{
  "data": {
    "a": {
      "slug": "clickhouse-mcp-server",
      "name": "ClickHouse MCP Server",
      "vendor": "ClickHouse",
      "vendorUrl": "https://clickhouse.com",
      "kind": "mcp",
      "category": "data",
      "summary": "ClickHouse's open-source MCP server for ClickHouse databases. The owner runs it locally or self-hosted, and it gives agents SQL queries, database and table listing, and an optional embedded chDB engine. Queries are read-only by default.",
      "url": "https://www.anchorterminal.com/tools/clickhouse-mcp-server",
      "markdownUrl": "https://www.anchorterminal.com/tools/clickhouse-mcp-server.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/clickhouse-mcp-server.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/clickhouse-mcp-server.json",
      "repo": "https://github.com/ClickHouse/mcp-clickhouse",
      "license": "Apache-2.0",
      "transports": [
        "stdio",
        "streamable-http",
        "sse"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "mcp-clickhouse"
        },
        {
          "registry": "oci",
          "name": "ghcr.io/clickhouse/mcp-clickhouse"
        }
      ],
      "auth": "mixed",
      "authNotes": "The server signs in to ClickHouse with `CLICKHOUSE_USER` and `CLICKHOUSE_PASSWORD`, or with an X.509 client certificate (`CLICKHOUSE_CLIENT_CERT`, added in 0.7.0), and can set a role with `CLICKHOUSE_ROLE`. An admin creates the user, self-serve, and ClickHouse grants set what it can do. stdio needs no caller credential. The HTTP and SSE transports refuse to start unless one of a static bearer token (`CLICKHOUSE_MCP_AUTH_TOKEN`), a FastMCP OAuth or OIDC provider (`FASTMCP_SERVER_AUTH`) or `CLICKHOUSE_MCP_AUTH_DISABLED=true` is set. Every caller shares the one ClickHouse user unless custom middleware overrides the connection per request.",
      "pricing": "free",
      "pricingNotes": "Free and open source under Apache-2.0, with nothing to buy for the server. It needs a ClickHouse database, which can be self-managed open-source ClickHouse, ClickHouse Cloud or the embedded chDB engine. The README gives a public SQL playground (`sql-clickhouse.clickhouse.com`, user `demo`, empty password) for trying it with no account. ClickHouse Cloud prices were not checked. The separate hosted Remote MCP server is a ClickHouse Cloud feature and is not what this listing grades (checked 2026-10-09).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the README, the changelog or the source (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": 3,
      "popularity": {
        "githubStars": 883,
        "npmWeekly": null,
        "pypiWeekly": 47206,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://github.com/ClickHouse/mcp-clickhouse#readme",
      "llmsTxt": "https://clickhouse.com/docs/llms.txt",
      "registryName": "io.github.ClickHouse/mcp-clickhouse",
      "capabilities": [
        "db.sql"
      ],
      "tags": [
        "official",
        "local",
        "open-source",
        "self-hosted",
        "mcp",
        "python",
        "docker",
        "read-only-mode",
        "database"
      ],
      "lastRelease": "2026-09-21",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.6,
        "grade": "B",
        "agentReady": false,
        "rank": 312,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 94,
          "payments": 60,
          "reliability": 74,
          "schema": 79,
          "security": 66,
          "transparency": 82
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -8,
        "negativeNotes": [
          "-3: release 0.3.0 on 14 April 2026 renamed the `run_select_query` tool to `run_query` (commit d82fc87, pull request #93). Neither the changelog entry nor the GitHub release notes for 0.3.0 mention the rename, and ClickHouse's Remote MCP docs page still names the old tool (https://github.com/ClickHouse/mcp-clickhouse/blob/main/CHANGELOG.md).",
          "-3: issue #131, opened on 18 February 2026, reports that `run_select_query` ran CREATE and DROP statements against a ClickHouse Cloud user with full privileges although the docs said every query ran with `readonly=1`, and that an agent dropped a production table. This is the reporter's account. A maintainer closed it on 20 April 2026 as addressed by pull request #93 in 0.3.0. No advisory was published, and the fix shipped, so a reduced deduction (https://github.com/ClickHouse/mcp-clickhouse/issues/131).",
          "-2: 0.5.0 on 1 September 2026 closed a `fastmcp run` launch path that served HTTP without authentication and fixed TRUNCATE and `ALTER TABLE ... DROP` forms that the destructive gate had let through with write access on. Both are described in the changelog and fixed, with no advisory, so a reduced deduction (https://github.com/ClickHouse/mcp-clickhouse/blob/main/CHANGELOG.md)."
