Head to head · SQL databases · October 2026 research run

ClickHouse MCP Server vs Snowflake-managed MCP server

ClickHouse MCP Server scores 64.6 (B) on agent readiness against Snowflake-managed MCP server's 56.4 (C), and leads in 5 of 7 scored categories. Snowflake-managed MCP server leads on security & auth. Both do sql databases.

Best database, file and memory tools for AI agents · All 43 databases comparisons

Which one, for what

ClickHouse MCP Server B

Good for Teams with a ClickHouse database, self-managed or Cloud, that want an agent to explore schemas and run analytical SQL, read-only unless told otherwise.

Ahead on

  • Reliability, 74 against 55
  • Schema & documentation, 79 against 61
  • Agent ergonomics, 65 against 46
  • Payments & pricing, 60 against 35
  • Maintenance & community, 94 against 55

Also in its favour

  • Runs on your own machine
  • Open source

Watch for

run_query returns every row. Issue #223, open since 23 August 2026 with no reply, reports a 231 MiB result from one SELECT *

Snowflake-managed MCP server C

Good for A company that already keeps its data in Snowflake and wants outside MCP clients to query it under existing roles, best through one Cortex Agent tool.

Ahead on

  • Security & auth, 77 against 66

Watch for

No rate limits for the MCP endpoint and no JSON-RPC error codes were found in the reviewed documentation

Score by category

CategoryWeight this runClickHouse MCP ServerSnowflake-managed MCP serverEdge
Reliability16%207455ClickHouse MCP Server +19
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27961ClickHouse MCP Server +18
Agent ergonomics13%16.26546ClickHouse MCP Server +19
Security & auth14%17.56677Snowflake-managed MCP server +11
Payments & pricing10%12.56035ClickHouse MCP Server +25
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.89455ClickHouse MCP Server +39
Transparency & trust7%8.88284Snowflake-managed MCP server +2
Negative events≤15-8-2
Total64.6 · B56.4 · C

Facts side by side

FactClickHouse MCP ServerSnowflake-managed MCP server
KindMCP serverMCP server
VendorClickHouseSnowflake Inc.
Hosted endpointno (local only)no (local only)
Transportsstdio, Streamable HTTP, SSE (legacy)Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreePay per use
x402nono
LicenceApache-2.0Proprietary service under Snowflake's terms of service
Tools exposed3none
Read-only variant documentedyesyes
llms.txtyesyes
MCP registryio.github.ClickHouse/mcp-clickhousenot listed
Last release2026-09-212026-08-20
Terms last updatedno document linked2026-04-16
Privacy policy last updatedno document linked2026-07-01
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticenot found in the text
Arbitration or class-action waiveryes
Popularity883 stars, 47k PyPI/wknone

Verdicts

ClickHouse MCP Server

Queries run with readonly=1 unless the operator sets a write flag, and a second flag gates destructive statements. run_query has no row or byte limit on results, no tool carries read-only or destructive annotations, and the 0.3.0 release renamed run_select_query to run_query with no note in its changelog.

Snowflake-managed MCP server

Tools are governed by Snowflake roles, the SQL tool is read-only by default, and sign-in runs through Snowflake OAuth or a company identity provider. No rate limits or tool-call error codes were found in the reviewed documentation, and a person must create the account, the server object and the OAuth integration before an agent can connect.

Before you call either

ClickHouse MCP Server

  1. Put a LIMIT on every run_query call. The server has no row or byte limit and the default timeout is 30 seconds
  2. Call the tool run_query. ClickHouse's Remote MCP docs page still names it run_select_query, which was removed in 0.3.0
  3. Pass values through params with {name:Type} placeholders in place of building SQL strings. Tuple and Map types can't be bound
  4. Set include_detailed_columns to false on list_tables for wide schemas. Page tokens are single-use and expire after one hour
  5. Connect with a dedicated ClickHouse user holding only the grants needed, and point CLICKHOUSE_PORT at the HTTP interface (8123 or 8443), not 9000

Snowflake-managed MCP server

  1. Send Accept: application/json, text/event-stream and read tools/call results as an SSE stream that ends with data: [DONE]
  2. Write the account hostname with hyphens, not underscores, or some clients fail to connect
  3. Check the user's DEFAULT_ROLE and DEFAULT_WAREHOUSE first. Clients that request session:role:all get the default role, and a missing warehouse stops the session starting
  4. Keep SQL results narrow. Responses over 250 KB are truncated with no paging, and agent tool responses can pass 200 KB
  5. Treat invalid_client from /oauth/token-request as a possible network policy block as well as a wrong credential

Questions

Which is better for AI agents, ClickHouse MCP Server or Snowflake-managed MCP server?

ClickHouse MCP Server scores 64.6 (B) on agent readiness against Snowflake-managed MCP server's 56.4 (C), and leads in 5 of 7 scored categories. Snowflake-managed MCP server leads on security & auth.

Do ClickHouse MCP Server and Snowflake-managed MCP server need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call ClickHouse MCP Server and Snowflake-managed MCP server without installing anything?

ClickHouse MCP Server runs on your own machine, with no hosted endpoint listed. No hosted endpoint is listed for Snowflake-managed MCP server.

Are ClickHouse MCP Server and Snowflake-managed MCP server open source?

ClickHouse MCP Server is open source (Apache-2.0). No open-source release is listed for Snowflake-managed MCP server.

Other comparisons with ClickHouse MCP Server or Snowflake-managed MCP server

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.