sqlpad-mcp
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@sqlpad-mcpwhat's the schema of the orders table in the analytics connection?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
SQLPad MCP Server
An MCP server for SQLPad. Point an AI agent at a SQLPad instance with its base URL and a service token, and the agent can discover connections, inspect schemas, run SQL, and manage saved queries.
Requirements
Node.js 20 or later.
A reachable SQLPad instance.
The SQLPad server must have
SQLPAD_SERVICE_TOKEN_SECRETconfigured. Without it, every Bearer-authenticated request returns401 Unauthorized.A service token generated in the SQLPad admin GUI.
Related MCP server: SQLite Database MCP Server
Quick start
No install step is needed — run it straight from npm:
SQLPAD_SERVICE_TOKEN=... npx sqlpad-mcp --base-url https://sqlpad.example.comOr install it globally:
npm install -g sqlpad-mcpThe server speaks MCP over stdio, so it is normally launched by an MCP client rather than by hand. Running it directly is still useful to verify credentials: on success it logs the detected SQLPad version to stderr.
Configuration
Env var | CLI flag | Default | Meaning |
|
| (required) | Base URL of the SQLPad instance; a subpath mount is supported. |
|
| (required) | Service token, sent as |
|
|
| Register the saved-query write tools. |
|
|
| Register the admin-only tools. |
|
|
| Cap on rows returned per statement. |
|
|
| How long to poll a batch before returning a resumable |
A CLI flag takes precedence over the corresponding environment variable. The batch poll interval (250 ms) is internal and not configurable.
Claude Code configuration
Add the server to your Claude Code mcp.json:
{
"mcpServers": {
"sqlpad": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"sqlpad-mcp",
"--base-url",
"https://sqlpad.example.com"
],
"env": {
"SQLPAD_SERVICE_TOKEN": "..."
}
}
}
}Supplying the token through env keeps it out of the process argument list, which is world-readable through ps.
To enable the gated tool groups, add "SQLPAD_ALLOW_WRITES": "true" or "SQLPAD_ALLOW_ADMIN": "true" to the same env block.
Tools
Twelve tools are always registered. Six more are gated behind the two SQLPAD_ALLOW_* flags and are off by default.
Execution
Tool | Description |
| Execute arbitrary SQL, including DDL and DML, by creating an asynchronous SQLPad batch, polling it to completion, and returning rows inline. Not sandboxed. Rows are capped by |
| Get a batch and its current statement statuses. Call this after |
| Page through a large finished statement result instead of re-running the query. Returns a bounded page converted to objects using the statement's column names. |
| Request cancellation of an asynchronous batch. SQLPad rejects cancellation when the connection does not support asynchronous execution. |
Discovery
Tool | Description |
| List the connections available to the service token. Works with a non-admin token, unlike |
| Get a bounded database schema for a connection. Unfiltered full-schema output can be enormous — prefer |
| List SQLPad database drivers, bounded by the requested limit. |
Saved queries
Tool | Description |
| List saved queries using optional connection, text, tag, ownership, creator, and sort filters. |
| Get one saved query by ID. |
| List distinct saved-query tags, with bounded local pagination. |
| List the calling user's query history, newest first, with bounded local pagination. |
| Format SQL text using SQLPad. Older SQLPad servers may not provide this endpoint. |
Saved-query writes — requires SQLPAD_ALLOW_WRITES=true
Tool | Description |
| Create a saved query. |
| Replace the editable fields of an existing saved query. |
| Permanently delete a saved query. |
Admin — requires SQLPAD_ALLOW_ADMIN=true
These call SQLPad endpoints that themselves require an admin service token.
Tool | Description |
| Get one connection by ID. |
| Test a connection configuration without saving it. |
| List SQLPad users, with explicit output bounds. |
How SQL execution works
SQLPad executes SQL through asynchronous batches. Creating a batch returns immediately; each statement moves from queued to started, then to finished or error. Results are fetched separately for each statement and are unavailable until that statement is finished.
The run_sql tool absorbs the full protocol — create, poll, fetch, and return rows — so an agent makes one call. If polling reaches the configured timeout, the tool returns a batchId that the agent can resume with instead of hanging.
Connections may have no default database. Qualify table names as schema.table, and use get_connection_schema to discover available schemas.
Security
run_sqlexecutes arbitrary SQL, including DDL and DML, and is not sandboxed.SQLPAD_ALLOW_WRITESonly gates mutation of SQLPad's own saved-query objects; it does not restrict SQL content. Use read-only database credentials on the SQLPad connection itself. That is the only real enforcement.SQLPad's
/api/service-tokensendpoints are deliberately not exposed. A tool that mints credentials is a privilege-escalation primitive.Admin tools are off by default.
The service token is redacted from all errors and logs. All logging goes to stderr because stdout is the JSON-RPC channel.
Batches are scoped to the token's own user, so the server only ever sees its own query history.
Contributing
Clone the repo and install dependencies:
git clone https://github.com/VAIBHAV7500/sqlpad-mcp.git
cd sqlpad-mcp
npm install
npm run buildCreate a branch for your change. Before opening a pull request, run:
npm run typecheck && npm run lint && npm testCI runs the same three commands on Node 20 and 22.
License
This server cannot be deployed
Maintenance
Related MCP Connectors
Model Context Protocol server for the Apideck Unified API. Connect any MCP-compatible agent framework to 100+ accounting systems, HRIS platforms, file storage providers, and more through one integration. More information https://www.apideck.com/mcp-server
Safe, read-only Postgres and MySQL access for AI agents. Audit log + column-level controls.
- OleanderOAuthdev.oleander
The all-in-one data stack for agents. Upload files, run SQL, evolve tables, and render charts.
Connect AI agents to ProductNow's context engine to search, create, review, and act.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceEnables AI agents to query databases via natural language using the Model Context Protocol, with automatic schema discovery, SQL query execution, and read-only safety checks.-
- FlicenseNot gradedqualityDmaintenanceEnables AI agents to connect to and query an SQLite database through the Model Context Protocol, allowing natural language interaction with database tables and data.-
- AlicenseAqualityDmaintenanceEnables AI agents to search and read Metabase dashboards and cards, explore database schema, and run read-only query previews through the Model Context Protocol.1715 npm2MIT
- FlicenseAqualityDmaintenanceEnables AI assistants to query, analyze, and manage SQL Server databases through natural language via the Model Context Protocol.61-