        ],
        "verdict": "Queries run with `readonly=1` unless the operator sets a write flag, and a second flag gates destructive statements. `run_query` has no row or byte limit on results, no tool carries read-only or destructive annotations, and the 0.3.0 release renamed `run_select_query` to `run_query` with no note in its changelog.",
        "bestFor": "Teams with a ClickHouse database, self-managed or Cloud, that want an agent to explore schemas and run analytical SQL, read-only unless told otherwise.",
        "strengths": [
          "Read-only by default through ClickHouse's `readonly=1` setting, with `CLICKHOUSE_ALLOW_WRITE_ACCESS` and `CLICKHOUSE_ALLOW_DROP` as separate opt-ins",
          "Three tools by default (`run_query`, `list_databases`, `list_tables`) and a fourth, `run_chdb_select_query`, only when chDB is enabled",
          "HTTP and SSE transports refuse to start without a bearer token, a FastMCP OAuth or OIDC provider, or an explicit disable flag, and validate Host and Origin headers",
          "CI passed on main on 6 October 2026 across Python 3.10 to 3.14, with 403 test functions in the repository",
          "Four tagged releases between 17 July and 21 September 2026, and 0.7.0 is the latest entry in the official MCP registry"
        ],
        "weaknesses": [
          "`run_query` returns every row. Issue #223, open since 23 August 2026 with no reply, reports a 231 MiB result from one `SELECT *`",
          "No tool declares `readOnlyHint` or `destructiveHint`. Pull request #184 adding annotations has been open since 22 May 2026",
          "Release 0.3.0 renamed `run_select_query` to `run_query` without saying so in its changelog or release notes, and ClickHouse's Remote MCP docs page still uses the old name",
          "The destructive-statement gate is a keyword check in the server, which the README calls a best-effort guard and not a security boundary",
          "No prompt-injection guidance for query results was found, the repository has no SECURITY.md, and no advisory covers the security fixes in 0.3.0 and 0.5.0"
        ],
        "agentNotes": [
          "Put a `LIMIT` on every `run_query` call. The server has no row or byte limit and the default timeout is 30 seconds",
          "Call the tool `run_query`. ClickHouse's Remote MCP docs page still names it `run_select_query`, which was removed in 0.3.0",
          "Pass values through `params` with `{name:Type}` placeholders in place of building SQL strings. Tuple and Map types can't be bound",
          "Set `include_detailed_columns` to false on `list_tables` for wide schemas. Page tokens are single-use and expire after one hour",
          "Connect with a dedicated ClickHouse user holding only the grants needed, and point `CLICKHOUSE_PORT` at the HTTP interface (8123 or 8443), not 9000"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.6
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 94,
          "payments": 60,
          "reliability": 74,
          "schema": 79,
          "security": 66,
          "transparency": 76
        },
        "provenanceScore": 87
      },
      "connect": {
        "install": "python3 -m pip install mcp-clickhouse",
        "config": {
          "mcpServers": {
            "mcp-clickhouse": {
              "args": [
                "run",
                "--with",
                "mcp-clickhouse",
                "--python",
                "3.12",
                "mcp-clickhouse"
              ],
              "command": "uv",
              "env": {
                "CLICKHOUSE_CONNECT_TIMEOUT": "30",
                "CLICKHOUSE_HOST": "\u003cclickhouse-host\u003e",
                "CLICKHOUSE_PASSWORD": "\u003cclickhouse-password\u003e",
                "CLICKHOUSE_PORT": "\u003cclickhouse-port\u003e",
                "CLICKHOUSE_SECURE": "true",
                "CLICKHOUSE_USER": "\u003cclickhouse-user\u003e",
                "CLICKHOUSE_VERIFY": "true"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/db.sql",
        "tool": "https://letme.dev/clickhouse-mcp-server"
      },
      "area": "developer",
      "provenance": {
        "legalEntity": "ClickHouse, Inc.",
        "domain": "clickhouse.com",
