Datablare is a hosted MariaDB MCP server: add your MariaDB database once and Claude, ChatGPT, Cursor, VS Code or Claude Code can query it through one project link. Each session is opened READ ONLY, every statement is bounded by MariaDB’s own max_statement_time, agents see only the tables and columns you allow, and every query is recorded.
MariaDB is not just MySQL
Many MCP servers treat MariaDB as a MySQL alias. The wire protocol is shared, but the details that matter for safe AI access are not:
- Timeouts. MySQL’s
max_execution_timeis in milliseconds and applies toSELECT. MariaDB usesmax_statement_time, in seconds, for every statement. - Read-only flag. MariaDB 11.1 renamed
tx_read_onlytotransaction_read_only. Datablare’s connection test checks both, so it can tell you truthfully that the session is read-only. - User limits. MariaDB lets you put
MAX_STATEMENT_TIMEon the user, a ceiling the database enforces whatever connects.
That is why Datablare has a separate MariaDB card. Choose it rather than MySQL when you add the source.
Why direct agent access to MariaDB is risky
An agent connected with the application’s credentials can run anything that login can: change rows, write files with SELECT … INTO OUTFILE, or hold a lock with GET_LOCK(). Every table is visible, including the ones with personal data, and nothing records which person’s question caused which query.
What Datablare adds
- Two read-only layers. The SQL guard admits one read statement and refuses write keywords,
INTO,OUTFILE,LOAD_FILE,SLEEP,BENCHMARKand lock functions. Then MariaDB’s ownREAD ONLYsession refuses data changes. - Your tables, your columns. Expose what agents need; hide
email,phoneor anything else. A hidden column is refused even when the agent names it. - Load protection. A time limit per statement, a row cap per query (1,000 by default, 5,000 at most), a ceiling on rows examined, a few concurrent queries per database, and optional daily limits.
- A full record. Audit shows each question, the SQL, who asked, the outcome, rows and time.
- Revocation. Disconnect, revoke a key or remove a person, and access ends.
Datablare is hosted in India and never stores your rows. More on security and how it works.
Create a read-only login first
MariaDB can cap the reader’s statement time at the database itself:
CREATE USER 'datablare_reader'@'%' IDENTIFIED BY 'choose-a-strong-password'
WITH MAX_USER_CONNECTIONS 5
MAX_STATEMENT_TIME 30;
GRANT SELECT, SHOW VIEW ON shop.* TO 'datablare_reader'@'%';
-- Keep a column out by granting columns instead of the table:
-- GRANT SELECT (id, city, created_at) ON shop.customers TO 'datablare_reader'@'%';
If your user’s timeout is stricter than Datablare’s, Datablare keeps yours. A replica used only for reads is an even safer target.
Example questions
Use the e-commerce sample to see the flow, then ask the same of your own MariaDB data:
- Which products were added in the last 30 days, and how many have sold?
- What share of orders contain more than one article?
- Which colours are overstocked compared with last month’s sales?
- What is revenue per week for the current quarter?
Connect MariaDB to your AI tools
Sign up free, add the MariaDB source, and connect Claude, Cursor or ChatGPT. Still on MySQL? See the MySQL MCP server page. Plans are on pricing.