mysql-mcp-server-sse

MCP.Pizza Chef: mangooer

Twelve tools cover listing tables, describing columns, paging through long results, and running a question you phrase in plain words. There is no key to buy — it needs your MySQL address, username and password, and it starts from Docker or Python rather than a one-line install. It is not read-only by default: inserts are permitted, and so are updates or deletes that name specific rows. A genuine safety check does block table drops and unbounded deletes. No code changes since June 2025.

Unmaintained · No commits in 15 months.
Data

Use This MCP server To

Ask how many orders came in last week List my tables and see what each column holds Find every customer record matching a name I give Correct a wrong value in one specific row Page through a long result fifty rows at a time Check which indexes exist on a slow table

README

MySQL查询服务器 / MySQL Query Server


1. 项目简介 / Project Introduction

本项目是基于MCP框架的MySQL查询服务器,支持通过SSE协议进行实时数据库操作,具备完善的安全、日志、配置和敏感信息保护机制,适用于开发、测试和生产环境下的安全MySQL数据访问。

This project is a MySQL query server based on the MCP framework, supporting real-time database operations via SSE protocol. It features comprehensive security, logging, configuration, and sensitive information protection mechanisms, suitable for secure MySQL data access in development, testing, and production environments.


2. 主要特性 / Key Features

  • 基于FastMCP框架,异步高性能

  • 支持高并发的数据库连接池,参数灵活可调

  • 支持SSE实时推送

  • 丰富的MySQL元数据与结构查询API

  • 自动事务管理与回滚

  • 多级SQL风险控制与注入防护

  • 数据库隔离安全:防止跨数据库访问,支持三级访问控制

  • 敏感信息自动隐藏与自定义

  • 灵活的环境变量配置

  • 完善的日志与错误处理

  • Docker支持,快速部署

  • Built on FastMCP framework, high-performance async

  • Connection pool for high concurrency, with flexible parameter tuning

  • SSE real-time push support

  • Rich MySQL metadata & schema query APIs

  • Automatic transaction management & rollback

  • Multi-level SQL risk control & injection protection

  • Database Isolation Security: Prevents cross-database access with 3-level access control

  • Automatic and customizable sensitive info masking

  • Flexible environment variable configuration

  • Robust logging & error handling

  • Docker support for quick deployment


3. 快速开始 / Quick Start

Docker 方式 / Docker Method

mysql-mcp-server-sse FAQ

Do I need a key or a paid account?
Neither. It uses your MySQL server address, username and password — the same credentials any database tool would ask for. Those go into environment settings, not into the conversation.
Can it change or delete my data?
Yes. Out of the box it will add rows, and update or delete rows that name specific records. Only whole-table wipes, table drops and deletes with no row filter are refused.
Is there a read-only mode?
Yes, but you have to switch it on. Setting the environment type to production limits it to reading and structure lookups; the default development setting allows writes.
Is the safety check genuine or just marketing?
Genuine. The guard is actually called before every query runs, and it parses the whole statement with a real SQL parser rather than glancing at the first word — which is better than most database connectors of this kind.
Should I copy the sample settings file as-is?
No. The shipped example file raises the allowed risk level a notch higher than the built-in default, which additionally permits updates that rewrite an entire table and lets the assistant create or alter tables. Start from the safer built-in defaults.
Does it hide passwords stored in my tables?
No. The advertised masking only covers MySQL's own server settings. Ordinary table data, including any password, email or card column, comes back in full.
Can I use this to get a quick sales figure?
Yes. Ask for last month's total and it will compose and run the query, then hand back the number with a note of how many rows it saw.
How hard is setup?
Developer level. You run a Docker container or a Python process, then point your assistant at the web address it listens on. There is no packaged installer and no ready-made config snippet in the README.
Are there security caveats?
Yes. It listens over the network with no login of its own, and the README's Docker example opens it on every network interface. Anyone who can reach that port can query your database, so keep it on your own machine or behind a firewall.
Is it still maintained?
The code has not changed since June 2025. It still runs, but expect no fixes. One documented switch, the query-check toggle, points at code that is never actually run, and the maximum query length really defaults to 1000 characters rather than the 5000 the README lists.