Connecting AI agents to production databases has always been a security nightmare. Handing over raw credentials to an LLM-driven tool is risky, especially when you need to maintain strict audit trails for compliance. Enter db-mcp-gateway, a self-hosted Model Context Protocol (MCP) gateway designed to sit squarely between your AI agent and the database. It acts as a secure proxy, storing passwords internally while exposing only necessary data to the requesting agent.

Credential Isolation and Identity Control

The core security model relies on credential isolation, identity verification, and immutable audit logging. Database URLs and passwords never leave the gateway environment. When an AI agent sends a request via the MCP protocol, the gateway authenticates the request and executes the query, returning only result rows. This design eliminates the risk of connection strings leaking into logs, error messages, or network traffic, a common vulnerability in direct-connection setups. Authentication is driven by existing SSO providers such as Okta, Google Workspace, Entra, Authentik, and Keycloak. The gateway handles browser-based login flows, meaning no embedded browsers are required on the client side. Permissions are managed through YAML grants that specify groups, allowed databases, and actions. For example, a 'backend-devs' group might be restricted to 'production_postgres' with 'query_read' permissions, limited to 1000 rows and requiring a reason field for every query.

Deployment and Audit Trails

Every query is logged with the SSO user, group, grant, and timestamp, stored in a PostgreSQL table for easy export and compliance review. Because the gateway is the sole component holding credentials, the audit log provides a complete, tamper-evident picture of data access. Configuration-as-code is enforced by keeping permissions in a version-controlled YAML file, reviewed via pull requests. Notably, the gateway does not expose an in-band admin UI, significantly reducing the attack surface.

Key Takeaways

  • Supports PostgreSQL and MongoDB; other databases are rejected at boot time.
  • Deployable via a single Docker container using image ghcr.io/developerz-ai/db-mcp-gateway:1.1.1.
  • Real-time validation ensures users who leave corporate groups lose access immediately.
  • Open source repository available at github.com/developerz-ai/db-mcp-gateway.

The Bottom Line

This is a practical solution for teams wanting to leverage AI for database queries without compromising security. By enforcing least privilege and centralizing audit logs, db-mcp-gateway makes it viable to grant production access to AI agents without the usual credential exposure risks.