Skip to content
Datablare

ClickHouse MCP Server with Read-Only Guardrails

A governed ClickHouse MCP server for Claude, ChatGPT and Cursor: readonly=2 on every query, scan limits, no external table functions, full audit log.

Setup

Connect ClickHouse in 5 steps

  1. Step 1: Create a SELECT-only user (recommended)

    Create datablare_reader with GRANT SELECT rather than a readonly profile, so Datablare can still apply per-query limits. Add a settings profile with your own ceilings.

  2. Step 2: Add ClickHouse as a data source

    In Settings → Project → Data connection, add a data source and pick ClickHouse. Enter host, username and password; the port defaults to 8443 with SSL on, which is what ClickHouse Cloud uses.

  3. Step 3: Check port, SSL and network

    Use 8443 with SSL, or 8123 for a server without TLS — both are ClickHouse's HTTP interface. Allow Datablare's IP, shown on the setup screen, in your IP access list.

  4. Step 4: Test and pick tables

    Test the connection and select the tables agents may query across the databases the user can see. Hide columns in Modeling.

  5. Step 5: Connect your AI tool

    On Connect your AI agent, add Datablare to Claude, ChatGPT, Cursor, VS Code or Claude Code and sign in.

Datablare is a governed ClickHouse MCP server: connect your ClickHouse Cloud service or self-hosted cluster once, and Claude, ChatGPT, Cursor, VS Code or Claude Code can query it through one project link. Every query runs with readonly=2, ClickHouse enforces Datablare’s time and scan limits, table functions that reach outside the database are refused, and each query is logged.

What makes ClickHouse different for AI agents

ClickHouse is built to scan billions of rows quickly — which is exactly why an unbounded agent is a problem. An open MCP server with a broad user can:

  • run an aggregation over a whole multi-billion-row table until a timeout;
  • use table functions like s3(), url(), remote() or mysql() to read from places you never exposed;
  • run executable() where it is enabled;
  • ALTER, OPTIMIZE or TRUNCATE if the user is allowed to.

How Datablare protects ClickHouse

  • readonly=2 on every query. ClickHouse refuses inserts, alters and schema changes, while still letting Datablare set the query’s own limits.
  • Scan limits ClickHouse enforces. Each query carries max_execution_time and a cap on rows read. ClickHouse checks its estimate before reading and refuses a query that would exceed it — better than quietly summing part of a table and returning a wrong answer that looks right.
  • No external table functions. The guard refuses url, file, s3, s3Cluster, hdfs, remote, remoteSecure, cluster, mysql, postgresql, jdbc, odbc, executable, azureBlobStorage, gcs and similar. Value-only functions like numbers stay available.
  • Tables and columns you choose. Hidden columns are refused even if the agent names them.
  • Audit and revocation. Who asked, the question, the SQL, outcome, rows and time; switch access off at once.

Results go straight to the agent and are never stored. Datablare is hosted in India. More on security and how it works.

ClickHouse notes

HTTPS port 8443

Datablare talks to ClickHouse over its HTTP interface. The default is port 8443 with SSL on, which matches ClickHouse Cloud. A self-hosted server without TLS uses 8123. Paste a clickhouse:// or https:// URL and Datablare fills in the fields. With SSL on, traffic is encrypted without insisting on a publicly signed certificate, as with self-hosted servers on other engines.

Databases and the default user

The database field defaults to default, but every database the user can see is listed either way, except system and information_schema. Tables are named database.table.

readonly=1 versus GRANT SELECT

If the user’s profile is readonly=1, ClickHouse forbids changing any setting — including the limits Datablare wants to add. Datablare then drops its own settings and relies on the profile to refuse writes. A user with only SELECT grants keeps both protections.

Create a read-only login first

CREATE USER datablare_reader IDENTIFIED BY 'choose-a-strong-password';

-- SELECT alone, rather than a readonly profile, so per-query limits still apply
GRANT SELECT ON analytics.* TO datablare_reader;

-- Your own ceilings. Where yours are stricter, yours apply.
CREATE SETTINGS PROFILE datablare_limits SETTINGS
  max_execution_time = 30,
  max_rows_to_read = 500000000,
  max_memory_usage = 10000000000,
  max_concurrent_queries_for_user = 5
TO datablare_reader;

-- Keep a column out by granting columns instead of the table:
-- GRANT SELECT(id, city, created_at) ON analytics.customers TO datablare_reader;

Example questions

Ask these against the e-commerce sample to see the flow, then point the same kind of question at your ClickHouse event or order tables:

  • What is daily revenue for the last 90 days?
  • Which hour of the day gets the most orders?
  • Which ten articles sold the most units last week?
  • How does the average basket size change by weekday?

Connect ClickHouse to your AI tools

Sign up free, add your ClickHouse service, and connect Cursor, Claude or Claude Code. Plans are on pricing.

FAQ

ClickHouse MCP server: questions

Which port does Datablare use for ClickHouse?

ClickHouse's HTTP interface: 8443 with SSL (the default, and what ClickHouse Cloud uses) or 8123 without. The native TCP port 9000 is not used.

Should the user have a readonly profile?

Prefer a user with only SELECT grants. A readonly=1 profile also refuses writes, but it blocks every setting change, so Datablare has to drop its per-query time and scan limits for that user.

Can an agent read S3, URLs or other servers through ClickHouse?

No. Table functions that reach outside the database — url, file, s3, remote, mysql, postgresql, jdbc, odbc, executable and others — are refused by the guard.

Why are there no relationships on the Modeling canvas?

ClickHouse has no foreign keys, and its primary key orders data rather than making rows unique, so Datablare shows columns without inventing relationships. You can describe how tables connect in the table context.

Ask ClickHouse from your AI tool

Other databases: PostgreSQL · MySQL · MariaDB · SQL Server · Oracle · Snowflake

Give your team answers from ClickHouse, read-only.

Start free with the e-commerce sample or your own database. Connect Claude in about two minutes.

30 minutes with the founder. Or WhatsApp / kamal@datablare.com