Datablare gives you a governed SQL Server MCP server, so you can connect Claude to SQL Server or Azure SQL — and GitHub Copilot, ChatGPT, Cursor or Claude Code too — without handing any of them a raw login. Every query is checked before it runs, executed inside a transaction that is always rolled back, limited to the tables and columns you exposed, and recorded in an audit log.
Why SQL Server needs extra care
PostgreSQL and MySQL can open a session the server itself keeps read-only. SQL Server cannot. Any MCP server that connects with a login able to write relies on the model behaving. Common trouble spots:
- application logins in
db_owner, or withdb_datawriter; EXECof stored procedures that change data;SELECT … INTOcreating tables,MERGEhiding behind aWITH;OPENROWSETand linked servers reaching other systems;WAITFOR DELAYholding a worker for as long as it is told.
How Datablare protects SQL Server
Layer 1 — the guard. Only one SELECT, WITH or VALUES statement passes. EXEC, INTO, MERGE, WAITFOR, OPENROWSET, OPENDATASOURCE, OPENQUERY, OPENXML and server-identity functions such as SERVERPROPERTY and HOST_NAME are refused, and a three-part name pointing at another database is refused.
Layer 2 — the session. Every connection runs with IMPLICIT_TRANSACTIONS ON and autocommit off, and is rolled back before it closes. Nothing a statement changed can survive.
Layer 3 — your login. A db_datareader login can’t write at all. On SQL Server this is the strongest protection, and the setup screen says so.
On top: choose tables, hide columns (a hidden column is refused even when named directly), audit every query, and revoke access instantly. Datablare is hosted in India and never stores result rows. It helps you meet DPDP · GDPR · HIPAA · CCPA/CPRA · PDPL obligations when AI tools touch customer data. More on security and how it works.
SQL Server and Azure SQL notes
Azure SQL
Azure SQL refuses unencrypted logins: switch on Use SSL when you add the source. Without it, Datablare still encrypts wherever the server offers encryption. Add the IP shown on the setup screen to the server’s firewall rules.
Default schema and dbo
SQL Server has no per-session search path. A bare name like Orders resolves in the login’s default schema, then dbo. Datablare runs bare names only when the login’s default schema is the one the exposed table is in; otherwise it asks the agent to write sales.Orders. Setting the reader’s default schema to where your data lives saves round trips:
ALTER USER datablare_reader WITH DEFAULT_SCHEMA = sales;
On-premises servers
A SQL Server inside your network can be reached through an SSH tunnel: turn on Connect through an SSH tunnel, add the public key Datablare shows to your bastion, and enter the database host as the bastion sees it.
Create a read-only login first
CREATE LOGIN datablare_reader WITH PASSWORD = 'Choose-a-strong-password1';
USE [shop];
CREATE USER datablare_reader FOR LOGIN datablare_reader;
-- Covers every table and view, including ones created later
ALTER ROLE db_datareader ADD MEMBER datablare_reader;
-- Keep a column out entirely:
-- DENY SELECT ON dbo.customers (email, phone) TO datablare_reader;
To cap its CPU and memory, use a Resource Governor workload group (Enterprise edition), or point Datablare at a readable secondary.
Example questions
Try these on the e-commerce sample, then on your own SQL Server data:
- What were total sales per month for the last six months?
- Which product categories do repeat customers buy most?
- Which articles are below ten units in stock?
- Which postcodes placed the most orders last month?
Connect SQL Server to your AI tools
Sign up free, add SQL Server or Azure SQL, and connect Claude, VS Code with Copilot or ChatGPT. Plans are on pricing.