Set up PlanetScale MCP Server

Hosted MCP server securely links Claude, Cursor, and other clients via OAuth to PlanetScale databases, schema, and Insights.

Published on 18.09.2026

What the PlanetScale MCP Server Is

The PlanetScale MCP Server connects AI-powered development tools such as Claude, Cursor, or Codex directly to PlanetScale databases. PlanetScale is a managed database provider built on Vitess and, more recently, also Postgres. According to the provider, this is a hosted MCP server that can access organizations, databases, branches, schema information, Insights data, and even the organization's stored payment method. Because the server is centrally hosted and doesn't need to be installed locally, setup is relatively simple for end users: it's enough to add the server in an MCP-capable client using a fixed server address.

Authentication and Access Control

According to the documentation, the connection to the server uses OAuth. Each client, such as Claude Code or Cursor, registers as its own OAuth application with PlanetScale, and when the connection is established, the user is redirected to sign in and grant access. For automated or unattended scenarios such as continuous integration pipelines, the server also supports service tokens, passed via a custom HTTP header. The scope of access is controlled through what the provider calls scopes: users decide whether the server gets no access, read-only access, or full access to organizations and individual databases. Access to the payment method is configurable separately, with tiers of no access, read-only, or full access including the ability to initiate a checkout.

Security for Database Queries

A key security feature, according to the provider, is that every single query runs on short-lived credentials created specifically for that purpose and deleted immediately after execution. Even so, PlanetScale explicitly warns against carelessly granting a language model write access to a production database and recommends carefully reviewing every query the agent proposes before it runs. For users who only need Insights data and schema recommendations without actually executing queries against the database, PlanetScale offers a restricted server variant that excludes the execution tools entirely.

Setup in Common Tools

For the most popular clients, such as Cursor or Visual Studio Code, PlanetScale provides one-click installation according to the documentation. Dedicated setup steps exist for Claude Code, OpenCode, Codex CLI, Amp CLI, Notion, and other tools, since configuration syntax differs by client. Users working with multiple Postgres databases within one organization will also find guidance on how to point the agent precisely at the correct database for a given project, avoiding mix-ups between environments.

Practical Value and Limitations

The server is well suited for quickly pulling schema information during development, identifying slow queries, or checking organizational metrics directly in a chat with the assistant, without switching between multiple interfaces. The limits appear once automated write access to production databases comes into play: human oversight remains essential there, and the provider's own warning should be taken seriously. Usability also depends entirely on a working internet connection to the hosted server, since this is not a locally run component. Anyone running the server in production should also periodically review which scopes are still actually needed and revoke permissions that are no longer used, since most clients make re-authorizing with adjusted rights straightforward.

Published on 18.09.2026

Categories

Frequently asked questions

Do I need a PlanetScale account?

Yes. The server authenticates via OAuth with the PlanetScale user credentials and only exposes the databases and branches authorized in the OAuth scope. Without an account, no tool calls are possible.

Do I need to install anything locally?

No. The PlanetScale MCP Server runs exclusively as a hosted remote service. Only the server URL in the AI client is needed; no npm package, local build, or own server infrastructure is required.

How do I limit risk with write operations?

Enable write access (`execute_write_query`) only for the databases and branches where it is actually needed. UPDATE/DELETE without a WHERE clause are blocked server-side; DDL operations require human confirmation. For pure analysis scenarios, use the insights-only endpoint.

What are service tokens and when are they used?

Service tokens are non-interactive credentials for CI systems and headless agents that cannot run an interactive browser OAuth flow. They are created in the PlanetScale dashboard and configured as a custom HTTP header in the AI client.