mcp-trino

MCP.Pizza Chef: tuannvm

Six tools let you list the connected data systems, drill down through their folders to a table, see its columns, check how a question would be answered before running it, and then run it. Anything that is not a read or a description is refused unless you deliberately switch writing on, and that block really is enforced in the code. Two defaults deserve a look before you point it at anything real: your Trino server's certificate is not checked, and the optional web mode listens on every network connection with sign-in switched off.

Data

Use This MCP server To

See which data systems my company has connected List the tables available in one area of the warehouse Check what columns a table has before I ask about it Count last month's orders across two different systems Preview how heavy a question is before running it

README

Trino MCP Server in Go

A high-performance Model Context Protocol (MCP) server for Trino implemented in Go. This project enables AI assistants to seamlessly interact with Trino's distributed SQL query engine through standardized MCP tools.

GitHub Workflow Status Go Version Trivy Scan SLSA 3 Go Report Card Go Reference Docker Image GitHub Release License: MIT

Trust Score

Overview

This project implements a Model Context Protocol (MCP) server for Trino in Go. It enables AI assistants to access Trino's distributed SQL query engine through standardized MCP tools.

Trino (formerly PrestoSQL) is a powerful distributed SQL query engine designed for fast analytics on large datasets.

mcp-trino FAQ

Do I need an API key?
No key. You need the address of a Trino cluster and a username, plus a password if yours asks for one. Those are ordinary sign-in details kept as settings on your own machine, not a key you sign up for.
Can it change or delete my company's data?
Not out of the box. Only reading and describing are permitted, and the check runs immediately before every question is sent, so it is real protection rather than a line in the documentation. Allowing writes is a deliberate setting, and once it is on, deletes and drops become possible.
Is anything in the defaults worth worrying about?
Two things. Your Trino server's certificate is not verified unless you change a setting, so the connection can be intercepted. And the optional web mode listens on every network connection your machine has, with sign-in off by default, meaning anyone who can reach that port could query your data as you. Stick to the plain local setup unless you have turned sign-in on.
Can I limit what it is allowed to see?
Yes. Settings let you restrict which systems, which areas and which tables appear at all, and the filter is applied whenever it lists or browses.
Which apps does it work in?
Claude Desktop, Claude Code, Cursor, Windsurf and ChatWise are all named, and any app that runs a local command will do. There is also a Docker image and a Kubernetes package.
How hard is setup?
One install command through Homebrew or a script, then a short settings block naming your Trino server and username. No building from source required.
Can I use this to answer a business question in plain English?
Yes, that is the point. Ask for last quarter's totals by region and it will find the right tables, write the query for you, and hand back the numbers.
Is it still maintained?
Yes. It was updated in July 2026, ships signed releases with security scanning in its build, and carries roughly two dozen open reports, which is normal for a project this active.
Can I use this at work?
Yes. It uses the MIT licence, the permissive kind with no obligation to publish anything you build on it.