OceanBaseBLOCK
MCP Server for OceanBase database and its tools
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Model Context Protocol (MCP) Server Collection for OceanBase Ecosystem
English | 简体中文
[](LICENSE) [](https://python.org) [](https://www.typescriptlang.org/)
📖 Project Overview
awesome-oceanbase-mcp is a Model Context Protocol (MCP) server repository specifically designed for the OceanBase ecosystem.
🎯 Mission: Enable AI assistants to interact directly with OceanBase databases and ecosystem components through standardized MCP protocols.
✨ Core Values:
- 🤖 AI-Friendly: Direct database operations within Claude, ChatGPT and other AI assistants
- 🔒 Secure & Reliable: Provides safe database access and operation mechanisms
- 🛠️ Complete Ecosystem: Covers the complete OceanBase product and tool chain
- 🚀 Ready to Use: Simple configuration to get started
🔍 What is MCP?
The Model Context Protocol (MCP) is an open protocol designed to enable seamless integration between AI applications and external data sources and tools. It provides a standardized way for AI models to access the contextual information and capabilities they need.
🚀 Quick Start
Prerequisites
If you don't have an OceanBase database instance yet, please:
- Visit OceanBase Official Repository to get the latest version
- Or use OceanBase Online Trial for quick setup
🗂️ MCP Server Collection
This repository provides complete MCP servers for the OceanBase ecosystem:
🔧 MCP Server 📝 Description 📚 Documentation
OceanBase MCP Server Provides secure interaction capabilities
faa944df9bd5OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add obcloud-mcp-server --env ALLOWED_TOKENS=${ALLOWED_TOKENS} --env OB_CLUSTER_PASSWORD=${OB_CLUSTER_PASSWORD} --env OB_PASSWORD=${OB_PASSWORD} --env OCP_ACCESS_KEY_ID=${OCP_ACCESS_KEY_ID} -- npx -y @oceanbase/[email protected]{
"mcpServers": {
"obcloud-mcp-server": {
"command": "npx",
"args": [
"-y",
"@oceanbase/[email protected]"
],
"env": {
"ALLOWED_TOKENS": "${ALLOWED_TOKENS}",
"OB_CLUSTER_PASSWORD": "${OB_CLUSTER_PASSWORD}",
"OB_PASSWORD": "${OB_PASSWORD}",
"OCP_ACCESS_KEY_ID": "${OCP_ACCESS_KEY_ID}"
}
}
}
}Exposed tools (134)
92 read · 30 write · 12 destructive. Blast radius: 12 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
activate_tenant | read | 激活备用租户 |
add_data_to_collection | write | |
add_memory | write | |
add_memory_with_profile | write | |
ai_complete | read | |
ai_rerank | read | |
call_obshell_sdk | read | 调用 obshell 的 sdk 方法 |
change_tenant_password | read | 修改租户密码 |
configure_cluster_connection | read | |
connect | write | create connection to oceanbase database |
create_ai_model | write | |
create_ai_model_endpoint | write | |
create_backup_policy | write | 在指定集群中创建备份策略 |
create_cluster | write | root_pwd = SYS_PASSWORD |
create_collection | write | |
create_oceanbase_performance_report | write | |
create_tenant | write | # Global variable `secure_file_priv` take a while to take effect, so we set it early (right after tenant creation) |
delete_all_memories | destructive | |
delete_backup_policy | destructive | 删除指定租户的备份策略 |
delete_cluster | destructive | 删除指定命名空间中的OceanBase集群 |
delete_collection | destructive | |
delete_documents | destructive | |
delete_memory | destructive | |
delete_memory_with_profile | destructive | |
delete_tenant | destructive | 删除指定租户 |
delete_user_profile | destructive | |
diagnostics | read | Diagnose the operational status of a tenant |
drop_ai_model | destructive | |
drop_ai_model_endpoint | destructive | |
execute_cluster_sql | write | |
