Skip to content
Datablare
Cursor code editor

Cursor MCP Database Access, Read-Only

Add a read-only Cursor MCP database server in one click. Agent mode queries Postgres, MySQL and more, limited to tables you choose, every query logged.

  • Read-only, checked by the SQL guard and kept read-only by the database.
  • Only the tables and columns you allow reach Cursor.
  • Every query on record under the person who asked.

Setup

Set up Cursor in 3 steps

  1. Step 1: Add Datablare to Cursor

    On Datablare's Connect page, choose Cursor and click Add to Cursor. Or paste the configuration shown into ~/.cursor/mcp.json (or Cursor Settings → MCP → Add).

  2. Step 2: Sign in from Cursor

    In Cursor Settings → MCP, Datablare shows Needs login. Click it, sign in to Datablare in your browser and choose Allow.

  3. Step 3: Ask in Agent mode

    Open Cursor's chat in Agent mode and ask about your data, for example: Using Datablare, what can you tell me from our orders data?

Datablare Connect page listing Claude, ChatGPT, Cursor, VS Code, Claude Code and other MCP clients, with the project’s MCP link and step-by-step sign-in instructions.
The Connect page in Datablare shows the exact steps and your project’s link for each tool.

To give Cursor MCP database access, add Datablare to Cursor with the Add to Cursor button on Datablare’s Connect page (or a three-line mcp.json), click Needs login, sign in and allow. Cursor’s Agent mode can then query your PostgreSQL, MySQL, ClickHouse or other database to answer questions while you code — read-only, restricted to the tables and columns you expose, and logged.

Why a raw database MCP server in Cursor is risky

The usual “cursor mcp postgres” setup runs a local server with a connection string in mcp.json. That puts a working database credential in a file on a developer’s machine, often one with more rights than it needs. Agent mode runs tools on its own; one confident wrong step and a DELETE without a WHERE reaches a real table. And there is no shared record of what the agent read.

What Datablare changes for Cursor users

  • No credential in the editor. mcp.json holds only the project link. Cursor signs in with OAuth, discovered automatically.
  • Writes refused twice. Datablare’s SQL guard allows one read statement only, then runs it in a read-only database session. Ask the agent to “fix the bad rows” and you get a refusal with a reason, not a changed table.
  • Only what you expose. A project manager picks the tables and can hide columns such as email or phone. Bare table names are matched only against exposed tables; an ambiguous name is refused and the agent is asked to qualify it.
  • Bounded queries. Each query returns at most 5,000 rows and stops after 60 seconds at most, and only a few run at once per database.
  • A team-wide record. Every call lands in Audit under the developer’s name. Each connection appears under Connected on the Connect page, labelled with the name Cursor gives itself, where you can disconnect it.

See how it works and security for the full query path.

The Cursor configuration

The Connect page fills in your link. The sign-in version looks like this:

{
  "mcpServers": {
    "datablare-your-project": {
      "url": "https://app.datablare.com/mcp/your-company/your-project/"
    }
  }
}

If you’d rather use a personal key — for a shared machine or an automated agent — the Connect page gives the same block with an Authorization: Bearer header. Keys start with dblr_, are shown once, and can be revoked on the MCP server page; revoking stops them immediately.

Useful in Cursor

Agent mode is good at the questions developers actually ask the database: “how many users hit this code path last week”, “what values does status really take”, “are there orders without positions”. Datablare also passes the table descriptions and rules you write in Modeling, so the agent knows amount is in paise or that test rows should be excluded.

Create a read-only login first

For a development or reporting database, a role with column-level grants keeps the most sensitive fields out even at the database level. A PostgreSQL example for an app schema:

CREATE ROLE datablare_reader LOGIN PASSWORD 'choose-a-strong-password'
  CONNECTION LIMIT 5;
GRANT USAGE ON SCHEMA app TO datablare_reader;
GRANT SELECT ON ALL TABLES IN SCHEMA app TO datablare_reader;
ALTER DEFAULT PRIVILEGES IN SCHEMA app GRANT SELECT ON TABLES TO datablare_reader;

-- Keep personal columns out at the source as well:
REVOKE SELECT ON app.customers FROM datablare_reader;
GRANT SELECT (id, city, created_at) ON app.customers TO datablare_reader;

Better still, point Datablare at a read replica. Engine details: PostgreSQL, MySQL, ClickHouse.

Try it with the e-commerce sample

Connect the one-click e-commerce sample and ask Cursor’s agent:

  • Which products were added most recently, and are they active?
  • Show stock levels for the ten best-selling articles.
  • Which labels are used by the most products?

Get going

Create a free account and click Add to Cursor. Compare plans on pricing. Using VS Code or the terminal? See VS Code and Claude Code.

FAQ

Cursor and Datablare: questions

Do I need to put a database password in mcp.json?

No. The configuration holds only your project's link. Cursor signs in to Datablare with OAuth; your database credentials stay encrypted in Datablare.

Can I use a key instead of signing in?

Yes. On the Connect page, open Can't sign in? Use a personal key, name the key and copy it — it is shown once. Datablare gives you the mcp.json with the key as an Authorization header.

Will Cursor's agent run migrations or writes through Datablare?

No. Datablare refuses anything that is not a single read, and the query runs in a read-only session or an always rolled-back transaction. Use your normal migration tooling for schema changes.

Does this work with a local Postgres on my laptop?

Datablare connects from its own servers, so the database needs a public address that allows Datablare's IP, or must be reached through an SSH tunnel you run.

Connect Cursor to your database today.

Start free with the e-commerce sample or your own database. Connect Claude in about two minutes.

30 minutes with the founder. Or WhatsApp / [email protected]