MySQL MCP server
Last verified: 2026-09
Query MySQL or MariaDB.
Community Databases & data Needs a secret Claude Desktop, Cursor, Windsurf, Claude Code, VS Code
What it does
One tool: mysql_query. Read-only by default; writes take an explicit flag. Also exposes mysql://tables as a resource for schema.
It sits in Databases & data: A database MCP is SQL or an API with your credentials.
Good for
- SELECT from a MariaDB/MySQL schema with a read-only user.
- Show tables / describe a table via mysql_query.
- Check whether a migration landed on staging.
- Keep writes behind the package's write flag, off by default.
Tools
- mysql_query — Run SQL. Read-only unless you enable writes.
Config (Claude Desktop / Cursor / Windsurf)
Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets.
Windows paths look like C:\\Users\\you\\project, not /path/to.
Host-side steps →
Claude Desktop
| OS | Config file |
|---|---|
| macOS | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Windows | %APPDATA%\Claude\claude_desktop_config.json
(usually C:\Users\<you>\AppData\Roaming\Claude\) |
| Linux | ~/.config/Claude/claude_desktop_config.json |
Cursor
| Scope | macOS / Linux | Windows |
|---|---|---|
| This project | .cursor/mcp.json in the repo root | |
| This user | ~/.cursor/mcp.json |
%USERPROFILE%\.cursor\mcp.json |
Windsurf
| OS | Config file |
|---|---|
| macOS / Linux | ~/.codeium/windsurf/mcp_config.json |
| Windows | %USERPROFILE%\.codeium\windsurf\mcp_config.json |
{
"mcpServers": {
"mysql": {
"command": "npx",
"args": [
"-y",
"@benborla/mcp-server-mysql"
],
"env": {
"MYSQL_HOST": "127.0.0.1",
"MYSQL_USER": "readonly",
"MYSQL_PASS": "...",
"MYSQL_DB": "app"
}
}
}
}
Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.
One-liner: npx -y @benborla/mcp-server-mysql
Secrets it wants: MYSQL_HOST, MYSQL_USER, MYSQL_PASS, MYSQL_DB
How to get started
- Create a MySQL user that can only SELECT the schemas you care about.
- Set MYSQL_HOST, MYSQL_USER, MYSQL_PASS, MYSQL_DB.
- Ask it to SHOW TABLES, then one SELECT with a LIMIT.
Access risk
A write-enabled flag plus a privileged user can DROP tables. Do not use root.
When to skip it
Skip it if the data is already in Postgres or you only need a local file (SQLite).
Instead: PostgreSQL, SQLite, Supabase.
Vs alternatives
| Server | Official? | Needs a secret? | Best for |
|---|---|---|---|
| MySQL | No | Yes | Query MySQL or MariaDB. |
| PostgreSQL | Yes | Yes | Run SQL against a Postgres database. |
| SQLite | Yes | No | Query a local SQLite file. |
| Supabase | No | Yes | Talk to a Supabase project: tables, auth, edge functions. |
More in Databases & data
FAQ
How many tools?
One: mysql_query. Schema also shows up as a mysql://tables resource.
Root user?
Do not. Create a SELECT-only user. Writes take an explicit flag plus a privileged user — that combination can DROP.
MySQL or Postgres server?
Match the engine you actually run. The official reference server is Postgres.
Password in env?
MYSQL_HOST, MYSQL_USER, MYSQL_PASS, MYSQL_DB. Same secret-on-disk problem as any DB URL.