MCP Server
MCP
Midplane
Safe-by-default SQL guardrails for AI agents: AST-checked queries, per-table policy, audit log.
Install
npx -y [email protected]
Configuration Example
{
"remotes": [],
"packages": [
{
"registryType": "npm",
"registryBaseUrl": "https://registry.npmjs.org",
"identifier": "midplane",
"version": "0.19.0",
"runtimeHint": "npx",
"transport": {
"type": "stdio"
},
"packageArguments": [
{
"value": "server",
"type": "positional",
"valueHint": "subcommand"
},
{
"type": "named",
"name": "--stdio"
}
],
"environmentVariables": [
{
"description": "Postgres connection string the agent's queries run against. Give it a least-privilege role: Midplane constrains what SQL is allowed, it does not widen or narrow what the role itself can reach.",
"isRequired": true,
"format": "string",
"isSecret": true,
"name": "DATABASE_URL"
},
{
"description": "Path to a policy YAML granting per-table read/read_write access, tenant scoping, and column masking. Omit for the safe default: reads allowed, writes and DDL denied. Generate one with `npx midplane init`.",
"format": "filepath",
"name": "MIDPLANE_POLICY_FILE"
},
{
"description": "Where the local SQLite audit log is written. Defaults to ~/.midplane/audit.db; read it back with `midplane audit denies`.",
"format": "filepath",
"name": "DB_PATH"
},
{
"description": "Set to 0 to disable anonymous usage telemetry (DO_NOT_TRACK=1 also works). Never includes SQL, table or column names, or identifiers.",
"default": "1",
"choices": [
"1",
"0",
"debug"
],
"name": "MIDPLANE_TELEMETRY"
}
]
},
{
"registryType": "oci",
"identifier": "docker.io/midplane/midplane:0.19.0",
"runtimeHint": "docker",
"transport": {
"type": "streamable-http",
"url": "http://localhost:8080/mcp"
},
"environmentVariables": [
{
"description": "Postgres connection string the agent's queries run against. Pass it with --env-file, never with an inline -e: a DSN on the docker command line leaks the password to `ps aux` and your shell history.",
"isRequired": true,
"format": "string",
"isSecret": true,
"name": "DATABASE_URL"
},
{
"description": "Path (inside the container) to a policy YAML granting per-table read/read_write access, tenant scoping, and column masking. Omit for the safe default: reads allowed, writes and DDL denied.",
"format": "filepath",
"name": "MIDPLANE_POLICY_FILE"
},
{
"description": "Port the Streamable HTTP transport binds. Must match the url above if changed.",
"default": "8080",
"name": "PORT"
}
]
}
]
}
mcp
model-context-protocol
npm
oci
By
Comments
Sign in to leave a comment