tokenlite-mysql-mcp

tokenlite-mysql-mcp

Secure and token-efficient MySQL MCP server built specifically for AI agents. Prevents hallucinations, optimizes context windows and blocks dangerous queries.

Category
访问服务器

README

TokenLite MySQL MCP

npm version

A robust and secure MySQL database server implemented under Anthropic's Model Context Protocol (MCP). Designed specifically to solve the shortcomings of current generic MCP servers through Graceful Degradation, Active Performance Protection, and Aggressive Token Optimization.


🌟 Core Pillars

  1. Safe-Query Optimizer (AST & EXPLAIN): Protects production databases by pre-analyzing queries. Blocks unindexed Full Table Scans that exceed configurable thresholds and injects strict LIMIT clauses automatically at the AST level.
  2. Granular AST-Based Write Permissions: By default, TokenLite is 100% Read-Only. You can surgically enable specific write operations (INSERT, UPDATE, DELETE, DDL) via environment variables. The firewall uses strict AST parsing to prevent SQL injection and comment-bypass attacks, and strictly prohibits privilege escalation commands (like GRANT or CALL).
  3. Session-Level Defense in Depth: If the server is configured in strict Read-Only mode (all write variables disabled), TokenLite injects SET SESSION TRANSACTION READ ONLY directly into the connection pool sockets. This guarantees that even if a theoretical bypass exists in the AST parser, the MySQL engine itself will physically reject any data modification.
  4. Business Intelligence Injection: Bridges the gap between raw data and company logic. Automatically attaches semantic dictionaries (metadata.json) to database schema exploration, and exposes Semantic Templates via the official MCP Prompts API (templates.json) so the LLM uses pre-approved analytical queries instead of hallucinating them.
  5. Graph-Based Semantic Schema: Avoids sending giant schemas to the LLM that saturate the context window. When a table is searched, the engine uses heuristics to deduce implicit relationships and packages the exact "Auto-Join Context".
  6. CSV Token Compression: Database results are efficiently transformed into tabular CSV markdown with unambiguous NULL representation (), saving up to 50% of Output Tokens compared to verbose JSON.

📋 Requirements

  • Node.js v20 or higher
  • MySQL 5.7 or higher (MySQL 8.0+ recommended)
  • A MySQL user with SELECT and SHOW VIEW privileges.

🚀 Installation & Usage

You can use this MCP server with any compatible client. Below are the configurations for the most popular ones.

1. Claude Desktop

Edit your claude_desktop_config.json (usually located at %APPDATA%\Claude\claude_desktop_config.json on Windows or ~/Library/Application Support/Claude/claude_desktop_config.json on macOS) and add the following:

Using NPX (Recommended)

{
  "mcpServers": {
    "tokenlite-mysql": {
      "command": "npx",
      "args": [
        "-y",
        "@andezdev/tokenlite-mysql-mcp"
      ],
      "env": {
        "DB_HOST": "localhost",
        "DB_PORT": "3306",
        "DB_USER": "your_db_user",
        "DB_PASSWORD": "your_password",
        "DB_NAME": "your_database",
        "MCP_SAFE_QUERY_MAX_ROWS": "1000",
        "MCP_SAFE_QUERY_ENABLE_BLOCKING": "true"
      }
    }
  }
}

2. Claude Code (CLI)

You can easily integrate this server globally into Claude Code:

claude mcp add tokenlite_mysql \
  -e DB_HOST="127.0.0.1" \
  -e DB_PORT="3306" \
  -e DB_USER="root" \
  -e DB_PASSWORD="your_password" \
  -e DB_NAME="your_database" \
  -- npx -y @andezdev/tokenlite-mysql-mcp

3. Cursor IDE

To use within Cursor IDE:

  1. Open Cursor Settings > Features > MCP.
  2. Click + Add New MCP Server.
  3. Set the Type to command.
  4. Name it tokenlite-mysql.
  5. Set the command to:
    npx -y @andezdev/tokenlite-mysql-mcp
    

(Note: Cursor handles environment variables directly in the IDE UI, make sure to add your DB credentials there).


