Turns tables, views and stored procedures into secured REST, GraphQL and MCP endpoints (the last as SQL MCP Server). It's open source, you host it yourself, and a JSON file sets it up, permissions by role included.
Also called DAB.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Data API builder in context, with comparison tables and the common traps.
Terms in this definition
- REST
Short for representational state transfer, the style of HTTP API that Azure services expose.
- MCP
Model Context Protocol, an open standard for making tools and data available to models. To use one, a Foundry agent points at a remote MCP server, naming it with a server label and giving its URL.
- LAST
Restricted to visual calculations, this DAX function reads a value from the final position along one of the visual's axes. Writing INDEX(-1) gives the same result.
- SQL MCP Server
Since version 1.7, Data API builder ships an MCP server that turns entities from dab-config.json into tools AI agents can call. The roles and permissions already applied to REST and GraphQL access govern it too.
- JSON
Text-based format for structured data. ARM templates and Cosmos DB documents are written in it, and most Azure REST APIs exchange request and response bodies as application/json.
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
Related terms
- @akv()
Available since version 1.6, this function lets a Data API builder config file pull in a Key Vault secret at load time from the vault endpoint you've configured. Substitutions made with
@env()happen earlier. - DAB CLI
Command line for Data API builder, installed as a .NET tool. Use
dab initanddab addto build the configuration file,dab validateto check it anddab startto run it. - @env()
In Data API builder's configuration, this function swaps in the value of an environment variable, or of an entry in a local .env file, as the configuration is loaded, so secrets like connection strings never have to appear in dab-config.json.
- L1L2
A Data API builder caching level that looks first in the in-memory level 1 cache, next in the distributed Redis level 2 cache and finally in the database. Cached entities use it by default; L1 on its own means in-memory caching only.
- Role inheritance
In Data API builder 2.0, an entity with no permissions defined for a named role falls back to authenticated, and authenticated falls back to anonymous, which saves repeating permission blocks.
- stdio
A way for MCP to work locally: the client launches the server as a process and they communicate via stdin and stdout. Data API builder's SQL MCP Server can run like this.