← Back to directory
COMPARE UP TO 4 SERVERS

Compare MCP servers

Compare scores, permissions, risks, and fit in one decision-focused table.

DimensionMCP Database ServerMCP server that provides database access to Claude for SQLite, SQL Server, PostgreSQL, and MySQLMCP ClickHouseConnect ClickHouse to your AI assistantsMCP Toolbox for DatabasesGoogle's official database MCP toolbox — define AI-accessible database tools via config
FMRS57 / 100 · C79 / 100 · B74 / 100 · B
Reliability10 / 2012 / 2013 / 20
Security and permissions8 / 2018 / 2013 / 20
Maintenance12 / 2017 / 2017 / 20
Documentation15 / 2017 / 2016 / 20
Setup experience12 / 2015 / 2015 / 20
Best for
  • Developers who need to interact with multiple database types
  • Claude users who want to operate databases using natural language
  • Scenarios requiring quick data export or insight recording
  • Teams already using ClickHouse who want AI assistants to access data directly.
  • Scenarios requiring fast, read-only data queries and schema exploration.
  • Teams that want precise control over which database operations an AI can perform, rather than open arbitrary SQL execution
  • Scenarios needing a unified MCP setup across multiple database engines
Not for
  • Scenarios requiring complex transaction handling or fine-grained permission control
  • High-concurrency database access in production environments
  • Non-relational databases (e.g., MongoDB)
  • Scenarios requiring write access to the database without explicit opt-in.
  • Production environments with stringent security requirements that avoid default permission settings.
  • Lightweight cases that just want to run a few ad-hoc SQL queries without maintaining a tools.yaml config (a simpler single-database MCP may be a better fit)
Required permissions
  • Requires database credentials (username, password)
  • May require network access to connect to remote databases
  • Requires file system access (for SQLite files)
  • Requires read-only access to ClickHouse database (default).
  • Optional: write access via CLICKHOUSE_ALLOW_WRITE_ACCESS.
  • Optional: destructive operations via CLICKHOUSE_ALLOW_DROP.
  • Database credentials (username/password/connection string) are supplied via env vars or config
  • A tool's actual permission is whatever SQL statement is defined in tools.yaml — designed for least privilege, but misconfiguration can still over-expose access
Risks and side effects
  • Write operations may cause data loss or corruption; use with caution
  • Credentials may be recorded in configuration files; manage carefully
  • Open network ports may pose security risks
  • If write access is enabled, AI might make unintended modifications.
  • If DROP access is enabled, data deletion could occur accidentally.
  • Credentials may be exposed via environment variables.
  • If tools.yaml defines SQL statements that allow unconstrained writes or deletes, the AI could accidentally modify data
  • The prebuilt toolsets (--prebuilt) favor convenience and may expose broader query capability than a specific business actually needs — use a custom tools.yaml in production
Supported clientsClaude DesktopClaude DesktopClaude Code, Gemini CLI, Zed, Antigravity
Tools1040