Install
$ agentstack add mcp-albahubio-mcp-azure-sql ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
mcp-azure-sql
Azure SQL + AI agents. 34 tools. One command.
Enterprise MCP server for Azure SQL & SQL Server. Azure AD auth • Tiered safety gates • Zero dependencies • Written in Go.
Quick Start
1 Add to your AI agent
> CLI agents — one command, done:
# Claude Code (Anthropic)
claude mcp add --transport stdio --scope user azure-sql -- npx -y mcp-azure-sql
# Codex CLI (OpenAI)
codex mcp add azure-sql -- npx -y mcp-azure-sql
# Gemini CLI (Google)
gemini mcp add -s user azure-sql npx -y mcp-azure-sql
> IDE agents — add this JSON block to your agent's config file:
{
"azure-sql": {
"command": "npx",
"args": ["-y", "mcp-azure-sql"],
"env": {
"AZURE_SQL_CONFIG_FILE": "~/.config/azure-sql-mcp/connections.json"
}
}
}
Where does this go? (click to expand)
| Agent | File | Key | |:------|:-----|:----| | | VS Code settings.json | "mcp" > "servers" | | | ~/.cursor/mcp.json | "mcpServers" | | | ~/.codeium/windsurf/mcp_config.json | "mcpServers" | | | Cline Settings UI or cline_mcp_settings.json | "mcpServers" | | | ~/.continue/config.yaml | mcpServers: (YAML) | | | claude_desktop_config.json | "mcpServers" |
2 Configure your databases
Create ~/.config/azure-sql-mcp/connections.json:
{
"defaults": { "auth": "azuread" },
"connections": [
{
"name": "dev",
"server": "myserver.database.windows.net",
"database": "myapp-dev",
"environment": "dev"
},
{
"name": "prod",
"server": "myserver.database.windows.net",
"database": "myapp-prod",
"environment": "prod",
"prod": true
}
]
}
> See [example-config.json](example-config.json) for SQL auth, connection strings, and all options.
3 Sign in to Azure
az login
✓ Done
Restart your AI agent. You now have 34 database tools.
Tools
Query & Execute query • execute
Schema listtables • describetable • describeindexes • describeforeignkeys • searchcolumns • tablerowcounts • searchobjects • describetriggers
Views / Procs / Functions listviews • describeview • liststoredprocs • describesproc • listfunctions • describe_function
Performance explainquery • activequeries • longrunningqueries • topqueriesbycpu • waitstats • blockingchains • indexusagestats • missingindexes • tablestatisticshealth • database_size
Connections listconnections • testconnection • connectioninfo • addconnection
Compliance comparetables • ef6migrationstatus • permissionaudit • hangfire_dashboard
Safety
Your AI agent cannot accidentally destroy production.
| | query | execute on dev | execute on prod | |:--|:--|:--|:--| | SELECT | ✓ | — | — | | INSERT / UPDATE / DELETE | ✗ | confirm=true | confirm=true | | DROP / TRUNCATE / ALTER | ✗ | confirm=true | Blocked | | EXEC / {call} | ✗ | confirm=true | confirm=true |
Production = any connection with "prod": true or "environment": "prod".
Authentication
| Mode | When to use | |:--|:--| | azuread (default) | Azure SQL via az login, managed identity, or service principal | | sql | Legacy SQL Server — add "user" and "password" to connection | | connstr | Custom — add "connection_string" with full connection string |
Why Go?
| | Go | TypeScript / Python | |:--|:--|:--| | Startup | ~5ms | 500ms+ | | Binary | Single 16MB file | Runtime + packages | | Memory | ~15MB | 80MB+ | | Install | Download → run | npm install + Node.js | | Azure AD | Native driver | @azure/identity shim | | Concurrency | Goroutines | Event loop / GIL |
Configuration reference
Config file
{
"defaults": { "auth": "azuread", "app_name": "my-app" },
"connections": [{
"name": "unique-name",
"server": "server.database.windows.net",
"database": "dbname",
"auth": "azuread",
"environment": "dev",
"description": "Human-readable note",
"prod": false
}]
}
Environment tags: dev sqa qa beta delta test preprod prod
Environment variables
# Legacy (no config file needed)
export AZURE_SQL_CONNECTIONS="dev=server.database.windows.net/mydb;qa=qaserver.database.windows.net/qadb"
# Override production list
export AZURE_SQL_PROD_CONNECTIONS="my-prod-db,my-staging-db"
Architecture
AI Agent ──stdio/JSON-RPC──> mcp-azure-sql ──Azure AD──> Azure SQL
│
├── 34 tools with MCP annotations
├── Tiered safety (read/write/dangerous)
├── Connection pool (30s ping skip)
├── Audit logging
└── Error sanitization
Built with mcp-go + go-mssqldb. MCP protocol 2024-11-05. Tool annotations (ReadOnlyHint, DestructiveHint, IdempotentHint, OpenWorldHint) on all 34 tools. Logging capability enabled.
Development & releases
go build -o mcp-azure-sql .
go vet ./...
./mcp-azure-sql --version
Release: git tag v1.3.0 && git push origin v1.3.0 → GitHub Actions builds 6 platform binaries via GoReleaser → npm auto-publishes.
Albahub, LLC • MIT License
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: albahubio
- Source: albahubio/mcp-azure-sql
- License: MIT
- Homepage: https://www.npmjs.com/package/mcp-azure-sql
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.