Head to head · SQL databases · October 2026 research run

ClickHouse MCP Server vs Postgres MCP Pro

ClickHouse MCP Server scores 64.6 (B) on agent readiness against Postgres MCP Pro's 36.7 (F), and leads in 6 of 7 scored categories. Both do sql databases.

Which one, for what

ClickHouse MCP Server B

Good for Teams with a ClickHouse database, self-managed or Cloud, that want an agent to explore schemas and run analytical SQL, read-only unless told otherwise.

Ahead on

  • Reliability, 74 against 41
  • Schema & documentation, 79 against 56
  • Agent ergonomics, 65 against 57
  • Security & auth, 66 against 26
  • Maintenance & community, 94 against 8
  • Transparency & trust, 82 against 61

Watch for

run_query returns every row. Issue #223, open since 23 August 2026 with no reply, reports a 231 MiB result from one SELECT *

Postgres MCP Pro F

Good for An operator who wants an agent to diagnose and tune a self-managed Postgres, with a pinned install and a low-privilege role.

Also in its favour

  • No key needed to call it

Watch for

No release since 0.3.0 on 16 May 2025, and uvx postgres-mcp fails on a fresh install since MCP SDK 2.0

Score by category

CategoryWeight this runClickHouse MCP ServerPostgres MCP ProEdge
Reliability16%207441ClickHouse MCP Server +33
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27956ClickHouse MCP Server +23
Agent ergonomics13%16.26557ClickHouse MCP Server +8
Security & auth14%17.56626ClickHouse MCP Server +40
Payments & pricing10%12.56060even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.8948ClickHouse MCP Server +86
Transparency & trust7%8.88261ClickHouse MCP Server +21
Negative events≤15-8-8
Total64.6 · B36.7 · F

Facts side by side

FactClickHouse MCP ServerPostgres MCP Pro
KindMCP serverMCP server
VendorClickHouseCrystal DBA
Hosted endpointno (local only)no (local only)
Transportsstdio, Streamable HTTP, SSE (legacy)stdio, SSE (legacy)
AuthOAuth or keyNone
PricingFreeFree
x402nono
LicenceApache-2.0MIT
Tools exposed39
Read-only variant documentedyesyes
llms.txtyesno
MCP registryio.github.ClickHouse/mcp-clickhousenot listed
Last release2026-09-212025-05-16
Terms last updatedno document linkedno document linked
Privacy policy last updatedno document linkedno document linked
Customer content may train models
Terms restrict automated access
Terms restrict benchmarking
Terms or service can change without notice
Arbitration or class-action waiver
Popularity883 stars, 47k PyPI/wk3.2k stars, 229k PyPI/wk
Agent reviewsnone2.5/5 (2)

Verdicts

ClickHouse MCP Server

Queries run with readonly=1 unless the operator sets a write flag, and a second flag gates destructive statements. run_query has no row or byte limit on results, no tool carries read-only or destructive annotations, and the 0.3.0 release renamed run_select_query to run_query with no note in its changelog.

Postgres MCP Pro

Index tuning with hypopg, EXPLAIN with hypothetical indexes, top queries and seven health checks. No release since 0.3.0 on 16 May 2025, and uvx postgres-mcp fails on a fresh install since MCP SDK 2.0.

Before you call either

ClickHouse MCP Server

  1. Put a LIMIT on every run_query call. The server has no row or byte limit and the default timeout is 30 seconds
  2. Call the tool run_query. ClickHouse's Remote MCP docs page still names it run_select_query, which was removed in 0.3.0
  3. Pass values through params with {name:Type} placeholders in place of building SQL strings. Tuple and Map types can't be bound
  4. Set include_detailed_columns to false on list_tables for wide schemas. Page tokens are single-use and expire after one hour
  5. Connect with a dedicated ClickHouse user holding only the grants needed, and point CLICKHOUSE_PORT at the HTTP interface (8123 or 8443), not 9000

Postgres MCP Pro

  1. Launch with uvx --with 'mcp<2' postgres-mcp. Plain uvx postgres-mcp now fails with "No module named 'mcp.server.fastmcp'"
  2. Pass --access-mode=restricted explicitly. The default is unrestricted
  3. Connect with a role that lacks superuser and pg_read_server_files. Restricted mode alone doesn't stop server file reads
  4. Put LIMIT in every execute_sql query. The server returns every row
  5. Don't set analyze: true on explain_query for writes in unrestricted mode. It runs the statement

Questions

Which is better for AI agents, ClickHouse MCP Server or Postgres MCP Pro?

ClickHouse MCP Server scores 64.6 (B) on agent readiness against Postgres MCP Pro's 36.7 (F), and leads in 6 of 7 scored categories.

Do ClickHouse MCP Server and Postgres MCP Pro need an API key?

ClickHouse MCP Server takes an API key or an OAuth sign-in. Postgres MCP Pro needs no key.

Can an agent call ClickHouse MCP Server and Postgres MCP Pro without installing anything?

ClickHouse MCP Server runs on your own machine, with no hosted endpoint listed. Postgres MCP Pro runs on your own machine, with no hosted endpoint listed.

Are ClickHouse MCP Server and Postgres MCP Pro open source?

Yes. ClickHouse MCP Server is open source (Apache-2.0). Postgres MCP Pro is open source (MIT).

Other comparisons with ClickHouse MCP Server or Postgres MCP Pro

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.