CentralMind Gateway
Infrastructure · tested 2026-08-22 · re-test due 2026-11-22 · by the Hlido desk, not the vendor
In short: An open-source gateway that turns any database into an MCP server or OpenAPI 3.1 in minutes — broad connector coverage and a serious plugin story (PII removal, auth, caching, tracing).
5 PASS · 0 FAIL of 5 public-surface claims
Quick answer
CentralMind Gateway scores 74/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-08-22). STEADY (74) for a well-documented, open-source database-to-MCP/OpenAPI gateway with unusually broad connector coverage and a security/observability plugin layer (PII removal, RLS, OAuth, caching, OTel) that takes the act
CentralMind Gateway addresses a concrete, current problem: safely exposing a production database to AI agents. Point it at a connection string and it generates a REST API (with Swagger UI) and an MCP SSE endpoint agents can consume. The documentation surface is strong and specific — a one-line Docker run, broad connector coverage (Postgres, MySQL, ClickHouse, BigQuery, Snowflake, MongoDB, MS SQL, Oracle, Supabase and more), named integrations (ChatGPT, LangChain, LlamaIndex, Claude Desktop, Cursor), and — importantly for the use case — a plugin layer that speaks directly to the risks of handing an agent a database: PII remover, Presidio anonymizer, API-keys, OAuth, row-level security via Lua, LRU cache and OpenTelemetry. That security/observability plugin set is what lifts it above a thin 'db-to-MCP' wrapper. It's open source (GHCR image, GitHub), which makes it verifiable and self-hostable. What keeps it at STEADY rather than higher from the public surface: it's a young infrastructure project whose reliability, performance and the real robustness of the auto-generated API and RLS enforcement can't be judged from docs alone, and it sits in a fast-moving space where the database-to-MCP pattern is becoming contested.
Why STEADY
STEADY (74) for a well-documented, open-source database-to-MCP/OpenAPI gateway with unusually broad connector coverage and a security/observability plugin layer (PII removal, RLS, OAuth, caching, OTel) that takes the actual risk of the use case seriously. Not VITAL because it's a young infra project whose reliability, performance and the robustness of auto-generated APIs and access controls can't be verified from the documentation surface. Not FADING: current, actively developed, and openly self-hostable.
Public-surface checklist
- PASS Homepage loads (required)
- PASS Primary value prop (required) — Expose your database to AI agents via MCP or OpenAPI in minutes
- PASS Cta present — Quickstart / Docker run
- PASS Pricing or access — Open source; GHCR image
- PASS Evidence or demo — Docs with runnable quickstart + interactive demo referenced; 1 screenshot captured
What we saw
1 screenshot captured by the Hlido engine during the reviewed run (run-5cd672ff99b57512-centralmind-ai). Our own captures — not vendor marketing material.
What it does well
- Turns a database into both an MCP server and an OpenAPI 3.1 REST API from a connection string
- Broad connector coverage: Postgres, MySQL, ClickHouse, BigQuery, Snowflake, MongoDB, MS SQL, Oracle, Supabase and more
- Security-aware plugin layer: PII remover, Presidio anonymizer, OAuth, API keys, Lua row-level security
- Operable and observable: LRU cache and OpenTelemetry plugins, one-line Docker run, Swagger UI
- Open source and self-hostable (GHCR image + GitHub), so behavior is verifiable
What it fails at
- Reliability and performance of the auto-generated API can't be judged from the documentation surface
- Robustness of access controls (RLS, PII removal) under real adversarial agent use is unproven from docs alone
- The database-to-MCP pattern is fast-becoming contested; durable differentiation isn't yet established
- Auto-generated APIs risk over-exposing schema/data unless carefully constrained — the burden is on the operator
Red flags
- Auto-generating an API/MCP surface over a live database is inherently sensitive; the safety of the result depends heavily on correct plugin configuration (RLS, PII removal, auth). The tooling exists, but the responsibility — and the failure mode — sits with the operator.
Best for
- Teams that need to expose an existing database to AI agents via MCP or REST quickly
- Data/platform engineers who want PII masking, RLS and OAuth in front of agent access
- Self-hosters who want an open-source, Docker-deployable gateway they can audit
- Multi-database environments needing one gateway across many connector types
Not recommended for
- Teams needing a vendor-backed, SLA'd managed service rather than a self-hosted OSS project
- Security-critical exposure where the auto-generated API and access controls must be independently certified first
- Simple single-app cases where a purpose-built endpoint is cheaper than a general gateway
Pricing & access
- Pricing findable on the public surfacePASS Open source; GHCR image (tested 2026-08-22)
Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-08-22.
Compared to
-
Postgrest
postgres-rest-vs-multidb-mcp
PostgREST is the mature, Postgres-only way to auto-generate a REST API; CentralMind adds MCP output, many more database connectors, and an agent-oriented security plugin layer. Choose PostgREST for a proven Postgres-only REST layer, CentralMind for multi-DB + MCP + agent controls.
Agent relevance
API CLI MCP Behavioral-testable
Agentic-Commerce Readiness 76/100 · COMMERCE-READY
Independent readiness for agent delegation & transaction. How it’s scored · check live
This product exists to make databases agent-consumable: it emits an MCP SSE endpoint and an OpenAPI 3.1 REST API, with documented integrations for Claude Desktop, Cursor, ChatGPT, LangChain and LlamaIndex. Open source and Docker-deployable, so it is directly behaviorally testable by an evaluating agent.
Agent-friendly score: 9/10
Score over time
The longitudinal record — every point is the score as published on that date. Raw series.
Evidence
- Database to MCP server or OpenAPI 3.1 — source (2026-08-22) verified
- One-line Docker run generates API + MCP SSE — source (2026-08-22) verified
- Broad database connector coverage — source (2026-08-22) verified
- Security/observability plugins (PII, OAuth, RLS, cache, OTel) — source (2026-08-22) verified
- Open source, GHCR image + GitHub — source (2026-08-22) verified
