{
  "data": {
    "a": {
      "slug": "clickhouse-mcp-server",
      "name": "ClickHouse MCP Server",
      "vendor": "ClickHouse",
      "vendorUrl": "https://clickhouse.com",
      "kind": "mcp",
      "category": "data",
      "summary": "ClickHouse's open-source MCP server for ClickHouse databases. The owner runs it locally or self-hosted, and it gives agents SQL queries, database and table listing, and an optional embedded chDB engine. Queries are read-only by default.",
      "url": "https://www.anchorterminal.com/tools/clickhouse-mcp-server",
      "markdownUrl": "https://www.anchorterminal.com/tools/clickhouse-mcp-server.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/clickhouse-mcp-server.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/clickhouse-mcp-server.json",
      "repo": "https://github.com/ClickHouse/mcp-clickhouse",
      "license": "Apache-2.0",
      "transports": [
        "stdio",
        "streamable-http",
        "sse"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "mcp-clickhouse"
        },
        {
          "registry": "oci",
          "name": "ghcr.io/clickhouse/mcp-clickhouse"
        }
      ],
      "auth": "mixed",
      "authNotes": "The server signs in to ClickHouse with `CLICKHOUSE_USER` and `CLICKHOUSE_PASSWORD`, or with an X.509 client certificate (`CLICKHOUSE_CLIENT_CERT`, added in 0.7.0), and can set a role with `CLICKHOUSE_ROLE`. An admin creates the user, self-serve, and ClickHouse grants set what it can do. stdio needs no caller credential. The HTTP and SSE transports refuse to start unless one of a static bearer token (`CLICKHOUSE_MCP_AUTH_TOKEN`), a FastMCP OAuth or OIDC provider (`FASTMCP_SERVER_AUTH`) or `CLICKHOUSE_MCP_AUTH_DISABLED=true` is set. Every caller shares the one ClickHouse user unless custom middleware overrides the connection per request.",
      "pricing": "free",
      "pricingNotes": "Free and open source under Apache-2.0, with nothing to buy for the server. It needs a ClickHouse database, which can be self-managed open-source ClickHouse, ClickHouse Cloud or the embedded chDB engine. The README gives a public SQL playground (`sql-clickhouse.clickhouse.com`, user `demo`, empty password) for trying it with no account. ClickHouse Cloud prices were not checked. The separate hosted Remote MCP server is a ClickHouse Cloud feature and is not what this listing grades (checked 2026-10-09).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the README, the changelog or the source (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": 3,
      "popularity": {
        "githubStars": 883,
        "npmWeekly": null,
        "pypiWeekly": 47206,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://github.com/ClickHouse/mcp-clickhouse#readme",
      "llmsTxt": "https://clickhouse.com/docs/llms.txt",
      "registryName": "io.github.ClickHouse/mcp-clickhouse",
      "capabilities": [
        "db.sql"
      ],
      "tags": [
        "official",
        "local",
        "open-source",
        "self-hosted",
        "mcp",
        "python",
        "docker",
        "read-only-mode",
        "database"
      ],
      "lastRelease": "2026-09-21",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.6,
        "grade": "B",
        "agentReady": false,
        "rank": 345,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 94,
          "payments": 60,
          "reliability": 74,
          "schema": 79,
          "security": 66,
          "transparency": 82
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -8,
        "negativeNotes": [
          "-3: release 0.3.0 on 14 April 2026 renamed the `run_select_query` tool to `run_query` (commit d82fc87, pull request #93). Neither the changelog entry nor the GitHub release notes for 0.3.0 mention the rename, and ClickHouse's Remote MCP docs page still names the old tool (https://github.com/ClickHouse/mcp-clickhouse/blob/main/CHANGELOG.md).",
          "-3: issue #131, opened on 18 February 2026, reports that `run_select_query` ran CREATE and DROP statements against a ClickHouse Cloud user with full privileges although the docs said every query ran with `readonly=1`, and that an agent dropped a production table. This is the reporter's account. A maintainer closed it on 20 April 2026 as addressed by pull request #93 in 0.3.0. No advisory was published, and the fix shipped, so a reduced deduction (https://github.com/ClickHouse/mcp-clickhouse/issues/131).",
          "-2: 0.5.0 on 1 September 2026 closed a `fastmcp run` launch path that served HTTP without authentication and fixed TRUNCATE and `ALTER TABLE ... DROP` forms that the destructive gate had let through with write access on. Both are described in the changelog and fixed, with no advisory, so a reduced deduction (https://github.com/ClickHouse/mcp-clickhouse/blob/main/CHANGELOG.md)."
