Open source MCP server for querying Brazilian public data sources, including economic, legislative, transparency, judicial, electoral, environmental, health, education, public-safety, aviation, and infrastructure datasets.
MCP-Brasil can query many Brazilian public data sources, some of which cover courts, elections, health, public safety, government contracts, public spending, and regulated sectors., The upstream acceptable-use policy prohibits doxing, stalking, unlawful electoral profiling, sensitive health-data misuse, unauthorized judicial data redistribution, re-identification, fake official claims, and other abusive uses., Outputs should not be treated as official government records without checking the original source, because the MCP server is an independent open source project and LLM clients can misread or hallucinate., Respect each upstream API's rate limits, license, attribution requirements, registration rules, and redistribution restrictions before batching or publishing results., Large local datasets are opt-in and can download sizable public data caches; review disk usage, refresh behavior, and cache retention before enabling them., Keep any optional DataJud, transparency, Meta, Anthropic, OAuth, or static bearer tokens scoped and separated from shared logs or test clients.
Privacy notes
Public records can still contain personal data or sensitive context, including judicial parties, health professionals, election candidates, public servants, suppliers, property records, campaign information, or location-linked records., The upstream sources document highlights elevated risk for health, electoral, judicial, education, public-safety, and other datasets; operators remain responsible for LGPD compliance and source-specific terms., Local DuckDB caches, terminal output, MCP client logs, chat transcripts, and exported analysis may retain query terms, public-record results, API keys, and derived datasets., Do not disable PII masking or set `MCP_BRASIL_LGPD_ALLOW_PII` without a documented legal basis and a retention/deletion plan., Attribute public data sources and preserve source context when sharing results with users or publishing downstream analysis.
Author
mcp-brasil contributors
Submitted by
oktofeesh1
Claim status
unclaimed
Last verified
2026-06-06
Decision playbook
Review trust signals before you adopt
Signals are present but mixed. Use the checklist below to confirm the source and operational safety for your environment.
Compare context
Selected
0
Current score
63
Baseline
—
Delta
No baseline selected
No major trust-signal divergence detected in the current selection.
Source and provenance checks
Needs review
Confirm ownership and provenance before trusting install instructions.
Source link availableRequired
Open the canonical repository and verify ownership.
Done
Source provenance statusRequired
Marked as source-backed.
Done
Metadata reviewed
No reviewed flag detected in metadata.
Pending
Safety and privacy checks
Complete
Validate risk disclosures before installation or API wiring.
Safety notes presentRequired
Review the listed safety guidance before running commands.
Done
Privacy notes presentRequired
Review data handling notes before connecting accounts or secrets.
Done
Trust level risk gateRequired
Trust level does not block evaluation.
Done
Package and install checks
Needs review
Check package metadata and artifact integrity signals.
Install payload available
Install or copy payload is available for review.
Done
Package verification flag
No package verification flag provided.
Pending
Checksum metadata
No checksum provided for downloaded artifact.
Pending
Compare-driven decision checks
Needs review
Use compare context to validate trade-offs before adoption.
Compare tray has multiple entries
Add at least one more entry to compare trust differences.
6 safety and 5 privacy notes across 5 risk areas. Review closely: credentials & tokens, permissions & scopes, network access.
5 areas
SafetyGeneralMCP-Brasil can query many Brazilian public data sources, some of which cover courts, elections, health, public safety, government contracts, public spending, and regulated sectors.
SafetyPermissions & scopesThe upstream acceptable-use policy prohibits doxing, stalking, unlawful electoral profiling, sensitive health-data misuse, unauthorized judicial data redistribution, re-identification, fake official claims, and other abusive uses.
SafetyGeneralOutputs should not be treated as official government records without checking the original source, because the MCP server is an independent open source project and LLM clients can misread or hallucinate.
SafetyGeneralRespect each upstream API's rate limits, license, attribution requirements, registration rules, and redistribution restrictions before batching or publishing results.
SafetyNetwork accessLarge local datasets are opt-in and can download sizable public data caches; review disk usage, refresh behavior, and cache retention before enabling them.
SafetyCredentials & tokensKeep any optional DataJud, transparency, Meta, Anthropic, OAuth, or static bearer tokens scoped and separated from shared logs or test clients.
PrivacyGeneralPublic records can still contain personal data or sensitive context, including judicial parties, health professionals, election candidates, public servants, suppliers, property records, campaign information, or location-linked records.
