Suggest a server AI tools directory →

MCP servers for databases and data

Last verified: 2026-09

A database MCP is SQL or an API with your credentials. There is no extra permission layer in the protocol. If the role can DROP TABLE, the model can too. The first install should be a read-only user on a copy or a dev instance — not the production owner URL from your password manager.

What to look for

  • Create a read-only role before you paste a URL into mcp.json.
  • SQLite: give the model a copy of the file. Postgres/MySQL: GRANT SELECT only.
  • Warehouse servers (Snowflake, BigQuery) cost money per query. Cap the warehouse size.

Side-by-side

ServerOfficial?Needs a secret?Best for
PostgreSQLYesYesRun SQL against a Postgres database.
SQLiteYesNoQuery a local SQLite file.
RedisYesYesGet and set keys in Redis.
MongoDBNoYesQuery MongoDB collections.
MySQLNoYesQuery MySQL or MariaDB.
ElasticsearchNoYesSearch an Elasticsearch cluster.
SnowflakeNoYesRun SQL on Snowflake.
BigQueryNoYesQuery Google BigQuery datasets.
NeonNoYesManage and query Neon Postgres.
SupabaseNoYesTalk to a Supabase project: tables, auth, edge functions.
AirtableNoYesRead and write Airtable bases.

All 11 servers

FAQ

Is Postgres safer than SQLite?

No. Safety is the role, not the engine. A read-only Postgres user is safer than a writable SQLite file.

Should I connect production?

Not to a general-purpose chat. Use a replica or a redacted dump.

Neon or Supabase vs raw Postgres?

Use the vendor server if you also need branches and project admin. Use Postgres if you only need SQL.