ClickHouse MCP Server
An MCP server for ClickHouse.
The server implements MCP 2026-07-28 and supports legacy initialize handshakes from
2024-11-05 through 2025-11-25. Modern clients use sessionless requests and
server/discover. Existing clients can continue to negotiate the legacy protocol.
[!NOTE]
HTTP requests without MCP-Protocol-Version are routed through legacy handling so
clients from before 2025-06-18 can continue to connect. MCP 2026-07-28 permits
this behavior on servers that support those clients. Modern clients should send the
header on every POST request.
Features
ClickHouse Tools
ClickHouse tool responses are JSON-encoded strings. Integers outside
[-9007199254740991, 9007199254740991] are returned as decimal strings to preserve exact
values in JavaScript clients. This applies to query rows and integer table metadata. Safe-range
integers and booleans keep their JSON types.
-
run_query
- Execute SQL queries on your ClickHouse cluster.
- Input:
query (string): The SQL query to execute.
- Queries run in read-only mode by default (
CLICKHOUSE_ALLOW_WRITE_ACCESS=false), but writes can be enabled explicitly if needed.
-
list_databases
- List all databases on your ClickHouse cluster.
-
list_tables
- List tables in a database with pagination.
- Required input:
database (string).
- Optional inputs:
like / not_like (string): Apply LIKE or NOT LIKE filters to table names.
page_token (string): Single-use token returned by a previous call. It is retained for up to one hour.
page_size (int, default 50): Number of tables returned per page; must be greater than 0.
include_detailed_columns (bool, default true): When false, omits column metadata for lighter responses while keeping the full create_table_query.
chDB Tools
run_chdb_select_query
- Execute SQL queries using chDB's embedded ClickHouse engine.
- Input:
query (string): The SQL query to execute.
- Integers outside
[-9007199254740991, 9007199254740991] are returned as decimal strings.
- Query data directly from various sources (files, URLs, databases) without ETL processes.
- Requires the optional
chdb extra: pip install 'mcp-clickhouse[chdb]'
Health Check Endpoint
When running with HTTP or SSE transport, a health check endpoint is available at /health. This endpoint:
- Returns
200 OK (body: OK) if the server is healthy and can connect to ClickHouse
- Returns
503 Service Unavailable with a generic error message if the server cannot connect to ClickHouse
- Returns
503 if a ClickHouse probe does not finish within two seconds. Concurrent requests share one in-flight probe
GET and HEAD requests to the endpoint are intentionally unauthenticated and exempt from Host and Origin validation so orchestrator probes (e.g. Kubernetes liveness/readiness, load balancers) can use runtime-assigned pod or target IPs without extra configuration. /health is reserved and cannot be used as the MCP transport path. The response body is deliberately minimal to avoid leaking backend version strings or error details; debug failures via the server logs.
Example:
curl http://localhost:8000/health
# Response: OK
Security
Authentication for HTTP/SSE Transports
When using HTTP or SSE transport, authentication is required by default. The stdio transport (default) does not require authentication as it only communicates via standard input/output.
Three authentication modes are supported. Pick one:
| Mode | When to use | Env var |
|---|
| Static bearer token | Simple deployments, internal services | CLICKHOUSE_MCP_AUTH_TOKEN |
| OAuth / OIDC (via FastMCP) | Azure Entra, Google, GitHub, WorkOS, etc. | FASTMCP_SERVER_AUTH=<provider-class-path> (+ provider-specific FASTMCP_SERVER_AUTH_* vars) |
| Disabled | Local development only | CLICKHOUSE_MCP_AUTH_DISABLED=true |
Startup fails if none of these are configured for HTTP/SSE transports.
Setting Up Authentication
-
Generate a secure token (can be any random string):
# Using uuidgen (macOS/Linux)
uuidgen
# Using openssl
openssl rand -hex 32
-
Configure the server with the token:
export CLICKHOUSE_MCP_AUTH_TOKEN="your-generated-token"
-
Configure your MCP client to include the token in requests:
For Claude Desktop with HTTP/SSE transport:
{
"mcpServers": {
"mcp-clickhouse": {
"url": "http://127.0.0.1:8000",
"headers": {
"Authorization": "Bearer your-generated-token"
}
}
}
}
Note: the /health endpoint is intentionally unauthenticated (see Health Check Endpoint above). To verify that bearer-token auth is actually rejecting unauthenticated requests, hit the MCP endpoint itself e.g. with the MCP Inspector, or by POSTing a JSON-RPC request to /mcp with and without the Authorization header and confirming the unauthenticated call returns 401.
