Best of · Developer & infrastructure
Best database, file and memory tools for AI agents
The 10 highest-scoring of 12 database, file and memory tools on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change.
- 12 ranked
- 2 agent-ready
- 2 accept x402
- 4 hosted endpoints
- Updated 9 October 2026
Top three
Picks by need
Worked out from the scores, prices and facts, so they change when the research does.
Schema & documentation
89/100 on schema & documentation, against 81 for the overall leader.
Agent ergonomics
88/100 on agent ergonomics, against 75 for the overall leader.
Maintenance & community
94/100 on maintenance & community, against 92 for the overall leader.
Transparency & trust
90/100 on transparency & trust, against 83 for the overall leader.
Paying per call with no account (x402)
accepts x402, $0.01 a call.
Also Nansen x402 API, accepts x402, $0.01 a call.
Self-hosting under an open licence
self-hosted, Apache-2 licence.
Also ClickHouse MCP Server, self-hosted, Apache-2 licence.
The shortlist
| # | Tool | Grade | Best for | Price | Where |
|---|---|---|---|---|---|
| 1 | MongoDB MCP Server MongoDB |
A 79.9 | Agents that query or administer MongoDB and Atlas, with read-only and confirmation controls an operator can rely on. | Free · OSS | local |
| 2 | Supabase API + MCP Supabase |
BB 75.6 | Agents building on or administering Supabase projects, and for retrieval that wants vectors, full-text and SQL filters in one database. | $25 / mo | hosted and local |
| 3 | CoinMarketCap x402 API CoinMarketCap |
B 68.3 | Agents that need current prices, rankings or DEX pair quotes without an account and can batch symbols. | $0.01 / call | hosted |
| 4 | Nansen x402 API Nansen |
B 67.4 | Agents that track wallets, token flows and Smart Money and want to pay per call without an account. | $0.01 / call | hosted |
| 5 | PlanetScale MCP Server PlanetScale |
B 66.4 | Agents that inspect and tune an existing PlanetScale database, using Insights, schema recommendations, error patterns and logs, with SQL when granted. | $5 / mo | hosted |
| 6 | ClickHouse MCP Server ClickHouse |
B 64.6 | Teams with a ClickHouse database, self-managed or Cloud, that want an agent to explore schemas and run analytical SQL, read-only unless told otherwise. | Free · OSS | local |
| 7 | Filesystem (MCP reference server) MCP project (reference servers) |
C 59.2 | Giving a local agent scoped read and write access to a project folder with host-side gating of writes through annotations. | Free · OSS | local |
| 8 | Snowflake-managed MCP server Snowflake Inc. |
C 56.4 | A company that already keeps its data in Snowflake and wants outside MCP clients to query it under existing roles, best through one Cortex Agent tool. | $2 / credit | local |
| 9 | Redis MCP Redis |
C 55.7 | Teams with a Redis database that want an agent to read and write keys, streams, JSON documents and vector indexes on a developer's machine. | Free · OSS | local |
| 10 | Memory (MCP reference server) MCP project (reference servers) |
C 54.2 | A single local agent that wants a small, inspectable store of facts about people and projects. | Free · OSS | local |
2 more are ranked in the full table.
How to choose
- Read and write scopeCheck whether access can be limited to read or write on named tables, collections or folders, since an agent with broad write access can destroy data.
- Self-hosted or hosted storageCheck whether a local file or memory tool keeps data on the agent's own machine or a hosted service, because that decides which data protection terms apply.
- Rate limits and result capsCheck the rate limits and row or result caps, since an agent that loops over queries will hit a throttle or get a truncated result without noticing.
- Network path and sub-processorsCheck which network paths and sub-processors touch query data, since a hosted database may route an agent's rows through infrastructure its operator never approved.
Each one in detail
MongoDB MCP Server
A 79.9/100MongoDB's official MCP server for querying and managing databases and Atlas resources, with configurable tool access.
Verdict --readOnly drops every create, update and delete tool, and --disabledTools trims by name, category or operation type. 53 tools with Atlas credentials, and most database tool descriptions are one line.
Choose it for Agents that query or administer MongoDB and Atlas, with read-only and confirmation controls an operator can rely on.
