← Back to directory
COMPARE UP TO 4 SERVERS

Compare MCP servers

Compare scores, permissions, risks, and fit in one decision-focused table.

DimensionSnowflake MCP Server (OSS, Deprecated)[Deprecated] Community MCP server for Snowflake Cortex AI and SQL orchestrationMCP ClickHouseConnect ClickHouse to your AI assistantsMCP Toolbox for DatabasesGoogle's official database MCP toolbox — define AI-accessible database tools via config
FMRS48 / 100 · D79 / 100 · B74 / 100 · B
Reliability7 / 2012 / 2013 / 20
Security and permissions10 / 2018 / 2013 / 20
Maintenance2 / 2017 / 2017 / 20
Documentation16 / 2017 / 2016 / 20
Setup experience13 / 2015 / 2015 / 20
Best for
  • Teams already on Snowflake who need to study or reproduce a legacy MCP integration for migration purposes
  • Developers researching this project's architecture before moving to the official Snowflake MCP Server
  • Teams already using ClickHouse who want AI assistants to access data directly.
  • Scenarios requiring fast, read-only data queries and schema exploration.
  • Teams that want precise control over which database operations an AI can perform, rather than open arbitrary SQL execution
  • Scenarios needing a unified MCP setup across multiple database engines
Not for
  • Any new project or production deployment, since the project is officially deprecated with no further fixes or features
  • Users unfamiliar with Snowflake RBAC and SQL statement allowlisting who cannot audit the permission configuration themselves
  • Scenarios requiring write access to the database without explicit opt-in.
  • Production environments with stringent security requirements that avoid default permission settings.
  • Lightweight cases that just want to run a few ad-hoc SQL queries without maintaining a tools.yaml config (a simpler single-database MCP may be a better fit)
Required permissions
  • Requires valid Snowflake credentials (username/password, PAT, key pair, OAuth, or SSO)
  • Server behavior is fully bound by the RBAC permissions of the connecting role, which needs access to the target databases/schemas/warehouses/Cortex services
  • Enabling SQL execution or object-management tools requires explicitly allowlisting SQL statement types (Create, Drop, Update, etc.) in the configuration file
  • Requires read-only access to ClickHouse database (default).
  • Optional: write access via CLICKHOUSE_ALLOW_WRITE_ACCESS.
  • Optional: destructive operations via CLICKHOUSE_ALLOW_DROP.
  • Database credentials (username/password/connection string) are supplied via env vars or config
  • A tool's actual permission is whatever SQL statement is defined in tools.yaml — designed for least privilege, but misconfiguration can still over-expose access
Risks and side effects
  • The project is officially marked deprecated and unmaintained, so unresolved security or functional issues may exist — not recommended for new deployments
  • Misconfigured sql_statement_permissions or an 'Unknown' statement type set to True can allow destructive SQL (DROP, DELETE, UPDATE) to execute beyond intended scope
  • Sensitive credentials (private keys, passwords) are passed via environment variables or CLI arguments, requiring careful protection of the deployment environment
  • Programmatic Access Tokens (PATs) do not evaluate secondary roles, forcing a single broadly-privileged role and coarser permission control
  • If write access is enabled, AI might make unintended modifications.
  • If DROP access is enabled, data deletion could occur accidentally.
  • Credentials may be exposed via environment variables.
  • If tools.yaml defines SQL statements that allow unconstrained writes or deletes, the AI could accidentally modify data
  • The prebuilt toolsets (--prebuilt) favor convenience and may expose broader query capability than a specific business actually needs — use a custom tools.yaml in production
Supported clientsClaude Desktop, Cursor, fast-agent, Codex, Visual Studio Code (GitHub Copilot)Claude DesktopClaude Code, Gemini CLI, Zed, Antigravity
Tools640