{
  "data": {
    "a": {
      "slug": "clickhouse-mcp-server",
      "name": "ClickHouse MCP Server",
      "vendor": "ClickHouse",
      "vendorUrl": "https://clickhouse.com",
      "kind": "mcp",
      "category": "data",
      "summary": "ClickHouse's open-source MCP server for ClickHouse databases. The owner runs it locally or self-hosted, and it gives agents SQL queries, database and table listing, and an optional embedded chDB engine. Queries are read-only by default.",
      "url": "https://www.anchorterminal.com/tools/clickhouse-mcp-server",
      "markdownUrl": "https://www.anchorterminal.com/tools/clickhouse-mcp-server.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/clickhouse-mcp-server.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/clickhouse-mcp-server.json",
      "repo": "https://github.com/ClickHouse/mcp-clickhouse",
      "license": "Apache-2.0",
      "transports": [
        "stdio",
        "streamable-http",
        "sse"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "mcp-clickhouse"
        },
        {
          "registry": "oci",
          "name": "ghcr.io/clickhouse/mcp-clickhouse"
        }
      ],
      "auth": "mixed",
      "authNotes": "The server signs in to ClickHouse with `CLICKHOUSE_USER` and `CLICKHOUSE_PASSWORD`, or with an X.509 client certificate (`CLICKHOUSE_CLIENT_CERT`, added in 0.7.0), and can set a role with `CLICKHOUSE_ROLE`. An admin creates the user, self-serve, and ClickHouse grants set what it can do. stdio needs no caller credential. The HTTP and SSE transports refuse to start unless one of a static bearer token (`CLICKHOUSE_MCP_AUTH_TOKEN`), a FastMCP OAuth or OIDC provider (`FASTMCP_SERVER_AUTH`) or `CLICKHOUSE_MCP_AUTH_DISABLED=true` is set. Every caller shares the one ClickHouse user unless custom middleware overrides the connection per request.",
      "pricing": "free",
      "pricingNotes": "Free and open source under Apache-2.0, with nothing to buy for the server. It needs a ClickHouse database, which can be self-managed open-source ClickHouse, ClickHouse Cloud or the embedded chDB engine. The README gives a public SQL playground (`sql-clickhouse.clickhouse.com`, user `demo`, empty password) for trying it with no account. ClickHouse Cloud prices were not checked. The separate hosted Remote MCP server is a ClickHouse Cloud feature and is not what this listing grades (checked 2026-10-09).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the README, the changelog or the source (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": 3,
      "popularity": {
        "githubStars": 883,
        "npmWeekly": null,
        "pypiWeekly": 47206,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://github.com/ClickHouse/mcp-clickhouse#readme",
      "llmsTxt": "https://clickhouse.com/docs/llms.txt",
      "registryName": "io.github.ClickHouse/mcp-clickhouse",
      "capabilities": [
        "db.sql"
      ],
      "tags": [
        "official",
        "local",
        "open-source",
        "self-hosted",
        "mcp",
        "python",
        "docker",
        "read-only-mode",
        "database"
      ],
      "lastRelease": "2026-09-21",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.6,
        "grade": "B",
        "agentReady": false,
        "rank": 312,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 94,
          "payments": 60,
          "reliability": 74,
          "schema": 79,
          "security": 66,
          "transparency": 82
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -8,
        "negativeNotes": [
          "-3: release 0.3.0 on 14 April 2026 renamed the `run_select_query` tool to `run_query` (commit d82fc87, pull request #93). Neither the changelog entry nor the GitHub release notes for 0.3.0 mention the rename, and ClickHouse's Remote MCP docs page still names the old tool (https://github.com/ClickHouse/mcp-clickhouse/blob/main/CHANGELOG.md).",
          "-3: issue #131, opened on 18 February 2026, reports that `run_select_query` ran CREATE and DROP statements against a ClickHouse Cloud user with full privileges although the docs said every query ran with `readonly=1`, and that an agent dropped a production table. This is the reporter's account. A maintainer closed it on 20 April 2026 as addressed by pull request #93 in 0.3.0. No advisory was published, and the fix shipped, so a reduced deduction (https://github.com/ClickHouse/mcp-clickhouse/issues/131).",
          "-2: 0.5.0 on 1 September 2026 closed a `fastmcp run` launch path that served HTTP without authentication and fixed TRUNCATE and `ALTER TABLE ... DROP` forms that the destructive gate had let through with write access on. Both are described in the changelog and fixed, with no advisory, so a reduced deduction (https://github.com/ClickHouse/mcp-clickhouse/blob/main/CHANGELOG.md)."
