Elyra
Elyra The coding agent eTerm The terminal that knows where each command ends Starf An activity monitor for Apple silicon that never invents a number Litr A small, native web browser for macOS Notr A notebook for macOS e The native code editor Elyra Grove Native local development environment Askr The real server for Laravel & PHP Elyra Framework Rust + Svelte 5 framework for desktop apps Elyra Conductor Local project conductor Refr Local-first PDF workspace for macOS Elyra Workspace A desktop workspace for coding agents Elyra SQL Server MySQL-compatible SQL server in Rust Elyra Félagi Agents as teammates on one board Elyra SQL Client Native desktop SQL workbench Elyra SQL Anywhere Replication-ready SQL engine Elyra Sjá SEO & GEO workspace for macOS Elyra DataGrid Server-driven data grid for Laravel
Release notes
Changelog
Elyra

Agents (MCP)

Requires Pro

ElyraSQL Client can act as an MCP server, the protocol AI agents such as Claude Code use to reach tools. An agent can then read the databases you have saved here: list tables, describe them, and run SELECTs. It does that through the connection you already set up, without a connection string of its own.

Why this rather than giving the agent a password:

  • The password stays in the keychain. The agent names a connection, for example Shop. The client looks up the password itself and never sends it to the agent.
  • Nothing is shared until you tick it. Each connection is opt-in.
  • Reads only. Writes are refused, whatever the agent sends.
  • You can see what it ran. Every agent query lands in your History, marked agent.

Set it up

  1. Open Settings (⌘/Ctrl + ,) → Agents (MCP).
  2. Tick the connections an agent may read. A production connection says so in red once ticked, because the agent can then read production data.
  3. Copy the setup line for your agent.

For Claude Code:

claude mcp add elyrasql -- "/Applications/ElyraSQL Client.app/Contents/MacOS/elyrasql-client" --mcp

For other MCP clients, the JSON form:

{
  "mcpServers": {
    "elyrasql": {
      "command": "/Applications/ElyraSQL Client.app/Contents/MacOS/elyrasql-client",
      "args": ["--mcp"]
    }
  }
}

The settings pane shows both with the path to your copy of the app filled in. If you move the app, copy the line again.

The app does not have to be running. The agent starts elyrasql-client --mcp as a background process, with no window, and stops it when it is done. Ticking or unticking a connection takes effect on the agent's next request, with no restart.

What an agent can do

Tool What it returns
list_connections The shared connections: id, name, engine, environment
list_databases Databases on one of them
list_tables Tables and views, with row estimates where the engine has them
describe_table Columns (type, nullability, key, default) and declared foreign keys
run_query The rows of one read, as JSON

Rows per query in the settings pane caps what run_query returns. The default is 100 and the maximum 1,000. The agent's context is the scarce resource, so a small cap pushes it to aggregate in SQL instead of paging through rows. Values longer than 500 characters are cut, and the result says so.

How writes are kept out

Each layer below is enough on its own for the common case. They are stacked because an agent's input is not something to trust.

  1. The statement is parsed, not guessed. It must be exactly one SELECT, WITH … SELECT, EXPLAIN, DESCRIBE or SHOW. It may not contain INTO, FOR UPDATE or an executable comment (/*! … */, /*M! … */, which the server runs but every check would read as a comment), and it must also pass the same read check the app uses elsewhere. Functions that reach outside the database or take locks are refused by name, for example LOAD_FILE, GET_LOCK, SLEEP and NEXTVAL. On ClickHouse, only table functions that stay on the server are allowed: numbers, zeros, generateRandom, values, null and merge. url(), s3(), file(), remote() and the rest are refused.
  2. The connection is opened read-only. The client's write rails refuse everything on it. A SQLite file is opened read-only by SQLite itself, and ClickHouse is asked for readonly=2, so those engines refuse writes too. On ElyraSQL, MySQL and MariaDB the read-only flag is the client's own, and layer 3 is the protection on the server.
  3. On ElyraSQL, MySQL and MariaDB, each read runs in a read-only transaction that is always rolled back. MySQL and MariaDB refuse a write inside it. ElyraSQL (1.12) accepts the syntax but does not enforce it, so there the rollback undoes a write that got past the layers above.
  4. Each read is bounded. It stops after 30 seconds, or sooner if the connection's own statement timeout is shorter.

The server's own privileges still apply on top. For the strictest setup, share a connection whose database user can only SELECT.

Troubleshooting

"No connections are shared with agents yet." Tick at least one connection in Settings → Agents (MCP).

"This is a Pro feature." The server starts on any edition and answers every request with this message, so the agent can tell you why it got nothing.

A remote connection is refused. Remote connections and SSH tunnels need Pro, exactly as they do in the app.