{"_id":"@dhipskind253/mssql-mcp","name":"@dhipskind253/mssql-mcp","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@dhipskind253/mssql-mcp","version":"0.1.0","description":"Read-only MSSQL MCP server. Connection details are loaded from AWS Secrets Manager — never from disk or env.","keywords":["mcp","model-context-protocol","mssql","sql-server","aws","aws-secrets-manager","claude","read-only"],"homepage":"https://github.com/dhipskind253/mssql-mcp#readme","bugs":{"url":"https://github.com/dhipskind253/mssql-mcp/issues"},"repository":{"type":"git","url":"git+https://github.com/dhipskind253/mssql-mcp.git"},"license":"MIT","author":{"name":"dhipskind253"},"type":"module","bin":{"mssql-mcp":"dist/index.js"},"scripts":{"build":"tsc && chmod +x dist/index.js","prepublishOnly":"npm run build"},"engines":{"node":">=18"},"dependencies":{"@aws-sdk/client-secrets-manager":"^3.620.0","@modelcontextprotocol/sdk":"^1.0.4","mssql":"^11.0.1","zod":"^3.23.8"},"devDependencies":{"@types/mssql":"^9.1.5","@types/node":"^20.14.0","typescript":"^5.5.4"},"gitHead":"f0033afe2c8c7ae7c5480804c76db18ec019b54c","_id":"@dhipskind253/mssql-mcp@0.1.0","_nodeVersion":"18.12.1","_npmVersion":"8.19.2","dist":{"integrity":"sha512-udYEC+eIaBcWG6EsVRR8mIJKQwr5iDpvhyT4li7+wdI3bjI5fgqvoLd7mRn+/8Kt63WsXVIC4FPyKJEK2d0a6Q==","shasum":"75923df05a4008f1008cb6b1f5684cca08ccd136","tarball":"https://registry.npmjs.org/@dhipskind253/mssql-mcp/-/mssql-mcp-0.1.0.tgz","fileCount":6,"unpackedSize":29466,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQD6WVr/V2Z09ghxApWchacw/3Hn/cuuJKaUUPtM44gM3wIhAKXZ8eHEDZ4LCjEdBYeFb/D7yCSycjR0Or0D60Y0wDOa"}]},"_npmUser":{"name":"dhipskind253","email":"dhipskind253@gmail.com"},"directories":{},"maintainers":[{"name":"dhipskind253","email":"dhipskind253@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mssql-mcp_0.1.0_1778210780075_0.3797089906311797"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-08T03:26:19.919Z","0.1.0":"2026-05-08T03:26:20.206Z","modified":"2026-05-08T03:26:20.462Z"},"maintainers":[{"name":"dhipskind253","email":"dhipskind253@gmail.com"}],"description":"Read-only MSSQL MCP server. Connection details are loaded from AWS Secrets Manager — never from disk or env.","homepage":"https://github.com/dhipskind253/mssql-mcp#readme","keywords":["mcp","model-context-protocol","mssql","sql-server","aws","aws-secrets-manager","claude","read-only"],"repository":{"type":"git","url":"git+https://github.com/dhipskind253/mssql-mcp.git"},"author":{"name":"dhipskind253"},"bugs":{"url":"https://github.com/dhipskind253/mssql-mcp/issues"},"license":"MIT","readme":"# mssql-mcp\r\n\r\nA read-only Microsoft SQL Server MCP server using connection\r\ndetails from **AWS Secrets Manager** at tool-call time — nothing\r\nis read from disk or environment variables except the secret reference\r\nitself.\r\n\r\nCross-platform: it's a pure-JavaScript MCP server (no native or ODBC\r\ndependencies), so it runs identically on macOS, Linux, and Windows via\r\n`npx`.\r\n\r\n## Configure in `.claude.json`\r\n\r\n```json\r\n{\r\n  \"mcpServers\": {\r\n    \"my-db\": {\r\n      \"command\": \"npx\",\r\n      \"args\": [\"-y\", \"mssql-mcp\"],\r\n      \"env\": {\r\n        \"AWS_ACCOUNT_ID\": \"123456789012\",\r\n        \"SECRET_NAME\": \"my-aws-secret\",\r\n        \"AWS_REGION\": \"us-east-1\",\r\n        \"TRUST_SERVER_CERTIFICATE\": \"false\"\r\n      }\r\n    }\r\n  }\r\n}\r\n```\r\n\r\n| Env var                     | Required | Default | Description                                                                         |\r\n| --------------------------- | -------- | ------- | ----------------------------------------------------------------------------------- |\r\n| `AWS_ACCOUNT_ID`            | yes      | —       | The AWS account where the secret lives. Combined with name + region into a full ARN. |\r\n| `SECRET_NAME`               | yes      | —       | The Secrets Manager secret name (no ARN suffix needed).                             |\r\n| `AWS_REGION`                | yes      | —       | AWS region the secret is in (e.g. `us-east-1`). Also picked up by the AWS SDK as its default region. |\r\n| `TRUST_SERVER_CERTIFICATE`  | no       | `false` | Skip TLS cert validation to the SQL Server. Accepts `true`/`false`/`1`/`0`/`yes`/`no`. Set `true` only if you understand why. |\r\n\r\nStandard AWS SDK env vars (`AWS_PROFILE`, `AWS_ACCESS_KEY_ID`, etc.) are\r\nhonored via the default credential provider chain. Most users just need\r\n`aws sso login` to be current.