dbackup-mcp
A typed MCP server for curated backup administration of DBackup via its API, exposing tools for backup jobs, execution history, notifications, storage, and bounded restore workflows.
README
dbackup-mcp
A typed Model Context Protocol server for curated backup administration of DBackup through its authenticated API.
This community project is not affiliated with or endorsed by the DBackup project. DBackup is licensed under GPL-3.0; dbackup-mcp is a separate integration project licensed under MIT.
What it covers
dbackup-mcp exposes explicit MCP workflows instead of a generic HTTP escape hatch. The current source package version is 0.1.0 and exposes 43 curated tools across:
- backup jobs and read-only job planning;
- execution history, cancellation and notification logs;
- database, storage and notification adapters;
- credential-profile references without credential reveal;
- backup inspection, verification and bounded restore workflows;
- capability and health diagnostics.
The server deliberately excludes raw HTTP, credential reveal, backup download/deletion, API-key administration, user/RBAC/SSO administration and unsupported DBackup UI-internal server actions.
See the complete Tool reference for every tool, mutation classification, destructive semantics, permissions and important guards.
Requirements
- Python
3.12+ - DBackup
3.2.0as the tested and supported baseline; other versions are unverified unless explicitly documented - a DBackup API key with only the permissions required by the enabled MCP workflows
- an MCP client or gateway that supports STDIO servers
uvfor the documented source workflow
Configuration
| Variable | Required | Default | Meaning |
|---|---|---|---|
DBACKUP_BASE_URL |
yes | - | DBackup HTTP(S) origin without /api, for example https://backup.example.com. |
DBACKUP_API_KEY_FILE |
yes | - | Private regular file containing one DBackup API key. Group/other permissions are rejected. |
DBACKUP_CREDENTIAL_SECRET_DIR |
no | - | Private directory containing mode-0600 JSON credential payload files for explicit credential create/update tools. |
DBACKUP_REQUEST_TIMEOUT_SECONDS |
no | 15 |
Per-request timeout in seconds, greater than zero and at most 120. |
Example MCP registration from an installed package:
{
"mcpServers": {
"dbackup": {
"command": "dbackup-mcp",
"env": {
"DBACKUP_BASE_URL": "https://backup.example.com",
"DBACKUP_API_KEY_FILE": "/run/secrets/dbackup-api-key",
"DBACKUP_CREDENTIAL_SECRET_DIR": "/run/secrets/dbackup-credentials"
}
}
}
}
Omit DBACKUP_CREDENTIAL_SECRET_DIR when the MCP should not create or update DBackup credential profiles from local secret files.
Running from source
The repository includes uv.lock for a reproducible source environment.
uv sync --frozen --extra test
DBACKUP_BASE_URL=https://backup.example.com \
DBACKUP_API_KEY_FILE=/run/secrets/dbackup-api-key \
uv run --frozen dbackup-mcp
A gateway can also launch the checkout with uv run --frozen --directory /path/to/dbackup-mcp dbackup-mcp and the same environment variables.
Permissions
DBackup remains the authorization boundary. Grant only the permissions required by the workflows exposed to a given MCP consumer; a gateway can further restrict the visible tool set.
The full 43-tool surface can require job, history, source, destination, notification, storage/restore and credential-reference permissions. It does not require credential reveal, backup download/delete, API-key administration, user/RBAC/SSO administration or recovery-kit access. See the Tool reference for the exact full-surface permission set.
Security
- API keys and credential payloads are file-backed and are never accepted as plaintext MCP arguments.
- Secret input files must be private regular files; adapter inputs reject DBackup-sensitive configuration keys and use credential-profile references instead.
- DBackup responses and error details are sanitized before model-visible output is returned.
- No generic request escape hatch exists.
- Destructive tools are explicitly annotated and confirmation is enforced where required; selected-file restore supports a dry-run path.
- All tools publish
openWorldHint=false.
See SECURITY.md for vulnerability reporting and the maintained security boundary.
Compatibility
DBackup 3.2.0 is the tested and supported baseline. The bundled OpenAPI description does not fully cover directory-job and granular file-restore behavior, so this project keeps a small source-verified 3.2.0 compatibility layer covered by contract tests.
Some objects used by DBackup's web job editor are available only through application-internal server actions rather than public API-key REST discovery. dbackup-mcp does not depend on those internal UI actions; known IDs may be supplied where the public job API accepts them. See the Tool reference for details.
Development and release
Run the repository-local verification entry point:
./scripts/verify.sh
GitHub Actions uses the same verification path. Dependabot maintains the locked dependency set within accepted compatibility ranges.
Normal development does not publish a release. An accepted strict SemVer tag (vMAJOR.MINOR.PATCH) triggers the release workflow, which fails closed while the repository is private, verifies the tag and package version, reruns verification, builds reproducible wheel/source artifacts plus SHA256SUMS, and publishes a GitHub Release. It does not publish to PyPI.
License
MIT. See LICENSE.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。