Define parameterized database tools in YAML and share them with agents through MCP or Toolbox SDKs.
Good to know
Requires a running Toolbox server, a supported source, and suitable credentials.
Written by @iluxav from the project's code and releases, not by its maintainers. Last updated for v1.14.0 (2026-10-08), so it may lag behind newer releases.
Thanks. Marked useful.
Thanks. The report went to osfeed, and the line gets checked against the repository.
Connect AI agents and MCP clients to databases to query data, inspect schemas, and run configured database operations.
Requires a running Toolbox server, a supported source, and suitable credentials.
Requires a configured source and credentials with permission for the requested operations.
Requires a configured source and credentials with permission for the requested operations.
Requires a configured source and credentials with permission for the requested operations.
Requires a configured source and credentials with permission for the requested operations.
Requires a configured source and credentials with permission for the requested operations.
Requires a configured source and credentials with permission for the requested operations.
Requires a configured source and credentials with permission for the requested operations.
Requires a configured source and credentials with permission for the requested operations.
Requires a configured source and credentials with permission for the requested operations.
Requires a configured source and credentials with permission for the requested operations.
Requires a configured source and credentials with permission for the requested operations.
Requires a configured source and credentials with permission for the requested operations.
Requires an appropriate telemetry exporter and backend.
Start the Toolbox server with `--ui`; the interface uses the configured tools and source permissions.
Requires an Oracle database and connection credentials.
Requires a configured PSC endpoint and source `ipType: psc`.
Requires the Dataform project and local compilation dependencies.
Requires Looker access; file mutations require a development-mode session.
Requires a configured source and credentials with permission for the requested operations.
Requires a configured source and credentials with permission for the requested operations.
Requires a configured source and credentials with permission for the requested operations.
Requires Cloud Healthcare datasets and API permissions.
Requires a Google Cloud project and Serverless Spark permissions.
Requires a client supporting MCP prompts.
Requires a configured source and credentials with permission for the requested operations.
Requires the Gemini Data Analytics API, configured database context, and suitable cloud credentials.
Requires a configured source and credentials with permission for the requested operations.
Requires an `embeddingModel` configuration and compatible embedding provider; parameters use `embeddedBy`.
Requires the tool configuration and source access.
Generated skills require an appropriate agent runtime and access to their tools.
Requires a configured source and credentials with permission for the requested operations.
Requires Google Cloud Logging permissions.
Requires an AlloyDB Omni instance and database credentials.
Requires Google Cloud Dataproc API access.
Requires compatible authorization configuration and client support.
Requires Cloud SQL PostgreSQL with the relevant vector-assist support.
Requires Google Cloud Storage credentials and permissions for the requested operations.
Requires a TLS certificate and private key.
Requires the Data Lineage API and appropriate cloud permissions.
Requires Windows on ARM64.
Requires a configured source and credentials with permission for the requested operations.
Requires the signature and verification key; availability varies by release artifact.
Requires a configured source and credentials with permission for the requested operations.
Group definitions and endpoint selection determine the exposed collection.
The endpoint is a container/server health check.
Requires Database Insights access and supported AlloyDB query-insights configuration.
Support is source-specific; AlloyDB session read-only enforcement requires PostgreSQL 17 or newer.
Requires a configured source and credentials with permission for the requested operations.
Requires a compatible Firestore database and credentials.
Requires clients supporting MCP resources; file templates need allowed paths and enforce file access limits.
Requires an MCP Apps-compatible client and UI resources with the MCP Apps MIME type.
Set instanceType to omni and omniEndpoint; configure TLS, mTLS, or password authentication. Catalog search is unsupported.
Experimental; requires MCP 2026-07-28 and the Toolbox extension. Secure parameters cannot have defaults, authServices, or required:false.
Adds Spanner Omni connections and supports authorized BigQuery views under dataset restrictions.
Also: Looker gains Explore retrieval and LookML dashboard discovery.
v1.14.0; use the release binaries or container image and configure the required source credentials.
Seeded by @iluxav with Codex
Adds Bigtable prebuilt tools and complete or paged data-agent discovery. Reverts the source-connection deferral introduced in v1.13.0.
Also: Data-agent listing can fetch all pages; v1.13.1 removes the briefly available deferred-connection flag.
v1.13.1; use the release binaries or container image and configure the required source credentials.
Seeded by @iluxav with Codex
Adds MCP resources and interactive tool interfaces, and exposes group discovery. Adds a configurable app-verification endpoint and stricter Looker embed-URL inputs.
Also: Also adds MCP Apps, app verification, and stricter Looker embed-URL inputs.
v1.12.0; use the release binaries or container image and configure the required source credentials.
Seeded by @iluxav with Codex
Adds source-level read-only controls, FalkorDB tools, and an experimental secure-parameter extension.
v1.10.0; use the release binaries or container image and configure the required source credentials.
Seeded by @iluxav with Codex
Adds AlloyDB query insights and Bigtable administration, and renames Spanner's read-only SQL tool.
v1.9.0; use the release binaries or container image and configure the required source credentials.
Seeded by @iluxav with Codex
Adds named groups, group-based skill generation, and a server health endpoint.
Also: Startup validation and HTTP address restrictions become stricter.
v1.8.0; use the release binaries or container image and configure the required source credentials.
