iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
The tool contract is what ports. Operations such as listing namespaces, listing tables, describing a table and running a query can be exposed through an MCP server and loaded as agent tools in LangChain, CrewAI and LlamaIndex. What does not carry over automatically is everything underneath the tool: which Iceberg features the catalog actually advertises, which engine version executes a query, how each framework names, filters and reports results, and who is allowed to call the tool with which credentials.
The four operations and three frameworks are a scope choice made for this article. They are not an official Iceberg tool bundle, and they are not a complete survey of agent frameworks. Use them to test portability, not as a recommended stack.
The layers a single tool call passes through
An agent tool call crosses five layers, and each one is usually owned by a different party. That is why a tool can work in one stack and fail in another even when the operation name is identical.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Catalog service. A REST catalog or another catalog implementation that tracks Iceberg tables and their metadata.
- Query engine or service. Needed whenever SQL must run. The table format does not execute queries on its own.
- MCP server. Publishes selected operations as tools. Tool names, schemas and result shapes are set by the server implementation.
- Framework adapter. Loads the server’s advertised tools into the framework’s own tool type.
- Credentials and policy. The identity, authorization and secret handling that decide what a call is permitted to do.
The four operations and how each one ports
The four operations below are examples chosen to cover what a data agent typically needs: discovery, schema inspection and execution. Apache Iceberg does not define them as an official set of agent tools.
#1 Best Overall
List namespaces
This is the most portable operation in concept. The agent asks which namespaces exist in the catalog. In practice, the result depends on the catalog and on what the MCP server chooses to expose, so confirm the output shape against the actual server before building prompts around it.
List tables
Discovery within a namespace follows the same pattern. Check that the server accepts a namespace argument and returns table identifiers in a form your agent can use directly, and that the framework passes the argument through without altering it.
Describe a table
This operation returns schema and related metadata. Verify that the chosen server exposes every field the agent relies on, such as column names and types. A schema the agent cannot read is a port that technically works and practically fails.
Run a query
This operation changes the most across stacks. Running a query requires a query engine or service behind the tool. A community overview of Iceberg MCP designs describes query execution as a possible MCP capability. That overview is third-party material describing an example design, not an Apache Software Foundation standard, and it does not guarantee that every server offers query execution.
Rank #3
Once the query runs, the engine’s version, its Iceberg feature support and its permission model decide what the agent can see and change. Portability ends at the tool call.
How the three frameworks load MCP tools
All three frameworks consume MCP tools, but each uses a different adapter or API. The package names and beta status below are as documented in October 2026 and change quickly.
Rank #4
| Framework | How MCP tools are loaded | Documented package or setting | Tool object produced |
|---|---|---|---|
| LangChain | Discovers the server’s tools and adapts them into LangChain’s native tools | langchain[mcp]>=1.4.0 for the langchain.mcp namespace, documented as beta |
LangChain tools |
| CrewAI | A direct mcps field, plus an advanced adapter route |
The mcp library is required for the integration; a specific package version is not stated in CrewAI’s MCP documentation |
Not stated in CrewAI’s MCP documentation |
| LlamaIndex | Exposes server tools as framework-native objects | llama-index-tools-mcp |
FunctionTool objects |
Framework behaviour to verify
Because the adapter is where each framework’s behaviour diverges, test the following on the exact framework and adapter versions you plan to deploy.
Free tools Windows power users keep installed
One-click scans. No signup required.
- Discovery and filtering: whether every server tool loads, or only the ones you select.
- Naming: whether the framework keeps the server’s tool name or changes it, and therefore what the model sees.
- Result structure: whether results arrive as structured data or as text the model must parse.
- Errors: how a server error appears to the agent, and whether it can distinguish a failed call from an empty result.
- Elicitation and approval: how the framework handles a server request for further input, and whether an action can pause for human approval.
- Async behaviour: whether the call runs synchronously inside your agent loop, and how that interacts with timeouts.
- Package versions: pin the framework and its MCP adapter together, because the adapter is the component most likely to change.
What does not port automatically
Catalog features are negotiated, not assumed
Apache’s REST Catalog documentation defines the term by implementation: “An Iceberg REST catalog is any catalog service that implements the Iceberg REST Catalog API specification.” Coverage therefore varies from one service to another. The REST client discovers which endpoints the server advertises and uses only the features it supports. If a server does not offer view or scan-planning endpoints, the functions behind them are unavailable to an agent, whatever framework sits in front.
Best Value
Multi-table commits are optional in the REST protocol. According to the documentation, engines commit tables individually today, and the feature is primarily a Java API capability. An agent that writes across several tables should not assume multi-table commits are available through every server or client.
Engine versions change what “supports Iceberg” means
Apache’s multi-engine documentation states: “Apache Iceberg is an open standard for huge analytic tables that can be used by any processing engine.” The format is shared, but engine connectors are built for specific engine versions. Incompatible upgrades can come with separate integration codebases and artifacts. A stack that says it supports Iceberg does not thereby guarantee that every engine version offers the same features, so any compatibility table for an agent deployment should list engine versions as a column.
Authentication and secrets
The REST Catalog documentation lists five authentication types: none, basic, oauth2, sigv4 and google. Its warning matters more for agents than for most clients: credential and token settings are secrets, and they can appear in engine UIs or event logs unless redaction covers them. Tracing and logging features in agent frameworks deserve the same check. Keep real credentials out of examples, prompts and configuration shown in documentation.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Implementations also differ in what they permit. A Cloudera repository for an Iceberg MCP server describes read-only access to Iceberg tables through Impala. That constraint belongs to that implementation. It is not a property of Iceberg or MCP in general, and a different server can expose write operations or none of these restrictions at all.
Quick Recap
A checklist before connecting an agent
- Catalog reach: which catalogs the implementation supports, such as REST, Glue or Hive. Confirm this for the implementation, not the protocol.
- Operation coverage: discovery, schema inspection, reads and queries, and any writes or maintenance actions. Separate implemented operations from planned ones.
- Feature negotiation: the endpoints the server advertises, which optional REST features it supports, and the engine versions it works with.
- Framework fit: the adapter, package version, tool filtering, result structure and error handling described above.
- Execution location: whether queries run in a separate engine, inside the MCP server, or in another service.
- Security boundary: identity and authorization enforcement, credential handling, secret redaction, read or write scope and the audit trail.
- Maintenance burden: how many adapters and version pairs must stay current as the catalog, engine, server and framework each change.
Limits of this comparison
- The sources behind this article establish no performance, adoption or compatibility percentages. Claims about speed, popularity or reliability are outside what can be supported here.
- Protocol behaviour comes from Apache’s documentation. Server and framework behaviour varies by implementation and version, so test each combination you intend to run.
- The operation names used here are this article’s examples. A given server may name, split or combine them differently.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

