mcp-tools-sql
Status: Under active development — not yet functional.
An MCP server for safe, configurable SQL database access. Exposes schema introspection, user-defined SELECT queries, and structured UPDATE operations as MCP tools for LLM-assisted workflows.
Key Ideas
- Configurable, not ad-hoc: Every query the LLM can run is defined upfront in config. The config is the security boundary.
- Schema discovery: Built-in tools to explore schemas, tables, columns, and foreign key relations.
- Structured updates: UPDATE operations are defined as table + key + fields, not raw SQL. The server generates the SQL.
- Split config: Query definitions live in the project repo (safe to commit). Credentials live in the user's home directory (never committed).
- Multi-backend: MS SQL Server (primary), PostgreSQL, SQLite.
Architecture
MCP Client (Claude Code, etc.)
↕ STDIO/MCP
mcp-tools-sql server
├── Built-in tools (schema introspection)
├── Configured query tools (from mcp-tools-sql.toml)
├── Configured update tools (from mcp-tools-sql.toml)
└── Backend abstraction
├── SQLite (stdlib)
├── MS SQL Server (pyodbc)
└── PostgreSQL (psycopg)
See docs/architecture/architecture.md for details.
Installation
pip install mcp-tools-sql # core + SQLite
pip install mcp-tools-sql[mssql] # + SQL Server support
pip install mcp-tools-sql[postgresql] # + PostgreSQL support
Quick Start
# Generate starter project query config (mcp-tools-sql.toml) and a
# database config skeleton at ~/.mcp-tools-sql/config.toml
mcp-tools-sql init --backend sqlite
# Edit ~/.mcp-tools-sql/config.toml and set the SQLite path, e.g.:
# [connections.default]
# backend = "sqlite"
# path = "./mydb.db"
# Validate environment, configs, dependencies, and connectivity
mcp-tools-sql verify
# Start MCP server
mcp-tools-sql --config mcp-tools-sql.toml
See docs/cli.md for the full CLI reference (all flags, example output, exit codes).
Configuration
Two config files:
| File | Purpose | Location |
|---|---|---|
mcp-tools-sql.toml |
Query/update definitions | Project dir (committed) |
~/.mcp-tools-sql/config.toml |
Database connections + credentials | User home (never committed) |
The --config flag overrides the project query config path; the
--database-config flag overrides the database config path.
See the planning document for full details.
License
MIT
Metadata
Release files for mcp-tools-sql 0.1.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| mcp_tools_sql-0.1.2.tar.gz | 159.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| mcp_tools_sql-0.1.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 222.3 kB
Release files / mcp_tools_sql-0.1.2.tar.gz
| Download URL | mcp_tools_sql-0.1.2.tar.gz |
|---|---|
| Size | 159.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
c9b346ad80a3f514c24f1cf6333bdf05024ecb2c49d61cd190a89204b2f3e0fd
|
|
BLAKE2b-256 checksum How to use checksums |
9f3d7bcf51fa9059ddfbbfeeacd0d6dd6d00d07bb80e75827fceec364fe4703d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 25, 2026.
Transparency logRelease files / mcp_tools_sql-0.1.2-py3-none-any.whl
| Download URL | mcp_tools_sql-0.1.2-py3-none-any.whl |
|---|---|
| Size | 62.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
cf3498b96ebf36a23a89787a5dad8843ebc39b748432737c161f0fdcfa3455ba
|
|
BLAKE2b-256 checksum How to use checksums |
5e1f48e793be4f04e3a24c28677e83288837a21074916bae917cac3456d66452
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 25, 2026.
Transparency log