Run alias-based queries against PostgreSQL, MySQL, MongoDB and Oracle without exposing credentials.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
mcp-name: io.github.renanlido/custom-mcp-database
An MCP server that lets AI agents run alias-based queries against PostgreSQL, MySQL, MongoDB and Oracle β without ever exposing credentials to the model. Connections are configured once and stored locally; the agent only ever references them by alias.
Works with Claude Code, Claude Desktop, Cursor, VS Code, Windsurf, Gemini CLI, and any other MCP client (all use the same stdio launch command).
There are two roles, on purpose. Keeping them separate is what stops your DB password from ever reaching the model.
The agent never installs credentials. You do, with the CLI. The secret stays on your machine and is never sent to the model.
Easiest way β the guided wizard (asks type, host, user, and how to supply the secret; optionally tests the connection):
Or do it in one line (you'll be prompted for the password β hidden input):
Point your MCP client at the server (see Install), then just ask:
"Using prod_ro, run
SELECT count(*) FROM orders."
The agent calls db_execute_query with the alias prod_ro β never a host, user,
or password. It physically cannot see the credentials; they live in your local config,
resolved only inside the server process at query time.
Why the agent can't add the DB: an MCP tool's arguments are produced and read by the
LLM. If the agent typed your password into an add tool, that password would land in the
model's context, the provider, and the logs. So credential setup is a human/CLI step by
design. (Need an agent to wire connections in an automated pipeline? See
MCP_DB_ALLOW_ADMIN_TOOLS in SECURITY.md β even then it only accepts a
reference to a secret, e.g. an env-var name, never the secret itself.)
Writes are off by default (read-only). To allow them for a task:
export MCP_DB_READONLY=0 MCP_DB_ALLOW_WRITES=1.
The server runs over stdio. The universal launch command is uvx custom-mcp-database run
(requires uv; the package is fetched from PyPI on first run).
Two options:
.mcpb (mcpb pack) and open it in Claude Desktop. See Distribution.examples/mcp-clients/claude-desktop.json to claude_desktop_config.json.Copy the matching snippet β all use the same command/args, only the file and key differ:
| Client | Config file | Key | Snippet |
|---|---|---|---|
| Cursor | ~/.cursor/mcp.json | mcpServers | cursor.json |
| VS Code | .vscode/mcp.json | servers | vscode.json |
| Windsurf | ~/.codeium/windsurf/mcp_config.json | mcpServers | windsurf.json |
| Gemini CLI | ~/.gemini/settings.json | mcpServers | gemini-cli.json |
Full client matrix and a local-checkout variant: examples/mcp-clients/README.md.
Configure connections from your terminal with the CLI β never through the agent. A connection's password is a real secret; if it were passed as an MCP tool argument it would enter the model's context (and the provider, transcripts, and logs). So the credential-management tools are off the MCP surface by default; provisioning is a human/CLI task. The agent only lists and uses aliases.
Omit --password/--uri to be prompted securely (hidden input, not stored in shell
history). Even better, keep the secret out of the config file entirely with
--password-env / --password-file (resolved at connection time):
Config location (override with MCP_DB_CONFIG):
$XDG_CONFIG_HOME/custom-mcp-database/mcp_config.sqlite3
(default ~/.config/custom-mcp-database/mcp_config.sqlite3, 0600).
If you pass a literal
--password/--uri, it is stored as plaintext JSON in that SQLite file. Prefer--password-env/--password-file(or--uri-env/--uri-file) so only a reference is stored. Either way, keep the file secret (it is0600, gitignored, not encrypted).
| Tool | Purpose |
|---|---|
db_list_aliases | List configured aliases and types |
db_execute_query | Run SQL or a MongoDB JSON filter |
db_list_collections | List MongoDB collections |
db_security_status | Report the active security policy |
db_add_database / db_remove_database are not exposed over MCP by default β manage
connections with the CLI. To opt into exposing them (the add tool only accepts secrets by
reference, never a literal password), set MCP_DB_ALLOW_ADMIN_TOOLS=1.
db_execute_query notes: SQL runs as given with parameterized binds (add your own
LIMIT); MongoDB takes a JSON filter + collection, caps results at 10 (--limit),
rejects empty filters, and coerces 24-char hex strings to ObjectId.
This server handles real credentials and production data, so it ships deny-by-default:
;-injection blocked), single statement per call.$where, $function, $accumulator, mapReduce, β¦).oracle_schema can't be used for injection).MCP_DB_MAX_ROWS (default 1000); secrets redacted from errors.0600 plaintext SQLite β keep the host disk encrypted.Check the live posture: custom-mcp-database security-status (or the db_security_status tool).
Enable writes for a specific task (then turn it back off):
Read the full protocol β least-privilege DB roles, TLS, prompt-injection handling, vulnerability reporting β in SECURITY.md. The app-layer guards are defense-in-depth; the authoritative control is a least-privilege database account.
Inspect tools interactively:
This repo ships ready-to-publish metadata for every major channel. All of it is
published automatically on push to main (see below):
| Channel | File | Published by |
|---|---|---|
| PyPI | pyproject.toml | release.yml (push to main) |
| MCP Registry | server.json | release.yml (push to main) |
| Claude Code plugin | .claude-plugin/plugin.json, .mcp.json | available on GitHub push |
| Claude Code marketplace | .claude-plugin/marketplace.json | available on GitHub push |
| Claude Desktop bundle | manifest.json | release.yml attaches .mcpb to the Release |
mainReleases are fully automated. On every push to main,
.github/workflows/release.yml:
feat: β minor, BREAKING CHANGE/type!: β major, anything else β patch;
add [skip release] to a commit message to skip).pyproject.toml and syncs it into every artifact
(server.json, manifest.json, plugin + marketplace) via scripts/sync_version.py β
version lives in one place, no hand-bumping.chore(release): vX [skip ci], tags vX, pushes..mcpb and cuts a GitHub Release with the wheel + bundle attached.The release commit carries [skip ci], so it does not re-trigger the workflow.
One-time setup (can't be automated β needs your accounts):
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/custom-mcp-database)<a href="https://allmcps.com/mcp/custom-mcp-database"><img src="https://allmcps.com/api/badge/custom-mcp-database?style=directory" alt="Custom MCP Database on AllMCPs" /></a>