{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_tv2aa2xvzhng","handle":"django-mcp-sql","url":"https://wellknown.network/agents/django-mcp-sql","links":{"self":"https://wellknown.network/agents/django-mcp-sql/record.json","html":"https://wellknown.network/agents/django-mcp-sql","markdown":"https://wellknown.network/agents/django-mcp-sql/record.md","api":"https://wellknown.network/api/v1/agents/django-mcp-sql","status":"https://wellknown.network/api/v1/agents/django-mcp-sql/status","claim":"https://wellknown.network/agents/django-mcp-sql/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/django-mcp-sql/claim.json","badge":"https://wellknown.network/agents/django-mcp-sql/badge.svg","openapi":"https://wellknown.network/openapi.json"},"ard":{"identifier":"urn:air::server:django-mcp-sql","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"django-mcp-sql","summary":"Read-only PostgreSQL surface for an LLM agent over the MCP protocol, with defense-in-depth at parser, executor, DB-role, and transport layers.","description":"# django-mcp-sql\n\n[![PyPI](https://img.shields.io/pypi/v/django-mcp-sql)](https://pypi.org/project/django-mcp-sql/)\n[![CI](https://github.com/thepapermen/django-mcp-sql/actions/workflows/ci.yml/badge.svg)](https://github.com/thepapermen/django-mcp-sql/actions/workflows/ci.yml)\n[![codecov](https://codecov.io/gh/thepapermen/django-mcp-sql/branch/main/graph/badge.svg)](https://codecov.io/gh/thepapermen/django-mcp-sql)\n[![django packages](https://img.shields.io/badge/Django%20Packages-django--mcp--sql-8c3c26.svg)](https://djangopackages.org/packages/p/django-mcp-sql/)\n[![Python versions](https://img.shields.io/pypi/pyversions/django-mcp-sql)](https://pypi.org/project/django-mcp-sql/)\n[![License: MIT](https://img.shields.io/pypi/l/django-mcp-sql)](https://github.com/thepapermen/django-mcp-sql/blob/main/LICENSE)\n[![Development status](https://img.shields.io/pypi/status/django-mcp-sql)](https://pypi.org/project/django-mcp-sql/)\n[![Ruff](https://img.shields.io/endpoint?url=https://raw.githubusercontent.com/astral-sh/ruff/main/assets/badge/v2.json)](https://github.com/astral-sh/ruff)\n[![Checked with mypy](https://www.mypy-lang.org/static/mypy_badge.svg)](https://mypy-lang.org/)\n\nLet an LLM agent — like Claude Code — run **read-only** SQL against your\nPostgreSQL database over the\n[Model Context Protocol](https://modelcontextprotocol.io/), without handing it\na database login or the ability to write anything.\n\n> **In one line:** the self-hosted, Postgres-only safe-execution-and-access-control\n> layer that gives Django shops the part of [QueryBear](https://querybear.com) a\n> SaaS can't — an agent reading a precisely-scoped slice of your database, with\n> your database credentials never leaving your infrastructure and the agent able\n> to reach only the slice you expose, never a login or the rest of your data.\n> Bring your own SQL-writing agent. ([How it compares](#how-it-compares) — and\n> [where your data actually goes](#where-your-data-actually-goes).)\n\n**It already runs in prod…","publisher":{"name":"Ivan Kharlamov, Claude (Anthropic)","url":null},"homepage":"https://github.com/thepapermen/django-mcp-sql/tree/main/docs","repository":"https://github.com/thepapermen/django-mcp-sql/blob/main/CHANGELOG.md","version":"0.1.0b5","license":null,"protocols":["mcp"],"tags":["django","mcp","postgresql","llm-agent","oauth","read-only-sql"],"pricing":null,"endpoints":[{"url":"pypi:django-mcp-sql","type":"package_pypi","auth":null,"probeable":false}],"skills":null,"tools":null,"extra":null,"attribution":{"kind":"pypi","name":"pypi","repoUrl":"pypi","summary":"pypi","version":"pypi","description":"pypi","homepageUrl":"pypi","publisherName":"pypi"}},"derived":{"capabilities":[{"slug":"data.database","name":"Databases","confidence":1,"provenance":"declared"},{"slug":"security.identity","name":"Identity & Access","confidence":1,"provenance":"declared"},{"slug":"dev.package-management","name":"Packages & Dependencies","confidence":0.768,"provenance":"derived"}],"categories":["data","dev","security"],"language":"en"},"observed":{"status":"unknown","statusReason":"Distributed as a package to run locally; no network endpoint to check.","lastOkAt":null,"lastProbedAt":null,"statusComputedAt":null,"reliability30d":null,"latestObservations":[],"tools":null,"package":{"name":"django-mcp-sql","registry":"pypi","observedAt":"2026-09-09T14:33:24.602Z","publishedAt":"2026-07-01T18:05:12.980659Z","latestVersion":"0.1.0b5"}},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"pypi","key":"django-mcp-sql","url":"https://pypi.org/project/django-mcp-sql/","firstSeenAt":"2026-09-09T14:31:48.299Z","fetchedAt":"2026-09-09T14:31:48.299Z","normalizedAt":"2026-09-09T14:31:48.299Z"}]},"firstSeenAt":"2026-09-09T14:31:48.299Z","updatedAt":"2026-09-09T14:33:24.602Z"}