Strengths
--readOnlydrops every create, update and delete tool, and--disabledToolstrims by name, category or operation type- Drops,
delete-many, user and access-list creation and$outor$mergepipelines ask for confirmation through elicitation by default - Results arrive inside per-call untrusted-data tags with a warning, on by default
Weaknesses
- 53 tools with Atlas credentials, and most database tool descriptions are one line
- Every database call needs
connectionIdsince v2.0.0, even with a configured connection string - Confirmation is skipped without a prompt when the client doesn't support elicitation
Price Free · OSSAuth OAuth or keyx402 nolocal
Supabase API + MCP
BB 75.6/100Hosted Postgres with an auto-generated REST API (PostgREST), GraphQL, auth, storage, realtime and Edge Functions, plus a Management API and an official MCP server.
Verdict OAuth 2.1 with dynamic client registration, plus personal access tokens scoped to chosen projects and permissions. Several multi-hour platform incidents between 27 August and 30 September.
Choose it for Agents building on or administering Supabase projects, and for retrieval that wants vectors, full-text and SQL filters in one database.
Strengths
- OAuth 2.1 with dynamic client registration, plus personal access tokens scoped to chosen projects and permissions
read_only,project_refandfeaturescut the server from 34 tools to as few as 6 and run SQL as a read-only role- Destructive SQL and cost-bearing creates ask for confirmation through elicitation since v0.13.0
Weaknesses
- Several multi-hour platform incidents between 27 August and 30 September
- Read-write with seven feature groups is the default, and the agent plugin has no read-only option
- Untrusted data in tables can still steer an agent that reads it, as Supabase says itself
Price $25 / moAuth OAuth or keyx402 nohosted and local
CoinMarketCap x402 API
B 68.3/100CoinMarketCap market-data endpoints for cryptocurrency and DEX quotes, with per-call USDC payments through x402.
Verdict x402 on four endpoints at $0.01 a call, with payment taken only when data is returned. Only four endpoints are sold by x402, and none of them covers history.
Choose it for Agents that need current prices, rankings or DEX pair quotes without an account and can batch symbols.
Strengths
- x402 on four endpoints at $0.01 a call, with payment taken only when data is returned
- Quotes accept many symbols per call, with batches up to 250 items since August 2026
- Free Basic plan without a card, and a keyless
/public-apimode for 19 endpoints
Weaknesses
- Only four endpoints are sold by x402, and none of them covers history
- x402 calls are limited to 30 a minute
- No
Retry-Afteron 429, only a 60-second reset rule
Price $0.01 / callAuth Nonex402 yeshosted
Nansen x402 API
B 67.4/100Nansen's on-chain analytics API for wallets, tokens and transaction flows, with per-call stablecoin payments through x402.
Verdict x402 on every Pro endpoint except labels, $0.01 or $0.05 a call, on Base, Solana or Monad. No status page, incident history or SLA that we could find.
Choose it for Agents that track wallets, token flows and Smart Money and want to pay per call without an account.
Strengths
- x402 on every Pro endpoint except labels, $0.01 or $0.05 a call, on Base, Solana or Monad
- Failed and rate-limited x402 calls aren't charged
- OpenAPI 3.1 on each endpoint page, llms.txt and Markdown copies of the docs
Weaknesses
- No status page, incident history or SLA that we could find
- No security policy, disclosure route or certification found
- Privacy policy gives no retention period and names no legal entity
Price $0.01 / callAuth Nonex402 yeshosted
PlanetScale MCP Server
B 66.4/100PlanetScale's hosted MCP server connects agents to PlanetScale Postgres, Vitess and Neki databases. Its 25 tools cover organisations, branches, schema, read and write SQL, Insights data, Postgres logs, invoices and documentation search, with OAuth or a service token.
Verdict OAuth scopes set no, read-only or full database access per organisation or database, each query runs on a credential created and deleted for that call, and an insights-only endpoint drops both SQL tools. Destructive statements are gated by a flag the model sets itself, no rate limit was found, and every plan needs a card.
Choose it for Agents that inspect and tune an existing PlanetScale database, using Insights, schema recommendations, error patterns and logs, with SQL when granted.
