Unified MCP server for SQL and NoSQL databases, powered by dockit and sqlkit desktop apps
Let your AI coding agent securely access all your databases, in plain language.
Local-first. Enterprise-grade security. Open source.
📖 Product Page · npm · dockit · sqlkit · Releases
English · 简体中文
This repository contains the Data Studio MCP Server, a Model Context Protocol server that gives AI coding agents direct access to your databases through the dockit and sqlkit desktop apps.
Install and launch dockit and/or sqlkit, add a database connection, and make sure Settings → MCP Bridge → Auto-start is enabled (it is by default). Install both apps for the full SQL + NoSQL tool set.
npm install -g @geek-fun/data-studio-mcp
Or run it without installing (npx downloads it on first run):
npx -y @geek-fun/data-studio-mcp
OpenAI Codex, one command:
codex mcp add data-studio -- npx -y @geek-fun/data-studio-mcp
Claude Code, one command:
claude mcp add --transport stdio data-studio -- npx -y @geek-fun/data-studio-mcp
Cursor. Create .cursor/mcp.json (project) or ~/.cursor/mcp.json (global):
{
"mcpServers": {
"data-studio": {
"command": "npx",
"args": ["-y", "@geek-fun/data-studio-mcp"]
}
}
}
Windsurf. Create ~/.codeium/windsurf/mcp_config.json (global only):
{
"mcpServers": {
"data-studio": {
"command": "npx",
"args": ["-y", "@geek-fun/data-studio-mcp"]
}
}
}
OpenCode. Add to opencode.json (project) or ~/.config/opencode/opencode.json (global):
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"data-studio": {
"type": "local",
"command": ["npx", "-y", "@geek-fun/data-studio-mcp"],
"enabled": true
}
}
}
Any other MCP client. Register a stdio server with command npx and args -y @geek-fun/data-studio-mcp.
Open Settings → MCP Bridge in dockit/sqlkit to control what the agent can do:
| Permission mode | What the agent can do |
|---|---|
| Read Only (default) | Explore schemas, run SELECT queries. No writes. |
| Data Read/Write | INSERT, UPDATE, index operations. No deletes/drops. |
| Full Access | Everything, including DELETE, DROP, TRUNCATE. |
Use plain language. The agent queries your databases for you:
orders*"The agent reads schemas, runs queries, and explores your data, then shows you every query it executed.
The LLM gets broad access to your data, but it never sees your credentials. The policy model gates every capability by risk level.
connection_id. Real credentials are resolved inside dockit/sqlkit and never cross the MCP boundary. Your passwords and keys stay on your machine, in your app.Ask in the policy. The client prompts the user for explicit confirmation before anything destructive runs.127.0.0.1 exclusively. It is unreachable from other machines, with no server to host and no API keys to manage.All tools follow the data_studio__{backend}__{action} convention. The User confirmation column shows which operations surface an explicit confirmation prompt in your AI client before they run.
| Tool | Backend | Risk | Requires permission | User confirmation |
|---|---|---|---|---|
data_studio__list_connections | Server | 🟢 Safe | Read Only | No |
data_studio__get_status | Server | 🟢 Safe | Read Only | No |
data_studio__sqlkit__list_databases | sqlkit | 🟢 Safe | Read Only | No |
data_studio__sqlkit__list_schemas | sqlkit | 🟢 Safe | Read Only | No |
data_studio__sqlkit__list_tables | sqlkit | 🟢 Safe | Read Only | No |
data_studio__sqlkit__get_schema | sqlkit | 🟢 Safe | Read Only | No |
data_studio__sqlkit__describe_table | sqlkit | 🟢 Safe | Read Only | No |
data_studio__sqlkit__explain_query | sqlkit | 🟢 Safe | Read Only | No |
data_studio__sqlkit__list_indexes | sqlkit | 🟢 Safe | Read Only | No |
data_studio__sqlkit__list_foreign_keys | sqlkit | 🟢 Safe | Read Only | No |
data_studio__sqlkit__list_views | sqlkit | 🟢 Safe | Read Only | No |
data_studio__sqlkit__list_procedures | sqlkit | 🟢 Safe | Read Only | No |
data_studio__sqlkit__list_functions | sqlkit | 🟢 Safe | Read Only | No |
data_studio__sqlkit__list_triggers | sqlkit | 🟢 Safe | Read Only | No |
data_studio__sqlkit__get_table_info | sqlkit | 🟢 Safe | Read Only | No |
data_studio__sqlkit__get_foreign_keys | sqlkit | 🟢 Safe | Read Only | No |
data_studio__sqlkit__list_sessions | sqlkit | 🟢 Safe | Read Only | No |
data_studio__sqlkit__get_slow_queries | sqlkit | 🟢 Safe | Read Only | No |
data_studio__sqlkit__list_connections | sqlkit | 🟢 Safe | Read Only | No |
data_studio__sqlkit__execute_query | sqlkit | 🟢 Safe | Read Only | No |
data_studio__sqlkit__get_object_ddl | sqlkit | 🟢 Safe | Read Only | No |
data_studio__sqlkit__execute_write | sqlkit | 🟡 Elevated | Data Read-Write | No |
data_studio__sqlkit__kill_session | sqlkit | 🟡 Elevated | Data Read-Write | No |
data_studio__sqlkit__grant_privilege | sqlkit | 🟡 Elevated | Data Read-Write | No |
data_studio__sqlkit__revoke_privilege | sqlkit | 🟡 Elevated | Data Read-Write | No |