⚙️ Environment Variables Reference

Variable Description Default Required
DB_HOST MySQL Host address localhost No
DB_PORT MySQL Port 3306 No
DB_USER MySQL Username root No
DB_PASSWORD MySQL Password '' No
DB_NAME MySQL Database name test Yes
MCP_SAFE_QUERY_MAX_ROWS Threshold for EXPLAIN to block unindexed Full Table Scans. 1000 No
MCP_SAFE_QUERY_ENABLE_BLOCKING Enable or disable the EXPLAIN guardrail. true No
MCP_METADATA_PATH Absolute path to your custom metadata.json dictionary. (Disabled) No
MCP_TEMPLATES_PATH Absolute path to your custom templates.json queries. (Disabled) No
TOOL_PREFIX Prefix for tool names (useful when running multiple instances). Derived from DB_NAME (e.g., mydb_). Random fallback only if DB_NAME is unset. No
MCP_RATE_LIMIT_RPM Max tool invocations per minute (sliding window). Set to 0 to disable. 60 No
MYSQL_QUERY_TIMEOUT Max execution time for a query (in ms). Aborts heavy queries to protect against DoS. 15000 No
MYSQL_CONNECTION_LIMIT Max concurrent pool connections. 10 No
MYSQL_CONNECT_TIMEOUT Max time to wait for a socket to establish (in ms). 10000 No
MYSQL_RETRY_ATTEMPTS Max retries on transient connection errors (ECONNREFUSED, PROTOCOL_CONNECTION_LOST, etc.). 3 No
MYSQL_RETRY_DELAY_MS Base delay (ms) for exponential backoff between retries (1s, 2s, 4s...). 1000 No
MYSQL_QUEUE_LIMIT Max queued requests when all pool connections are busy. Prevents unbounded growth if MySQL is down. 50 No
MCP_DDL_CACHE_TTL Time-to-live (in seconds) for cached DDL statements. Reduces latency on repeated search_schema calls. Invalidated by refresh_schema. 60 No
MCP_LOG_LEVEL Minimum severity for MCP log notifications: debug, info, notice, warning, error, critical, alert, emergency. info No
ALLOW_INSERT_OPERATION Enable INSERT and REPLACE queries. false No
ALLOW_UPDATE_OPERATION Enable UPDATE queries. false No
ALLOW_DELETE_OPERATION Enable DELETE and TRUNCATE queries. false No
ALLOW_DDL_OPERATION Enable Data Definition Language (CREATE, ALTER, DROP, RENAME). false No

🛡️ Business Intelligence Features (Opt-in)

TokenLite can teach the LLM about your company's business rules. To enable this, map the absolute paths of two JSON files via .env or your MCP client config:

metadata.json (Semantic Dictionary)

Translate integer statuses or internal jargon so the LLM understands the data.

{
  "orders.status": {
    "pending": "The order is waiting for payment validation",
    "shipped": "The order has left the warehouse"
  }
}

Custom Relationships

Define FK mappings the heuristic engine can't auto-detect (e.g., created_by → users). Add a _relationships key to your metadata.json:

{
  "orders.status": { "pending": "...", "shipped": "..." },
  "_relationships": {
    "orders.created_by": "users.id",
    "categories.parent_id": "categories.id"
  }
}

These are treated as authoritative (not heuristic) and take priority over automatic detection.

The heuristic engine also assigns a confidence score (0–100) to each inferred FK based on name matching (+40), data type validation (+30), primary key verification (+20), and index presence (+10). Only FKs scoring ≥70 are accepted.

templates.json (Pre-approved SQL)

Stop the LLM from hallucinating complex metrics by providing vetted templates.

[
  {
    "name": "Customer Lifetime Value (LTV)",
    "description": "Calculates total revenue generated by delivered orders per customer.",
    "sql": "SELECT c.id, SUM(oi.price) FROM customers c JOIN orders o... WHERE o.status='delivered'"
  }
]

📈 Benchmarks & Token Savings

TokenLite includes an automated benchmark suite using o200k_base tokenization (GPT-4o/GPT-5 standard) to measure efficiency improvements. Token counts are approximate — Claude 4.x uses a proprietary tokenizer; actual counts may vary slightly.