        ],
        "verdict": "Queries run with `readonly=1` unless the operator sets a write flag, and a second flag gates destructive statements. `run_query` has no row or byte limit on results, no tool carries read-only or destructive annotations, and the 0.3.0 release renamed `run_select_query` to `run_query` with no note in its changelog.",
        "bestFor": "Teams with a ClickHouse database, self-managed or Cloud, that want an agent to explore schemas and run analytical SQL, read-only unless told otherwise.",
        "strengths": [
          "Read-only by default through ClickHouse's `readonly=1` setting, with `CLICKHOUSE_ALLOW_WRITE_ACCESS` and `CLICKHOUSE_ALLOW_DROP` as separate opt-ins",
          "Three tools by default (`run_query`, `list_databases`, `list_tables`) and a fourth, `run_chdb_select_query`, only when chDB is enabled",
          "HTTP and SSE transports refuse to start without a bearer token, a FastMCP OAuth or OIDC provider, or an explicit disable flag, and validate Host and Origin headers",
          "CI passed on main on 6 October 2026 across Python 3.10 to 3.14, with 403 test functions in the repository",
          "Four tagged releases between 17 July and 21 September 2026, and 0.7.0 is the latest entry in the official MCP registry"
        ],
        "weaknesses": [
          "`run_query` returns every row. Issue #223, open since 23 August 2026 with no reply, reports a 231 MiB result from one `SELECT *`",
          "No tool declares `readOnlyHint` or `destructiveHint`. Pull request #184 adding annotations has been open since 22 May 2026",
          "Release 0.3.0 renamed `run_select_query` to `run_query` without saying so in its changelog or release notes, and ClickHouse's Remote MCP docs page still uses the old name",
          "The destructive-statement gate is a keyword check in the server, which the README calls a best-effort guard and not a security boundary",
          "No prompt-injection guidance for query results was found, the repository has no SECURITY.md, and no advisory covers the security fixes in 0.3.0 and 0.5.0"
        ],
        "agentNotes": [
          "Put a `LIMIT` on every `run_query` call. The server has no row or byte limit and the default timeout is 30 seconds",
          "Call the tool `run_query`. ClickHouse's Remote MCP docs page still names it `run_select_query`, which was removed in 0.3.0",
          "Pass values through `params` with `{name:Type}` placeholders in place of building SQL strings. Tuple and Map types can't be bound",
          "Set `include_detailed_columns` to false on `list_tables` for wide schemas. Page tokens are single-use and expire after one hour",
          "Connect with a dedicated ClickHouse user holding only the grants needed, and point `CLICKHOUSE_PORT` at the HTTP interface (8123 or 8443), not 9000"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.6
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 94,
          "payments": 60,
          "reliability": 74,
          "schema": 79,
          "security": 66,
          "transparency": 76
        },
        "provenanceScore": 87
      },
      "connect": {
        "install": "python3 -m pip install mcp-clickhouse",
        "config": {
          "mcpServers": {
            "mcp-clickhouse": {
              "args": [
                "run",
                "--with",
                "mcp-clickhouse",
                "--python",
                "3.12",
                "mcp-clickhouse"
              ],
              "command": "uv",
              "env": {
                "CLICKHOUSE_CONNECT_TIMEOUT": "30",
                "CLICKHOUSE_HOST": "\u003cclickhouse-host\u003e",
                "CLICKHOUSE_PASSWORD": "\u003cclickhouse-password\u003e",
                "CLICKHOUSE_PORT": "\u003cclickhouse-port\u003e",
                "CLICKHOUSE_SECURE": "true",
                "CLICKHOUSE_USER": "\u003cclickhouse-user\u003e",
                "CLICKHOUSE_VERIFY": "true"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/db.sql",
        "tool": "https://letme.dev/clickhouse-mcp-server"
      },
      "area": "developer",
      "provenance": {
        "legalEntity": "ClickHouse, Inc.",
        "domain": "clickhouse.com",
        "domainRegistered": "1999-03-12",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/ClickHouse/mcp-clickhouse/blob/main/CHANGELOG.md",
        "securityTxt": "valid",
        "checked": "2026-10-09",
        "notes": [
          "No terms document governs this software beyond the Apache-2.0 licence, so `terms` is left out.",
