One governed MCP surface
Expose MySQL without handing the model an unrestricted database connection.
MySQL · MCP
Connect AI clients to MySQL through hs-sql-agent's MCP surface, typed SQL compiler, access policy, Safe DML workflow, and audit boundary.
Expose MySQL without handing the model an unrestricted database connection.
Keep MySQL-specific SQL semantics inside an explicit source/target capability boundary.
Apply database scope, table policy, tool restrictions, rate limits, Safe DML, and audit before commit.
hs-sql-agent does not treat a model-generated MySQL statement as trusted simply because the provider could execute it. SQL first enters the typed validation and capability pipeline.
Provider support means the runtime can connect, inspect metadata, compile supported statements, and execute them under policy. It does not mean every vendor-specific syntax form is accepted automatically.
MCP clients can discover schemas, tables, and columns through the built-in metadata tools before constructing MySQL SQL. This reduces blind schema guessing and keeps discovery inside the same authenticated database scope.
The MySQL path follows the same rule as every other provider: unsupported syntax or cross-provider semantics are rejected at the appropriate validation/capability boundary rather than silently rewritten into a query with different behavior.
MySQL syntax is validated against MySQL rules rather than accepted as interchangeable SQL. Version-sensitive features can be gated by the declared server version, and provider-specific coercion semantics are not silently exported to another database.
Current compiler contracts require MySQL 8.0.1+ for recursive CTE support. MySQL DATE(expr) semantics also remain fail-closed for cross-dialect lowering when the operand meaning cannot be proven equivalent.
| Compiler contract example | Behavior |
|---|---|
WITH RECURSIVE ... | Requires MySQL 8.0.1+ when server-version capability checks are enabled. |
SELECT DATE(created_at) ... → PostgreSQL | Rejected when MySQL DATE(expr) coercion semantics cannot be proven equivalent on the target. |
These examples are a search-oriented summary of the compiler boundary, not a complete SQL compatibility matrix. Unsupported or unproven semantics continue to fail closed.
The MCP tool surface is shared, but each database keeps its own source grammar, capability checks, and provider-specific rendering rules.
Direct database credentials make the model or MCP client responsible for everything the database account can do. hs-sql-agent keeps the real MySQL connection server-side and evaluates SQL against the compiler, MCP-key scope, table policy, tool restrictions, and runtime limits before execution.
That keeps raw SQL available as an expressive agent interface without turning generated SQL into unrestricted database authority.