Skip to content
Datablare
VS Code with GitHub Copilot

VS Code MCP Database for GitHub Copilot

Give GitHub Copilot a read-only VS Code MCP database connection: SQL Server, Postgres and more, only the tables you allow, every query on record.

  • Read-only, checked by the SQL guard and kept read-only by the database.
  • Only the tables and columns you allow reach VS Code.
  • Every query on record under the person who asked.

Setup

Set up VS Code in 3 steps

  1. Step 1: Add Datablare to VS Code

    On Datablare's Connect page, choose VS Code and click Add to VS Code. Or run MCP: Add Server from the Command Palette, choose HTTP and paste your project's link, or add it to .vscode/mcp.json.

  2. Step 2: Sign in for Datablare

    When VS Code asks to sign in for Datablare, click Allow, sign in to Datablare in the browser and choose Allow again.

  3. Step 3: Ask Copilot in Agent mode

    Open Copilot Chat, switch to Agent mode and ask, for example: Using Datablare, what can you tell me from our sales data?

Datablare Connect page listing Claude, ChatGPT, Cursor, VS Code, Claude Code and other MCP clients, with the project’s MCP link and step-by-step sign-in instructions.
The Connect page in Datablare shows the exact steps and your project’s link for each tool.

The quickest VS Code MCP database setup is to click Add to VS Code on Datablare’s Connect page, approve the sign-in, and ask GitHub Copilot in Agent mode. Copilot can then query SQL Server, PostgreSQL, Oracle and the other supported engines through Datablare — read-only, scoped to the tables and columns your team exposes, and logged under each developer’s name. No connection string goes into your workspace.

What goes wrong with a local database MCP server

Many “github copilot mcp sql server” guides wire VS Code to a local MCP server holding a SQL Server login. In a shared repository that tends to spread: the config is copied between machines, the login is the one that was handy (often with write rights), and Copilot’s agent is free to try any statement the login allows. If someone later asks what the agent read from production, there is no answer.

What Datablare gives a Copilot team

  • One link, personal sign-in. The workspace config holds the project link. Each developer signs in to Datablare with OAuth and gets exactly their own access.
  • Read-only, enforced twice. The SQL guard refuses writes, EXEC, SELECT … INTO, MERGE, WAITFOR, OPENROWSET and multiple statements. What passes runs in a session that cannot keep a change.
  • Down to the column. Expose the tables Copilot needs; hide columns like email or phone. Hidden columns are refused even when named directly.
  • Every query on record. Audit shows each call — who, the question, the SQL, outcome, rows, time — and the connection appears under Connected on the Connect page, labelled with the name VS Code gives itself.
  • Revocable. Disconnect it there, revoke a key, or remove the person; access stops.

Datablare is hosted in India and never stores query results. Details: how it works, security.

The VS Code configuration

.vscode/mcp.json for sign-in:

{
  "servers": {
    "datablare-your-project": {
      "type": "http",
      "url": "https://app.datablare.com/mcp/your-company/your-project/"
    }
  }
}

Need a key instead — for example in a dev container that cannot open a browser? Open Can’t sign in? Use a personal key on the Connect page; it shows the same block with an Authorization: Bearer header. Keys are shown once and stop working the moment they are revoked.

SQL Server specifics

Copilot tends to write bare table names like Orders. On SQL Server those resolve in the login’s default schema, so Datablare runs them only when that default is the schema the exposed table lives in; otherwise it asks for schema.table. Writing names in full (sales.Orders) avoids the round trip. Azure SQL needs Use SSL on. More on the SQL Server page.

Create a read-only login first

SQL Server has no read-only session, so a reader login matters more here. In the target database:

CREATE LOGIN datablare_reader WITH PASSWORD = 'Choose-a-strong-password1';

USE [your_database];
CREATE USER datablare_reader FOR LOGIN datablare_reader;
ALTER ROLE db_datareader ADD MEMBER datablare_reader;

-- Keep a column out entirely:
-- DENY SELECT ON dbo.customers (email, phone) TO datablare_reader;

db_datareader covers tables and views created later too. Using PostgreSQL or Oracle instead? See PostgreSQL and Oracle.

Questions to try on the e-commerce sample

Connect the one-click sample and ask Copilot:

  • Which products in the Electronics category are currently active?
  • What is the revenue per colour for last month?
  • Which customers have more than one shipping address?

Open Audit afterwards to review the SQL Copilot generated.

Start

Sign up free, click Add to VS Code, and sign in. Plans are on pricing. Also see Cursor and Claude Code.

FAQ

VS Code and Datablare: questions

Does this work with GitHub Copilot?

Yes. Datablare is a remote MCP server over HTTP, which VS Code adds for Copilot Chat in Agent mode. Sign-in uses OAuth, so no secret goes into mcp.json.

Can I commit .vscode/mcp.json to the repository?

The sign-in version contains only your project's link, not a password or key, and each developer signs in with their own Datablare account. A configuration with a personal key in it should not be committed.

Will Copilot be able to modify my SQL Server database?

No. Datablare's guard refuses anything but a single read, and on SQL Server every query runs inside a transaction that is always rolled back. A login in db_datareader adds a third layer.

Can different developers see different tables?

Yes. Access follows each person's Datablare role and project; a manager can also limit someone to certain data sources within a project.

Connect VS Code to your database today.

Start free with the e-commerce sample or your own database. Connect Claude in about two minutes.

30 minutes with the founder. Or WhatsApp / kamal@datablare.com