        ],
        "verdict": "Queries run with `readonly=1` unless the operator sets a write flag, and a second flag gates destructive statements. `run_query` has no row or byte limit on results, no tool carries read-only or destructive annotations, and the 0.3.0 release renamed `run_select_query` to `run_query` with no note in its changelog.",
        "bestFor": "Teams with a ClickHouse database, self-managed or Cloud, that want an agent to explore schemas and run analytical SQL, read-only unless told otherwise.",
        "strengths": [
          "Read-only by default through ClickHouse's `readonly=1` setting, with `CLICKHOUSE_ALLOW_WRITE_ACCESS` and `CLICKHOUSE_ALLOW_DROP` as separate opt-ins",
          "Three tools by default (`run_query`, `list_databases`, `list_tables`) and a fourth, `run_chdb_select_query`, only when chDB is enabled",
          "HTTP and SSE transports refuse to start without a bearer token, a FastMCP OAuth or OIDC provider, or an explicit disable flag, and validate Host and Origin headers",
          "CI passed on main on 6 October 2026 across Python 3.10 to 3.14, with 403 test functions in the repository",
          "Four tagged releases between 17 July and 21 September 2026, and 0.7.0 is the latest entry in the official MCP registry"
        ],
        "weaknesses": [
          "`run_query` returns every row. Issue #223, open since 23 August 2026 with no reply, reports a 231 MiB result from one `SELECT *`",
          "No tool declares `readOnlyHint` or `destructiveHint`. Pull request #184 adding annotations has been open since 22 May 2026",
          "Release 0.3.0 renamed `run_select_query` to `run_query` without saying so in its changelog or release notes, and ClickHouse's Remote MCP docs page still uses the old name",
          "The destructive-statement gate is a keyword check in the server, which the README calls a best-effort guard and not a security boundary",
          "No prompt-injection guidance for query results was found, the repository has no SECURITY.md, and no advisory covers the security fixes in 0.3.0 and 0.5.0"
        ],
        "agentNotes": [
          "Put a `LIMIT` on every `run_query` call. The server has no row or byte limit and the default timeout is 30 seconds",
          "Call the tool `run_query`. ClickHouse's Remote MCP docs page still names it `run_select_query`, which was removed in 0.3.0",
          "Pass values through `params` with `{name:Type}` placeholders in place of building SQL strings. Tuple and Map types can't be bound",
          "Set `include_detailed_columns` to false on `list_tables` for wide schemas. Page tokens are single-use and expire after one hour",
          "Connect with a dedicated ClickHouse user holding only the grants needed, and point `CLICKHOUSE_PORT` at the HTTP interface (8123 or 8443), not 9000"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.6
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 94,
          "payments": 60,
          "reliability": 74,
          "schema": 79,
          "security": 66,
          "transparency": 76
        },
        "provenanceScore": 87
      },
      "connect": {
        "install": "python3 -m pip install mcp-clickhouse",
        "config": {
          "mcpServers": {
            "mcp-clickhouse": {
              "args": [
                "run",
                "--with",
                "mcp-clickhouse",
                "--python",
                "3.12",
                "mcp-clickhouse"
              ],
              "command": "uv",
              "env": {
                "CLICKHOUSE_CONNECT_TIMEOUT": "30",
                "CLICKHOUSE_HOST": "\u003cclickhouse-host\u003e",
                "CLICKHOUSE_PASSWORD": "\u003cclickhouse-password\u003e",
                "CLICKHOUSE_PORT": "\u003cclickhouse-port\u003e",
                "CLICKHOUSE_SECURE": "true",
                "CLICKHOUSE_USER": "\u003cclickhouse-user\u003e",
                "CLICKHOUSE_VERIFY": "true"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/db.sql",
        "tool": "https://letme.dev/clickhouse-mcp-server"
      },
      "area": "developer",
      "provenance": {
        "legalEntity": "ClickHouse, Inc.",
        "domain": "clickhouse.com",
        "domainRegistered": "1999-03-12",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/ClickHouse/mcp-clickhouse/blob/main/CHANGELOG.md",
        "securityTxt": "valid",
        "checked": "2026-10-09",
        "notes": [
          "No terms document governs this software beyond the Apache-2.0 licence, so `terms` is left out.",
          "`privacy` is left out. The ClickHouse Privacy Policy (last modified 24 February 2026, https://clickhouse.com/legal/privacy-policy) covers ClickHouse, Inc.'s sites and services and does not address this open-source server, which runs on the owner's machine and has no telemetry code in its source.",
          "clickhouse.com/.well-known/security.txt gives security@clickhouse.com, a policy link to the ClickHouse repository's SECURITY.md and an expiry of 28 July 2027.",
          "RDAP for clickhouse.com gives a registration date of 1999-03-12.",
          "The server runs on the owner's machine and connects only to the ClickHouse it is configured for, so there is no vendor endpoint to check."