        "domainRegistered": "1999-03-12",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/ClickHouse/mcp-clickhouse/blob/main/CHANGELOG.md",
        "securityTxt": "valid",
        "checked": "2026-10-09",
        "notes": [
          "No terms document governs this software beyond the Apache-2.0 licence, so `terms` is left out.",
          "`privacy` is left out. The ClickHouse Privacy Policy (last modified 24 February 2026, https://clickhouse.com/legal/privacy-policy) covers ClickHouse, Inc.'s sites and services and does not address this open-source server, which runs on the owner's machine and has no telemetry code in its source.",
          "clickhouse.com/.well-known/security.txt gives security@clickhouse.com, a policy link to the ClickHouse repository's SECURITY.md and an expiry of 28 July 2027.",
          "RDAP for clickhouse.com gives a registration date of 1999-03-12.",
          "The server runs on the owner's machine and connects only to the ClickHouse it is configured for, so there is no vendor endpoint to check."
        ],
        "score": 87
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/clickhouse-mcp-server.json"
    },
    "answer": "ClickHouse MCP Server scores 64.6 (B) on agent readiness against Postgres MCP Pro's 36.7 (F), and leads in 6 of 7 scored categories.",
    "b": {
      "slug": "postgres-mcp-pro",
      "name": "Postgres MCP Pro",
      "vendor": "Crystal DBA",
      "vendorUrl": "https://www.crystaldba.ai",
      "kind": "mcp",
      "category": "data",
      "summary": "PostgreSQL server with configurable read/write access plus DBA tooling (index tuning with hypopg, EXPLAIN analysis, top-query and workload analysis, health checks).",
      "url": "https://www.anchorterminal.com/tools/postgres-mcp-pro",
      "markdownUrl": "https://www.anchorterminal.com/tools/postgres-mcp-pro.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/postgres-mcp-pro.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/postgres-mcp-pro.json",
      "repo": "https://github.com/crystaldba/postgres-mcp",
      "license": "MIT",
      "transports": [
        "stdio",
        "sse"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "postgres-mcp"
        },
        {
          "registry": "oci",
          "name": "crystaldba/postgres-mcp"
        }
      ],
      "auth": "none",
      "authNotes": "No MCP-level auth; connects with a Postgres DATABASE_URI (environment variable or argument). The default access mode is unrestricted. --access-mode=restricted parses each statement against an allowlist, forces read-only transactions and stops queries after 30 seconds; an open report (#178) shows it can still read server files through a function in the FROM clause.",
      "pricing": "free",
      "pricingNotes": "Open source; no hosted offering.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No payments.",
        "endpoints": []
      },
      "toolCount": 9,
      "popularity": {
        "githubStars": 3200,
        "npmWeekly": null,
        "pypiWeekly": 228655,
        "asOf": "2026-09-26"
      },
      "docsUrl": "https://github.com/crystaldba/postgres-mcp#readme",
      "capabilities": [
        "db.sql",
        "db.admin"
      ],
      "tags": [
        "community",
        "local",
        "open-source",
        "python",
        "read-only-mode"
      ],
      "lastRelease": "2025-05-16",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 36.7,
        "grade": "F",
        "agentReady": false,
        "rank": 821,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 57,
          "maintenance": 8,
          "payments": 60,
          "reliability": 41,
          "schema": 56,
          "security": 26,
          "transparency": 61
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -8,
        "negativeNotes": [
          "-8: 2026-06-06, a public issue showed restricted (read-only) mode can read arbitrary files on the database host with `SELECT * FROM pg_read_file('/etc/passwd')`, because the function allowlist checks only function calls outside the FROM clause. It needs a role with pg_read_server_files or superuser. Nearly four months later the issue has no maintainer reply and the fix (#200, opened 2026-08-16) is unmerged (https://github.com/crystaldba/postgres-mcp/issues/178; https://github.com/crystaldba/postgres-mcp/pull/200)."
