WoWSQL

com.wowsqlv1.0.0更新于 Oct 5, 2026

Managed Postgres MCP: projects, SQL, docs search, and storage buckets via OAuth.

已验证Streamable HTTP可网页运行Files & StorageDatabases

概览

AI 生成的概览

托管 Postgres 的 MCP 服务器,让助手通过 OAuth 操作 WoWSQL 项目、执行 SQL、搜索文档并管理存储桶。

功能
WoWSQL 是面向托管 Postgres 平台的远程 HTTP MCP 端点。据描述,它提供项目、SQL 执行、文档搜索和存储桶相关工具。README 说明其采用带 PKCE 的 OAuth 2.0 授权码流程,MCP 进程作为 OAuth 受保护资源,并将授权元数据代理到 WoWSQL API。请求是以 Bearer 令牌向 /mcp 发送的 JSON-RPC POST,可通过带参数的 URL 限定项目和只读模式。
适用场景
当助手需要查看或查询 WoWSQL 托管的 Postgres 项目、查阅平台文档或管理存储桶,而不想离开聊天客户端时使用。适合已在使用 WoWSQL、希望通过 Cursor 等 MCP 客户端进行数据库操作的团队。
运行要求
可使用 远程端点,或基于 @wowsql/mcp-server-wowsql 包自建 Node.js 进程。需要针对 WoWSQL API 的带 PKCE 的 OAuth 2.0 授权码流程,以及用于 POST /mcp 的 Bearer 访问令牌。自建需配置 WOWSQL_API_BASE,可选 WOWSQL_OAUTH_ISSUER_URL、MCP_PUBLIC_URL、PORT 或 MCP_PORT、MCP_HOST;令牌校验还要求 WoWSQL API 后端在运行。
安装前请注意
该服务器可执行 SQL 并管理存储桶,可能读取、写入或删除 WoWSQL 项目中的数据。尽量使用带 read_only=true 的限定 URL。MCP_ALLOW_UNAUTHENTICATED=true 会跳过 Bearer 校验,文档标注为不安全,仅限本地测试。OAuth 令牌和 API 基础地址属敏感信息,.env.local 不应提交到版本库。

安装

在 SourceWeft 中

  1. 打开 控制台中的 WoWSQL,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。

其他 MCP 客户端

把它添加到你客户端的 mcpServers 配置中。

{
  "mcpServers": {
    "mcp": {
      "type": "http",
      "url": "https://mcp.wowsql.com/mcp"
    }
  }
}

README

WoWSQL MCP (Model Context Protocol)

wowsql-style HTTP MCP with OAuth 2.0 authorization code + PKCE on the WoWSQL API.

Packages

PackageDescription
packages/mcp-server-wowsql@wowsql/mcp-server-wowsql — HTTP MCP server, createToolSchemas() for AI SDK

Quick start (self-hosted MCP process)

From the repo root:

bash
cd mcpnpm installnpm run buildnpm start

Authentication (OAuth 2.0 + MCP)

The MCP process is an OAuth protected resource (not the authorization server):

  1. POST /mcp requires Authorization: Bearer <access_token> unless MCP_ALLOW_UNAUTHENTICATED=true (dev only).
  2. Missing/invalid tokens get 401 with WWW-Authenticate: Bearer ... resource_metadata="<url>" so MCP clients (Cursor, etc.) can start OAuth.
  3. Token validation calls your API: GET {WOWSQL_API_BASE}/api/v1/auth/me with the same Bearer token (must match the JWT issued by WoWSQL OAuth or login).
  4. Discovery
    • Authorization server metadata (WoWSQL API): GET {WOWSQL_API_BASE}/.well-known/oauth-authorization-server
    • Protected resource metadata (this MCP host): GET /.well-known/oauth-protected-resource/mcp

Cursor / Electron: OAuth metadata is rewritten so authorization_endpoint, token_endpoint, and registration_endpoint point at this MCP host (e.g. http://localhost:8787/...). The MCP process proxies those requests to WOWSQL_API_BASE, so the IDE does not need a working direct fetch to localhost:8000 for OAuth (which often shows up as fetch failed). You still need FastAPI running on WOWSQL_API_BASE so the proxy can reach it.