OAuth / OIDC via FastMCP
For production deployments with identity providers (Azure Entra, Google, GitHub, WorkOS, etc.), delegate authentication to FastMCP's built-in auth providers instead of using a static token. Set FASTMCP_SERVER_AUTH to the full class path of a FastMCP auth provider, along with the provider-specific FASTMCP_SERVER_AUTH_* variables, and leave CLICKHOUSE_MCP_AUTH_TOKEN unset.
Example (Azure Entra):
export FASTMCP_SERVER_AUTH=fastmcp.server.auth.providers.azure.AzureProvider
export FASTMCP_SERVER_AUTH_AZURE_TENANT_ID="<tenant-id>"
export FASTMCP_SERVER_AUTH_AZURE_CLIENT_ID="<client-id>"
export FASTMCP_SERVER_AUTH_AZURE_CLIENT_SECRET="<client-secret>"
export FASTMCP_SERVER_AUTH_AZURE_BASE_URL="https://mcp.example.com"
export FASTMCP_SERVER_AUTH_AZURE_REQUIRED_SCOPES="read access_as_user"
mcp-clickhouse retains these FastMCP 2.14.7 environment prefixes for the FastMCP 4.0.0
built-in providers:
| Provider class path | Provider variable prefix |
|---|
fastmcp.server.auth.providers.auth0.Auth0Provider | FASTMCP_SERVER_AUTH_AUTH0_ |
fastmcp.server.auth.providers.aws.AWSCognitoProvider | FASTMCP_SERVER_AUTH_AWS_COGNITO_ |
fastmcp.server.auth.providers.azure.AzureProvider | FASTMCP_SERVER_AUTH_AZURE_ |
fastmcp.server.auth.providers.descope.DescopeProvider | FASTMCP_SERVER_AUTH_DESCOPEPROVIDER_ |
fastmcp.server.auth.providers.discord.DiscordProvider | FASTMCP_SERVER_AUTH_DISCORD_ |
fastmcp.server.auth.providers.github.GitHubProvider | FASTMCP_SERVER_AUTH_GITHUB_ |
fastmcp.server.auth.providers.google.GoogleProvider | FASTMCP_SERVER_AUTH_GOOGLE_ |
Append the uppercase provider field name to the prefix. See the
FastMCP docs for each provider's configuration
requirements.
Auth values set directly in the process environment take precedence case-insensitively.
The default .env load starts at the installed mcp_clickhouse package directory,
resolves symlinks first, and walks upward to the filesystem root. It loads the first
.env it finds and loads nothing if there is none. It never reads the working
directory, regardless of how the server is launched. A source checkout normally finds
the repository root .env. That file may also provide FASTMCP_SERVER_AUTH and its
provider fields. Its values take precedence over the explicit or compatibility auth
file.
For FastMCP 2 compatibility, mcp-clickhouse reads missing provider fields from .env
in the working directory, but that compatibility fallback cannot select
FASTMCP_SERVER_AUTH. A process-set FASTMCP_ENV_FILE replaces that compatibility
fallback and may provide both the selector and provider fields. Set it before startup.
The mcp-clickhouse compatibility loader reads only FASTMCP_SERVER_AUTH and
FASTMCP_SERVER_AUTH_* from that file, so it cannot inject CLICKHOUSE_* settings.
FastMCP 4 may use the same file for its own broader settings. A custom provider receives
no environment-derived constructor arguments and must support no-argument construction.
Treat both discovered and working-directory .env files as trusted authentication
configuration. Anyone who can create or write a .env in any directory from the package
directory up to the filesystem root can control which file is discovered, select the
provider, and set its fields. Anyone who can write the working-directory file controls every provider
field absent from the process and discovered configuration, including signing keys,
issuers and endpoints, and client secrets. A process-set FASTMCP_ENV_FILE that points
to an operator-owned file disables the working-directory fallback.
FastMCP 4 changed the default OAuth proxy client store. Deployments that relied on
FastMCP 2's default OAuth proxy storage must have clients register and authorize again.
Compatible custom storage, static bearer tokens, and JWT verification are unaffected.
Development Mode (Disabling Authentication)
For local development and testing only, you can disable authentication by setting:
export CLICKHOUSE_MCP_AUTH_DISABLED=true
export CLICKHOUSE_MCP_ALLOWED_HOSTS=127.0.0.1:8000,localhost:8000
WARNING: Only use this for local development. Do not disable authentication when the server is exposed to any network.
