Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
MCP server for DuckDB database queries
This repository provides an MCP server that connects an agent to a DuckDB database file. The agent can send SQL through one `query` tool instead of using separate database actions.
Builders who want their agent to query, inspect, and update a DuckDB database through MCP.
You can use an agent to work with DuckDB data without leaving your chat or editor.
What it does
Single SQL query tool
Exposes one `query` tool that runs any valid DuckDB SQL statement.
Read-only mode
Supports `--readonly` so the database opens with native read-only protection and blocks writes.
Keep connection mode
Supports `--keep-connection` to reuse one DuckDB connection for the server lifetime.
Claude Desktop setup
Shows an MCP config example that launches the server with `uvx`.
How to get it
- 1To install DuckDB Server for Claude Desktop automatically via Smithery
npx -y @smithery/cli install mcp-server-duckdb --client claude
README
mcp-server-duckdb
A Model Context Protocol (MCP) server implementation for DuckDB, providing database interaction capabilities through MCP tools. It would be interesting to have LLM analyze it. DuckDB is suitable for local analysis.
Overview
This server enables interaction with a DuckDB database through the Model Context Protocol, allowing for database operations like querying, table creation, and schema inspection.
Components
Resources
Currently, no custom resources are implemented.
Prompts
Currently, no custom prompts are implemented.
Tools
The server implements the following database interaction tool:
- query: Execute any SQL query on the DuckDB database
- Input:
query(string) - Any valid DuckDB SQL statement - Output: Query results as text (or success message for operations like CREATE/INSERT)
- Input:
[!NOTE] The server provides a single unified
queryfunction rather than separate specialized functions, as modern LLMs can generate appropriate SQL for any database operation (SELECT, CREATE TABLE, JOIN, etc.) without requiring separate endpoints.
[!NOTE] When the server is running in
readonlymode, DuckDB's native readonly protection is enforced. This ensures that the Language Model (LLM) cannot perform any write operations (CREATE, INSERT, UPDATE, DELETE), maintaining data integrity and preventing unintended changes.
Configuration
Required Parameters
- db-path (string): Path to the DuckDB database file
- The server will automatically create the database file and parent directories if they don't exist
- If
--readonlyis specified and the database file doesn't exist, the server will fail to start with an error
Optional Parameters
- --readonly: Run server in read-only mode (default:
false)- Description: When this flag is set, the server operates in read-only mode. This means:
- The DuckDB database will be opened with
read_only=True, preventing any write operations. - If the specified database file does not exist, it will not be created.
- Security Benefit: Prevents the Language Model (LLM) from performing any write operations, ensuring that the database remains unaltered.
- The DuckDB database will be opened with
- Reference: For more details on read-only connections in DuckDB, see the DuckDB Python API documentation.
- Description: When this flag is set, the server operates in read-only mode. This means:
- --keep-connection: Re-uses a single DuckDB connection mode (default:
false)- Description: When this flag is set, Re-uses a single DuckDB connection for the entire server lifetime. Enables TEMP objects & slightly faster queries, but can hold an exclusive lock on the file.
Installation
Installing via Smithery
To install DuckDB Server for Claude Desktop automatically via Smithery:
npx -y @smithery/cli install mcp-server-duckdb --client claude
Claude Desktop Integration
Configure the MCP server in Claude Desktop's configuration file:
MacOS
Location: ~/Library/Application Support/Claude/claude_desktop_config.json
Windows
Location: %APPDATA%/Claude/claude_desktop_config.json
{
"mcpServers": {
"duckdb": {
"command": "uvx",
"args": [
"mcp-server-duckdb",
"--db-path",
"~/mcp-server-duckdb/data/data.db"
]
}
}
}
- Note:
~/mcp-server-duckdb/data/data.dbshould be replaced with the actual path to the DuckDB database file.
Development
Prerequisites
- Python with
uvpackage manager - DuckDB Python package
- MCP server dependencies
Debugging
Debugging MCP servers can be challenging due to their stdio-based communication. We recommend using the MCP Inspector for the best debugging experience.
Using MCP Inspector
- Install the inspector using npm:
npx @modelcontextprotocol/inspector uv --directory ~/codes/mcp-server-duckdb run mcp-server-duckdb --db-path ~/mcp-server-duckdb/data/data.db
- Open the provided URL in your browser to access the debugging interface
The inspector provides visibility into:
- Request/response communication
- Tool execution
- Server state
- Error messages
Files in the repo
- .github
- .vscode
- src
- tests
- .gitignore
- .python-version
- LICENSE
- pyproject.toml
- README.md
- uv.lock
Discussion (0)
Ask about usage, or say what you built with itSign in to join the discussion.
No comments yet. Be the first to say what this is good for.
More connectors
High-performance code intelligence MCP server. Indexes codebases into a persistent knowledge graph — average repo in milliseconds. 158 languages, sub-ms queries, 99% fewer tokens. Single static binary, zero dependencies.

Universal provider proxy for OpenAI Codex & Claude Code — use any LLM (Claude, Gemini, Grok, DeepSeek, Ollama…) with Codex CLI, App, SDK, and Claude Code
Git-native persistent memory for AI coding agents. Implements Google OKF v0.2 with sub-300µs in-memory BM25 search, embedded MCP server, and progressive disclosure. Slashes token bloat by 80% with zero external databases or dependencies. Built in pure Go.
Local-first code intelligence graph for MCP and CLI. Builds a persistent map of your codebase so AI coding tools read only what matters, with benchmarked context reductions on reviews and large-repo workflows.
Stop your AI from making things up — it proposes, deterministic tools decide, every claim checked against ground truth with evidence. Grounded facts and context survive resets. Reverse engineering is the proving ground. MCP server + CLI.