Midplane
Local package path declaredCredentials listedRepository declared by sourceUpdated 2026-08-25
ai.midplane/midplane · Registry status: active
At a glance
Safe-by-default SQL guardrails for AI agents: AST-checked queries, per-table policy, audit log.
Vendor's own description, untranslated and unverified
- Execution location
- Local package path declaredMCP-Register · 2026-08-20
- Required secrets declared
- Credentials listedMCP-Register · 2026-08-20
- Declared version and change
0.20.0· Source-reported change date 2026-08-25MCP-Register · 2026-08-26- Repository as declared
- github.com/midplaneai/midplaneMCP-Register · 2026-08-20
- Configuration
- can be built from the disclosed start template
Inspect connection paths and prerequisites
Related categories
- MCP servers for databases338
- MCP servers with declared required secrets6,067
- Locally executed MCP servers17,056
- MCP servers with a repository URL30,107
- MCP servers with a path argument498
- Local MCP servers with a repository URL16,152
6 of 10 categories. All categories in the segment catalogue
Page last changed:
Sources and collection
- Runs
- Local package path declared
- Credentials
- Credentials listed
- Registry record changed
- 2026-08-25
- Setup
- Template available
- Registry name
ai.midplane/midplane- Package coordinate
npm:midplane- Declared version
0.20.0- Source-reported listing date
- 2026-08-25
- Source-reported change date
- 2026-08-25
- First seen by tracevero
- 2026-08-20
- Vendor's website
- https://midplane.ai/docs
Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin. What the confidence levels mean
Measured values
| Required secrets declared | Credentials listed yes Original data – Required secret variables (raw): DATABASE_URL, DATABASE_URL Original data – Required secret headers (raw): confirmed absent Source: MCP-Register · collected on 2026-08-20 · derived |
|---|---|
| Execution location | Local package path declared local Original data – Transports (raw): stdio, streamable-http Source: MCP-Register · collected on 2026-08-20 · derived |
| Path argument present | yes Original data – Path arguments (raw): confirmed absent Original data – Path environment variables (raw): DB_PATH, MIDPLANE_POLICY_FILE Source: MCP-Register · collected on 2026-08-20 · derived |
| Repository URL listed | Repository declared by source yes Original data – Repository (raw): https://github.com/midplaneai/midplane Source: MCP-Register · collected on 2026-08-20 · derived |
| Field of use, derived from the vendor description | Databases Original data – Description (raw): Safe-by-default SQL guardrails for AI agents: AST-checked queries, per-table policy, audit log. Source: MCP-Register · collected on 2026-08-26 · derived |
| Declared version | 0.20.0 Source: MCP-Register · collected on 2026-08-26 · self-declared |
What is measured is what a manifest declares, not what a piece of software does. This registry fetches no repository URL, no endpoint and no package index; nothing here is verified. Which value comes from which source, and by which rule it was formed, is set out in the Methodology.
Source data25
Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin.
| Description (raw) | Safe-by-default SQL guardrails for AI agents: AST-checked queries, per-table policy, audit log. Source: MCP-Register · collected on 2026-08-26 · self-declared |
|---|---|
| Environment variables (raw) | DATABASE_URL, MIDPLANE_POLICY_FILE, DB_PATH, MIDPLANE_TELEMETRY, DATABASE_URL, MIDPLANE_POLICY_FILE, PORT Source: MCP-Register · collected on 2026-08-20 · self-declared |
| Required secret variables (raw) | DATABASE_URL, DATABASE_URL Source: MCP-Register · collected on 2026-08-20 · self-declared |
| Transports (raw) | stdio, streamable-http Source: MCP-Register · collected on 2026-08-20 · self-declared |
| Path arguments (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-20 · self-declared |
| Repository (raw) | https://github.com/midplaneai/midplane Source: MCP-Register · collected on 2026-08-20 · self-declared |
| Package registries (raw) | npm, oci Source: MCP-Register · collected on 2026-08-20 · self-declared |
| Required secret headers (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-20 · self-declared |
| Path environment variables (raw) | DB_PATH, MIDPLANE_POLICY_FILE Source: MCP-Register · collected on 2026-08-20 · self-declared |
| Remote URLs (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-20 · self-declared |
| Remote hosts (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-20 · self-declared |
| Registry status message (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-20 · self-declared |
| First listed in the registry (raw) | 2026-08-25 Source: MCP-Register · collected on 2026-08-26 · self-declared |
| Last changed in the registry (raw) | 2026-08-25 Source: MCP-Register · collected on 2026-08-26 · self-declared |
| Schema version of the raw record (raw) | https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json Source: MCP-Register · collected on 2026-08-20 · self-declared |
| Delivery form (raw) | package Source: MCP-Register · collected on 2026-08-20 · self-declared |
| Repository platform (raw) | github Source: MCP-Register · collected on 2026-08-20 · self-declared |
| Repository subfolder (raw) | engine/packages/mcp-server Source: MCP-Register · collected on 2026-08-20 · self-declared |
| Package identifiers (raw) | docker.io/midplane/midplane:0.20.0, midplane Source: MCP-Register · collected on 2026-08-26 · self-declared |
| Package versions (raw) | 0.20.0 Source: MCP-Register · collected on 2026-08-26 · self-declared |
| Runtime hints (raw) | docker · npx Source: MCP-Register · collected on 2026-08-20 · self-declared |
| Environment variable formats (raw) | filepath, string Source: MCP-Register · collected on 2026-08-20 · self-declared |