PrivacyPermissions & scopesThe upstream sources document highlights elevated risk for health, electoral, judicial, education, public-safety, and other datasets; operators remain responsible for LGPD compliance and source-specific terms.
PrivacyCredentials & tokensLocal DuckDB caches, terminal output, MCP client logs, chat transcripts, and exported analysis may retain query terms, public-record results, API keys, and derived datasets.
PrivacyData retentionDo not disable PII masking or set `MCP_BRASIL_LGPD_ALLOW_PII` without a documented legal basis and a retention/deletion plan.
PrivacyGeneralAttribute public data sources and preserve source context when sharing results with users or publishing downstream analysis.
Disclosure: Community-maintained open source MCP server for Brazilian public data, published as the `mcp-brasil` Python package under the MIT license for code; upstream data sources have separate licenses and restrictions.
Safety notes
MCP-Brasil can query many Brazilian public data sources, some of which cover courts, elections, health, public safety, government contracts, public spending, and regulated sectors.
The upstream acceptable-use policy prohibits doxing, stalking, unlawful electoral profiling, sensitive health-data misuse, unauthorized judicial data redistribution, re-identification, fake official claims, and other abusive uses.
Outputs should not be treated as official government records without checking the original source, because the MCP server is an independent open source project and LLM clients can misread or hallucinate.
Respect each upstream API's rate limits, license, attribution requirements, registration rules, and redistribution restrictions before batching or publishing results.
Large local datasets are opt-in and can download sizable public data caches; review disk usage, refresh behavior, and cache retention before enabling them.
Keep any optional DataJud, transparency, Meta, Anthropic, OAuth, or static bearer tokens scoped and separated from shared logs or test clients.
Privacy notes
Public records can still contain personal data or sensitive context, including judicial parties, health professionals, election candidates, public servants, suppliers, property records, campaign information, or location-linked records.
The upstream sources document highlights elevated risk for health, electoral, judicial, education, public-safety, and other datasets; operators remain responsible for LGPD compliance and source-specific terms.
Local DuckDB caches, terminal output, MCP client logs, chat transcripts, and exported analysis may retain query terms, public-record results, API keys, and derived datasets.
Do not disable PII masking or set `MCP_BRASIL_LGPD_ALLOW_PII` without a documented legal basis and a retention/deletion plan.
Attribute public data sources and preserve source context when sharing results with users or publishing downstream analysis.
Prerequisites
Python 3.10 or newer with `uvx` available.
Review of the upstream acceptable-use policy and source license notes before using outputs in commercial, journalistic, legal, medical, financial, electoral, or civic-decision workflows.
Optional API keys for data sources such as Portal da Transparencia, DataJud, or Meta Ad Library when those features are needed.
Optional local dataset cache configuration when enabling large DuckDB-backed datasets through `MCP_BRASIL_DATASETS`.
A plan for rate limiting, attribution, and human review when querying public agencies or redistributing analysis.
Schema details
Install type
cli
Troubleshooting
No
Source repository stats
Scope
Source repo
Collection metadata
Estimated setup
15 minutes
Difficulty
advanced
Tool listing metadata
Disclosure
Community-maintained open source MCP server for Brazilian public data, published as the `mcp-brasil` Python package under the MIT license for code; upstream data sources have separate licenses and restrictions.
MCP-Brasil connects Claude and other MCP clients to Brazilian public APIs and
datasets. It is useful for supervised research and civic data workflows that
need to inspect economic series, government transparency data, legislation,
public spending, courts, elections, environmental data, health datasets,
education statistics, public safety, aviation, infrastructure, and related
public records.
Use it when an agent needs a source-aware way to search, plan, and execute
Brazilian public-data queries while keeping attribution, acceptable-use limits,
and privacy review in the workflow.
These sources were reviewed on 2026-06-06. Prefer the live repository,
README, PyPI metadata, license, package manifest, acceptable-use policy, data
source notes, server entrypoint, and runtime settings for current setup,
scope, and risk details.
Features
Query Brazilian public APIs across economic, legislative, transparency,
judicial, electoral, environmental, health, education, security, aviation,
energy, and infrastructure topics.
Search available features and tools before calling a specific data source.
Plan multi-step public-data queries with the planejar_consulta tool.
Execute batches of related calls through the server's batch-dispatch support.
Use optional API keys for data sources that require registration.
