AI agents that need to read from production databases must do so without exposing credentials. db-mcp-gateway is a self hosteded MCP gateway that sits between an AI agent and a database. It stores passwords inside the gateway, enforces identity checks, and records every query. The result is a system that lets developers and platform teams grant limited access while keeping audit trails for compliance.
The gateway follows three core principles: credential isolation, identity and access control, and immutable audit logging. Each principle is implemented with concrete mechanisms that can be inspected in the source code.
Database URLs and passwords never leave the gateway. An AI agent sends a request using the MCP protocol, the gateway authenticates the request, and then runs the query against the database. The response contains only result rows, never a connection string. This eliminates the risk of credential leakage in logs, error messages, or network traffic.
Authentication is driven by SSO providers such as Okta, Google Workspace, Entra, Authentik and Keycloak. The gateway performs a browser based login flow, so no embedded browsers are required. Permissions are expressed as YAML grants. A grant specifies a group, the databases it may access, allowed actions, and optional constraints such as schemas, row limits and a required reason field.
grants:
- group: backend-devs
databases: [production_postgres]
actions: [query_read]
constraints:
schemas: [public, analytics]
row_limit: 1000
require_reason: true
Group based permissions let you map corporate groups to database roles. Real time validation ensures that a user who leaves a group loses access immediately.
Every query is logged with the SSO user, group, grant and timestamp. The logs are stored in a PostgreSQL table that can be exported for compliance reviews. Because the gateway is the only component that knows the credentials, the audit log provides a complete picture of who accessed what data and when.
Permissions live in a YAML file that can be version controlled. Changes are reviewed through pull requests, ensuring that any modification to database access is auditable. The gateway does not expose an in-band admin UI, which reduces the attack surface.
Deploying db-mcp-gateway is straightforward. A single Docker container runs the gateway, and a configuration file mounts into the container. The gateway supports PostgreSQL and MongoDB; other databases are rejected at boot time.
docker pull ghcr.io/developerz-ai/db-mcp-gateway:1.1.1
docker run -p 8080:8080 -v $(pwd)/config.yaml:/app/config.yaml ghcr.io/developerz-ai/db-mcp-gateway:1.1.1
The container stores its state and audit logs in PostgreSQL, making it easy to integrate with existing monitoring and backup pipelines.
db-mcp-gateway delivers a security first approach to AI driven database access. By isolating credentials, integrating with existing SSO providers, and recording every query, it enables teams to adopt AI agents without compromising security or compliance. The open source repository is available at https://github.com/developerz-ai/db-mcp-gateway.