Skip to content
Datablare
Terminal

Claude Code Database MCP, Read-Only

Add a read-only Claude Code database MCP server with one command. Query Postgres and six other engines, only tables you allow, every query audited.

  • Read-only, checked by the SQL guard and kept read-only by the database.
  • Only the tables and columns you allow reach Claude Code.
  • Every query on record under the person who asked.

Setup

Set up Claude Code in 3 steps

  1. Step 1: Add the server

    Run the command from Datablare's Connect page once in a terminal: claude mcp add --transport http with your server name and project link.

  2. Step 2: Authenticate

    Start Claude Code, type /mcp, pick the Datablare server and choose Authenticate. Your browser opens: sign in to Datablare and choose Allow.

  3. Step 3: Ask about your data

    Ask Claude Code a question, for example: Using Datablare, what can you tell me from our orders data?

Datablare Connect page listing Claude, ChatGPT, Cursor, VS Code, Claude Code and other MCP clients, with the project’s MCP link and step-by-step sign-in instructions.
The Connect page in Datablare shows the exact steps and your project’s link for each tool.

To give Claude Code database access through MCP, run one command — claude mcp add --transport http with your Datablare project link — then type /mcp in Claude Code, choose Authenticate and allow it in the browser. Claude Code can then query your PostgreSQL, MySQL, Snowflake or other database while it works in your repository: read-only, limited to the tables and columns you expose, with every query in Datablare’s audit log.

The usual Claude Code postgres MCP setup, and its gaps

Searching “claude code postgres mcp” turns up local servers started with a full connection string. That is fine for a throwaway database. For anything shared it means:

  • a credential in your shell history or project config, often a superuser on dev;
  • an agent that can run whatever that login can, including writes;
  • no record of the queries outside your terminal scrollback;
  • one setup per developer, each with its own password to rotate.

What Datablare changes

Datablare is a remote MCP server; Claude Code talks to it over HTTP and never holds a database password.

  • Read-only, enforced twice. The SQL guard lets through one SELECT, WITH or VALUES statement and nothing else — no COPY, SET, DO, CALL, pg_sleep or dblink. Then the database itself keeps it read-only: a read-only session, or an always rolled-back transaction on SQL Server and Snowflake.
  • Scoped per project. Expose only the tables the work needs; hide columns with personal data. A bare name like orders resolves only to an exposed table, never to an unexposed one that happens to come first in the search path.
  • Bounded. 1,000 rows by default, 5,000 at most; 30 seconds by default, 60 at most.
  • Audited. Every call is recorded under your name in Audit.
  • Revocable. Disconnect from the Connect page, revoke a key, or have an admin remove access — it stops.

Datablare is hosted in India and does not store result rows. More: how it works, security.

The command

The Connect page fills in your server name and link:

claude mcp add --transport http datablare-your-project \
  https://app.datablare.com/mcp/your-company/your-project/

Then, inside Claude Code:

/mcp

Pick the Datablare server, choose Authenticate, sign in and click Allow.

With a personal key

For CI jobs or remote machines without a browser, use a personal key instead of signing in:

claude mcp add --transport http datablare-your-project \
  https://app.datablare.com/mcp/your-company/your-project/ \
  --header "Authorization: Bearer dblr_..."

Name the key after what uses it (“Claude Code on build box”) so you can switch one off without the others.

What Claude Code can call

Datablare exposes a small set of tools: list your projects and data sources, list the exposed tables, read the context you wrote (descriptions, rules, example questions), and run a read query. Good context — “amount is in paise”, “exclude test orders” — makes the SQL right the first time.

Create a read-only login first

Give Datablare its own Postgres role, then prove it cannot write before you connect it:

CREATE ROLE datablare_reader LOGIN PASSWORD 'choose-a-strong-password'
  CONNECTION LIMIT 5;
ALTER ROLE datablare_reader SET idle_in_transaction_session_timeout = '60s';
GRANT USAGE ON SCHEMA public TO datablare_reader;
GRANT SELECT ON ALL TABLES IN SCHEMA public TO datablare_reader;

-- Signed in as datablare_reader, this must fail with "permission denied":
-- INSERT INTO public.orders DEFAULT VALUES;

Datablare’s connection test also reports whether the login can only read. Other engines: PostgreSQL, MySQL, Snowflake.

Try it on the e-commerce sample

Connect the one-click sample, then ask Claude Code:

  • Which articles have a reduced price, and by how much on average?
  • How many orders were placed per day last week?
  • Which product labels have no active products?

Get started

Sign up free, copy the command from the Connect page, and authenticate. See pricing for plans, or set up Cursor or VS Code next.

FAQ

Claude Code and Datablare: questions

Can I use a key instead of the browser sign-in?

Yes. Create a personal key on the Connect page and add --header "Authorization: Bearer <your key>" to the claude mcp add command. The key is shown once; revoke it any time and it stops working immediately.

Can Claude Code write to my Postgres database through Datablare?

No. Datablare refuses anything that is not a single read, and every PostgreSQL connection is opened with default_transaction_read_only on, so Postgres itself rejects writes.

Does the database have to be reachable from my laptop?

No. Datablare connects to the database from its own servers, so Claude Code only needs to reach Datablare. The database must allow Datablare's IP or be reached through an SSH tunnel.

Where can I see what Claude Code ran?

In Datablare's Audit page: every call with who asked, the question, the SQL, the outcome, rows and time.

Connect Claude Code to your database today.

Start free with the e-commerce sample or your own database. Connect Claude in about two minutes.

30 minutes with the founder. Or WhatsApp / [email protected]