Connect Claude to PlanetScale's official hosted MCP server for organizations, databases, branches, schemas, Insights, documentation search, and scoped SQL query workflows.
PlanetScale's hosted MCP server is controlled by OAuth scopes. Choose no access or read-only access unless the task explicitly requires write queries or broader database permissions., Use the Insights-only endpoint at `https://mcp.pscale.dev/mcp/planetscale-insights-only` when Claude only needs Insights data and should not receive SQL query execution tools., Write query access can affect live production data. PlanetScale documents safeguards for blocking `UPDATE` or `DELETE` without `WHERE`, blocking `TRUNCATE`, and prompting for DDL confirmation, but those safeguards do not replace review, least privilege, backups, or change-control approval., Confirm the organization, database, branch, and database engine before approving any query. For PostgreSQL databases, provide the intended `postgres_database_name` when using query tools., Broad read queries, schema scans, and repeated Insights searches can still affect cost, privacy, and operational load. Limit row counts, date ranges, branch scope, and prompt loops., PlanetScale says MCP queries are tagged with `source=planetscale-mcp`. Review those entries in Insights when auditing assistant-driven database activity.
Privacy notes
PlanetScale MCP can return organization names, database names, branch names, schema details, Insights data, query text, query performance, invoice details, region information, cluster size SKUs, and documentation search results into the model conversation., PlanetScale documents that query execution uses short-lived ephemeral credentials that are created on demand and deleted immediately after the query. Treat MCP outputs, prompts, transcripts, screenshots, and client logs as separate records that may persist outside PlanetScale., Do not paste service tokens, connection strings, passwords, production row exports, customer data, secrets, invoice PDFs, private schema names, or raw incident data into prompts, tickets, issue comments, or PR descriptions., If the MCP client stores chat history or tool results, confirm that its retention and sharing settings are acceptable before connecting production PlanetScale databases.
Author
PlanetScale
Submitted by
MkDev11
Claim status
unclaimed
Last verified
2026-06-05
Decision playbook
Review trust signals before you adopt
Signals are present but mixed. Use the checklist below to confirm the source and operational safety for your environment.
Compare context
Selected
0
Current score
78
Baseline
—
Delta
No baseline selected
No major trust-signal divergence detected in the current selection.
Source and provenance checks
Complete
Confirm ownership and provenance before trusting install instructions.
Source link availableRequired
Open the canonical repository and verify ownership.
Done
Source provenance statusRequired
Marked as source-backed.
Done
Metadata reviewed
Registry metadata indicates a reviewed listing.
Done
Safety and privacy checks
Complete
Validate risk disclosures before installation or API wiring.
Safety notes presentRequired
Review the listed safety guidance before running commands.
Done
Privacy notes presentRequired
Review data handling notes before connecting accounts or secrets.
Done
Trust level risk gateRequired
Trust level does not block evaluation.
Done
Package and install checks
Needs review
Check package metadata and artifact integrity signals.
Install payload available
Install or copy payload is available for review.
Done
Package verification flag
No package verification flag provided.
Pending
Checksum metadata
No checksum provided for downloaded artifact.
Pending
Compare-driven decision checks
Needs review
Use compare context to validate trade-offs before adoption.
Compare tray has multiple entries
Add at least one more entry to compare trust differences.
6 safety and 4 privacy notes across 6 risk areas. Review closely: credentials & tokens, permissions & scopes, network access.
6 areas
SafetyCredentials & tokensPlanetScale's hosted MCP server is controlled by OAuth scopes. Choose no access or read-only access unless the task explicitly requires write queries or broader database permissions.
SafetyNetwork accessUse the Insights-only endpoint at `https://mcp.pscale.dev/mcp/planetscale-insights-only` when Claude only needs Insights data and should not receive SQL query execution tools.
SafetyExecution & processesWrite query access can affect live production data. PlanetScale documents safeguards for blocking `UPDATE` or `DELETE` without `WHERE`, blocking `TRUNCATE`, and prompting for DDL confirmation, but those safeguards do not replace review, least privilege, backups, or change-control approval.
