Remote MCP server vs open-source MCP server
ClickHouse offers two MCP servers.
The remote MCP server provides the richest integration with ClickHouse Cloud, including service management, backup monitoring, ClickPipe visibility, and billing data, with no infrastructure to manage.
For self-hosted ClickHouse instances, see the open-source MCP server guides.
Enabling the remote MCP server
The remote MCP server must be enabled per service before it can accept connections. In the ClickHouse Cloud console, open your service, click the Connect button, select MCP, and enable it. Enabling or disabling the remote MCP server requires thecontrol-plane:service:manage-mcp permission (see Console roles and permissions).
For detailed steps with screenshots, see the setup guide.
Endpoint
Once enabled, the remote MCP server is available at:Authentication
The remote MCP server supports two authentication methods:- OAuth 2.0: Recommended for interactive clients. When an MCP client connects for the first time, it opens a browser window for the user to sign in with their ClickHouse Cloud credentials. Access is scoped to the organizations and services the authenticated user has permission to access.
-
ClickHouse Cloud API key: Intended for remote, headless, and automated environments where a browser-based OAuth flow is not practical. Send the API key ID and secret using HTTP Basic authentication:
Safety
All tools exposed by the remote MCP server are read-only. Each tool is annotated withreadOnlyHint: true in its MCP metadata. No tool can modify data, alter service configuration, or perform any destructive operation.