          "`privacy` is left out. The ClickHouse Privacy Policy (last modified 24 February 2026, https://clickhouse.com/legal/privacy-policy) covers ClickHouse, Inc.'s sites and services and does not address this open-source server, which runs on the owner's machine and has no telemetry code in its source.",
          "clickhouse.com/.well-known/security.txt gives security@clickhouse.com, a policy link to the ClickHouse repository's SECURITY.md and an expiry of 28 July 2027.",
          "RDAP for clickhouse.com gives a registration date of 1999-03-12.",
          "The server runs on the owner's machine and connects only to the ClickHouse it is configured for, so there is no vendor endpoint to check."
        ],
        "score": 87
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/clickhouse-mcp-server.json"
    },
    "answer": "ClickHouse MCP Server scores 64.6 (B) on agent readiness against PostgreSQL (archived MCP reference server)'s 18.4 (F), and leads in 6 of 7 scored categories.",
    "b": {
      "slug": "postgres-reference-server-archived",
      "name": "PostgreSQL (archived MCP reference server)",
      "vendor": "Model Context Protocol (archived)",
      "vendorUrl": "https://github.com/modelcontextprotocol/servers-archived",
      "kind": "mcp",
      "category": "data",
      "summary": "Archived PostgreSQL reference MCP server for SQL queries. Its read-only transaction wrapper has a documented bypass.",
      "url": "https://www.anchorterminal.com/tools/postgres-reference-server-archived",
      "markdownUrl": "https://www.anchorterminal.com/tools/postgres-reference-server-archived.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/postgres-reference-server-archived.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/postgres-reference-server-archived.json",
      "repo": "https://github.com/modelcontextprotocol/servers-archived",
      "license": "MIT",
      "transports": [
        "stdio"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@modelcontextprotocol/server-postgres"
        }
      ],
      "auth": "none",
      "authNotes": "Connection string, password included, passed as a CLI argument. Queries run inside a read-only transaction that a query starting with `COMMIT;` can escape, so the database role is the only real limit.",
      "pricing": "free",
      "pricingNotes": "Open source; unmaintained.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "Archived reference server, no payments.",
        "endpoints": []
      },
      "toolCount": 1,
      "popularity": {
        "githubStars": 294,
        "npmWeekly": 118589,
        "pypiWeekly": null,
        "asOf": "2026-10-01"
      },
      "docsUrl": "https://github.com/modelcontextprotocol/servers-archived/tree/main/src/postgres",
      "capabilities": [
        "db.sql"
      ],
      "tags": [
        "reference",
        "archived",
        "local",
        "open-source",
        "superseded"
      ],
      "lastRelease": "2024-12-04",
      "graded": true,
      "disclosure": "MCP started at Anthropic, which makes the Claude models our research agents and review panel run on (Anthropic donated it to the Agentic AI Foundation, a directed fund under the Linux Foundation, in December 2025), and this server is graded by the same checklist as every other listing.",
      "anchor": {
        "graded": true,
        "score": 18.4,
        "grade": "F",
        "agentReady": false,
        "rank": 838,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 38,
          "maintenance": 0,
          "payments": 60,
          "reliability": 13,
          "schema": 29,
          "security": 5,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "high",
          "date": "2026-10-01"
        },
        "negative": -10,
        "negativeNotes": [
          "-8: 2026-09-30, the read-only bypass Datadog Security Labs published on 21 August 2025 (SQL injection that escapes the read-only transaction and runs arbitrary SQL) is still unfixed, with no advisory, and the package drew 118,589 npm downloads in the week to 30 September 2026. We date it by that week, not by the disclosure, because the exposure is current. Every new install still gets the hole, and the fix that would let the deduction decay never came (https://securitylabs.datadoghq.com/articles/mcp-vulnerability-case-study-SQL-injection-in-the-postgresql-mcp-server/; https://api.npmjs.org/downloads/point/2026-09-24:2026-09-30/@modelcontextprotocol/server-postgres).",
          "-2: the tool description (\"Run a read-only SQL query\") and the main repository's README (\"Read-only database access\") still promise a guarantee the code doesn't keep, a misleading claim since the August 2025 disclosure (https://github.com/modelcontextprotocol/servers-archived/blob/main/src/postgres/index.ts; https://github.com/modelcontextprotocol/servers#archived)."