Custom Middleware
You can add custom middleware to the MCP server without modifying the source code. FastMCP provides a middleware system that allows you to intercept and process MCP protocol messages (tool calls, resource reads, prompts, etc.).
How to Use
- Create a Python module with middleware classes extending
Middleware and a setup_middleware(mcp) function:
# my_middleware.py
import logging
from fastmcp.server.middleware import Middleware, MiddlewareContext, CallNext
logger = logging.getLogger("my-middleware")
class LoggingMiddleware(Middleware):
"""Log all tool calls."""
async def on_call_tool(self, context: MiddlewareContext, call_next: CallNext):
tool_name = context.message.name if hasattr(context.message, 'name') else 'unknown'
logger.info(f"Calling tool: {tool_name}")
result = await call_next(context)
logger.info(f"Tool {tool_name} completed")
return result
def setup_middleware(mcp):
"""Register middleware with the MCP server."""
mcp.add_middleware(LoggingMiddleware())
- Set the
MCP_MIDDLEWARE_MODULE environment variable to the module name (without .py extension):
{
"mcpServers": {
"mcp-clickhouse": {
"command": "uv",
"args": ["run", "--with", "mcp-clickhouse", "--python", "3.12", "mcp-clickhouse"],
"env": {
"CLICKHOUSE_HOST": "<clickhouse-host>",
"CLICKHOUSE_USER": "<clickhouse-user>",
"CLICKHOUSE_PASSWORD": "<clickhouse-password>",
"MCP_MIDDLEWARE_MODULE": "my_middleware"
}
}
}
}
- Ensure your middleware module is in Python's import path (e.g., in the same directory where the MCP server runs, or installed as a package).
Example Middleware
An example middleware module is provided in example_middleware.py showing common patterns:
- Logging all MCP requests
- Logging tool calls specifically
- Measuring request processing time
To use the example:
"env": {
"MCP_MIDDLEWARE_MODULE": "example_middleware"
}
Middleware Capabilities
The Middleware base class provides hooks for different MCP operations:
on_message(context, call_next) - Called for all messages
on_request(context, call_next) - Called for all requests
on_notification(context, call_next) - Called for all notifications
on_call_tool(context, call_next) - Called when a tool is executed
on_read_resource(context, call_next) - Called when a resource is read
on_get_prompt(context, call_next) - Called when a prompt is retrieved
on_list_tools(context, call_next) - Called when listing tools
on_list_resources(context, call_next) - Called when listing resources
on_list_resource_templates(context, call_next) - Called when listing resource templates
on_list_prompts(context, call_next) - Called when listing prompts
Each hook receives a MiddlewareContext object containing the message and metadata, and a call_next function to continue the pipeline.
Dynamic Client Configuration via Context State
Middleware can override ClickHouse client configuration on a per-request basis using the CLIENT_CONFIG_OVERRIDES_KEY context state key. The server merges these overrides with the base configuration from environment variables.
from fastmcp.server.dependencies import get_context
from fastmcp.server.middleware import CallNext, Middleware, MiddlewareContext
from mcp_clickhouse.mcp_server import CLIENT_CONFIG_OVERRIDES_KEY
class ClientConfigMiddleware(Middleware):
async def on_call_tool(self, context: MiddlewareContext, call_next: CallNext):
ctx = get_context()
await ctx.set_state(
CLIENT_CONFIG_OVERRIDES_KEY,
{
"connect_timeout": 60,
"send_receive_timeout": 120,
},
serializable=False,
)
return await call_next(context)
This enables advanced use cases like dynamic timeout adjustments, tenant-specific routing, or per-user connection settings.
The state value must be a dictionary. Nested settings and generic_args values must be
mappings and are merged with the base configuration. Invalid values fail the tool call before
a ClickHouse client is created. CLICKHOUSE_ROLE remains active unless the override explicitly
supplies settings.role. Top-level role and ch_role keys, plus the same keys under
generic_args, are rejected.
Treat these overrides as trusted middleware input. Middleware must authenticate and authorize
request-derived values before setting them. Use serializable=False so FastMCP keeps the
value in request-local state. The default serializable=True stores session state and is
rejected by the server. The server snapshots the value before dispatching blocking database
work. Do not store tenant data in session-scoped Context state. A rejected session-scoped
override remains attached to a legacy MCP session and causes later tool calls in that session
to fail until the client reconnects. A per-request ClickHouse role is connection configuration,
not a tenant authorization boundary. Enforce tenant isolation with ClickHouse users, roles,
and grants.
