Skip to content
Datablare

Oracle MCP Server, Read-Only for Claude

A governed Oracle MCP server: read-only transactions, no PL/SQL package calls, only the schemas and tables you expose, and every agent query on record.

Setup

Connect Oracle in 5 steps

  1. Step 1: Create a reader user (recommended)

    Create datablare_reader with CREATE SESSION and SELECT on the tables you want to expose, plus a profile that limits sessions and reads. The setup screen shows the SQL.

  2. Step 2: Add Oracle as a data source

    In Settings → Project → Data connection, add a data source and pick Oracle. Enter host, port 1521, username, password and the service name (not the SID), or paste an oracle:// string.

  3. Step 3: Choose TCPS and network access

    Turn on Use SSL to connect over TCPS. Allow Datablare's IP, shown on the setup screen, or reach a database inside your network through an SSH tunnel.

  4. Step 4: Test and select tables

    Test the connection; Datablare reports what the user can do. Select the OWNER.TABLE entries agents may read and hide sensitive columns in Modeling.

  5. Step 5: Connect your AI agent

    On Connect your AI agent, add the project link to Claude, ChatGPT, Cursor, VS Code or Claude Code and sign in.

Datablare is a governed Oracle MCP server for teams who want Claude, ChatGPT, VS Code with Copilot, Cursor or Claude Code to answer questions from Oracle Database without a privileged login in anyone’s config. Each session is a read-only transaction, PL/SQL package calls are refused, agents see only the tables and columns you expose, and every query is recorded.

Oracle-specific risks for AI agents

Oracle’s reach goes well beyond tables. A model that can run arbitrary SQL under a broad user can:

  • call UTL_HTTP or HTTPURITYPE to reach the network from a SELECT;
  • run SQL passed as a string through DBMS_SQL or DBMS_XMLGEN;
  • sleep with DBMS_LOCK, holding a session open;
  • declare an autonomous transaction in a WITH FUNCTION block, which escapes a read-only transaction;
  • read SYS_CONTEXT('USERENV', …) to learn about the host and login.

A blocklist of function names can’t keep up with Oracle’s packages, so Datablare checks Oracle the other way round.

How Datablare protects Oracle

  • Read-only transaction. Every session runs SET TRANSACTION READ ONLY before any query, so Oracle refuses data changes.
  • No packages, an allow-list of functions. The guard refuses any package or method call — UTL_*, DBMS_*, OWA_*, CTX_* and others, even reached through an owner like SYS. — and accepts only built-in functions it knows. PRAGMA and identity functions such as SYS_CONTEXT and USERENV are refused.
  • DDL stopped first. Oracle commits before DDL, which would end the read-only transaction, so CREATE, ALTER, DROP and the rest are refused before reaching the database.
  • Tables and columns you choose, with hidden columns refused even when named directly.
  • Audit and revocation. Every query is logged with who asked and the SQL; keys and connections can be switched off at once.

Datablare is hosted in India and passes result rows through without storing them. See security and how it works.

Oracle notes

Thin mode, no client install

Datablare uses python-oracledb in thin mode, so no Oracle Instant Client is needed. You supply the host, port 1521, a user and the service name — for example ORCLPDB1 — not the SID.

TCPS

With Use SSL on, Datablare connects over TCPS; otherwise plain TCP.

Schemas are owners

Tables are listed as OWNER.TABLE, and the schemas Oracle ships with are left out, so a fresh connection lists your application’s tables rather than the dictionary. When an agent writes a bare name, Datablare sets the session’s current schema to the owner of the exposed table for that query, so ORDERS means APP_OWNER.ORDERS — not something in the reader’s own schema.

Create a read-only login first

CREATE USER datablare_reader IDENTIFIED BY "Choose-a-strong-password1";
GRANT CREATE SESSION TO datablare_reader;

-- One grant per table to expose:
GRANT SELECT ON app_owner.orders TO datablare_reader;
GRANT SELECT ON app_owner.customers TO datablare_reader;

-- Oracle 23ai can grant a whole schema at once:
-- GRANT SELECT ANY TABLE ON SCHEMA app_owner TO datablare_reader;

-- Limit how hard it can work (CPU and read limits need RESOURCE_LIMIT = TRUE):
CREATE PROFILE datablare_limits LIMIT
  SESSIONS_PER_USER 5
  CPU_PER_CALL 6000
  LOGICAL_READS_PER_CALL 50000000;
ALTER USER datablare_reader PROFILE datablare_limits;

To keep a column out at the database, expose a view without it and grant the view instead of the table.

Example questions

Try the flow on the e-commerce sample, then ask your Oracle data the same kind of thing:

  • What was revenue by product category in the last financial quarter?
  • Which customers placed their first order this month?
  • Which articles have had a price reduction and still sell slowly?
  • What is the average number of articles per order?

Connect Oracle to your AI tools

Create a free account, add your Oracle database, and connect Claude, ChatGPT or VS Code. See pricing for plans.

FAQ

Oracle MCP server: questions

Do I need an Oracle client installed anywhere?

No. Datablare connects with python-oracledb in thin mode, which talks to Oracle directly without Instant Client. You only provide host, port, service name and a user.

Service name or SID?

Service name, for example ORCLPDB1. Datablare does not connect by SID.

Can an agent call PL/SQL packages like UTL_HTTP or DBMS_SQL?

No. On Oracle the guard refuses every package or method call (UTL_, DBMS_, OWA_ and similar) and allows only known built-in functions. WITH FUNCTION blocks using PRAGMA are refused too.

How are schemas handled?

Tables are listed as OWNER.TABLE, and schemas that ship with the database are left out. When an agent uses a bare table name, Datablare sets the session's current schema to the exposed table's owner for that query.

Ask Oracle from your AI tool

Other databases: PostgreSQL · MySQL · MariaDB · SQL Server · ClickHouse · Snowflake

Give your team answers from Oracle, read-only.

Start free with the e-commerce sample or your own database. Connect Claude in about two minutes.

30 minutes with the founder. Or WhatsApp / kamal@datablare.com