Server data from the Official MCP Registry
MCP server for PostgreSQL. Read-only by default, row caps, timeouts, secrets never logged.
About
MCP server for PostgreSQL. Read-only by default, row caps, timeouts, secrets never logged.
Security Report
database-mcp is a well-designed MCP server for SQL database access with strong security fundamentals. It implements read-only mode by default, enforces statement timeouts, caps result rows, and properly handles sensitive credentials through a Secret type that prevents logging. The codebase demonstrates mature security practices including parameterized queries, minimal tool surface, and multi-layer guardrails. Minor code quality observations do not materially impact security. Package verification found 2 issues (1 critical, 0 high severity).
8 files analyzed · 6 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
Unverified package source
We couldn't verify that the installable package matches the reviewed source code. Proceed with caution.
What You'll Need
Set these up before or after installing:
Environment variable: POSTGRES_HOST
Environment variable: POSTGRES_USER
Environment variable: POSTGRES_PASSWORD
Environment variable: POSTGRES_DATABASE
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-arifulislamat-database-mcp-postgres": {
"env": {
"POSTGRES_HOST": "your-postgres-host-here",
"POSTGRES_USER": "your-postgres-user-here",
"POSTGRES_DATABASE": "your-postgres-database-here",
"POSTGRES_PASSWORD": "your-postgres-password-here"
},
"args": [
"-y",
"database-mcp"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
database-mcp
MCP servers that give AI clients safe, structured access to SQL databases.
One installable package per database engine, in TypeScript (npm) and Python
(PyPI). Every package exposes the same minimal two-tool surface,
execute_sql and search_objects, with guardrails on by default: read-only
mode, row caps, and statement timeouts.
Packages
| Engine | TypeScript (npm) | Python (PyPI) |
|---|---|---|
| SQLite | @database-mcp/sqlite | database-mcp-sqlite |
| libSQL | @database-mcp/libsql | database-mcp-libsql |
| MySQL | @database-mcp/mysql | database-mcp-mysql |
| MariaDB | @database-mcp/mariadb | database-mcp-mariadb |
| Postgres | @database-mcp/postgres | database-mcp-postgres |
Both lines are published and pass the same language-agnostic conformance suite against real databases in CI, so behavior is identical regardless of language. Every engine is also listed on the MCP Registry with both install options.
Go and Rust implementations are planned.
Design principles
- Two tools, no more. A tiny tool surface keeps the model's context window
clean.
search_objectsprogressively discloses schema: call it with no arguments to list tables, with a table name to get columns, indexes, and foreign keys. - Safe by default. Read-only mode is enforced in two layers: a conservative SQL guard, plus a session-level read-only setting in the database itself. Rows are capped (default 1000) and statements time out (default 30s).
- Configured at launch, never via chat. Connection details come from flags, a YAML config file, or environment variables. Credentials are never accepted through a tool call.
- Secrets never appear in logs. Passwords live in non-printable secret types, DSNs are sanitized before logging, and a redaction filter guards the log boundary.
Quick start
Pick your engine's package; each README has the full config surface. SQLite via npm:
{
"mcpServers": {
"sqlite": {
"command": "npx",
"args": ["-y", "@database-mcp/sqlite", "--dsn", "/absolute/path/to/database.db"]
}
}
}
Or via PyPI: use "command": "uvx" and
"args": ["database-mcp-sqlite", "--dsn", "/absolute/path/to/database.db"].
Flags, environment variables, and YAML config are identical across both
lines.
Networked engines take credentials from the environment (MYSQL_*,
MARIADB_*, POSTGRES_*/DATABASE_URL, LIBSQL_URL/LIBSQL_AUTH_TOKEN),
*_FILE mounted secrets, or a YAML file via --config. Never from a chat
prompt.
Contributing
See CONTRIBUTING.md. The short version: the conformance
suite is the definition of done. A change is mergeable only when
conformance/run.mjs passes against every affected server.
License
Reviews
No reviews yet
Be the first to review this server!
More Data & Analytics MCP Servers
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
FinAgent
Freeby mcp-marketplace · Finance
Free stock data and market news for any MCP-compatible AI assistant.
Google Workspace MCP
Freeby Taylorwilsdon · Productivity
Control Gmail, Calendar, Docs, Sheets, Drive, and more from your AI
