SQLite MCP Server
A Model Context Protocol (MCP) server that enables AI clients to interact with a SQLite database (in-memory or file-based) via a full suite of SQL tools and resources.
Data Querying
read_query— Execute read-only SQL (SELECT,WITH/CTEs,EXPLAIN) to fetch and inspect data
Data Modification
write_query— RunINSERT,UPDATE,DELETE, orREPLACEstatements; returns affected row count
Table Management
create_table— Create new tables with fullCREATE TABLESQLdrop_table— Permanently drop a table (irreversible)list_tables— List all user-created tablesdescribe_table— Inspect a table's columns, types, constraints, indexes, and foreign keys
Knowledge & Insights
append_insight— Record business insights or analytical observations into a persistent memo resource (memo://insights)
Resources & Prompts
Access the full database schema via the
sqlite://{db}/schemaresourceUse the built-in
mcp-demoprompt for a guided walkthrough of creating tables, inserting data, and querying
Transport & Deployment
Connect via stdio (for Claude Desktop, Cursor, etc.) or Streamable HTTP (for remote clients)
Deploy with Docker for containerized access
Secure HTTP with bearer-token authentication (
MCP_AUTH_TOKEN), configurable host/port, and DNS-rebinding protectionBuilt-in query validation and injection prevention
Supports containerized deployment of the SQLite MCP server for easier distribution and deployment
Provides SSE connection capabilities for n8n workflows, allowing n8n to interact with the SQLite database through the MCP client node
Supports deployment on Railway platform through Nixpacks building process
Supports deployment on Render platform through Nixpacks building process
Provides SQLite database operations including executing SQL queries, managing tables, and tracking business insights through standardized MCP tools
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@SQLite MCP Servershow me the last 10 orders from the customers table"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
SQLite MCP Server
A Model Context Protocol (MCP) server that provides SQLite database operations. Supports both stdio (for Claude Desktop, Cursor, etc.) and Streamable HTTP (for remote clients) transports.
Features
In-memory or file-based SQLite database
Dual transport: stdio and Streamable HTTP
SQL operations with input validation and injection protection
Table management (CREATE, DROP, LIST, DESCRIBE)
Database schema exposed as an MCP resource
Business insights memo tracking
Docker support
Related MCP server: SQLite MCP Server
Quick Start
Stdio (Claude Desktop, Cursor, etc.)
npm install && npm run build
node build/index.jsAdd to your Claude Desktop config (claude_desktop_config.json):
{
"mcpServers": {
"sqlite": {
"command": "node",
"args": ["/path/to/sqlite-mcp-server/build/index.js"]
}
}
}With a file-based database:
{
"mcpServers": {
"sqlite": {
"command": "node",
"args": ["/path/to/sqlite-mcp-server/build/index.js", "/path/to/database.db"]
}
}
}Streamable HTTP (remote clients)
node build/index.js --httpThe server exposes a single endpoint at http://localhost:3000/mcp following the MCP Streamable HTTP specification. By default it binds to 127.0.0.1. To reach it from another host or a container, set HOST=0.0.0.0 — but read the Security section first: the HTTP transport has no authentication.
Docker
docker build -t sqlite-mcp-server .
docker run -d -p 3000:3000 -e HOST=0.0.0.0 --name sqlite-mcp sqlite-mcp-serverHOST=0.0.0.0 is required so the server is reachable through the published port. Connecting from the host via localhost:3000 works out of the box; to reach it under any other hostname, add that host to MCP_ALLOWED_HOSTS.
Configuration
Option | Description | Default |
| Use Streamable HTTP transport instead of stdio | stdio |
First non-flag argument | Path to SQLite database file |
|
| Database path (env var alternative) |
|
| HTTP server port (HTTP mode only) |
|
| Interface to bind in HTTP mode. Use |
|
| Comma-separated |
|
| Bearer token required on all | (none) |
Examples:
# In-memory database on stdio
node build/index.js
# File-based database on stdio
node build/index.js ./data.db
# HTTP mode with custom port
PORT=8080 node build/index.js --http ./data.db
# Using environment variable
SQLITE_DB_PATH=./data.db node build/index.js --httpAvailable Tools
Tool | Description |
| Execute SELECT, WITH (CTE), or EXPLAIN queries |
| Execute INSERT, UPDATE, DELETE, or REPLACE queries |
| Create a new table with a CREATE TABLE statement |
| Drop a table (irreversible) |
| List all user-created tables |
| Get table schema: columns, indexes, and foreign keys |
| Add a business insight to the memo resource |
Resources
URI | Description |
| Full schema (CREATE statements) for all tables |
| Accumulated business insights from analysis |
Prompts
Name | Description |
| Guided walkthrough: creates tables, inserts sample data, runs queries for a given topic |
Remote Connection
Streamable HTTP
Connect any MCP-compatible client to http://your-host:3000/mcp. The server supports:
POST /mcp— send MCP messages (session created on initialize)GET /mcp— SSE stream for session resumabilityDELETE /mcp— terminate a sessionGET /health— health check endpoint
Sessions are managed via the Mcp-Session-Id header.
