Database MCP Server
MCP 서버는 AI 클라이언트가 SQL 데이터베이스에 안전하고 구조화된 방식으로 접근할 수 있도록 합니다. 데이터베이스 엔진별로 하나의 설치 가능한 패키지가 제공됩니다. 각 패키지는 동일한 최소한의 두 가지 도구(execute_sql 및 search_objects)를 노출하며, 기본적으로 읽기 전용 모드, 행 제한, 명령문 시간 제한과 같은 보호 장치가 활성화되어 있습니다.
문서
database-mcp
MCP servers that give AI clients safe, structured access to SQL databases.
One installable package per database engine, in TypeScript (npm) and Python
(PyPI). Every package exposes the same minimal two-tool surface,
execute_sql and search_objects, with guardrails on by default: read-only
mode, row caps, and statement timeouts.
Packages
| Engine | TypeScript (npm) | Python (PyPI) |
|---|---|---|
| SQLite | @database-mcp/sqlite | database-mcp-sqlite |
| libSQL | @database-mcp/libsql | database-mcp-libsql |
| MySQL | @database-mcp/mysql | database-mcp-mysql |
| MariaDB | @database-mcp/mariadb | database-mcp-mariadb |
| Postgres | @database-mcp/postgres | database-mcp-postgres |
Both lines are published and pass the same language-agnostic conformance suite against real databases in CI, so behavior is identical regardless of language. Every engine is also listed on the MCP Registry with both install options.
Go and Rust implementations are planned.
Design principles
- Two tools, no more. A tiny tool surface keeps the model's context window
clean.
search_objectsprogressively discloses schema: call it with no arguments to list tables, with a table name to get columns, indexes, and foreign keys. - Safe by default. Read-only mode is enforced in two layers: a conservative SQL guard, plus a session-level read-only setting in the database itself. Rows are capped (default 1000) and statements time out (default 30s).
- Configured at launch, never via chat. Connection details come from flags, a YAML config file, or environment variables. Credentials are never accepted through a tool call.
- Secrets never appear in logs. Passwords live in non-printable secret types, DSNs are sanitized before logging, and a redaction filter guards the log boundary.
Quick start
Pick your engine's package; each README has the full config surface. SQLite via npm:
{
"mcpServers": {
"sqlite": {
"command": "npx",
"args": ["-y", "@database-mcp/sqlite", "--dsn", "/absolute/path/to/database.db"]
}
}
}
Or via PyPI: use "command": "uvx" and
"args": ["database-mcp-sqlite", "--dsn", "/absolute/path/to/database.db"].
Flags, environment variables, and YAML config are identical across both
lines.
Networked engines take credentials from the environment (MYSQL_*,
MARIADB_*, POSTGRES_*/DATABASE_URL, LIBSQL_URL/LIBSQL_AUTH_TOKEN),
*_FILE mounted secrets, or a YAML file via --config. Never from a chat
prompt.
Contributing
See CONTRIBUTING.md. The short version: the conformance
suite is the definition of done. A change is mergeable only when
conformance/run.mjs passes against every affected server.