Skip to main content
Glama
etugrand

SQLite MCP Server

by etugrand

SQLite MCP Server

CI License: ISC

A Model Context Protocol (MCP) server that provides SQLite database operations. Supports both stdio (for Claude Desktop, Cursor, etc.) and Streamable HTTP (for remote clients) transports.

Features

  • In-memory or file-based SQLite database

  • Dual transport: stdio and Streamable HTTP

  • SQL operations with input validation and injection protection

  • Table management (CREATE, DROP, LIST, DESCRIBE)

  • Database schema exposed as an MCP resource

  • Business insights memo tracking

  • Docker support

Related MCP server: SQLite MCP Server

Quick Start

Stdio (Claude Desktop, Cursor, etc.)

npm install && npm run build
node build/index.js

Add to your Claude Desktop config (claude_desktop_config.json):

{
  "mcpServers": {
    "sqlite": {
      "command": "node",
      "args": ["/path/to/sqlite-mcp-server/build/index.js"]
    }
  }
}

With a file-based database:

{
  "mcpServers": {
    "sqlite": {
      "command": "node",
      "args": ["/path/to/sqlite-mcp-server/build/index.js", "/path/to/database.db"]
    }
  }
}

Streamable HTTP (remote clients)

node build/index.js --http

The server exposes a single endpoint at http://localhost:3000/mcp following the MCP Streamable HTTP specification. By default it binds to 127.0.0.1. To reach it from another host or a container, set HOST=0.0.0.0 — but read the Security section first: the HTTP transport has no authentication.

Docker

docker build -t sqlite-mcp-server .
docker run -d -p 3000:3000 -e HOST=0.0.0.0 --name sqlite-mcp sqlite-mcp-server

HOST=0.0.0.0 is required so the server is reachable through the published port. Connecting from the host via localhost:3000 works out of the box; to reach it under any other hostname, add that host to MCP_ALLOWED_HOSTS.

Configuration

Option

Description

Default

--http

Use Streamable HTTP transport instead of stdio

stdio

First non-flag argument

Path to SQLite database file

:memory:

SQLITE_DB_PATH

Database path (env var alternative)

:memory:

PORT

HTTP server port (HTTP mode only)

3000

HOST

Interface to bind in HTTP mode. Use 0.0.0.0 to expose beyond localhost

127.0.0.1

MCP_ALLOWED_HOSTS

Comma-separated Host header allow-list for DNS-rebinding protection

localhost:$PORT,127.0.0.1:$PORT

MCP_AUTH_TOKEN

Bearer token required on all /mcp requests (HTTP mode). Unset = auth disabled

(none)

Examples:

# In-memory database on stdio
node build/index.js

# File-based database on stdio
node build/index.js ./data.db

# HTTP mode with custom port
PORT=8080 node build/index.js --http ./data.db

# Using environment variable
SQLITE_DB_PATH=./data.db node build/index.js --http

Available Tools

Tool

Description

read_query

Execute SELECT, WITH (CTE), or EXPLAIN queries

write_query

Execute INSERT, UPDATE, DELETE, or REPLACE queries

create_table

Create a new table with a CREATE TABLE statement

drop_table

Drop a table (irreversible)

list_tables

List all user-created tables

describe_table

Get table schema: columns, indexes, and foreign keys

append_insight

Add a business insight to the memo resource

Resources

URI

Description

sqlite://{db}/schema

Full schema (CREATE statements) for all tables

memo://insights

Accumulated business insights from analysis

Prompts

Name

Description

mcp-demo

Guided walkthrough: creates tables, inserts sample data, runs queries for a given topic

Remote Connection

Streamable HTTP

Connect any MCP-compatible client to http://your-host:3000/mcp. The server supports:

  • POST /mcp — send MCP messages (session created on initialize)

  • GET /mcp — SSE stream for session resumability

  • DELETE /mcp — terminate a session

  • GET /health — health check endpoint

Sessions are managed via the Mcp-Session-Id header.

