Point Claude, Cursor, or Codex at one URL and sign in — no API keys. Your agent explores your schema, validates queries, and ships data apps. Read-only by design.
No API key — your agent signs in with your Mako account in the next step.
https://your-mako-host/api/mcpclaude mcp add --transport http mako https://your-mako-host/api/mcp
Then type /mcp inside a session — your browser opens to sign in.
Your browser opens once: sign in, pick a workspace, approve read-only access. Then:
“Using the mako tools, explore my data and build an app showing revenue by month, then give me a preview link.”
Under a minute, no keys to manage. Data access is read-only — there is no write mode to misconfigure.
The server ships its own instructions with the MCP handshake, so agents figure out the workflow on their own. These prompts work verbatim — copy one into your first session.
The agent lists connections, walks the schema, and samples rows — then explains what it found.
“Using the mako tools, explore my database and explain the schema — what are the main tables and how do they relate?”
Validated, read-only SQL against your live connection — with the query shown so you can save it.
“What were our top 10 customers by revenue last quarter? Use the mako tools and show me the SQL.”
A real React app bound to a validated query, rendered headlessly to verify, delivered as a preview link.
“Build a Mako app with a bar chart of signups per week and a cohort filter. Verify it renders, then give me the preview link.”
The agent reads the app's files and version history, edits, and re-renders — like a code review with hands.
“Open the app called account-health, find why the risk table is empty, and fix it.”
There is no write scope to misconfigure. Every query must be a single read-only statement, enforced inside the database where the engine supports it — Postgres read-only transactions, MySQL READ ONLY, ClickHouse readonly=2. Engines without a reliable read-only mode refuse agent queries outright. MCP keys work only on the MCP endpoint, and read-only tools are annotated so clients skip approval prompts for safe calls.
No — that's the point. Your agent (Claude Code, Cursor, Codex) uses the subscription you already have. Mako provides the data layer over MCP; the tokens are yours.
No. Data access over MCP is read-only by design — there is no scope, flag, or setting that enables writes. Queries are validated as single read-only statements and executed inside read-only transactions where the engine supports them. Engines without a reliable read-only mode (BigQuery, MSSQL, D1/KV) refuse agent queries unless the connection itself uses read-restricted credentials.
No. Add the URL in your client and sign in with your Mako account — you pick which workspace to grant (read-only) on the consent screen. Workspace API keys still work as a Bearer header for headless environments like CI.
Claude (web and Claude Code), Cursor, Codex — and any other MCP client that speaks Streamable HTTP, with OAuth sign-in or a Bearer API key.
Discover connections and schemas, sample and query data (read-only), run long queries via saved consoles, and build full Mako apps: write files, bind validated queries as data sources, render drafts headlessly to self-verify, mint shareable preview links, and publish versions.
No. Tool results are deliberately compact (compact JSON, trimmed metadata, optional screenshot-free renders) so the agent burns as few of your tokens as possible — and none of ours.
Keys created before MCP scopes existed keep working for the REST API but are refused on MCP. Sign in via OAuth instead, or create a new key for headless use.
One URL, one sign-in. Your agent does the rest — and it can't write a single row.