Skip to content
hs-sql-agent

Firebird · MCP

Firebird MCP Server for AI agents.

Connect AI clients to Firebird through hs-sql-agent's MCP surface, typed SQL compiler, access policy, Safe DML workflow, and audit boundary.

01

One governed MCP surface

Expose Firebird without handing the model an unrestricted database connection.

02

Dialect-aware compiler

Keep Firebird-specific SQL semantics inside an explicit source/target capability boundary.

03

Policy before execution

Apply database scope, table policy, tool restrictions, rate limits, Safe DML, and audit before commit.

Firebird stays behind a compiler boundary

hs-sql-agent does not treat a model-generated Firebird statement as trusted simply because the provider could execute it. SQL first enters the typed validation and capability pipeline.

Provider support means the runtime can connect, inspect metadata, compile supported statements, and execute them under policy. It does not mean every vendor-specific syntax form is accepted automatically.

Use metadata before guessing schema

MCP clients can discover schemas, tables, and columns through the built-in metadata tools before constructing Firebird SQL. This reduces blind schema guessing and keeps discovery inside the same authenticated database scope.

  • get_schemas
  • get_tables
  • get_columns
  • execute_query_sql
  • execute_dml_sql

Fail closed when semantics are not proven

The Firebird path follows the same rule as every other provider: unsupported syntax or cross-provider semantics are rejected at the appropriate validation/capability boundary rather than silently rewritten into a query with different behavior.

Firebird is a first-class dialect boundary

Firebird does not share a permissive generic-SQL fallback with the other providers. Its syntax and capability checks remain explicit so unsupported forms are rejected before provider execution.

The compiler contract requires Firebird 2.1+ for recursive CTE support and rejects LIMIT as non-Firebird source syntax. Provider-specific rules therefore remain observable instead of disappearing behind a common MCP tool name.

Compiler contract exampleBehavior
WITH RECURSIVE ... FROM RDB$DATABASERequires Firebird 2.1+ when the declared server version is evaluated.
SELECT id FROM users LIMIT 5Rejected as non-Firebird source syntax.

These examples are a search-oriented summary of the compiler boundary, not a complete SQL compatibility matrix. Unsupported or unproven semantics continue to fail closed.

Compare database MCP targets

The MCP tool surface is shared, but each database keeps its own source grammar, capability checks, and provider-specific rendering rules.

Why use a Firebird MCP server instead of direct database access?

Direct database credentials make the model or MCP client responsible for everything the database account can do. hs-sql-agent keeps the real Firebird connection server-side and evaluates SQL against the compiler, MCP-key scope, table policy, tool restrictions, and runtime limits before execution.

That keeps raw SQL available as an expressive agent interface without turning generated SQL into unrestricted database authority.

  • raw SQL remains available for supported statements
  • database credentials stay behind the server boundary
  • unsupported semantics fail closed before execution
  • DML can require explicit human approval