Reported issues for MCP Toolbox for Databases
Pod holds 24 of 326 problems reported by people outside the maintainer team. Issues filed by the project's own owners, members and collaborators are excluded entirely — a maintainer's release checklist is not a warning to a prospective user.
Back to MCP Toolbox for Databases.
Most discussed
feat: Add policy-based automatic PII detection and dynamic masking
Feature Request
Is your feature request related to a problem? Please describe. Enterprises using MCP Toolbox to connect AI agents to databases face significant privacy compliance challenges (GDPR, CCPA, HIPAA, etc.) when query results contain personally identifiable information (PII). While MCP Toolbox provides secure access controls, it lacks intelligent output filtering to automatically detect and mask PII in query results before they reach LLMs or applications.
Describe the soluti
Read the thread · 2026-06-06 · open · outside contributor · 17 comments
MCP OAuth flow ignores PRM authorization_servers and user is redirected to /authorize → 404
Prerequisites
- I've searched the current open issues
- I've updated to the latest version of Toolbox
Toolbox version
1.2.0
Environment
- MCP server:
googleapis/mcp-toolboxv1.2.0 with--prebuilt=lookerconfigured in EKS - Authorization server: Looker (
https://<authorization_server_url>.com) - Reproduction date: 2026-05-22
prm.json: |
{
"resource": "https://<mcp_resource_url>/mcp",
"authorization_servers": ["https://<authorization_s
[Read the thread](https://github.com/googleapis/mcp-toolbox/issues/3278) · 2026-05-22 · open · external user · 15 comments
### Default DNS-rebinding protection allows all domains by defaults
### Expected Behavior
The googleapis/genai-toolbox doesn't, by default, validate the `Origin` header when requests are sent to it, thus violating one of the clauses of both the 2025-06-18 and 2025-11-25 MCP specifications.
- 2025-06-18: [Base Protocol > Transports: 2.0.1 Security Warning](https://modelcontextprotocol.io/specification/2025-06-18/basic/transports#security-warning)
- 2025-11-25: [Base Protocol > Transports: 2.0.1 Security Warning](https://modelcontextprotocol.io/specification/2
[Read the thread](https://github.com/googleapis/mcp-toolbox/issues/3113) · 2026-04-22 · closed · external user · 13 comments
### ArangoDB
### Prerequisites
- [x] Search the [current open issues](https://github.com/googleapis/genai-toolbox/issues)
### What are you trying to do that currently feels hard or impossible?
Describe the data source you’d like to see supported
ArangoDB is a native multi‑model database that combines document, graph, and key/value data models in a single distributed engine, with a unified query language (AQL) and first‑class support for joins and traversals across different models. It is widely used in AI
[Read the thread](https://github.com/googleapis/mcp-toolbox/issues/2290) · 2026-01-11 · open · external user · 13 comments
### Feature Request: Add new source type cloud-logging for querying Google Cloud logs
### Prerequisites
- [x] Search the [current open issues](https://github.com/googleapis/genai-toolbox/issues)
### What are you trying to do that currently feels hard or impossible?
Add a new source type called cloud-logging to the MCP Toolbox that enables agents and tools to directly query and analyze logs from Google Cloud Logging (formerly Stackdriver).
This source should allow users to:
Query logs using Cloud Logging’s advanced filters.
Stream or batch retrieve log entries for a given re
[Read the thread](https://github.com/googleapis/mcp-toolbox/issues/1772) · 2025-10-23 · closed · external user · 12 comments
### Using ToolboxClient from an ADK agent
### Prerequisites
- [x] Search the [current open issues](https://github.com/googleapis/genai-toolbox/issues)
### Question
I am currently running MCP Toolbox (v0.9.0) on Cloud Run utilising toolbox-core (v0.4.0) within an ADK agent which is deployed to Agent Engine.
When using locally with adk web as well as when deployed to Agent Engine and Agentspace everything works when using the ToolboxSyncClient and auth_methods.get_google_id_token methods.
