MySQL MCP Server
MySQL MCP サーバー
MySQLデータベースとの安全なやり取りを可能にするモデルコンテキストプロトコル(MCP)実装。このサーバーコンポーネントは、AIアプリケーション(ホスト/クライアント)とMySQLデータベース間の通信を容易にし、制御されたインターフェースを通じてデータベースの探索と分析をより安全かつ構造化します。
注: MySQL MCP サーバーは、スタンドアロン サーバーとして使用するように設計されているのではなく、AI アプリケーションと MySQL データベース間の通信プロトコル実装として設計されています。
特徴
利用可能な MySQL テーブルをリソースとして一覧表示する
表の内容を読む
適切なエラー処理でSQLクエリを実行する
環境変数による安全なデータベースアクセス
包括的なログ記録
Related MCP server: PostgreSQL MCP Server
インストール
手動インストール
pip install mysql-mcp-serverSmithery経由でインストール
Smithery経由で Claude Desktop 用の MySQL MCP Server を自動的にインストールするには:
npx -y @smithery/cli install mysql-mcp-server --client claude構成
次の環境変数を設定します。
MYSQL_HOST=localhost # Database host
MYSQL_PORT=3306 # Optional: Database port (defaults to 3306 if not specified)
MYSQL_USER=your_username
MYSQL_PASSWORD=your_password
MYSQL_DATABASE=your_database使用法
クロード・デスクトップ
これをclaude_desktop_config.jsonに追加します:
{
"mcpServers": {
"mysql": {
"command": "uv",
"args": [
"--directory",
"path/to/mysql_mcp_server",
"run",
"mysql_mcp_server"
],
"env": {
"MYSQL_HOST": "localhost",
"MYSQL_PORT": "3306",
"MYSQL_USER": "your_username",
"MYSQL_PASSWORD": "your_password",
"MYSQL_DATABASE": "your_database"
}
}
}
}Visual Studio Codeを使用
mcp.jsonに以下を追加します:
{
"servers": {
"mysql": {
"type": "stdio",
"command": "uvx",
"args": [
"--from",
"mysql-mcp-server",
"mysql_mcp_server"
],
"env": {
"MYSQL_HOST": "localhost",
"MYSQL_PORT": "3306",
"MYSQL_USER": "your_username",
"MYSQL_PASSWORD": "your_password",
"MYSQL_DATABASE": "your_database"
}
}
}注: これを動作させるには uv をインストールする必要があります
MCP Inspectorによるデバッグ
MySQL MCP Server はスタンドアロンで実行したり、Python を使用してコマンドラインから直接実行したりすることを目的としていませんが、MCP Inspector を使用してデバッグすることができます。
MCP インスペクターは、MCP 実装をテストおよびデバッグするための便利な方法を提供します。
# Install dependencies
pip install -r requirements.txt
# Use the MCP Inspector for debugging (do not run directly with Python)MySQL MCP サーバーは、Claude Desktop などの AI アプリケーションと統合されるように設計されており、スタンドアロンの Python プログラムとして直接実行しないでください。
発達
# Clone the repository
git clone https://github.com/yourusername/mysql_mcp_server.git
cd mysql_mcp_server
# Create virtual environment
python -m venv venv
source venv/bin/activate # or `venv\Scripts\activate` on Windows
# Install development dependencies
pip install -r requirements-dev.txt
# Run tests
pytestセキュリティに関する考慮事項
環境変数や資格情報をコミットしないでください
必要最小限の権限を持つデータベースユーザーを使用する
本番環境での使用にクエリホワイトリストを実装することを検討する
すべてのデータベース操作を監視して記録する
セキュリティのベストプラクティス
このMCP実装は、データベースアクセスを必要とします。セキュリティのため、
最小限の権限を持つ専用のMySQLユーザーを作成する
ルート認証情報や管理者アカウントは使用しないでください
必要な操作のみにデータベースアクセスを制限する
監査目的でログを有効にする
データベースアクセスの定期的なセキュリティレビュー
詳細な手順については、 MySQL セキュリティ構成ガイドを参照してください。
制限付きMySQLユーザーの作成
適切な権限の設定
データベースアクセスの監視
セキュリティのベストプラクティス
⚠️ 重要: データベース アクセスを構成するときは、常に最小権限の原則に従ってください。
ライセンス
MIT ライセンス - 詳細については LICENSE ファイルを参照してください。
貢献
リポジトリをフォークする
機能ブランチを作成します(
git checkout -b feature/amazing-feature)変更をコミットします (
git commit -m 'Add some amazing feature')ブランチにプッシュする (
git push origin feature/amazing-feature)プルリクエストを開く
Available Tools
3 toolsexecute_sqlADestructive
Execute a SQL statement against the MySQL server. Use for SELECT, DML (INSERT/UPDATE/DELETE), SHOW, DESCRIBE, and ad-hoc queries. Supports cross-database queries using database.table notation. Single statements only — use fully qualified names instead of USE statements.
| Name | Required | Description | Default |
|---|---|---|---|
| query | Yes | The SQL statement to execute. Single statements only. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The annotations already indicate destructiveHint=true, so the destructive nature is clear. The description adds behavioral info: single statements only, cross-database support, and avoidance of USE statements. This adds value beyond the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences long, well-structured, and front-loaded with the core action. Every sentence adds value without redundancy. No fluff.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (SQL execution), the description covers usage guidelines and parameter semantics well. However, it lacks any mention of output format (e.g., rows for SELECT, affected rows for DML) or error handling, which would be helpful since no output schema exists.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the schema already documents the 'query' parameter. The description adds practical guidance like using fully qualified names and avoiding USE statements, which enriches understanding beyond the schema's basic description.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states it executes SQL statements against MySQL server and lists supported statement types (SELECT, DML, SHOW, DESCRIBE, ad-hoc). It distinguishes from USE statements and mentions cross-database queries. However, it doesn't explicitly differentiate from sibling tools like get_schema_info, so a 4 is appropriate.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly states when to use the tool: for SELECT, DML, SHOW, DESCRIBE, and ad-hoc queries. It also provides guidance to use fully qualified names instead of USE statements and to use single statements only. This gives clear context for appropriate usage, though it doesn't mention when not to use it (e.g., for metadata queries).
