Best of · Developer & infrastructure

Best database, file and memory tools for AI agents

The 10 highest-scoring of 12 database, file and memory tools on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change.

  • 12 ranked
  • 2 agent-ready
  • 2 accept x402
  • 4 hosted endpoints
  • Updated 9 October 2026

Top three

Picks by need

Worked out from the scores, prices and facts, so they change when the research does.

Highest score overall

MongoDB MCP Server A

A, 79.9/100 on the benchmark.

Also Supabase API + MCP, BB, 75.6/100.

Schema & documentation

Supabase API + MCP BB

89/100 on schema & documentation, against 81 for the overall leader.

Agent ergonomics

Supabase API + MCP BB

88/100 on agent ergonomics, against 75 for the overall leader.

Security & auth

Supabase API + MCP BB

84/100 on security & auth, against 81 for the overall leader.

Maintenance & community

ClickHouse MCP Server B

94/100 on maintenance & community, against 92 for the overall leader.

Transparency & trust

Supabase API + MCP BB

90/100 on transparency & trust, against 83 for the overall leader.

Paying per call with no account (x402)

CoinMarketCap x402 API B

accepts x402, $0.01 a call.

Also Nansen x402 API, accepts x402, $0.01 a call.

A hosted MCP endpoint

Supabase API + MCP BB

remote MCP server, nothing to install.

Self-hosting under an open licence

Supabase API + MCP BB

self-hosted, Apache-2 licence.

Also ClickHouse MCP Server, self-hosted, Apache-2 licence.

The shortlist

#ToolGradeBest forPriceWhere
1 MongoDB MCP Server
MongoDB
A 79.9 Agents that query or administer MongoDB and Atlas, with read-only and confirmation controls an operator can rely on. Free · OSS local
2 Supabase API + MCP
Supabase
BB 75.6 Agents building on or administering Supabase projects, and for retrieval that wants vectors, full-text and SQL filters in one database. $25 / mo hosted and local
3 CoinMarketCap x402 API
CoinMarketCap
B 68.3 Agents that need current prices, rankings or DEX pair quotes without an account and can batch symbols. $0.01 / call hosted
4 Nansen x402 API
Nansen
B 67.4 Agents that track wallets, token flows and Smart Money and want to pay per call without an account. $0.01 / call hosted
5 PlanetScale MCP Server
PlanetScale
B 66.4 Agents that inspect and tune an existing PlanetScale database, using Insights, schema recommendations, error patterns and logs, with SQL when granted. $5 / mo hosted
6 ClickHouse MCP Server
ClickHouse
B 64.6 Teams with a ClickHouse database, self-managed or Cloud, that want an agent to explore schemas and run analytical SQL, read-only unless told otherwise. Free · OSS local
7 Filesystem (MCP reference server)
MCP project (reference servers)
C 59.2 Giving a local agent scoped read and write access to a project folder with host-side gating of writes through annotations. Free · OSS local
8 Snowflake-managed MCP server
Snowflake Inc.
C 56.4 A company that already keeps its data in Snowflake and wants outside MCP clients to query it under existing roles, best through one Cortex Agent tool. $2 / credit local
9 Redis MCP
Redis
C 55.7 Teams with a Redis database that want an agent to read and write keys, streams, JSON documents and vector indexes on a developer's machine. Free · OSS local
10 Memory (MCP reference server)
MCP project (reference servers)
C 54.2 A single local agent that wants a small, inspectable store of facts about people and projects. Free · OSS local

2 more are ranked in the full table.

How to choose

  1. Read and write scopeCheck whether access can be limited to read or write on named tables, collections or folders, since an agent with broad write access can destroy data.
  2. Self-hosted or hosted storageCheck whether a local file or memory tool keeps data on the agent's own machine or a hosted service, because that decides which data protection terms apply.
  3. Rate limits and result capsCheck the rate limits and row or result caps, since an agent that loops over queries will hit a throttle or get a truncated result without noticing.
  4. Network path and sub-processorsCheck which network paths and sub-processors touch query data, since a hosted database may route an agent's rows through infrastructure its operator never approved.

Each one in detail

#1

MongoDB MCP Server

A 79.9/100

MongoDB's official MCP server for querying and managing databases and Atlas resources, with configurable tool access.

Verdict --readOnly drops every create, update and delete tool, and --disabledTools trims by name, category or operation type. 53 tools with Atlas credentials, and most database tool descriptions are one line.

Choose it for Agents that query or administer MongoDB and Atlas, with read-only and confirmation controls an operator can rely on.

