Agents (MCP)
Requires Pro
ElyraSQL Client can act as an MCP server, the protocol AI agents such as
Claude Code use to reach tools. An agent can then read the databases you have
saved here: list tables, describe them, and run SELECTs. It does that through
the connection you already set up, without a connection string of its own.
Why this rather than giving the agent a password:
- The password stays in the keychain. The agent names a connection, for
example
Shop. The client looks up the password itself and never sends it to the agent. - Nothing is shared until you tick it. Each connection is opt-in.
- Reads only. Writes are refused, whatever the agent sends.
- You can see what it ran. Every agent query lands in your History, marked agent.
Set it up
- Open Settings (⌘/Ctrl + ,) → Agents (MCP).
- Tick the connections an agent may read. A production connection says so in red once ticked, because the agent can then read production data.
- Copy the setup line for your agent.
For Claude Code:
claude mcp add elyrasql -- "/Applications/ElyraSQL Client.app/Contents/MacOS/elyrasql-client" --mcp
For other MCP clients, the JSON form:
{
"mcpServers": {
"elyrasql": {
"command": "/Applications/ElyraSQL Client.app/Contents/MacOS/elyrasql-client",
"args": ["--mcp"]
}
}
}
The settings pane shows both with the path to your copy of the app filled in. If you move the app, copy the line again.
The app does not have to be running. The agent starts elyrasql-client --mcp
as a background process, with no window, and stops it when it is done.
Ticking or unticking a connection takes effect on the agent's next request, with
no restart.
What an agent can do
| Tool | What it returns |
|---|---|
list_connections |
The shared connections: id, name, engine, environment |
list_databases |
Databases on one of them |
list_tables |
Tables and views, with row estimates where the engine has them |
describe_table |
Columns (type, nullability, key, default) and declared foreign keys |
run_query |
The rows of one read, as JSON |
Rows per query in the settings pane caps what run_query returns. The
default is 100 and the maximum 1,000. The agent's context is the scarce
resource, so a small cap pushes it to aggregate in SQL instead of paging through
rows. Values longer than 500 characters are cut, and the result says so.
How writes are kept out
Each layer below is enough on its own for the common case. They are stacked because an agent's input is not something to trust.
- The statement is parsed, not guessed. It must be exactly one
SELECT,WITH … SELECT,EXPLAIN,DESCRIBEorSHOW. It may not containINTO,FOR UPDATEor an executable comment (/*! … */,/*M! … */, which the server runs but every check would read as a comment), and it must also pass the same read check the app uses elsewhere. Functions that reach outside the database or take locks are refused by name, for exampleLOAD_FILE,GET_LOCK,SLEEPandNEXTVAL. On ClickHouse, only table functions that stay on the server are allowed:numbers,zeros,generateRandom,values,nullandmerge.url(),s3(),file(),remote()and the rest are refused. - The connection is opened read-only. The client's write rails refuse
everything on it. A SQLite file is opened read-only by SQLite itself, and
ClickHouse is asked for
readonly=2, so those engines refuse writes too. On ElyraSQL, MySQL and MariaDB the read-only flag is the client's own, and layer 3 is the protection on the server. - On ElyraSQL, MySQL and MariaDB, each read runs in a read-only transaction that is always rolled back. MySQL and MariaDB refuse a write inside it. ElyraSQL (1.12) accepts the syntax but does not enforce it, so there the rollback undoes a write that got past the layers above.
- Each read is bounded. It stops after 30 seconds, or sooner if the connection's own statement timeout is shorter.
The server's own privileges still apply on top. For the strictest setup, share
a connection whose database user can only SELECT.
Troubleshooting
"No connections are shared with agents yet." Tick at least one connection in Settings → Agents (MCP).
"This is a Pro feature." The server starts on any edition and answers every request with this message, so the agent can tell you why it got nothing.
A remote connection is refused. Remote connections and SSH tunnels need Pro, exactly as they do in the app.