Datablare is a governed Oracle MCP server for teams who want Claude, ChatGPT, VS Code with Copilot, Cursor or Claude Code to answer questions from Oracle Database without a privileged login in anyone’s config. Each session is a read-only transaction, PL/SQL package calls are refused, agents see only the tables and columns you expose, and every query is recorded.
Oracle-specific risks for AI agents
Oracle’s reach goes well beyond tables. A model that can run arbitrary SQL under a broad user can:
- call
UTL_HTTPorHTTPURITYPEto reach the network from aSELECT; - run SQL passed as a string through
DBMS_SQLorDBMS_XMLGEN; - sleep with
DBMS_LOCK, holding a session open; - declare an autonomous transaction in a
WITH FUNCTIONblock, which escapes a read-only transaction; - read
SYS_CONTEXT('USERENV', …)to learn about the host and login.
A blocklist of function names can’t keep up with Oracle’s packages, so Datablare checks Oracle the other way round.
How Datablare protects Oracle
- Read-only transaction. Every session runs
SET TRANSACTION READ ONLYbefore any query, so Oracle refuses data changes. - No packages, an allow-list of functions. The guard refuses any package or method call —
UTL_*,DBMS_*,OWA_*,CTX_*and others, even reached through an owner likeSYS.— and accepts only built-in functions it knows.PRAGMAand identity functions such asSYS_CONTEXTandUSERENVare refused. - DDL stopped first. Oracle commits before DDL, which would end the read-only transaction, so
CREATE,ALTER,DROPand the rest are refused before reaching the database. - Tables and columns you choose, with hidden columns refused even when named directly.
- Audit and revocation. Every query is logged with who asked and the SQL; keys and connections can be switched off at once.
Datablare is hosted in India and passes result rows through without storing them. See security and how it works.
Oracle notes
Thin mode, no client install
Datablare uses python-oracledb in thin mode, so no Oracle Instant Client is needed. You supply the host, port 1521, a user and the service name — for example ORCLPDB1 — not the SID.
TCPS
With Use SSL on, Datablare connects over TCPS; otherwise plain TCP.
Schemas are owners
Tables are listed as OWNER.TABLE, and the schemas Oracle ships with are left out, so a fresh connection lists your application’s tables rather than the dictionary. When an agent writes a bare name, Datablare sets the session’s current schema to the owner of the exposed table for that query, so ORDERS means APP_OWNER.ORDERS — not something in the reader’s own schema.
Create a read-only login first
CREATE USER datablare_reader IDENTIFIED BY "Choose-a-strong-password1";
GRANT CREATE SESSION TO datablare_reader;
-- One grant per table to expose:
GRANT SELECT ON app_owner.orders TO datablare_reader;
GRANT SELECT ON app_owner.customers TO datablare_reader;
-- Oracle 23ai can grant a whole schema at once:
-- GRANT SELECT ANY TABLE ON SCHEMA app_owner TO datablare_reader;
-- Limit how hard it can work (CPU and read limits need RESOURCE_LIMIT = TRUE):
CREATE PROFILE datablare_limits LIMIT
SESSIONS_PER_USER 5
CPU_PER_CALL 6000
LOGICAL_READS_PER_CALL 50000000;
ALTER USER datablare_reader PROFILE datablare_limits;
To keep a column out at the database, expose a view without it and grant the view instead of the table.
Example questions
Try the flow on the e-commerce sample, then ask your Oracle data the same kind of thing:
- What was revenue by product category in the last financial quarter?
- Which customers placed their first order this month?
- Which articles have had a price reduction and still sell slowly?
- What is the average number of articles per order?
Connect Oracle to your AI tools
Create a free account, add your Oracle database, and connect Claude, ChatGPT or VS Code. See pricing for plans.