Strengths

  • --readOnly drops every create, update and delete tool, and --disabledTools trims by name, category or operation type
  • Drops, delete-many, user and access-list creation and $out or $merge pipelines ask for confirmation through elicitation by default
  • Results arrive inside per-call untrusted-data tags with a warning, on by default

Weaknesses

  • 53 tools with Atlas credentials, and most database tool descriptions are one line
  • Every database call needs connectionId since v2.0.0, even with a configured connection string
  • Confirmation is skipped without a prompt when the client doesn't support elicitation

Price Free · OSSAuth OAuth or keyx402 nolocal

Full assessment

#2

Supabase API + MCP

BB 75.6/100

Hosted Postgres with an auto-generated REST API (PostgREST), GraphQL, auth, storage, realtime and Edge Functions, plus a Management API and an official MCP server.

Verdict OAuth 2.1 with dynamic client registration, plus personal access tokens scoped to chosen projects and permissions. Several multi-hour platform incidents between 27 August and 30 September.

Choose it for Agents building on or administering Supabase projects, and for retrieval that wants vectors, full-text and SQL filters in one database.

Strengths

  • OAuth 2.1 with dynamic client registration, plus personal access tokens scoped to chosen projects and permissions
  • read_only, project_ref and features cut the server from 34 tools to as few as 6 and run SQL as a read-only role
  • Destructive SQL and cost-bearing creates ask for confirmation through elicitation since v0.13.0

Weaknesses

  • Several multi-hour platform incidents between 27 August and 30 September
  • Read-write with seven feature groups is the default, and the agent plugin has no read-only option
  • Untrusted data in tables can still steer an agent that reads it, as Supabase says itself

Price $25 / moAuth OAuth or keyx402 nohosted and local

Full assessment · Against #1, MongoDB MCP Server

#3

CoinMarketCap x402 API

B 68.3/100

CoinMarketCap market-data endpoints for cryptocurrency and DEX quotes, with per-call USDC payments through x402.

Verdict x402 on four endpoints at $0.01 a call, with payment taken only when data is returned. Only four endpoints are sold by x402, and none of them covers history.

Choose it for Agents that need current prices, rankings or DEX pair quotes without an account and can batch symbols.

Strengths

  • x402 on four endpoints at $0.01 a call, with payment taken only when data is returned
  • Quotes accept many symbols per call, with batches up to 250 items since August 2026
  • Free Basic plan without a card, and a keyless /public-api mode for 19 endpoints

Weaknesses

  • Only four endpoints are sold by x402, and none of them covers history
  • x402 calls are limited to 30 a minute
  • No Retry-After on 429, only a 60-second reset rule

Price $0.01 / callAuth Nonex402 yeshosted

Full assessment

#4

Nansen x402 API

B 67.4/100

Nansen's on-chain analytics API for wallets, tokens and transaction flows, with per-call stablecoin payments through x402.

Verdict x402 on every Pro endpoint except labels, $0.01 or $0.05 a call, on Base, Solana or Monad. No status page, incident history or SLA that we could find.

Choose it for Agents that track wallets, token flows and Smart Money and want to pay per call without an account.

Strengths

  • x402 on every Pro endpoint except labels, $0.01 or $0.05 a call, on Base, Solana or Monad
  • Failed and rate-limited x402 calls aren't charged
  • OpenAPI 3.1 on each endpoint page, llms.txt and Markdown copies of the docs

Weaknesses

  • No status page, incident history or SLA that we could find
  • No security policy, disclosure route or certification found
  • Privacy policy gives no retention period and names no legal entity

Price $0.01 / callAuth Nonex402 yeshosted

Full assessment

#5

PlanetScale MCP Server

B 66.4/100

PlanetScale's hosted MCP server connects agents to PlanetScale Postgres, Vitess and Neki databases. Its 25 tools cover organisations, branches, schema, read and write SQL, Insights data, Postgres logs, invoices and documentation search, with OAuth or a service token.

Verdict OAuth scopes set no, read-only or full database access per organisation or database, each query runs on a credential created and deleted for that call, and an insights-only endpoint drops both SQL tools. Destructive statements are gated by a flag the model sets itself, no rate limit was found, and every plan needs a card.

Choose it for Agents that inspect and tune an existing PlanetScale database, using Insights, schema recommendations, error patterns and logs, with SQL when granted.