data_studio__sqlkit__execute_delete | sqlkit | 🔴 Destructive | Full Access | Yes |
data_studio__sqlkit__execute_ddl | sqlkit | 🔴 Destructive | Full Access | Yes |
data_studio__es__search | dockit · Elasticsearch | 🟢 Safe | Read Only | No |
data_studio__es__get_document | dockit · Elasticsearch | 🟢 Safe | Read Only | No |
data_studio__es__cat_indices | dockit · Elasticsearch | 🟢 Safe | Read Only | No |
data_studio__es__get_mapping | dockit · Elasticsearch | 🟢 Safe | Read Only | No |
data_studio__es__cat_aliases | dockit · Elasticsearch | 🟢 Safe | Read Only | No |
data_studio__es__get_alias | dockit · Elasticsearch | 🟢 Safe | Read Only | No |
data_studio__es__count | dockit · Elasticsearch | 🟢 Safe | Read Only | No |
data_studio__es__cluster_health | dockit · Elasticsearch | 🟢 Safe | Read Only | No |
data_studio__es__cat_nodes | dockit · Elasticsearch | 🟢 Safe | Read Only | No |
data_studio__es__cat_shards | dockit · Elasticsearch | 🟢 Safe | Read Only | No |
data_studio__es__list_snapshots | dockit · Elasticsearch | 🟢 Safe | Read Only | No |
data_studio__es__index_document | dockit · Elasticsearch | 🟡 Elevated | Data Read-Write | No |
data_studio__es__update_document | dockit · Elasticsearch | 🟡 Elevated | Data Read-Write | No |
data_studio__es__create_index | dockit · Elasticsearch | 🟡 Elevated | Data Read-Write | No |
data_studio__es__put_mapping | dockit · Elasticsearch | 🟡 Elevated | Data Read-Write | No |
data_studio__es__put_alias | dockit · Elasticsearch | 🟡 Elevated | Data Read-Write | No |
data_studio__es__update_aliases | dockit · Elasticsearch | 🟡 Elevated | Data Read-Write | No |
data_studio__es__bulk | dockit · Elasticsearch | 🟡 Elevated | Data Read-Write | No |
data_studio__es__reindex | dockit · Elasticsearch | 🟡 Elevated | Data Read-Write | No |
data_studio__es__restore_snapshot | dockit · Elasticsearch | 🟡 Elevated | Data Read-Write | No |
data_studio__es__delete_document | dockit · Elasticsearch | 🔴 Destructive | Full Access | Yes |
data_studio__es__delete_by_query | dockit · Elasticsearch | 🔴 Destructive | Full Access | Yes |
data_studio__es__delete_index | dockit · Elasticsearch | 🔴 Destructive | Full Access | Yes |
data_studio__es__delete_alias | dockit · Elasticsearch | 🔴 Destructive | Full Access | Yes |
data_studio__mongo__list_databases | dockit · MongoDB | 🟢 Safe | Read Only | No |
data_studio__mongo__list_collections | dockit · MongoDB | 🟢 Safe | Read Only | No |
data_studio__mongo__find | dockit · MongoDB | 🟢 Safe | Read Only | No |
data_studio__mongo__collection_stats | dockit · MongoDB | 🟢 Safe | Read Only | No |
data_studio__mongo__database_stats | dockit · MongoDB | 🟢 Safe | Read Only | No |
data_studio__mongo__server_status | dockit · MongoDB | 🟢 Safe | Read Only | No |
data_studio__mongo__repl_set_status | dockit · MongoDB | 🟢 Safe | Read Only | No |
data_studio__mongo__shard_status | dockit · MongoDB | 🟢 Safe | Read Only | No |
data_studio__mongo__count_documents | dockit · MongoDB | 🟢 Safe | Read Only | No |
data_studio__mongo__list_indexes | dockit · MongoDB | 🟢 Safe | Read Only | No |
data_studio__mongo__sample_documents | dockit · MongoDB | 🟢 Safe | Read Only | No |
data_studio__mongo__distinct | dockit · MongoDB | 🟢 Safe | Read Only | No |
data_studio__mongo__get_slow_queries | dockit · MongoDB | 🟢 Safe | Read Only | No |
data_studio__mongo__list_users | dockit · MongoDB | 🟢 Safe | Read Only | No |
data_studio__mongo__aggregate | dockit · MongoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__mongo__insert_one | dockit · MongoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__mongo__update_many | dockit · MongoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__mongo__create_database | dockit · MongoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__mongo__create_collection | dockit · MongoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__mongo__update_document | dockit · MongoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__mongo__rename_collection | dockit · MongoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__mongo__clone_collection | dockit · MongoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__mongo__create_index | dockit · MongoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__mongo__drop_index | dockit · MongoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__mongo__insert_many | dockit · MongoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__mongo__find_one_and_update | dockit · MongoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__mongo__bulk_write | dockit · MongoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__mongo__delete_many | dockit · MongoDB | 🔴 Destructive | Full Access | Yes |
data_studio__mongo__drop_database | dockit · MongoDB | 🔴 Destructive | Full Access | Yes |