SafetyGeneralConfirm the organization, database, branch, and database engine before approving any query. For PostgreSQL databases, provide the intended `postgres_database_name` when using query tools.
SafetyPermissions & scopesBroad read queries, schema scans, and repeated Insights searches can still affect cost, privacy, and operational load. Limit row counts, date ranges, branch scope, and prompt loops.
SafetyGeneralPlanetScale says MCP queries are tagged with `source=planetscale-mcp`. Review those entries in Insights when auditing assistant-driven database activity.
PrivacyGeneralPlanetScale MCP can return organization names, database names, branch names, schema details, Insights data, query text, query performance, invoice details, region information, cluster size SKUs, and documentation search results into the model conversation.
PrivacyCredentials & tokensPlanetScale documents that query execution uses short-lived ephemeral credentials that are created on demand and deleted immediately after the query. Treat MCP outputs, prompts, transcripts, screenshots, and client logs as separate records that may persist outside PlanetScale.
PrivacyCredentials & tokensDo not paste service tokens, connection strings, passwords, production row exports, customer data, secrets, invoice PDFs, private schema names, or raw incident data into prompts, tickets, issue comments, or PR descriptions.
PrivacyData retentionIf the MCP client stores chat history or tool results, confirm that its retention and sharing settings are acceptable before connecting production PlanetScale databases.
Safety notes
PlanetScale's hosted MCP server is controlled by OAuth scopes. Choose no access or read-only access unless the task explicitly requires write queries or broader database permissions.
Use the Insights-only endpoint at `https://mcp.pscale.dev/mcp/planetscale-insights-only` when Claude only needs Insights data and should not receive SQL query execution tools.
Write query access can affect live production data. PlanetScale documents safeguards for blocking `UPDATE` or `DELETE` without `WHERE`, blocking `TRUNCATE`, and prompting for DDL confirmation, but those safeguards do not replace review, least privilege, backups, or change-control approval.
Confirm the organization, database, branch, and database engine before approving any query. For PostgreSQL databases, provide the intended `postgres_database_name` when using query tools.
Broad read queries, schema scans, and repeated Insights searches can still affect cost, privacy, and operational load. Limit row counts, date ranges, branch scope, and prompt loops.
PlanetScale says MCP queries are tagged with `source=planetscale-mcp`. Review those entries in Insights when auditing assistant-driven database activity.
Privacy notes
PlanetScale MCP can return organization names, database names, branch names, schema details, Insights data, query text, query performance, invoice details, region information, cluster size SKUs, and documentation search results into the model conversation.
PlanetScale documents that query execution uses short-lived ephemeral credentials that are created on demand and deleted immediately after the query. Treat MCP outputs, prompts, transcripts, screenshots, and client logs as separate records that may persist outside PlanetScale.
Do not paste service tokens, connection strings, passwords, production row exports, customer data, secrets, invoice PDFs, private schema names, or raw incident data into prompts, tickets, issue comments, or PR descriptions.
If the MCP client stores chat history or tool results, confirm that its retention and sharing settings are acceptable before connecting production PlanetScale databases.
Prerequisites
PlanetScale account with access to the organizations, databases, and branches you want Claude to inspect.
MCP-capable client with remote HTTP server support, such as Claude, Claude Code, Cursor, VS Code, Codex, Gemini CLI, Amp, OpenCode, Notion, or another compatible client.
Browser access for the PlanetScale OAuth authorization flow when the MCP client connects.
Decision on whether the assistant needs no database access, read-only database access, full database access, or Insights-only access.
Approval from the database owner before enabling write queries, DDL assistance, invoice visibility, or production database access.
A written target organization, database, and branch for each workflow so the assistant does not browse unrelated PlanetScale resources.
PlanetScale MCP Server is PlanetScale's official hosted Model Context Protocol
server for connecting Claude and other MCP-capable clients to PlanetScale
organizations, databases, branches, schemas, Insights, documentation search, and
selected account operations. It runs as a remote HTTP server at
https://mcp.pscale.dev/mcp/planetscale and uses PlanetScale OAuth to grant the
client configurable permissions.