Strengths

  • OAuth scopes grant no, read-only or full access per organisation or per database, and administrators can cap query access for all members since 8 October 2026
  • Each query uses a database credential created for that call and deleted afterwards, and read queries run under a reader role
  • An insights-only endpoint omits planetscale_execute_read_query and planetscale_execute_write_query

Weaknesses

  • DELETE and DDL confirmation is a confirm_destructive flag the model sets, not a prompt the client shows the person
  • The write-query check matches the start of the statement by regular expression, so a statement behind a leading comment or a type it does not list is not matched, per the source
  • No rate limit for the MCP server or the API was found. The OpenAPI file lists 429 with no figures

Price $5 / moAuth OAuth or keyx402 nohosted

Full assessment · Against #1, MongoDB MCP Server

#6

ClickHouse MCP Server

B 64.6/100

ClickHouse's open-source MCP server for ClickHouse databases. The owner runs it locally or self-hosted, and it gives agents SQL queries, database and table listing, and an optional embedded chDB engine. Queries are read-only by default.

Verdict Queries run with readonly=1 unless the operator sets a write flag, and a second flag gates destructive statements. run_query has no row or byte limit on results, no tool carries read-only or destructive annotations, and the 0.3.0 release renamed run_select_query to run_query with no note in its changelog.

Choose it for Teams with a ClickHouse database, self-managed or Cloud, that want an agent to explore schemas and run analytical SQL, read-only unless told otherwise.

Strengths

  • Read-only by default through ClickHouse's readonly=1 setting, with CLICKHOUSE_ALLOW_WRITE_ACCESS and CLICKHOUSE_ALLOW_DROP as separate opt-ins
  • Three tools by default (run_query, list_databases, list_tables) and a fourth, run_chdb_select_query, only when chDB is enabled
  • HTTP and SSE transports refuse to start without a bearer token, a FastMCP OAuth or OIDC provider, or an explicit disable flag, and validate Host and Origin headers

Weaknesses

  • run_query returns every row. Issue #223, open since 23 August 2026 with no reply, reports a 231 MiB result from one SELECT *
  • No tool declares readOnlyHint or destructiveHint. Pull request #184 adding annotations has been open since 22 May 2026
  • Release 0.3.0 renamed run_select_query to run_query without saying so in its changelog or release notes, and ClickHouse's Remote MCP docs page still uses the old name

Price Free · OSSAuth OAuth or keyx402 nolocal

Full assessment · Against #1, MongoDB MCP Server

#7

Filesystem (MCP reference server)

C 59.2/100

Reference server for secure local file operations (read, write, edit, search, directory listing) restricted to allowed directories supplied as arguments or via MCP Roots.

Verdict All 14 tools carry readOnlyHint, and the four write tools set destructiveHint and idempotentHint accurately. No depth limit on directory_tree and no size cap on reads or search results.

Choose it for Giving a local agent scoped read and write access to a project folder with host-side gating of writes through annotations.

Strengths

  • All 14 tools carry readOnlyHint, and the four write tools set destructiveHint and idempotentHint accurately
  • Paths are confined to allowed directories from arguments or MCP Roots, with symlink targets resolved and checked
  • edit_file returns a git-style diff and takes dryRun

Weaknesses

  • No depth limit on directory_tree and no size cap on reads or search results
  • No read-only mode in the server itself, only read-only Docker mounts
  • About 3,200 tokens of tool definitions by our estimate, with no toolsets to trim them

Price Free · OSSAuth Nonex402 nolocal

Full assessment

Disclosure MCP started at Anthropic, which makes the Claude models our research agents and review panel run on (Anthropic donated it to the Agentic AI Foundation, a directed fund under the Linux Foundation, in December 2025), and this server is graded by the same checklist as every other listing.

#8

Snowflake-managed MCP server

C 56.4/100

Snowflake's managed MCP server is an object created in a Snowflake account that exposes Cortex Agents, Cortex Search, Cortex Analyst, SQL execution and custom functions, each as an MCP tool, over HTTP, with OAuth and role-based access control.

Verdict Tools are governed by Snowflake roles, the SQL tool is read-only by default, and sign-in runs through Snowflake OAuth or a company identity provider. No rate limits or tool-call error codes were found in the reviewed documentation, and a person must create the account, the server object and the OAuth integration before an agent can connect.

Choose it for A company that already keeps its data in Snowflake and wants outside MCP clients to query it under existing roles, best through one Cortex Agent tool.