        ],
        "verdict": "The server exposes one small query tool. Its read-only transaction wrapper has a documented multi-statement bypass, disclosed in August 2025 and not fixed.",
        "bestFor": "Nothing new.",
        "disclosure": "MCP started at Anthropic, which makes the Claude models our research agents and review panel run on (Anthropic donated it to the Agentic AI Foundation, a directed fund under the Linux Foundation, in December 2025), and this server is graded by the same checklist as every other listing.",
        "strengths": [
          "One tool of about 180 characters, cheap to load into context",
          "Table column lists exposed as MCP resources",
          "MIT and about 150 lines, easy to audit or fork"
        ],
        "weaknesses": [
          "The read-only transaction can be escaped with a multi-statement query, disclosed in August 2025 and never fixed",
          "Archived on 29 May 2025 with no security guarantees, and pinned to MCP SDK 1.0.1",
          "Connection string and password passed on the command line, visible in process lists",
          "No row limit, pagination or tool annotations",
          "The npm deprecation message names no successor, so installs keep coming"
        ],
        "agentNotes": [
          "Don't use for new work. Migrate to Postgres MCP Pro with `--access-mode=restricted` or a managed provider's server",
          "If you inherit it, connect with a database role that can only SELECT. The transaction won't stop writes",
          "Add `LIMIT` to every query. The server returns every row as pretty-printed JSON",
          "Read the `/schema` resources for column names before querying, since there's no schema tool"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 1.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "high",
            "grade": "F",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 18.4
          }
        ],
        "editorialScores": {
          "ergonomics": 38,
          "maintenance": 0,
          "payments": 60,
          "reliability": 13,
          "schema": 29,
          "security": 5,
          "transparency": 80
        },
        "provenanceScore": 69
      },
      "letme": {
        "capability": "https://letme.dev/db.sql",
        "tool": "https://letme.dev/postgres-reference-server-archived"
      },
      "supersededBy": [
        "postgres-mcp-pro",
        "supabase-mcp"
      ],
      "sameCompany": [
        "fetch-reference-server",
        "git-reference-server",
        "puppeteer-reference-server-archived",
        "filesystem-reference-server",
        "memory-reference-server",
        "sequential-thinking-reference-server"
      ],
      "area": "developer",
      "provenance": {
        "legalEntity": "Model Context Protocol, a Series of LF Projects, LLC",
        "domain": "modelcontextprotocol.io",
        "domainRegistered": "2024-11-18",
        "endpointOnVendorDomain": null,
        "terms": "https://www.lfprojects.org/policies/terms-of-use/",
        "privacy": "https://www.lfprojects.org/policies/privacy-policy/",
        "statusPage": "",
        "changelog": "https://github.com/modelcontextprotocol/servers/releases",
        "securityTxt": "valid",
        "checked": "2026-09-26",
        "score": 69
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/postgres-reference-server-archived.json",
      "live": {
        "slug": "postgres-reference-server-archived",
        "versions": [
          {
            "registry": "npm",
            "name": "@modelcontextprotocol/server-postgres",
            "version": "0.6.2",
            "seenAt": "2026-10-08T16:25:56.880682428Z"
          }
        ],
        "githubStars": 303,
        "npmWeekly": 116675,
        "securityTxt": {
          "url": "https://modelcontextprotocol.io/.well-known/security.txt",
          "state": "valid",
          "checkedAt": "2026-10-08T15:38:47.022642624Z"
        },
        "domain": {
          "domain": "modelcontextprotocol.io",
          "checkedAt": "2026-10-04T13:06:56.741922917Z"
        },
