Connect SQL Server to MCP for Claude, ChatGPT and Cursor
Connect SQL Server to MCP with AgentUI, whether the database runs in the cloud or on a server in your office. You describe the tools you want, like "overdue invoices for a customer", and the AI writes them. Each person then adds one link to the assistant they already use and signs in with their own account.
Nothing to host, no port to open. Revoke any connection from the panel.
Northwind Foods has 3 invoices past 30 days, totalling $11,175.50. The oldest is 47 days late.
How to connect SQL Server to MCP in three steps
Connect the database
A cloud SQL Server connects through the SQL integration. One on an office server gets the AgentUI Connector, which dials out over HTTPS, so your firewall stays as it is.
Describe the tools
Tell the builder AI what each tool should do. It writes the tool, with a fixed query and the inputs it needs, and you switch it on or off in the MCP panel.
Add one link to the assistant
Every app gets its own MCP address. Paste it into Claude, ChatGPT, Cursor, Codex or Windsurf, sign in, and the tools show up in the chat.
Custom tools instead of handing the AI raw SQL
A tool is a named action with a query you approved, so the assistant asks for what it needs and can't run anything else. Each tool can be marked read-only, and an app can hold up to 100 of them. A few examples:
- tool_overdue_invoicesInvoices more than 30 days late for one customer
- tool_stock_by_warehouseOn-hand quantity for a product, per warehouse
- tool_late_shipmentsOrders that shipped after their due date this week
- tool_customer_summaryOpen orders, balance and last purchase for one account
One SQL Server MCP server for every AI your team uses
Nobody has to switch assistants. Sales can stay in ChatGPT, finance in Claude and the developer in Cursor, and they all call the same tools against the same database.
What IT will want to know before you connect SQL Server to MCP
- Each person signs in with their own account. There's no shared API key sitting in someone's config file.
- Connections can be view-only, and you can turn off "Assistants may change data" for a whole environment.
- Every connection is listed with when it was last used. Revoke one and its calls stop.
- Through the on-prem connector, queries can only read: SELECT and WITH run, and each one is rolled back. The database password never leaves your server.
Limits worth knowing
- The on-prem connector reads Microsoft SQL Server only, up to 1,000 rows and 30 seconds per query.
- Each MCP call has 30 seconds to answer, so tools should ask for a summary, not a whole table.
- Queries to SQL Server run with the app's connection, not each person's database login. Use a tool's access rule to decide who can call it.
- SQL Server connections come with the Team plan and up.
What happens after you connect
If the database is on an office server, your IT person gets a Word setup guide with screenshots and installs one service. We can join that call. Then you describe your first tool, test it in Claude or ChatGPT, and add the next one when someone asks for it. A real person stays on your account, so the tools don't depend on one employee.
Go deeper
Give your team's AI one tool it can trust
Connect SQL Server, describe the first tool, and paste the link into Claude or ChatGPT. Book a call if you'd rather build it with us.
Nothing to host, no port to open. Revoke any connection from the panel.