Skip to main content
Glama
ThinAirTelematics

ThinAir Data

Official
README.md
# ThinAir Data MCP Server

**The only MCP database server for PostgreSQL, MySQL, and SQL Server in one session** — 26 tools across 4 tiers — schema introspection, cross-database compare, query firewall, PII scanning, N+1 detection, and runtime connection management. Read-only data access by design.

**<!-- BEGIN:TOOLCOUNT -->26<!-- END:TOOLCOUNT --> tools** · PostgreSQL · MySQL · SQL Server · Read-only data access, schema discovery, profiling, SQL safety, anomaly detection

[![npm version](https://img.shields.io/npm/v/@thinairtelematics/data)](https://www.npmjs.com/package/@thinairtelematics/data)
[![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE)
[![smithery badge](https://smithery.ai/badge/thinair/data)](https://smithery.ai/servers/thinair/data)

```console
> describe_schema("fleet")
✓ 42 tables discovered · 6 high-value entities
✓ no write permissions enabled
> ask("Which vehicles had the most idle time last week?")
✓ generated safe read-only SQL · returned 10 rows · flagged 3 exceptions
```

## Part of ThinAir

ThinAir Data is part of the ThinAir platform for fleet visibility, analytics, operational search, reporting, and AI-assisted decision support.

## Hosted product vs this repository

- `data.thinair.co` is the hosted ThinAir product.
- This repository is the thin public MCP package/pointer for developers and AI-agent clients.
- Production use may require a ThinAir account, API key, OAuth connection, or hosted workspace.

## What It Does

ThinAir Data is a [Model Context Protocol (MCP)](https://modelcontextprotocol.io) server that gives AI agents secure, **read-only** access to your databases — no custom backend required. Designed for read-only production access when configured correctly. ThinAir Data enforces read-only behavior through SQL guards, database-session read-only mode where supported, and optional per-connection firewall rules. You should still use least-privilege database credentials and avoid exposing sensitive tables unless required.

- **Multi-database** — PostgreSQL, MySQL, SQL Server in a single session. Cross-database compare with one tool call.
- **Read-only by design** — SQL guards, database-session read-only mode where supported, and optional per-connection firewall rules.
- **Dialect-aware** — every tool understands `SELECT TOP 10` (mssql) vs `LIMIT` (others) and routes syntax correctly per connection.
- **Tiered capability** — 26 tools across 4 tiers: schema introspection, query execution + history, EXPLAIN/optimization, anomaly detection, PII scanning, N+1 detection, query firewall, cross-DB compare, and runtime connection management (add/remove).
- **Connections are managed at runtime** — added per-tenant via the `add_connection` tool after sign-in. Never an env var or install-time config.

## Product Links

- **Product:** https://data.thinair.co
- **Connect a database:** https://data.thinair.co/connect
- **Docs:** https://data.thinair.co/docs/getting-started
- **Pricing:** https://data.thinair.co/checkout
- **ThinAir:** https://thinair.co

## Agent Discovery

<!-- BEGIN:AGENT-DISCOVERY -->
Autonomous agents and directory crawlers can discover this server's capabilities
without parsing this README. All three surfaces are live and served by the hosted
product:

| Surface | URL | Carries |
|---------|-----|---------|
| Agent card (A2A) | `https://data.thinair.co/.well-known/agent-card.json` | Protocol version, endpoint, transport, auth schemes, and all 26 skills |
| Skills index | `https://data.thinair.co/.well-known/skills.json` | Machine-readable catalog of the 26 tools |
| LLM guide | `https://data.thinair.co/llms.txt` | Plain-text orientation for language models |

The MCP endpoint itself is `https://data.thinair.co/mcp` (streamable-http; OAuth 2.1
keyless, or `Authorization: Bearer`).
<!-- END:AGENT-DISCOVERY -->