\r\n\r\n## Required secret JSON\r\n\r\nThe secret value must be a JSON document with at least these fields:\r\n\r\n```json\r\n{\r\n  \"host\": \"myserver.database.windows.net\",\r\n  \"port\": 1433,\r\n  \"database\": \"mydb\",\r\n  \"username\": \"ro_user\",\r\n  \"password\": \"...\"\r\n}\r\n```\r\n\r\n`database` may also be supplied as **`dbname`** — the field name AWS uses\r\nin its built-in RDS-credentials secret template. If both are present,\r\n`database` wins.\r\n\r\nOptional fields (with defaults shown):\r\n\r\n| Field     | Default | Notes              |\r\n| --------- | ------- | ------------------ |\r\n| `port`    | `1433`  |                    |\r\n| `encrypt` | `true`  | TLS to the server. |\r\n\r\n> TLS cert trust is **not** read from the secret — set\r\n> `TRUST_SERVER_CERTIFICATE` in the MCP server's `env` block instead.\r\n> Any `trustServerCertificate` field in the secret JSON is ignored.\r\n\r\n## Read-only by design\r\n\r\nThis server cannot insert, update, or delete data. Two layers enforce that:\r\n\r\n1. The `run_select` tool lexically rejects anything that isn't a single\r\n   `SELECT` or `WITH` (CTE) statement — including `INSERT`, `UPDATE`,\r\n   `DELETE`, `EXEC`, `MERGE`, `DROP`, `ALTER`, `SELECT INTO`, etc.\r\n2. No other tool emits write SQL. `get_procedure_definition` returns\r\n   procedure source — it does not run procedures.\r\n\r\n> **Courtesy note:** treat the lexical check as UX, not a security\r\n> boundary. As a courtesy to your future self, configure the credentials\r\n> you put in Secrets Manager to be a **read-only database login** — one\r\n> with `SELECT` and `VIEW DEFINITION` only. That way an accidental write\r\n> (or a future bug here) is rejected by SQL Server itself.\r\n\r\n## Refreshing AWS credentials without restarting\r\n\r\nBecause the server uses the default AWS credential chain, an expired SSO\r\nsession can be recovered without restarting Claude or the MCP server:\r\n\r\n1. Run `aws sso login` in any terminal.\r\n2. Ask Claude to call the **`refresh_secret`** tool.\r\n3. Continue working.\r\n\r\nIf a tool call fails because of AWS auth, the error message will tell\r\nyou exactly that and prompt the same flow. Errors are tagged with stable\r\nprefixes:\r\n\r\n| Prefix                    | Meaning                                            |\r\n| ------------------------- | -------------------------------------------------- |\r\n| `[AWS_AUTH_REQUIRED]`     | SSO session expired or no credentials available.   |\r\n| `[AWS_ACCESS_DENIED]`     | Principal lacks `secretsmanager:GetSecretValue`.   |\r\n| `[AWS_SECRET_NOT_FOUND]`  | Secret name / account / region mismatch.           |\r\n| `[AWS_SECRET_INVALID]`    | Secret JSON is missing fields or malformed.        |\r\n| `[DB_CONNECT_FAILED]`     | Could not reach the SQL Server instance.           |\r\n| `[DB_QUERY_FAILED]`       | SQL Server returned an error executing the query.  |\r\n| `[INVALID_QUERY]`         | The submitted query violated the read-only rules.  |\r\n\r\n## Tools\r\n\r\n| Tool                       | Purpose                                                  |\r\n| -------------------------- | -------------------------------------------------------- |\r\n| `list_schemas`             | User schemas in the database.                            |\r\n| `list_tables`              | Tables, optionally filtered by schema.                   |\r\n| `describe_table`           | Columns, types, nullability, identity, PK, defaults.     |\r\n| `list_indexes`             | Indexes on a table (one row per index/column).           |\r\n| `list_foreign_keys`        | Outgoing FKs from a table.                               |\r\n| `list_views`               | Views, optionally filtered by schema.                    |\r\n| `get_view_definition`      | View source SQL.                                         |\r\n| `list_procedures`          | Stored procedures, optionally filtered by schema.        |\r\n| `get_procedure_definition` | Procedure source SQL (does not execute).                 |\r\n| `sample_rows`              | `SELECT TOP n * FROM schema.table` (default 10, max 100). |\r\n| `run_select`               | Single SELECT/CTE, capped at `max_rows` (default 100, hard max 1000). |\r\n| `refresh_secret`           | Re-fetch the secret and reconnect.                       |\r\n\r\n## Local development\r\n\r\n```bash\r\nnpm install\r\nnpm run build\r\n# point your .claude.json command at the local build:\r\n#   \"command\": \"node\",\r\n#   \"args\": [\"/absolute/path/to/mssql-mcp/dist/index.js\"]\r\n```\r\n","readmeFilename":"README.md","_rev":"1-593fbc6040e4588497be7403b136b9ef"}