io.github.arifulislamat/database-mcp-postgres

MCP server for PostgreSQL. Read-only by default, row caps, timeouts, secrets never logged.

DatabasesPythonv0.4.2

database-mcp

CI License: MIT npm PyPI Node >= 20

MCP servers that give AI clients safe, structured access to SQL databases.

One installable package per database engine, in TypeScript (npm) and Python (PyPI). Every package exposes the same minimal two-tool surface, execute_sql and search_objects, with guardrails on by default: read-only mode, row caps, and statement timeouts.

Packages

EngineTypeScript (npm)Python (PyPI)
SQLite@database-mcp/sqlite npmdatabase-mcp-sqlite PyPI
libSQL@database-mcp/libsql npmdatabase-mcp-libsql PyPI
MySQL@database-mcp/mysql npmdatabase-mcp-mysql PyPI
MariaDB@database-mcp/mariadb npmdatabase-mcp-mariadb PyPI
Postgres@database-mcp/postgres npmdatabase-mcp-postgres PyPI

Both lines are published and pass the same language-agnostic conformance suite against real databases in CI, so behavior is identical regardless of language. Every engine is also listed on the MCP Registry with both install options.

Go and Rust implementations are planned.

Design principles

  • Two tools, no more. A tiny tool surface keeps the model's context window clean. search_objects progressively discloses schema: call it with no arguments to list tables, with a table name to get columns, indexes, and foreign keys.
  • Safe by default. Read-only mode is enforced in two layers: a conservative SQL guard, plus a session-level read-only setting in the database itself. Rows are capped (default 1000) and statements time out (default 30s).
  • Configured at launch, never via chat. Connection details come from flags, a YAML config file, or environment variables. Credentials are never accepted through a tool call.
  • Secrets never appear in logs. Passwords live in non-printable secret types, DSNs are sanitized before logging, and a redaction filter guards the log boundary.

Quick start

Pick your engine's package; each README has the full config surface. SQLite via npm:

{
  "mcpServers": {
    "sqlite": {
      "command": "npx",
      "args": ["-y", "@database-mcp/sqlite", "--dsn", "/absolute/path/to/database.db"]
    }
  }
}

Or via PyPI: use "command": "uvx" and "args": ["database-mcp-sqlite", "--dsn", "/absolute/path/to/database.db"]. Flags, environment variables, and YAML config are identical across both lines.

Networked engines take credentials from the environment (MYSQL_*, MARIADB_*, POSTGRES_*/DATABASE_URL, LIBSQL_URL/LIBSQL_AUTH_TOKEN), *_FILE mounted secrets, or a YAML file via --config. Never from a chat prompt.

Contributing

See CONTRIBUTING.md. The short version: the conformance suite is the definition of done. A change is mergeable only when conformance/run.mjs passes against every affected server.

License

MIT

Installation

Source-derived launch command. Check the maintainer’s required arguments and credentials before running:

bash
npx -y @database-mcp/postgres

Set up in your AI client

Merge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.

json
{
  "mcpServers": {
    "io-github-arifulislamat-database-mcp-postgres": {
      "command": "npx",
      "args": [
        "-y",
        "@database-mcp/postgres"
      ]
    }
  }
}

Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.

Claude Desktop setup reference

Package

@database-mcp/postgresnpm

Compatible MCP Clients

io.github.arifulislamat/database-mcp-postgres works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.

  • Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.
  • Cursor~/.cursor/mcp.jsonRestart Cursor for changes to take effect.
  • VS Code.vscode/mcp.jsonReload VS Code window for changes to take effect.
  • Windsurf~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect.
  • Claude Code.mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.

Learn More