QueryIO
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| QUERYIO_MAX_ROWS | No | Maximum rows returned by query. Default 100. | 100 |
| QUERYIO_AUDIT_LOG | No | Path to append-only JSONL audit log. Set to 'off' to disable. Default ~/.queryio/audit.jsonl. | ~/.queryio/audit.jsonl |
| QUERYIO_REDACT_ADD | No | Comma-separated column names to add to redaction patterns. Default empty. | |
| QUERYIO_DATABASE_URL | Yes | PostgreSQL connection string (postgres://user:pass@host:port/db). CLI args and .env scanning are forbidden. | |
| QUERYIO_REDACT_REMOVE | No | Comma-separated column names to remove from redaction patterns. Default empty. | |
| QUERYIO_LOCK_TIMEOUT_MS | No | Server-side lock_timeout set per transaction in PostgreSQL (milliseconds). Default 1000 (1s). | 1000 |
| QUERYIO_MAX_VALUE_LENGTH | No | Character limit for individual column string values before truncation with …[+size]. Default 200. | 200 |
| QUERYIO_AUDIT_INCLUDE_SQL | No | When "true", includes raw SQL query text in audit logs. Keep false to avoid logging sensitive literals. Default false. | false |
| QUERYIO_MAX_RESPONSE_BYTES | No | Maximum serialized response size before retrieval stops (truncated_by: "bytes"). Bounds query only. Default 32768 (32 KB). | 32768 |
| QUERYIO_INSPECT_DEADLINE_MS | No | Total server-side deadline for an entire inspect_row call (milliseconds). Default 5000 (5s). | 5000 |
| QUERYIO_INSPECT_RELATED_ROWS | No | Maximum rows returned per relation in inspect_row. Default 5. | 5 |
| QUERYIO_STATEMENT_TIMEOUT_MS | No | Server-side statement_timeout set per transaction in PostgreSQL (milliseconds). Default 5000 (5s). | 5000 |
| QUERYIO_INSPECT_MAX_RELATIONS | No | Maximum number of relations inspected before capping with reason max_relations. Default 25. | 25 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| queryA | Run one read-only SQL statement (SELECT, WITH, VALUES, TABLE, SHOW) against PostgreSQL. Runs in a read-only transaction that is always rolled back, with server-side timeouts. Results are bounded: has_more means more rows existed (truncated_by says whether the row cap or byte budget stopped retrieval), and long values are cut with a …[+size] marker. Columns with sensitive-looking names (password, token, api_key, ...) come back as [redacted], counted in columns_redacted and values_redacted. |
| list_tablesA | List tables outside system schemas: schema-qualified name, estimated_rows (planner estimate, null if never analyzed; no scans), and column count. Optional filter: case-insensitive substring matched against table and column names. |
| describe_tablesA | Describe several tables in one call: columns (name, type, nullable), primary key, outgoing and incoming foreign keys (constraint, from_table/from_columns, to_table/to_columns, paired by position), and indexes. Each column carries planner statistics (no scans): stats_available, and when true null_frac, n_distinct (negative = minus the distinct fraction of rows, -1 = unique) and, for enum-like non-sensitive columns, common_values with frequencies. Columns matching a redaction pattern get stats_available: false, redacted: true. Unknown tables get a per-table error; the rest still succeed. |
| inspect_rowA | Fetch one row by its full primary key plus its depth-1 declared foreign-key neighborhood in one call. Each relation is one FK constraint: direction outgoing (rows the root references) or incoming (rows referencing the root), the related table, constraint, source_columns (referencing) paired by position with target_columns (referenced), status (ok, timeout, error), and compact rows (columns once, rows as arrays). Each relation returns up to N rows (default 5) ordered by the related table's primary key (order_by; ctid without one), never by recency; has_more means more rows existed, with no count. Relations not attempted due to the relation cap or total deadline are listed in relations_not_attempted with reason (max_relations, deadline). Values are truncated and redacted as in query, totalled in values_truncated and values_redacted. Tables without a declared primary key need query instead. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 4 tools
Each tool has a clearly distinct role: query runs arbitrary SQL, list_tables enumerates tables, describe_tables returns schema/statistics, and inspect_row fetches a single row plus its FK neighborhood. There is no overlap that would cause misselection.
list_tables, describe_tables, and inspect_row follow a consistent verb_noun pattern, while query is a bare verb/noun that breaks the pattern slightly. Still predictable and readable overall.
Four tools is well-scoped for a read-only PostgreSQL exploration server; each tool covers a distinct layer (raw SQL, table listing, schema detail, row+FK inspection) and earns its place.
For an intentionally read-only server, the surface covers listing, schema description, querying, and row/relationship inspection well. Write operations and connection/health introspection are absent, but that appears to be by design rather than a functional gap.