If MCP_PUBLIC_URL is unset, PRM and 401 resource_metadata are derived from each request’s Host (and X-Forwarded-Proto), so http://localhost:8787/mcp and http://127.0.0.1:8787/mcp each get matching metadata. Set MCP_PUBLIC_URL when the MCP is behind a reverse proxy or you need a single fixed origin in production.

VariableDefaultPurpose
WOWSQL_API_BASEhttps://api.wowsql.comWoWSQL FastAPI base URL (no trailing slash).
WOWSQL_OAUTH_ISSUER_URLsame as WOWSQL_API_BASEissuer advertised in PRM (authorization_servers).
MCP_PUBLIC_URLunsetIf set, fixed public origin (no /mcp path) for OAuth PRM + WWW-Authenticate; overrides Host-based derivation.
MCP_ALLOW_UNAUTHENTICATEDunsetIf true, skips Bearer check (insecure; local testing only).
PORT / MCP_PORT8787MCP HTTP port.
MCP_HOST0.0.0.0Bind address.

Option A — .env / .env.local (recommended)
Copy packages/mcp-server-wowsql/.env.example to .env or .env.local in that folder. The CLI loads .env, then .env.local (overrides), then the process cwd .env. Use .env.local for machine-specific values (e.g. http://localhost:8000) without committing them.

bash
cd mcp/packages/mcp-server-wowsqlcp .env.example .env# edit .env — set WOWSQL_API_BASE to your APInpm run build   # from mcp root: npm run build -w @wowsql/mcp-server-wowsqlnpm start

Option B — shell (no file)

PowerShell:

powershell
cd mcp$env:WOWSQL_API_BASE="http://localhost:8005"$env:PORT="8787"npm start

bash / zsh:

bash
cd mcpexport WOWSQL_API_BASE=http://localhost:8005export PORT=8787npm start

Endpoints

  • MCP (Streamable HTTP): POST http://localhost:8787/mcp — JSON-RPC body; append query params for scoping. MCP clients (Cursor, etc.) use this.
  • MCP (browser): GET http://localhost:8787/mcp returns 401 with a short “not authorized” page (no public metadata). The protocol is POST JSON-RPC with Authorization: Bearer.
  • Health: GET http://localhost:8787/health

Example scoped URL for clients:

http://localhost:8787/mcp?project_ref=<uuid-or-slug>&read_only=true&features=database,docs

OAuth (API)

  • Metadata: GET https://api.wowsql.com/.well-known/oauth-authorization-server
  • Authorize (redirect to dashboard): GET /api/v1/auth/oauth/mcp/authorize
  • Approve (logged-in user): POST /api/v1/auth/oauth/mcp/approve
  • Token: POST /api/v1/auth/oauth/mcp/token (grant_type=authorization_code or refresh_token)

Dashboard consent UI: /mcp/oauth on the app (see dashboard/app/mcp/oauth/page.tsx).

Deploy mcp.wowsql.com

  1. Run this Node service behind TLS (reverse proxy or platform of your choice).
  2. Set WOWSQL_API_BASE / WOWSQL_OAUTH_ISSUER_URL to https://api.wowsql.com (not 127.0.0.1:8000/8001). Blue/green flips change the backend host port; the public hostname always follows the active slot via NPM.
  3. Set MCP_PUBLIC_URL=https://mcp.wowsql.com.
  4. Point DNS mcp.wowsql.com to the service; health check: GET /health.
  5. Ensure CORS and OAuth redirect_uri values include your MCP client callbacks (see oauth_clients seed + env).

EC2 blue/green: ./deploy/ec2-blue-green.sh mcp sets those env vars automatically.

npm publish

bash
cd mcp/packages/mcp-server-wowsqlnpm version patchnpm publish --access public

Requires an npm org scope @wowsql (or change name in package.json).

来源:README.md,提交 98f0793

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v1.0.0最新Oct 5, 2026