{"_id":"midplane","_rev":"2-dea40942435e21ea616f9ffe1ab7fba5","name":"midplane","dist-tags":{"latest":"0.20.0"},"versions":{"0.19.0":{"name":"midplane","version":"0.19.0","keywords":["mcp","modelcontextprotocol","postgres","sql","ai-agents","guardrails","audit"],"license":"MIT","_id":"midplane@0.19.0","maintainers":[{"name":"dustinlange","email":"dustin@midplane.ai"}],"homepage":"https://midplane.ai/docs","bugs":{"url":"https://github.com/midplaneai/midplane/issues"},"bin":{"midplane":"dist/cli.js"},"dist":{"shasum":"71c1e378f3b768c5a12d1b3f1511362c930fe5a2","tarball":"https://registry.npmjs.org/midplane/-/midplane-0.19.0.tgz","fileCount":5,"integrity":"sha512-2jtAg++0BdRRt6kEbhcOEVdrJizL7avkb/2rpgL/MjKxht/YtKdOTLTyXHA/PMPDCGIW35EugAIgl+aPFiLZMg==","signatures":[{"sig":"MEQCIB9+28pSbAiS6dLACWb/yrzXq6hXjd9kJn7aLip/PmIrAiBA/mlchPJdeuPOV7cwDyB0I0PjiMBjU5TfaFZvipXmFQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":328898},"main":"dist/cli.js","type":"module","engines":{"bun":">=1.3.0","node":">=22.16"},"gitHead":"927b48ad5735ce41876467e7d8eee4d7c07eec60","mcpName":"ai.midplane/midplane","scripts":{"build:npm":"bun scripts/build-npm.ts","qa:wizard":"bun scripts/qa/drive-init-wizard.ts","prepublishOnly":"bun scripts/build-npm.ts"},"_npmUser":{"name":"dustinlange","email":"dustin@midplane.ai"},"repository":{"url":"git+https://github.com/midplaneai/midplane.git","type":"git","directory":"engine/packages/mcp-server"},"_npmVersion":"12.0.2","description":"Safe-by-default SQL guardrails for AI agents. MCP server for Postgres over stdio + Streamable HTTP: parses every statement with a real SQL AST, enforces a per-table access policy, and audits before the query runs.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"pg":"^8.13.0","zod":"^4.0.0","pino":"^9.5.0","ulid":"^2.3.0","js-yaml":"^4.1.0","libpg-query":"^16.7.0","@clack/prompts":"^1.5.1","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"@types/pg":"^8.11.10","@types/js-yaml":"^4.0.9","@midplane/engine":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/midplane_0.19.0_1787133104275_0.3798660378398133","host":"s3://npm-registry-packages-npm-production"}},"0.20.0":{"name":"midplane","version":"0.20.0","description":"Safe-by-default SQL guardrails for AI agents. MCP server for Postgres over stdio + Streamable HTTP: parses every statement with a real SQL AST, enforces a per-table access policy, and audits before the query runs.","keywords":["mcp","modelcontextprotocol","postgres","sql","ai-agents","guardrails","audit"],"homepage":"https://midplane.ai/docs","repository":{"type":"git","url":"git+https://github.com/midplaneai/midplane.git","directory":"engine/packages/mcp-server"},"bugs":{"url":"https://github.com/midplaneai/midplane/issues"},"license":"MIT","type":"module","mcpName":"ai.midplane/midplane","main":"dist/cli.js","bin":{"midplane":"dist/cli.js"},"publishConfig":{"access":"public","provenance":true},"scripts":{"build:npm":"bun scripts/build-npm.ts","qa:wizard":"bun scripts/qa/drive-init-wizard.ts","prepublishOnly":"bun scripts/build-npm.ts"},"dependencies":{"@clack/prompts":"^1.5.1","@modelcontextprotocol/sdk":"^1.29.0","js-yaml":"^4.1.0","libpg-query":"^16.7.0","pg":"^8.13.0","pino":"^9.5.0","ulid":"^2.3.0","zod":"^4.0.0"},"devDependencies":{"@midplane/engine":"workspace:*","@types/js-yaml":"^4.0.9","@types/pg":"^8.11.10"},"engines":{"node":">=22.16","bun":">=1.3.0"},"gitHead":"39f2e10346319b5563ed8ee9ecc945af89089db9","_id":"midplane@0.20.0","_nodeVersion":"24.19.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-U/+XS47NtC3tA3vqfK0f9hz8i96bjun2DGK5ZJc4jDAbkyq8TAWU4s4HLue6ZjNNvfH/RyyDWAtPcfAaO8nsKA==","shasum":"31935ef85e2be4b9c304751bfd706d5465077a2e","tarball":"https://registry.npmjs.org/midplane/-/midplane-0.20.0.tgz","fileCount":5,"unpackedSize":336672,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/midplane@0.20.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCKLjnOJgnLLdEGtw5eCq4uwVjrQB1f7hpGITDPvb1FWQIgfHoPE+UJZmEiSlbrGOJ57LSMRbBJHgg23VYRDb/6NxE="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:19f6a1e9-bcd8-4385-9221-f92ed2d8bc68"}},"directories":{},"maintainers":[{"name":"dustinlange","email":"dustin@midplane.ai"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/midplane_0.20.0_1787663235071_0.6049016537419372"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-19T09:51:44.071Z","modified":"2026-08-25T13:07:15.544Z","0.19.0":"2026-08-19T09:51:44.411Z","0.20.0":"2026-08-25T13:07:15.216Z"},"bugs":{"url":"https://github.com/midplaneai/midplane/issues"},"license":"MIT","homepage":"https://midplane.ai/docs","keywords":["mcp","modelcontextprotocol","postgres","sql","ai-agents","guardrails","audit"],"repository":{"type":"git","url":"git+https://github.com/midplaneai/midplane.git","directory":"engine/packages/mcp-server"},"description":"Safe-by-default SQL guardrails for AI agents. MCP server for Postgres over stdio + Streamable HTTP: parses every statement with a real SQL AST, enforces a per-table access policy, and audits before the query runs.","maintainers":[{"name":"dustinlange","email":"dustin@midplane.ai"}],"readme":"# midplane\n\n**Safe-by-default SQL guardrails for AI agents.