MCP Toolbox for Databases

Infrastructure · tested 2026-08-23 · re-test due 2026-11-23 · by the Hlido desk, not the vendor

In short: Google's open-source MCP server for enterprise databases — dual-purpose, well-documented, and already tracking the newest stateless MCP spec.

5 PASS · 0 FAIL of 5 public-surface claims

Quick answer

MCP Toolbox for Databases scores 85/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-08-23). STEADY (85) for a well-maintained, well-documented open-source MCP server with a clear dual-purpose architecture, explicit spec-version discipline, and observability treated as a first-class documentation section.

MCP Toolbox for Databases connects AI agents, IDEs and applications directly to enterprise databases, and it does two separable jobs rather than one. The build-time half is a ready-to-use MCP server with prebuilt generic tools — list_tables, execute_sql and similar — that lets Gemini CLI, Antigravity, Claude Code, Codex or any MCP client explore a schema and generate code without boilerplate. The run-time half is a framework for defining your own constrained tools: structured queries, semantic search, NL2SQL, scoped so a production agent gets exactly the surface you intend and nothing more. That split matters, because the generic tools are the thing you want in an IDE and precisely the thing you do not want pointed at production. The documentation surface is the strongest signal here. Versioned docs with a version selector, a stated position on supported MCP versions separating stable releases from draft specifications, sections for configuration, deployment, and monitoring and observability, and a same-page notice that the project already supports the 2026-07-28 stateless MCP spec. Projects that document their own spec-compatibility boundary tend to be the ones that maintain it. The repository rename from genai-toolbox to mcp-toolbox is announced in-page with the exact git remote command, which is a small thing that says something about the maintenance posture. What the public surface does not settle is operational: there is no independent security review linked, and the security model for the generic execute_sql path in a shared environment is left to the deployer. Read the security guidance before pointing this at anything that matters.

Why STEADY

STEADY (85) for a well-maintained, well-documented open-source MCP server with a clear dual-purpose architecture, explicit spec-version discipline, and observability treated as a first-class documentation section. Vendor backing raises the continuity floor. Not VITAL because the surface leaves the security model of the generic database-access path to the deployer without a linked independent review, and because a prebuilt execute_sql tool is a genuinely sharp edge that deserves more guardrail documentation than the introduction gives it.

Public-surface checklist

What we saw

2 screenshots captured by the Hlido engine during the reviewed run (run-44b375bce0aea04e-mcp-toolbox-dev). Our own captures — not vendor marketing material.

MCP Toolbox for Databases — run screenshot 1 (home.png)
home.png
MCP Toolbox for Databases — run screenshot 2 (page_.png)
page_.png

What it does well

What it fails at

Best for

  • Teams giving IDE agents read access to a development database without hand-writing an MCP server
  • Production agents needing tightly scoped, predefined database tools rather than open SQL
  • Organisations standardising on MCP who want a vendor-maintained server rather than a bespoke one
  • NL2SQL and semantic-search use cases that need a defined tool boundary

Not recommended for

  • Anyone wanting to point generic SQL execution at production without building their own guardrails
  • Teams needing a linked third-party security attestation before adoption
  • Lightweight single-database use where a purpose-built server is simpler

Pricing & access

Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-08-23.

Compared to

Agent relevance

API CLI MCP SDK Behavioral-testable

Agentic-Commerce Readiness 85/100 · COMMERCE-READY

Independent readiness for agent delegation & transaction. How it’s scored · check live

This is an MCP server by definition — that is the whole product. Documented quickstart via NPX, install and run paths, and named client compatibility (Gemini CLI, Antigravity, Claude Code, Codex, other MCP clients). The custom-tools framework lets an operator define exactly the tool surface an agent sees, which is the correct control point for production agents.

Agent-friendly score: 10/10

Evidence

scorecard.json · transparency passport · registry · methodology

More: compare agents · best of · developer tools · incident registry

Verdict by Hlido Editor, our automated editorial system · Method: public-surface-tier-1+editorial-narrative-v2 · Methodology version 2026.05 · Next review due 2026-11-23

How this page was produced. The scores, claim verdicts and evidence come from automated hands-on testing of the product’s public surface. The written analysis is drafted by an AI system, and pages publish without a person reviewing each one. Hlido publishes this record and answers for it — tell us if anything here is wrong and we will correct it.

Embed this trust badge

Hlido trust score

Live, always-current independent score — free to embed on your site or README. No vendor pays for placement.

Markdown

[![Hlido trust score](https://hlido.eu/badge/googleapis-genai-toolbox.svg)](https://hlido.eu/check/?agent=googleapis-genai-toolbox)

HTML

<a href="https://hlido.eu/check/?agent=googleapis-genai-toolbox"><img src="https://hlido.eu/badge/googleapis-genai-toolbox.svg" alt="Hlido trust score"></a>