        ],
        "score": 87
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/clickhouse-mcp-server.json",
      "live": {
        "slug": "clickhouse-mcp-server",
        "versions": [
          {
            "registry": "github",
            "name": "ClickHouse/mcp-clickhouse",
            "version": "v0.7.0",
            "released": "2026-09-21",
            "seenAt": "2026-10-09T16:45:37.005577252Z"
          },
          {
            "registry": "pypi",
            "name": "mcp-clickhouse",
            "version": "0.7.0",
            "released": "2026-09-21",
            "seenAt": "2026-10-09T16:45:36.761584684Z"
          }
        ],
        "githubStars": 883,
        "pypiWeekly": 49925,
        "securityTxt": {
          "url": "https://clickhouse.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-07-28T00:00:00.000Z",
          "checkedAt": "2026-10-09T15:39:17.233983608Z"
        },
        "llmsTxt": {
          "url": "https://clickhouse.com/docs/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-09T14:01:36.103621843Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/ClickHouse/mcp-clickhouse/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:44:23.144194276Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b42b96107c3d"
          }
        ],
        "updatedAt": "2026-10-09T18:44:23.144194276Z"
      }
    },
    "answer": "ClickHouse MCP Server scores 64.6 (B) on agent readiness against Snowflake-managed MCP server's 56.4 (C), and leads in 5 of 7 scored categories. Snowflake-managed MCP server leads on security \u0026 auth.",
    "b": {
      "slug": "snowflake-managed",
      "name": "Snowflake-managed MCP server",
      "vendor": "Snowflake Inc.",
      "vendorUrl": "https://www.snowflake.com",
      "kind": "mcp",
      "category": "data",
      "summary": "Snowflake's managed MCP server is an object created in a Snowflake account that exposes Cortex Agents, Cortex Search, Cortex Analyst, SQL execution and custom functions, each as an MCP tool, over HTTP, with OAuth and role-based access control.",
      "url": "https://www.anchorterminal.com/tools/snowflake-managed",
      "markdownUrl": "https://www.anchorterminal.com/tools/snowflake-managed.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/snowflake-managed.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/snowflake-managed.json",
      "license": "Proprietary service under Snowflake's terms of service",
      "transports": [
        "streamable-http"
      ],
      "packages": [],
      "auth": "mixed",
      "authNotes": "OAuth 2.0 is the documented default. An administrator creates a Snowflake OAuth security integration (confidential, or public with PKCE) and gives its client ID and secret to the MCP client, because dynamic client registration is not supported. Since 22 July 2026 a schema, database or account can bind its MCP servers to an External OAuth integration such as Okta or Microsoft Entra ID. Scopes of the form `session:role:\u003crole_name\u003e` pick the session's primary role. Programmatic access tokens are also accepted, expire after 15 days by default and 365 at most, and Snowflake recommends OAuth over them. There is no self-serve key an agent can mint for itself.",
      "pricing": "usage",
      "pricingNotes": "No charge is listed for the MCP server itself. Tools bill at the rates of what they call. SQL and custom tools use warehouse compute in Platform Credits, from $2.00 a credit on demand for Standard edition in US regions. Cortex Agents and Cortex Search bill in AI Credits at $2.00 each with global routing. A 30-day trial needs only an email address, with Cortex tools disabled until a card is added (checked 2026-10-09).",
      "priceSummary": "$2 / credit",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the MCP server docs, the AI pricing page or the Service Consumption Table (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-mcp",
      "llmsTxt": "https://docs.snowflake.com/llms.txt",
      "capabilities": [
        "db.sql",
        "knowledge.search",
        "analytics.query"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "oauth",
        "read-only-mode",
        "database",
        "enterprise",
        "llms-txt",
        "status-page",
        "soc2",
        "usage-priced",
        "free-trial"
      ],
      "lastRelease": "2026-08-20",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 56.4,
        "grade": "C",
        "agentReady": false,
        "rank": 633,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 46,
          "maintenance": 55,
          "payments": 35,
          "reliability": 55,
          "schema": 61,
          "security": 77,
          "transparency": 84
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -2,
        "negativeNotes": [
          "20 August 2026. `tools/call` responses changed from a single JSON body to an SSE stream as an unbundled behaviour change that accounts could not disable, outside the eight-week bundle process. Clients reading one JSON body broke. The change is documented with migration steps and clients that follow the MCP specification were unaffected, so the deduction is small. Whether notice was given before the release date was not established (https://docs.snowflake.com/en/release-notes/bcr-bundles/un-bundled/bcr-2405)."
