Atlas is the AI data analyst you can run anywhere. It answers plain-English questions across your SQL warehouses and REST APIs — grounded in a semantic layer you author, a Knowledge Base of your own docs, the query patterns it learns as your team approves them, and a Company Atlas of what your colleagues have said and someone has stood behind.
Documentation · Live Demo · The Semantic Layer · MCP Guide · Issues
Ask two tools what revenue was last quarter and you can get two different numbers. Atlas reads your definitions first.
Four context surfaces, each with a different job — and a boundary between them that Atlas enforces rather than trusts:
| What it is | Its job | |
|---|---|---|
| Semantic layer | YAML on disk — entities, dimensions, measures, joins, glossary terms, pinned metrics | The sole authoritative surface. The table whitelist, pinned metric SQL, and glossary gating are enforced, not suggested |
| Knowledge Base | Your own docs — mirrored through ten vendor connectors (Notion, Confluence (Cloud + Data Center), GitBook, Zendesk, Salesforce, Intercom, Front, Help Scout, Freshdesk) or uploaded directly | Descriptive only. Runbooks, definitions, policies. Never queried as data, never extends the whitelist, never gates the agent (ADR-0028) |
| Learned patterns | The query shapes Atlas keeps as your team approves them | The canonical joins for your domain — earned from real use rather than authored up front |
| Company Atlas | Claims drawn from what your company already says — chat, meeting transcripts, mail — each carrying its source, its date, and the person who approved it | Nothing counts until a person approves it. Facts are ACL-scoped fail-closed, superseded rather than deleted, and readable as of a past date. Contradictions are surfaced with both sources, never arbitrated (ADR-0036) |
That descriptive-vs-authoritative split is the point: a runbook can inform an answer, but only the semantic layer can authorize the SQL behind it.
The Company Atlas is the newest of the four and the one you opt into: extraction ships off by default (ATLAS_BRAIN_EXTRACTION_ENABLED), so nothing is drawn from your chat, transcripts, or mail until you turn it on — and once on, a claim still waits for a person before it counts.
Every YAML field exists because an LLM needs it to write correct SQL: sample_values ground the agent in real data, glossary.status: ambiguous forces clarifying questions, metrics.objective picks MAX vs MIN, query_patterns teach the canonical join shapes for your domain.
The same grounded agent, reachable however your team already works:
- Chat UI — built in, with the SQL on display behind every answer
- Dashboards — draft-first and publish-gated, so private work stays private until you ship it (ADR-0029)
- MCP server — Claude Desktop, Cursor, Continue, or any MCP client, over stdio or OAuth 2.1
- Embeddable widget — script tag or React component, in your own app
- Chat platforms — six, Slack one-click; Teams, Discord, Telegram, and WhatsApp with your own bot (Google Chat coming soon)
- REST API + CLI — headless, typed, scriptable
Built with Hono, Vercel AI SDK, and bun. Supports Anthropic, OpenAI, Bedrock, Ollama, any OpenAI-compatible endpoint, and Vercel AI Gateway. Works with PostgreSQL, MySQL, ClickHouse, Snowflake, DuckDB, BigQuery, Elasticsearch, and Salesforce.
bun create atlas-agent my-app
cd my-app
# edit .env and set your LLM API key (Anthropic / OpenAI / etc.)
bun run dev
# Open http://localhost:3000The scaffold seeds the canonical NovaMart e-commerce dataset (52 tables, ~480K rows) by default — twelve generic e-commerce KPIs ship as starter prompts inside the chat UI; the canonical 5 below drive the eval harness (#2025) and the docs/landing copy. The scaffold defaults to SQLite + Anthropic; pass --defaults for non-interactive setup or follow the prompts to pick PostgreSQL / OpenAI / etc.
Ask one of the canonical questions in the chat UI:
- "What's our GMV this quarter?"
- "What's our top-performing category by GMV this month?"
- "Monthly GMV trend over the past 6 months."
- "Show me revenue last quarter." — Atlas asks which definition you mean (GMV vs. net revenue vs. seller revenue) because
revenueisstatus: ambiguousin the glossary - "What are our most common return reasons?"
The agent reads your YAML semantic layer first, picks the right entities, writes SQL, runs it through the validation pipeline, and returns answers with the underlying SQL on display.
The default landing for fresh installs is chat-first — admins can flip to admin in Settings → Profile. See the Default Landing guide for the underlying preference.
Once you have an Atlas instance (local from the demo above, self-hosted, or a hosted workspace), add it to Claude Desktop, Cursor, or Continue with one command. Auto-detects the client and merges into its config:
bunx @useatlas/mcp init --local # paste-ready config for a local Atlas instance
bunx @useatlas/mcp init --local --write # merge into the detected client config (with a .bak)
bunx @useatlas/mcp init --hosted --write # for an app.useatlas.dev workspace via OAuth 2.1On WSL2? Bun's
bunxshim has resolution issues on some WSL2 setups — substitutebun x(space-separated) for anybunxcommand above (e.g.bun x @useatlas/mcp init --local). The space-separated form is a bun subcommand and resolves correctly.
