Shop MCP Server
Provides analytics on a SQLite database for an online store, enabling queries on customers, orders, and products, with read-only safe SQL execution.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Shop MCP ServerShow me the top 5 products by revenue"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Shop MCP Server
Local MCP server for analytics of an online store's SQLite database. The AI agent calls an MCP tool, the server converts the request into a safe SQL SELECT, directly reads shop.db, and returns a structured result.
Host-приложение
├── AI-агент / LLM
└── MCP-клиент
│ JSON-RPC / stdio
▼
Shop MCP Server
│ read-only SQLite
▼
data/shop.dbFeatures
direct SQLite connection without HTTP or a separate DB server;
MCP
stdiotransport;query_shopandinspect_databasediscovery viatools/list;eight example tasks in the description and JSON Schema of the tool;
plain text, JSON intent, or a ready-made safe
SELECT;exclusion of
cancelledorders from all analytics;pagination and result limiting;
multi-level read-only protection.
Related MCP server: Read-Only SQLite Shop Database MCP Server
Installation
Requires Python 3.11 or newer.
python3 -m venv .venv
.venv/bin/python -m pip install -e '.[dev]'The prepared database is already located in data/shop.db. It contains 150 customers, the customers.country field is filled in for all customers, and 45 customers belong to Germany.
Re-preparing the database
The source database is not modified. The command creates a new working copy and adds country TEXT NOT NULL with reproducible synthetic values:
.venv/bin/shop-prepare-db /path/to/original/shop.db ./data/shop.dbThe distribution depends only on customers.id, so re-preparation yields the same values. The countries are test data and do not describe the actual location of customers.
Path configuration
The path is determined in the following order:
SHOP_DB_PATH;JSON file from
SHOP_MCP_CONFIGorconfig/shop_mcp.json;data/shop.dbrelative to the working directory.
An example environment variable is in .env.example, and the MCP client configuration is in config/mcp.example.json. Replace /absolute/path/to/MCPDeveloper with the absolute path to the project.
Running
Usually the MCP client starts the server from its own configuration. To run the process manually:
SHOP_DB_PATH=./data/shop.db .venv/bin/python -m shop_mcp.serverstdout is reserved for MCP JSON-RPC. Diagnostics are not output to the protocol stream.
Tools
inspect_database
Arguments:
{"action": "list_tables"}or:
{"action": "describe_table", "table": "customers"}query_shop
Arguments:
{
"request": "Сколько клиентов из Германии?",
"limit": 100,
"offset": 0
}Examples declared via tools/list:
What tables are in the database and what fields do they have?
How many customers are from Germany?
Which country has the most customers?
Which customer spent the most? Return the name, email, and total amount.
Show the top 5 products by quantity sold and revenue.
Show the top 3 categories by revenue.
What was the revenue in 2025?
Which customer placed the most orders?
You can pass a structured intent:
{
"request": "{\"intent\": \"revenue_by_year\", \"year\": 2025}"
}Or a ready-made query:
{
"request": "SELECT name, category FROM products ORDER BY name"
}Business rules
orders.status = 'cancelled'does not participate in metrics.Customer spending and annual revenue are calculated from
orders.total_amount.Product and category revenue is calculated as
quantity * unit_price.The year interval is half-open: from January 1 inclusive to January 1 of the next year exclusive.
In the provided database, all orders belong to 2026, so revenue for 2025 is
0.
Security
The server opens SQLite via mode=ro, enables query_only, sets up a SQLite authorizer, forbids multiple statements, DML, DDL, ATTACH, modifying PRAGMA, extension loading, and limits execution time.
Any attempt to perform an operation other than SELECT returns a precise answer:
Не доступный вариант запросаInternal SQLite errors, stack traces, and local paths are not returned to the client.
Testing
.venv/bin/pytest
.venv/bin/ruff check .
.venv/bin/ruff format --check .The tests include a real MCP server launch as a subprocess, a ClientSession connection via stdio, tools/list, calls to both tools, analytical scenarios, and attempts to modify the database.
The full approved specification is in docs/specification.md.
Available Tools
2 toolsinspect_databaseПросмотр структуры базы интернет-магазинаB
Возвращает список таблиц или поля выбранной таблицы. Используйте action=list_tables либо action=describe_table.
