Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ—„οΈ Databases
  3. SQL Safe MCP
S
Health: Not checked yetWe have not completed a health check for this listing yet.No health check has run yet.

SQL Safe MCP

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View Repository

Minimal, read-only, PII-safe MCP server for SQL databases.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

One-click editor setup isn’t available for this listing yet β€” we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ
No confirmed setup config for this listing yet. We only publish a config block when the install details come from the project itself β€” its README, its docs, or a verified owner. We haven’t found those for SQL Safe MCP, and we’d rather show nothing than a guess you’d paste into your client. Follow the project’s own setup instructions for the current steps.
Install Directory Badge Claim listing AlternativesπŸ—„οΈ More in Databases

Documentation Overview

sql-safe-mcp

A PII-safe, read-only MCP server for coding agents working with SQL Server, MySQL and MariaDB: schema knowledge and safe queries without write-capable tools or plaintext exposure of configured PII columns.

CI Release PyPI Version Python License: MIT

Model Context Protocol compatible MCP Registry: io.github.proprock/sql-safe-mcp

Read the data. Protect the identity.

Read the data. Protect the identity.

Give a coding agent the schema knowledge it needs to write correct code - servers, databases, tables, columns, keys, indexes, and stored procedures. On aliases you mark all_pii_safe, it can also query real rows while configured personal data stays hidden behind authenticated tokens.

PII-safe by default. Read-only by design.

  • PII-safe by default - on an all_pii_safe server, the columns you configure come back as alias-bound, authenticated tokens (pii:v1:...), never as plaintext. An agent can still project, count, and filter on them with = and IN using tokens it was given, so it can follow a record without reading it. Tokens do not work on another server alias or with another key.
  • Read-only by construction - seven tools, all annotated read-only. No tool writes data, and the server never executes SQL an agent wrote: metadata comes from SQLAlchemy Inspector and fixed catalog queries, and execute_sql runs only a validated, regenerated SELECT.
  • Multiple servers, isolated policies - one MCP process can expose multiple named SQL Server, MySQL, and MariaDB instances. Each alias has its own connection, access level, and, when enabled, PII key and protection rules. Every database operation targets an explicit alias; there is no network discovery.

Operational safeguards

  • Fails closed - SQL validation is an allowlist. Unknown syntax, unresolved lineage, and unsupported protected-value types are refused, not guessed at. The verification evidence is in the security model.
  • Least access first - access_level: metadata (the default) exposes database navigation and table structure; meta_and_code additionally exposes stored procedures; execute_sql needs an explicit all_pii_safe alias with its own key. Database permissions stay the primary control, so use a least-privilege login.
  • Secrets stay out of sight - connection URLs live in YAML with ${NAME} placeholders resolved from the environment. They never appear in logs or model-visible errors.
  • Compact, predictable output - object-rooted results with stable sorting, literal case-insensitive name filters, and stored procedure lists that do not expand definitions.
  • Errors an agent can act on - an ambiguous name lists the candidate schemas. Errors never contain connection details, credentials, keys, tokens, or rows.
  • Tested against attacks, not just examples - the SQL and PII boundary is checked with an adversarial corpus of hostile statements, property-based tests (token isolation, tamper resistance), a live attack run against a really writable login with before/after snapshots, and mutation testing. Results are in Verification of the SQL boundary.
  • Diagnosable failures - a timeout or connection error carries a Reference, and the stderr log records the connection stage, elapsed time, and driver error for the same reference, with credentials removed. See Logging.
ToolAccessPurpose
list_servers🟒 readConfigured server aliases
list_databases🟒 readDatabases visible to the credentials
list_tables🟒 readBase tables, filtered by schema or name
get_table_definition🟒 readColumns, keys, constraints, and indexes of one table
list_stored_procedures🟒 readStored procedures, without definitions; requires meta_and_code or all_pii_safe
get_stored_procedure🟒 readThe definition of one stored procedure; requires meta_and_code or all_pii_safe
execute_sql🟒 readOne restricted SELECT on an all_pii_safe server; protected columns return tokens

[!NOTE] Status: SQL Server supports every tool. MySQL and MariaDB (engine: mysql or mariadb, mysql+pymysql URLs) support every tool too. schema is always null there because the database is the catalog, and execute_sql uses LIMIT instead of TOP. See architecture.md.

Quick start

Install

bash
uvx sql-safe-mcp

or

Terminal
pip install sql-safe-mcp

Pin a version when you want a fixed surface: uvx sql-safe-mcp==1.5.1.

Requires Python 3.12–3.14, uv (or pip), and Microsoft ODBC Driver 18 for SQL Server when you connect to SQL Server. MySQL and MariaDB use the bundled PyMySQL driver and need nothing else.

Verified against SQL Server 2022, MySQL 8.4, and MariaDB 11.4 (see checks.md).

Or you can even ask an agent to install it
text
Install sql-safe-mcp as a stdio MCP server.
Ask whether to install it for this project/workspace or at user level. Then:
detect and preserve the host's existing MCP config;
configure the server to run via uvx sql-safe-mcp;
create a YAML config template with env placeholders only;
add SQL_SAFE_MCP_CONFIG;
report the env variables the user must set.
Do not store secrets or connection data in tracked files or output. Validate with
sql-safe-mcp --check-config once variables are available.

