PluginBench
MCP Server
Active
MIT

io.github.spences10/mcp-sqlite-tools MCP Server

io.github.spences10/mcp-sqlite-tools

Safe, local SQLite database operations for MCP clients with read, write, schema, and transaction tools.

What is the io.github.spences10/mcp-sqlite-tools MCP server?

The mcp-sqlite-tools MCP server provides safe, local SQLite database operations through explicit read, write, schema, transaction, CSV, backup, and maintenance tools. It uses Node's built-in SQLite driver with no native addon dependency, and restricts database and CSV paths through configuration for security.

This server gives MCP clients like Claude and Cursor full control over local SQLite databases. It separates read-only tools from destructive operations so clients can apply approval policies, supports transactions with nested savepoints, and includes CSV import/export, schema management, and online backups. Use it to query, modify, and maintain SQLite databases safely from your AI assistant.

How to install io.github.spences10/mcp-sqlite-tools

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "mcp-sqlite-tools": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-sqlite-tools"
      ]
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • open_database — Open an existing database
  • close_database — Close one database connection
  • list_databases — Find database files in a directory
  • database_info — Read file and SQLite metadata
  • list_tables — List tables and views
  • describe_table — Read columns and constraints
  • backup_database — Create a consistent online backup
  • export_csv — Export a table or read-only query
  • export_schema — Export schema as SQL or JSON
  • execute_read_query — Run one SQLite read-only statement
  • create_database — Create a new database file
  • create_table — Create a table from validated columns
  • drop_table — Drop a table and its data
  • execute_write_query — Run INSERT, UPDATE, or DELETE
  • execute_schema_query — Run one schema statement
  • bulk_insert — Insert records in batches
  • import_csv — Import a headered CSV file
  • import_schema — Apply SQL or JSON schema objects
  • vacuum_database — Rebuild a database to reclaim space
  • begin_transaction — Begin a transaction or nested savepoint

Use cases

  • Query local SQLite databases and retrieve results with pagination and named parameters
  • Create, modify, and drop tables and schemas programmatically
  • Import and export data via CSV files for data integration workflows
  • Perform multi-step database operations using transactions with nested savepoints
  • Back up and maintain SQLite databases with online backups and vacuum operations

io.github.spences10/mcp-sqlite-tools MCP server FAQ

What is mcp-sqlite-tools?

It's an MCP server that gives AI assistants like Claude safe, local access to SQLite databases. It provides separate tools for read-only queries, writes, schema changes, transactions, and maintenance so clients can enforce approval policies.

Is it free?

Yes, mcp-sqlite-tools is open source under the MIT License.

How do I install it in Cursor or Claude?

Use the MCPick tool: `npx -y mcpick add --name sqlite-tools --command npx --args "-y,mcp-sqlite-tools"` and select your client. Or manually add it to your client's configuration JSON with `command: npx` and `args: ["-y", "mcp-sqlite-tools"]`.

Does it require authentication?

No, it operates on local SQLite files. You control access by setting the `SQLITE_DEFAULT_PATH` environment variable to restrict which directories the server can access.

What are the system requirements?

Node.js 24.12 or later and an MCP client with stdio server support (Claude, Cursor, VS Code, etc.).

Can I use it with remote databases?

No, mcp-sqlite-tools is designed for local SQLite files only. Database and CSV paths are validated and restricted to configured directories for security.

README (reference)

Source of truth, from the repository.

mcp-sqlite-tools

A Model Context Protocol (MCP) server for safe, local SQLite database operations. It gives MCP clients explicit read, write, schema, transaction, CSV, backup, and maintenance tools.

Features

  • Open, create, inspect, back up, vacuum, and close SQLite databases
  • List, describe, create, and drop tables
  • Run paginated read queries with named or positional parameters
  • Run explicit write and schema queries
  • Import and export headered CSV files
  • Use transactions with nested savepoints
  • Export and import schemas as SQL or JSON
  • Restrict database and CSV paths through configuration
  • Classify destructive tools for client approval policies
  • Use Node's built-in SQLite driver with no native addon dependency

Requirements

  • Node.js 24.12 or later
  • An MCP client with stdio server support

Configure your MCP client

The MCP client starts this server through npx; a global installation is not required.

Install with MCPick

MCPick can add the server to a supported client without manual JSON editing. This command targets Claude Code's local scope by default:

npx -y mcpick add \
  --name sqlite-tools \
  --command npx \
  --args "-y,mcp-sqlite-tools"

Select a client and scope explicitly when needed:

npx -y mcpick add \
  --name sqlite-tools \
  --command npx \
  --args "-y,mcp-sqlite-tools" \
  --client vscode \
  --scope project

The add command supports Claude Code, Gemini CLI, VS Code, Cursor, Windsurf, OpenCode, and Pi. Run npx mcpick clients to see current client capabilities, scopes, and configuration locations.

The examples track the latest package release. For reproducible configuration, replace mcp-sqlite-tools in --args with an exact version such as mcp-sqlite-tools@x.y.z.

Manual configuration

For unsupported clients or advanced configuration, add the server manually:

{
	"mcpServers": {
		"mcp-sqlite-tools": {
			"command": "npx",
			"args": ["-y", "mcp-sqlite-tools"],
			"env": {
				"SQLITE_DEFAULT_PATH": ".",
				"SQLITE_ALLOW_ABSOLUTE_PATHS": "true",
				"SQLITE_BUSY_TIMEOUT": "30000",
				"SQLITE_JOURNAL_MODE": "wal",
				"SQLITE_BACKUP_PATH": "./backups"
			}
		}
	}
}

VS Code uses a servers object instead of mcpServers. See the configuration guide for more client-specific examples.

