YugabyteDB MCP Server (yugabyte/yugabytedb-mcp-server) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it yet. No publisher has claimed this listing.
An MCP server implementation for YugabyteDB that allows LLMs to directly interact with your database.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
yugabyte
Source: mcp.so
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
YB_MCP_TRANSPORTstdio (default) or http.MCP_HOSTBind host for HTTP transport. Default 127.0.0.1 (loopback). Set to 0.0.0.0 to expose on all interfaces — auth becomes mandatory in that case (see MCP_AUTH_PROVIDER).MCP_PORTYB_MCP_STATELESS_HTTPtrue enables stateless Streamable-HTTP — required for multi-replica self-hosted deployments.YUGABYTEDB_URLlibpq connection string (e.g. host=… port=5433 dbname=… user=… password=…).YB_AWS_SSL_ROOT_CERT_SECRET_ARNARN of an AWS Secrets Manager secret holding the YugabyteDB TLS root certificate.YB_AWS_SSL_ROOT_CERT_KEYJSON key inside the secret when it stores multiple certs.YB_SSL_ROOT_CERT_PATHWhere to write the fetched cert. Default /tmp/yb-root.crt.YB_AWS_SSL_ROOT_CERT_SECRET_REGIONAWS region of the secret.YB_MCP_MAX_INSERT_ROWSYB_MCP_REQUIRE_WHERE_ON_UPDATEReject UPDATE without a WHERE clause. Default false.YB_MCP_REQUIRE_WHERE_ON_DELETEReject DELETE without a WHERE clause. Default false.YB_MCP_ENABLE_WRITE_QUERYrun_write_query — INSERT/UPDATE/DELETE/MERGE/TRUNCATE/DDL gated by a guardrail blocklist (destructive, disabled by default — enable with --enable-write-query or =true)MCP_AUTH_PROVIDERcognito or oidc. Leave unset to disable auth. Full OIDC/Cognito setup + per-user identity mapping is documented in [OIDC.md](OIDC.md).YB_MCP_IDENTITY_CLAIMYB_MCP_IDENTITY_MAPYB_MCP_IDENTITY_MAP_NAMEYB_MCP_POOL_MIN_SIZEYB_MCP_POOL_MAX_SIZEYB_MCP_STATEMENT_TIMEOUT_MS(SET LOCAL statement_timeout applied to everyYB_MCP_MAX_RESULT_ROWSYB_MCP_MAX_RESULT_BYTESYB_MCP_MAX_QUERY_LENMCP_ALLOWED_ORIGINSComma-separated allowlist of Origin values for DNS-rebinding defense. Case-insensitive (RFC 6454). Defaults to MCP_BASE_URL.MCP_BASE_URLPublic base URL the server is reachable at (e.g. https://mcp.example.com).YB_LOG_LEVELLog level for the yugabytedb-mcp logger family (default INFO).COGNITO_USER_POOL_IDCOGNITO_AWS_REGIONCOGNITO_CLIENT_IDCOGNITO_CLIENT_SECRETOIDC_CONFIG_URLOIDC_CLIENT_IDOIDC_CLIENT_SECRETOIDC_AUDIENCESecrets not logged
1 secret value sent to logger.warning
Redact or omit secret values from log output.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/yugabyte/yugabytedb-mcp-server)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check