When it is deployed I am seeing some weird
[Read the thread](https://github.com/googleapis/mcp-toolbox/issues/955) · 2025-07-22 · closed · external user · 16 comments
### Validating parameters before hitting the query
### Prerequisites
- [x] Search the [current open issues](https://github.com/googleapis/genai-toolbox/issues)
### Question
As in most real world consumption of this project, LLMs will be used to trigger these tools. LLMs might pick incorrect parameter or we might want to alter the parameters on some conditions. In a fastmcp implementation, we can put the validation/alteration inside the tool but here as only queries can be fired, what's the best place to put the validation/alteration in? Pleas
[Read the thread](https://github.com/googleapis/mcp-toolbox/issues/708) · 2025-06-13 · closed · external user · 14 comments
### Support usage of `parameters` fields with non-filtering parameters
### Prerequisites
- [x] I've searched the current open issues
- [x] I've updated to the latest version of Toolbox
### Toolbox version
0.4.0+binary.linux.amd64.0.4.0.4ed16ccd18768ac02402356f9660526b3452418b
### Environment
1. Linux aaronpc2025 6.8.0-59-generic #61-Ubuntu SMP PREEMPT_DYNAMIC Fri Apr 11 23:16:11 UTC 2025 x86_64 x86_64 x86_64 GNU/Linux
2. Downloaded from https://github.com/googleapis/genai-toolbox/releases
### Client
_No response_
### Expected Behavior
When running a mysql
[Read the thread](https://github.com/googleapis/mcp-toolbox/issues/535) · 2025-05-06 · closed · external user · 14 comments
## Most recent
### feat(source/vertica): add Vertica database source and SQL tools
### Prerequisites
- [x] Search the [current open issues](https://github.com/googleapis/mcp-toolbox/issues)
### What are you trying to do that currently feels hard or impossible?
I would like to add Vertica support to MCP Toolbox.
Vertica is a columnar analytical database commonly used for large-scale data warehouse and analytics workloads.
Currently, MCP Toolbox does not have a native Vertica source. Because of this, users cannot:
- Define custom SQL tools backed by Vertica
- Use Toolbox c
[Read the thread](https://github.com/googleapis/mcp-toolbox/issues/3883) · 2026-08-27 · open · external user · 0 comments
### [Feature Request] Allow disabling or configuring export interval for Cloud Trace spans (TraceService/BatchWriteSpans)
### Prerequisites
- [x] Search the [current open issues](https://github.com/googleapis/mcp-toolbox/issues)
### Question
Issue Description
Environment Details
Tool: MCP Toolbox
Version: v1.2.0
Connector/Database: BigQuery
Feature: Telemetry (Tracing)
Problem Description
After enabling the telemetry feature in mcp-toolbox (v1.2.0) while using the BigQuery tool, the system repeatedly issues span write requests to Google Cloud Trace (google.devtools.cloudtrace.v2.TraceService/BatchWriteSpa
[Read the thread](https://github.com/googleapis/mcp-toolbox/issues/3862) · 2026-08-24 · open · external user · 1 comment
### Reloading config file drops all prebuilt tools from server
### Prerequisites
- [x] I've searched the current open issues
- [x] I've updated to the latest version of Toolbox
### Toolbox version
1.9.0
### Environment
1. OS type and version: macOS 26.6.2
2. How are you running Toolbox: As a downloaded binary (e.g. from `curl -O https://storage.googleapis.com/mcp-toolbox-for-databases/v$VERSION/linux/amd64/toolbox`)
### Client
### Expected Behavior
Modifying a custom configuration file should trigger a reload and update the custom configs, while
[Read the thread](https://github.com/googleapis/mcp-toolbox/issues/3859) · 2026-08-21 · closed · outside contributor · 0 comments
### feat(source/db2): add support for IBM Db2 database source and tools
### Prerequisites
- [x] Search the [current open issues](https://github.com/googleapis/mcp-toolbox/issues)
### What are you trying to do that currently feels hard or impossible?
We want to connect AI agents, IDE assistants (such as Google Antigravity, Gemini CLI, Claude Code), and custom production applications to IBM Db2 databases via MCP (Model Context Protocol).
