Skip to content

Midplane

Local package path declaredCredentials listedRepository declared by sourceUpdated 2026-08-25

ai.midplane/midplane · Registry status: active

At a glance

Safe-by-default SQL guardrails for AI agents: AST-checked queries, per-table policy, audit log.

Vendor's own description, untranslated and unverified

Execution location
Local package path declaredMCP-Register · 2026-08-20
Required secrets declared
Credentials listedMCP-Register · 2026-08-20
Declared version and change
0.20.0 · Source-reported change date 2026-08-25MCP-Register · 2026-08-26
Repository as declared
github.com/midplaneai/midplaneMCP-Register · 2026-08-20
Configuration
can be built from the disclosed start template

Inspect connection paths and prerequisites

Related categories

6 of 10 categories. All categories in the segment catalogue

Page last changed:

Sources and collection
Runs
Local package path declared
Credentials
Credentials listed
Registry record changed
2026-08-25
Setup
Template available
Registry name
ai.midplane/midplane
Package coordinate
npm:midplane
Declared version
0.20.0
Source-reported listing date
2026-08-25
Source-reported change date
2026-08-25
First seen by tracevero
2026-08-20
Vendor's website
https://midplane.ai/docs

Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin. What the confidence levels mean

Measured values

Measured values
Required secrets declaredCredentials listed yes
Original data – Required secret variables (raw): DATABASE_URL, DATABASE_URL
Original data – Required secret headers (raw): confirmed absent
Source: MCP-Register · collected on 2026-08-20 · derived
Execution locationLocal package path declared local
Original data – Transports (raw): stdio, streamable-http
Source: MCP-Register · collected on 2026-08-20 · derived
Path argument presentyes
Original data – Path arguments (raw): confirmed absent
Original data – Path environment variables (raw): DB_PATH, MIDPLANE_POLICY_FILE
Source: MCP-Register · collected on 2026-08-20 · derived
Repository URL listedRepository declared by source yes
Original data – Repository (raw): https://github.com/midplaneai/midplane
Source: MCP-Register · collected on 2026-08-20 · derived
Field of use, derived from the vendor descriptionDatabases
Original data – Description (raw): Safe-by-default SQL guardrails for AI agents: AST-checked queries, per-table policy, audit log.
Source: MCP-Register · collected on 2026-08-26 · derived
Declared version0.20.0
Source: MCP-Register · collected on 2026-08-26 · self-declared

What is measured is what a manifest declares, not what a piece of software does. This registry fetches no repository URL, no endpoint and no package index; nothing here is verified. Which value comes from which source, and by which rule it was formed, is set out in the Methodology.

Source data25

Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin.

Raw values
Description (raw)Safe-by-default SQL guardrails for AI agents: AST-checked queries, per-table policy, audit log.
Source: MCP-Register · collected on 2026-08-26 · self-declared
Environment variables (raw)DATABASE_URL, MIDPLANE_POLICY_FILE, DB_PATH, MIDPLANE_TELEMETRY, DATABASE_URL, MIDPLANE_POLICY_FILE, PORT
Source: MCP-Register · collected on 2026-08-20 · self-declared
Required secret variables (raw)DATABASE_URL, DATABASE_URL
Source: MCP-Register · collected on 2026-08-20 · self-declared
Transports (raw)stdio, streamable-http
Source: MCP-Register · collected on 2026-08-20 · self-declared
Path arguments (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-20 · self-declared
Repository (raw)https://github.com/midplaneai/midplane
Source: MCP-Register · collected on 2026-08-20 · self-declared
Package registries (raw)npm, oci
Source: MCP-Register · collected on 2026-08-20 · self-declared
Required secret headers (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-20 · self-declared
Path environment variables (raw)DB_PATH, MIDPLANE_POLICY_FILE
Source: MCP-Register · collected on 2026-08-20 · self-declared
Remote URLs (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-20 · self-declared
Remote hosts (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-20 · self-declared
Registry status message (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-20 · self-declared
First listed in the registry (raw)2026-08-25
Source: MCP-Register · collected on 2026-08-26 · self-declared
Last changed in the registry (raw)2026-08-25
Source: MCP-Register · collected on 2026-08-26 · self-declared
Schema version of the raw record (raw)https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json
Source: MCP-Register · collected on 2026-08-20 · self-declared
Delivery form (raw)package
Source: MCP-Register · collected on 2026-08-20 · self-declared
Repository platform (raw)github
Source: MCP-Register · collected on 2026-08-20 · self-declared
Repository subfolder (raw)engine/packages/mcp-server
Source: MCP-Register · collected on 2026-08-20 · self-declared
Package identifiers (raw)docker.io/midplane/midplane:0.20.0, midplane
Source: MCP-Register · collected on 2026-08-26 · self-declared
Package versions (raw)0.20.0
Source: MCP-Register · collected on 2026-08-26 · self-declared
Runtime hints (raw)docker · npx
Source: MCP-Register · collected on 2026-08-20 · self-declared
Environment variable formats (raw)filepath, string
Source: MCP-Register · collected on 2026-08-20 · self-declared
Environment variable descriptions (raw)DATABASE_URL=Postgres connection string the agent's queries run against. Give it a least-privilege role: Midplane constrains what SQL is allowed, it does not widen or narrow what the role itself can reach. · DATABASE_URL=Postgres connection string the agent's queries run against. Pass it with --env-file, never with an inline -e: a DSN on the docker command line leaks the password to `ps aux` and your shell history. · DB_PATH=Where the local SQLite audit log is written. Defaults to ~/.midplane/audit.db; read it back with `midplane audit denies`. · MIDPLANE_POLICY_FILE=Path (inside the container) to a policy YAML granting per-table read/read_write access, tenant scoping, and column masking. Omit for the safe default: reads allowed, writes and DDL denied. · MIDPLANE_POLICY_FILE=Path to a policy YAML granting per-table read/read_write access, tenant scoping, and column masking. Omit for the safe default: reads allowed, writes and DDL denied. Generate one with `npx midplane init`. · MIDPLANE_TELEMETRY=Set to 0 to disable anonymous usage telemetry (DO_NOT_TRACK=1 also works). Never includes SQL, table or column names, or identifiers. · PORT=Port the Streamable HTTP transport binds. Must match the url above if changed.
Source: MCP-Register · collected on 2026-08-20 · self-declared
Icon formats (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-20 · self-declared
Connection paths (source structure){"packages":[{"registryType":"npm","identifier":"midplane","version":"0.20.0","runtimeHint":"npx","transport":"stdio","environment":[{"name":"DATABASE_URL","description":"Postgres connection string the agent's queries run against. Give it a least-privilege role: Midplane constrains what SQL is allowed, it does not widen or narrow what the role itself can reach.","format":"string","required":true,"secret":true},{"name":"MIDPLANE_POLICY_FILE","description":"Path to a policy YAML granting per-table read/read_write access, tenant scoping, and column masking. Omit for the safe default: reads allowed, writes and DDL denied. Generate one with `npx midplane init`.","format":"filepath","required":false,"secret":false},{"name":"DB_PATH","description":"Where the local SQLite audit log is written. Defaults to ~/.midplane/audit.db; read it back with `midplane audit denies`.","format":"filepath","required":false,"secret":false},{"name":"MIDPLANE_TELEMETRY","description":"Set to 0 to disable anonymous usage telemetry (DO_NOT_TRACK=1 also works). Never includes SQL, table or column names, or identifiers.","required":false,"secret":false}],"additional_arguments_declared":true},{"registryType":"oci","identifier":"docker.io/midplane/midplane:0.20.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"DATABASE_URL","description":"Postgres connection string the agent's queries run against. Pass it with --env-file, never with an inline -e: a DSN on the docker command line leaks the password to `ps aux` and your shell history.","format":"string","required":true,"secret":true},{"name":"MIDPLANE_POLICY_FILE","description":"Path (inside the container) to a policy YAML granting per-table read/read_write access, tenant scoping, and column masking. Omit for the safe default: reads allowed, writes and DDL denied.","format":"filepath","required":false,"secret":false},{"name":"PORT","description":"Port the Streamable HTTP transport binds. Must match the url above if changed.","required":false,"secret":false}],"additional_arguments_declared":false}],"remotes":[]}
Source: MCP-Register · collected on 2026-09-08 · self-declared
Embed this badge