        ],
        "verdict": "Tools are governed by Snowflake roles, the SQL tool is read-only by default, and sign-in runs through Snowflake OAuth or a company identity provider. No rate limits or tool-call error codes were found in the reviewed documentation, and a person must create the account, the server object and the OAuth integration before an agent can connect.",
        "bestFor": "A company that already keeps its data in Snowflake and wants outside MCP clients to query it under existing roles, best through one Cortex Agent tool.",
        "strengths": [
          "Each tool needs its own grant. `USAGE` on the MCP server does not give access to the agent, search service, semantic view, function or procedure behind a tool",
          "The SQL execution tool defaults to `read_only: true` and takes a `query_timeout` and a named warehouse",
          "OAuth with PKCE for public clients, role scopes, an allowed-roles list and, since 22 July 2026, binding to an external identity provider with RFC 9728 metadata",
          "Generally available since 4 November 2025, under a 99.9 per cent monthly availability SLA with service credits",
          "Per-credit prices by region and edition are public in the Service Consumption Table, and the docs publish llms.txt and Markdown copies of every page"
        ],
        "weaknesses": [
          "No rate limits for the MCP endpoint and no JSON-RPC error codes were found in the reviewed documentation",
          "No dynamic client registration. An administrator creates a security integration and hands the client ID and secret to each MCP client",
          "On 20 August 2026 `tools/call` responses changed from one JSON body to an SSE stream, outside a behaviour change bundle and with no way to disable it",
          "Resources, prompts, roots, notifications, sampling, version negotiation and lifecycle phases are unsupported, and SQL and custom tool responses are cut at 250 KB",
          "status.snowflake.com shows two incidents marked critical (25 and 27 September 2026) and one marked major (6 October) in the 15 days its front page lists",
          "Cortex tools stay disabled on a trial account until a credit card is added"
        ],
        "agentNotes": [
          "Send `Accept: application/json, text/event-stream` and read `tools/call` results as an SSE stream that ends with `data: [DONE]`",
          "Write the account hostname with hyphens, not underscores, or some clients fail to connect",
          "Check the user's `DEFAULT_ROLE` and `DEFAULT_WAREHOUSE` first. Clients that request `session:role:all` get the default role, and a missing warehouse stops the session starting",
          "Keep SQL results narrow. Responses over 250 KB are truncated with no paging, and agent tool responses can pass 200 KB",
          "Treat `invalid_client` from `/oauth/token-request` as a possible network policy block as well as a wrong credential"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 56.4
          }
        ],
        "editorialScores": {
          "ergonomics": 46,
          "maintenance": 55,
          "payments": 35,
          "reliability": 55,
          "schema": 61,
          "security": 77,
          "transparency": 68
        },
        "provenanceScore": 99
      },
      "connect": {
        "config": {
          "mcpServers": {
            "snowflake": {
              "auth": {
                "CLIENT_ID": "${env:MCP_CLIENT_ID}",
                "CLIENT_SECRET": "${env:MCP_CLIENT_SECRET}"
              },
              "url": "https://\u003caccount_url\u003e/api/v2/databases/\u003cdatabase\u003e/schemas/\u003cschema\u003e/mcp-servers/\u003cname\u003e"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/db.sql",
        "tool": "https://letme.dev/snowflake-managed"
      },
      "area": "developer",
      "unitPrices": [
        {
          "item": "Platform Credit, Standard edition, on demand",
          "unit": "credit",
          "usd": 2,
          "note": "AWS US East. $3.00 on Enterprise. Higher in other regions. Used by SQL and custom tools through a warehouse"
        },
        {
          "item": "AI Credit, global routing",
          "unit": "credit",
          "usd": 2,
          "note": "$2.20 with regional routing. Used by Cortex Agents and Cortex Search"
        }
      ],
      "provenance": {
        "legalEntity": "Snowflake Inc.",
        "domain": "snowflake.com",
        "domainRegistered": "1995-07-08",
        "endpointOnVendorDomain": true,
        "terms": "https://www.snowflake.com/en/legal/terms-of-service/self-service-on-demand-terms-of-service/",
        "privacy": "https://www.snowflake.com/en/legal/privacy/privacy-policy/",
        "statusPage": "https://status.snowflake.com",
        "changelog": "https://docs.snowflake.com/en/release-notes/new-features",
        "securityTxt": "valid",
        "checked": "2026-10-09",
        "notes": [
          "The Privacy Notice (updated 1 July 2026) names Snowflake Inc., Suite 3A, 106 East Babcock Street, Bozeman, Montana 59715, and says it does not apply to Customer Data, which the customer agreement and the DPA govern.",
          "The terms link is the Self-Service On Demand Terms of Service (updated 16 April 2026), which a self-serve account accepts. Contract customers sign the Master Terms at https://www.snowflake.com/en/legal/terms-of-service/.",
          "Each MCP server answers on the customer's account URL, which the docs give as https://\u003corgname\u003e-\u003caccount_name\u003e.snowflakecomputing.com, a second Snowflake domain.",
          "security.txt at www.snowflake.com/.well-known/security.txt names security@snowflake.com and a HackerOne policy, and expires on 17 August 2027.",
          "RDAP for snowflake.com gives a registration date of 1995-07-08."