        "updatedAt": "2026-10-08T16:25:57.905086295Z"
      }
    },
    "facts": [
      {
        "a": "MCP server",
        "b": "MCP server",
        "name": "Kind"
      },
      {
        "a": "ClickHouse",
        "b": "Model Context Protocol (archived)",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "stdio, Streamable HTTP, SSE (legacy)",
        "b": "stdio",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "None",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0",
        "b": "MIT",
        "name": "Licence"
      },
      {
        "a": "3",
        "b": "1",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "io.github.ClickHouse/mcp-clickhouse",
        "b": "not listed",
        "name": "MCP registry"
      },
      {
        "a": "2026-09-21",
        "b": "2024-12-04",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "2021-09-08",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "2023-03-15",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "883 stars, 47k PyPI/wk",
        "b": "294 stars, 119k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "1.5/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "ClickHouse MCP Server scores 64.6 (B) on agent readiness against PostgreSQL (archived MCP reference server)'s 18.4 (F), and leads in 6 of 7 scored categories.",
        "question": "Which is better for AI agents, ClickHouse MCP Server or PostgreSQL (archived MCP reference server)?"
      },
      {
        "answer": "ClickHouse MCP Server takes an API key or an OAuth sign-in. PostgreSQL (archived MCP reference server) needs no key.",
        "question": "Do ClickHouse MCP Server and PostgreSQL (archived MCP reference server) need an API key?"
      },
      {
        "answer": "ClickHouse MCP Server runs on your own machine, with no hosted endpoint listed. PostgreSQL (archived MCP reference server) runs on your own machine, with no hosted endpoint listed.",
        "question": "Can an agent call ClickHouse MCP Server and PostgreSQL (archived MCP reference server) without installing anything?"
      },
      {
        "answer": "Yes. ClickHouse MCP Server is open source (Apache-2.0). PostgreSQL (archived MCP reference server) is open source (MIT).",
        "question": "Are ClickHouse MCP Server and PostgreSQL (archived MCP reference server) open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 74 against 13",
          "Schema \u0026 documentation, 79 against 29",
          "Agent ergonomics, 65 against 38",
          "Security \u0026 auth, 66 against 5",
          "Maintenance \u0026 community, 94 against 0",
          "Transparency \u0026 trust, 82 against 75"
        ],
        "also": null,
        "goodFor": "Teams with a ClickHouse database, self-managed or Cloud, that want an agent to explore schemas and run analytical SQL, read-only unless told otherwise.",
        "slug": "clickhouse-mcp-server",
        "watchFor": "`run_query` returns every row. Issue #223, open since 23 August 2026 with no reply, reports a 231 MiB result from one `SELECT *`"
      },
      {
        "aheadOn": null,
        "also": [
          "No key needed to call it"
        ],
        "goodFor": "Nothing new.",
        "slug": "postgres-reference-server-archived",
        "watchFor": "The read-only transaction can be escaped with a multi-statement query, disclosed in August 2025 and never fixed"
      }
    ],
    "job": {
      "capability": "db.sql",
      "name": "SQL databases"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-mcp-pro.json",
        "title": "ClickHouse MCP Server vs Postgres MCP Pro",
        "url": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-mcp-pro"
      },
      {
        "json": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-supabase-mcp.json",
        "title": "ClickHouse MCP Server vs Supabase API + MCP",
        "url": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-supabase-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/postgres-mcp-pro-vs-postgres-reference-server-archived.json",
