Identity-scoped schema selection for text-to-SQL. Returns only the tables the caller may read.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent โ or use 1-click editor setup below.
One-click editor setup isnโt available for this listing yet โ we donโt have a confirmed install command, and weโd rather show nothing than point your editor at the wrong package or host. Follow the projectโs own setup instructions, linked above.
Your text-to-SQL agent picks which tables to show the model before anyone checks what the caller is allowed to read. schemagate does the check first: it filters the schema by the caller's grants, so restricted tables are absent from the prompt rather than ranked low. Works with LangChain, MCP, or any SQL agent, on Postgres, Oracle, MySQL, SQL Server and SQLite.
With row-level security alone the failure is quiet: the model writes valid SQL against a table the caller cannot read, RLS strips every row, and the user is told "no records found" โ indistinguishable from "this data does not exist."
Demo ยท Install ยท Benchmarks ยท Local models ยท What it costs ยท Coming from Vanna
Same question, two callers, no database and no key:
Absent, not ranked low. A table the caller may not read never enters the prompt, so no rewording of the question reaches it and there is nothing to filter out of the answer afterwards.

Try it in the browser โ no install, no database, no model call.
The selection is a prompt, so the rest follows:
Rows, from a question, with no database to set up โ that runs against a
bundled 42-object schema. Point it at your own with --url:
No key? Drop --provider and it prints a prompt to paste into any chat, then
run the SQL it gives you back with --sql "SELECT ...".
More of the bundled schema, with the questions people actually type:
Against your own database it's the same shape:
schemagate studio opens a local page where you type questions, switch the caller's
roles, edit hints, and watch what reaches the prompt and what doesn't. The same
page runs publicly at https://ashishsinha1602.github.io/schemagate/ on the six
bundled schemas, in your browser, with no server behind it. The selector on that page is a JavaScript
port of this library, and a test runs both against 1,789 cases and requires
identical rankings.
If you're coming from Vanna (archived March 2026), docs/migrating-from-vanna.md
is the short version: Vanna applied identity when the SQL ran; schemagate applies
it before the model sees the schema. Your User maps to a Principal in one
line.
Every text-to-SQL call pays for the schema in the prompt. Dump the whole thing
and you pay for every table on every question; hand the model six tables and
you pay for six. Measured on the test schemas, average over their golden
questions, same built-in estimator as tests/bench.py:
| schema | objects | full schema, every call | schemagate, average | reduction |
|---|---|---|---|---|
| Commerce | 42 | 2,483 tokens | 604 | 76% |
| Clinical claims | 27 | 1,568 | 543 | 65% |
| Claims warehouse (star) | 51 | 3,312 | 880 | 73% |
| Bank ledger and trading | 39 | 2,255 | 637 | 72% |
| IoT telemetry | 40 | 2,125 | 448 | 79% |
| Hostile (4 schemas, copies of everything) | 260 | 16,095 | 444 | 97% |
The last row is the one that matters: the selection stays around six tables no matter how big the schema is, so the saving grows with the schema. Real databases are the last row, not the first.
Worked example, with a price you should replace with your own: a 260-object schema, 5,000 questions a day, an input price of $3 per million tokens. Full schema: 16,095 ร 5,000 ร 30 = 2.4 billion tokens a month, about $7,200. With schemagate: 444 ร 5,000 ร 30 = 67 million, about $200. The browser demo has these two numbers as editable fields under the stats, so you can put in your own volume and price and watch it recompute against whatever question you ask.
Two more things that cost nothing here and money elsewhere: the selector itself never calls a model (BM25 plus a hashed embedder, offline, milliseconds), and the optional descriptions can be written by any chat window you already pay for instead of an API key โ see Without an API key.
Two things go wrong when you point an LLM at a database schema.
The first is cost. Most systems paste the whole schema into the prompt on every question. That's fine for twenty tables and ruinous for two thousand.
The second is worse, and it's the reason I wrote this. Schema selection happens before the query runs, so it happens before row-level security can do anything. If your selection step isn't identity-aware, the model gets handed a table the caller can't read. It writes perfectly good SQL. RLS or VPD filters every row out. The user sees "no records found" and believes it.
That's not an access-denied message. It's a wrong answer with a confident tone, and the user has no way to tell the difference. Filtering the catalog by identity first is the only way I know to avoid it.
hr_compensation is not in that result and its name does not appear anywhere
in the prompt text.
That's the whole thing. One dependency (SQLAlchemy), no API key, no model download. The default embedder is a hashed n-gram vectoriser that runs offline and gives byte-identical results on every machine.
Extras, all optional:
huggingface is the no-key, nothing-leaves-the-machine path, and it is the
one extra that is heavy: about 2 GB of wheels plus a 3.1 GB model download the
first time you use it. It is deliberately kept out of schemagate[all].
docs/local-models.md has the whole story โ the
downloads, the load you wait through once, what it is good at and where it is worse
than a hosted model.
Every release is signed. The wheels carry PEP 740
attestations โ a signature from GitHub naming the workflow, repository and
commit that built that exact file. Nothing is uploaded by hand and there is no
API token to steal. Check one yourself with
gh attestation verify <wheel> --repo ashishsinha1602/schemagate.
Every wheel on PyPI carries a signed provenance attestation naming the commit that built it:
gh attestation verify <wheel> --repo ashishsinha1602/schemagate.
Or without installing anything, with every driver already in the image:
No reviews yet โ be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/schemagate)<a href="https://allmcps.com/mcp/schemagate"><img src="https://allmcps.com/api/badge/schemagate?style=directory" alt="Schemagate on AllMCPs" /></a>