multi-monetdb-mcp-server
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@multi-monetdb-mcp-serverlist my MonetDB databases and show the schema of the analytics one"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
multi-monetdb-mcp-server
One MCP server for all your MonetDB databases.
A companion to multi-postgres-mcp-server, built for MonetDB column-store databases.
Documentation
Document | Audience | Contents |
AI agents & developers | Tool call sequences, decision flow, examples | |
Operators | Config file template | |
This README | Setup | Install, Cursor config, environment restriction |
Related MCP server: mcp-postgres
Features
One server for all MonetDB databases
Config file with named labels (
analytics,staging, …)Dynamic connect — user provides credentials at runtime via
mdb_connectHot reload — config changes apply within ~5 seconds, no restart
--labelfilter — expose only one database per Cursor project--no-dynamic— block runtimemdb_connectfor locked-down projectsRead-only by default — writes blocked unless
readOnly: false
Two connection modes
Always call mdb_list_databases first — it tells the AI which mode applies.
Mode | When | How |
A — Config label | DB defined in |
|
B — Dynamic | User gives credentials in chat |
|
See USAGE.md for full examples and AI workflow.
Quick Start
1. Install & build
cd multi-monetdb-mcp-server
npm install
npm run build2. Add to Cursor
Global or project .cursor/mcp.json:
{
"mcpServers": {
"monetdb": {
"command": "node",
"args": ["C:/Code/MCPServer/multi-monetdb-mcp-server/dist/index.js"]
}
}
}3. First use
Ask the AI to call mdb_list_databases. It will show config labels or guide you through mdb_connect.
Restricting access per project (Cursor)
When multiple environments exist (production, staging, dev), you can limit what the AI sees per Cursor project using .cursor/mcp.json in each project folder.
Option 1: --label (single database from shared config)
One global ~/.mcp-monetdb/config.json holds all environments. Each project exposes only its label:
~/.mcp-monetdb/config.json (shared):
{
"connections": [
{ "label": "production", "host": "prod.db.com", "port": 50000, "user": "ro", "password": "...", "database": "warehouse", "readOnly": true },
{ "label": "staging", "host": "stg.db.com", "port": 50000, "user": "dev", "password": "...", "database": "warehouse", "readOnly": true },
{ "label": "local", "host": "localhost", "port": 50000, "user": "monetdb", "password": "monetdb", "database": "demo", "readOnly": false }
]
}Project A — .cursor/mcp.json (production only):
{
"mcpServers": {
"monetdb": {
"command": "node",
"args": [
"C:/Code/MCPServer/multi-monetdb-mcp-server/dist/index.js",
"--label",
"production"
]
}
}
}Project B — .cursor/mcp.json (staging only):
{
"mcpServers": {
"monetdb": {
"command": "node",
"args": [
"C:/Code/MCPServer/multi-monetdb-mcp-server/dist/index.js",
"--label",
"staging"
]
}
}
}Effect:
mdb_list_databasesshows only the filtered labelAI cannot see other environment names
AI uses
database="production"(or"staging") on tool calls
Option 2: Project-specific config file
Each project has its own config with only the connections it needs:
Project A — .cursor/mcp.json:
{
"mcpServers": {
"monetdb": {
"command": "node",
"args": [
"C:/Code/MCPServer/multi-monetdb-mcp-server/dist/index.js",
"--config",
"C:/Projects/ProjectA/.cursor/monetdb.json"
]
}
}
}ProjectA/.cursor/monetdb.json:
{
"connections": [
{
"label": "production",
"host": "prod.db.com",
"port": 50000,
"user": "readonly",
"password": "secret",
"database": "warehouse",
"readOnly": true
}
]
}Effect:
Other environments are not in the file at all
No
--labelneeded — only one connection existsBest for strongest isolation between teams/projects
Option 3: --no-dynamic (block runtime credentials)
Prevent the AI from calling mdb_connect with arbitrary credentials. Use with --label or a project config:
{
"mcpServers": {
"monetdb": {
"command": "node",
"args": [
"C:/Code/MCPServer/multi-monetdb-mcp-server/dist/index.js",