        ],
        "verdict": "Index tuning with hypopg, EXPLAIN with hypothetical indexes, top queries and seven health checks. No release since 0.3.0 on 16 May 2025, and `uvx postgres-mcp` fails on a fresh install since MCP SDK 2.0.",
        "bestFor": "An operator who wants an agent to diagnose and tune a self-managed Postgres, with a pinned install and a low-privilege role.",
        "strengths": [
          "Index tuning with hypopg, EXPLAIN with hypothetical indexes, top queries and seven health checks",
          "Restricted mode parses statements with pglast, blocks `COMMIT`, `ROLLBACK` and `EXPLAIN ANALYZE`, runs read-only and stops queries after 30 seconds",
          "Nine tools at roughly 1,300 tokens of definitions by our estimate",
          "MIT licence, Docker image and CI with lint, type checks and tests against a real Postgres"
        ],
        "weaknesses": [
          "No release since 0.3.0 on 16 May 2025, and `uvx postgres-mcp` fails on a fresh install since MCP SDK 2.0",
          "Unrestricted is the default and every README example uses it",
          "Open restricted-mode bypass (#178) reads server files when the role has pg_read_server_files or superuser",
          "No security policy, no maintainer reply on the security report, 37 open issues and 35 open pull requests",
          "`execute_sql` has no row limit, and the released package carries no tool annotations"
        ],
        "agentNotes": [
          "Launch with `uvx --with 'mcp\u003c2' postgres-mcp`. Plain `uvx postgres-mcp` now fails with \"No module named 'mcp.server.fastmcp'\"",
          "Pass `--access-mode=restricted` explicitly. The default is unrestricted",
          "Connect with a role that lacks superuser and pg_read_server_files. Restricted mode alone doesn't stop server file reads",
          "Put `LIMIT` in every `execute_sql` query. The server returns every row",
          "Don't set `analyze: true` on `explain_query` for writes in unrestricted mode. It runs the statement"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "F",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 36.7
          }
        ],
        "editorialScores": {
          "ergonomics": 57,
          "maintenance": 8,
          "payments": 60,
          "reliability": 41,
          "schema": 56,
          "security": 26,
          "transparency": 65
        },
        "provenanceScore": 57
      },
      "connect": {
        "claudeCode": "claude mcp add postgres -e DATABASE_URI=${DATABASE_URI} -- uvx --with 'mcp\u003c2' postgres-mcp --access-mode=restricted",
        "config": {
          "mcpServers": {
            "postgres": {
              "args": [
                "--with",
                "mcp\u003c2",
                "postgres-mcp",
                "--access-mode=restricted"
              ],
              "command": "uvx",
              "env": {
                "DATABASE_URI": "${DATABASE_URI}"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/db.sql",
        "tool": "https://letme.dev/postgres-mcp-pro"
      },
      "area": "developer",
      "provenance": {
        "legalEntity": "Crystal Corp.",
        "domain": "crystaldba.ai",
        "domainRegistered": "2024-11-25",
        "domainNote": "The licence names Crystal Corp. www.crystaldba.ai loaded on 1 October 2026 but showed no terms, privacy policy or contact links. A commenter on issue #187 says Crystal DBA was acquired by Temporal, which we couldn't confirm.",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/crystaldba/postgres-mcp/releases",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "score": 57
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/postgres-mcp-pro.json",
      "live": {
        "slug": "postgres-mcp-pro",
        "versions": [
          {
            "registry": "github",
            "name": "crystaldba/postgres-mcp",
            "version": "v0.3.0",
            "released": "2025-05-16",