Enable large local DuckDB-backed datasets only when needed.
Run over stdio for local MCP clients or through FastMCP HTTP transport for
hosted deployments.
Configure optional static bearer-token or OAuth authentication for HTTP
deployments.
Installation
Install and run the published Python package with uvx:
Most sources can be explored without optional API keys, but restricted sources
such as transparency, judicial, or third-party ad-library data may need their
own credentials and terms review.
Use Cases
Compare public economic indicators against legislative or budget activity.
Research public procurement, spending, contracts, suppliers, and sanctions.
Inspect legislative proposals, votes, representatives, and committees.
Explore environmental, health, education, or public-safety datasets with
source attribution.
Combine multiple public sources into an auditable research plan.
Support civic-tech, journalism, policy research, and public-interest
investigation workflows with human review.
Prototype internal data assistants for Brazilian public-data teams.
Safety and Privacy
MCP-Brasil is an access layer over public data, not an official source of truth.
Review the upstream acceptable-use policy and source notes before using it for
decisions, publication, compliance workflows, or redistribution.
Treat public-record results as potentially privacy-sensitive. Keep PII masking
enabled, avoid re-identification, do not present AI-written summaries as
official records, and verify high-impact answers against the original agency or
data-source page.
Large local datasets can create durable DuckDB caches. Store them somewhere
appropriate for the sensitivity of the queries, document who can access them,
and delete caches when they are no longer needed.
Open source MCP server for querying Brazilian public data sources, including economic, legislative, transparency, judicial, electoral, environmental, health, education, public-safety, aviation, and infrastructure datasets.
Official data.gouv.fr MCP server for searching French national open datasets, exploring organizations and data services, inspecting resources, querying tabular data, and retrieving dataset metrics through Claude.
No-key multi-engine MCP server, CLI, and local daemon for web search and public web content retrieval across engines such as Bing, DuckDuckGo, Brave, Exa, Baidu, CSDN, Juejin, Startpage, and Sogou.
Local-first codebase intelligence MCP server that indexes repositories with tree-sitter, stores searchable chunks in DuckDB, and gives Claude semantic search, regex search, daemon status, and deep code research tools.
✓MCP-Brasil can query many Brazilian public data sources, some of which cover courts, elections, health, public safety, government contracts, public spending, and regulated sectors.
The upstream acceptable-use policy prohibits doxing, stalking, unlawful electoral profiling, sensitive health-data misuse, unauthorized judicial data redistribution, re-identification, fake official claims, and other abusive uses.
Outputs should not be treated as official government records without checking the original source, because the MCP server is an independent open source project and LLM clients can misread or hallucinate.
Respect each upstream API's rate limits, license, attribution requirements, registration rules, and redistribution restrictions before batching or publishing results.
Large local datasets are opt-in and can download sizable public data caches; review disk usage, refresh behavior, and cache retention before enabling them.
Keep any optional DataJud, transparency, Meta, Anthropic, OAuth, or static bearer tokens scoped and separated from shared logs or test clients.
✓The hosted endpoint is documented as publicly available without access restrictions, so treat requests and returned public-data context as externally visible.
Tools are read-only but can retrieve dataset metadata, resource URLs, rows from tabular resources, service OpenAPI specs, metrics, and organization details that may influence decisions.
Public open data can be stale, incomplete, licensed with reuse conditions, or unsuitable for operational decisions without checking the dataset publisher and update cadence.
Tabular queries can return rows from large resources; use small page sizes and pagination instead of asking an agent to pull entire datasets through chat.
If self-hosting, review MCP_HOST, allowed hosts, allowed origins, Sentry, Matomo, and API-environment settings before exposing the server.
✓open-webSearch can send search queries to multiple public engines and fetch public web pages, GitHub READMEs, CSDN articles, Juejin articles, and other supported targets.
Search and fetch results can be incomplete, stale, rate-limited, blocked, region-dependent, or affected by search-engine ranking and scraping protections.
Respect each target site's terms and robots expectations; do not use the server for abusive scraping, credentialed browsing, paywall bypass, or personal-data harvesting.
The optional local daemon exposes HTTP endpoints for local tooling; keep it bound to trusted local interfaces and do not treat it as a public internet API.
Proxy settings, Playwright WebSocket/CDP endpoints, and reused browser sessions can route traffic or cookies through external systems; configure them deliberately.
Leave TLS verification enabled unless a specific target has a broken certificate chain and the risk has been accepted.
