Skip to content
Datablare

SQL Server MCP Server for Claude & Copilot

Connect Claude to SQL Server or Azure SQL through a governed SQL Server MCP server: reads only, rolled-back sessions, your tables, every query logged.

Setup

Connect SQL Server in 5 steps

  1. Step 1: Create a db_datareader login

    Create a login and database user for Datablare and add it to db_datareader. On SQL Server this login is the strongest protection you hold, so don't skip it.

  2. Step 2: Add SQL Server as a data source

    In Settings → Project → Data connection, add a data source and pick SQL Server. Enter host, port 1433, username, password and database name, or paste a sqlserver:// connection string.

  3. Step 3: Turn on SSL for Azure SQL

    Azure SQL refuses unencrypted logins, so switch on Use SSL. Then allow Datablare's IP, shown on the setup screen, in the server firewall, or use an SSH tunnel for an on-premises server.

  4. Step 4: Test and choose tables

    Test the connection; Datablare reports whether the login can write. Select the tables agents may query and hide columns in Modeling.

  5. Step 5: Connect Claude, Copilot or another agent

    On Connect your AI agent, pick Claude, ChatGPT, VS Code, Cursor or Claude Code and follow the sign-in steps.

Datablare gives you a governed SQL Server MCP server, so you can connect Claude to SQL Server or Azure SQL — and GitHub Copilot, ChatGPT, Cursor or Claude Code too — without handing any of them a raw login. Every query is checked before it runs, executed inside a transaction that is always rolled back, limited to the tables and columns you exposed, and recorded in an audit log.

Why SQL Server needs extra care

PostgreSQL and MySQL can open a session the server itself keeps read-only. SQL Server cannot. Any MCP server that connects with a login able to write relies on the model behaving. Common trouble spots:

  • application logins in db_owner, or with db_datawriter;
  • EXEC of stored procedures that change data;
  • SELECT … INTO creating tables, MERGE hiding behind a WITH;
  • OPENROWSET and linked servers reaching other systems;
  • WAITFOR DELAY holding a worker for as long as it is told.

How Datablare protects SQL Server

Layer 1 — the guard. Only one SELECT, WITH or VALUES statement passes. EXEC, INTO, MERGE, WAITFOR, OPENROWSET, OPENDATASOURCE, OPENQUERY, OPENXML and server-identity functions such as SERVERPROPERTY and HOST_NAME are refused, and a three-part name pointing at another database is refused.

Layer 2 — the session. Every connection runs with IMPLICIT_TRANSACTIONS ON and autocommit off, and is rolled back before it closes. Nothing a statement changed can survive.

Layer 3 — your login. A db_datareader login can’t write at all. On SQL Server this is the strongest protection, and the setup screen says so.

On top: choose tables, hide columns (a hidden column is refused even when named directly), audit every query, and revoke access instantly. Datablare is hosted in India and never stores result rows. It helps you meet DPDP · GDPR · HIPAA · CCPA/CPRA · PDPL obligations when AI tools touch customer data. More on security and how it works.

SQL Server and Azure SQL notes

Azure SQL

Azure SQL refuses unencrypted logins: switch on Use SSL when you add the source. Without it, Datablare still encrypts wherever the server offers encryption. Add the IP shown on the setup screen to the server’s firewall rules.

Default schema and dbo

SQL Server has no per-session search path. A bare name like Orders resolves in the login’s default schema, then dbo. Datablare runs bare names only when the login’s default schema is the one the exposed table is in; otherwise it asks the agent to write sales.Orders. Setting the reader’s default schema to where your data lives saves round trips:

ALTER USER datablare_reader WITH DEFAULT_SCHEMA = sales;

On-premises servers

A SQL Server inside your network can be reached through an SSH tunnel: turn on Connect through an SSH tunnel, add the public key Datablare shows to your bastion, and enter the database host as the bastion sees it.

Create a read-only login first

CREATE LOGIN datablare_reader WITH PASSWORD = 'Choose-a-strong-password1';

USE [shop];
CREATE USER datablare_reader FOR LOGIN datablare_reader;

-- Covers every table and view, including ones created later
ALTER ROLE db_datareader ADD MEMBER datablare_reader;

-- Keep a column out entirely:
-- DENY SELECT ON dbo.customers (email, phone) TO datablare_reader;

To cap its CPU and memory, use a Resource Governor workload group (Enterprise edition), or point Datablare at a readable secondary.

Example questions

Try these on the e-commerce sample, then on your own SQL Server data:

  • What were total sales per month for the last six months?
  • Which product categories do repeat customers buy most?
  • Which articles are below ten units in stock?
  • Which postcodes placed the most orders last month?

Connect SQL Server to your AI tools

Sign up free, add SQL Server or Azure SQL, and connect Claude, VS Code with Copilot or ChatGPT. Plans are on pricing.

FAQ

SQL Server MCP server: questions

Does this work with Azure SQL Database?

Yes. Choose SQL Server, turn on Use SSL (Azure SQL refuses unencrypted logins) and allow Datablare's IP in the Azure SQL firewall.

If there is no read-only session, how are writes stopped?

Three ways: the SQL guard refuses anything that is not a single read; each session runs inside a transaction that is always rolled back; and your own db_datareader login cannot write in the first place.

Why does Datablare ask for schema-qualified table names sometimes?

SQL Server resolves a bare name in the login's default schema, then dbo. Datablare runs bare names only when that default is the schema the exposed table is in; otherwise it asks the agent to write schema.table.

Can an agent use OPENROWSET or linked servers?

No. OPENROWSET, OPENDATASOURCE, OPENQUERY and OPENXML are refused, as are three-part names pointing at another database, EXEC, SELECT INTO, MERGE and WAITFOR.

How do I find Datablare's sessions on my server?

Datablare connects with the application name Datablare, so its sessions are easy to spot in your monitoring.

Ask SQL Server from your AI tool

Other databases: PostgreSQL · MySQL · MariaDB · Oracle · ClickHouse · Snowflake

Give your team answers from SQL Server, read-only.

Start free with the e-commerce sample or your own database. Connect Claude in about two minutes.

30 minutes with the founder. Or WhatsApp / [email protected]