        "title": "Postgres MCP Pro vs PostgreSQL (archived MCP reference server)",
        "url": "https://www.anchorterminal.com/compare/postgres-mcp-pro-vs-postgres-reference-server-archived"
      },
      {
        "json": "https://www.anchorterminal.com/compare/postgres-reference-server-archived-vs-supabase-mcp.json",
        "title": "PostgreSQL (archived MCP reference server) vs Supabase API + MCP",
        "url": "https://www.anchorterminal.com/compare/postgres-reference-server-archived-vs-supabase-mcp"
      }
    ],
    "scores": [
      {
        "by": 61,
        "clickhouse-mcp-server": 74,
        "edge": "clickhouse-mcp-server",
        "key": "reliability",
        "name": "Reliability",
        "postgres-reference-server-archived": 13,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 50,
        "clickhouse-mcp-server": 79,
        "edge": "clickhouse-mcp-server",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "postgres-reference-server-archived": 29,
        "weight": 13
      },
      {
        "by": 27,
        "clickhouse-mcp-server": 65,
        "edge": "clickhouse-mcp-server",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "postgres-reference-server-archived": 38,
        "weight": 13
      },
      {
        "by": 61,
        "clickhouse-mcp-server": 66,
        "edge": "clickhouse-mcp-server",
        "key": "security",
        "name": "Security \u0026 auth",
        "postgres-reference-server-archived": 5,
        "weight": 14
      },
      {
        "by": 0,
        "clickhouse-mcp-server": 60,
        "edge": "",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "postgres-reference-server-archived": 60,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 94,
        "clickhouse-mcp-server": 94,
        "edge": "clickhouse-mcp-server",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "postgres-reference-server-archived": 0,
        "weight": 7
      },
      {
        "by": 7,
        "clickhouse-mcp-server": 82,
        "edge": "clickhouse-mcp-server",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "postgres-reference-server-archived": 75,
        "weight": 7
      }
    ],
    "summary": "ClickHouse MCP Server scores 64.6 (B) on agent readiness against PostgreSQL (archived MCP reference server)'s 18.4 (F), and leads in 6 of 7 scored categories. Both do sql databases.",
    "verdicts": {
      "clickhouse-mcp-server": "Queries run with `readonly=1` unless the operator sets a write flag, and a second flag gates destructive statements. `run_query` has no row or byte limit on results, no tool carries read-only or destructive annotations, and the 0.3.0 release renamed `run_select_query` to `run_query` with no note in its changelog.",
      "postgres-reference-server-archived": "The server exposes one small query tool. Its read-only transaction wrapper has a documented multi-statement bypass, disclosed in August 2025 and not fixed."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-reference-server-archived",
    "json": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-reference-server-archived.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-reference-server-archived.md",
    "slim": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-reference-server-archived.min.md"
  },
  "markdown": "ClickHouse MCP Server scores 64.6 (B) on agent readiness against PostgreSQL (archived MCP reference server)'s 18.4 (F), and leads in 6 of 7 scored categories. Both do sql databases.\n\n- ClickHouse MCP Server: grade B, 64.6/100, rank #312 of 842. Markdown https://www.anchorterminal.com/tools/clickhouse-mcp-server.md · JSON https://www.anchorterminal.com/api/v1/tools/clickhouse-mcp-server.json\n- PostgreSQL (archived MCP reference server): grade F, 18.4/100, rank #838 of 842. Markdown https://www.anchorterminal.com/tools/postgres-reference-server-archived.md · JSON https://www.anchorterminal.com/api/v1/tools/postgres-reference-server-archived.json\n\n## Which one, for what\n\n### ClickHouse MCP Server (B)\n\nGood for: Teams with a ClickHouse database, self-managed or Cloud, that want an agent to explore schemas and run analytical SQL, read-only unless told otherwise.