Quarry MCP Server

Safety-railed database access for agents: Postgres, MySQL, Redis. Read-only by default.

Local serverstdioPython

What is the Quarry MCP server?

Safety-railed database access for agents: Postgres, MySQL, Redis. Read-only by default. That is what the quarry mcp server brings to an AI assistant: the same capability, reachable through the Model Context Protocol rather than a separate app or dashboard.

The short version

Every database tool you know — DBeaver, TablePlus, pgAdmin — assumes a human at the keyboard. But increasingly, the entity running your queries is an AI agent, and agents need different guarantees:

The tools it exposes

The server publishes 12 tools. What each one is for:

  • Read — only by default**: writes/DDL blocked with exit code 8; --write to allow
  • GUI — an env pill in the sidebar shows a small badge when that connection's tunnel is routed through the proxy; the workspace manager shows each
  • Multi — tab editor** — each tab remembers its SQL + connection, across restarts
  • Type — aware data grid: sorting, column resize, keyboard navigation (arrows + Enter), cell inspection with a collapsible JSON tree
  • TYPE — aware Redis key browsing
  • Cross — environment schema/data diff
  • Single — binary distribution
  • Layer — Count
  • unit — 568
  • integration — 110
  • e2e — 45
  • browser — 20

Getting it running

Installation goes through your MCP client rather than a global install: point it at quarry-db on PyPI and it is fetched when the client starts. The copy-paste blocks for Claude Desktop, Claude Code and Cursor are further down this page.

How it compares

Plenty of database access servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. Quarry's toolset — Read, GUI, Multi and 9 more — is a fair guide to whether it matches your workflow. It is maintained by Wangggym; worth a glance at recent repository activity before you build anything load-bearing on it.

SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.

Things to watch

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • With 12 tools registered it takes up a noticeable share of the context window; turn it off in projects that never touch Quarry.
  • Keep per-call confirmation enabled while you learn its behaviour; it is the cheapest safeguard you have.

Available tools

ToolWhat it does
Readonly by default**: writes/DDL blocked with exit code 8; --write to allow
GUIan env pill in the sidebar shows a small badge when that connection's tunnel is routed through the proxy; the workspace manager shows each workspace's proxy toggle alongside the currently discovered proxy address. Both a
Multitab editor** — each tab remembers its SQL + connection, across restarts
Typeaware data grid: sorting, column resize, **keyboard navigation** (arrows + Enter), cell inspection with a **collapsible JSON tree**
TYPEaware Redis key browsing
Crossenvironment schema/data diff
Singlebinary distribution
LayerCount
unit568
integration110
e2e45
browser20

How to install the Quarry MCP server

```json
// or any MCP client (.mcp.json)
{ "mcpServers": { "quarry": { "command": "qy", "args": ["mcp", "--workspace", "/path/to/workspace"] } } }

Configuration as documented by the project. Restart the client after saving.

Example prompts to try

  • Use Quarry to Read.
  • Use Quarry to GUI.
  • Use Quarry to Multi.

Frequently asked questions

It connects Quarry to MCP-compatible AI assistants such as Claude and Cursor, exposing 12 tools (Read, GUI, Multi, and more) that the assistant can call on your behalf. Instead of copying data back and forth by hand, the assistant works with Quarry directly.