Skip to content
Datablare

MariaDB MCP Server, Read-Only for AI Agents

A read-only MariaDB MCP server for Claude, ChatGPT and Cursor: READ ONLY sessions, MariaDB's own statement timeout, tables you choose and a full audit log.

Setup

Connect MariaDB in 5 steps

  1. Step 1: Create a MariaDB reader (recommended)

    Create datablare_reader with SELECT and SHOW VIEW, a connection cap and MAX_STATEMENT_TIME. The setup screen gives you the SQL.

  2. Step 2: Choose MariaDB, not MySQL

    In Settings → Project → Data connection, add a data source and pick the MariaDB card, so MariaDB's own timeout setting is used. Enter host, port 3306, username and password, or paste a mariadb:// string.

  3. Step 3: Open the network path

    Turn on Use SSL if required. Allow Datablare's IP, shown on the setup screen, or connect through an SSH tunnel to a bastion on your network.

  4. Step 4: Test, then select tables

    Test the connection — Datablare checks whether the login can write — and select the tables agents may read. Hide columns in Modeling.

  5. Step 5: Add Datablare to your AI tool

    From Connect your AI agent, add the project link to Claude, ChatGPT, Cursor, VS Code or Claude Code and sign in.

Datablare is a hosted MariaDB MCP server: add your MariaDB database once and Claude, ChatGPT, Cursor, VS Code or Claude Code can query it through one project link. Each session is opened READ ONLY, every statement is bounded by MariaDB’s own max_statement_time, agents see only the tables and columns you allow, and every query is recorded.

MariaDB is not just MySQL

Many MCP servers treat MariaDB as a MySQL alias. The wire protocol is shared, but the details that matter for safe AI access are not:

  • Timeouts. MySQL’s max_execution_time is in milliseconds and applies to SELECT. MariaDB uses max_statement_time, in seconds, for every statement.
  • Read-only flag. MariaDB 11.1 renamed tx_read_only to transaction_read_only. Datablare’s connection test checks both, so it can tell you truthfully that the session is read-only.
  • User limits. MariaDB lets you put MAX_STATEMENT_TIME on the user, a ceiling the database enforces whatever connects.

That is why Datablare has a separate MariaDB card. Choose it rather than MySQL when you add the source.

Why direct agent access to MariaDB is risky

An agent connected with the application’s credentials can run anything that login can: change rows, write files with SELECT … INTO OUTFILE, or hold a lock with GET_LOCK(). Every table is visible, including the ones with personal data, and nothing records which person’s question caused which query.

What Datablare adds

  • Two read-only layers. The SQL guard admits one read statement and refuses write keywords, INTO, OUTFILE, LOAD_FILE, SLEEP, BENCHMARK and lock functions. Then MariaDB’s own READ ONLY session refuses data changes.
  • Your tables, your columns. Expose what agents need; hide email, phone or anything else. A hidden column is refused even when the agent names it.
  • Load protection. A time limit per statement, a row cap per query (1,000 by default, 5,000 at most), a ceiling on rows examined, a few concurrent queries per database, and optional daily limits.
  • A full record. Audit shows each question, the SQL, who asked, the outcome, rows and time.
  • Revocation. Disconnect, revoke a key or remove a person, and access ends.

Datablare is hosted in India and never stores your rows. More on security and how it works.

Create a read-only login first

MariaDB can cap the reader’s statement time at the database itself:

CREATE USER 'datablare_reader'@'%' IDENTIFIED BY 'choose-a-strong-password'
  WITH MAX_USER_CONNECTIONS 5
       MAX_STATEMENT_TIME 30;

GRANT SELECT, SHOW VIEW ON shop.* TO 'datablare_reader'@'%';

-- Keep a column out by granting columns instead of the table:
-- GRANT SELECT (id, city, created_at) ON shop.customers TO 'datablare_reader'@'%';

If your user’s timeout is stricter than Datablare’s, Datablare keeps yours. A replica used only for reads is an even safer target.

Example questions

Use the e-commerce sample to see the flow, then ask the same of your own MariaDB data:

  • Which products were added in the last 30 days, and how many have sold?
  • What share of orders contain more than one article?
  • Which colours are overstocked compared with last month’s sales?
  • What is revenue per week for the current quarter?

Connect MariaDB to your AI tools

Sign up free, add the MariaDB source, and connect Claude, Cursor or ChatGPT. Still on MySQL? See the MySQL MCP server page. Plans are on pricing.

FAQ

MariaDB MCP server: questions

Why does Datablare treat MariaDB separately from MySQL?

The two have drifted apart. Datablare's MariaDB driver uses max_statement_time, measured in seconds and covering every statement, where MySQL uses max_execution_time in milliseconds for SELECTs. It also reads the read-only flag under either name MariaDB versions use.

Which MariaDB versions work?

The driver checks both transaction_read_only and the older tx_read_only variable, so it reports correctly on versions before and after the rename in MariaDB 11.1.

Can I limit the reader on the MariaDB side too?

Yes. MariaDB lets you set MAX_USER_CONNECTIONS and MAX_STATEMENT_TIME on the user itself. Datablare keeps your timeout when it is stricter than its own.

Do I need SSH?

Only for a MariaDB server on a private network. A server with a public address that allows Datablare's IP connects directly.

Ask MariaDB from your AI tool

Other databases: PostgreSQL · MySQL · SQL Server · Oracle · ClickHouse · Snowflake

Give your team answers from MariaDB, read-only.

Start free with the e-commerce sample or your own database. Connect Claude in about two minutes.

30 minutes with the founder. Or WhatsApp / kamal@datablare.com