| Environment variable descriptions (raw) | DATABASE_URL=Postgres connection string the agent's queries run against. Give it a least-privilege role: Midplane constrains what SQL is allowed, it does not widen or narrow what the role itself can reach. · DATABASE_URL=Postgres connection string the agent's queries run against. Pass it with --env-file, never with an inline -e: a DSN on the docker command line leaks the password to `ps aux` and your shell history. · DB_PATH=Where the local SQLite audit log is written. Defaults to ~/.midplane/audit.db; read it back with `midplane audit denies`. · MIDPLANE_POLICY_FILE=Path (inside the container) to a policy YAML granting per-table read/read_write access, tenant scoping, and column masking. Omit for the safe default: reads allowed, writes and DDL denied. · MIDPLANE_POLICY_FILE=Path to a policy YAML granting per-table read/read_write access, tenant scoping, and column masking. Omit for the safe default: reads allowed, writes and DDL denied. Generate one with `npx midplane init`. · MIDPLANE_TELEMETRY=Set to 0 to disable anonymous usage telemetry (DO_NOT_TRACK=1 also works). Never includes SQL, table or column names, or identifiers. · PORT=Port the Streamable HTTP transport binds. Must match the url above if changed. Source: MCP-Register · collected on 2026-08-20 · self-declared |
| Icon formats (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-20 · self-declared |
| Connection paths (source structure) | {"packages":[{"registryType":"npm","identifier":"midplane","version":"0.20.0","runtimeHint":"npx","transport":"stdio","environment":[{"name":"DATABASE_URL","description":"Postgres connection string the agent's queries run against. Give it a least-privilege role: Midplane constrains what SQL is allowed, it does not widen or narrow what the role itself can reach.","format":"string","required":true,"secret":true},{"name":"MIDPLANE_POLICY_FILE","description":"Path to a policy YAML granting per-table read/read_write access, tenant scoping, and column masking. Omit for the safe default: reads allowed, writes and DDL denied. Generate one with `npx midplane init`.","format":"filepath","required":false,"secret":false},{"name":"DB_PATH","description":"Where the local SQLite audit log is written. Defaults to ~/.midplane/audit.db; read it back with `midplane audit denies`.","format":"filepath","required":false,"secret":false},{"name":"MIDPLANE_TELEMETRY","description":"Set to 0 to disable anonymous usage telemetry (DO_NOT_TRACK=1 also works). Never includes SQL, table or column names, or identifiers.","required":false,"secret":false}],"additional_arguments_declared":true},{"registryType":"oci","identifier":"docker.io/midplane/midplane:0.20.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"DATABASE_URL","description":"Postgres connection string the agent's queries run against. Pass it with --env-file, never with an inline -e: a DSN on the docker command line leaks the password to `ps aux` and your shell history.","format":"string","required":true,"secret":true},{"name":"MIDPLANE_POLICY_FILE","description":"Path (inside the container) to a policy YAML granting per-table read/read_write access, tenant scoping, and column masking. Omit for the safe default: reads allowed, writes and DDL denied.","format":"filepath","required":false,"secret":false},{"name":"PORT","description":"Port the Streamable HTTP transport binds. Must match the url above if changed.","required":false,"secret":false}],"additional_arguments_declared":false}],"remotes":[]} Source: MCP-Register · collected on 2026-09-08 · self-declared |
Embed this badge
Paste this line into a README of your own. The badge states how many values the registry holds for the entry and when it last looked, and it links back to this page.
[](https://tracevero.com/mcp/ai-midplane-midplane)
The image is drawn again on every request, so it always reports the current state while the pasted line stays as it is. It carries no rating and no traffic light – only the two measured figures.
Changes
| 2026-09-08 | Connection paths (source structure): – → {"packages":[{"registryType":"npm","identifier":"midplane","version":"0.20.0","runtimeHint":"npx","transport":"stdio","environment":[{"name":"DATABASE_URL","description":"Postgres connection string the agent's queries run against. Give it a least-privilege role: Midplane constrains what SQL is allowed, it does not widen or narrow what the role itself can reach.","format":"string","required":true,"secret":true},{"name":"MIDPLANE_POLICY_FILE","description":"Path to a policy YAML granting per-table read/read_write access, tenant scoping, and column masking. Omit for the safe default: reads allowed, writes and DDL denied. Generate one with `npx midplane init`.","format":"filepath","required":false,"secret":false},{"name":"DB_PATH","description":"Where the local SQLite audit log is written. Defaults to ~/.midplane/audit.db; read it back with `midplane audit denies`.","format":"filepath","required":false,"secret":false},{"name":"MIDPLANE_TELEMETRY","description":"Set to 0 to disable anonymous usage telemetry (DO_NOT_TRACK=1 also works). Never includes SQL, table or column names, or identifiers.","required":false,"secret":false}],"additional_arguments_declared":true},{"registryType":"oci","identifier":"docker.io/midplane/midplane:0.20.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"DATABASE_URL","description":"Postgres connection string the agent's queries run against. Pass it with --env-file, never with an inline -e: a DSN on the docker command line leaks the password to `ps aux` and your shell history.","format":"string","required":true,"secret":true},{"name":"MIDPLANE_POLICY_FILE","description":"Path (inside the container) to a policy YAML granting per-table read/read_write access, tenant scoping, and column masking. Omit for the safe default: reads allowed, writes and DDL denied.","format":"filepath","required":false,"secret":false},{"name":"PORT","description":"Port the Streamable HTTP transport binds. Must match the url above if changed.","required":false,"secret":false}],"additional_arguments_declared":false}],"remotes":[]} |
|---|---|
| 2026-08-26 | Field of use, derived from the vendor description: – → Databases |
| 2026-08-26 | Description (raw): – → Safe-by-default SQL guardrails for AI agents: AST-checked queries, per-table policy, audit log. |
These are the 3 most recent changes to this entry. Full history
tracevero · https://tracevero.com/mcp/ai-midplane-midplane