sql-mini-mcp
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@sql-mini-mcpshow me the stored procedures in the Sales database"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
sql-safe-mcp
A read-only, PII-safe SQL Server, MySQL and MariaDB MCP server for coding agents: schema knowledge and safe queries, with no way to change or leak data.
Read the data. Protect the identity.
General-purpose database MCP servers hand the agent a raw SQL prompt and dozens of tools. This
server gives a coding agent the schema knowledge it needs to write correct code - servers,
databases, tables, columns, keys, indexes, stored procedures - and, on servers you mark
pii_safe, a way to look at real rows without ever seeing the personal data in them.
Read-only by design. PII-safe by default
Read-only by construction - seven tools, all annotated read-only. No tool writes data, and the server never executes SQL an agent wrote: metadata comes from SQLAlchemy Inspector and fixed catalog queries, and
execute_sqlruns only a validated, regeneratedSELECT.PII-safe by default - on a
pii_safeserver, the columns you configure come back as alias-bound, authenticated tokens (pii:v1:...), never as plaintext. An agent can still project, count, and filter on them with=andINusing tokens it was given, so it can follow a record without reading it. Tokens do not work on another server alias or with another key.Fails closed - SQL validation is an allowlist. Unknown syntax, unresolved lineage, and unsupported protected-value types are refused, not guessed at. The verification evidence is in the security model.
Least access first -
access_level: metadata(the default) exposes schema only;execute_sqlneeds an explicitpii_safealias with its own key. Database permissions stay the primary control, so use a least-privilege login.
Related MCP server: sqlserver-mcp
Also
Your aliases, not your network - the agent sees only the server aliases you configure. There is no network discovery, and the catalog is not published as MCP resources.
Secrets stay out of sight - connection URLs live in YAML with
${NAME}placeholders resolved from the environment. They never appear in logs or model-visible errors.Compact, predictable output - object-rooted results with stable sorting, literal case-insensitive name filters, and stored procedure lists that do not expand definitions.
Errors an agent can act on - an ambiguous name lists the candidate schemas. Errors never contain connection details, credentials, keys, tokens, or rows.
On PyPI -
uvx sql-safe-mcp, no repo clone required.
Tool | Access | Purpose |
| 🟢 read | Configured server aliases |
| 🟢 read | Databases visible to the credentials |
| 🟢 read | Base tables, filtered by schema or name |
| 🟢 read | Columns, keys, constraints, and indexes of one table |
| 🟢 read | Stored procedures, without definitions |
| 🟢 read | The definition of one stored procedure |
| 🟢 read | One restricted |
Status: SQL Server supports every tool. MySQL and MariaDB (engine: mysql or mariadb,
mysql+pymysql URLs) support every tool too. schema is always null there because the
database is the catalog, and execute_sql uses LIMIT instead of TOP. See
ARCHITECTURE.md.
More detail lives in docs/: the configuration reference,
what the tools return, and the security model.
Install
uvx sql-safe-mcpor
pip install sql-safe-mcpPin a version when you want a fixed surface: uvx sql-safe-mcp==1.2.0.
Requires Python 3.12+, uv (or pip), and
Microsoft ODBC Driver 18 for SQL Server
when you connect to SQL Server. MySQL and MariaDB use the bundled PyMySQL driver and need nothing
else.
Verified against SQL Server 2022, MySQL 8.4, and MariaDB 11.4 (see CHECKS.md).
Configure
Copy sql-safe-mcp.example.yaml to sql-safe-mcp.yaml, list your
servers, and keep credentials in environment variables:
version: 1
servers:
reporting:
engine: sqlserver
access_level: metadata
connection_url: "${REPORTING_SQL_URL}"Point the server at the file with SQL_SAFE_MCP_CONFIG (or --config), and check it without
connecting to any database:
SQL_SAFE_MCP_CONFIG=sql-safe-mcp.yaml uvx sql-safe-mcp --check-configConfiguration is validated at startup, and an error names the problem without printing a URL or secret. Keep credentials in the host's own configuration and never commit them. The server acts with the database account's permissions, so use a dedicated login with the least access the job needs. Every setting, including the runtime limits, is in configuration.md.
claude mcp add --env SQL_SAFE_MCP_CONFIG=/path/to/sql-safe-mcp.yaml --env REPORTING_SQL_URL=mssql+pyodbc://... --transport stdio sql-safe -- uvx sql-safe-mcpPut at least one other option between the last --env and the server name, as above - the CLI
otherwise reads the name as another KEY=value pair.
In claude_desktop_config.json:
{
"mcpServers": {
"sql-safe": {
"command": "uvx",
"args": ["sql-safe-mcp"],
"env": {
"SQL_SAFE_MCP_CONFIG": "/path/to/sql-safe-mcp.yaml",
"REPORTING_SQL_URL": "mssql+pyodbc://..."
}
}
}
}codex mcp add sql-safe --env SQL_SAFE_MCP_CONFIG=/path/to/sql-safe-mcp.yaml --env REPORTING_SQL_URL=mssql+pyodbc://... -- uvx sql-safe-mcpCommand uvx, argument sql-safe-mcp, and the environment variables your configuration
references, plus SQL_SAFE_MCP_CONFIG. The server speaks MCP over stdio and logs only to stderr.
PII-safe queries
Mark an alias access_level: pii_safe, give it its own key, and list the protected columns:
servers:
legacy_prod:
engine: sqlserver
access_level: pii_safe
connection_url: "${LEGACY_PROD_SQL_URL}"
pii_key_env: LEGACY_PROD_PII_KEY
pii:
rules:
- database: "*"
schema: dbo
table: Users
columns: [Email, FirstName, LastName]execute_sql then accepts one restricted SELECT. Protected cells come back as tokens, and a
token is accepted only in = and IN predicates on the same alias. Protection covers the columns
you list, so list every column that holds personal data. The rule format, key generation, and the
accepted SQL are in configuration.md and tools.md.
Security
The MCP caller, SQL input, database metadata, rows, and tokens are untrusted; the operator, the process environment, and the database credentials are the trusted boundary. Database permissions remain the primary authorization control - this server never widens them. The full model and its verification are in SECURITY-MODEL.md. To report a vulnerability, use the private channel in SECURITY.md.
Contributing
Setup, checks, the test commands, the branch and commit conventions, and the release model are in CONTRIBUTING.md. Changes that affect someone running the server are recorded in CHANGELOG.md.
License
MIT.
This server cannot be deployed
Maintenance
Related MCP Connectors
Provides read access to your GKE and Kubernetes resources.
Generate, fix, explain and run read-only SQL on PostgreSQL, MySQL and SQL Server
Safe, read-only Postgres and MySQL access for AI agents. Audit log + column-level controls.
Query your org's data in natural language — read-only MCP access to SQL, NoSQL, files & warehouses.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceRead-only SQL Server MCP server enabling safe database queries, table listing, and schema inspection with built-in security protections.MIT
- FlicenseNot gradedqualityDmaintenanceEnables secure interaction with Microsoft SQL Server databases, allowing schema exploration, metadata retrieval, and read-only query execution through natural language.1-
- FlicenseNot gradedqualityDmaintenanceEnables read-only exploration and querying of Microsoft SQL Server databases through a standardized interface.2-
- FlicenseNot gradedqualityDmaintenanceEnables read-only SQL querying and schema inspection across MSSQL, PostgreSQL, and MySQL databases via MCP tools.-