MCPLow riskUnclaimed

valv

Let coding agents query any SQL database safely. Read-only by default and scoped by your policies.

valv.shvalv.sh/mcp★ 5Updated Jul 28, 2026

server.json

{
  "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
  "name": "sh.valv/mcp",
  "description": "Let coding agents query any SQL database safely. Read-only by default and scoped by your policies.",
  "title": "valv",
  "repository": {
    "url": "https://github.com/valv-dev/valv",
    "source": "github",
    "subfolder": "packages/mcp"
  },
  "version": "0.6.2",
  "websiteUrl": "https://valv.sh",
  "packages": [
    {
      "registryType": "npm",
      "identifier": "@valv/mcp",
      "version": "0.6.2",
      "transport": {
        "type": "stdio"
      },
      "environmentVariables": [
        {
          "description": "Database connection string. PostgreSQL, MySQL, SQLite, CockroachDB, or a ClickHouse HTTP URL.",
          "isRequired": true,
          "format": "string",
          "isSecret": true,
          "name": "DATABASE_URL"
        },
        {
          "description": "Datasource provider: postgresql, mysql, sqlite, or clickhouse. Inferred from DATABASE_URL when omitted.",
          "format": "string",
          "choices": [
            "postgresql",
            "mysql",
            "sqlite",
            "clickhouse"
          ],
          "name": "VALV_PROVIDER"
        },
        {
          "description": "Database name. Required for ClickHouse, whose URL does not carry one.",
          "format": "string",
          "name": "VALV_DATABASE"
        },
        {
          "description": "Comma-separated allow-list of tables. When set, only these are exposed to the agent.",
          "format": "string",
          "name": "VALV_TABLES"
        },
        {
          "description": "Comma-separated deny-list of tables, applied after the allow-list.",
          "format": "string",
          "name": "VALV_EXCLUDE"
        },
        {
          "description": "Path to a policy module that takes full control of access. Without it, the server is read-only across all tables.",
          "format": "filepath",
          "name": "VALV_POLICY_FILE"
        },
        {
          "description": "JSON context object the policy reads, e.g. {\"tenant\":{\"id\":\"acme\"}}.",
          "format": "string",
          "name": "VALV_CONTEXT"
        },
        {
          "description": "Serve over Streamable HTTP on this port instead of stdio.",
          "format": "number",
          "name": "VALV_HTTP_PORT"
        }
      ]
    }
  ]
}

Permissions

DeclaredDetected
Runs code—node
Installs—npm:@valv/mcp@0.6.2
Runs install scripts—None
NetworkNoneNone
Needs credentialsDATABASE_URLDATABASE_URL
Outside the workspace—None
Agent tools—None

Checks

Low risk · Nothing worth a warning was found.

Not reviewed by a person · Checked by rules; the model review is not switched on yet.

Versions

  1. #10.6.2latestOct 7, 2026