        ],
        "score": 99
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/snowflake-managed.json",
      "live": {
        "slug": "snowflake-managed",
        "vendorStatus": {
          "page": "https://status.snowflake.com",
          "indicator": "minor",
          "summary": "Partially Degraded Service",
          "checkedAt": "2026-10-10T02:06:28.433171094Z"
        },
        "pages": [
          {
            "url": "https://docs.snowflake.com/en/release-notes/new-features",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:38:22.182288094Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e4104fceb66c"
          },
          {
            "url": "https://www.snowflake.com/en/legal/privacy/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:54:26.035718718Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "baf8ac1c3f70"
          },
          {
            "url": "https://www.snowflake.com/en/legal/terms-of-service/self-service-on-demand-terms-of-service/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:54:28.152417291Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5b6b42771109"
          }
        ],
        "updatedAt": "2026-10-10T02:06:28.433171094Z"
      }
    },
    "facts": [
      {
        "a": "MCP server",
        "b": "MCP server",
        "name": "Kind"
      },
      {
        "a": "ClickHouse",
        "b": "Snowflake Inc.",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "stdio, Streamable HTTP, SSE (legacy)",
        "b": "Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Pay per use",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0",
        "b": "Proprietary service under Snowflake's terms of service",
        "name": "Licence"
      },
      {
        "a": "3",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "io.github.ClickHouse/mcp-clickhouse",
        "b": "not listed",
        "name": "MCP registry"
      },
      {
        "a": "2026-09-21",
        "b": "2026-08-20",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "2026-04-16",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "2026-07-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "883 stars, 47k PyPI/wk",
        "b": "none",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "ClickHouse MCP Server scores 64.6 (B) on agent readiness against Snowflake-managed MCP server's 56.4 (C), and leads in 5 of 7 scored categories. Snowflake-managed MCP server leads on security \u0026 auth.",
        "question": "Which is better for AI agents, ClickHouse MCP Server or Snowflake-managed MCP server?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do ClickHouse MCP Server and Snowflake-managed MCP server need an API key?"
      },
      {
        "answer": "ClickHouse MCP Server runs on your own machine, with no hosted endpoint listed. No hosted endpoint is listed for Snowflake-managed MCP server.",
        "question": "Can an agent call ClickHouse MCP Server and Snowflake-managed MCP server without installing anything?"
      },
      {
        "answer": "ClickHouse MCP Server is open source (Apache-2.0). No open-source release is listed for Snowflake-managed MCP server.",
        "question": "Are ClickHouse MCP Server and Snowflake-managed MCP server open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 74 against 55",
          "Schema \u0026 documentation, 79 against 61",
          "Agent ergonomics, 65 against 46",
          "Payments \u0026 pricing, 60 against 35",
          "Maintenance \u0026 community, 94 against 55"
        ],
        "also": [
          "Runs on your own machine",
          "Open source"
        ],
        "goodFor": "Teams with a ClickHouse database, self-managed or Cloud, that want an agent to explore schemas and run analytical SQL, read-only unless told otherwise.",
        "slug": "clickhouse-mcp-server",
        "watchFor": "`run_query` returns every row. Issue #223, open since 23 August 2026 with no reply, reports a 231 MiB result from one `SELECT *`"
      },
      {
        "aheadOn": [
          "Security \u0026 auth, 77 against 66"
        ],
        "also": null,
        "goodFor": "A company that already keeps its data in Snowflake and wants outside MCP clients to query it under existing roles, best through one Cortex Agent tool.",
        "slug": "snowflake-managed",
        "watchFor": "No rate limits for the MCP endpoint and no JSON-RPC error codes were found in the reviewed documentation"
      }
    ],
    "job": {
      "capability": "db.sql",
      "name": "SQL databases"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-planetscale-mcp.json",
        "title": "ClickHouse MCP Server vs PlanetScale MCP Server",
        "url": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-planetscale-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-mcp-pro.json",
        "title": "ClickHouse MCP Server vs Postgres MCP Pro",
        "url": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-mcp-pro"
      },
      {
        "json": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-reference-server-archived.json",