\n\nAhead on:\n- Reliability, 74 against 13\n- Schema \u0026 documentation, 79 against 29\n- Agent ergonomics, 65 against 38\n- Security \u0026 auth, 66 against 5\n- Maintenance \u0026 community, 94 against 0\n- Transparency \u0026 trust, 82 against 75\n\nWatch for: `run_query` returns every row. Issue #223, open since 23 August 2026 with no reply, reports a 231 MiB result from one `SELECT *`\n\n### PostgreSQL (archived MCP reference server) (F)\n\nGood for: Nothing new.\n\nAlso in its favour:\n- No key needed to call it\n\nWatch for: The read-only transaction can be escaped with a multi-statement query, disclosed in August 2025 and never fixed\n\n\n## Score by category\n\n| Category | Weight | ClickHouse MCP Server | PostgreSQL (archived MCP reference server) | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 74 | 13 | ClickHouse MCP Server +61 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 79 | 29 | ClickHouse MCP Server +50 |\n| Agent ergonomics | 13% (16.2 this run) | 65 | 38 | ClickHouse MCP Server +27 |\n| Security \u0026 auth | 14% (17.5 this run) | 66 | 5 | ClickHouse MCP Server +61 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 60 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 94 | 0 | ClickHouse MCP Server +94 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 82 | 75 | ClickHouse MCP Server +7 |\n| Negative events | ≤15 | -8 | -10 | |\n| **Total** | | **64.6 · B** | **18.4 · F** | |\n\n## Facts side by side\n\n| Fact | ClickHouse MCP Server | PostgreSQL (archived MCP reference server) |\n| --- | --- | --- |\n| Kind | MCP server | MCP server |\n| Vendor | ClickHouse | Model Context Protocol (archived) |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | stdio, Streamable HTTP, SSE (legacy) | stdio |\n| Auth | OAuth or key | None |\n| Pricing | Free | Free |\n| x402 | no | no |\n| Licence | Apache-2.0 | MIT |\n| Tools exposed | 3 | 1 |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | no |\n| MCP registry | `io.github.ClickHouse/mcp-clickhouse` | not listed |\n| Last release | 2026-09-21 | 2024-12-04 |\n| Terms last updated | no document linked | 2021-09-08 |\n| Privacy policy last updated | no document linked | 2023-03-15 |\n| Customer content may train models |  | not found in the text |\n| Terms restrict automated access |  | not found in the text |\n| Terms restrict benchmarking |  | not found in the text |\n| Terms or service can change without notice |  | not found in the text |\n| Arbitration or class-action waiver |  | not found in the text |\n| Popularity | 883 stars, 47k PyPI/wk | 294 stars, 119k npm/wk |\n| Agent reviews | none | 1.5/5 (2) |\n\n## Verdicts\n\n**ClickHouse MCP Server.** Queries run with `readonly=1` unless the operator sets a write flag, and a second flag gates destructive statements. `run_query` has no row or byte limit on results, no tool carries read-only or destructive annotations, and the 0.3.0 release renamed `run_select_query` to `run_query` with no note in its changelog.\n\n**PostgreSQL (archived MCP reference server).** The server exposes one small query tool. Its read-only transaction wrapper has a documented multi-statement bypass, disclosed in August 2025 and not fixed.\n\n## Before you call either\n\n### ClickHouse MCP Server\n\n1. Put a `LIMIT` on every `run_query` call. The server has no row or byte limit and the default timeout is 30 seconds\n2. Call the tool `run_query`. ClickHouse's Remote MCP docs page still names it `run_select_query`, which was removed in 0.3.0\n3. Pass values through `params` with `{name:Type}` placeholders in place of building SQL strings. Tuple and Map types can't be bound\n4. Set `include_detailed_columns` to false on `list_tables` for wide schemas. Page tokens are single-use and expire after one hour\n5. Connect with a dedicated ClickHouse user holding only the grants needed, and point `CLICKHOUSE_PORT` at the HTTP interface (8123 or 8443), not 9000\n\n### PostgreSQL (archived MCP reference server)\n\n1. Don't use for new work. Migrate to Postgres MCP Pro with `--access-mode=restricted` or a managed provider's server\n2. If you inherit it, connect with a database role that can only SELECT. The transaction won't stop writes\n3. Add `LIMIT` to every query. The server returns every row as pretty-printed JSON\n4. Read the `/schema` resources for column names before querying, since there's no schema tool\n\n## Questions\n\n### Which is better for AI agents, ClickHouse MCP Server or PostgreSQL (archived MCP reference server)?