Environment variables

VariablePurposeDefault
SQLITE_DEFAULT_PATHBase directory for database files.
SQLITE_ALLOW_ABSOLUTE_PATHSAllow paths outside the default directorytrue
SQLITE_BACKUP_PATHDefault backup directoryDefault database path
SQLITE_BUSY_TIMEOUTSQLite lock busy timeout in milliseconds30000
SQLITE_JOURNAL_MODEdelete, truncate, persist, or walwal
DEBUGEnable diagnostic loggingfalse

When SQLITE_ALLOW_ABSOLUTE_PATHS=false, relative and absolute paths must resolve inside SQLITE_DEFAULT_PATH. Symbolic links cannot be used to escape that directory.

Use SQLITE_JOURNAL_MODE=delete for databases in file-synchronized directories. The unsafe SQLite modes memory and off are not accepted.

SQLITE_MAX_QUERY_TIME remains available as a deprecated alias for SQLITE_BUSY_TIMEOUT. It does not limit wall-clock query runtime.

Tools

Tools are separated by intent so MCP clients can apply clear approval rules.

Safe and read-only

ToolPurpose
open_databaseOpen an existing database
close_databaseClose one database connection
list_databasesFind database files in a directory
database_infoRead file and SQLite metadata
list_tablesList tables and views
describe_tableRead columns and constraints
backup_databaseCreate a consistent online backup
export_csvExport a table or read-only query
export_schemaExport schema as SQL or JSON
execute_read_queryRun one SQLite read-only statement

Writes, schema, and maintenance

ToolPurpose
create_databaseCreate a new database file
create_tableCreate a table from validated columns
drop_tableDrop a table and its data
execute_write_queryRun INSERT, UPDATE, or DELETE
execute_schema_queryRun one schema statement
bulk_insertInsert records in batches
import_csvImport a headered CSV file
import_schemaApply SQL or JSON schema objects
vacuum_databaseRebuild a database to reclaim space
begin_transactionBegin a transaction or nested savepoint
commit_transactionCommit or release a savepoint
rollback_transactionRoll back a transaction or savepoint

See the complete API reference for parameters, responses, examples, pagination, and CSV options.

Safety model

The server does not treat every SQL string as equivalent:

  • execute_read_query uses SQLite's authorizer API to reject writes, schema changes, unsafe PRAGMAs, attachment, and multiple statements.
  • Write, schema, transaction, and destructive administration actions use separate tools so clients can request approval.
  • Database and CSV paths are resolved and validated before access.
  • Identifiers generated by tools are quoted.
  • Values are bound as parameters rather than interpolated into SQL.
  • Backups use SQLite's online backup API and include committed WAL data.

A client can allow read-only tools and require approval for destructive tools. Always review SQL and file paths before approving changes. Back up important databases before schema changes, imports, or large writes.

Why native SQLite?

Using node:sqlite removes the native addon, its install script, and its platform-specific binaries. A clean production install fell from 31.3 MB with better-sqlite3 to 3.6 MB with native SQLite, an 88.5% reduction. The npm tarball itself is similar in size: 63.1 KB native versus 60.0 KB published. The large saving is in the installed dependency tree.

The migration also removes better-sqlite3 and its type package. It makes installation independent of prebuilt addon availability or a working native compiler.

Driver benchmark

Lower times are better. These medians use 20,000 rows, two warmups, and seven measured runs per driver. Each sample uses a new database and the driver order alternates. Setup is outside the measured region except for the insert workload.

Workloadnode:sqlitebetter-sqlite3Native result
Insert transaction11.13 ms23.78 ms2.14× faster
Indexed point reads25.23 ms21.40 ms17.9% slower
Full row scan6.39 ms3.29 ms94.3% slower
Update transaction8.04 ms15.40 ms1.92× faster
Online backup0.55 ms0.38 ms45.0% slower

Measured on Linux x64 with Node.js 24.15.0 and an AMD Ryzen AI 9 HX 370. Node used SQLite 3.51.3; better-sqlite3@13.0.1 used SQLite 3.53.3. These microbenchmarks show driver trade-offs, not complete MCP performance. MCP transport and validation costs are not included.

Development

git clone https://github.com/spences10/mcp-sqlite-tools.git
cd mcp-sqlite-tools
pnpm install
pnpm run check
pnpm test
pnpm run build

See development and architecture for module responsibilities and other development commands.

Documentation

Contributing

Issues and pull requests are welcome.

License

MIT License. See LICENSE.

Related MCP servers

Query and manage Turso SQLite databases directly from Claude and other LLMs with secure read/write separation.

17
TypeScript
MIT
View repository →

Unified web search, AI answers, GitHub code search, and web extraction across Tavily, Brave, Kagi, Exa, Linkup, and Firecrawl.

343
TypeScript
MIT
View repository →

Verifiable crypto signals, recorded history and always-on monitoring for AI agents via x402 on Base.

0
JavaScript
MIT
View repository →

Calibrated world model for AI agents. 40 tools: world state, markets, trading. Kalshi + Polymarket.

View repository →
TETenderFit logo

TenderFit

Active

UK public-procurement qualification for agents, paid via x402 USDC on Base.

0
View repository →

Turn any video into viral clips and clip live streams, from any AI agent.

0
View repository →