        "title": "ClickHouse MCP Server vs PostgreSQL (archived MCP reference server)",
        "url": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-reference-server-archived"
      },
      {
        "json": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-supabase-mcp.json",
        "title": "ClickHouse MCP Server vs Supabase API + MCP",
        "url": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-supabase-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/planetscale-mcp-vs-snowflake-managed.json",
        "title": "PlanetScale MCP Server vs Snowflake-managed MCP server",
        "url": "https://www.anchorterminal.com/compare/planetscale-mcp-vs-snowflake-managed"
      },
      {
        "json": "https://www.anchorterminal.com/compare/postgres-mcp-pro-vs-snowflake-managed.json",
        "title": "Postgres MCP Pro vs Snowflake-managed MCP server",
        "url": "https://www.anchorterminal.com/compare/postgres-mcp-pro-vs-snowflake-managed"
      },
      {
        "json": "https://www.anchorterminal.com/compare/postgres-reference-server-archived-vs-snowflake-managed.json",
        "title": "PostgreSQL (archived MCP reference server) vs Snowflake-managed MCP server",
        "url": "https://www.anchorterminal.com/compare/postgres-reference-server-archived-vs-snowflake-managed"
      },
      {
        "json": "https://www.anchorterminal.com/compare/snowflake-managed-vs-supabase-mcp.json",
        "title": "Snowflake-managed MCP server vs Supabase API + MCP",
        "url": "https://www.anchorterminal.com/compare/snowflake-managed-vs-supabase-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-mongodb-mcp.json",
        "title": "ClickHouse MCP Server vs MongoDB MCP Server",
        "url": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-mongodb-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-redis-mcp.json",
        "title": "ClickHouse MCP Server vs Redis MCP",
        "url": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-redis-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mongodb-mcp-vs-snowflake-managed.json",
        "title": "MongoDB MCP Server vs Snowflake-managed MCP server",
        "url": "https://www.anchorterminal.com/compare/mongodb-mcp-vs-snowflake-managed"
      },
      {
        "json": "https://www.anchorterminal.com/compare/redis-mcp-vs-snowflake-managed.json",
        "title": "Redis MCP vs Snowflake-managed MCP server",
        "url": "https://www.anchorterminal.com/compare/redis-mcp-vs-snowflake-managed"
      }
    ],
    "scores": [
      {
        "by": 19,
        "clickhouse-mcp-server": 74,
        "edge": "clickhouse-mcp-server",
        "key": "reliability",
        "name": "Reliability",
        "snowflake-managed": 55,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 18,
        "clickhouse-mcp-server": 79,
        "edge": "clickhouse-mcp-server",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "snowflake-managed": 61,
        "weight": 13
      },
      {
        "by": 19,
        "clickhouse-mcp-server": 65,
        "edge": "clickhouse-mcp-server",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "snowflake-managed": 46,
        "weight": 13
      },
      {
        "by": 11,
        "clickhouse-mcp-server": 66,
        "edge": "snowflake-managed",
        "key": "security",
        "name": "Security \u0026 auth",
        "snowflake-managed": 77,
        "weight": 14
      },
      {
        "by": 25,
        "clickhouse-mcp-server": 60,
        "edge": "clickhouse-mcp-server",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "snowflake-managed": 35,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 39,
        "clickhouse-mcp-server": 94,
        "edge": "clickhouse-mcp-server",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "snowflake-managed": 55,
        "weight": 7
      },
      {
        "by": 2,
        "clickhouse-mcp-server": 82,
        "edge": "snowflake-managed",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "snowflake-managed": 84,
        "weight": 7
      }
    ],
    "summary": "ClickHouse MCP Server scores 64.6 (B) on agent readiness against Snowflake-managed MCP server's 56.4 (C), and leads in 5 of 7 scored categories. Snowflake-managed MCP server leads on security \u0026 auth. Both do sql databases.",
    "verdicts": {
      "clickhouse-mcp-server": "Queries run with `readonly=1` unless the operator sets a write flag, and a second flag gates destructive statements. `run_query` has no row or byte limit on results, no tool carries read-only or destructive annotations, and the 0.3.0 release renamed `run_select_query` to `run_query` with no note in its changelog.",
      "snowflake-managed": "Tools are governed by Snowflake roles, the SQL tool is read-only by default, and sign-in runs through Snowflake OAuth or a company identity provider. No rate limits or tool-call error codes were found in the reviewed documentation, and a person must create the account, the server object and the OAuth integration before an agent can connect."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-snowflake-managed",