Paste this line into a README of your own. The badge states how many values the registry holds for the entry and when it last looked, and it links back to this page.

tracevero: number of measured values and date of collection for this registry entry

[![tracevero: number of measured values and date of collection for this registry entry](https://tracevero.com/badge/mcp/ai-midplane-midplane.svg)](https://tracevero.com/mcp/ai-midplane-midplane)

The image is drawn again on every request, so it always reports the current state while the pasted line stays as it is. It carries no rating and no traffic light – only the two measured figures.

Changes

Changes
2026-09-08Connection paths (source structure): – → {"packages":[{"registryType":"npm","identifier":"midplane","version":"0.20.0","runtimeHint":"npx","transport":"stdio","environment":[{"name":"DATABASE_URL","description":"Postgres connection string the agent's queries run against. Give it a least-privilege role: Midplane constrains what SQL is allowed, it does not widen or narrow what the role itself can reach.","format":"string","required":true,"secret":true},{"name":"MIDPLANE_POLICY_FILE","description":"Path to a policy YAML granting per-table read/read_write access, tenant scoping, and column masking. Omit for the safe default: reads allowed, writes and DDL denied. Generate one with `npx midplane init`.","format":"filepath","required":false,"secret":false},{"name":"DB_PATH","description":"Where the local SQLite audit log is written. Defaults to ~/.midplane/audit.db; read it back with `midplane audit denies`.","format":"filepath","required":false,"secret":false},{"name":"MIDPLANE_TELEMETRY","description":"Set to 0 to disable anonymous usage telemetry (DO_NOT_TRACK=1 also works). Never includes SQL, table or column names, or identifiers.","required":false,"secret":false}],"additional_arguments_declared":true},{"registryType":"oci","identifier":"docker.io/midplane/midplane:0.20.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"DATABASE_URL","description":"Postgres connection string the agent's queries run against. Pass it with --env-file, never with an inline -e: a DSN on the docker command line leaks the password to `ps aux` and your shell history.","format":"string","required":true,"secret":true},{"name":"MIDPLANE_POLICY_FILE","description":"Path (inside the container) to a policy YAML granting per-table read/read_write access, tenant scoping, and column masking. Omit for the safe default: reads allowed, writes and DDL denied.","format":"filepath","required":false,"secret":false},{"name":"PORT","description":"Port the Streamable HTTP transport binds. Must match the url above if changed.","required":false,"secret":false}],"additional_arguments_declared":false}],"remotes":[]}
2026-08-26Field of use, derived from the vendor description: – → Databases
2026-08-26Description (raw): – → Safe-by-default SQL guardrails for AI agents: AST-checked queries, per-table policy, audit log.

These are the 3 most recent changes to this entry. Full history

tracevero · https://tracevero.com/mcp/ai-midplane-midplane