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_schema_infoARead-only
Get column metadata for a table or all tables in the configured database: column names, data types, nullability, default values, and comments. Call this before querying an unfamiliar table. Omit table_name to see all tables at once. Accepts bare table names (uses MYSQL_DATABASE) or database.table for cross-database lookups.
| Name | Required | Description | Default |
|---|---|---|---|
| table_name | No | Optional: bare table name, or database.table for a cross-database lookup. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true and destructiveHint=false, so the safety profile is covered. The description adds that it returns specific metadata and uses MYSQL_DATABASE, which is useful but not extensive.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three sentences: first states purpose, second gives usage advice, third explains parameter usage. Front-loaded and no superfluous wording.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a read-only metadata tool with one optional parameter, the description covers what it returns and how to use it. Output schema is absent, but the description lists the metadata fields, which is sufficient.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% with a description for the parameter. The description adds valuable context: omitting table_name returns all tables, and bare names use MYSQL_DATABASE. This goes beyond the schema description.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: 'Get column metadata for a table or all tables in the configured database' with a specific list of metadata included (column names, data types, etc.). It distinguishes from siblings by implying it's for schema exploration before querying.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly advises 'Call this before querying an unfamiliar table' and explains optional usage with 'Omit table_name to see all tables at once.' Lacks direct comparison with sibling tools but provides clear context for when to use.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_table_sampleARead-only
Fetch a small sample of rows from a table to understand its data format and content. Use alongside get_schema_info before writing complex queries. Accepts bare table names (uses MYSQL_DATABASE) or database.table for cross-database lookups.
| Name | Required | Description | Default |
|---|---|---|---|
| table_name | Yes | Table to sample. Use database.table notation for cross-database queries. | |
| limit | No | Number of rows to return (default 5, max 20). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already mark the tool as readOnlyHint=true and destructiveHint=false. The description adds transparency by specifying 'small sample' and the default/max limit behavior, which is valuable beyond annotations. No contradictions detected.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences, no redundant words. The first sentence front-loads the core purpose; the second adds usage and naming tips. Every sentence earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple tool with two parameters and no output schema, the description covers the essential aspects: what it does, how to use it, and naming conventions. It is complete enough for an AI agent to select and invoke correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100% (both parameters described). The description adds value by explaining that table_name can be bare (using MYSQL_DATABASE) or in database.table format, which goes beyond the schema's description. For limit, the schema already states default and max, so no further addition needed.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action ('Fetch a small sample'), the resource ('from a table'), and the purpose ('to understand its data format and content'). It distinguishes itself from sibling tools by mentioning alongside get_schema_info and before writing complex queries, implying this tool is for exploration, not execution or schema understanding.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly advises using the tool alongside get_schema_info before writing complex queries, providing clear context for when to use it. It also explains naming conventions (bare table vs database.table). However, it lacks explicit guidance on when not to use it or comparison to execute_sql for arbitrary queries.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
3 tool updates
v0.4.1- Changed
execute_sql1 field changed- changed
Input schema / properties / query / descriptionPrevious value: -"The SQL query to execute"New value: +"The SQL statement to execute. Single statements only."
- Added
get_schema_info - Added
get_table_sample
1 tool update
v1.0.0- First observed
execute_sql
TDQS
Each tool has a distinct and clear purpose: executing SQL, retrieving schema metadata, and fetching sample data. No overlap in functionality.
All tool names follow a consistent verb_noun pattern in snake_case (execute_sql, get_schema_info, get_table_sample), making them predictable.
Three tools is appropriate for the server's scope—covering query execution, schema inspection, and data sampling. Not too few or excessive.
Covers core database interaction needs (query, schema, sample). Minor gaps like database listing or DDL support exist but are acceptable for the stated purpose.
Maintenance
Related MCP Connectors
Safe, read-only Postgres and MySQL access for AI agents. Audit log + column-level controls.
Query 40 databases from Claude, ChatGPT, or Cursor — on any device. Read-only, encrypted, audited.
Explore, query, and inspect SQLite databases with ease. List tables, preview results, and view det…
- OleanderOAuthdev.oleander
The all-in-one data stack for agents. Upload files, run SQL, evolve tables, and render charts.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceEnables secure interaction with MySQL databases, allowing AI assistants to list tables, read data, and execute SQL queries through a controlled interface.-
- AlicenseNot gradedqualityNot gradedmaintenanceProvides AI assistants with safe, controlled access to PostgreSQL databases with read-only defaults, granular permissions, query safety features, and schema introspection capabilities.1-
- FlicenseNot gradedqualityCmaintenanceEnables read-only SQL database access for AI assistants, allowing schema exploration and safe query execution without risk of data modification.-
- AlicenseNot gradedqualityBmaintenanceEnables AI assistants to safely query and explore SQL Server and PostgreSQL databases with read-only access, supporting schema discovery, relationship exploration, and query execution.373MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/designcomputer/mysql_mcp_server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server