agent-toolbox
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@agent-toolboxRun a Python snippet to analyze the recent signups trend."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
agent-toolbox
An MCP tool server exposing sandboxed Python execution and read-only SQL
against a service database. Deployed independently of any agent that talks
to it -- it's a plain MCP server, usable by this project's agent repo or
by any other MCP client.
Setup
uv sync --group devCopy .env.example to .env and fill in the paths/URLs:
cp .env.example .envAPP_ENV=debug
USER_DB_HOST=/absolute/path/to/sqlite
USER_DB_NAME=user
TOOLBOX_URL=http://127.0.0.1:8001/mcpRelated MCP server: postgres-mcp-server
Running it
make run
# uv run uvicorn bootstrap.application.toolbox_application:app --host 0.0.0.0 --port 8001URL | |
MCP endpoint |
|
Health |
|
Point any MCP client's connector base_url at the MCP endpoint above --
timeout, transport (streamable_http), and auth are configured the same
way as any other MCP connector.
Configuration
Everything lives under config/ -- config/root.yml plus
config/debug/connector/*.yml. TOOLBOX_URL must match whatever URL
clients use to reach this service; it's used to derive this server's own
ASGI mount path and allowed host, not to bind the listener (the listener's
host/port come from the --host/--port flags passed to uvicorn).
Only the Host header matching TOOLBOX_URL is accepted by default (DNS
rebinding protection, from the mcp SDK's transport security) -- any other
Host gets a 421 Invalid Host header. If another client reaches this
service a different way (e.g. a LAN hostname, testing directly from
Postman), add it to TOOLBOX_EXTRA_ALLOWED_HOSTS (comma-separated) instead
of changing TOOLBOX_URL, which would break clients using the original
host.
Logging
By default this service logs through loguru. To switch to Python's
standard logging module instead:
Open
src/bootstrap/di/base_di.pyReplace the
LoguruLoggerimport withStandardLogger(from pycraftcore.logger.adapter import StandardLogger)In
_logging, replaceLoguruLogger()withStandardLogger()In
_telemetry_provider, remove theself._logging.attach(log_handler)line --StandardLoggeralready flows into the same pipeline the OTel exporter is attached to at the root logger, so keeping that line would ship every log line twiceRestart the service
No config file or environment variable change is needed -- this is a one-line adapter swap in the composition root.
Development
make check # lint + typecheck + tests
make test
make lint
make format
make typecheckPre-commit hooks
uv run pre-commit install --hook-type pre-commit --hook-type pre-push
uv run pre-commit run --all-files --hook-stage pre-commitMCP inspection
npx @modelcontextprotocol/inspectorDeploying
make docker_build
helm install agent-toolbox devops/helm -f devops/helm/values.yamlThis server cannot be deployed
Maintenance
Related MCP Connectors
Governed data discovery, exact queries, decisions, simulations, and runtime utilities over MCP.
Paid remote MCP for governed database query review, SQL simulation, approvals, and audits.
Read-only MCP access to sessions, funnels, campaigns, errors, live visitors, and anomalies.
Query your org's data in natural language — read-only MCP access to SQL, NoSQL, files & warehouses.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceEnables SQL query execution and database structure browsing via MCP tools and resources.MIT
- AlicenseNot gradedqualityDmaintenanceEnables inspecting database schemas and executing read-only SQL queries on a PostgreSQL database via MCP tools.8 npmMIT
- FlicenseNot gradedqualityBmaintenanceEnables secure execution of Python code, SQL queries, and metric fetching through MCP with ephemeral Docker sandboxing.-
- AlicenseNot gradedqualityDmaintenanceEnables AI agents and workflows to safely explore and query data in ephemeral sandboxed databases via MCP, with guardrails and snapshot capabilities.22MIT