Strengths
- OAuth scopes grant no, read-only or full access per organisation or per database, and administrators can cap query access for all members since 8 October 2026
- Each query uses a database credential created for that call and deleted afterwards, and read queries run under a reader role
- An insights-only endpoint omits
planetscale_execute_read_queryandplanetscale_execute_write_query
Weaknesses
- DELETE and DDL confirmation is a
confirm_destructiveflag the model sets, not a prompt the client shows the person - The write-query check matches the start of the statement by regular expression, so a statement behind a leading comment or a type it does not list is not matched, per the source
- No rate limit for the MCP server or the API was found. The OpenAPI file lists 429 with no figures
Price $5 / moAuth OAuth or keyx402 nohosted
ClickHouse MCP Server
B 64.6/100ClickHouse's open-source MCP server for ClickHouse databases. The owner runs it locally or self-hosted, and it gives agents SQL queries, database and table listing, and an optional embedded chDB engine. Queries are read-only by default.
Verdict Queries run with readonly=1 unless the operator sets a write flag, and a second flag gates destructive statements. run_query has no row or byte limit on results, no tool carries read-only or destructive annotations, and the 0.3.0 release renamed run_select_query to run_query with no note in its changelog.
Choose it for Teams with a ClickHouse database, self-managed or Cloud, that want an agent to explore schemas and run analytical SQL, read-only unless told otherwise.
Strengths
- Read-only by default through ClickHouse's
readonly=1setting, withCLICKHOUSE_ALLOW_WRITE_ACCESSandCLICKHOUSE_ALLOW_DROPas separate opt-ins - Three tools by default (
run_query,list_databases,list_tables) and a fourth,run_chdb_select_query, only when chDB is enabled - HTTP and SSE transports refuse to start without a bearer token, a FastMCP OAuth or OIDC provider, or an explicit disable flag, and validate Host and Origin headers
Weaknesses
run_queryreturns every row. Issue #223, open since 23 August 2026 with no reply, reports a 231 MiB result from oneSELECT *- No tool declares
readOnlyHintordestructiveHint. Pull request #184 adding annotations has been open since 22 May 2026 - Release 0.3.0 renamed
run_select_querytorun_querywithout saying so in its changelog or release notes, and ClickHouse's Remote MCP docs page still uses the old name
Price Free · OSSAuth OAuth or keyx402 nolocal
Filesystem (MCP reference server)
C 59.2/100Reference server for secure local file operations (read, write, edit, search, directory listing) restricted to allowed directories supplied as arguments or via MCP Roots.
Verdict All 14 tools carry readOnlyHint, and the four write tools set destructiveHint and idempotentHint accurately. No depth limit on directory_tree and no size cap on reads or search results.
Choose it for Giving a local agent scoped read and write access to a project folder with host-side gating of writes through annotations.
Strengths
- All 14 tools carry
readOnlyHint, and the four write tools setdestructiveHintandidempotentHintaccurately - Paths are confined to allowed directories from arguments or MCP Roots, with symlink targets resolved and checked
edit_filereturns a git-style diff and takesdryRun
Weaknesses
- No depth limit on
directory_treeand no size cap on reads or search results - No read-only mode in the server itself, only read-only Docker mounts
- About 3,200 tokens of tool definitions by our estimate, with no toolsets to trim them
Price Free · OSSAuth Nonex402 nolocal
Disclosure MCP started at Anthropic, which makes the Claude models our research agents and review panel run on (Anthropic donated it to the Agentic AI Foundation, a directed fund under the Linux Foundation, in December 2025), and this server is graded by the same checklist as every other listing.
Snowflake-managed MCP server
C 56.4/100Snowflake's managed MCP server is an object created in a Snowflake account that exposes Cortex Agents, Cortex Search, Cortex Analyst, SQL execution and custom functions, each as an MCP tool, over HTTP, with OAuth and role-based access control.
Verdict Tools are governed by Snowflake roles, the SQL tool is read-only by default, and sign-in runs through Snowflake OAuth or a company identity provider. No rate limits or tool-call error codes were found in the reviewed documentation, and a person must create the account, the server object and the OAuth integration before an agent can connect.
Choose it for A company that already keeps its data in Snowflake and wants outside MCP clients to query it under existing roles, best through one Cortex Agent tool.
Strengths
- Each tool needs its own grant.
