orionbelt-semantic-layer-mcp
MCP server for the OrionBelt Semantic Layer. Enables LLMs to explore semantic models, compile queries, and execute analytics via natural language. Works with Claude, Cursor, Windsurf, Copilot.
Install / Use
claude mcp add ralforion -- npx -y github:ralforion/orionbelt-semantic-layer-mcpIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
AI & Machine LearningSupported Platforms
Our assessment of orionbelt-semantic-layer-mcp
orionbelt-semantic-layer-mcp scores 83/100 on our quality scale, 531st of 841 AI & Machine Learning skills we index.
Its MCP Server is 35 KB long, well organised into 42 sections with 15 code examples: a thorough specification that gives an agent plenty to work with.
It has 3 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated yesterday, so orionbelt-semantic-layer-mcp is actively maintained.
- Our last check on 2026-09-12 found the source still online.
- It is released under the Apache-2.0 license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 92/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.
AI review by kimi-k2.7-code on 2026-09-24. Automated pattern scan on 2026-09-24. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
orionbelt-semantic-layer-mcp compared with similar skills
All 4 of these similar skills score higher than orionbelt-semantic-layer-mcp; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| orionbelt-semantic-layer-mcp (this skill)by ralforion | 83 | 3 | 1d ago | MCP Server |
| claude-memby thedotmack | 100 | 94.9k | today | CLAUDE.md |
| Agent-Reachby Panniantong | 100 | 86.2k | 14d ago | CLAUDE.md |
| Understand-Anythingby Egonex-AI | 100 | 84.7k | 1d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.1k | today | CLAUDE.md |
Frequently asked questions
- How do I install orionbelt-semantic-layer-mcp?
- Run
claude mcp add ralforion -- npx -y github:ralforion/orionbelt-semantic-layer-mcp. The install tabs above show the steps for each supported agent. - Which AI agents does orionbelt-semantic-layer-mcp work with?
- It is written for Claude Code, Claude Desktop, Cursor, GitHub Copilot and Windsurf, as a MCP Server file. Other agents that read the same format can often use it too.
- Is orionbelt-semantic-layer-mcp safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It is Apache-2.0-licensed and scores 92/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is orionbelt-semantic-layer-mcp still maintained?
- The repository was last updated yesterday, so orionbelt-semantic-layer-mcp is actively maintained.
Skill content
View source on GitHubA thin MCP server that delegates all business logic to the OrionBelt® Semantic Layer REST API via HTTP. No embedded engine — pure API pass-through.
Architecture
The OrionBelt® Semantic Layer platform has two deployment modes. This MCP server supports both:
- Standalone — Deploy the OrionBelt® Semantic Layer API anywhere (Cloud Run, Docker, localhost) and point this MCP server at it via
API_BASE_URL. - Hosted — Connect to the public Cloud Run deployment with zero local setup (see Hosted MCP Server below).
┌────────────┐ ┌──────────────────────────────────────────────────────┐
│ LLM Client │ │ OrionBelt® Platform │
│ │ │ │
│ Claude, │──MCP──│──> server.py ──HTTP /v1──> Semantic Layer REST API │
│ Cursor, │ │ (FastMCP (FastAPI: parse OBML, │
│ any MCP │ │ + httpx) validate, compile │
│ client │ │ to SQL) │
└────────────┘ └──────────────────────────────────────────────────────┘
- No business logic — all tool calls delegate to the REST API (v1 endpoints)
- Dual-mode — auto-detects single-model or multi-model API mode at startup
- Auto-session management — creates an API session on first tool call, caches the ID (multi-model mode)
- 24 tools (single-model mode) or 28 tools (multi-model mode) for querying (QueryObject), execution, batch, discovery, composability (ACR), examples, diagrams, RDF/SPARQL, business rules (list, explain, evaluate), ontology links (concept mappings, namespaces, unmapped artefacts), OSI export, model validation (offline or against the live datasource), and OBML reference + function catalog + JSON schemas. (29 distinct tools exist in total; the API mode selects which subset is active — they overlap in 23 — and no client ever sees all 29 at once.) The visible surface is narrowed further in the design-time phase and when query execution is disabled (see Design-time vs run-time tool switching)
- 5 prompts + 2 resources for OBML / OBSQL reference, business rules, and usage guidance
Live Demo
A public demo of the OrionBelt® Semantic Layer API is available at:
API endpoint:
https://orionbelt.ralforion.com— Swagger UI | ReDoc | Gradio UI
Set API_BASE_URL=https://orionbelt.ralforion.com in your .env file to use it (see .env.example).
Installation
uv sync
For development (includes pytest, respx, ruff):
uv sync --all-groups
Usage
stdio (default)
uv run server.py
HTTP transport
MCP_TRANSPORT=http uv run python server.py
The HTTP transport runs stateless by default (MCP_STATELESS_HTTP=true):
every request is self-contained, with no Mcp-Session-Id, no stream
resumability, and no server-initiated messages. Nothing here needs that state —
the tool phase is derived from explicit loaded-model state rather than from the
connection, and no tool sends progress, sampling, or elicitation requests — so
instances can sit behind a load balancer without session affinity. Set
MCP_STATELESS_HTTP=false to restore per-connection sessions; sse always runs
stateful, since it is a long-lived per-connection stream.
