CIIFragments Studio is CII-accredited: recover up to 20% of your software development spendLearn more

API integration for Metabase

We build your Metabase connector

We embed Metabase in your application: each customer sees their own figures, filtered automatically, without opening a second tool.

  • Senior product team
  • Metabase embedding in production
  • from scoping to monitoring
In short

What does the Metabase integration do and why embed dashboards in your application?

Metabase is a business intelligence tool that lets business teams create reports and dashboards without writing SQL. Its API and embedding feature let you embed those dashboards directly in your application, filtered by client or scope, without the user having to log into a separate tool. You integrate it when clients or teams need to see their own data in context within your product, rather than receiving a CSV export or switching to an external reporting tool.

Use cases

What our clients build on the Metabase API

01

Customer portal: my orders, my balance

JWT iframe, locked client_id from the session. The customer does not see Metabase, nor other accounts.

02

Internal back office as full app embedding

The analyst keeps the same groups as your directory, in the back office you control. One login.

03

Q&A assistant on sales

Agent API, the user's rights, not free SQL, not an admin key in the chatbot.

04

Monthly export of a card to PDF

Service-account session, not an analyst's password. Company 2FA / SSO break this flow if it is aimed at a human.

For you

What this changes in your product

Engineering in service of a measurable outcome: figures in the portal, same system of record, each account sees its rows.

The customer no longer switches to a BI tool

The dashboard lives next to the file. No more Monday CSV or second Metabase login.

The analyst stays in your back office

Single sign-on, same groups. BI opens in the journey you control.

Each account only sees its rows

The customer filter comes from the session, not a manipulable URL parameter. Confidentiality holds.

BI can stay on your side

Controlled hosting, server-side signatures. You keep control of the figures, without exposing Metabase on the internet.

Method

How we ship your Metabase connector

01

Scoping

Static for a filterable KPI, modular/SSO for an authenticated portal. Cloud or self-host. One mode per case, documented.

02

JWT

Locked parameters = session IDs, embedding secret server-side only. Group mapping for SSO.

03

Development

Server-side signing, refresh endpoint for the Agent API (iat < 180 s), never the secret in front, never apiKey in modular prod.

04

Monitoring

Embedding secret rotation rehearsed in staging. Self-host: private network, SSO, backups. Metabase is not naked on the Internet.

The API

What the Metabase API allows

REST /api/*
Session, cards, dashboards, database, permissions. Service account for automation, not an analyst's password.
Static / guest embedding
Iframe + JWT signed with the embedding secret. Resource id + locked parameters. No row-level security, no drill-through.
Modular / SSO embedding
JWT or SAML, real permissions. Backend endpoint { jwt: "..." } for the SDK. API keys forbidden in production.
Agent API
Semantic layer for agents / MCP. JWT iat < 180 s, email and groups claims. Map the user's rights, not an admin key.
Vocabulary

Metabase API vocabulary

Locked parameters
Values frozen in the static JWT, typically a client_id. From the app session, never from a query string. Without them, static does not isolate rows.
Embedding secret
One secret for all static embeds. Theft opens every dashboard. Rotation = every backend. Never in front.
iat < 180 s
On the Agent API, the JWT must have an iat under 180 seconds. A one-hour session token is rejected. A refresh endpoint is mandatory.
Static vs SSO
Static: locked params, no row-level security, no drill-through. SSO / modular: real permissions, IdP groups. Two products, two quotes.
X-Metabase-Session
Session cookie after POST /api/session. Service account, not the analyst. The API key carries the permissions of the key's group, shared by every caller.
Self-host
Versions, migrations, Metabase's internal Postgres. This is not a cloud API. Private network, SSO, backups. Metabase is not exposed naked on the Internet.
Good to know

The real constraints of the Metabase API

01

Static is not row-level security

Locked params vs SSO permissions. Promising each customer only sees their rows in static without a locked param is a hole. Drill-through in static is impossible.

02

One embedding secret for everything

Theft opens every embedded dashboard. Rotation touches every backend that signs static JWTs. We rehearse it in staging before production, not on a live portal.

03

Agent API JWT: 180 seconds

A one-hour session JWT is rejected. Without a refresh endpoint, the assistant dies mid-conversation. This is not optional, and it is not the same token as static embedding.

04

apiKey in modular prod = no

The docs forbid it. A demo with apiKey does not ship. Self-host: this is operations (versions, Postgres, network), not only an API.

Which embed

Static embedding or SSO / modular?

Two ways to embed Metabase. The right one depends on who looks at the dashboard and what they are allowed to see.

CriterionStaticGuest JWTSSO / modularReal permissions
Row isolationLocked params onlyRow-level, IdP groups
Drill-throughImpossibleDepends on full / SDK embed
SecretOne secret for all staticSSO JWT, not that secret
API keyOut of scopeForbidden in modular prod
User sessionNo, guestYes
Time to first embedShorterIdP, groups, SDK
The right caseFilterable public KPIAuthenticated portal

We pick one mode per case and document it. Mixing static and SSO on the same screen is the surest way to a filter hole. The secret never leaves the server.

Our expertise

What we measure on a Metabase integration

15 d
first embedded dashboard in prod
180 s
Agent API iat, refresh in place
0
embedding secret exposed to the front
4
senior developers on the project

We combine Metabase with

The stack around Metabase on our projects.

  • PostgreSQL
  • Slack
  • n8n
  • Node.js
  • HubSpot
FAQ

Metabase: your questions

Three decisions, then code. Pick one embed mode per case: static (JWT, locked params) for a filterable KPI, modular/SSO for an authenticated portal. Sign JWTs on the server, IDs from the session, never from a query string. For the Agent API: JWT iat < 180 s and refresh, group mapping, not an admin key. Self-host: private network, SSO, backups. The sensitive part is not the iframe, it is the embedding secret, locked params and the ban on API keys in modular production.

Static: parameters locked in the JWT (client_id from the session), embedding secret server-only. Without a locked param, static does not isolate rows. SSO / modular: real permissions, IdP groups, never an apiKey in production. Do not promise drill-through in static (official docs). A stolen embedding secret opens every static dashboard: rotation rehearsed in staging. That is the test of a BI integrator, not a cosmetic setting.

The docs require an iat under 180 seconds. A one-hour session JWT is rejected. Without a refresh endpoint, the assistant dies mid-conversation. It is not the same token as static embedding. We put refresh in from the prototype, and we never put an admin API key in a user chatbot: permissions are those of the key's group, shared by every caller. A short iat is a product constraint, not a setting we skip.

Yes, and that is often the argument. BI stays in the VPC, the business software signs JWTs. This is not a cloud API: versions, migrations, internal Postgres, SSO, backups, Metabase not naked on the Internet. Embedded Looker or Power BI do not offer the same sovereignty / price ratio. The integration quote includes operations if self-host is in scope, otherwise Metabase cloud, without inventing unpublished hourly quotas.

A first static dashboard filterable by client_id ships in two to three weeks. An SSO / modular portal, Agent API and self-host are closer to six to eight weeks, plus operations if Metabase is not already in place. Duration depends on embed mode, IdP and the semantic model. We scope the perimeter up front and give you a firm estimate before we start, including the embed mode chosen.

A Metabase integration project?

Let's talk. 30 minutes to scope static or SSO, possible self-host, and tell you frankly what locked params will hold.

Discuss my Metabase project
Discuss my Metabase project