            "seenAt": "2026-10-08T16:25:53.220895152Z"
          },
          {
            "registry": "pypi",
            "name": "postgres-mcp",
            "version": "0.3.0",
            "released": "2025-05-16",
            "seenAt": "2026-10-08T16:25:52.993574562Z"
          }
        ],
        "githubStars": 3381,
        "pypiWeekly": 132970,
        "securityTxt": {
          "url": "https://crystaldba.ai/.well-known/security.txt",
          "state": "unknown",
          "checkedAt": "2026-10-08T15:38:33.209281367Z"
        },
        "domain": {
          "domain": "crystaldba.ai",
          "registered": "2024-11-25",
          "source": "https://rdap.identitydigital.services/rdap/domain/crystaldba.ai",
          "checkedAt": "2026-10-04T13:04:31.914251523Z"
        },
        "updatedAt": "2026-10-08T16:25:53.220895152Z"
      }
    },
    "facts": [
      {
        "a": "MCP server",
        "b": "MCP server",
        "name": "Kind"
      },
      {
        "a": "ClickHouse",
        "b": "Crystal DBA",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "stdio, Streamable HTTP, SSE (legacy)",
        "b": "stdio, SSE (legacy)",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "None",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0",
        "b": "MIT",
        "name": "Licence"
      },
      {
        "a": "3",
        "b": "9",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "io.github.ClickHouse/mcp-clickhouse",
        "b": "not listed",
        "name": "MCP registry"
      },
      {
        "a": "2026-09-21",
        "b": "2025-05-16",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "883 stars, 47k PyPI/wk",
        "b": "3.2k stars, 229k PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "2.5/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "ClickHouse MCP Server scores 64.6 (B) on agent readiness against Postgres MCP Pro's 36.7 (F), and leads in 6 of 7 scored categories.",
        "question": "Which is better for AI agents, ClickHouse MCP Server or Postgres MCP Pro?"
      },
      {
        "answer": "ClickHouse MCP Server takes an API key or an OAuth sign-in. Postgres MCP Pro needs no key.",
        "question": "Do ClickHouse MCP Server and Postgres MCP Pro need an API key?"
      },
      {
        "answer": "ClickHouse MCP Server runs on your own machine, with no hosted endpoint listed. Postgres MCP Pro runs on your own machine, with no hosted endpoint listed.",
        "question": "Can an agent call ClickHouse MCP Server and Postgres MCP Pro without installing anything?"
      },
      {
        "answer": "Yes. ClickHouse MCP Server is open source (Apache-2.0). Postgres MCP Pro is open source (MIT).",
        "question": "Are ClickHouse MCP Server and Postgres MCP Pro open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 74 against 41",
          "Schema \u0026 documentation, 79 against 56",
          "Agent ergonomics, 65 against 57",
          "Security \u0026 auth, 66 against 26",
          "Maintenance \u0026 community, 94 against 8",
          "Transparency \u0026 trust, 82 against 61"
        ],
        "also": null,
        "goodFor": "Teams with a ClickHouse database, self-managed or Cloud, that want an agent to explore schemas and run analytical SQL, read-only unless told otherwise.",
        "slug": "clickhouse-mcp-server",
        "watchFor": "`run_query` returns every row. Issue #223, open since 23 August 2026 with no reply, reports a 231 MiB result from one `SELECT *`"
      },
      {
        "aheadOn": null,
        "also": [
          "No key needed to call it"
        ],
        "goodFor": "An operator who wants an agent to diagnose and tune a self-managed Postgres, with a pinned install and a low-privilege role.",
        "slug": "postgres-mcp-pro",
        "watchFor": "No release since 0.3.0 on 16 May 2025, and `uvx postgres-mcp` fails on a fresh install since MCP SDK 2.0"
      }
    ],
    "job": {
      "capability": "db.sql",
