The Best MCP Servers for Databases in 2026

Ten ways to connect Claude, ChatGPT or Cursor to a database, checked against each project's docs, with who each one is wrong for.

Updated 8 October 2026. Prices checked 8 October 2026 against each vendor’s own pricing page.

  1. One local server for Postgres, MySQL, SQL Server, Oracle and SQLite

  2. Developers on self-managed Postgres

  3. Supabase MCPFree with Supabase

    Supabase projects

  4. Neon MCPFree with Neon

    Neon projects, development work

  5. Google BigQuery MCP serverBigQuery query costs

    Teams whose data lives only in BigQuery

  6. Platform teams that want to define exactly which tools an agent gets

  7. ClickHouse Cloud and self-hosted ClickHouse

  8. AWS Labs MCP serversFree, Apache-2.0

    AWS shops that want IAM-based access

  9. Oracle developers already using SQLcl

  10. SaturnSQLFrom €19/user/mo

    Teams querying several engines from Claude or ChatGPT on the web

    Try SaturnSQL free

What a database MCP server does

The Model Context Protocol lets an AI client call tools. A database MCP server gives it a handful: list the tables, read the columns, run a query. Connect one and you can ask Claude "how many accounts churned last month?" and it writes the SQL, runs it against your live database and answers with the real number. The servers below differ on three things that matter more than the tool list: where they run, how they authenticate, and what stops the assistant from changing data.

If your situation isStart with
Supabase or Neon onlyTheir own hosted server
BigQuery onlyGoogle's BigQuery MCP server
ClickHouse Cloud onlyClickHouse Cloud remote MCP
One developer, self-managed PostgresPostgres MCP Pro (restricted mode)
One developer, several enginesBytebase DBHub
Aurora, RDS or Redshift with IAMAWS Labs servers
A team, several engines, Claude or ChatGPT on the webSaturnSQL

One server is missing on purpose: the original reference @modelcontextprotocol/server-postgres. It was archived in 2025, and Datadog Security Labs showed its read-only transaction could be escaped by sending COMMIT; followed by any statement. Plenty of old tutorials still install it.

1. Bytebase DBHub: the best open-source multi-database server

Bytebase DBHub: DBHub is a single MCP server that speaks PostgreSQL, MySQL, MariaDB, SQL Server, Oracle and SQLite. You point it at a DSN or a TOML file listing several databases, and run it with npx or Docker over stdio or HTTP. It is the example the Claude Code docs use for connecting a database, which says something about how well it behaves.

  • Strengths: covers most relational engines in one process, a per-tool readonly setting backed by the engine's own read-only transaction, active and widely used.
  • Weaknesses: it runs on your machine with the credentials in a file, the HTTP mode's bearer token is off by default and is not OAuth, so it does not plug into Claude or ChatGPT on the web.

2. Postgres MCP Pro: the best self-hosted Postgres server

Postgres MCP Pro: Crystal DBA's Postgres MCP Pro is one of the most popular dedicated Postgres servers now that the original reference server is archived. It runs in Docker or Python, over stdio or an SSE endpoint you host, with the connection string in its config.

  • Strengths: a restricted access mode that wraps every query in a read-only transaction with an execution time limit, actively maintained, Postgres-specific rather than lowest common denominator.
  • Weaknesses: Postgres only, one more local process per developer, and the unrestricted mode is full read-write, so the mode you pick matters.

3. Supabase MCP: the best choice if you are on Supabase

Supabase MCP: Supabase hosts its own MCP server at mcp.supabase.com with OAuth sign-in, so there is nothing to install. Adding read_only=true to the URL runs queries as a read-only Postgres user, and project_ref scopes it to a single project.

  • Strengths: hosted with OAuth, works in web clients, Supabase-aware tools beyond SQL.
  • Weaknesses: Supabase only. It is also where the best-known database MCP incident happened: a support ticket containing hidden instructions got an agent to read an integration tokens table, which is why read-only mode and project scoping are worth turning on.

4. Neon MCP: for Neon development branches

Neon MCP: Neon runs a hosted MCP server at mcp.neon.tech with OAuth or an API key, and a readonly flag that limits SQL to reads.

  • Strengths: hosted, OAuth, a read-only flag.
  • Weaknesses: Neon only, and Neon's own README says it does not recommend the server for production environments.

5. Google BigQuery MCP server: the default for BigQuery

Google BigQuery MCP server: Google hosts a BigQuery MCP endpoint at bigquery.googleapis.com/mcp. You authenticate with OAuth and IAM roles, and a separate execute_sql_readonly tool rejects DML, DDL and Python UDFs. Results are capped at 3,000 rows and queries at three minutes.

  • Strengths: first-party, hosted, read-only tool built in, permissions follow your existing IAM.
  • Weaknesses: BigQuery only, and access follows each user's IAM roles, which is right for some teams and a lot of role management for others.

6. MCP Toolbox for Databases: the most configurable

MCP Toolbox for Databases: Google's MCP Toolbox (formerly genai-toolbox) is a binary you configure with sources and tools: BigQuery, Cloud SQL, AlloyDB, Spanner, Postgres, MySQL, SQL Server, Oracle, ClickHouse, Snowflake, Trino and more. Instead of handing an agent a raw SQL tool, you can define named, parameterised queries.