Use it when Claude needs current database context while planning migrations,
debugging query performance, inspecting branches, reviewing schema changes, or
drafting database recommendations. Start with read-only or Insights-only access
for analysis tasks, and enable write query access only for a specific approved
workflow.
Features
Official PlanetScale documentation page for MCP setup, client instructions,
OAuth permissions, query handling, tools, and troubleshooting.
Hosted remote HTTP MCP server at https://mcp.pscale.dev/mcp/planetscale.
Insights-only hosted endpoint at
https://mcp.pscale.dev/mcp/planetscale-insights-only.
Claude connector listing and custom connector setup.
Claude Code plugin setup through the PlanetScale Claude plugin marketplace.
Direct Claude Code, Cursor, VS Code, Codex CLI, Gemini CLI, OpenCode, Amp,
Notion, and other MCP client setup paths.
OAuth-scoped access with no access, read-only access, or full access at the
organization or per-database level.
Short-lived ephemeral database credentials for query execution.
Read query routing to a replica when a replica is configured.
Query attribution with source=planetscale-mcp comments visible in Insights.
Public TypeScript source repository for the direct tools and shared helpers.
Additional hosted tools generated from PlanetScale's OpenAPI specification.
Tool Surface
PlanetScale documents tools for listing and inspecting organizations,
databases, branches, branch schemas, regions, cluster size SKUs, invoices,
invoice line items, Insights, documentation search, and schema recommendations.
The hosted server can also expose SQL tools for read queries and write queries
when the selected OAuth permissions allow them.
The open source repository contains direct TypeScript tool implementations and
shared helpers. PlanetScale notes that the full hosted server also includes
additional tools generated from its OpenAPI specification, so the hosted server
can have a broader tool surface than the repository alone.
Show that PlanetScale MCP Server for Claude is listed on HeyClaude. Paste this Markdown into your README — it renders the badge and links back to this page.
[](https://heyclau.de/entry/mcp/planetscale-mcp-server)
How it compares
PlanetScale MCP Server for Claude side by side with 3 alternatives on trust, install, platform support, and disclosed safety notes — all from reviewed registry metadata.
1 trust signal differ across this comparison (Submitter).
Connect Claude to PlanetScale's official hosted MCP server for organizations, databases, branches, schemas, Insights, documentation search, and scoped SQL query workflows.
✓PlanetScale's hosted MCP server is controlled by OAuth scopes. Choose no access or read-only access unless the task explicitly requires write queries or broader database permissions.
Use the Insights-only endpoint at `https://mcp.pscale.dev/mcp/planetscale-insights-only` when Claude only needs Insights data and should not receive SQL query execution tools.
Write query access can affect live production data. PlanetScale documents safeguards for blocking `UPDATE` or `DELETE` without `WHERE`, blocking `TRUNCATE`, and prompting for DDL confirmation, but those safeguards do not replace review, least privilege, backups, or change-control approval.
Confirm the organization, database, branch, and database engine before approving any query. For PostgreSQL databases, provide the intended `postgres_database_name` when using query tools.
Broad read queries, schema scans, and repeated Insights searches can still affect cost, privacy, and operational load. Limit row counts, date ranges, branch scope, and prompt loops.
PlanetScale says MCP queries are tagged with `source=planetscale-mcp`. Review those entries in Insights when auditing assistant-driven database activity.
✓DBHub can execute SQL queries against configured databases.
SQL execution can read, create, update, delete, or otherwise modify data depending on database permissions and requested queries.
Configure read-only mode, row limits, query timeouts, least-privilege credentials, and human review before using DBHub with production or sensitive databases.
Custom tools can wrap reusable parameterized SQL, so review their definitions before allowing agents to call them.
✓The server exposes a single `query` tool that can execute any valid DuckDB SQL statement against the configured database.
Without `--readonly`, the server can create the database file, create tables, insert data, update rows, delete rows, and mutate database state.
With `--readonly`, the server opens DuckDB with native read-only protection and fails to start if the database file or parent directory is missing.
The `--keep-connection` option can hold a persistent DuckDB connection and file lock for the server lifetime.
Treat SQL generated by a model as executable code; review queries before running them on important data.
✓MariaDB MCP connects Claude to a live database and exposes schema inspection plus SQL execution tools.