✓ChunkHound reads source files, Markdown, text, PDFs, and supported config files under the target directory and stores indexed chunks in a local database.
Realtime indexing and daemon mode can continue watching project files after the initial MCP connection.
Code research and web search tools require embedding, reranking, and LLM configuration and may invoke local CLIs or external model APIs depending on settings.
Exclude generated files, vendored dependencies, secrets, large artifacts, and unrelated repositories before indexing broad workspace roots.
Review MCP client configuration carefully when using an absolute project path in a global Claude Desktop config.
Privacy notes
✓Public records can still contain personal data or sensitive context, including judicial parties, health professionals, election candidates, public servants, suppliers, property records, campaign information, or location-linked records.
The upstream sources document highlights elevated risk for health, electoral, judicial, education, public-safety, and other datasets; operators remain responsible for LGPD compliance and source-specific terms.
Local DuckDB caches, terminal output, MCP client logs, chat transcripts, and exported analysis may retain query terms, public-record results, API keys, and derived datasets.
Do not disable PII masking or set `MCP_BRASIL_LGPD_ALLOW_PII` without a documented legal basis and a retention/deletion plan.
Attribute public data sources and preserve source context when sharing results with users or publishing downstream analysis.
✓Search terms, dataset interests, resource IDs, user-agent headers, request URLs, tool names, and returned dataset rows may be visible to the hosted MCP service, MCP client, model provider, and logs.
The server includes optional Matomo and Sentry instrumentation in source; hosted deployments may apply their own analytics and error-reporting policies.
Public datasets can still contain personal data, geographic sensitivity, business identifiers, or regulated information; review source metadata and reuse terms before sharing results.
Avoid placing private investigation notes, customer context, or unpublished analysis inside prompts when a generic dataset search is enough.
✓Search queries, fetched URLs, result titles, snippets, article content, proxy URLs, browser endpoints, and fetched page text can be exposed to MCP clients, logs, and model context.
Live search engines and fetched websites may observe queries, IP address, proxy exit, browser fingerprints, cookies, timing, and request headers.
Playwright fallback or CDP reuse can expose browser state, existing cookies, logged-in sessions, or verification state to fetched pages.
The project includes public URL validation and private-network target protections, but operators should still avoid fetching internal, secret, or customer-specific URLs.
Redact sensitive search terms and downloaded page content before sharing transcripts or logs.
✓Indexed chunks, file paths, symbols, comments, Markdown, PDFs, configuration values, database files, daemon state, and search results can reveal proprietary source code and internal architecture.
Embedding, reranking, LLM, and web search providers may receive code-derived queries or snippets if configured.
Local ChunkHound database files, logs, daemon state, and MCP transcripts may retain code-derived context after the session ends.
Avoid sharing ChunkHound databases, config files with API keys, verbose logs, research outputs, and screenshots from private repositories.
Prerequisites
Python 3.10 or newer with `uvx` available.
Review of the upstream acceptable-use policy and source license notes before using outputs in commercial, journalistic, legal, medical, financial, electoral, or civic-decision workflows.
Optional API keys for data sources such as Portal da Transparencia, DataJud, or Meta Ad Library when those features are needed.
Optional local dataset cache configuration when enabling large DuckDB-backed datasets through `MCP_BRASIL_DATASETS`.
MCP client that supports Streamable HTTP or a remote MCP bridge such as mcp-remote.
Agreement on whether hosted data.gouv.fr MCP requests may be sent to the public hosted endpoint.
Public-data review process for datasets that may contain personal, sensitive, stale, or jurisdiction-specific information.
Python 3.13 or newer only if self-hosting the repository instead of using the hosted endpoint.
Node.js 18 or newer for the published npm package.
Review of search-engine terms, scraping limits, rate limits, and allowed use for the target websites.
Optional proxy configuration only when live search or fetch traffic must route through an approved proxy.
Optional Playwright or browser endpoint setup only when request-based search/fetch is insufficient.
Python 3.10 or newer and the `uv` package manager.
A local repository or workspace you are authorized to index.
ChunkHound JSON config reviewed for database path, excludes, embeddings, and LLM provider settings.
Optional embedding provider credentials for semantic search, or regex-only usage when no embedding key is configured.
Install
uvx --from mcp-brasil python -m mcp_brasil.server
claude mcp add --transport http datagouv https://mcp.data.gouv.fr/mcp