Three open source business intelligence tools turn a database into charts and dashboards on your own server, and what sets them apart first is how much SQL they expect from you. Metabase lets you build a question with the mouse, without writing SQL, but keeps SAML and OIDC sign-in, row-level security and full embedding for its paid plans. Apache Superset, an Apache Software Foundation project with no paid edition, builds charts on datasets defined once for the whole team, and its docs point production installs to Kubernetes. Redash is BSD-licensed and starts every chart from a hand-written query; volunteer maintainers have kept it going since 2023, with no backing from Databricks, which bought the company behind it.
No SQL, SQL, or a data warehouse: who each tool is for
Metabase's README promises that anyone in the company can ask questions without knowing SQL. Its visual editor filters, summarizes and joins tables with point and click, and "View SQL" shows the query it will send. A SQL editor takes over for more involved queries, with two catches: turning a visual question into SQL is one-way, and a question written in SQL only gets a limited drill-through menu.
Superset is aimed at teams that already run a data warehouse. It stores no data of its own: every chart sends a SQL query to the database that holds the data, and the FAQ calls Superset a thin layer on top, to the point of telling you to tune the warehouse when things are slow. A chart is built without code on a dataset, meaning a table or view whose metrics are defined once, or written in SQL Lab. The exploration UI works on a single table or view, so combining tables takes a view, a table prepared upstream, or SQL. The README says Superset can "replace or augment" proprietary BI tools.
Redash starts from the query. Its README splits the roles: people who write SQL explore and visualize, and the rest of the organisation reads what they built. Queries are written in SQL, or in the source's own language for MongoDB or Elasticsearch, and parameters in double curly braces rerun them on another date or value. The "Query Results" source joins the output of several queries in an in-memory SQLite database, a PostgreSQL table with a Google Sheets tab for instance, though it can fail on a large result. Users without full access to a data source only get typed parameters (number, date, dropdown list): text parameters, open to SQL injection, stay closed to them.
Metabase documents eighteen official database drivers, plus community drivers that its cloud won't accept. Superset can query any engine that has a Python driver and a SQLAlchemy dialect. The built-in list in Redash's README runs to 69 sources, among them Prometheus, Google Sheets, CSV or Excel files and JSON APIs.
What each tool needs to run
Read from the repositories and documentation on 7 October 2026.
| Tool | Licence | What you run | Queries | Paid edition | Latest release |
|---|---|---|---|---|---|
| Metabase | AGPL-3.0, except the enterprise/ directory | a Docker image or a JAR (Java 25); PostgreSQL advised for its own data | visual editor without SQL, or SQL | Pro and Enterprise: SAML, OIDC, row-level security, full embedding | 0.63.19, 1 Oct 2026 |
| Apache Superset | Apache-2.0 | Python app, metadata database, cache (usually Redis), Celery workers; Kubernetes in production | no-code datasets, or SQL Lab | none; hosted version sold by Preset | 6.1.0, 13 May 2026 |
| Redash | BSD-2-Clause | PostgreSQL, Redis, web server, scheduler, workers; at least 4 GB of RAM | SQL, or the source's own language | none; no hosted plan listed | 26.9.0, 24 Sep 2026 |
Out of the box, Metabase keeps its own data in a local H2 database, which its docs say to avoid in production: they recommend PostgreSQL and also accept MySQL 8.4 or MariaDB 10.6. No minimum memory is documented, and by default the JVM claims about a quarter of the machine's RAM.
Superset won't start without a SECRET_KEY, and its default Docker image, lean, ships no database driver, not even for the metadata store, so you build your own image. The cache and the Celery workers are optional, but alerts, reports and async queries depend on them. Docker Compose is for trying it out: the project doesn't support it in production because it can't provide high availability, and the PostgreSQL it starts isn't backed up. Kubernetes is the recommended route, and the docs say it takes someone who knows Kubernetes. The Helm chart has been deprecated since 9 September 2026 in favour of an operator at version 0.3.0, whose v1alpha1 API may still change. On memory, the FAQ reports community admins finding 8 GB of RAM and 2 vCPUs enough for a moderately sized instance, with sizing driven by the number of users more than by data volume. Superset also sends telemetry to Scarf by default: SCARF_ANALYTICS=false only turns off the page-view pixel, and the Docker image gateway and the npm package have to be opted out of separately.
Redash's reference Compose file, in the getredash/setup repository, starts eight containers, including three workers and an nginx, and every documented install method goes through Docker. The setup script's FAQ calls it fine for production on a small deployment. Beyond that, it recommends moving PostgreSQL, and probably Redis, onto their own servers and running Redash on at least two servers.
Who maintains each project, and how often it ships
Metabase is backed by a company that sells Metabase Cloud and the Pro and Enterprise editions: the first thing its README offers is a free trial of the cloud version. It shipped six major versions between January and July 2026, from 58.1 on 6 January to 63.1 on 21 July, and 64.0 has been in beta since 24 September. Fixes land on several branches at once: on 1 September, six releases went out, from 58 to 63. Support for the open source edition is the community forum.
Apache Superset is an Apache Software Foundation project. Preset, founded by Superset's creator, sells a hosted version and says its team contributes over 75% of the project's commits. A release comes out every five to seven months: 5.0.0 in June 2025, 6.0.0 in December 2025 after four release candidates, 6.1.0 on 13 May 2026. Version 6.0.0 fixed four CVEs, including a bypass of SQL Lab's read-only mode on PostgreSQL.
Databricks acquired the company behind Redash in June 2020. In April 2023, Arik Fraimovich, the project's author, relaunched it as a community project with seven volunteer maintainers; Databricks keeps an internal fork built into its platform and doesn't support development of the open source version. Nothing shipped between 10.1.0 in November 2021 and 25.1.0 in January 2025; since then the project has put out two releases a year, numbered by year and month. Version 26.9.0, released on 24 September 2026, fixes thirteen published security advisories, six of them rated high, and its release notes urge every installation to upgrade, especially those where users have different permissions on data sources.
Licences, paid editions and hosted plans
Metabase's repository mixes two licences: AGPL-3.0 outside the enterprise/ directory, a commercial licence inside it. Every release ships as two images, metabase/metabase for the open source edition and metabase/metabase-enterprise, which only unlocks its features with a licence token. Pro and Enterprise keep SAML, JWT and OIDC sign-in, two-factor authentication, row- and column-level security, exporting content between instances, Git sync and the log of who viewed what. The open source edition allows unlimited users, Google sign-in and LDAP. It can embed charts and dashboards in another application, but with a "Powered by Metabase" banner and without the visual editor; removing the banner or embedding the whole application takes Pro or Enterprise. At the prices listed on 7 October 2026, Pro costs 575 dollars a month for ten users, then 12 dollars per user, and Enterprise starts at 20,000 dollars a year; both can be self-hosted or run on Metabase Cloud. A Starter plan, at 100 dollars a month for five users, exists only in the cloud.
Superset is entirely under Apache-2.0, with nothing held back. Part of what Metabase charges for is free here: row-level security filters attached to datasets, sign-in through OAuth or LDAP, and embedding a dashboard in another application through a JavaScript SDK and a guest token. The paid offer lives at Preset, which hosts Superset for free up to five users, then at 20 dollars per user per month on an annual plan. Its pricing page keeps scheduled reports and alerts for paid plans, while a self-hosted Superset instance provides them too once its Celery workers are running.
Redash is under BSD-2-Clause, and its code handles Google OAuth, SAML, LDAP, JWT tokens and identities passed by a reverse proxy. The redash.io site lists no pricing and no hosted plan.