Development
-
In test-services directory run docker compose up -d to start the ClickHouse cluster.
-
Add the following variables to a .env file in the root of the repository.
Note: The use of the default user in this context is intended solely for local development purposes.
CLICKHOUSE_HOST=localhost
CLICKHOUSE_PORT=8123
CLICKHOUSE_USER=default
CLICKHOUSE_PASSWORD=clickhouse
-
Run uv sync to install the dependencies. To install uv follow the instructions here. Then do source .venv/bin/activate.
-
For easy testing with the MCP Inspector, run uv run fastmcp dev inspector mcp_clickhouse/mcp_server.py:mcp to start the MCP server.
-
To test with HTTP transport and the health check endpoint:
# For development, disable authentication
CLICKHOUSE_MCP_SERVER_TRANSPORT=http CLICKHOUSE_MCP_AUTH_DISABLED=true CLICKHOUSE_MCP_ALLOWED_HOSTS=127.0.0.1:8000,localhost:8000 python -m mcp_clickhouse.main
# Or with authentication (generate a token first)
CLICKHOUSE_MCP_SERVER_TRANSPORT=http CLICKHOUSE_MCP_AUTH_TOKEN="your-token" python -m mcp_clickhouse.main
# Then in another terminal:
curl http://localhost:8000/health
Environment Variables
Configuration is split into independent groups. Mixing them up is a common cause of hard-to-debug connection failures:
| Group | Variables | Controls |
|---|
| ClickHouse database connection | CLICKHOUSE_HOST, CLICKHOUSE_PORT, CLICKHOUSE_SECURE, CLICKHOUSE_VERIFY, … | How this MCP server connects to your ClickHouse cluster over the HTTP interface |
| MCP server / transport | CLICKHOUSE_MCP_*, FASTMCP_SERVER_AUTH, FASTMCP_SERVER_AUTH_*, FASTMCP_ENV_FILE | MCP transport, authentication, and query-tool execution limits |
| Middleware / chDB | MCP_MIDDLEWARE_MODULE, CHDB_* | Optional extensions |
[!IMPORTANT]
Variables such as CLICKHOUSE_SECURE, CLICKHOUSE_VERIFY, and CLICKHOUSE_PORT apply to the ClickHouse database connection only. They do not configure TLS, ports, or auth for the MCP protocol endpoint.
Example: if the MCP server runs in Kubernetes behind an ingress that terminates TLS, that is an MCP transport concern. Keep CLICKHOUSE_SECURE aligned with how the pod reaches ClickHouse itself (HTTPS → true, plain HTTP → false). Setting CLICKHOUSE_SECURE=false because the MCP server is behind an ingress will make the server dial ClickHouse over HTTP—often against an HTTPS-only port—and produce opaque HTTP/TLS errors in the server logs.
ClickHouse database connection
These variables configure the clickhouse-connect HTTP client and the behavior of ClickHouse-backed tools such as run_query, list_databases, and list_tables.
mcp-clickhouse requires clickhouse-connect 1.0.0 or newer.
Required Variables
CLICKHOUSE_HOST: The hostname of your ClickHouse server (database endpoint, not the MCP server bind address)
CLICKHOUSE_USER: The username for ClickHouse authentication
CLICKHOUSE_PASSWORD: The password for ClickHouse authentication
[!CAUTION]
It is important to treat your MCP database user as you would any external client connecting to your database, granting only the minimum necessary privileges required for its operation. The use of default or administrative users should be strictly avoided at all times.
Optional Variables
CLICKHOUSE_PORT: HTTP interface port of your ClickHouse server
- Default:
8443 if CLICKHOUSE_SECURE=true, 8123 if CLICKHOUSE_SECURE=false
- Usually doesn't need to be set unless using a non-standard port
- Must be an HTTP interface port, not the native TCP protocol port used by
clickhouse-client
- Common values:
- HTTP:
8123 (plain) / 8443 (TLS) — used by this server and ClickHouse Cloud HTTPS
- Native TCP (not supported here):
9000 (plain) / 9440 (TLS) — used by clickhouse-client
- If the server responds with
Port 9000 is for clickhouse-client program, you are pointed at the native protocol; switch to the HTTP port (8123/8443 or your deployment's HTTP mapping)
CLICKHOUSE_ROLE: The ClickHouse role to use for authentication
- Default: None
- Set this if your user requires a specific role
CLICKHOUSE_SECURE: Enable HTTPS for the ClickHouse database connection (not for MCP clients)
- Default:
"true"
- Set to
"false" only when the MCP server reaches ClickHouse over plain HTTP (typical for local Docker Compose on port )
MCP server and transport
These variables control the MCP process itself, including transport, authentication, and query-tool execution limits. They are independent of the ClickHouse database settings above. See also Authentication for HTTP/SSE Transports.