Configure server

Copy sql-safe-mcp.example-simple.yaml to sql-safe-mcp.yaml. This smallest configuration exposes schema metadata from one SQL Server instance and does not allow row queries. Keep the complete connection URL in an environment variable:

yaml
version: 1
servers:
  reporting:
    engine: sqlserver
    access_level: metadata
    connection_url: "${REPORTING_SQL_URL}"

Here reporting is the value an agent passes as server. A missing variable, or an engine that does not match the URL dialect, stops the MCP server at startup. For multiple servers, local PII rules, shared PII rule sets, logging, and runtime limits, use the commented examples in the configuration reference.

Check the configuration

After defining every environment variable referenced by the YAML file, point the server at it with SQL_SAFE_MCP_CONFIG (or --config) and check it without connecting to any database:

bash
SQL_SAFE_MCP_CONFIG=sql-safe-mcp.yaml uvx sql-safe-mcp --check-config

Configuration is validated at startup, and an error names the problem without printing a URL or secret. Keep credentials in the host's own configuration and never commit them. The server acts with the database account's permissions, so use a dedicated login with the least access the job needs.

Connect an MCP client

Every client configuration needs SQL_SAFE_MCP_CONFIG plus the environment variables referenced by your YAML file. Keep connection URLs and PII keys in the MCP host's environment or configuration, never in the YAML file or other tracked files.

Claude Code
Terminal
claude mcp add --env SQL_SAFE_MCP_CONFIG=/path/to/sql-safe-mcp.yaml --env REPORTING_SQL_URL=mssql+pyodbc://... --transport stdio sql-safe -- uvx sql-safe-mcp

Put at least one other option between the last --env and the server name, as above. Otherwise, the CLI reads the name as another KEY=value pair.

Claude Desktop

Add the server to claude_desktop_config.json:

config.json
{
  "mcpServers": {
    "sql-safe": {
      "command": "uvx",
      "args": ["sql-safe-mcp"],
      "env": {
        "SQL_SAFE_MCP_CONFIG": "/path/to/sql-safe-mcp.yaml",
        "REPORTING_SQL_URL": "mssql+pyodbc://..."
      }
    }
  }
}
Codex CLI
bash
codex mcp add sql-safe --env SQL_SAFE_MCP_CONFIG=/path/to/sql-safe-mcp.yaml --env REPORTING_SQL_URL=mssql+pyodbc://... -- uvx sql-safe-mcp
Any other stdio host

Use command uvx, argument sql-safe-mcp, and set SQL_SAFE_MCP_CONFIG plus every environment variable referenced by the configuration file. The server writes MCP messages to stdout and logs only to stderr.

PII-safe queries

execute_sql on the billing alias allows one restricted SELECT. For example, these arguments:

config.json
{
  "server": "billing",
  "database": "Billing",
  "sql": "SELECT CustomerId, Email FROM dbo.Customers"
}

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Databases View all alternatives
  • M
    MCP Toolbox for Databases

    MCP Toolbox for Databases enables your agent to connect to your database.

    πŸ—„οΈ Databases1 views
    Compare vs MCP Toolbox for Databases β†’
  • M
    MCP Server Mysql

    MySQL database integration in NodeJS with configurable access controls and schema inspection

    πŸ—„οΈ Databases3 views
    Compare vs MCP Server Mysql β†’
  • D
    Dataassist IO

    Query your org's data in natural language β€” read-only MCP access to SQL, NoSQL, files & warehouses.

    πŸ—„οΈ Databases2 views
    Compare vs Dataassist IO β†’
  • P
    Postgres MCP

    All-in-one MCP server for Postgres development and operations, with tools for performance analysis, tuning, and health checks

    πŸ—„οΈ Databases1 views
    Compare vs Postgres MCP β†’

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about SQL Safe MCP

We don't have a confirmed install command for SQL Safe MCP yet, so we don't publish a generated one β€” a guessed package name would point at the wrong package or none at all. Follow the project's own README or setup instructions (https://github.com/proprock/sql-safe-mcp) for the current steps.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewSQL Safe MCP AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/sql-safe-mcp?style=directory)](https://allmcps.com/mcp/sql-safe-mcp)
HTML Embed
<a href="https://allmcps.com/mcp/sql-safe-mcp"><img src="https://allmcps.com/api/badge/sql-safe-mcp?style=directory" alt="SQL Safe MCP on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ—„οΈDatabases
More technical detailsExpand β–Ύ
Last updatedSep 28, 2026
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
25Quality signal: Emerging Β· 25/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership8/20
Documentation & tools10/30
Adoption & activity1/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… Spotlight Slot

Feature Your MCP Server

Get maximum visibility for your server across our directory, search results, and detail pages.

Spotlight Your Server

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge and attach your website β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ—„οΈ Databases β†’Best MCP servers for Databases β†’Alternatives to SQL Safe MCP β†’Install in Claude DesktopInstall in CursorInstall in VS CodeSetup guides for all 13 MCP clients