execute_sql | write | Execute an SQL on the OceanBase server. |
export_csv_file_from_seekdb | read | |
full_text_search | read | |
get_ai_model_endpoints | read | |
get_all_obshell_sdk_methods | read | 获取 obshell 所有可供用户使用的 sdk 方法 |
get_all_oceanbase_tenants | read | |
get_all_server_nodes | read | |
get_current_tenant | read | |
get_current_time | read | Get current time from OceanBase database. |
get_memory_by_id | read | |
get_ob_ash_report | read | |
get_obshell_sdk_methods_description | read | 获取 obshell 的 sdk 方法的描述 |
get_oceanbase_alarm_detail | read | |
get_oceanbase_alarms | read | |
get_oceanbase_cluster_parameters | read | |
get_oceanbase_cluster_server_stats | read | |
get_oceanbase_cluster_servers | read | |
get_oceanbase_cluster_snapshots | read | |
get_oceanbase_cluster_stats | read | |
get_oceanbase_cluster_tenants | read | |
get_oceanbase_cluster_units | read | |
get_oceanbase_cluster_zones | read | |
get_oceanbase_inspection_item_last_result | read | |
get_oceanbase_inspection_overview | read | |
get_oceanbase_inspection_report | read | |
get_oceanbase_inspection_report_info | read | |
get_oceanbase_inspection_tasks | read | |
get_oceanbase_metric_data_with_label | read | |
get_oceanbase_metric_groups | read | |
get_oceanbase_obproxy_cluster_detail | read | |
get_oceanbase_obproxy_cluster_parameters | read | |
get_oceanbase_performance_report | read | |
get_oceanbase_sql_text | read | |
get_oceanbase_tenant_databases | read | |
get_oceanbase_tenant_detail | read | |
get_oceanbase_tenant_objects | read | |
get_oceanbase_tenant_parameters | read | |
get_oceanbase_tenant_role_detail | read | |
get_oceanbase_tenant_roles | read | |
get_oceanbase_tenant_slow_sql | read | |
get_oceanbase_tenant_top_sql | read | |
get_oceanbase_tenant_units | read | |
get_oceanbase_tenant_user_detail | read | |
get_oceanbase_tenant_users | read | |
get_oceanbase_zone_servers | read | |
get_registered_ai_models | read | |
get_resource_capacity | read | |
get_user_profile | read | |
has_collection | read | |
hybrid_search | read | |
import_csv_file_to_seekdb | write | |
install_component | write | 安装OceanBase组件, 目前支持ob-operator,ob-dashboard, local-path-provisioner,cert-manager,不支持其他组件, |
install_ob_operator | write | 安装ob-operator |
install_okctl | write | 安装okctl |
list_all_clusters | read | 列出所有的OceanBase集群 |
list_backup_policies | read | 列出指定集群中的所有备份策略 |
list_collections | read | |
list_databases | read | describe databases by teant id |
list_instances | read | list oceanbase instances |
list_memories | read | |
list_obproxy_clusters | read | |
list_oceanbase_clusters | read | |
list_tenants | read | describe tenants by instance id |
list_user_profiles | read | |
obcloud-workflow | read | obcloud 操作的工作流 |
obdiag_analyze_log | read | |
obdiag_check_run | write | |
obdiag_cluster_list | read | |
obdiag_display_list | read | |
obdiag_display_run | write | |
obdiag_gather_log | read | |
oceanbase_hybrid_search | read | |
oceanbase_text_search | read | |
oceanbase_vector_search | read | |
pause_backup_policy | read | 暂停指定租户的备份策略 |
peek_collection | read | |
query | read | query infos from tenant |
query_collection | read | |
replay_tenant_log | read | 回放租户日志 |
resume_backup_policy | read | 恢复指定租户的备份策略 |
run_oceanbase_inspection | write | |
scale_cluster | read | 扩缩OceanBase集群,支持添加/调整/删除可用区 |
scale_tenant | read | 扩缩租户资源,一次只能执行一种类型的扩展操作 |
search_memories | read | |
search_memories_with_profile | read | |
search_oceanbase_document | read | |
seekdb_memory_delete | destructive | |