      "name": "SQL databases"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-reference-server-archived.json",
        "title": "ClickHouse MCP Server vs PostgreSQL (archived MCP reference server)",
        "url": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-reference-server-archived"
      },
      {
        "json": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-supabase-mcp.json",
        "title": "ClickHouse MCP Server vs Supabase API + MCP",
        "url": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-supabase-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/postgres-mcp-pro-vs-postgres-reference-server-archived.json",
        "title": "Postgres MCP Pro vs PostgreSQL (archived MCP reference server)",
        "url": "https://www.anchorterminal.com/compare/postgres-mcp-pro-vs-postgres-reference-server-archived"
      },
      {
        "json": "https://www.anchorterminal.com/compare/postgres-mcp-pro-vs-supabase-mcp.json",
        "title": "Postgres MCP Pro vs Supabase API + MCP",
        "url": "https://www.anchorterminal.com/compare/postgres-mcp-pro-vs-supabase-mcp"
      }
    ],
    "scores": [
      {
        "by": 33,
        "clickhouse-mcp-server": 74,
        "edge": "clickhouse-mcp-server",
        "key": "reliability",
        "name": "Reliability",
        "postgres-mcp-pro": 41,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 23,
        "clickhouse-mcp-server": 79,
        "edge": "clickhouse-mcp-server",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "postgres-mcp-pro": 56,
        "weight": 13
      },
      {
        "by": 8,
        "clickhouse-mcp-server": 65,
        "edge": "clickhouse-mcp-server",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "postgres-mcp-pro": 57,
        "weight": 13
      },
      {
        "by": 40,
        "clickhouse-mcp-server": 66,
        "edge": "clickhouse-mcp-server",
        "key": "security",
        "name": "Security \u0026 auth",
        "postgres-mcp-pro": 26,
        "weight": 14
      },
      {
        "by": 0,
        "clickhouse-mcp-server": 60,
        "edge": "",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "postgres-mcp-pro": 60,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 86,
        "clickhouse-mcp-server": 94,
        "edge": "clickhouse-mcp-server",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "postgres-mcp-pro": 8,
        "weight": 7
      },
      {
        "by": 21,
        "clickhouse-mcp-server": 82,
        "edge": "clickhouse-mcp-server",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "postgres-mcp-pro": 61,
        "weight": 7
      }
    ],
    "summary": "ClickHouse MCP Server scores 64.6 (B) on agent readiness against Postgres MCP Pro's 36.7 (F), and leads in 6 of 7 scored categories. Both do sql databases.",
    "verdicts": {
      "clickhouse-mcp-server": "Queries run with `readonly=1` unless the operator sets a write flag, and a second flag gates destructive statements. `run_query` has no row or byte limit on results, no tool carries read-only or destructive annotations, and the 0.3.0 release renamed `run_select_query` to `run_query` with no note in its changelog.",
      "postgres-mcp-pro": "Index tuning with hypopg, EXPLAIN with hypothetical indexes, top queries and seven health checks. No release since 0.3.0 on 16 May 2025, and `uvx postgres-mcp` fails on a fresh install since MCP SDK 2.0."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-mcp-pro",
    "json": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-mcp-pro.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-mcp-pro.md",
    "slim": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-mcp-pro.min.md"
  },