Restart Claude Desktop / Cursor and ask the same canonical questions through your AI client. See the MCP guide for the full flow — hosted (mcp.useatlas.dev over OAuth 2.1 + DCR + PKCE) and self-hosted (stdio) live in the same page under tabs.
A 20-line slice of semantic/entities/orders.yml from the bundled NovaMart e-commerce demo (#2021):
name: Orders
type: fact_table
table: orders
grain: one row per order
description: |
Customer orders — the primary fact table for revenue analysis.
shipping_cost uses MIXED UNITS (some rows in dollars, some in cents).
dimensions:
- name: status
sql: status
type: string
sample_values: [pending, processing, shipped, delivered, cancelled]
- name: order_month
sql: TO_CHAR(created_at, 'YYYY-MM')
type: string
virtual: true
measures:
- name: total_gmv_cents
sql: total_cents
type: sum
joins:
- target_entity: Customers
relationship: many_to_one
join_columns: { from: customer_id, to: id }That YAML is the contract between your team and the agent — version-controlled, code-reviewed, diffable. Sibling files (glossary.yml, metrics/*.yml, catalog.yml) round it out: glossary terms with status: ambiguous force the agent to clarify, metrics with objective: maximize / minimize make optimization direction explicit, and the catalog routes the agent to the right entity for a given question.
See the full Semantic Layer reference for the complete schema.
Atlas also ships an embeddable chat widget for any frontend:
<script
src="https://your-atlas.example.com/widget.js"
data-api-url="https://your-atlas.example.com"
data-theme="dark"
></script>Or use the React component:
import { AtlasChat } from "@useatlas/react";
export default function App() {
return <AtlasChat apiUrl="https://your-atlas.example.com" />;
}The widget supports programmatic control (Atlas.open(), Atlas.ask("..."), Atlas.destroy()), event callbacks, and theming. See the widget docs.
| Atlas | Traditional BI | Other text-to-SQL | |
|---|---|---|---|
| Semantic layer | YAML on disk — query_patterns, virtual_dimensions, glossary.status: ambiguous, metrics.objective are all first-class |
Proprietary metadata, GUI-authored | None or limited |
| Your docs as context | Knowledge Base pillar — ten vendor connectors, descriptive-only by construction (never extends the SQL whitelist) | Separate wiki, unlinked | None |
| Dashboards | Draft-first, publish-gated — built from chat answers, private until you ship | Core product, GUI-authored | Rare |
| Agent-native | MCP server first — Claude Desktop, Cursor, Continue with bunx @useatlas/mcp init |
Bolted-on AI feature | Standalone chat UI |
| Embeddable | Script tag, React component, headless API, MCP, 6 chat platforms (Slack one-click; Teams/Discord/Telegram/WhatsApp bring-your-own-bot; Google Chat coming soon) | Standalone app | Standalone app |
| Deploy anywhere | Docker, Railway, Vercel, or your own infra | Vendor-hosted | Vendor-hosted |
| Plugin ecosystem | 24 plugins across 5 types — extend anything | Closed | Limited |
| Open source | AGPL-3.0 core, MIT client libs | Proprietary | Varies |
| Multi-database | PostgreSQL, MySQL, ClickHouse, Snowflake, DuckDB, BigQuery, Elasticsearch, Salesforce | Usually one | Usually one |
| REST APIs as datasources | Stripe, GitHub, Notion, any OpenAPI spec — read like a datasource, write-gated; generic OpenAPI installs auto-refresh | None | None |
Docker:
git clone https://github.com/AtlasDevHQ/atlas-starter-docker.git && cd atlas-starter-docker
cp .env.example .env # Set your API key + database URL
docker compose up| Platform | Starter | Guide |
|---|---|---|
| Vercel | atlas-starter-vercel | Next.js + embedded Hono API + Neon Postgres |
| Railway | atlas-starter-railway | Docker + sidecar sandbox + Railway Postgres |
| Docker | atlas-starter-docker | Docker Compose + optional nsjail isolation |
- User (or agent) asks a natural language question — over MCP, the chat widget, the API, or a chat platform (Slack, Teams, Discord, Telegram, or WhatsApp; Google Chat coming soon)
- Agent explores the YAML semantic layer — entities, glossary, metrics, query patterns
- Agent writes SQL, validated through a 7-layer security pipeline (empty check, regex guard, AST parse, table whitelist, RLS injection, auto-LIMIT, statement timeout)
- Results are returned with charts and an interpreted narrative
Question → YAML semantic layer → SQL generation → 7-layer validation → Query execution → Charts + narrative
bun run atlas -- init # Profile DB and generate YAMLs
bun run atlas -- init --enrich # Profile + LLM enrichment
bun run atlas -- init --demo # Load NovaMart demo data + profileatlas/
├── packages/
│ ├── api/ # @atlas/api — Hono API server + agent loop + tools + auth
│ ├── web/ # @atlas/web — Next.js frontend + chat UI components
│ ├── cli/ # @atlas/cli — CLI (profiler, schema diff, enrichment)
│ ├── mcp/ # @atlas/mcp — MCP server (Claude Desktop, Cursor, etc.)
