mcp-oracle
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mcp-oracleshow me the schema for the employees table"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
mcp-oracle
An MCP server that gives LLM agents direct access to an
Oracle database over stdio. Ships up to five tools: read-only queries, DML/DDL execution
with auto-commit, anonymous PL/SQL blocks with DBMS_OUTPUT capture, and schema
introspection. Starts read-only by default — the write tools aren't merely blocked,
they're not registered at all until you opt in.
Built with FastMCP and python-oracledb (thin mode — no Oracle Instant Client required).
Tools
Tool | Purpose |
| Execute |
| Execute a single DML/DDL statement ( |
| Run an anonymous |
| List all tables in the configured schema |
| Column name, type, length, and nullability for a table |
execute and execute_plsql only exist when ORACLE_READONLY=false; in the default
read-only mode they are never registered, so clients can't call what isn't there.
Statements are routed by their first keyword (leading SQL comments are skipped), so each tool rejects work that belongs to a sibling tool with a hint about where it should go.
All statements run with ALTER SESSION SET CURRENT_SCHEMA = <ORACLE_SCHEMA>, so
unqualified object names resolve against the configured schema.
Related MCP server: MCP-Oracle
Requirements
Python 3.10+
Reachable Oracle database (tested against Oracle 23ai Free /
freepdb1)No Oracle Instant Client needed — python-oracledb thin mode is used by default
Getting started
Install into a venv
python -m venv .venv
source .venv/bin/activate
pip install -r requirements.txtOr run it as a package
pyproject.toml exposes a mcp-oracle console script, so pipx/uvx can install and
run it without maintaining a project-local venv:
pipx install .
mcp-oracle
# or run without installing at all:
uvx --from . mcp-oracleConfigure
Copy .env.example to .env and fill in your credentials:
cp .env.example .envVariable | Default | Description |
|
| Database user |
|
| Password |
|
| DSN ( |
|
| Schema set via |
|
| On by default — |
|
| Per-statement call timeout in milliseconds, applied to all cursors; |
| (unset — off) |
|
Real environment variables take precedence over .env values, so one-off overrides like
ORACLE_READONLY=false mcp-oracle work without editing the file.
First run
Out of the box the server starts in read-only mode: only query, list_tables and
describe_table are exposed. To get execute and execute_plsql, set
ORACLE_READONLY=false in .env (or in the process environment — it wins over .env).
Running
Stdio transport (what MCP clients spawn):
python server.py
# or, if installed as a package:
mcp-oracleMCP Inspector for interactive poking:
mcp dev server.pyClient configuration
Example for mcp.json-style configs (Claude Desktop, Windsurf, Cursor, Devin, …):
{
"mcpServers": {
"oracle": {
"command": "/path/to/mcp-oracle/.venv/bin/python",
"args": ["/path/to/mcp-oracle/server.py"]
}
}
}Point command at the venv interpreter so dependencies resolve without activating
anything. If you installed via pipx, "command": "mcp-oracle" works too.
Security notes
Read-only by default.
execute/execute_plsqlare not registered at all unlessORACLE_READONLY=false. The strongest write protection is a client that can't see the tools.The keyword gating in
query/execute/execute_plsqlis a routing convenience, not a security boundary. Real enforcement must come from grants onORACLE_USER— run the server with a least-privilege account.executeandexecute_plsqlcommit unconditionally. There is no rollback, no dry run, no undo. Point this at production only if you enjoy adrenaline.ORACLE_CALL_TIMEOUT_MScaps every statement at 30 s by default — raise it for legitimately long calls rather than disabling it.ORACLE_LOG_LEVELwrites diagnostics to stderr only; stdout is reserved for the stdio MCP transport. The password is never logged.Never commit
.env— it's in.gitignore, keep it that way.
License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Safe, read-only Postgres and MySQL access for AI agents. Audit log + column-level controls.
Query 40 databases from Claude, ChatGPT, or Cursor — on any device. Read-only, encrypted, audited.
- dataOAuthco.thinair
PostgreSQL, MySQL, and SQL Server in one session. 26 read-only MCP tools for AI agents.
Query your org's data in natural language — read-only MCP access to SQL, NoSQL, files & warehouses.
Related MCP Servers
- FlicenseNot gradedqualityBmaintenanceEnables read-only exploration of Oracle databases through natural language, providing schema inspection and safe bounded SQL query execution.-
- FlicenseNot gradedqualityBmaintenanceEnables AI agents to connect to Oracle databases for schema exploration, PL/SQL source inspection, and read-only SQL queries, with optional write operations when explicitly enabled.-
- AlicenseNot gradedqualityCmaintenanceEnables AI agents to safely inspect Oracle Database schemas, objects, and PL/SQL source with a strict read-only guard, without ever modifying data.21 npmMIT
- AlicenseAqualityAmaintenanceEnables Oracle Database schema introspection and SQL execution over stdio, letting MCP hosts list tables, describe columns, and run SQL—read-only by default with opt-in writes.312 npmMIT