The default read-only mode allows SELECT, SHOW, DESCRIBE, DESC, and USE-style queries, but the README warns that database privileges are the only reliable way to guarantee read-only access.
The server includes a `create_database` tool and optional vector-store tools that can create, insert into, search, and delete vector-store tables when enabled.
If `MCP_READ_ONLY=false` or credentials have broad privileges, model-generated SQL can create, modify, delete, or expose database state.
The server checks for risky FILE privilege behavior, but teams should revoke FILE and other unnecessary global privileges from the connected MariaDB user.
HTTP and SSE transports require explicit authentication and restricted host/origin settings before any non-local use.
Embedding providers can receive document text or derived content when vector-store tooling is enabled.
Privacy notes
✓PlanetScale MCP can return organization names, database names, branch names, schema details, Insights data, query text, query performance, invoice details, region information, cluster size SKUs, and documentation search results into the model conversation.
PlanetScale documents that query execution uses short-lived ephemeral credentials that are created on demand and deleted immediately after the query. Treat MCP outputs, prompts, transcripts, screenshots, and client logs as separate records that may persist outside PlanetScale.
Do not paste service tokens, connection strings, passwords, production row exports, customer data, secrets, invoice PDFs, private schema names, or raw incident data into prompts, tickets, issue comments, or PR descriptions.
If the MCP client stores chat history or tool results, confirm that its retention and sharing settings are acceptable before connecting production PlanetScale databases.
✓Database connection strings, hostnames, schemas, table names, column names, row data, query text, query results, traces, and errors may be visible to the MCP client and model provider.
Databases can contain personal data, customer records, credentials, business metrics, audit logs, payment data, healthcare data, and proprietary operational state.
Avoid exposing production databases or regulated data unless the database, MCP client, and model session are approved for that access.
✓Tool calls and results can expose database paths, table names, schemas, query text, row values, file paths referenced by SQL, and analytical results to the MCP client and model provider.
DuckDB can query local files and extensions depending on SQL, configuration, and installed capabilities; keep the server scoped to approved data directories.
Do not point writable sessions at production, customer, regulated, or irreplaceable DuckDB files without backups and explicit approval.
Query errors can reveal schema names, file paths, and data-shape details.
✓Database credentials, hostnames, database names, schemas, table names, column names, SQL text, query results, errors, and log files may be visible to the MCP client and model provider.
MariaDB data can include customer records, credentials, audit logs, business metrics, payment data, healthcare data, or other regulated information.
Vector-store tables can persist source documents, embeddings, metadata, and semantic-search results inside MariaDB.
OPENAI_API_KEY, GEMINI_API_KEY, HF_MODEL settings, SSL certificate paths, dotenv files, and database passwords should stay out of prompts, issues, logs, screenshots, and committed files.
Review log retention because the server writes logs to `logs/mcp_server.log` by default.
Prerequisites
PlanetScale account with access to the organizations, databases, and branches you want Claude to inspect.
MCP-capable client with remote HTTP server support, such as Claude, Claude Code, Cursor, VS Code, Codex, Gemini CLI, Amp, OpenCode, Notion, or another compatible client.
Browser access for the PlanetScale OAuth authorization flow when the MCP client connects.
Decision on whether the assistant needs no database access, read-only database access, full database access, or Insights-only access.
Node.js and npx available to the MCP client runtime.
A PostgreSQL, MySQL, MariaDB, SQL Server, or SQLite database connection.
Database credentials with the minimum privileges needed for the workflow.
Read-only permissions or DBHub guardrails configured before connecting production data.
Python and `uvx` available to the MCP client runtime.
Existing DuckDB database file when using `--readonly`.
Path to a DuckDB database file that Claude is allowed to query.
Decision on whether the server should run in read-only mode before connecting it to an agent.
Python 3.11 and uv available to the MCP client runtime.
Reviewed checkout of the MariaDB MCP repository with dependencies installed.
MariaDB database host, port, database name, username, and password.
Least-privilege MariaDB user scoped to only the databases and operations Claude should access.
Install
claude mcp add --transport http "planetscale" https://mcp.pscale.dev/mcp/planetscale