Minimal, read-only, PII-safe MCP server for SQL databases.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
A PII-safe, read-only MCP server for coding agents working with SQL Server, MySQL and MariaDB: schema knowledge and safe queries without write-capable tools or plaintext exposure of configured PII columns.
Read the data. Protect the identity.
Give a coding agent the schema knowledge it needs to write correct code - servers, databases,
tables, columns, keys, indexes, and stored procedures. On aliases you mark all_pii_safe, it can also
query real rows while configured personal data stays hidden behind authenticated tokens.
all_pii_safe server, the columns you configure come back as
alias-bound, authenticated tokens (pii:v1:...), never as plaintext. An agent can still
project, count, and filter on them with = and IN using tokens it was given, so it can follow
a record without reading it. Tokens do not work on another server alias or with another key.execute_sql runs only a validated, regenerated SELECT.access_level: metadata (the default) exposes database navigation and
table structure; meta_and_code additionally exposes stored procedures; execute_sql needs an
explicit all_pii_safe alias with its own key. Database permissions stay the primary control,
so use a least-privilege login.${NAME} placeholders resolved
from the environment. They never appear in logs or model-visible errors.Reference, and the stderr
log records the connection stage, elapsed time, and driver error for the same reference, with
credentials removed. See Logging.| Tool | Access | Purpose |
|---|---|---|
list_servers | π’ read | Configured server aliases |
list_databases | π’ read | Databases visible to the credentials |
list_tables | π’ read | Base tables, filtered by schema or name |
get_table_definition | π’ read | Columns, keys, constraints, and indexes of one table |
list_stored_procedures | π’ read | Stored procedures, without definitions; requires meta_and_code or all_pii_safe |
get_stored_procedure | π’ read | The definition of one stored procedure; requires meta_and_code or all_pii_safe |
execute_sql | π’ read | One restricted SELECT on an all_pii_safe server; protected columns return tokens |
[!NOTE] Status: SQL Server supports every tool. MySQL and MariaDB (
engine: mysqlormariadb,mysql+pymysqlURLs) support every tool too.schemais alwaysnullthere because the database is the catalog, andexecute_sqlusesLIMITinstead ofTOP. See architecture.md.
or
Pin a version when you want a fixed surface: uvx sql-safe-mcp==1.5.1.
Requires Python 3.12β3.14, uv (or pip), and
Microsoft ODBC Driver 18 for SQL Server
when you connect to SQL Server. MySQL and MariaDB use the bundled PyMySQL driver and need nothing
else.
Verified against SQL Server 2022, MySQL 8.4, and MariaDB 11.4 (see checks.md).
Copy sql-safe-mcp.example-simple.yaml to
sql-safe-mcp.yaml. This smallest configuration exposes schema metadata from one SQL Server
instance and does not allow row queries. Keep the complete connection URL in an environment
variable:
Here reporting is the value an agent passes as server. A missing variable, or an engine that
does not match the URL dialect, stops the MCP server at startup. For multiple servers, local PII
rules, shared PII rule sets, logging, and runtime limits, use the commented examples in the
configuration reference.
After defining every environment variable referenced by the YAML file, point the server at it with
SQL_SAFE_MCP_CONFIG (or --config) and check it without connecting to any database:
Configuration is validated at startup, and an error names the problem without printing a URL or secret. Keep credentials in the host's own configuration and never commit them. The server acts with the database account's permissions, so use a dedicated login with the least access the job needs.
Every client configuration needs SQL_SAFE_MCP_CONFIG plus the environment variables referenced
by your YAML file. Keep connection URLs and PII keys in the MCP host's environment or
configuration, never in the YAML file or other tracked files.
Put at least one other option between the last --env and the server name, as above. Otherwise,
the CLI reads the name as another KEY=value pair.
Add the server to claude_desktop_config.json:
Use command uvx, argument sql-safe-mcp, and set SQL_SAFE_MCP_CONFIG plus every environment
variable referenced by the configuration file. The server writes MCP messages to stdout and logs
only to stderr.
execute_sql on the billing alias allows one restricted SELECT. For example, these arguments:
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/sql-safe-mcp)<a href="https://allmcps.com/mcp/sql-safe-mcp"><img src="https://allmcps.com/api/badge/sql-safe-mcp?style=directory" alt="SQL Safe MCP on AllMCPs" /></a>