To run the benchmark in your own environment:

npm run benchmark

Baseline: Standard MCP Pattern

The benchmark compares against the standard pattern used by generic MySQL MCP servers: full schema exposed as information_schema.columns in pretty-printed JSON, and query results returned as JSON.stringify(rows, null, 2) with execution time metadata.

1. Schema Discovery (Input Tokens)

Standard MCP servers dump the entire schema to the LLM. For large databases, this consumes thousands of input tokens on every turn. TokenLite's relational graph serves a localized Auto-Join Context (target table + direct parent tables + direct child tables).

Scenario Standard MCP Pattern TokenLite 📉 Savings
Mock (50 tables, Enterprise CRM) 15,566 tokens 883 tokens 94.3%
Live (9 tables, Test DB) 2,208 tokens 531 tokens 75.9%

Savings scale with the number of tables: the more tables in the database, the higher the savings because the standard pattern dumps all of them while TokenLite only fetches the target + 1-hop relationships.

2. Query Result Payloads (Output Tokens)

TokenLite converts raw database rows to a dense, structured CSV layout. This avoids JSON syntax overhead (brackets, braces, repeated keys) and compresses the output payload returned to the LLM.

Mock data (varied: NULLs, long descriptions, mixed lengths):

Rows Returned Standard MCP Pattern (Tokens) TokenLite CSV (Tokens) 📉 Output Savings (%)
10 rows 1,167 601 48.5%
50 rows 5,803 2,927 49.6%
100 rows 11,607 5,842 49.7%
500 rows 57,990 29,119 49.8%

Live data (real MySQL test database with NULLs, ENUMs, variable-length text):

Rows Returned Standard MCP Pattern (Tokens) TokenLite CSV (Tokens) 📉 Output Savings (%)
10 rows 1,007 628 37.6%
50 rows 5,029 3,114 38.1%
100 rows 10,071 6,232 38.1%
500 rows 50,327 31,116 38.2%

📊 Logging & Observability

TokenLite uses MCP-native logging via notifications/message instead of raw stderr output. Clients that support MCP logging (e.g., MCP Inspector) will receive structured log messages with severity levels, logger names, and JSON data.

Severity levels (from least to most severe): debug, info, notice, warning, error, critical, alert, emergency.

The server emits logs at info level and above by default. Control the minimum level via MCP_LOG_LEVEL or dynamically at runtime through the MCP logging/setLevel request.

Before the MCP session is established (e.g., during pool initialization), logs fall back to stderr.


🌐 Advanced Networking & Remote Connections

By design, tokenlite-mysql-mcp adheres to the Unix philosophy: it does one thing (AI-driven MySQL interactions) and does it securely via the standard stdio transport. It deliberately avoids bloating the codebase with HTTP servers or built-in SSH clients.

If you need to connect to remote databases or expose this server over the network, here are the recommended, enterprise-grade alternatives:

1. Connecting to Remote Databases (SSH Tunnels)

Instead of embedding SSH libraries, we recommend using native OS tunnels. This is much more secure, respects your ~/.ssh/config, and supports advanced authentication (2FA, hardware keys).

Simply open a terminal and run:

ssh -N -L 3306:127.0.0.1:3306 user@your-remote-server.com

Then, point tokenlite-mysql-mcp to localhost and port 3306.

2. Exposing the MCP Server over HTTP/Network

If you need to host this MCP Server in the cloud (AWS, GCP) and have multiple Claude desktop clients connect to it remotely via HTTP/SSE, do not modify this codebase to add Express/HTTP logic. Instead, wrap the process using standard open-source MCP proxies like mcp-proxy. This cleanly separates the transport layer security from the AI logic.

🐛 Troubleshooting

Error: OptimizerError: Full table scan detected... The LLM attempted to execute a query that requires scanning thousands of rows without using an index. Solution: Use explain_query to see the full EXPLAIN output and understand why the query was blocked. Rewrite the query with an indexed WHERE clause. If you truly need to scan the whole table, increase MCP_SAFE_QUERY_MAX_ROWS in your config.

Error: calling "initialize": invalid character... This means the MCP JSON-RPC protocol crashed. Ensure you are passing the correct DB credentials and that the database is running and accessible from the machine where the MCP server runs.


Built for the AI Engineering era.


推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选