MCP Toolbox for Databases
Infrastructure · tested 2026-08-23 · re-test due 2026-11-23 · by the Hlido desk, not the vendor
In short: Google's open-source MCP server for enterprise databases — dual-purpose, well-documented, and already tracking the newest stateless MCP spec.
5 PASS · 0 FAIL of 5 public-surface claims
Quick answer
MCP Toolbox for Databases scores 85/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-08-23). STEADY (85) for a well-maintained, well-documented open-source MCP server with a clear dual-purpose architecture, explicit spec-version discipline, and observability treated as a first-class documentation section.
MCP Toolbox for Databases connects AI agents, IDEs and applications directly to enterprise databases, and it does two separable jobs rather than one. The build-time half is a ready-to-use MCP server with prebuilt generic tools — list_tables, execute_sql and similar — that lets Gemini CLI, Antigravity, Claude Code, Codex or any MCP client explore a schema and generate code without boilerplate. The run-time half is a framework for defining your own constrained tools: structured queries, semantic search, NL2SQL, scoped so a production agent gets exactly the surface you intend and nothing more. That split matters, because the generic tools are the thing you want in an IDE and precisely the thing you do not want pointed at production. The documentation surface is the strongest signal here. Versioned docs with a version selector, a stated position on supported MCP versions separating stable releases from draft specifications, sections for configuration, deployment, and monitoring and observability, and a same-page notice that the project already supports the 2026-07-28 stateless MCP spec. Projects that document their own spec-compatibility boundary tend to be the ones that maintain it. The repository rename from genai-toolbox to mcp-toolbox is announced in-page with the exact git remote command, which is a small thing that says something about the maintenance posture. What the public surface does not settle is operational: there is no independent security review linked, and the security model for the generic execute_sql path in a shared environment is left to the deployer. Read the security guidance before pointing this at anything that matters.
Why STEADY
STEADY (85) for a well-maintained, well-documented open-source MCP server with a clear dual-purpose architecture, explicit spec-version discipline, and observability treated as a first-class documentation section. Vendor backing raises the continuity floor. Not VITAL because the surface leaves the security model of the generic database-access path to the deployer without a linked independent review, and because a prebuilt execute_sql tool is a genuinely sharp edge that deserves more guardrail documentation than the introduction gives it.
Public-surface checklist
- PASS Homepage loads (required)
- PASS Primary value prop (required) — Connects your AI agents, IDEs, and applications directly to your enterprise databases
- PASS Cta present (required) — Quickstart: Running Toolbox using NPX
- PASS Pricing or access — Open source; access terms stated, no paywall on documentation or releases
- PASS Evidence or demo — 2 screenshots captured; quickstart, samples and reference sections present
What we saw
2 screenshots captured by the Hlido engine during the reviewed run (run-44b375bce0aea04e-mcp-toolbox-dev). Our own captures — not vendor marketing material.
What it does well
- Clean separation of build-time exploration tools from run-time constrained production tools
- Explicit supported-MCP-version statement distinguishing stable releases from draft specs
- Already supports the 2026-07-28 stateless MCP spec, with a launch write-up
- Documentation covers configuration, deployment, and monitoring & observability as first-class sections
- Open source with vendor backing — a higher continuity floor than a solo project
- Repository rename announced in-page with the exact remediation command
What it fails at
- No independent security review linked from the introduction
- Generic execute_sql tooling is a sharp edge; guardrails are left to the deployer
- Configuration format has already changed (flat format), requiring a version selector to read older docs
- Introduction alone is a 13-minute read — the on-ramp is not light
- No public statement on tested database coverage limits from this surface
Best for
- Teams giving IDE agents read access to a development database without hand-writing an MCP server
- Production agents needing tightly scoped, predefined database tools rather than open SQL
- Organisations standardising on MCP who want a vendor-maintained server rather than a bespoke one
- NL2SQL and semantic-search use cases that need a defined tool boundary
Not recommended for
- Anyone wanting to point generic SQL execution at production without building their own guardrails
- Teams needing a linked third-party security attestation before adoption
- Lightweight single-database use where a purpose-built server is simpler
Pricing & access
- Pricing findable on the public surfacePASS Open source; access terms stated, no paywall on documentation or releases (tested 2026-08-23)
Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-08-23.
Compared to
-
@langchain/mcp-adapters
server-vs-adapter
The LangChain adapters bridge existing MCP servers into a framework; Toolbox IS the server, and owns the database connection and tool definition. Use the adapters to consume, Toolbox to expose.
-
ViperJuice/mcp-gateway
endpoint-vs-gateway
A gateway multiplexes and routes across many MCP servers; Toolbox is the specialised database endpoint one of them would front. Different layers of the same stack.
Agent relevance
API CLI MCP SDK Behavioral-testable
Agentic-Commerce Readiness 85/100 · COMMERCE-READY
Independent readiness for agent delegation & transaction. How it’s scored · check live
This is an MCP server by definition — that is the whole product. Documented quickstart via NPX, install and run paths, and named client compatibility (Gemini CLI, Antigravity, Claude Code, Codex, other MCP clients). The custom-tools framework lets an operator define exactly the tool surface an agent sees, which is the correct control point for production agents.
Agent-friendly score: 10/10
Score over time
The longitudinal record — every point is the score as published on that date. Raw series.
Evidence
- Open-source MCP server connecting AI agents to enterprise databases — source (2026-08-23) verified
- Dual purpose: prebuilt generic tools and a custom tools framework — source (2026-08-23) verified
- Supports the 2026-07-28 stateless MCP spec — source (2026-08-23) verified
- Documentation includes Monitoring & Observability and Deploy sections — source (2026-08-23) verified
- Explicit Supported MCP Version section separating stable releases from draft specifications — source (2026-08-23) verified

