@affanshahid/sql-mcp-server
v0.1.3
Published
An MCP server for connecting to and running queries on SQL databases. Supports built-in SSH tunneling
Maintainers
Readme
SQL MCP Server
An MCP server for connecting to and running queries on SQL databases. Supports built-in SSH tunneling.
Supported databases: MySQL, MariaDB, PostgreSQL, SQLite.
Install
Run Directly
npx -y @affanshahid/sql-mcp-servernpm
npm install -g @affanshahid/sql-mcp-serverShell (macOS / Linux)
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/affanshahid/sql-mcp-server/releases/latest/download/sql-mcp-server-installer.sh | shPowerShell (Windows)
powershell -ExecutionPolicy Bypass -c "irm https://github.com/affanshahid/sql-mcp-server/releases/latest/download/sql-mcp-server-installer.ps1 | iex"Build From Source
cargo install sql-mcp-server --lockedUsage
{
"mcpServers": {
"sql": {
"command": "npx",
"args": ["-y", "@affanshahid/sql-mcp-server"],
"env": {
"DATABASE_URL": "postgres://user:pass@host:5432/dbname"
}
}
}
}SSH tunneling
To reach a database that isn't directly accessible, supply SSH options and the server will open a local forward and connect through it:
{
"mcpServers": {
"sql": {
"command": "npx",
"args": ["-y", "@affanshahid/sql-mcp-server"],
"env": {
"DATABASE_URL": "postgres://user:[email protected]:5432/dbname",
"SSH_HOST": "bastion.example.com",
"SSH_USERNAME": "deploy",
"SSH_PRIVATE_KEY": "/home/you/.ssh/id_ed25519"
}
}
}
}Authentication also accepts a password (SSH_PASSWORD) instead.
Permissions
By default only SELECT is allowed. Use DATABASE_OPERATIONS to permit more:
{
"mcpServers": {
"sql": {
"command": "npx",
"args": ["-y", "@affanshahid/sql-mcp-server"],
"env": {
"DATABASE_URL": "postgres://user:pass@host:5432/dbname",
"DATABASE_OPERATIONS": "select,insert,update"
}
}
}
}Possible values: select, insert, update, delete, ddl.
Additional guards (off by default):
DENY_LIMITLESS_SELECT— rejectSELECTwithoutLIMIT.DENY_BOUNDLESS_UPDATE— rejectUPDATEwithoutWHERE.DENY_BOUNDLESS_DELETE— rejectDELETEwithoutWHERE.
Configuration reference
Every option can be set as either a CLI flag or an environment variable.
| Flag | Env | Default |
| ------------------------- | ----------------------- | -------- |
| -d, --database-url | DATABASE_URL | — |
| -o, --operations | DATABASE_OPERATIONS | select |
| --deny-limitless-select | DENY_LIMITLESS_SELECT | false |
| --deny-boundless-update | DENY_BOUNDLESS_UPDATE | false |
| --deny-boundless-delete | DENY_BOUNDLESS_DELETE | false |
| -H, --host | SSH_HOST | — |
| -P, --port | SSH_PORT | 22 |
| -u, --username | SSH_USERNAME | — |
| -p, --password | SSH_PASSWORD | — |
| -i, --private-key | SSH_PRIVATE_KEY | — |
