database-mcp
MCP servers for SQL databases. One package per engine (SQLite, libSQL, MySQL, MariaDB, Postgres), two tools, read-only by default, secrets never in logs.
Documentation
database-mcp
MCP servers that give AI clients safe, structured access to SQL databases.
One installable package per database engine, in TypeScript (npm) and Python
(PyPI). Every package exposes the same minimal two-tool surface,
`execute_sql` and `search_objects`, with guardrails on by default: read-only
mode, row caps, and statement timeouts.
Packages
| Engine | TypeScript (npm) | Python (PyPI) |
|---|---|---|
| SQLite | `@database-mcp/sqlite`  | `database-mcp-sqlite`  |
| libSQL | `@database-mcp/libsql`  | `database-mcp-libsql`  |
| MySQL | `@database-mcp/mysql`  | `database-mcp-mysql`  |
| MariaDB | `@database-mcp/mariadb`  | `database-mcp-mariadb`  |
| Postgres | `@database-mcp/postgres`  | `database-mcp-postgres`  |
Both lines are published and pass the same language-agnostic conformance
suite against real databases in CI, so behavior is identical regardless of
language. Every engine is also listed on the
MCP Registry with both install
options.
Go and Rust implementations are planned.
Design principles
- Two tools, no more. A tiny tool surface keeps the model's context window
clean. `search_objects` progressively discloses schema: call it with no
arguments to list tables, with a table name to get columns, indexes, and
foreign keys.
- Safe by default. Read-only mode is enforced in two layers: a
conservative SQL guard, plus a session-level read-only setting in the
database itself. Rows are capped (default 1000) and statements time out
(default 30s).
- Configured at launch, never via chat. Connection details come from
flags, a YAML config file, or environment variables. Credentials are never
accepted through a tool call.
- Secrets never appear in logs. Passwords live in non-printable secret
types, DSNs are sanitized before logging, and a redaction filter guards the
log boundary.
Quick start
Pick your engine's package; each README has the full config surface. SQLite
via npm:
{
"mcpServers": {
"sqlite": {
"command": "npx",
"args": ["-y", "@database-mcp/sqlite", "--dsn", "/absolute/path/to/database.db"]
}
}
}Or via PyPI: use `"command": "uvx"` and
`"args": ["database-mcp-sqlite", "--dsn", "/absolute/path/to/database.db"]`.
Flags, environment variables, and YAML config are identical across both
lines.
Networked engines take credentials from the environment (`MYSQL_*`,
`MARIADB_*`, `POSTGRES_*`/`DATABASE_URL`, `LIBSQL_URL`/`LIBSQL_AUTH_TOKEN`),
`*_FILE` mounted secrets, or a YAML file via `--config`. Never from a chat
prompt.
Contributing
See CONTRIBUTING.md. The short version: the conformance
suite is the definition of done. A change is mergeable only when
`conformance/run.mjs` passes against every affected server.
License
Frequently asked questions
What is database-mcp?
database-mcp is MCP servers for SQL databases. One package per engine (SQLite, libSQL, MySQL, MariaDB, Postgres), two tools, read-only by default, secrets never in logs.
How do I install database-mcp?
Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.
Is database-mcp open source?
Yes — it is hosted on GitHub at https://github.com/arifulislamat/database-mcp and has 5 stars.
Related MCP tools
Python SQL Parser and Transpiler
Give your AI agents persistent, collective memory — with deduplicating absorb, supersession lineage, semantic search, and a graph UI. Speaks MCP.
Fast and Accurate Code Search for Agents. Uses 99% fewer tokens than grep+read
Cut AI token costs 95%+ on code exploration. The leading MCP server for precise, symbol-level GitHub code retrieval via tree-sitter AST. Works with Claude Code, Cursor & any MCP client. 313B+ tokens saved.
MCP server and Claude plugin for Postgres skills and documentation. Helps AI coding tools generate better PostgreSQL code.
AI-powered OSINT agent with interactive REPL, MCP server, and CLI. 19 tools. Works with Claude, GPT-4, or local models. For authorized security research only.
Run your own MCP server? See who uses it and what to fix.
Measure it with TrackMCP