Note this is the transport session only. The upstream API session and the set of loaded models remain process-global and shared by every client of an instance, unchanged by this flag.
Transport security
The HTTP/SSE transport terminates no TLS and authenticates no caller — it expects an ingress in front that does both. These are two separate jobs, and no platform does both for you by default.
On Cloud Run, the intended deployment, TLS is automatic: the service URL is
served over HTTPS and plain HTTP is forwarded to the container. Access control
is not. It is a deploy-time choice, settled any of three ways — IAM invoker
permission, an --ingress restriction, or an authenticating load balancer in
front. With none of them, --allow-unauthenticated leaves the service reachable
by anyone who learns its URL, over HTTPS, with no credential required. Encrypted
is not the same as restricted.
This matters because the two hops have different answers:
| Hop | Security |
| --- | --- |
| MCP client → this server | stdio: pipes to a child process, no socket at all. http/sse: whatever the ingress in front provides — nothing if there is none |
| This server → the API | TLS whenever API_BASE_URL is https:// (the default), with certificates verified against httpx's default CA bundle (certifi), or against API_CA_CERT for a private CA; API_CLIENT_CERT adds a client certificate for mutual TLS. There is no verify=False and no way to disable it short of an http:// URL |
Exposing the HTTP transport directly is the case to avoid. Anything that can
reach the port can call every registered tool — including execute_query where
the capability is enabled — spending this server's own API_KEY against the
API, over a channel readable in transit. The credential never crosses that hop;
the access it buys does.
The server warns at startup when it detects this: an http/sse transport
bound to a non-loopback address, off Cloud Run, without MCP_BEHIND_PROXY=true.
Bind MCP_SERVER_HOST to loopback, put an authenticating TLS ingress in front,
or set MCP_BEHIND_PROXY=true to acknowledge a proxy the server has no way to
see.
On Cloud Run it logs an informational note instead of that warning, naming the
half that is still yours: TLS is handled, access control is whatever you
deployed with. Silence there is not evidence the service is restricted — the
process cannot read its own IAM policy or ingress setting. Confirm one of the
three above is in place; if one is, MCP_BEHIND_PROXY=true records that and
silences the note.
The API's own
*_TLS_*settings are the server half and none of them is read here.PGWIRE_TLS_*andFLIGHT_TLS_*(2.28.0) secure listeners this server never connects to.API_TLS_*(2.29.0) makes the REST API serve HTTPS itself, andAPI_TLS_CLIENT_CAmakes it require a client certificate — which is what the settings below are for.
TLS to the API
When the API serves HTTPS with a certificate from a private CA, or requires
mutual TLS — API_TLS_CLIENT_CA on the API, or a gateway in front that asks
for a client certificate — point this server at the material:
API_BASE_URL=https://obsl.internal:8000
API_CA_CERT=/certs/ca.crt # trust this CA instead of the default store
API_CLIENT_CERT=/certs/mcp.crt # present this certificate…
API_CLIENT_KEY=/certs/mcp.key # …with this key (omit if it is in the same PEM)
The certificate is loaded when the server starts, on every transport, so a path
that is missing, unreadable, or not what it claims stops startup naming the
setting and the file — rather than surfacing later as an SSL error from inside
the HTTP client. The startup banner's API TLS: line reports what the hop
ended up with.
API_CA_CERTreplaces the default trust store, it does not extend it. Unset, verification uses httpx's default (certifi, orSSL_CERT_FILE/SSL_CERT_DIR), and adding a client certificate does not change that.- These require an
https://API_BASE_URL. Onhttp://there is no handshake, so nothing would be presented or verified; that configuration is refused rather than left to read as TLS. - Password-protected keys are refused, not prompted for. Under
stdio, stdin is the MCP pipe, so OpenSSL's terminal prompt would corrupt the protocol or hang. Provide the key decrypted, protected by file permissions or a secret mount.
MCP client configuration
Add to your MCP client config (e.g. claude_desktop_config.json):
{
"mcpServers": {
"orionbelt": {
"command": "uv",
"args": ["run", "python", "server.py"],
"cwd": "/path/to/orionbelt-semantic-layer-mcp"
}
}
}
Configuration
Environment variables or .env file (pydantic-settings). See .env.example for defaults.
| Variable | Default | Description |
| ----------------- | ------------ | ------------------------------------- |
| API_BASE_URL | — (required) | OrionBelt® Semantic Layer REST API URL |
| API_KEY | — (unset) | API credential; required only when the API runs with `AUTH_MODE=api_
Truncated for display — read the full file on GitHub.
Related Skills
claude-mem
94.9kPersistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
Agent-Reach
86.2kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
Understand-Anything
84.7kGraphs that teach > graphs that impress. Turn any code into an interactive knowledge graph you can explore, search, and ask questions about. Works with Claude Code, Codex, Cursor, Copilot, Gemini CLI, and more.
headroom
74.1kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
