Internal evaluation Read-only endpointv0.1.1

tidbcloud-mcp

An MCP server that lets your AI agent (Claude Code, Cursor, VS Code, Claude Desktop) inspect TiDB Cloud clusters and query data, safely. This shared endpoint exposes read tools only: no create, no execute, no delete.

1. Your TiDB Cloud keys

Create a management API key in the TiDB Cloud console (Organization Settings > API Keys): you get a public and a private key. Paste both here once. Every command on this page, hosted and local, fills in from these.

Your keys never leave this page. Encoding runs in your browser with inline JavaScript; the page loads nothing external and sends nothing anywhere.

2. Connect to the hosted server (read-only)

Pick your client and copy the snippet. Your keys from step 1 are already filled in.

Run this in a terminal, then start a new session and check /mcp.

Add to ~/.cursor/mcp.json, or use the one-click install.

Add to Cursor

Add to .vscode/mcp.json. Note the top-level key is servers, not mcpServers.

Claude Desktop and any client that can launch a command: bridge with mcp-remote. This is the universal fallback.

ChatGPT is not supported today: its connectors accept OAuth or no-auth only, and this endpoint authenticates by header.

Optional: run it locally to test writes

Only needed if you want to exercise writes and the preflight/confirm flow; the hosted server above already covers read-only. Run it on your own machine, where enabling writes is your explicit startup decision. This uses the same two keys from step 1 (passed as env vars, so the command below contains them in plain text).

git clone https://github.com/tidbcloud/mcp-server.git
cd mcp-server && pnpm install && pnpm build

Run in a terminal, then start a new session.

Add to ~/.cursor/mcp.json.

Add to .vscode/mcp.json (top-level key is servers).

Add to claude_desktop_config.json, then restart the app.

Default is --allow-write (data DML/DDL). Check the box above for --allow-admin (adds cluster create and delete). Omit both flags for a read-only local server. The keys ride along as env vars, so these contain them in plain text; use them in your own machine only.