Midplane routes MCP agent access to Postgres through SQL policies, masking, approvals, containment, and a hash-chained audit log.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
Inspect callable tools, capabilities, and parameters exposed to AI agents by Midplane.
The Midplane MCP server gives AI agents an MCP connection to Postgres through a gateway that runs inside the network hosting the databases. The gateway opens database connections itself and executes SQL using its own database role. Agents do not connect directly to Postgres.
Every statement is parsed with Postgres's parser before execution. Midplane evaluates the parsed statement against policy, records the event, and runs it only when the request is allowed. This makes the gateway suitable for agent workflows that need access to real tables without granting unrestricted database permissions.
Access is denied by default at the table level and can be defined per table. Masking changes sensitive values in the SQL before filters, joins, or aggregates process them. Supported masking behavior described by the project includes hashing, retaining only part of a value, generalizing dates, and replacing values with NULL.
An agent connects to the gateway over MCP. The gateway checks the statement, applies policy decisions and any required masks, writes an audit record, and then sends permitted SQL to Postgres. The gateway can also make outbound-only connections to Midplane Cloud, while the database remains in the user's network. In the documented cloud setup, the cloud does not hold database credentials or receive database rows.
Several controls apply to query execution. Midplane permits one statement at a time, requires a WHERE clause for writes, and rejects writes concealed inside a WITH clause. Reads use read-only transactions and timeouts. A write can be paused for human approval; the approval is tied to the exact statement and compared with the row count shown to the approver.
The gateway can mark an agent as tainted after it reads a column labeled untrusted, such as a support-ticket or email field. Once tainted, the agent's writes are held and access to secret tables is closed. Audit data is stored on the gateway's disk in a hash-chained log that can be exported and verified with one command.
The project provides a midplane npm package that can be run with npx, plus a container image at ghcr.io/midplaneai/midplane. The quickstart requires Node 24.16 or newer, Docker, and an MCP client such as Claude Code. It starts a sample database and a local-mode gateway with Docker Compose; the sample flow is designed to keep data on the local machine.
For a local deployment, use the project's local-mode documentation and configure the gateway for the target Postgres database and policies. A separate Midplane Cloud setup provides a policy dashboard, approvals, and a query log, but cloud access is invite-only according to the supplied material. The gateway remains next to the database in either deployment model.
Local mode has no person available to approve a held write, so a write requiring approval is refused there. The quickstart also demonstrates that reading prompt-injection content can taint the agent and prevent subsequent access to secret tables.
Midplane is specifically described as a gateway for Postgres databases; the supplied material does not document support for other database engines. The README also does not list named MCP tool identifiers or environment-variable names, so configuration details should be taken from the project's documentation rather than inferred from this listing.
Factual signals from GitHub, npm, and our automated checks — not a rating.
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/midplane)<a href="https://allmcps.com/mcp/midplane"><img src="https://allmcps.com/api/badge/midplane?style=directory" alt="Midplane on AllMCPs" /></a>