Back to Browse

Rowsafe MCP Server

Developer ToolsLow Risk10.0MCP RegistryRemote
Free

Server data from the Official MCP Registry

PostgreSQL backups and a safety net for AI agents: check recoverability, set restore points.

About

PostgreSQL backups and a safety net for AI agents: check recoverability, set restore points.

Remote endpoints: streamable-http: https://api.rowsafe.sh/mcp

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (2 strong, 1 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry.

Endpoint verified · Requires authentication · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Found in Source Code

Found by scanning the linked source code. This listing connects to a hosted endpoint, so none of this runs on your machine: it describes what the server software does where it is hosted.

file_system

Applies to the server that hosts this plugin, not to your machine.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Connect

Remote Plugin

No local installation needed. Your AI client connects to the remote endpoint directly.

Add this to your MCP configuration to connect:

{
  "mcpServers": {
    "sh-rowsafe-rowsafe": {
      "url": "https://api.rowsafe.sh/mcp"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Rowsafe

The database admin you never hired. Rowsafe looks after the databases you run on your own servers: backups you can restore to any second, a restore test every week, monitoring with one-click fixes, and a safety net for AI coding agents.

This repository is the open-source part of Rowsafe: the agent, the rowsafe CLI, the installer and the MCP server. Everything that touches your data is here, under Apache-2.0.

Docs: rowsafe.sh/docs

Databases, on Linux servers and in Docker:

  • PostgreSQL 13–18, MySQL 8.0/8.4, MariaDB 10.6–11.4, MongoDB 6.0–8.0, ClickHouse 24.8–26.8
  • Redis 7.0+ and Valkey 7.2+ (standalone servers)
  • SQLite (restore to any second needs WAL mode)

Features per database: protocol.EngineCapabilities.

Get started

rowsafe login
rowsafe hosts enroll-token                       # prints the install command
curl -fsSL https://rowsafe.sh | sudo sh -s rse_… # on the database server

Rewind: continuous backups, restore to any second.

rowsafe mark before-drop                  # a named restore point (a Mark)
rowsafe rewind copy app --at "14:04"      # a copy as of 14:04, next to production
rowsafe rewind compare app                # rows missing or changed in production
rowsafe rewind rows app public.orders     # bring the missing rows back
rowsafe rewind database app --at "14:04"  # rewind in place, with undo

Proof: a weekly automatic restore test (rowsafe proof app).

Pulse: a 0–100 health score with fixes you apply (rowsafe pulse, rowsafe fix app), slow queries (rowsafe top app), insights and tuning.

Guard: rowsafe mcp, the Claude Code and Codex plugins and the GitHub Action save a Mark before migrations, destructive SQL and deploys. AI agents can ask for any change to production; an owner or admin approves it in the dashboard. Agents can never approve.

Full guide: Quickstart.

What's in this repository

PathWhat it is
cmd/rowsafe-agent, internal/agentThe agent: outbound HTTPS only, a fixed set of tasks, no arbitrary commands or SQL.
cmd/rowsafe, clientThe CLI.
mcp, integrations/Guard: the MCP server, Claude Code and Codex plugins, and the GitHub Action (rowsafe/action).
collect, tuneMonitoring, and settings recommendations.
protocolAPI types shared by the agent, the CLI and the control plane.
internal/pgbackrest, internal/pginspectPostgreSQL.
internal/engineMySQL/MariaDB, MongoDB, ClickHouse, Redis/Valkey, SQLite.
scripts/install.shThe installer served at https://rowsafe.sh.
release, cmd/rowsafe-releaseRelease signing and verification.

Safety

  • Never restarts or changes production on its own. Restarts, fixes, rewinds and settings changes run only when a person confirms them.
  • Fixes come from a fixed list and are re-checked on the server right before they run.
  • Restore tests and copies are isolated from production and its backups.
  • Your data and secrets stay on your server. Backups are encrypted before upload; Rowsafe sees table names and counts, not rows.
  • Signed, reproducible releases with automatic rollback. See verifying releases.
  • Monitoring is read-only. ROWSAFE_COLLECT_QUERY_TEXT=false keeps query text on your server; ROWSAFE_MONITORING=false turns it off.

Build

make build. Locally built agents never auto-update.

Contributing and security

CONTRIBUTING.md · docs in rowsafe/docs · report vulnerabilities through security advisories (SECURITY.md).

License

Apache License 2.0. Copyright 2026 Adraa Labs.

Reviews

No reviews yet

Be the first to review this server!