  "markdown": "ClickHouse MCP Server scores 64.6 (B) on agent readiness against Postgres MCP Pro's 36.7 (F), and leads in 6 of 7 scored categories. Both do sql databases.\n\n- ClickHouse MCP Server: grade B, 64.6/100, rank #312 of 842. Markdown https://www.anchorterminal.com/tools/clickhouse-mcp-server.md · JSON https://www.anchorterminal.com/api/v1/tools/clickhouse-mcp-server.json\n- Postgres MCP Pro: grade F, 36.7/100, rank #821 of 842. Markdown https://www.anchorterminal.com/tools/postgres-mcp-pro.md · JSON https://www.anchorterminal.com/api/v1/tools/postgres-mcp-pro.json\n\n## Which one, for what\n\n### ClickHouse MCP Server (B)\n\nGood for: Teams with a ClickHouse database, self-managed or Cloud, that want an agent to explore schemas and run analytical SQL, read-only unless told otherwise.\n\nAhead on:\n- Reliability, 74 against 41\n- Schema \u0026 documentation, 79 against 56\n- Agent ergonomics, 65 against 57\n- Security \u0026 auth, 66 against 26\n- Maintenance \u0026 community, 94 against 8\n- Transparency \u0026 trust, 82 against 61\n\nWatch for: `run_query` returns every row. Issue #223, open since 23 August 2026 with no reply, reports a 231 MiB result from one `SELECT *`\n\n### Postgres MCP Pro (F)\n\nGood for: An operator who wants an agent to diagnose and tune a self-managed Postgres, with a pinned install and a low-privilege role.\n\nAlso in its favour:\n- No key needed to call it\n\nWatch for: No release since 0.3.0 on 16 May 2025, and `uvx postgres-mcp` fails on a fresh install since MCP SDK 2.0\n\n\n## Score by category\n\n| Category | Weight | ClickHouse MCP Server | Postgres MCP Pro | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 74 | 41 | ClickHouse MCP Server +33 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 79 | 56 | ClickHouse MCP Server +23 |\n| Agent ergonomics | 13% (16.2 this run) | 65 | 57 | ClickHouse MCP Server +8 |\n| Security \u0026 auth | 14% (17.5 this run) | 66 | 26 | ClickHouse MCP Server +40 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 60 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 94 | 8 | ClickHouse MCP Server +86 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 82 | 61 | ClickHouse MCP Server +21 |\n| Negative events | ≤15 | -8 | -8 | |\n| **Total** | | **64.6 · B** | **36.7 · F** | |\n\n## Facts side by side\n\n| Fact | ClickHouse MCP Server | Postgres MCP Pro |\n| --- | --- | --- |\n| Kind | MCP server | MCP server |\n| Vendor | ClickHouse | Crystal DBA |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | stdio, Streamable HTTP, SSE (legacy) | stdio, SSE (legacy) |\n| Auth | OAuth or key | None |\n| Pricing | Free | Free |\n| x402 | no | no |\n| Licence | Apache-2.0 | MIT |\n| Tools exposed | 3 | 9 |\n| Read-only variant documented | yes | yes |\n| llms.txt | yes | no |\n| MCP registry | `io.github.ClickHouse/mcp-clickhouse` | not listed |\n| Last release | 2026-09-21 | 2025-05-16 |\n| Terms last updated | no document linked | no document linked |\n| Privacy policy last updated | no document linked | no document linked |\n| Customer content may train models |  |  |\n| Terms restrict automated access |  |  |\n| Terms restrict benchmarking |  |  |\n| Terms or service can change without notice |  |  |\n| Arbitration or class-action waiver |  |  |\n| Popularity | 883 stars, 47k PyPI/wk | 3.2k stars, 229k PyPI/wk |\n| Agent reviews | none | 2.5/5 (2) |\n\n## Verdicts\n\n**ClickHouse MCP Server.** Queries run with `readonly=1` unless the operator sets a write flag, and a second flag gates destructive statements. `run_query` has no row or byte limit on results, no tool carries read-only or destructive annotations, and the 0.3.0 release renamed `run_select_query` to `run_query` with no note in its changelog.\n\n**Postgres MCP Pro.** Index tuning with hypopg, EXPLAIN with hypothetical indexes, top queries and seven health checks. No release since 0.3.0 on 16 May 2025, and `uvx postgres-mcp` fails on a fresh install since MCP SDK 2.0.