Authentication
Set MCP_AUTH_TOKEN to require a bearer token on every /mcp request (/health stays open):
MCP_AUTH_TOKEN=$(openssl rand -hex 32) HOST=0.0.0.0 node build/index.js --httpClients then send Authorization: Bearer <token>. When MCP_AUTH_TOKEN is unset, authentication is disabled — fine for a localhost-only bind, but do not expose the server publicly without it.
Security
Query validation: each tool only accepts its intended SQL statement type
Multi-statement injection blocked: stacked statements are rejected, with string literals and comments stripped before the check
Table names validated against
^[a-zA-Z_][a-zA-Z0-9_]*$Foreign keys enabled by default
HTTP transport binds to
127.0.0.1by default, with DNS-rebinding protection (MCP_ALLOWED_HOSTS)Optional bearer-token auth on the HTTP transport via
MCP_AUTH_TOKEN(timing-safe check)
Set MCP_AUTH_TOKEN before exposing the HTTP transport beyond localhost. For production, also front it with a reverse proxy that terminates TLS. See SECURITY.md for the full model and how to report a vulnerability.
Development
npm install
npm run build
npm test # build + run the validator test suite
npm start # stdio mode
npm run start:http # HTTP modeLicense
Available Tools
1 toolcreate_tableB
Create a new table in the database with a full CREATE TABLE SQL statement.
| Name | Required | Description | Default |
|---|---|---|---|
| query | Yes | CREATE TABLE SQL statement |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden of behavioral disclosure. It fails to mention side effects (e.g., if table exists), permission requirements, or that it modifies state, which is critical for a write operation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single efficient sentence with no wasted words, though minor expansion for behavioral details would improve it without harming conciseness.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple one-parameter tool with no output schema, the description covers the essential purpose but lacks details on error handling, permission requirements, or SQL dialect support.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema already describes the 'query' parameter fully. The description adds the word 'full', implying a complete statement, but no additional meaning beyond the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb 'create', the resource 'table', and specifies it uses a full CREATE TABLE SQL statement, effectively distinguishing it from sibling tools like drop_table or list_tables.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies use for creating a table but provides no explicit guidance on when to use this tool versus alternatives like write_query, nor when not to use it.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
6 tool updates
v1.1.0- Removed
append_insight - Removed
describe_table - Removed
drop_table - Removed
list_tables - Removed
read_query - Removed
write_query
7 tool updates
- Added
append_insight - Added
create_table - Added
describe_table - Added
drop_table - Added
list_tables - Added
read_query - Added
write_query
TDQS
With only one tool, there is no possibility of confusion between tools. The single tool's purpose is clearly distinct by default.
With a single tool, naming consistency is trivially maintained. The name 'create_table' follows a clear verb_noun pattern.
A single tool for a SQLite server is far too few for the apparent scope. Typical database operations are missing, making the tool set feel extremely thin.
The server only supports table creation, lacking essential operations like querying, inserting, updating, deleting, or dropping tables. This represents significant gaps for any database interaction.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
A Model Context Protocol (MCP) server for Selise Blocks Cloud integration
A comprehensive Model Context Protocol (MCP) server that enables AI assistants to interact with yo…
Model Context Protocol server for Studex tools, notifications, and profile integrations
A Model Context Protocol server for Wix AI tools
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceA Model Context Protocol server that provides tools for connecting to and interacting with various database systems (SQLite, PostgreSQL, MySQL/MariaDB, SQL Server) through a unified interface.3-
- AlicenseNot gradedqualityDmaintenanceA Model Context Protocol server implementation that enables AI assistants to execute SQL queries and interact with SQLite databases through a structured interface.7MIT
- AlicenseAqualityDmaintenanceA Model Context Protocol server that allows users to store, retrieve, update, and delete memories using SQLite storage.510MIT
- AlicenseBqualityDmaintenanceA Model Context Protocol server that enables AI assistants to interact with SQLite databases by connecting to database files, listing tables, describing schemas, and executing queries.61882MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/etugrand/sqlite-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server