Datablare works as a hosted MySQL MCP server: connect your MySQL database once, and Claude, ChatGPT, Cursor, VS Code or Claude Code can answer questions from it through a single project link. Every session is set to READ ONLY at the server, queries are checked before they run, agents see only the tables and columns you choose, and each query lands in an audit log.
What can go wrong with a direct MySQL connection
Pointing an AI agent at MySQL with the application’s login hands it more than reads. Typical problems:
- the app user holds
INSERT,UPDATE,DELETEand oftenALTERon everything; SELECT … INTO OUTFILEandLOAD_FILE()touch the server’s file system;SLEEP(),BENCHMARK()andGET_LOCK()tie up connections;- the
customerstable sits next toorders, phone numbers and all.
What Datablare adds for MySQL
- Read-only, enforced twice. The guard refuses anything but one read statement — including
INTO,OUTFILE,DUMPFILE,LOAD_FILEand sleep or lock functions. The session itself isREAD ONLY, so MySQL refuses data changes. - Choose tables, hide columns. Expose only what agents need, across one or several databases. Hide
phoneoremailin Modeling and any query that reads them is refused. - Protect the server. Per-query time limits, row caps and a ceiling on rows examined, plus a small number of concurrent queries per database and optional daily limits.
- Audit every query. Who asked, the question, the SQL, the outcome, rows and time.
- Revoke instantly. Disconnect a connection or remove a person and their access ends.
Results pass through to the agent and are never stored. Datablare is hosted in India. See security and how it works.
MySQL notes
Databases are schemas
MySQL calls a schema a “database”. Datablare lists every database the login can see (except mysql, information_schema, performance_schema and sys) and names tables database.table. When a query uses bare names, Datablare opens the session on the database those names were matched in, so orders resolves to the exposed table.
Time and size limits
Each query gets max_execution_time (30 seconds by default, 60 at most), or your user’s own setting if it is stricter. Datablare also sets sql_select_limit and max_join_size, so a query that would examine an enormous number of rows is refused with a hint to filter on an indexed column or aggregate a smaller slice.
Managed MySQL
Cloud MySQL with a public address connects directly; allow Datablare’s IP in the security group or firewall. With Use SSL on, traffic is encrypted. For a server on a private network, turn on Connect through an SSH tunnel and add the public key Datablare shows to your bastion.
Create a read-only login first
CREATE USER 'datablare_reader'@'%' IDENTIFIED BY 'choose-a-strong-password'
WITH MAX_USER_CONNECTIONS 5;
GRANT SELECT, SHOW VIEW ON shop.* TO 'datablare_reader'@'%';
-- To keep a column out entirely, grant columns instead of the table:
-- GRANT SELECT (id, city, created_at) ON shop.customers TO 'datablare_reader'@'%';
Better still, point Datablare at a read replica rather than the primary.
Example questions
Try these with the e-commerce sample first, then on your own MySQL shop database:
- How many orders did we get last week, by day?
- What is the average discount on articles that are currently active?
- Which customers have not ordered in the last 90 days?
- Which product labels drive the most revenue?
Connect MySQL to your AI tools
Create a free account, add your MySQL database and connect ChatGPT, Claude or Cursor. Running MariaDB? See the MariaDB MCP server page. Plans are on pricing.