Databases

MCP Toolbox for Databases: one server for 20+ databases

Google's open-source database MCP server: one flag connects Postgres, MySQL, BigQuery and more, and a YAML file defines safe tools that run only fixed SQL.

Project and installation docs

View project

https://github.com/googleapis/mcp-toolbox

A team with Postgres, BigQuery and Redis that picks a separate MCP server for each soon ends up with a mess of configs and permissions. MCP Toolbox for Databases, maintained under Google’s googleapis organization, covers more than twenty data sources from one server. During development you query with ready-made tools; in production a config file pins down exactly which SQL an agent may run. It had about 17k stars as of 2026-10-06.

What it does

  • Prebuilt tools: a flag like --prebuilt=postgres gives generic tools such as list_tables and execute_sql, and --prebuilt=postgres/data loads only the SQL toolset; the Google Antigravity MCP Store also offers one-click install for these.
  • Wide coverage: AlloyDB, BigQuery, Cloud SQL, Spanner, Firestore and Knowledge Catalog (formerly Dataplex) on Google Cloud, plus PostgreSQL, MySQL, MariaDB, SQL Server, Oracle, MongoDB, Redis, Elasticsearch, CockroachDB, ClickHouse, Couchbase, Neo4j, Snowflake, Trino and more — over twenty sources in all.
  • Custom tools: declare sources and parameterized SQL statements in tools.yaml, and the agent can call only the queries you wrote; official Python, JS/TS, Go and Java SDKs wire these tools into ADK, LangChain or LlamaIndex in under ten lines of code.
  • Production plumbing: connection pooling, IAM auth, and OpenTelemetry metrics and tracing built in; a --ui flag opens a web console for testing tools and toolsets by hand, and skills-generate packages a toolset as an Agent Skill you can install straight into Gemini CLI.

Who it’s for

  • Developers who want to query data and inspect schemas from Claude Code or Gemini CLI, especially on Google Cloud databases.
  • Backend engineers exposing a database to a production agent that may run only reviewed queries.
  • Application developers wiring database tools into ADK, LangChain or LlamaIndex who don’t want to write separate connection and auth logic for each data source.

Setup

Needs Node.js, plus the connection environment variables for your database (see the docs). For Postgres:

{
  "mcpServers": {
    "toolbox-postgres": {
      "command": "npx",
      "args": ["-y", "@toolbox-sdk/server", "--prebuilt=postgres", "--stdio"]
    }
  }
}

Besides running it with npx, the README also covers binary and container-image installs for longer-running deployments; the repo was recently renamed from genai-toolbox to mcp-toolbox, so an existing deployment needs its git remote updated on upgrade.

Our take

Most database servers handle one engine; this one’s value is uniformity, with the same config style, auth and observability everywhere, so switching databases means changing one flag. It also separates “query freely while developing” from “run only fixed SQL in production”, and the second mode is far safer than handing an agent an all-purpose execute_sql. It predates MCP itself under the name Gen AI Toolbox for Databases and was renamed once MCP compatibility landed. Note that the prebuilt execute_sql runs whatever SQL the model sends, so connect with a read-only role; for deep single-engine features such as the index tuning in Postgres MCP Pro, a dedicated server goes further. Licensed Apache-2.0.