Safety-railed database access for agents: Postgres, MySQL, Redis. Read-only by default.
Safety-railed database access for agents: Postgres, MySQL, Redis. Read-only by default. That is what the quarry mcp server brings to an AI assistant: the same capability, reachable through the Model Context Protocol rather than a separate app or dashboard.
Every database tool you know — DBeaver, TablePlus, pgAdmin — assumes a human at the keyboard. But increasingly, the entity running your queries is an AI agent, and agents need different guarantees:
The server publishes 12 tools. What each one is for:
Read — only by default**: writes/DDL blocked with exit code 8; --write to allowGUI — an env pill in the sidebar shows a small badge when that connection's tunnel is routed through the proxy; the workspace manager shows eachMulti — tab editor** — each tab remembers its SQL + connection, across restartsType — aware data grid: sorting, column resize, keyboard navigation (arrows + Enter), cell inspection with a collapsible JSON treeTYPE — aware Redis key browsingCross — environment schema/data diffSingle — binary distributionLayer — Countunit — 568integration — 110e2e — 45browser — 20Installation goes through your MCP client rather than a global install: point it at quarry-db on PyPI and it is fetched when the client starts. The copy-paste blocks for Claude Desktop, Claude Code and Cursor are further down this page.
Plenty of database access servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. Quarry's toolset — Read, GUI, Multi and 9 more — is a fair guide to whether it matches your workflow. It is maintained by Wangggym; worth a glance at recent repository activity before you build anything load-bearing on it.
SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.
| Tool | What it does |
|---|---|
| Read | only by default**: writes/DDL blocked with exit code 8; --write to allow |
| GUI | an env pill in the sidebar shows a small badge when that connection's tunnel is routed through the proxy; the workspace manager shows each workspace's proxy toggle alongside the currently discovered proxy address. Both a |
| Multi | tab editor** — each tab remembers its SQL + connection, across restarts |
| Type | aware data grid: sorting, column resize, **keyboard navigation** (arrows + Enter), cell inspection with a **collapsible JSON tree** |
| TYPE | aware Redis key browsing |
| Cross | environment schema/data diff |
| Single | binary distribution |
| Layer | Count |
| unit | 568 |
| integration | 110 |
| e2e | 45 |
| browser | 20 |
```json
// or any MCP client (.mcp.json)
{ "mcpServers": { "quarry": { "command": "qy", "args": ["mcp", "--workspace", "/path/to/workspace"] } } }Configuration as documented by the project. Restart the client after saving.
Read-only SQL access to Postgres — let your assistant inspect schemas and answer questions from real data.
Manage your whole Supabase project in conversation — database, auth, storage, Edge Functions and branches.
Query, modify and analyse local SQLite databases in conversation — the fastest way to chat with a data file.
Metabase ships its own MCP endpoint — search your BI content, build and run queries, and save questions and dashboards without leaving the chat.
Official MongoDB server covering data, schemas and Atlas management — from find queries to spinning up clusters.
Serverless Postgres with database branching — point your assistant at Neon and let it work on disposable copies.