Suggest a server AI tools directory →

MySQL MCP server

Last verified: 2026-09

Query MySQL or MariaDB.

Community Databases & data Needs a secret Claude Desktop, Cursor, Windsurf, Claude Code, VS Code

What it does

One tool: mysql_query. Read-only by default; writes take an explicit flag. Also exposes mysql://tables as a resource for schema.

It sits in Databases & data: A database MCP is SQL or an API with your credentials.

Good for

  • SELECT from a MariaDB/MySQL schema with a read-only user.
  • Show tables / describe a table via mysql_query.
  • Check whether a migration landed on staging.
  • Keep writes behind the package's write flag, off by default.

Tools

  • mysql_query — Run SQL. Read-only unless you enable writes.

Config (Claude Desktop / Cursor / Windsurf)

Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets. Windows paths look like C:\\Users\\you\\project, not /path/to. Host-side steps →

Claude Desktop

OSConfig file
macOS~/Library/Application Support/Claude/claude_desktop_config.json
Windows%APPDATA%\Claude\claude_desktop_config.json (usually C:\Users\<you>\AppData\Roaming\Claude\)
Linux~/.config/Claude/claude_desktop_config.json

Cursor

ScopemacOS / LinuxWindows
This project.cursor/mcp.json in the repo root
This user~/.cursor/mcp.json %USERPROFILE%\.cursor\mcp.json

Windsurf

OSConfig file
macOS / Linux~/.codeium/windsurf/mcp_config.json
Windows%USERPROFILE%\.codeium\windsurf\mcp_config.json
{
  "mcpServers": {
    "mysql": {
      "command": "npx",
      "args": [
        "-y",
        "@benborla/mcp-server-mysql"
      ],
      "env": {
        "MYSQL_HOST": "127.0.0.1",
        "MYSQL_USER": "readonly",
        "MYSQL_PASS": "...",
        "MYSQL_DB": "app"
      }
    }
  }
}

Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.

One-liner: npx -y @benborla/mcp-server-mysql

Secrets it wants: MYSQL_HOST, MYSQL_USER, MYSQL_PASS, MYSQL_DB

Source repo →

How to get started

  1. Create a MySQL user that can only SELECT the schemas you care about.
  2. Set MYSQL_HOST, MYSQL_USER, MYSQL_PASS, MYSQL_DB.
  3. Ask it to SHOW TABLES, then one SELECT with a LIMIT.

Access risk

A write-enabled flag plus a privileged user can DROP tables. Do not use root.

When to skip it

Skip it if the data is already in Postgres or you only need a local file (SQLite).

Instead: PostgreSQL, SQLite, Supabase.

Vs alternatives

ServerOfficial?Needs a secret?Best for
MySQLNoYesQuery MySQL or MariaDB.
PostgreSQLYesYesRun SQL against a Postgres database.
SQLiteYesNoQuery a local SQLite file.
SupabaseNoYesTalk to a Supabase project: tables, auth, edge functions.

More in Databases & data

All 11 in this category →

FAQ

How many tools?

One: mysql_query. Schema also shows up as a mysql://tables resource.

Root user?

Do not. Create a SELECT-only user. Writes take an explicit flag plus a privileged user — that combination can DROP.

MySQL or Postgres server?

Match the engine you actually run. The official reference server is Postgres.

Password in env?

MYSQL_HOST, MYSQL_USER, MYSQL_PASS, MYSQL_DB. Same secret-on-disk problem as any DB URL.