What a self-hosted database MCP server is
A database MCP server is a small program that speaks the Model Context Protocol: it shows an AI agent your tables and runs the SQL
the agent writes. A self-hosted one is open source and runs wherever you start it, usually on your laptop, with a connection string
as its main setting. The archived PostgreSQL reference server, for example, started with
npx -y @modelcontextprotocol/server-postgres and ran every query in a READ ONLY transaction. DBHub, an
MIT-licensed server from Bytebase, covers six engines, can hold several connections in one file, and offers a read-only mode, row
limits and timeouts.
For one developer on a local or development database, that is hard to beat: free, quick to start, code you can read, and nothing passing through a third party.
What changes when a whole team uses it
- Credentials spread. A local server needs the connection string on every machine that runs it.
- Read-only depends on the setup. Some servers use a read-only transaction or flag, some don’t. The database login you hand over is the real limit, so it must be a read-only one.
- No shared record. Nobody can see, in one place, who asked which question and what SQL ran.
- Access is all or nothing. Removing one person usually means changing a password everyone shares.
- The web apps need a public server. Anthropic’s help centre says Claude connects to custom connectors from Anthropic’s cloud, not your device. Hosting the server, adding sign-in and patching it become your job.
How Datablare handles the same jobs
Each Datablare project gets one remote MCP link for Claude, ChatGPT, Cursor, VS Code and Claude Code. People sign in with OAuth as themselves, so every query in the audit log carries a name, and one person’s access can be revoked without touching anyone else’s. Read-only is enforced twice, by the SQL guard and by the database. You choose tables and hide columns per project, and private databases are reached through an SSH tunnel.
One project can hold, say, a PostgreSQL orders database and a MySQL CRM behind the same link; each SQL statement runs on one database and the agent combines the answers. These controls help you meet DPDP, GDPR, HIPAA, CCPA/CPRA and PDPL obligations. Details are on how it works and security.
Using both
Many teams keep a self-hosted server for local development and a gateway for anything shared. Datablare’s Free plan covers one project with two data sources, enough to try it on the same database. See pricing or start free.