| Name | Required | Description | Default |
|---|---|---|---|
| table | No | Название таблицы для describe_table | |
| action | Yes | Действие: list_tables или describe_table |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries full responsibility for behavioral disclosure. It only states that it returns tables or fields, which is basic. It does not disclose any side effects, permission requirements, error behaviors, or what happens when the table does not exist. For a read-only inspection tool this is relatively benign, but the coverage is minimal.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence that fully conveys the essential information. It is front-loaded with the primary function and immediately outlines the two actions. No redundancy or filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given that an output schema exists, the return format is likely covered elsewhere. The description is sufficient for a simple schema-inspection tool, but it lacks any mention of error handling or the distinction from query_shop. It is adequate but not comprehensive.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema already provides 100% coverage: 'action' is described as 'list_tables or describe_table' and 'table' as 'table name for describe_table'. The description repeats this mapping without adding new information, so it meets the baseline but does not exceed it.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: it returns a list of tables or fields of a selected table. This is a specific verb-resource combination and distinguishes it from the sibling query_shop, which presumably queries data rather than schema. The two modes (list_tables, describe_table) are explicitly mentioned.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides instructions on how to use the tool (choose action) but does not explain when to use this tool versus the sibling query_shop. It offers no context about typical scenarios, prerequisites, or exclusions. The usage guidance is limited to internal action selection, not selection among alternatives.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
query_shopЗапрос к базе интернет-магазинаA
Выполняет аналитический запрос к базе интернет-магазина только для чтения. MCP преобразует запрос в безопасный SQL SELECT. Отменённые заказы не учитываются. Примеры: 1) Какие таблицы есть в базе и какие в них поля? 2) Сколько клиентов из Германии? 3) В какой стране больше всего клиентов? 4) Какой клиент потратил больше всего? Верни имя, email и общую сумму. 5) Покажи топ-5 товаров по проданному количеству и выручке. 6) Покажи топ-3 категории по выручке. 7) Какая выручка была в 2025 году? 8) Какой клиент сделал больше всего заказов?
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Максимальное число строк | |
| offset | No | Смещение для пагинации | |
| request | Yes | Аналитический запрос обычным текстом, JSON intent или SQL SELECT. |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It explicitly states the tool is read-only, that MCP converts queries into safe SQL SELECT, and that canceled orders are excluded from results. This is useful and goes beyond minimal. It does not mention error handling or response format, but the core behavior is well disclosed.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is fairly long because it contains eight examples, but those examples are practical and illustrate valid request formats that are directly relevant to the tool. The purpose statement is front-loaded, and each example adds value, so the length is justified. It is well-structured and not overly verbose.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a natural-language query tool that has an output schema (indicated by the schema signals), the description covers essential context: what the tool does, how it handles queries, and what data is excluded (canceled orders). It could add more about limitations or error behavior, but given the output schema exists and the description is already thorough, it is largely complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100% — every parameter has a clear description. The description itself adds little beyond the schema: it repeats the request examples but does not elaborate on limit or offset semantics, which the schema already covers adequately. The baseline of 3 is appropriate because the schema handles the heavy lifting.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb and resource: 'performs a read-only analytical query to the online store database' and explains the MCP converts queries to safe SQL SELECT. It is specific about being read-only and analytical, which differentiates it from a generic database tool and gives a clear sense of its function, though it does not explicitly name the sibling tool.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is implied through a set of concrete examples that show typical analytical questions (e.g., 'which country has most customers?'). However, the description does not explicitly state when to use this tool versus the sibling 'inspect_database', nor does it provide any exclusions or when-not-to-use guidance. It relies on the reader to infer that this is for read-only analytical queries.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
2 tool updates
v0.1.0- First observed
inspect_database - First observed
query_shop
TDQS
The two tools have clearly distinct purposes: one handles database schema inspection (list tables/describe fields), the other executes analytical queries. There is no overlap in their functional boundaries, making selection unambiguous for an agent.
Both tools follow a consistent verb_noun snake_case pattern ('inspect_database', 'query_shop'), using clear, descriptive verbs. Naming style is uniform and predictable.
With only 2 tools, the server feels minimal for a shop analytics domain. While the query tool is versatile, a more granular set (e.g., get_customers, get_orders) might be expected. The count is borderline, not excessive but thin.
The tool surface fully covers the stated purpose: schema discovery via inspect_database and arbitrary read-only analytical queries via query_shop. There are no obvious gaps for a read-only analytics server, as the query tool can address any data retrieval need.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Explore, query, and inspect SQLite databases with ease. List tables, preview results, and view det…
Safe, read-only Postgres and MySQL access for AI agents. Audit log + column-level controls.
Query 40 databases from Claude, ChatGPT, or Cursor — on any device. Read-only, encrypted, audited.
Commerce intelligence for AI agents. Diagnose drop-offs, fix checkouts, optimize pricing.
Related MCP Servers
- FlicenseAqualityCmaintenanceEnables AI agents to answer analytical questions about an online store's SQLite database through specialized read-only tools, without any risk of modifying the underlying data.8-
- FlicenseAqualityCmaintenanceEnables AI agents to safely inspect and query an SQLite e-commerce database with tools for listing tables, describing schemas, and running read-only SQL queries while blocking destructive operations.4-
- FlicenseAqualityCmaintenanceEnables AI agents to read-only query an online store's SQLite database, listing tables, inspecting schemas, and running SELECT queries over customers, products, orders, and order items.3-
- FlicenseNot gradedqualityCmaintenanceEnables AI agents to read-only analyze a SQLite e-commerce database, exploring schema and running analytical SQL queries over stdio.-
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/k0ry/MCPDeveloper'
If you have feedback or need assistance with the MCP directory API, please join our Discord server