mssql-mcp
A read-only MCP server for Microsoft SQL Server that allows running SELECT queries and analyzing query performance with statistics.
README
mssql-mcp
A read-only MCP server for Microsoft SQL Server. It lets an MCP client run
SELECT queries against a database and inspect how those queries perform.
It provides two main capabilities:
- Run
SELECTqueries and return the rows as JSON. - Analyze a
SELECTunderSET STATISTICS XML/IO/TIMEand return performance data as JSON: estimated vs. actual rows, logical and physical reads, statement timing, missing-index suggestions, and plan warnings.
For a local Docker/Colima setup, see
local-readme.md. This document covers a Windows machine connecting to a remote SQL Server.
Tools
| Tool | Description |
|---|---|
query |
Run a single SELECT and return the rows as JSON. |
analyze_query |
Run a SELECT with statistics collection enabled and return performance metrics. |
list_tables |
List tables and views in the current database. |
describe_table |
Column names, types, nullability, and defaults for a table. |
By default only SELECT and WITH statements are permitted. See
Security.
Requirements
- Node.js 18 or later. Install the LTS build from https://nodejs.org and
confirm with
node -v. - Network access from this machine to the SQL Server. The default port is TCP 1433; make sure any firewall between the two allows it.
- A SQL Server Authentication login (username and password) with read access to the target database.
Setup
Open PowerShell in the project folder and run:
cd C:\Tools\mssql-mcp
copy .env.example .env
npm install
npm run build
Then edit .env with the details for your server (see the next section).
Connecting to a remote server
.env holds the connection settings. It is git-ignored and is the only place
credentials are stored.
MSSQL_SERVER=sqlserver.corp.example.com
MSSQL_PORT=1433
MSSQL_USER=reporting_user
MSSQL_PASSWORD=your-password
MSSQL_DATABASE=Sales
MSSQL_ENCRYPT=true
MSSQL_TRUST_SERVER_CERT=false
MSSQL_SERVERcan be a hostname, fully qualified domain name, or IP address. For a named instance, useHOST\INSTANCEand setMSSQL_PORTto that instance's port.MSSQL_ENCRYPT=trueencrypts the connection. Keep it on for a remote server.MSSQL_TRUST_SERVER_CERT=falserequires the server to present a certificate your machine already trusts. Set it totrueonly when the server uses a self-signed certificate.- To point at a different server or database later, edit
.envand restart the client.
Verify the connection before wiring up a client:
node dist\index.js
It prints a readiness line to standard error and then waits for input. Press Ctrl+C to stop. If the connection fails, the error message states the reason.
Registering with a client
The client starts the server as a subprocess and communicates over standard
input/output. Credentials stay in .env; the client configuration holds no
secrets.
opencode (opencode.json):
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"mssql": {
"type": "local",
"command": ["node", "C:\\Tools\\mssql-mcp\\dist\\index.js"],
"enabled": true
}
}
}
Claude Code (.mcp.json):
{
"mcpServers": {
"mssql": {
"command": "node",
"args": ["C:\\Tools\\mssql-mcp\\dist\\index.js"]
}
}
}
Use the full path to dist\index.js, and double the backslashes in JSON. Start
the client from the folder that contains its configuration file. Any env
values set in the client configuration take precedence over .env.
analyze_query output
{
"row_count": 100,
"truncated": false,
"rows": [ /* result rows, capped at maxRows */ ],
"timing": { "cpu_ms": 53, "elapsed_ms": 53 },
"io_by_table": [
{ "table": "Orders", "scan_count": 1, "logical_reads": 283,
"physical_reads": 0, "read_ahead_reads": 0 }
],
"statement": { "est_rows": 100, "subtree_cost": 0.30 },
"operators": [
{ "node_id": 0, "parent_node_id": null, "depth": 0,
"physical_op": "Sort", "cost_pct": 100 },
{ "node_id": 1, "parent_node_id": 0, "depth": 1,
"physical_op": "Clustered Index Scan",
"est_rows": 100, "actual_rows": 100, "rows_read": 50000,
"actual_logical_reads": 283, "cost_pct": 88 }
],
"missing_indexes": [
{ "impact_pct": 94.6, "table": "dbo.Orders",
"create": "CREATE INDEX IX_Orders_CustomerId ON [dbo].[Orders] ([CustomerId]) INCLUDE ([Amount]);" }
],
"warnings": []
}
Reads and timing come from the plan's runtime counters (ActualLogicalReads,
QueryTimeStats). io_by_table is parsed from the STATISTICS IO messages, so
it matches the Messages tab in SQL Server Management Studio.
Operators are returned in tree order. Each carries node_id, parent_node_id,
and depth. The root (node_id 0) is the final step and runs last; the deepest
leaf runs first and feeds its parent up toward the root.
Logging
Set MSSQL_LOG=true in .env to append a record of every tool call, including
the arguments received and the result returned, to mssql-mcp\mcp.log. The file
is git-ignored.
[2026-07-05T15:06:26Z] CALL #2 query
INPUT (from client):
{ "sql": "SELECT TOP 2 name FROM sys.tables ORDER BY name" }
[2026-07-05T15:06:27Z] DONE #2 query · 1002 ms
OUTPUT (to client):
{ "row_count": 2, "rows": [ { "name": "Orders" } ] }
Each call is numbered so a request and its response can be matched even when
calls overlap. Set MSSQL_LOG_FILE for a custom path and MSSQL_LOG_MAX for the
maximum characters per entry before truncation (default 20000).
To follow the log live in PowerShell:
Get-Content .\mcp.log -Wait
Rate limiting
Two limits guard against overloading the server, both configured in .env:
MSSQL_RATE_MAXrequests perMSSQL_RATE_WINDOW_MSmilliseconds.MSSQL_MAX_CONCURRENTqueries in flight at once.
Set any of them to 0 to disable that limit. When a limit is reached, the tool
returns an error with a retry hint and does not contact the database.
Security
MSSQL_READONLY=true (the default) rejects anything that is not a single
SELECT or WITH statement and blocks write and DDL keywords. This is a
convenience check, not a replacement for database permissions.
Enforce read-only access at the server by connecting with a login that has read rights only:
CREATE LOGIN reporting_user WITH PASSWORD = 'your-password';
CREATE USER reporting_user FOR LOGIN reporting_user;
ALTER ROLE db_datareader ADD MEMBER reporting_user;
Point MSSQL_USER and MSSQL_PASSWORD at that login. Set MSSQL_READONLY=false
only when you intend to allow writes.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。