The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Mysql MCP Server listing page.
A Model Context Protocol (MCP) implementation that enables secure interaction with MySQL databases. This server component facilitates communication between AI applications (hosts/clients) and MySQL databases, making database exploration and analysis safer and more structured through a controlled interface.
Note: MySQL MCP Server supports both standard input/output (STDIO) and Streamable HTTP (SSE) transport modes. The SSE mode is recommended for remote/self-hosted deployments.
MYSQL_DATABASE)MCP_TRANSPORT=sse)To install MySQL MCP Server for Claude Desktop automatically via Smithery:
Add --scope project after mcp add to keep the registration in the current workspace. See Autohand Code for current CLI details.
Set the following environment variables:
.env file loadingOn startup the server automatically loads a .env file via python-dotenv, so for local use you can simply:
The file is read from the process working directory (and parent directories), which works when you run the server yourself from the project folder.
⚠️ Claude Code / Claude Desktop: these hosts launch the server from their own working directory, so the project's
.envwill not be found and you'll seeMissing required database configuration. Put yourMYSQL_*values in theenvblock of the MCP config (shown in the Usage section below) rather than relying on.env.
When MYSQL_DATABASE is not set, the server operates in multi-database mode:
list_resources returns all user databases (system databases are filtered out)mydb.mytable in SQL queriesUSE db; SELECT ...) are not supported.execute_sqlExecutes any standard SQL query.
query (string)SELECT, SHOW, DESCRIBE, and DML (INSERT, UPDATE, DELETE). DML operations are marked with a destructive hint.database.table notation to query any database regardless of the MYSQL_DATABASE setting.get_schema_infoProvides detailed metadata about database structures.
table_name (optional string)database.table to query a table outside MYSQL_DATABASE; bare names use the configured database.$ (dots are allowed as a separator between database and table names).get_table_sampleFetches a representative sample of data.
table_name (string), limit (optional integer, max 20)database.table to sample a table outside MYSQL_DATABASE; bare names use the configured database.$ (dots are allowed as a separator between database and table names).In addition to tools, the server exposes MCP prompts — guided, multi-step workflows that a client can launch on demand. In Claude Code they appear as slash commands (/mcp__<server>__<prompt>); in Claude Desktop they appear in the prompts (+) menu.
| Prompt | Arguments | Description |
|---|---|---|
explore_database | (none) | Systematically explore the database: discover available tables, inspect their schemas, sample the data, and summarize what's there. |
analyze_table | table_name (required) | Deep-dive into a specific table: retrieve its schema, sample its data, and suggest useful queries. Accepts database.table notation for cross-database lookups. |
Example (Claude Code):
Both prompts orchestrate the existing get_schema_info and get_table_sample tools; explore_database also uses resource listing to enumerate tables.
Add this to your claude_desktop_config.json:
For more detailed examples and agent-specific guidance, see MCP_USECASES.md.
Add this to your mcp.json:
Note: Will need to install uv for this to work
While MySQL MCP Server isn't intended to be run standalone or directly from the command line with Python, you can use the MCP Inspector to debug it.
The MCP Inspector provides a convenient way to test and debug your MCP implementation:
The MySQL MCP Server is designed to be integrated with AI applications like Claude Desktop and should not be run directly as a standalone Python program.
Identifier Validation: Table and database names passed to get_schema_info and get_table_sample are validated against a strict whitelist (alphanumeric, underscore, and $ only; a single dot is allowed as a database.table separator). Other special characters are rejected to prevent SQL injection.
Encrypted Access: Full support for SSL/TLS and SSH Tunneling for secure remote connections.
Log Privacy: Passwords and SSH private keys are automatically masked in server logs.
Least Privilege: Always use a dedicated MySQL user with minimal required permissions.
SSE transport has no built-in authentication. The SSE server binds to 0.0.0.0 by default and accepts connections without credentials. If you expose it beyond localhost, place it behind a reverse proxy (nginx, Caddy, Traefik) that enforces authentication. Example with nginx and HTTP Basic Auth:
Set MCP_SSE_HOST=127.0.0.1 so the server only listens on loopback and the proxy is the sole public entry point. Set MCP_SSE_ALLOWED_HOSTS to the public hostname your proxy forwards (e.g. MCP_SSE_ALLOWED_HOSTS=myserver.example.com:443).
See SECURITY.md for a comprehensive guide on securing your deployment.
This MCP implementation requires database access to function. For security:
See MySQL Security Configuration Guide for detailed instructions on:
⚠️ IMPORTANT: Always follow the principle of least privilege when configuring database access.
MIT License - see LICENSE file for details.
git checkout -b feature/amazing-feature)git commit -m 'Add some amazing feature')git push origin feature/amazing-feature)