Strengths

  • Each tool needs its own grant. USAGE on the MCP server does not give access to the agent, search service, semantic view, function or procedure behind a tool
  • The SQL execution tool defaults to read_only: true and takes a query_timeout and a named warehouse
  • OAuth with PKCE for public clients, role scopes, an allowed-roles list and, since 22 July 2026, binding to an external identity provider with RFC 9728 metadata

Weaknesses

  • No rate limits for the MCP endpoint and no JSON-RPC error codes were found in the reviewed documentation
  • No dynamic client registration. An administrator creates a security integration and hands the client ID and secret to each MCP client
  • On 20 August 2026 tools/call responses changed from one JSON body to an SSE stream, outside a behaviour change bundle and with no way to disable it

Price $2 / creditAuth OAuth or keyx402 nolocal

Full assessment · Against #1, MongoDB MCP Server

#9

Redis MCP

C 55.7/100

Redis's open-source MCP server for Redis databases. The owner runs it locally over stdio, and it gives agents tools for strings, hashes, lists, sets, sorted sets, streams, pub/sub, JSON documents and vector search.

Verdict Redis's server, under the MIT licence, maps 53 tools onto Redis commands, with typed inputs and a nightly CI run that passed on 9 October 2026. It has no read-only mode, no tool annotations and no changelog file, release 0.5.1 changed the unsubscribe input without a note, and PyPI installs failed to start from 28 July to 5 August 2026.

Choose it for Teams with a Redis database that want an agent to read and write keys, streams, JSON documents and vector indexes on a developer's machine.

Strengths

  • Maintained by Redis under the MIT licence, with 0.5.1 marked latest in the official MCP registry as io.github.redis/mcp-redis
  • Nightly CI passed on main on 9 October 2026 across Python 3.10 to 3.14 against a live Redis, with 347 test functions and an 80 per cent coverage floor
  • No tool runs an arbitrary Redis command. Each of the 53 tools maps to a named operation, and none exposes FLUSHALL, CONFIG or EVAL

Weaknesses

  • 53 tools load at once, with no toolsets and no read-only subset. Pull request #161 for a tool allowlist has been open since 28 July 2026
  • No tool declares readOnlyHint or destructiveHint, and nothing asks for confirmation before delete, json_del or xgroup_destroy. Pull request #181 was opened on 8 October 2026
  • Fresh PyPI installs failed to start from 28 July to 5 August 2026, because 0.5.0 had no upper bound on the mcp package (issues #163 and #169)

Price Free · OSSAuth OAuth or keyx402 nolocal

Full assessment · Against #1, MongoDB MCP Server

#10

Memory (MCP reference server)

C 54.2/100

Knowledge-graph persistent memory reference server (entities, relations, observations) stored as JSONL at MEMORY_FILE_PATH.

Verdict Nine tools with typed schemas and accurate read, destructive and idempotent annotations. No pagination or limits. read_graph returns everything and search_nodes every match.

Choose it for A single local agent that wants a small, inspectable store of facts about people and projects.

Strengths

  • Nine tools with typed schemas and accurate read, destructive and idempotent annotations
  • Plain JSONL storage at a path you choose, easy to back up, diff and edit by hand
  • Writes are atomic since 2026.8.31, so an interrupted save can't truncate the file

Weaknesses

  • No pagination or limits. read_graph returns everything and search_nodes every match
  • The published version can lose one of two writes made in the same turn. The fix is merged but unreleased
  • Search is case-insensitive substring matching, with no ranking or semantics

Price Free · OSSAuth Nonex402 nolocal

Full assessment

Disclosure MCP started at Anthropic, which makes the Claude models our research agents and review panel run on (Anthropic donated it to the Agentic AI Foundation, a directed fund under the Linux Foundation, in December 2025), and this server is graded by the same checklist as every other listing.

Head to head

All 43 comparisons in this category

Questions

What are the highest-rated database, file and memory tools for AI agents?

MongoDB MCP Server has the highest benchmark score of the 12 ranked database, file and memory tools, 79.9 (A). Supabase API + MCP is second with 75.6 (BB).

How many database, file and memory tools are agent-ready?

2 of the 12 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.

Which database, file and memory tools accept x402 payments?

CoinMarketCap x402 API and Nansen x402 API. An agent can pay these per call in USDC with no account.

How is this list ranked?

By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 9 October 2026.

How this list is made

The order is the Anchor benchmark score, the same number as on each listing and in the top list. Each listing is graded from public evidence against the benchmark checklist, and the picks above are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.

Full ranked table · 43 head-to-head comparisons · Best tools in every category

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.