    "json": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-snowflake-managed.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-snowflake-managed.md",
    "slim": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-snowflake-managed.min.md"
  },
  "markdown": "ClickHouse MCP Server scores 64.6 (B) on agent readiness against Snowflake-managed MCP server's 56.4 (C), and leads in 5 of 7 scored categories. Snowflake-managed MCP server leads on security \u0026 auth. Both do sql databases.\n\n- ClickHouse MCP Server: grade B, 64.6/100, rank #345 of 950. Markdown https://www.anchorterminal.com/tools/clickhouse-mcp-server.md · JSON https://www.anchorterminal.com/api/v1/tools/clickhouse-mcp-server.json\n- Snowflake-managed MCP server: grade C, 56.4/100, rank #633 of 950. Markdown https://www.anchorterminal.com/tools/snowflake-managed.md · JSON https://www.anchorterminal.com/api/v1/tools/snowflake-managed.json\n- Best database, file and memory tools for AI agents: https://www.anchorterminal.com/best/data/index.md\n- All 43 databases comparisons: https://www.anchorterminal.com/compare/data/index.md\n\n## Which one, for what\n\n### ClickHouse MCP Server (B)\n\nGood for: Teams with a ClickHouse database, self-managed or Cloud, that want an agent to explore schemas and run analytical SQL, read-only unless told otherwise.\n\nAhead on:\n- Reliability, 74 against 55\n- Schema \u0026 documentation, 79 against 61\n- Agent ergonomics, 65 against 46\n- Payments \u0026 pricing, 60 against 35\n- Maintenance \u0026 community, 94 against 55\n\nAlso in its favour:\n- Runs on your own machine\n- Open source\n\nWatch for: `run_query` returns every row. Issue #223, open since 23 August 2026 with no reply, reports a 231 MiB result from one `SELECT *`\n\n### Snowflake-managed MCP server (C)\n\nGood for: A company that already keeps its data in Snowflake and wants outside MCP clients to query it under existing roles, best through one Cortex Agent tool.\n\nAhead on:\n- Security \u0026 auth, 77 against 66\n\nWatch for: No rate limits for the MCP endpoint and no JSON-RPC error codes were found in the reviewed documentation\n\n\n## Score by category\n\n| Category | Weight | ClickHouse MCP Server | Snowflake-managed MCP server | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 74 | 55 | ClickHouse MCP Server +19 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 79 | 61 | ClickHouse MCP Server +18 |\n| Agent ergonomics | 13% (16.2 this run) | 65 | 46 | ClickHouse MCP Server +19 |\n| Security \u0026 auth | 14% (17.5 this run) | 66 | 77 | Snowflake-managed MCP server +11 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 35 | ClickHouse MCP Server +25 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 94 | 55 | ClickHouse MCP Server +39 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 82 | 84 | Snowflake-managed MCP server +2 |\n| Negative events | ≤15 | -8 | -2 | |\n| **Total** | | **64.6 · B** | **56.4 · C** | |\n\n## Facts side by side\n\n| Fact | ClickHouse MCP Server | Snowflake-managed MCP server |\n| --- | --- | --- |\n| Kind | MCP server | MCP server |\n| Vendor | ClickHouse | Snowflake Inc. |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | stdio, Streamable HTTP, SSE (legacy) | Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Free | Pay per use |\n| x402 | no | no |\n| Licence | Apache-2.0 | Proprietary service under Snowflake's terms of service |\n| Tools exposed | 3 | none |\n| Read-only variant documented | yes | yes |\n| llms.txt | yes | yes |\n| MCP registry | `io.github.ClickHouse/mcp-clickhouse` | not listed |\n| Last release | 2026-09-21 | 2026-08-20 |\n| Terms last updated | no document linked | 2026-04-16 |\n| Privacy policy last updated | no document linked | 2026-07-01 |\n| Customer content may train models |  | not found in the text |\n| Terms restrict automated access |  | not found in the text |\n| Terms restrict benchmarking |  | not found in the text |\n| Terms or service can change without notice |  | not found in the text |\n| Arbitration or class-action waiver |  | yes |\n| Popularity | 883 stars, 47k PyPI/wk | none |\n\n## Verdicts\n\n**ClickHouse MCP Server.** Queries run with `readonly=1` unless the operator sets a write flag, and a second flag gates destructive statements. `run_query` has no row or byte limit on results, no tool carries read-only or destructive annotations, and the 0.3.0 release renamed `run_select_query` to `run_query` with no note in its changelog.\n\n**Snowflake-managed MCP server.** Tools are governed by Snowflake roles, the SQL tool is read-only by default, and sign-in runs through Snowflake OAuth or a company identity provider. No rate limits or tool-call error codes were found in the reviewed documentation, and a person must create the account, the server object and the OAuth integration before an agent can connect.