MCP Server — for AI agents

Mako MCP for any agent

Point Claude, Cursor, or Codex at one URL and sign in — no API keys. Your agent explores your schema, validates queries, and ships data apps. Read-only by design.

Copy the Mako MCP URL

No API key — your agent signs in with your Mako account in the next step.

https://your-mako-host/api/mcp

Run one command

claude mcp add --transport http mako https://your-mako-host/api/mcp

Then type /mcp inside a session — your browser opens to sign in.

Sign in and ask it something

Your browser opens once: sign in, pick a workspace, approve read-only access. Then:

“Using the mako tools, explore my data and build an app showing revenue by month, then give me a preview link.”

Under a minute, no keys to manage. Data access is read-only — there is no write mode to misconfigure.

The Toolkit

Ask for the outcome

The server ships its own instructions with the MCP handshake, so agents figure out the workflow on their own. These prompts work verbatim — copy one into your first session.

Map an unfamiliar database

The agent lists connections, walks the schema, and samples rows — then explains what it found.

“Using the mako tools, explore my database and explain the schema — what are the main tables and how do they relate?”

Answer a revenue question

Validated, read-only SQL against your live connection — with the query shown so you can save it.

“What were our top 10 customers by revenue last quarter? Use the mako tools and show me the SQL.”

Ship an internal dashboard

A real React app bound to a validated query, rendered headlessly to verify, delivered as a preview link.

“Build a Mako app with a bar chart of signups per week and a cohort filter. Verify it renders, then give me the preview link.”

Fix an app your teammate started

The agent reads the app's files and version history, edits, and re-renders — like a code review with hands.

“Open the app called account-health, find why the risk table is empty, and fix it.”

Read-only by design

An agent that can't break production

There is no write scope to misconfigure. Every query must be a single read-only statement, enforced inside the database where the engine supports it — Postgres read-only transactions, MySQL READ ONLY, ClickHouse readonly=2. Engines without a reliable read-only mode refuse agent queries outright. MCP keys work only on the MCP endpoint, and read-only tools are annotated so clients skip approval prompts for safe calls.

Mako — MCP
sql_execute_query — rejected
query UPDATE accounts SET plan = 'free'
✗ Mako MCP access is read-only: database writes are not supported over MCP.
query SELECT plan, count(*) FROM accounts GROUP BY 1
✓ 4 rows — 38 ms — read-only transaction
FAQ

Got questions?

Mako — FAQ
Do I need a separate AI subscription?

No — that's the point. Your agent (Claude Code, Cursor, Codex) uses the subscription you already have. Mako provides the data layer over MCP; the tokens are yours.

Can the agent modify my database?

No. Data access over MCP is read-only by design — there is no scope, flag, or setting that enables writes. Queries are validated as single read-only statements and executed inside read-only transactions where the engine supports them. Engines without a reliable read-only mode (BigQuery, MSSQL, D1/KV) refuse agent queries unless the connection itself uses read-restricted credentials.

Do I need an API key?

No. Add the URL in your client and sign in with your Mako account — you pick which workspace to grant (read-only) on the consent screen. Workspace API keys still work as a Bearer header for headless environments like CI.

Which clients are supported?

Claude (web and Claude Code), Cursor, Codex — and any other MCP client that speaks Streamable HTTP, with OAuth sign-in or a Bearer API key.

What can the agent actually do?

Discover connections and schemas, sample and query data (read-only), run long queries via saved consoles, and build full Mako apps: write files, bind validated queries as data sources, render drafts headlessly to self-verify, mint shareable preview links, and publish versions.

Does it cost Mako credits or tokens?

No. Tool results are deliberately compact (compact JSON, trimmed metadata, optional screenshot-free renders) so the agent burns as few of your tokens as possible — and none of ours.

Do old API keys work?

Keys created before MCP scopes existed keep working for the REST API but are refused on MCP. Sign in via OAuth instead, or create a new key for headless use.

Give your agent a data layer.

One URL, one sign-in. Your agent does the rest — and it can't write a single row.