from the cube URI and keeping the highest schema:version
among published cubes. Unusual URI shapes may not collapse cleanly; use
latest_only=False to inspect every version.PYTHONPATH=src pytest tests/ -m "not live" # offline, used in CI
PYTHONPATH=src pytest tests/ -m "live" # hits the real endpoint
python -m ruff check src tests
The live tests earn their place: the observationSet indirection (a cube's
observations hang off cube:observationSet, never directly off the cube) is a
structural assumption that a mock cannot validate. It is covered by a live test.
See CONTRIBUTING.md for the ground rules (read-only, one
egress host, anchored queries) and the local dev loop. Further reading:
EXAMPLES.md for use cases by audience with the tool-selection
table, docs/roadmap.md for the project phase, and
PUBLISHING.md for the PyPI / MCP Registry release process.
See SECURITY.md for the security posture and how to report a
vulnerability.
MIT License — see LICENSE. The LINDAS data remains subject to the licence each publisher declares on the cube.
Hayal Oezkan · github.com/malkreide
Licence: MIT. The cube data remains subject to the licence each publisher declares.
Ownership marker used by the MCP Registry to link this PyPI package to the GitHub namespace:
mcp-name: io.github.malkreide/lindas-mcp
The negotiated MCP protocol version is managed by the pinned mcp SDK
(mcp>=1.28.1 in pyproject.toml), which Dependabot keeps current. SDK upgrades
are therefore a reviewed change: any protocol-affecting bump is called out in
CHANGELOG.md, and the tool contract is guarded independently by
tool-definitions.lock.json (SEC-022) so a change to the tool surface fails CI
until reviewed.
Be the first to review this server!
by Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
by Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
by Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.