│ ├── sandbox-sidecar/ # @atlas/sandbox-sidecar — Isolated explore sidecar
│ ├── sdk/ # @useatlas/sdk — TypeScript SDK
│ ├── react/ # @useatlas/react — Embeddable chat component + hooks
│ ├── types/ # @useatlas/types — Shared wire-format types
│ ├── schemas/ # @useatlas/schemas — Shared Zod schemas
│ ├── plugin-sdk/ # @useatlas/plugin-sdk — Plugin type definitions
│ ├── webhook-publisher/# @useatlas/webhook-publisher — HMAC-signed outbound webhooks
│ ├── oauth-helper/ # @atlas/oauth-helper — OAuth 2.1 + DCR + PKCE primitives (internal)
│ ├── okf-bundle/ # @atlas/okf-bundle — OKF knowledge-bundle builder (internal)
│ └── fumadocs-okf/ # @atlas/fumadocs-okf — Fumadocs → OKF adapter (internal)
├── plugins/ # 24 plugins (datasource, context, interaction, action, sandbox)
├── ee/ # @atlas/ee — Enterprise features (source-available, commercial license)
├── create-atlas/ # Scaffolding CLI (bun create atlas-agent)
├── apps/
│ ├── www/ # Landing page (useatlas.dev)
│ └── docs/ # Documentation (docs.useatlas.dev)
└── examples/ # Docker + Vercel deploy examples
SQL validation runs through multiple layers. Your database credentials and query results never leave your infrastructure — only questions reach the LLM provider (use Ollama for fully self-hosted).
| Layer | What it does |
|---|---|
| Read-only enforcement | Only SELECT queries allowed (regex + AST validation) |
| AST parsing | node-sql-parser verifies single-statement SELECT |
| Table whitelist | Only tables in your semantic layer are queryable |
| Auto LIMIT | Every query gets a LIMIT (default 1000) |
| Statement timeout | Queries killed after 30s (configurable) |
| Sandboxed execution | Filesystem access runs in Vercel Sandbox, nsjail, or the sidecar — with e2b, Daytona, and Railway available as bring-your-own-cloud backends |
| Row-level security | Optional RLS injection per-user |
See sandbox architecture for the full threat model.
| Variable | Default | Description |
|---|---|---|
ATLAS_PROVIDER |
anthropic |
LLM provider (anthropic, openai, bedrock, ollama, openai-compatible, gateway) |
ATLAS_MODEL |
Provider default | Model ID override |
DATABASE_URL |
— | Atlas internal Postgres for auth, audit, settings |
ATLAS_DATASOURCE_URL |
— | Analytics datasource (PostgreSQL, MySQL, etc.) |
ATLAS_ROW_LIMIT |
1000 |
Max rows per query |
ATLAS_QUERY_TIMEOUT |
30000 |
Query timeout in ms |
See .env.example for all options.
- The Semantic Layer — Entities, dimensions, measures, joins, glossary, metrics — the YAML format reference
- Knowledge Base — Mirror your own docs as descriptive context, via connectors or upload
- Dashboards — Draft-first, publish-gated dashboards built from chat answers
- MCP Server — Use Atlas from Claude Desktop, Cursor, Continue
- Quick Start — Local dev from zero to asking questions
- Demo Dataset — NovaMart e-commerce dataset and canonical questions
- Deploy Options — Docker, Railway, Vercel, and more
- Connect Your Data — Connect to an existing database safely
- Widget Embedding — Script tag and React component
- Bring Your Own Frontend — Nuxt, SvelteKit, React/Vite, TanStack Start
- Plugin Authoring — Build custom plugins
- Security & Sandbox — Threat model, isolation tiers
- Enterprise Boundary —
/eefeatures, AGPL vs commercial split,requireEnterpriseAPI
Quick development setup:
git clone https://github.com/AtlasDevHQ/atlas.git && cd atlas
bun install
bun run db:up # Start Postgres + sandbox sidecar
cp .env.example .env # Set ATLAS_PROVIDER + API key
bun run dev # http://localhost:3000Atlas was inspired by Abhi Sivasailam's work on Vercel's internal data agent d0 and the open-source vercel-labs/oss-data-analyst template. The core insight — invest in a rich semantic layer, trust the model, and keep the tool surface minimal — came from that work.
The Atlas server and core packages (@atlas/api, @atlas/cli, @atlas/web, @atlas/mcp, @atlas/sandbox-sidecar) are licensed under AGPL-3.0. If you modify the server and serve it to users, you must share those modifications.
The client libraries (@useatlas/sdk, @useatlas/react, @useatlas/types, @useatlas/plugin-sdk) and all plugins are licensed under MIT. Embed them in proprietary apps with no restrictions.
The ee/ directory (@atlas/ee — SSO, SCIM, custom roles, approval workflows, residency, branding, and the rest of the SaaS surfaces) is source-available under a commercial license. Self-hosted users get the full AGPL core for free; the commercial license adds enterprise governance and the polished hosted experience. See the Enterprise Boundary page for the full feature inventory.