** An MCP server that sits between\nan AI agent (Claude, Cursor, any MCP client) and your Postgres database. It parses\nevery statement with a real SQL AST — not a regex blocklist — enforces a\ndeclarative per-table access policy, blocks destructive DML/DDL, and writes an\naudit row **before** the query executes.\n\n[![npm](https://img.shields.io/npm/v/midplane.svg)](https://www.npmjs.com/package/midplane)\n[![License: MIT](https://img.shields.io/badge/license-MIT-blue.svg)](./LICENSE)\n\n📖 Full documentation: **[midplane.ai/docs](https://midplane.ai/docs)**\n\n## Point an agent at it\n\nNo install — `npx` fetches it on first run. Add this to your MCP client's config\n(Claude Code, Claude Desktop, Cursor — they all take this shape):\n\n```json\n{\n  \"mcpServers\": {\n    \"midplane\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"midplane\", \"server\", \"--stdio\"],\n      \"env\": { \"DATABASE_URL\": \"postgres://user:pass@host:5432/db\" }\n    }\n  }\n}\n```\n\nKeep the connection string in that `env` block rather than on a command line,\nwhere it would leak to `ps aux` and your shell history. The block still lands in\na plaintext config file, so give Midplane its own least-privilege Postgres role:\nit governs which SQL runs, not what the role underneath it can reach.\n\nOut of the box: reads are allowed, writes and DDL are denied, and every query is\naudited. Nothing to configure to be safe — configure only to open things up.\n\n## Write a policy\n\n```bash\nnpx -y midplane init\n```\n\nConnects read-only, introspects your schema, suggests a tenant column, and writes\na validated `midplane.policy.yaml`. Point the server at it with\n`MIDPLANE_POLICY_FILE`. The non-interactive equivalent for CI is\n`midplane policy init`.\n\n## What it blocks\n\n- **Destructive writes by default** — a `DELETE` targeting a table is denied even\n  when it carries a `WHERE`, until you opt that table into `read_write`.\n- **Whole-table wipes and schema destruction** — unqualified `DELETE` / `UPDATE`\n  (no `WHERE`), and every `DROP` / `TRUNCATE` / `ALTER`, regardless of the\n  table's access level.\n- **Stacked-statement injection** — two statements separated by a semicolon in a\n  single call are refused at parse time. This is the canonical injection vector\n  and is denied unconditionally.\n- **Writes hidden inside a read** — a CTE that performs a write and then selects\n  from it is denied at the inner write, not the outer `SELECT`. The same\n  recursive walk covers subqueries, UNION arms, and JOINs.\n\nWorked examples of each, with the exact SQL and the denial message, are in the\n[policy reference](https://midplane.ai/docs) and the repository README.\n\n## CLI\n\n```\nmidplane [server]    Run the MCP server   (--stdio | --http)\nmidplane init        Interactive setup: introspect the DB, write a policy\nmidplane query ...   Send one query through the server as an agent would\nmidplane doctor      Preflight + smoke checks (config, DB, audit, canary)\nmidplane audit ...   Read the local audit log (tail | since | denies | show | stats)\nmidplane policy ...  Author/validate/lint/dry-run a policy file\n```\n\nThe audit log is a local SQLite database at `~/.midplane/audit.db` (override with\n`DB_PATH`). `midplane audit denies` answers the question operators actually ask:\nwhat got blocked, and why.\n\n## Transports\n\n- **stdio** (`--stdio`) — how MCP clients spawn a local server.\n- **Streamable HTTP** (`--http`, the default) — serves `/mcp` on `PORT` (8080).\n\n## Other ways to run it\n\n- **Docker** — `midplane/midplane`, a self-contained image with no Node or\n  `node_modules` in it.\n- **Managed cloud** — [app.midplane.ai](https://app.midplane.ai), with a\n  dashboard, policy editor, and hosted audit log.\n- **Self-host the full app** — `./bin/self-host up` from the\n  [repo](https://github.com/midplaneai/midplane).\n\n## Requirements\n\nNode 22.16+ or 24+ (the audit log uses the `node:sqlite` builtin), or Bun 1.3+.\n`npx` ships with Node, so there is nothing else to install — no native modules,\nno compiler. Below 22.16 the bin refuses to start and tells you why, rather than\nfailing partway through with a stack trace from whichever dependency happened to\nreach a newer builtin first.\n\n## Telemetry\n\nAnonymous, on by default, documented in full in\n[TELEMETRY.md](https://github.com/midplaneai/midplane/blob/main/engine/TELEMETRY.md).\nNo SQL, no table or column names, no identifiers. Disable with\n`MIDPLANE_TELEMETRY=0` or `DO_NOT_TRACK=1`.\n\n## License\n\nMIT — see [LICENSE](./LICENSE). Source at\n[github.com/midplaneai/midplane](https://github.com/midplaneai/midplane).\nSecurity issues: see\n[SECURITY.md](https://github.com/midplaneai/midplane/blob/main/engine/SECURITY.md) —\nplease don't open a public issue.\n","readmeFilename":"README.md"}