CLICKHOUSE_MCP_SERVER_TRANSPORT: Sets the transport method for the MCP server
- Default:
"stdio"
- Valid options:
"stdio", "http", "sse". This is useful for local development with tools like MCP Inspector.
stdio is typical for Claude Desktop; http/sse expose a network listener (bind host/port below)
"sse" selects the deprecated standalone HTTP+SSE transport and logs a warning. Use "http" for Streamable HTTP in new deployments.
CLICKHOUSE_MCP_BIND_HOST: Host to bind the MCP server to when using HTTP or SSE transport
- Default:
"127.0.0.1"
- Set to
"0.0.0.0" to bind to all network interfaces (useful for Docker or remote access)
- Only used when transport is
"http" or "sse" — not related to CLICKHOUSE_HOST
CLICKHOUSE_MCP_BIND_PORT: Port to bind the MCP server to when using HTTP or SSE transport
- Default:
"8000"
- Only used when transport is
"http" or "sse" — not related to
Reverse proxy Host handling
Preserve Host when possible. This keeps forwarded Host trust disabled:
location / {
proxy_pass http://mcp-clickhouse:8000;
proxy_set_header Host $http_host;
proxy_set_header X-Forwarded-Host "";
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-Proto $scheme;
}
Sanitize X-Forwarded-For and X-Forwarded-Proto independently of X-Forwarded-Host trust. Uvicorn may trust those headers based on the proxy peer even when CLICKHOUSE_MCP_TRUSTED_PROXIES is unset.
CLICKHOUSE_MCP_ALLOWED_HOSTS=mcp.example.com
Stock nginx changes Host to the upstream name for proxied requests. It does not create or overwrite X-Forwarded-Host. If preserving Host is not possible, overwrite the forwarded header at the trusted edge:
location / {
proxy_pass http://mcp-clickhouse:8000;
proxy_set_header X-Forwarded-Host $http_host;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-Proto $scheme;
}
CLICKHOUSE_MCP_ALLOWED_HOSTS=mcp.example.com
CLICKHOUSE_MCP_TRUSTED_PROXIES=10.20.0.8
The second configuration is safe only when 10.20.0.8 is the proxy's immediate source address, the server port is isolated from other clients, and nginx overwrites the incoming forwarding headers as shown. For a proxy chain, each trusted hop must discard unverified incoming values before constructing the new forwarding headers.
On an IPv6 or dual-stack bind, IPv4 proxies may appear as IPv4-mapped addresses such as ::ffff:10.20.0.8; these are matched against IPv4 entries automatically. Envoy's append_x_forwarded_host appends to an existing X-Forwarded-Host rather than overwriting it, producing a comma separated list that is rejected, so configure the trusted hop to overwrite the header instead. On Kubernetes with source NAT (for example externalTrafficPolicy: Cluster) the observed peer may be a node IP rather than the proxy pod, so trust the pod or node CIDR as appropriate; ingress-nginx overwrites both Host and X-Forwarded-Host itself.
Middleware Variables
MCP_MIDDLEWARE_MODULE: Python module name containing custom middleware to inject into the MCP server
- Default: None (no middleware loaded)
- Set to the module name (without
.py extension) of your middleware module
- The module must provide a
setup_middleware(mcp) function
- See Custom Middleware for details and examples
chDB Variables
CHDB_ENABLED: Enable/disable chDB functionality
- Default:
"false"
- Set to
"true" to enable chDB tools
- Requires installing the optional extra:
mcp-clickhouse[chdb]
CHDB_DATA_PATH: The path to the chDB data directory
- Default:
":memory:" (in-memory database)
- Use
:memory: for in-memory database
- Use a file path for persistent storage (e.g.,
/path/to/chdb/data)
Common configuration pitfalls
CLICKHOUSE_SECURE vs MCP / ingress TLS — Turning off CLICKHOUSE_SECURE because the MCP server sits behind Kubernetes ingress, a reverse proxy, or is reached over plain HTTP does not disable database TLS; it only changes how this process connects to ClickHouse. Configure ingress TLS separately from the database client settings.