seekdb_memory_insert | write | |
seekdb_memory_query | read | |
seekdb_memory_update | write | |
set_oceanbase_cluster_parameters | write | |
set_oceanbase_tenant_parameters | write | |
show_backup_policy | read | 查看指定租户的备份策略 |
show_cluster | read | 显示指定OceanBase集群的概览 |
show_tenant | read | 显示租户信息 |
switchover_tenant | read | 切换主备租户 |
update_backup_policy | write | 更新指定租户的备份策略 |
update_cluster | write | 更新OceanBase集群,支持CPU/内存/存储的调整 |
update_collection | write | |
update_component | write | 更新OceanBase组件, 目前支持ob-operator,ob-dashboard, local-path-provisioner,cert-manager,不支持其他组件, |
update_memory | write | |
update_tenant | write | 更新租户信息 |
upgrade_cluster | read | 升级OceanBase集群,请指定新的镜像 |
upgrade_tenant | read | 升级租户 |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
rejectUnauthorized: false,
importlib.import_module(f"okctl_mcp_server.tools.{tool_name}")logger.warning(f"Invalid token provided: {token[:10]}...")logger.debug(f"Valid token accepted: {token[:10]}...")delete_all_memories, delete_backup_policy, delete_cluster, delete_collection, delete_documents, delete_memory, delete_memory_with_profile, delete_tenant, delete_user_profile, drop_ai_model, drop_ai_mo
.env.template
.env.template
.env.template
.env.template
md5_hash = hashlib.md5(data).hexdigest().upper()
"url": "http://127.0.0.1:6000/sse"
"url": "http://127.0.0.1:6000/sse"
- URL: `http://127.0.0.1:6000/sse`
"url": "http://127.0.0.1:6000/mcp"
"url": "http://127.0.0.1:6000/mcp"
[<img src="https://cursor.com/deeplink/mcp-install-dark.svg" alt="Install in Cursor">](https://cursor.com/en/install-mcp?name=OceanBase-MCP&config=eyJjb21tYW5kIjogInV2eCIsICJhcmdzIjogWyItLWZyb20iLCAib
[<img src="https://cursor.com/deeplink/mcp-install-dark.svg" alt="Install in Cursor">](https://cursor.com/en/install-mcp?name=OceanBase-MCP&config=eyJjb21tYW5kIjogInV2eCIsICJhcmdzIjogWyItLWZyb20iLCAib
html_content = base64.b64decode(content_base64)
pytest, pytest-asyncio, pytest-cov, black, isort, mypy, ruff
mcp, fastmcp, mysql-connector-python, python-dotenv, beautifulsoup4, certifi, requests
@modelcontextprotocol/sdk, axios, dayjs, dotenv, http-cookie-agent, mysql2, node-rsa, tough-cookie
- [✔️] **Get ASH report** - Generate [Active Session History](https://www.oceanbase.com/docs/common-oceanbase-database-cn-1000000002013776) reports
cat > .env << EOF
**Step 2: Load environment variables**
cat > .env << EOF
Gates applied: no_behavioural_pass.
faa944df9bd5full audit observations/trust-audit/mcp-server/oceanbase__oceanbase-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | faa944df9bd5 | BLOCK | D | 69 | first audit |
Questions
What is the OceanBase MCP server?
MCP Server for OceanBase database and its tools
What tools does OceanBase expose?
134 in total: 92 read-only, 30 that write, and 12 that can delete or overwrite (delete_all_memories, delete_backup_policy, delete_cluster, delete_collection, delete_documents). Every one is listed on this page with its risk.
Is OceanBase safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 12 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does OceanBase need?
It reads ALLOWED_TOKENS, OB_CLUSTER_PASSWORD, OB_PASSWORD, OCP_ACCESS_KEY_ID, OCP_ACCESS_KEY_SECRET, SEEKDB_PASSWORD and SYS_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does OceanBase run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @oceanbase/obcloud-mcp-server at 0.0.7.
How current is this page?
The grade is for one exact copy of the source (faa944df9bd5), read on 2026-10-08. The repository is watched and re-audited when it changes.