data_studio__mongo__drop_collection | dockit · MongoDB | 🔴 Destructive | Full Access | Yes |
data_studio__mongo__delete_document | dockit · MongoDB | 🔴 Destructive | Full Access | Yes |
data_studio__mongo__truncate_collection | dockit · MongoDB | 🔴 Destructive | Full Access | Yes |
data_studio__dynamo__execute_query | dockit · DynamoDB | 🟢 Safe | Read Only | No |
data_studio__dynamo__describe_table | dockit · DynamoDB | 🟢 Safe | Read Only | No |
data_studio__dynamo__list_tables | dockit · DynamoDB | 🟢 Safe | Read Only | No |
data_studio__dynamo__query_table | dockit · DynamoDB | 🟢 Safe | Read Only | No |
data_studio__dynamo__scan_table | dockit · DynamoDB | 🟢 Safe | Read Only | No |
data_studio__dynamo__batch_get_items | dockit · DynamoDB | 🟢 Safe | Read Only | No |
data_studio__dynamo__describe_continuous_backups | dockit · DynamoDB | 🟢 Safe | Read Only | No |
data_studio__dynamo__describe_ttl | dockit · DynamoDB | 🟢 Safe | Read Only | No |
data_studio__dynamo__get_table_metrics | dockit · DynamoDB | 🟢 Safe | Read Only | No |
data_studio__dynamo__list_backups | dockit · DynamoDB | 🟢 Safe | Read Only | No |
data_studio__dynamo__describe_backup | dockit · DynamoDB | 🟢 Safe | Read Only | No |
data_studio__dynamo__describe_limits | dockit · DynamoDB | 🟢 Safe | Read Only | No |
data_studio__dynamo__list_tags | dockit · DynamoDB | 🟢 Safe | Read Only | No |
data_studio__dynamo__execute_write | dockit · DynamoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__dynamo__create_item | dockit · DynamoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__dynamo__batch_write_items | dockit · DynamoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__dynamo__update_item | dockit · DynamoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__dynamo__transact_write_items | dockit · DynamoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__dynamo__create_gsi | dockit · DynamoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__dynamo__update_gsi | dockit · DynamoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__dynamo__create_table | dockit · DynamoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__dynamo__update_table_config | dockit · DynamoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__dynamo__update_ttl | dockit · DynamoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__dynamo__update_pitr | dockit · DynamoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__dynamo__update_streams | dockit · DynamoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__dynamo__restore_table | dockit · DynamoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__dynamo__create_backup | dockit · DynamoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__dynamo__tag_resource | dockit · DynamoDB | 🟡 Elevated | Data Read-Write | No |
data_studio__dynamo__execute_delete | dockit · DynamoDB | 🔴 Destructive | Full Access | Yes |
data_studio__dynamo__delete_item | dockit · DynamoDB | 🔴 Destructive | Full Access | Yes |
data_studio__dynamo__delete_gsi | dockit · DynamoDB | 🔴 Destructive | Full Access | Yes |
data_studio__dynamo__delete_table | dockit · DynamoDB | 🔴 Destructive | Full Access | Yes |
data_studio__dynamo__truncate_table | dockit · DynamoDB | 🔴 Destructive | Full Access | Yes |
| 116 tools total. Read-only operations run automatically under Read Only mode. Elevated operations (writes, index/schema changes) require Data Read-Write. Destructive operations (DELETE, DROP, TRUNCATE) require Full Access and always surface an explicit user confirmation prompt. |
code agent (Claude Code / Cursor / OpenCode ...)
|
| MCP stdio protocol
v
@geek-fun/data-studio-mcp ← npm package (pure TypeScript)
|
| HTTP (localhost)
+----------------+----------------+
v v |
dockit:9120 sqlkit:9121 |
(NoSQL bridge) (SQL bridge) |
| | |
v v |
Elasticsearch PostgreSQL |
MongoDB MySQL |
DynamoDB SQL Server |
OpenSearch SQLite |
The MCP server is a thin routing layer. All database drivers, SSH tunnels, and connection management live in the desktop apps, which expose a local HTTP bridge (127.0.0.1 only). The MCP server auto-discovers running backends via each app's port file.
This repository also contains the data-studio-agent Rust framework, the shared AI agent loop (provider adapters, streaming, tool calling, context compaction) that powers the built-in assistants in dockit and sqlkit.
See crates/data-studio-agent/README.md for installation, architecture, and integration guides.
Apache 2.0. See LICENSE.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y @geek-fun/data-studio-mcpMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-geek-fun-data-studio": {
"command": "npx",
"args": [
"-y",
"@geek-fun/data-studio-mcp"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup reference@geek-fun/data-studio-mcpnpmData Studio works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.