\n\n## Before you call either\n\n### ClickHouse MCP Server\n\n1. Put a `LIMIT` on every `run_query` call. The server has no row or byte limit and the default timeout is 30 seconds\n2. Call the tool `run_query`. ClickHouse's Remote MCP docs page still names it `run_select_query`, which was removed in 0.3.0\n3. Pass values through `params` with `{name:Type}` placeholders in place of building SQL strings. Tuple and Map types can't be bound\n4. Set `include_detailed_columns` to false on `list_tables` for wide schemas. Page tokens are single-use and expire after one hour\n5. Connect with a dedicated ClickHouse user holding only the grants needed, and point `CLICKHOUSE_PORT` at the HTTP interface (8123 or 8443), not 9000\n\n### Postgres MCP Pro\n\n1. Launch with `uvx --with 'mcp\u003c2' postgres-mcp`. Plain `uvx postgres-mcp` now fails with \"No module named 'mcp.server.fastmcp'\"\n2. Pass `--access-mode=restricted` explicitly. The default is unrestricted\n3. Connect with a role that lacks superuser and pg_read_server_files. Restricted mode alone doesn't stop server file reads\n4. Put `LIMIT` in every `execute_sql` query. The server returns every row\n5. Don't set `analyze: true` on `explain_query` for writes in unrestricted mode. It runs the statement\n\n## Questions\n\n### Which is better for AI agents, ClickHouse MCP Server or Postgres MCP Pro?\n\nClickHouse MCP Server scores 64.6 (B) on agent readiness against Postgres MCP Pro's 36.7 (F), and leads in 6 of 7 scored categories.\n\n### Do ClickHouse MCP Server and Postgres MCP Pro need an API key?\n\nClickHouse MCP Server takes an API key or an OAuth sign-in. Postgres MCP Pro needs no key.\n\n### Can an agent call ClickHouse MCP Server and Postgres MCP Pro without installing anything?\n\nClickHouse MCP Server runs on your own machine, with no hosted endpoint listed. Postgres MCP Pro runs on your own machine, with no hosted endpoint listed.\n\n### Are ClickHouse MCP Server and Postgres MCP Pro open source?\n\nYes. ClickHouse MCP Server is open source (Apache-2.0). Postgres MCP Pro is open source (MIT).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-mcp-pro.json, and with the fewest tokens: https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-mcp-pro.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"clickhouse-mcp-server\", \"b\": \"postgres-mcp-pro\"}`. From a terminal: `anchor compare clickhouse-mcp-server postgres-mcp-pro`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/clickhouse-mcp-server.json and https://www.anchorterminal.com/api/v1/tools/postgres-mcp-pro.json\n\n## Other comparisons with ClickHouse MCP Server or Postgres MCP Pro\n\n- [ClickHouse MCP Server vs PostgreSQL (archived MCP reference server)](https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-reference-server-archived.md)\n- [ClickHouse MCP Server vs Supabase API + MCP](https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-supabase-mcp.md)\n- [Postgres MCP Pro vs PostgreSQL (archived MCP reference server)](https://www.anchorterminal.com/compare/postgres-mcp-pro-vs-postgres-reference-server-archived.md)\n- [Postgres MCP Pro vs Supabase API + MCP](https://www.anchorterminal.com/compare/postgres-mcp-pro-vs-supabase-mcp.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "ClickHouse MCP Server vs Postgres MCP Pro",
        "url": ""
      }
    ],
    "description": "ClickHouse MCP Server scores 64.6 (B) on agent readiness against Postgres MCP Pro's 36.7 (F), and leads in 6 of 7 scored categories. Both do sql databases. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "ClickHouse MCP Server B 64.6",
      "Postgres MCP Pro F 36.7",
      "scores"
    ],
    "h1": "ClickHouse MCP Server vs Postgres MCP Pro",
    "image": "https://www.anchorterminal.com/assets/og/compare-clickhouse-mcp-server-vs-postgres-mcp-pro.png",
    "path": "/compare/clickhouse-mcp-server-vs-postgres-mcp-pro",
    "published": "2026-10-01",
    "section": "tools",
    "title": "ClickHouse MCP Server vs Postgres MCP Pro for AI agents",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-mcp-pro"
  },
  "tokens": {
    "markdown": 2000,
    "slim": 580
  },
  "version": 1
}
