crispy-mysql-mcp-guard
Provides tools for interacting with MariaDB databases, allowing read-only queries by default and opt-in write operations (insert, update, delete, DDL) per connection, along with schema inspection.
Provides tools for interacting with MySQL databases, allowing read-only queries by default and opt-in write operations (insert, update, delete, DDL) per connection, along with schema inspection.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@crispy-mysql-mcp-guardshow me the top 5 customers by revenue in the shop-dev database"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
crispy-mysql-mcp-guard
A Model Context Protocol server for MySQL (and MariaDB) where every connection decides separately which operations it allows: select, insert, update, delete and ddl.
Default is read only. Anything else has to be switched on, per connection, in plain JSON.
One server, any number of connections, each with its own permissions.
Reads run in a
READ ONLYtransaction, so the database itself refuses writes on the read path.Exactly one statement per call. Multi-statements, executable comments (
/*! ... */),INTO OUTFILE,LOAD_FILE(),LOAD DATA,GRANT,SET,CALL,USEand user/role management are rejected.Result sets are capped (
maxRows, default 1000) and reporttruncated. Large results are streamed and cut off, not loaded into memory first.No password ever leaves the server:
mysql_list_connectionsshows host, database and permissions only.Configuration is JSON (command-line flags or a file). The server does not read
MYSQL_*environment variables, so a project.envcannot change which database you talk to.
Quick start
No npm release yet; run it straight from GitHub (needs Node 20+):
npx -y github:andrenalin282/crispy-mysql-mcp-guard --helpClaude Code / any .mcp.json
One connection, configured inline, same shape as most MCP servers:
{
"mcpServers": {
"mysql-shop": {
"type": "stdio",
"command": "npx",
"args": [
"-y", "github:andrenalin282/crispy-mysql-mcp-guard",
"--name", "shop",
"--host", "localhost",
"--port", "3306",
"--user", "shop_user",
"--password", "secret",
"--database", "shop",
"--allow", "select,insert,update"
]
}
}
}--allow takes any of select,insert,update,delete,ddl. Leave it out for read only.
Several connections, one config file (keeps passwords out of .mcp.json):
{
"mcpServers": {
"mysql": {
"type": "stdio",
"command": "npx",
"args": ["-y", "github:andrenalin282/crispy-mysql-mcp-guard", "--config", "/home/me/.config/crispy-mysql-mcp-guard/config.json"]
}
}
}{
"connections": {
"shop-live": {
"host": "db.example.com",
"user": "reader",
"password": "${SHOP_LIVE_PASSWORD}",
"database": "shop",
"ssl": true,
"allow": { "select": true }
},
"shop-dev": {
"host": "localhost",
"user": "root",
"password": "dev",
"database": "shop_dev",
"allow": { "select": true, "insert": true, "update": true, "delete": true, "ddl": false },
"maxRows": 500,
"timeoutMs": 15000
}
}
}The agent then picks a connection per call: mysql_query with "connection": "shop-dev". With a single connection the name can be omitted.
A full example is in mysql-mcp.example.json.
Where the config is read from
First match wins:
--config <file>(relative paths are resolved against the working directory)single-connection flags (
--host,--user, ...)MYSQL_MCP_GUARD_CONFIG(path to a config file)./mysql-mcp.json~/.config/crispy-mysql-mcp-guard/config.json
Related MCP server: MariaDB MCP Server
Connection options
Option | Default | Description |
|
| |
|
| |
| required | |
|
| Literal, or |
| none | Default schema. |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| Maximum rows returned per query (1 to 100000). |
|
| Query timeout. |
Command-line flags for a single connection: --name --host --port --user --password --database --ssl --allow --max-rows --timeout-ms. Unknown options, unknown operations and typos in the JSON are errors, not ignored.
Which statement needs which permission
Statement | Needs |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| whatever |
everything else | rejected |
Tools
Tool | What it does |
| Connections with host, database, allowed operations, limits. No passwords. |
| Runs one statement ( |
| Lists tables, or with |
Writes run in a transaction that is committed on success and rolled back on error. DDL commits implicitly in MySQL, as always. BIGINT values beyond 2^53 are returned as strings. Binary columns are summarized instead of dumped.
Security model, honestly
This is a guard rail for an AI agent, not a security boundary.
Use a database account with the least privileges you need. The
allowflags are checked by the server before the statement is sent; the database account is the real limit. A connection withallow: { select: true }and aSELECT-only account cannot be talked into anything else.The statement classifier is deliberately strict and refuses what it does not understand. It is not a full SQL parser, so a read can still call a stored function that writes; the
READ ONLYtransaction makes the server reject that on the read path.CALLis not supported at all, because a stored procedure can do anything its definer can.Passwords given as
--passwordare visible in the process list and in.mcp.json. Prefer a config file with mode600and${VAR}references for anything shared.There is no
WHEREcheck:DELETE FROM tis allowed ifdeleteis on. Give the agentdeleteonly where that is acceptable.
Development
npm install
npm run typecheck
npm testUnit tests (SQL classifier, config) run anywhere. Integration and end-to-end tests need a MySQL or MariaDB server with a database t, an account u (all privileges on t) and an account ro (SELECT only), both with password pw:
MMG_TEST_PORT=3306 MMG_TEST_HOST=127.0.0.1 npm testWithout MMG_TEST_PORT those tests are skipped.
Compatibility: tested against MariaDB 10.11 and MySQL 8.4.
License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
- dataOAuthco.thinair
PostgreSQL, MySQL, and SQL Server in one session. 26 read-only MCP tools for AI agents.
Guard AI agents' PostgreSQL/MySQL access via MCP: SQL audit, auth, masking, write approval
Let AI agents query data and act across all your business apps via MCP.
Draxlr's remote MCP server connects AI assistants to your SQL databases and dashboards. Explore schemas, run read-only queries, manage saved queries and dashboards, and export results, all with row-level security so each user sees only their own data.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables interaction with MySQL databases through MCP, supporting query execution, table operations (insert, update, delete), and schema inspection for natural language database management.185 npmMIT
- AlicenseBqualityCmaintenanceEnables AI assistants to securely interact with MariaDB and MySQL databases using granular per-connection read/write permissions and transaction support. It allows users to manage multiple database connections, explore schemas, and execute controlled SQL queries through a standardized interface.621 npm5MIT
- AlicenseAqualityDmaintenanceEnables AI agents to safely interact with MySQL/MariaDB databases, supporting read-only queries by default with optional write operations and access control.8MIT
- AlicenseAqualityDmaintenanceEnables AI agents to query and manage MySQL databases through a structured MCP interface, supporting SQL execution, table inspection, and database operations.98 npmMIT