Seeded by @iluxav with Codex
Adds ArcadeDB tools, ClickHouse embedding parameters, and catalog data-product management.
v1.7.0; use the release binaries or container image and configure the required source credentials.
Seeded by @iluxav with Codex
Adds richer Looker query parameters and catalog data-product tools; release binaries gain signatures.
v1.6.0; use the release binaries or container image and configure the required source credentials.
Seeded by @iluxav with Codex
Enables offline skill generation, source-level access restrictions, and selected prebuilt toolsets.
Also: MCP auth, internal HTTP destinations, and AlloyDB Omni password configuration may require changes.
v1.5.0; use the release binaries or container image and configure the required source credentials.
Seeded by @iluxav with Codex
Adds Data Lineage tools and Windows ARM64 support; generic token validation is stricter.
v1.4.0; use the release binaries or container image and configure the required source credentials.
Seeded by @iluxav with Codex
Adds tool-level authorization scopes and multi-database Cloud SQL execution; toolset boundaries are enforced.
v1.3.0; use the release binaries or container image and configure the required source credentials.
Seeded by @iluxav with Codex
Adds Cloud Storage operations, a TLS listener, and BigQuery query-cost limits.
v1.2.0; use the release binaries or container image and configure the required source credentials.
Seeded by @iluxav with Codex
Covers v0.32.0, the first stable v1.0.0, and v1.1.0: updates the Go module name, adds data-agent and vector-search tools, and separates Looker Git-branch operations.
Also: Adds Cloud SQL PostgreSQL vector assist and repairs Looker configuration.
v1.1.0; use the release binaries or container image and configure the required source credentials.
Seeded by @iluxav with Codex
Adds generic MCP authorization and disables the legacy API by default; configuration names and CLI flags change.
v0.31.0; use the release binaries or container image and configure the required source credentials. Beta release; the public API can change.
Seeded by @iluxav with Codex
Splits prebuilt toolsets by task and replaces the telemetry metric surface. Adds configuration migration and explicit server startup commands, and generates separate skills per toolset.
Also: Prebuilt toolsets and metric names change; source builds require newer Go.
v0.30.0; use the release binaries or container image and configure the required source credentials. Beta release; the public API can change.
Seeded by @iluxav with Codex
Adds Dataproc inspection, Redis TLS, and more LookML development tools.
v0.28.0; use the release binaries or container image and configure the required source credentials. Beta release; the public API can change.
Seeded by @iluxav with Codex
Adds direct CLI invocation and skill generation, with new database and logging integrations.
Also: Flat configuration is available while nested files remain compatible.
v0.27.0; use the release binaries or container image and configure the required source credentials. Beta release; the public API can change.
Seeded by @iluxav with Codex
Adds Cloud SQL backup tools and multiple prebuilt configurations; tool names and GDA input names require migration.
v0.26.0; use the release binaries or container image and configure the required source credentials. Beta release; the public API can change.
Seeded by @iluxav with Codex
Adds Snowflake tools and embedding models for PostgreSQL parameters.
Also: Cloud SQL MySQL prebuilt configurations now permit IAM without user/password variables.
v0.25.0; use the release binaries or container image and configure the required source credentials. Beta release; the public API can change.
Seeded by @iluxav with Codex
Adds Gemini Data Analytics integration and permits combined prebuilt and custom configurations.
v0.24.0; use the release binaries or container image and configure the required source credentials. Beta release; the public API can change.
Seeded by @iluxav with Codex
Adds Spark batch creation and database inspection tools; BigQuery numeric output becomes decimal strings. Adds MariaDB support and PostgreSQL statistics; Spark responses gain console and logging links.
Also: Also adds Spark batch creation, PostgreSQL statistics, and new output formats.
v0.23.0; use the release binaries or container image and configure the required source credentials. Beta release; the public API can change.
Seeded by @iluxav with Codex
Adds PostgreSQL operational tools and changes Spanner table metadata to nested JSON.
v0.21.0; use the release binaries or container image and configure the required source credentials. Beta release; the public API can change.
Seeded by @iluxav with Codex
Adds database integrations, Spark batch inspection, and broader schema inspection. Adds configurable prompts and PostgreSQL inspection tools.
Also: Also adds Elasticsearch, MindsDB, SingleStore, Cloud Healthcare, and Spark tools, with BigQuery and AlloyDB upgrade notes.
v0.20.0; use the release binaries or container image and configure the required source credentials. Beta release; the public API can change.
Seeded by @iluxav with Codex
Adds LookML file tools and parameter constraints; HTTP tools accept the full 2xx success range.
v0.18.0; use the release binaries or container image and configure the required source credentials. Beta release; the public API can change.
Seeded by @iluxav with Codex
Adds Oracle tools and PSC connections, and extends Looker and BigQuery operations.
Also: Also adds local Dataform compilation and fixes MySQL table listing.
v0.17.0; use the release binaries or container image and configure the required source credentials. Beta release; the public API can change.
Seeded by @iluxav with Codex
YAML defines sources, parameterized tools, and named toolsets. SDKs load these tools for applications, and configuration reloads dynamically by default.
v0.16.0; use the release binaries or container image and configure the required source credentials.
Seeded by @iluxav with Codex