"--label",
"production",
"--no-dynamic"
]
}
}
}Effect:
mdb_connectis rejected — config labels onlyUser cannot bypass restriction by pasting credentials in chat
Recommended for production-facing projects
Option 4: Combine all restrictions (recommended for production)
{
"mcpServers": {
"monetdb": {
"command": "node",
"args": [
"C:/Code/MCPServer/multi-monetdb-mcp-server/dist/index.js",
"--config",
"C:/Projects/MyApp/.cursor/monetdb.json",
"--label",
"production",
"--no-dynamic"
]
}
}
}Restriction summary
Flag / setting | What it restricts |
| Only one config label visible to AI |
| Which config file to load (project-specific) |
| Blocks |
| Blocks INSERT/UPDATE/DELETE/DROP in SQL |
| Hides a connection from shared config (soft disable) |
Custom config via environment variable
Alternative to --config in args:
{
"mcpServers": {
"monetdb": {
"command": "node",
"args": ["C:/Code/MCPServer/multi-monetdb-mcp-server/dist/index.js", "--label", "staging"],
"env": {
"MCP_MONETDB_CONFIG": "C:/Projects/MyApp/.cursor/monetdb.json"
}
}
}
}Default config path: ~/.mcp-monetdb/config.json
Config file reference
{
"connections": [
{
"label": "analytics",
"host": "db.example.com",
"port": 50000,
"user": "readonly_user",
"password": "secret",
"database": "analytics",
"enabled": true,
"readOnly": true
}
]
}Field | Default | Description |
| (required) | Name used as |
| — | MonetDB server hostname |
|
| MAPI port |
| — | Username |
|
| Password |
| — | Database name |
| — | Full MAPI URL (alternative to host/user/password/database) |
|
| Set |
|
| Block write queries |
|
| Connection timeout (ms) |
Environment variable substitution in config values:
{ "password": "${MONETDB_PASSWORD:-monetdb}" }Tools
Tool | Description |
| Start here. Labels, session status, connection guide |
| Runtime credentials (blocked when |
| Close dynamic session |
| Execute SQL |
| List tables |
| Column types |
| List schemas |
| Connectivity check |
| EXPLAIN plan |
Security
Read-only by default (
readOnly: true)Use
--no-dynamic+--labelin production Cursor projectsDynamic credentials never saved to config
Multi-statement queries rejected
Config passwords excluded from git via
.gitignore
Source layout
src/
index.ts Entry point
types.ts Shared types
config/ CLI, schemas, loader
connection/ Pool, dynamic session
sql/ Safety, query execution
guidance/ AI connection guide
tools/ MCP tool registrationsLicense
This server cannot be deployed
Maintenance
Related MCP Connectors
- dataOAuthco.thinair
PostgreSQL, MySQL, and SQL Server in one session. 26 read-only MCP tools for AI agents.
Draxlr's remote MCP server connects AI assistants to your SQL databases and dashboards. Explore schemas, run read-only queries, manage saved queries and dashboards, and export results, all with row-level security so each user sees only their own data.
Safe, read-only Postgres and MySQL access for AI agents. Audit log + column-level controls.
List datasets, schemas, run APL queries, and use prompts for exploration, anomalies, and monitoring.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables safe exploration and querying of multiple databases (PostgreSQL, MySQL, SQLite, DB2) with read-only defaults, connection pooling, and parameterized queries for SQL injection prevention.1MIT
- FlicenseNot gradedqualityDmaintenanceEnables AI agents to execute SQL queries and introspect PostgreSQL schemas, tables, and indexes with read-only safety by default. Supports optional write operations and works with Claude, LangChain, and other agents via stdio or HTTP transports.-
- AlicenseAqualityBmaintenanceProvides AI agents a secure MCP interface to a single MySQL or MariaDB database, enabling schema inspection, read-only queries, query planning, and guarded write operations with strict safety controls.623 npmMIT
- AlicenseNot gradedqualityAmaintenanceEnables AI agents to safely explore and query databases across SQLite, PostgreSQL, MySQL, and MSSQL, with schema introspection, natural language queries, and data profiling.MIT