  • Strengths: the widest engine coverage of any server here, fine-grained control over what the agent can call, widely used.
  • Weaknesses: you run and configure it yourself, there is no single read-only switch to rely on, and Redshift is not on the source list.

7. ClickHouse MCP: for ClickHouse

ClickHouse MCP: ClickHouse maintains two options: the open-source mcp-clickhouse server, which runs locally and is read-only unless you switch writes on, and a hosted remote server for ClickHouse Cloud services, where all tools are read-only and sign-in is OAuth or an API key.

  • Strengths: first-party, read-only by default in both forms, a hosted option for Cloud users.
  • Weaknesses: the hosted server only covers ClickHouse Cloud services, so self-hosted clusters are back to a local process.

8. AWS Labs MCP servers: for Aurora, RDS and Redshift

AWS Labs MCP servers: AWS Labs publishes separate MCP servers for Aurora and RDS Postgres, Aurora and RDS MySQL, and Redshift. They run locally and authenticate with AWS profiles, Secrets Manager or IAM, and the Postgres and MySQL ones can go through the RDS Data API.

  • Strengths: IAM instead of passwords, the Redshift server is read-only and single-statement over the Data API.
  • Weaknesses: AWS-hosted databases only, and AWS itself describes the MySQL server's read-only check as a best-effort text filter, not a security boundary.

9. Oracle SQLcl MCP server: for Oracle

Oracle SQLcl MCP server: Oracle built MCP into SQLcl: run sql -mcp (SQLcl 25.2 or later, Java 17) and it serves your saved SQLcl connections to the AI client. Autonomous Database also has a managed MCP server, but it exposes tools you define in PL/SQL rather than general SQL.

  • Strengths: official, uses connections you already have in SQLcl.
  • Weaknesses: local only, and its restrict levels block host commands and scripts but the docs describe no read-only mode for SQL itself, so use a read-only database user.

10. SaturnSQL: hosted, for teams on several databases

SaturnSQL: SaturnSQL is our own product, so weigh this entry accordingly. It is a browser SQL workspace with a hosted MCP server at mcp.saturnsql.com: you sign in with OAuth from Claude, ChatGPT, Cursor or Claude Code, and the assistant can query any connection your team has set up in SaturnSQL, whether PostgreSQL, MySQL, SQL Server, Oracle, BigQuery, ClickHouse or Redshift. Connections start in read-only mode, where each call accepts one SELECT, WITH or EXPLAIN statement, and queries the assistant saves land in the team's shared library, where they can be scheduled to Google Sheets or Slack.

  • Strengths: one hosted endpoint for every engine including self-hosted and private databases (SSH tunnel), database passwords never reach the AI client, works in web and desktop clients alike.
  • Weaknesses: a paid product (the MCP server needs the Starter plan), fewer engines than MCP Toolbox, and read-only mode is a statement check that can be switched off per connection, so pair it with a read-only database user.

Setup guides for SaturnSQL per database: PostgreSQL, MySQL, SQL Server, Oracle, BigQuery, ClickHouse and Redshift. And per client: Claude, ChatGPT, Cursor and Claude Code.

How to connect an LLM to a database safely

  • Use a read-only database user. Every read-only mode above is a second line of defence. Text filters have been bypassed, and AWS calls its own one best effort. A role that can only SELECT the schemas you want exposed is the real boundary. Our read-only user guide has the grants for each engine.
  • Keep credentials out of config files. A connection string in claude_desktop_config.json or a shared .cursor/mcp.json ends up in screenshots, dotfile repos and backups. Hosted servers with OAuth keep the password on the server side.
  • Mind prompt injection. Rows the assistant reads can contain instructions. Do not give the same agent sensitive tables and a tool that can send data somewhere else.
  • Cap the result size. A wide SELECT * can flood the context window and your bill. Prefer servers with row limits.

Frequently asked questions

What is a database MCP server?

An MCP (Model Context Protocol) server is a small service that gives an AI client such as Claude, ChatGPT or Cursor a set of tools it can call. A database MCP server exposes tools like listing tables, reading a schema and running SQL, so the assistant can answer questions from your live data instead of guessing.

Is it safe to connect an LLM to a production database?

It can be, if the server is read-only and the database user it connects with can only read what the assistant needs. Read-only checks that inspect SQL text have been bypassed before, for example the archived reference Postgres server, so a least-privilege database role is the real boundary. Prompt injection is the other risk: data the assistant reads can contain instructions, so do not give one agent both sensitive data and a way to send it elsewhere.

What is the difference between a local and a remote MCP server?

A local server runs as a process on your machine over stdio, with the database credentials in its config, and works with desktop clients such as Claude Desktop, Claude Code and Cursor. A remote server is hosted at an HTTPS URL, usually with OAuth sign-in, and also works in web clients such as Claude.ai and ChatGPT.

Which MCP server should I use for PostgreSQL?

On Supabase or Neon, use their hosted servers. On self-managed Postgres, Postgres MCP Pro in restricted mode or DBHub are the strongest local options. For Aurora or RDS with IAM, the AWS Labs server. If several people or several engines are involved, a hosted multi-database server such as SaturnSQL avoids a local process and a connection string on every laptop.

Is the official Postgres MCP server still maintained?

No. The reference @modelcontextprotocol/server-postgres was archived in 2025, and its read-only transaction could be escaped with a multi-statement query. Use a maintained server instead.

Connect Claude or ChatGPT to every database your team uses