- Native protocol ports —
CLICKHOUSE_PORT must target ClickHouse's HTTP interface (8123/8443 by default). Ports 9000/9440 are for the native TCP protocol (clickhouse-client) and will not work with this server.
- Host confusion —
CLICKHOUSE_HOST is the database hostname. CLICKHOUSE_MCP_BIND_HOST is only the address the MCP HTTP/SSE server listens on.
Example Configurations
For local development with Docker:
# Required variables
CLICKHOUSE_HOST=localhost
CLICKHOUSE_USER=default
CLICKHOUSE_PASSWORD=clickhouse
# Optional: Override defaults for local development
CLICKHOUSE_SECURE=false # Uses port 8123 automatically
CLICKHOUSE_VERIFY=false
For ClickHouse Cloud:
# Required variables
CLICKHOUSE_HOST=your-instance.clickhouse.cloud
CLICKHOUSE_USER=default
CLICKHOUSE_PASSWORD=your-password
# Optional: These use secure defaults
# CLICKHOUSE_SECURE=true # Uses port 8443 automatically
# CLICKHOUSE_DATABASE=your_database
For ClickHouse SQL Playground:
CLICKHOUSE_HOST=sql-clickhouse.clickhouse.com
CLICKHOUSE_USER=demo
CLICKHOUSE_PASSWORD=
# Uses secure defaults (HTTPS on port 8443)
For chDB only (in-memory):
# chDB configuration
CHDB_ENABLED=true
CLICKHOUSE_ENABLED=false
# CHDB_DATA_PATH defaults to :memory:
For chDB with persistent storage:
# chDB configuration
CHDB_ENABLED=true
CLICKHOUSE_ENABLED=false
CHDB_DATA_PATH=/path/to/chdb/data
For MCP Inspector or remote access with HTTP transport:
CLICKHOUSE_HOST=localhost
CLICKHOUSE_USER=default
CLICKHOUSE_PASSWORD=clickhouse
CLICKHOUSE_MCP_SERVER_TRANSPORT=http
CLICKHOUSE_MCP_BIND_HOST=0.0.0.0 # Bind to all interfaces
CLICKHOUSE_MCP_BIND_PORT=4200 # Custom port (default: 8000)
CLICKHOUSE_MCP_AUTH_TOKEN=your-generated-token # One auth mode required for HTTP/SSE (or FASTMCP_SERVER_AUTH, or CLICKHOUSE_MCP_AUTH_DISABLED=true)
CLICKHOUSE_MCP_ALLOWED_HOSTS=127.0.0.1:4200,localhost:4200,mcp.example.com:4200 # Include every Host value clients and proxies send
For local development with HTTP transport (authentication disabled):
CLICKHOUSE_HOST=localhost
CLICKHOUSE_USER=default
CLICKHOUSE_PASSWORD=clickhouse
CLICKHOUSE_MCP_SERVER_TRANSPORT=http
CLICKHOUSE_MCP_AUTH_DISABLED=true # Only for local development!
CLICKHOUSE_MCP_ALLOWED_HOSTS=127.0.0.1:8000,localhost:8000
When using HTTP transport, the server will run on the configured port (default 8000). For example, with the above configuration:
- MCP endpoint:
http://localhost:8000/mcp
- Health check:
http://localhost:8000/health
You can set these variables in your environment, in a .env file, or in the Claude Desktop configuration:
{
"mcpServers": {
"mcp-clickhouse": {
"command": "uv",
"args": [
"run",
"--with",
"mcp-clickhouse",
"--python",
"3.12",
"mcp-clickhouse"
],
"env": {
"CLICKHOUSE_HOST": "<clickhouse-host>",
"CLICKHOUSE_USER": "<clickhouse-user>",
"CLICKHOUSE_PASSWORD": "<clickhouse-password>",
"CLICKHOUSE_DATABASE": "<optional-database>",
"CLICKHOUSE_MCP_SERVER_TRANSPORT": "stdio",
"CLICKHOUSE_MCP_BIND_HOST": "127.0.0.1",
"CLICKHOUSE_MCP_BIND_PORT": "8000"
}
}
}
}
Note: The bind host and port settings are only used when transport is set to "http" or "sse".
Running tests
uv sync --all-extras --dev # install dev dependencies
uv run ruff check . # run linting
docker compose up -d test_services # start ClickHouse
uv run pytest -v tests
uv run pytest -v tests/test_tool.py # ClickHouse only
CHDB_ENABLED=true uv run --extra chdb pytest -v tests/test_chdb_tool.py # chDB only
YouTube Overview