Authentication

Set MCP_AUTH_TOKEN to require a bearer token on every /mcp request (/health stays open):

MCP_AUTH_TOKEN=$(openssl rand -hex 32) HOST=0.0.0.0 node build/index.js --http

Clients then send Authorization: Bearer <token>. When MCP_AUTH_TOKEN is unset, authentication is disabled — fine for a localhost-only bind, but do not expose the server publicly without it.

Security

  • Query validation: each tool only accepts its intended SQL statement type

  • Multi-statement injection blocked: stacked statements are rejected, with string literals and comments stripped before the check

  • Table names validated against ^[a-zA-Z_][a-zA-Z0-9_]*$

  • Foreign keys enabled by default

  • HTTP transport binds to 127.0.0.1 by default, with DNS-rebinding protection (MCP_ALLOWED_HOSTS)

  • Optional bearer-token auth on the HTTP transport via MCP_AUTH_TOKEN (timing-safe check)

Set MCP_AUTH_TOKEN before exposing the HTTP transport beyond localhost. For production, also front it with a reverse proxy that terminates TLS. See SECURITY.md for the full model and how to report a vulnerability.

Development

npm install
npm run build
npm test           # build + run the validator test suite
npm start          # stdio mode
npm run start:http # HTTP mode

License

ISC

Available Tools

1 tool
create_tableB

Create a new table in the database with a full CREATE TABLE SQL statement.

ParametersJSON Schema
NameRequiredDescriptionDefault
queryYesCREATE TABLE SQL statement

TDQS

B3.4/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden of behavioral disclosure. It fails to mention side effects (e.g., if table exists), permission requirements, or that it modifies state, which is critical for a write operation.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single efficient sentence with no wasted words, though minor expansion for behavioral details would improve it without harming conciseness.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a simple one-parameter tool with no output schema, the description covers the essential purpose but lacks details on error handling, permission requirements, or SQL dialect support.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema already describes the 'query' parameter fully. The description adds the word 'full', implying a complete statement, but no additional meaning beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the verb 'create', the resource 'table', and specifies it uses a full CREATE TABLE SQL statement, effectively distinguishing it from sibling tools like drop_table or list_tables.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies use for creating a table but provides no explicit guidance on when to use this tool versus alternatives like write_query, nor when not to use it.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 6 tool updatesv1.1.0
    • Removedappend_insight
    • Removeddescribe_table
    • Removeddrop_table
    • Removedlist_tables
    • Removedread_query
    • Removedwrite_query
  2. 7 tool updates
    • Addedappend_insight
    • Addedcreate_table
    • Addeddescribe_table
    • Addeddrop_table
    • Addedlist_tables
    • Addedread_query
    • Addedwrite_query

TDQS

B3.4/5.0
Disambiguation5/5

With only one tool, there is no possibility of confusion between tools. The single tool's purpose is clearly distinct by default.

Naming Consistency5/5

With a single tool, naming consistency is trivially maintained. The name 'create_table' follows a clear verb_noun pattern.

Tool Count2/5

A single tool for a SQLite server is far too few for the apparent scope. Typical database operations are missing, making the tool set feel extremely thin.

Completeness2/5

The server only supports table creation, lacking essential operations like querying, inserting, updating, deleting, or dropping tables. This represents significant gaps for any database interaction.

Maintenance

ActivitySlowing
ResponsivenessSyncing

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • F
    license
    Not graded
    quality
    D
    maintenance
    A Model Context Protocol server that provides tools for connecting to and interacting with various database systems (SQLite, PostgreSQL, MySQL/MariaDB, SQL Server) through a unified interface.
    3
    -
  • A
    license
    Not graded
    quality
    D
    maintenance
    A Model Context Protocol server implementation that enables AI assistants to execute SQL queries and interact with SQLite databases through a structured interface.
    7
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    A Model Context Protocol server that allows users to store, retrieve, update, and delete memories using SQLite storage.
    5
    10
    MIT
  • A
    license
    B
    quality
    D
    maintenance
    A Model Context Protocol server that enables AI assistants to interact with SQLite databases by connecting to database files, listing tables, describing schemas, and executing queries.
    6
    188
    2
    MIT

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/etugrand/sqlite-mcp-server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server