\n\n## Before you call either\n\n### ClickHouse MCP Server\n\n1. Put a `LIMIT` on every `run_query` call. The server has no row or byte limit and the default timeout is 30 seconds\n2. Call the tool `run_query`. ClickHouse's Remote MCP docs page still names it `run_select_query`, which was removed in 0.3.0\n3. Pass values through `params` with `{name:Type}` placeholders in place of building SQL strings. Tuple and Map types can't be bound\n4. Set `include_detailed_columns` to false on `list_tables` for wide schemas. Page tokens are single-use and expire after one hour\n5. Connect with a dedicated ClickHouse user holding only the grants needed, and point `CLICKHOUSE_PORT` at the HTTP interface (8123 or 8443), not 9000\n\n### Snowflake-managed MCP server\n\n1. Send `Accept: application/json, text/event-stream` and read `tools/call` results as an SSE stream that ends with `data: [DONE]`\n2. Write the account hostname with hyphens, not underscores, or some clients fail to connect\n3. Check the user's `DEFAULT_ROLE` and `DEFAULT_WAREHOUSE` first. Clients that request `session:role:all` get the default role, and a missing warehouse stops the session starting\n4. Keep SQL results narrow. Responses over 250 KB are truncated with no paging, and agent tool responses can pass 200 KB\n5. Treat `invalid_client` from `/oauth/token-request` as a possible network policy block as well as a wrong credential\n\n## Questions\n\n### Which is better for AI agents, ClickHouse MCP Server or Snowflake-managed MCP server?\n\nClickHouse MCP Server scores 64.6 (B) on agent readiness against Snowflake-managed MCP server's 56.4 (C), and leads in 5 of 7 scored categories. Snowflake-managed MCP server leads on security \u0026 auth.\n\n### Do ClickHouse MCP Server and Snowflake-managed MCP server need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call ClickHouse MCP Server and Snowflake-managed MCP server without installing anything?\n\nClickHouse MCP Server runs on your own machine, with no hosted endpoint listed. No hosted endpoint is listed for Snowflake-managed MCP server.\n\n### Are ClickHouse MCP Server and Snowflake-managed MCP server open source?\n\nClickHouse MCP Server is open source (Apache-2.0). No open-source release is listed for Snowflake-managed MCP server.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-snowflake-managed.json, and with the fewest tokens: https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-snowflake-managed.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"clickhouse-mcp-server\", \"b\": \"snowflake-managed\"}`. From a terminal: `anchor compare clickhouse-mcp-server snowflake-managed`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/clickhouse-mcp-server.json and https://www.anchorterminal.com/api/v1/tools/snowflake-managed.json\n\n## Other comparisons with ClickHouse MCP Server or Snowflake-managed MCP server\n\n- [ClickHouse MCP Server vs PlanetScale MCP Server](https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-planetscale-mcp.md)\n- [ClickHouse MCP Server vs Postgres MCP Pro](https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-mcp-pro.md)\n- [ClickHouse MCP Server vs PostgreSQL (archived MCP reference server)](https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-postgres-reference-server-archived.md)\n- [ClickHouse MCP Server vs Supabase API + MCP](https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-supabase-mcp.md)\n- [PlanetScale MCP Server vs Snowflake-managed MCP server](https://www.anchorterminal.com/compare/planetscale-mcp-vs-snowflake-managed.md)\n- [Postgres MCP Pro vs Snowflake-managed MCP server](https://www.anchorterminal.com/compare/postgres-mcp-pro-vs-snowflake-managed.md)\n- [PostgreSQL (archived MCP reference server) vs Snowflake-managed MCP server](https://www.anchorterminal.com/compare/postgres-reference-server-archived-vs-snowflake-managed.md)\n- [Snowflake-managed MCP server vs Supabase API + MCP](https://www.anchorterminal.com/compare/snowflake-managed-vs-supabase-mcp.md)\n- [ClickHouse MCP Server vs MongoDB MCP Server](https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-mongodb-mcp.md)\n- [ClickHouse MCP Server vs Redis MCP](https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-redis-mcp.md)\n- [MongoDB MCP Server vs Snowflake-managed MCP server](https://www.anchorterminal.com/compare/mongodb-mcp-vs-snowflake-managed.md)\n- [Redis MCP vs Snowflake-managed MCP server](https://www.anchorterminal.com/compare/redis-mcp-vs-snowflake-managed.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "ClickHouse MCP Server vs Snowflake-managed MCP server",
        "url": ""
      }
    ],
    "description": "ClickHouse scores 64.6 (B) to Snowflake-managed's 56.4 (C) for sql databases. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "ClickHouse MCP Server B 64.6",
      "Snowflake-managed MCP server C 56.4",
      "scores"
    ],
    "h1": "ClickHouse MCP Server vs Snowflake-managed MCP server",
    "image": "https://www.anchorterminal.com/assets/og/compare-clickhouse-mcp-server-vs-snowflake-managed.png",
    "path": "/compare/clickhouse-mcp-server-vs-snowflake-managed",
    "published": "2026-10-01",
    "section": "tools",
    "title": "ClickHouse vs Snowflake-managed for AI agents (2026) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-snowflake-managed"
  },
  "tokens": {
    "markdown": 2500,
    "slim": 730
  },
  "version": 1
}