USAGEon the MCP server does not give access to the agent, search service, semantic view, function or procedure behind a tool - The SQL execution tool defaults to
read_only: trueand takes aquery_timeoutand a named warehouse - OAuth with PKCE for public clients, role scopes, an allowed-roles list and, since 22 July 2026, binding to an external identity provider with RFC 9728 metadata
Weaknesses
- No rate limits for the MCP endpoint and no JSON-RPC error codes were found in the reviewed documentation
- No dynamic client registration. An administrator creates a security integration and hands the client ID and secret to each MCP client
- On 20 August 2026
tools/callresponses changed from one JSON body to an SSE stream, outside a behaviour change bundle and with no way to disable it
Price $2 / creditAuth OAuth or keyx402 nolocal
Redis MCP
C 55.7/100Redis's open-source MCP server for Redis databases. The owner runs it locally over stdio, and it gives agents tools for strings, hashes, lists, sets, sorted sets, streams, pub/sub, JSON documents and vector search.
Verdict Redis's server, under the MIT licence, maps 53 tools onto Redis commands, with typed inputs and a nightly CI run that passed on 9 October 2026. It has no read-only mode, no tool annotations and no changelog file, release 0.5.1 changed the unsubscribe input without a note, and PyPI installs failed to start from 28 July to 5 August 2026.
Choose it for Teams with a Redis database that want an agent to read and write keys, streams, JSON documents and vector indexes on a developer's machine.
Strengths
- Maintained by Redis under the MIT licence, with 0.5.1 marked latest in the official MCP registry as
io.github.redis/mcp-redis - Nightly CI passed on main on 9 October 2026 across Python 3.10 to 3.14 against a live Redis, with 347 test functions and an 80 per cent coverage floor
- No tool runs an arbitrary Redis command. Each of the 53 tools maps to a named operation, and none exposes
FLUSHALL,CONFIGorEVAL
Weaknesses
- 53 tools load at once, with no toolsets and no read-only subset. Pull request #161 for a tool allowlist has been open since 28 July 2026
- No tool declares
readOnlyHintordestructiveHint, and nothing asks for confirmation beforedelete,json_delorxgroup_destroy. Pull request #181 was opened on 8 October 2026 - Fresh PyPI installs failed to start from 28 July to 5 August 2026, because 0.5.0 had no upper bound on the
mcppackage (issues #163 and #169)
Price Free · OSSAuth OAuth or keyx402 nolocal
Memory (MCP reference server)
C 54.2/100Knowledge-graph persistent memory reference server (entities, relations, observations) stored as JSONL at MEMORY_FILE_PATH.
Verdict Nine tools with typed schemas and accurate read, destructive and idempotent annotations. No pagination or limits. read_graph returns everything and search_nodes every match.
Choose it for A single local agent that wants a small, inspectable store of facts about people and projects.
Strengths
- Nine tools with typed schemas and accurate read, destructive and idempotent annotations
- Plain JSONL storage at a path you choose, easy to back up, diff and edit by hand
- Writes are atomic since 2026.8.31, so an interrupted save can't truncate the file
Weaknesses
- No pagination or limits.
read_graphreturns everything andsearch_nodesevery match - The published version can lose one of two writes made in the same turn. The fix is merged but unreleased
- Search is case-insensitive substring matching, with no ranking or semantics
Price Free · OSSAuth Nonex402 nolocal
Disclosure MCP started at Anthropic, which makes the Claude models our research agents and review panel run on (Anthropic donated it to the Agentic AI Foundation, a directed fund under the Linux Foundation, in December 2025), and this server is graded by the same checklist as every other listing.
Head to head
- MongoDB MCP Server vs Supabase API + MCP A 79.9 vs BB 75.6
- MongoDB MCP Server vs PlanetScale MCP Server A 79.9 vs B 66.4
- PlanetScale MCP Server vs Supabase API + MCP B 66.4 vs BB 75.6
- CoinMarketCap x402 API vs Nansen x402 API B 68.3 vs B 67.4
Questions
What are the highest-rated database, file and memory tools for AI agents?
MongoDB MCP Server has the highest benchmark score of the 12 ranked database, file and memory tools, 79.9 (A). Supabase API + MCP is second with 75.6 (BB).
How many database, file and memory tools are agent-ready?
2 of the 12 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.
Which database, file and memory tools accept x402 payments?
CoinMarketCap x402 API and Nansen x402 API. An agent can pay these per call in USDC with no account.
How is this list ranked?
By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 9 October 2026.
How this list is made
The order is the Anchor benchmark score, the same number as on each listing and in the top list. Each listing is graded from public evidence against the benchmark checklist, and the picks above are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.
Full ranked table · 43 head-to-head comparisons · Best tools in every category