Datablare is a governed ClickHouse MCP server: connect your ClickHouse Cloud service or self-hosted cluster once, and Claude, ChatGPT, Cursor, VS Code or Claude Code can query it through one project link. Every query runs with readonly=2, ClickHouse enforces Datablare’s time and scan limits, table functions that reach outside the database are refused, and each query is logged.
What makes ClickHouse different for AI agents
ClickHouse is built to scan billions of rows quickly — which is exactly why an unbounded agent is a problem. An open MCP server with a broad user can:
- run an aggregation over a whole multi-billion-row table until a timeout;
- use table functions like
s3(),url(),remote()ormysql()to read from places you never exposed; - run
executable()where it is enabled; ALTER,OPTIMIZEorTRUNCATEif the user is allowed to.
How Datablare protects ClickHouse
- readonly=2 on every query. ClickHouse refuses inserts, alters and schema changes, while still letting Datablare set the query’s own limits.
- Scan limits ClickHouse enforces. Each query carries
max_execution_timeand a cap on rows read. ClickHouse checks its estimate before reading and refuses a query that would exceed it — better than quietly summing part of a table and returning a wrong answer that looks right. - No external table functions. The guard refuses
url,file,s3,s3Cluster,hdfs,remote,remoteSecure,cluster,mysql,postgresql,jdbc,odbc,executable,azureBlobStorage,gcsand similar. Value-only functions likenumbersstay available. - Tables and columns you choose. Hidden columns are refused even if the agent names them.
- Audit and revocation. Who asked, the question, the SQL, outcome, rows and time; switch access off at once.
Results go straight to the agent and are never stored. Datablare is hosted in India. More on security and how it works.
ClickHouse notes
HTTPS port 8443
Datablare talks to ClickHouse over its HTTP interface. The default is port 8443 with SSL on, which matches ClickHouse Cloud. A self-hosted server without TLS uses 8123. Paste a clickhouse:// or https:// URL and Datablare fills in the fields. With SSL on, traffic is encrypted without insisting on a publicly signed certificate, as with self-hosted servers on other engines.
Databases and the default user
The database field defaults to default, but every database the user can see is listed either way, except system and information_schema. Tables are named database.table.
readonly=1 versus GRANT SELECT
If the user’s profile is readonly=1, ClickHouse forbids changing any setting — including the limits Datablare wants to add. Datablare then drops its own settings and relies on the profile to refuse writes. A user with only SELECT grants keeps both protections.
Create a read-only login first
CREATE USER datablare_reader IDENTIFIED BY 'choose-a-strong-password';
-- SELECT alone, rather than a readonly profile, so per-query limits still apply
GRANT SELECT ON analytics.* TO datablare_reader;
-- Your own ceilings. Where yours are stricter, yours apply.
CREATE SETTINGS PROFILE datablare_limits SETTINGS
max_execution_time = 30,
max_rows_to_read = 500000000,
max_memory_usage = 10000000000,
max_concurrent_queries_for_user = 5
TO datablare_reader;
-- Keep a column out by granting columns instead of the table:
-- GRANT SELECT(id, city, created_at) ON analytics.customers TO datablare_reader;
Example questions
Ask these against the e-commerce sample to see the flow, then point the same kind of question at your ClickHouse event or order tables:
- What is daily revenue for the last 90 days?
- Which hour of the day gets the most orders?
- Which ten articles sold the most units last week?
- How does the average basket size change by weekday?
Connect ClickHouse to your AI tools
Sign up free, add your ClickHouse service, and connect Cursor, Claude or Claude Code. Plans are on pricing.