## Tools (selected — full list of 26 in [docs](https://data.thinair.co/docs/tools))

<!-- BEGIN:TOOLS -->
| Tool | Tier | Description |
|------|------|-------------|
| `list_connections` | discover | List connected databases with names + dialects |
| `describe_schema` | discover | Get schema, columns, indexes, FKs across any connection |
| `query_sql` | discover | Execute a parameterized read-only SQL query |
| `query_history` | build | Recent queries with timing, row counts, status |
| `data_profile` | build | Distributions, null rates, cardinality on a table |
| `cross_db_query` | architect | Run the same query across 2–4 connections (regional/dialect compare) |
| `detect_anomalies` | architect | Statistical outliers in row growth, latency, value distributions |
| `pii_scan` | architect | Scan a table for PII patterns (SSN, email, phone, credit card) |
| `find_n_plus_one` | architect | Identify N+1 query patterns in `query_history` |
| `query_firewall` | architect | Per-connection custom-block rules (deny specific tables/queries) |

`add_connection`, `remove_connection`, `optimize_query`, `explain_query`, `suggest_queries`, `generate_migration`, `generate_seed_data`, `watch_table`, `saved_queries`, `impact_analysis`, `configure_allowlist`, and others round out the 26-tool surface.
<!-- END:TOOLS -->

## Quick Start

### Claude Desktop, Cursor, Windsurf — OAuth (recommended, keyless)

Add to your client's MCP config (e.g. `~/Library/Application Support/Claude/claude_desktop_config.json`):

```json
{
  "mcpServers": {
    "thinair-data": {
      "url": "https://data.thinair.co/mcp"
    }
  }
}
```

The OAuth flow completes at first use — no manual token setup required. After sign-in, your agent calls `add_connection` to register a database with its DSN — connections are tenant-scoped and reusable across sessions.

### API key (for non-OAuth clients)

```json
{
  "mcpServers": {
    "thinair-data": {
      "url": "https://data.thinair.co/mcp",
      "headers": {
        "Authorization": "Bearer ta_live_..."
      }
    }
  }
}
```

Get a key at https://data.thinair.co/connect.

### npx (CLI / scripts)

```bash
npx -y @thinairtelematics/data
```

Prints a config block to stdout. OAuth-keyless by default.

## Supported Databases

Database connections are added at **runtime** via the `add_connection` MCP tool — pass the DSN once, the connection becomes a named resource the agent can reuse across sessions. Three dialects supported:

| Database | Connection string format |
|----------|--------------------------|
| PostgreSQL | `postgresql://user:pass@host:5432/db` |
| MySQL | `mysql://user:pass@host:3306/db` |
| SQL Server | `sqlserver://user:pass@host:1433/db` |

You do **not** put a DSN in your client's config. The `add_connection` tool is how connections enter the session.

## Example Usage

Once connected, ask your AI:

- *"Show me all rows that haven’t updated in the last 24 hours across staging and prod"*
- *"What are the top 10 slowest queries this week?"*
- *"Scan the customers table for PII patterns"*
- *"Which tables have the most N+1 query exposure?"*

## Not for secrets

Do not commit DSNs, passwords, tokens, private keys, or production credentials. Use OAuth, the hosted connection flow, or your MCP client's secret storage.

## npm Package

[npmjs.com/package/@thinairtelematics/data](https://www.npmjs.com/package/@thinairtelematics/data)

> Previously published as `thinair-data` (now deprecated in favor of the scoped package).

## License

MIT © [ThinAir Telematics](https://thinair.co)

TDQS

A3.7/5.0

Scored across 23 tools

Disambiguation4/5

Most tools have clearly distinct purposes (schema, querying, profiling, etc.), though analyze_table and data_profile overlap in table statistics, and explain_query with optimize_query both address performance. Descriptions effectively differentiate them, but ambiguity exists for a couple of pairs.

Naming Consistency4/5

The majority of tool names follow a verb_noun pattern (analyze_table, describe_schema, etc.), but there are minor deviations like cross_db_query (adjective_noun) and quota (single noun). Overall pattern is consistent and readable.

Tool Count3/5

At 23 tools, the set is on the heavier side for a data management server. While each tool serves a distinct purpose (schema, querying, profiling, security, migrations), the number is borderline and could feel bloated for simpler use cases.

Completeness5/5

The tool surface is highly comprehensive for a data observability/management server, covering schema discovery, query execution/optimization, profiling, PII scanning, anomaly detection, migrations, security, and admin tasks. No obvious gaps within the intended scope.

Maintenance

ActivityMaintained
ResponsivenessNo issues