Tableau
Tableau Server or Tableau Cloud.
Access mode: Read-only
Required information
| Field | Details |
|---|---|
| Server URL | Tableau Server URL or Tableau Cloud pod URL. |
| Site name | Tableau site (can be “Default”). |
| Authentication | PAT (preferred), username/password, or trusted ticket. |
| Scope | Projects/workbooks to access. Metadata API for lineage. |
Network considerations
Tableau Cloud: HTTPS. No VPN needed.
Tableau Server (on-prem): VPN or reverse proxy. REST API at /api/<version>/.
Metadata API: Requires Tableau Server 2019.3+ or Tableau Cloud. GraphQL endpoint at /api/metadata/graphql.
Credential and auth management
Preferred: Personal Access Token (PAT). Generated in Tableau user settings. Scoped to the user’s permissions. 1-year max expiry.
Alternative: Service account + password. For environments where PATs aren’t available.
Permissions: User needs “Viewer” or “Explorer” site role with access to target projects. For Metadata API: “Site Admin Explorer” or custom role with metadata permissions.
Session management: REST API uses auth tokens from sign-in. 240-min default timeout.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Authentication | POST /api/3.x/auth/signin | Returns auth token + site ID |
| Site access | GET /api/3.x/sites/<id> | Returns site metadata |
| Workbook listing | GET /api/3.x/sites/<id>/workbooks | Lists workbooks |
| Metadata / lineage | POST /api/metadata/graphql with query for tables upstream | Returns lineage data |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.