linkit-dev-sql-mcp
v0.1.0
Published
MCP server for read-only SQL Server queries across LinkIt dev environments (internal/staging/uat/preprod/prod/au)
Maintainers
Readme
linkit-dev-sql-mcp
MCP server for read-only SQL Server queries across LinkIt environments:
internal / staging / uat / preprod / prod / au.
Same UX as teamwork-mcp: connections are stored in the OS keychain
(or an AES-256-GCM encrypted file), so MCP client config files never contain secrets.
The first tool call without a configured env opens a local setup page where you
enter host + database + user + password per env (each connection is tested before saving).
Features
- MCP server over stdio
- Read-only by construction: only single
SELECT/WITH...SELECTstatements pass validation —INSERT/UPDATE/DELETE/MERGE, DDL, andEXECare blocked (inspect procedures withexplore/procedure_infoinstead of executing them). Still, prefer adb_datareaderlogin for defense in depth. - Multi-env: every tool takes an explicit
envparam — there is no default, soprodis only touched when you sayenv="prod". - Smart result guard:
maxRows(default 50, max 500), server-sideSET ROWCOUNTcap when your query has noTOP/OFFSET, long-text cell trimming, ~120 KB response byte-cap,truncatedflag + hints, opt-incountTotal. - Catalog discovery for huge DBs: all
exploreactions are paginated (page/pageSize, max 100) withLIKEsearch — never dumps the whole catalog. - Setup page + CLI (
auth/status/test/logout), CI overrides via env vars.
Install as a Claude Code / Cowork plugin (easiest, no config editing)
claude plugin marketplace add sondv5/linkit-dev-sql-mcp
claude plugin install linkit-sql@linkit-dev-sql-mcpThe first time anyone calls a SQL tool for an unconfigured env, the guided setup page opens automatically for them to enter their own per-env connections (stored locally in their OS keychain) — nothing to configure by hand.
Install / Run
npx -y linkit-dev-sql-mcp@latestThe first time you call any tool for an env with no connection, the server will:
- Open your browser to a local setup page (
http://127.0.0.1:<port>/setup/<nonce>) - You enter host + port + database + user + password for that env → the server tests the connection, then saves it
- Retry the tool you just called — everything works, no restart needed
For local development:
npm install
npm run build
node dist/bin.jsA CLI is also available for terminal users:
npx -y linkit-dev-sql-mcp@latest auth # pick envs, enter connections, test and save
npx -y linkit-dev-sql-mcp@latest status # show configured envs
npx -y linkit-dev-sql-mcp@latest test # test connectivity (or: test prod)
npx -y linkit-dev-sql-mcp@latest logout # remove all stored connectionsMCP Client Config
{
"mcpServers": {
"linkit-sql": {
"command": "npx",
"args": ["-y", "linkit-dev-sql-mcp@latest"]
}
}
}Ready-made templates are included in this repository:
.cursor/mcp.json
.mcp.json
.codex/config.toml
opencode.json(See teamwork-mcp README for per-client instructions — same pattern, server name linkit-sql.)
Tools (3 grouped tools, action-dispatched)
| Tool | Type | Actions (via action param) |
| --- | --- | --- |
| query | read | select — one SELECT/WITH statement; maxRows (default 50, max 500), countTotal, trimChars, per-call database override |
| explore | read | list_databases, list_tables (search/schema filter), table_info (columns/indexes/FKs/approx rows), list_views, list_procedures, procedure_info (params + definition ≤8000 chars), list_functions, function_info, search_objects (unioned LIKE search, type filter) — all paginated |
| system | local | status (envs/storage, no passwords), test (connectivity + latency, all or one env), logout (remove connections) |
Typical flow for a big unknown DB:
explore/list_databases(orsystem/statusto see what's configured)explore/search_objectswith a keyword, orexplore/list_tableswithsearchexplore/table_infofor the shortlistquery/selectwith a filteredSELECT ... WHERE ...and smallmaxRows
Environment Variables (optional, for CI)
Per-env overrides (they win over stored connections):
LINKIT_SQL_<ENV>_HOST / _PORT / _DB / _USER / _PASSWORD / _ENCRYPT / _TRUST_CERTENV is one of INTERNAL, STAGING, UAT, PREPROD, PROD, AU.
Note: env vars are plaintext — prefer the keychain for interactive use.
Security
- The server is read-only at the SQL-text layer, but SQL Server cannot enforce
that by itself — always connect with a read-only login (
db_datareader, nodb_owner/db_ddladmin), especially forprod. EXEC/sp_executesql/SELECT...INTOare blocked, so stored procedures can be inspected but not executed through this server.envis required on every tool — there is no implicit default env, so an agent cannot "accidentally" query prod while meaning staging.- Never pass credentials via
argsinmcp.json(visible in process lists). - The server only logs to stderr; stdout is reserved for JSON-RPC.
Dev
npm install
npm run build # tsc -> dist/
npm run dev # watch mode
node dist/bin.js --helpLicense
MIT
