Skip to content
Datablare

MySQL MCP Server for Claude and ChatGPT

Connect Claude, ChatGPT or Cursor through a read-only MySQL MCP server. Sessions are READ ONLY, tables and columns are yours to choose, every query logged.

Setup

Connect MySQL in 5 steps

  1. Step 1: Create a read-only MySQL user (recommended)

    Create datablare_reader with SELECT and SHOW VIEW on the databases you want to expose. Datablare's setup screen shows the exact SQL.

  2. Step 2: Add MySQL as a data source

    In Settings → Project → Data connection, add a data source and pick MySQL. Enter host, port 3306, username and password, or paste a mysql:// connection string. The database name is optional.

  3. Step 3: Set up SSL and network access

    Turn on Use SSL for managed MySQL that requires it. Allow the IP shown on the setup screen through your firewall or security group, or use an SSH tunnel for a private server.

  4. Step 4: Test and pick tables

    Test the connection; Datablare tells you if the login can only read. Then pick the tables agents may query across the databases the login can see.

  5. Step 5: Connect an AI tool

    Open Connect your AI agent and add Datablare to Claude, ChatGPT, Cursor, VS Code or Claude Code with one link and a sign-in.

Datablare works as a hosted MySQL MCP server: connect your MySQL database once, and Claude, ChatGPT, Cursor, VS Code or Claude Code can answer questions from it through a single project link. Every session is set to READ ONLY at the server, queries are checked before they run, agents see only the tables and columns you choose, and each query lands in an audit log.

What can go wrong with a direct MySQL connection

Pointing an AI agent at MySQL with the application’s login hands it more than reads. Typical problems:

  • the app user holds INSERT, UPDATE, DELETE and often ALTER on everything;
  • SELECT … INTO OUTFILE and LOAD_FILE() touch the server’s file system;
  • SLEEP(), BENCHMARK() and GET_LOCK() tie up connections;
  • the customers table sits next to orders, phone numbers and all.

What Datablare adds for MySQL

  • Read-only, enforced twice. The guard refuses anything but one read statement — including INTO, OUTFILE, DUMPFILE, LOAD_FILE and sleep or lock functions. The session itself is READ ONLY, so MySQL refuses data changes.
  • Choose tables, hide columns. Expose only what agents need, across one or several databases. Hide phone or email in Modeling and any query that reads them is refused.
  • Protect the server. Per-query time limits, row caps and a ceiling on rows examined, plus a small number of concurrent queries per database and optional daily limits.
  • Audit every query. Who asked, the question, the SQL, the outcome, rows and time.
  • Revoke instantly. Disconnect a connection or remove a person and their access ends.

Results pass through to the agent and are never stored. Datablare is hosted in India. See security and how it works.

MySQL notes

Databases are schemas

MySQL calls a schema a “database”. Datablare lists every database the login can see (except mysql, information_schema, performance_schema and sys) and names tables database.table. When a query uses bare names, Datablare opens the session on the database those names were matched in, so orders resolves to the exposed table.

Time and size limits

Each query gets max_execution_time (30 seconds by default, 60 at most), or your user’s own setting if it is stricter. Datablare also sets sql_select_limit and max_join_size, so a query that would examine an enormous number of rows is refused with a hint to filter on an indexed column or aggregate a smaller slice.

Managed MySQL

Cloud MySQL with a public address connects directly; allow Datablare’s IP in the security group or firewall. With Use SSL on, traffic is encrypted. For a server on a private network, turn on Connect through an SSH tunnel and add the public key Datablare shows to your bastion.

Create a read-only login first

CREATE USER 'datablare_reader'@'%' IDENTIFIED BY 'choose-a-strong-password'
  WITH MAX_USER_CONNECTIONS 5;

GRANT SELECT, SHOW VIEW ON shop.* TO 'datablare_reader'@'%';

-- To keep a column out entirely, grant columns instead of the table:
-- GRANT SELECT (id, city, created_at) ON shop.customers TO 'datablare_reader'@'%';

Better still, point Datablare at a read replica rather than the primary.

Example questions

Try these with the e-commerce sample first, then on your own MySQL shop database:

  • How many orders did we get last week, by day?
  • What is the average discount on articles that are currently active?
  • Which customers have not ordered in the last 90 days?
  • Which product labels drive the most revenue?

Connect MySQL to your AI tools

Create a free account, add your MySQL database and connect ChatGPT, Claude or Cursor. Running MariaDB? See the MariaDB MCP server page. Plans are on pricing.

FAQ

MySQL MCP server: questions

Why is the database name optional?

In MySQL a database is what other engines call a schema. Datablare lists every database the login can see, as database.table, whether or not you enter one.

Does SSL verify the server certificate?

With Use SSL on, the connection is encrypted without insisting on a publicly signed certificate, which suits managed MySQL hosts that use their own certificate authority.

Can a heavy agent query overload my MySQL server?

Each query has a time limit (MySQL's max_execution_time), a row cap, and a ceiling on rows examined; a query that would scan too much is refused with advice to filter or aggregate. Only a few queries run at once per database.

Is MariaDB handled the same way?

Almost. MariaDB has its own driver profile in Datablare with a different timeout setting. See the MariaDB page.

Ask MySQL from your AI tool

Other databases: PostgreSQL · MariaDB · SQL Server · Oracle · ClickHouse · Snowflake

Give your team answers from MySQL, read-only.

Start free with the e-commerce sample or your own database. Connect Claude in about two minutes.

30 minutes with the founder. Or WhatsApp / kamal@datablare.com