Hardened, self-hosted Excalidraw MCP server with SQLite persistence, multi-tenancy, auto-sync, security middleware, and 369 tests
If you already use Excalidraw, the excalidraw mcp server is the piece that lets your assistant work with it directly. Hardened, self-hosted Excalidraw MCP server with SQLite persistence, multi-tenancy, auto-sync, security middleware, and 369 tests.
A hardened, fully local, self-hosted Excalidraw MCP server with SQLite persistence, multi-tenancy, auto-sync, and production-grade security — designed to run entirely on your machine without depending on excalidraw.com.
The toolset is worth reading before you wire it up, because it tells you what the integration is really for:
Category — ToolsLayout — align_elements, distribute_elements, group_elements, ungroup_elements, lock_elements, unlock_elementsViewport — set_viewportResources — get_resourceMulti-Tenancy — list_tenants, switch_tenantProjects — list_projects, switch_projectCursor — The Cursor tool exposed by this serverConfiguration is passed through the environment: CANVAS_PORT, EXCALIDRAW_DB_PATH, EXPRESS_SERVER_URL, EXCALIDRAW_API_KEY. Treat anything key-shaped as a real credential — scope it to the minimum the server needs, and rotate it if it ever lands in a shared config.
| Requirement | Why | Check | |---|---|---| | Node.js >= 20 (LTS 20 or 22 recommended) | Runtime | node --version | | C++ build tools | better-sqlite3 compiles native bindings | See below | | npm (bundled with Node.js) | Package manager | npm --version |
Because this one is hosted, setup is mostly authentication — you point your client at the endpoint and approve access. Nothing runs on your machine, so there is no runtime to keep patched.
Among the database access options, the useful question is rarely "what can it do" but "what does it cost you to run" — permissions, credentials, and how much of your context its toolset consumes. Excalidraw's toolset — Category, Layout, Viewport and 4 more — is a fair guide to whether it matches your workflow. It is maintained by new.blacc; worth a glance at recent repository activity before you build anything load-bearing on it.
SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.
| Tool | What it does |
|---|---|
| Category | Tools |
| Layout | align_elements, distribute_elements, group_elements, ungroup_elements, lock_elements, unlock_elements |
| Viewport | set_viewport |
| Resources | get_resource |
| Multi-Tenancy | list_tenants, switch_tenant |
| Projects | list_projects, switch_project |
| Cursor | The Cursor tool exposed by this server. |
Or, if installed from source:
```json
{
"mcpServers": {
"excalidraw-canvas": {
"command": "node",
"args": ["/absolute/path/to/mcp-excalidraw-local/dist/index.js"],
"env": {
"CANVAS_PORT": "3000"
}
}
}
}Configuration as documented by the project. Restart the client after saving.
| Requirement | Why | Check | |---|---|---| | Node.js >= 20 (LTS 20 or 22 recommended) | Runtime | node --version | | C++ build tools | better-sqlite3 compiles native bindings | See below | | npm (bundled with Node.js) | Package manager | npm --version |
| Variable | Description | Required |
|---|---|---|
| CANVAS_PORT | Configuration value read at startup. | Optional |
| EXCALIDRAW_DB_PATH | Filesystem location the server is allowed to use. | Optional |
| EXPRESS_SERVER_URL | Endpoint or connection string the server talks to. | Yes |
| EXCALIDRAW_API_KEY | Credential the server authenticates with. | Yes |
Read-only SQL access to Postgres — let your assistant inspect schemas and answer questions from real data.
Manage your whole Supabase project in conversation — database, auth, storage, Edge Functions and branches.
Query, modify and analyse local SQLite databases in conversation — the fastest way to chat with a data file.
Metabase ships its own MCP endpoint — search your BI content, build and run queries, and save questions and dashboards without leaving the chat.
Official MongoDB server covering data, schemas and Atlas management — from find queries to spinning up clusters.
Serverless Postgres with database branching — point your assistant at Neon and let it work on disposable copies.