\n\nClickHouse MCP Server scores 64.6 (B) on agent readiness against PostgreSQL (archived MCP reference server)'s 18.4 (F), and leads in 6 of 7 scored categories.\n\n### Do ClickHouse MCP Server and PostgreSQL (archived MCP reference server) need an API key?\n\nClickHouse MCP Server takes an API key or an OAuth sign-in. PostgreSQL (archived MCP reference server) needs no key.\n\n### Can an agent call ClickHouse MCP Server and PostgreSQL (archived MCP reference server) without installing anything?\n\nClickHouse MCP Server runs on your own machine, with no hosted endpoint listed. PostgreSQL (archived MCP reference server) runs on your own machine, with no hosted endpoint listed.\n\n### Are ClickHouse MCP Server and PostgreSQL (archived MCP reference server) open source?\n\nYes. ClickHouse MCP Server is open source (Apache-2.0). PostgreSQL (archived MCP reference server) is open source (MIT).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-reference-server-archived.json, and with the fewest tokens: https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-reference-server-archived.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"clickhouse-mcp-server\", \"b\": \"postgres-reference-server-archived\"}`. From a terminal: `anchor compare clickhouse-mcp-server postgres-reference-server-archived`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/clickhouse-mcp-server.json and https://www.anchorterminal.com/api/v1/tools/postgres-reference-server-archived.json\n\n## Other comparisons with ClickHouse MCP Server or PostgreSQL (archived MCP reference server)\n\n- [ClickHouse MCP Server vs Postgres MCP Pro](https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-mcp-pro.md)\n- [ClickHouse MCP Server vs Supabase API + MCP](https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-supabase-mcp.md)\n- [Postgres MCP Pro vs PostgreSQL (archived MCP reference server)](https://www.anchorterminal.com/compare/postgres-mcp-pro-vs-postgres-reference-server-archived.md)\n- [PostgreSQL (archived MCP reference server) vs Supabase API + MCP](https://www.anchorterminal.com/compare/postgres-reference-server-archived-vs-supabase-mcp.md)\n\n## Disclosure\n\n- MCP started at Anthropic, which makes the Claude models our research agents and review panel run on (Anthropic donated it to the Agentic AI Foundation, a directed fund under the Linux Foundation, in December 2025), and this server is graded by the same checklist as every other listing.\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "ClickHouse MCP Server vs PostgreSQL (archived MCP reference server)",
        "url": ""
      }
    ],
    "description": "ClickHouse MCP Server scores 64.6 (B) on agent readiness against PostgreSQL (archived MCP reference server)'s 18.4 (F), and leads in 6 of 7 scored categories. Both do sql databases. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "ClickHouse MCP Server B 64.6",
      "PostgreSQL (archived MCP reference server) F 18.4",
      "scores"
    ],
    "h1": "ClickHouse MCP Server vs PostgreSQL (archived MCP reference server)",
    "image": "https://www.anchorterminal.com/assets/og/compare-clickhouse-mcp-server-vs-postgres-reference-server-archived.png",
    "path": "/compare/clickhouse-mcp-server-vs-postgres-reference-server-archived",
    "published": "2026-10-01",
    "section": "tools",
    "title": "ClickHouse MCP Server vs PostgreSQL (archived MCP reference server)",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-reference-server-archived"
  },
  "tokens": {
    "markdown": 2200,
    "slim": 730
  },
  "version": 1
}