IBM Db2 is widely adopted across enterprise environments (e.g., banking, financial services, retail, and insurance) for mission-
[Read the thread](https://github.com/googleapis/mcp-toolbox/issues/3858) · 2026-08-21 · open · external user · 3 comments
### Add a mongodb-list-collections tool to discover collections in a database
### Prerequisites
- [x] Search the [current open issues](https://github.com/googleapis/mcp-toolbox/issues)
### What are you trying to do that currently feels hard or impossible?
After merging https://github.com/googleapis/mcp-toolbox/pull/3715, a single MongoDB tool config can leave collection out and have the agent supply it at runtime (https://github.com/googleapis/mcp-toolbox/issues/1679). But that only works if the agent already knows the collection name. There's no way for it to ask "wha
[Read the thread](https://github.com/googleapis/mcp-toolbox/issues/3848) · 2026-08-19 · open · outside contributor · 4 comments
### initialize with protocolVersion 2026-07-28 returns -32601 instead of negotiating (behaviour changed in 1.8.0)
## Summary
An `initialize` request carrying `"protocolVersion": "2026-07-28"` is answered with `-32601 invalid method initialize` on **1.8.0** and **1.9.0**. On **1.7.0** the same request negotiates normally and the server replies with `2025-11-25`.
The graceful downgrade is otherwise intact — `2026-07-28` is the only value that fails. Unknown versions still negotiate fine, which is what makes this look like a gap rather than a policy: the version is known well enough to be routed, and being k
[Read the thread](https://github.com/googleapis/mcp-toolbox/issues/3834) · 2026-08-17 · closed · external user · 4 comments
### Auth (Generic) - Allow ForceIntrospection, pass optional Client ID/Secret on Introspect
### Prerequisites
- [x] Search the [current open issues](https://github.com/googleapis/mcp-toolbox/issues)
### What are you trying to do that currently feels hard or impossible?
Today, for JWT validation, it assumes that JWKS validation should be sufficient. However there are some identity providers who require introspection validation on the access_token. Additionally, some identity providers require a client id / client secret are provided as part of the introspection request.
### Sugge
[Read the thread](https://github.com/googleapis/mcp-toolbox/issues/3832) · 2026-08-15 · open · external user · 3 comments
### Looker tool to import dashboard from lookml
### Prerequisites
- [x] Search the [current open issues](https://github.com/googleapis/mcp-toolbox/issues)
### What are you trying to do that currently feels hard or impossible?
Exposing this existing Looker API as a tool is very valuable for non developers to be able to create rich dashboards via AI generated code without needing to execute tons of tools calls to iteratively construct a looker dashboard:
https://docs.cloud.google.com/looker/docs/reference/looker-api/latest/methods/Dashboard
[Read the thread](https://github.com/googleapis/mcp-toolbox/issues/3825) · 2026-08-14 · open · external user · 0 comments
### refactor(tools): move Annotations field into tools.ConfigBase
## Description
Currently, `Annotations *tools.ToolAnnotations` is individually defined on every tool's `Config` struct across all packages (e.g., in `internal/tools/<source>/<tool>/<tool>.go`).
Since `ToolAnnotations` (`readOnlyHint`, `destructiveHint`, `idempotentHint`, `openWorldHint`) are standard MCP metadata applicable to all tools, this field should be centralized in `tools.ConfigBase` alongside `Name`, `Description`, `AuthRequired`, and `ScopesRequired`.
Because every tool's `Config`
[Read the thread](https://github.com/googleapis/mcp-toolbox/issues/3809) · 2026-08-12 · open · outside contributor · 1 comment
### UUIDv7 serialized to Array of numbers.
### Prerequisites
- [x] I've searched the current open issues
- [x] I've updated to the latest version of Toolbox
### Toolbox version
1.8.0
### Environment
1. OS type and version: (output of `uname -a`)
2. How are you running Toolbox:
- As a downloaded binary (e.g. from `curl -O https://storage.googleapis.com/mcp-toolbox-for-databases/v$VERSION/linux/amd64/toolbox`)
- As a container (e.g. from `us-central1-docker.pkg.dev/database-toolbox/toolbox/toolbox:$VERSION`)
- Compiled from sou
[Read the thread](https://github.com/googleapis/mcp-toolbox/issues/3795) · 2026-08-08 · closed · external user · 0 comments
### error: unable to parse commented lines in tools.yaml
### Prerequisites
- [x] I've searched the current open issues
- [x] I've updated to the latest version of Toolbox
### Toolbox version
1.8.0
### Environment
error logs
mcp-toolbox | 2026-08-08T18:25:08.595565905Z ERROR "unable to parse config file at "/app/tools.yaml": error parsing environment variables: environment variable not found: "YOUR_GOOGLE_CLIENT_ID" (line 18, column 17)" mcp-toolbox | Error: unable to parse config file at "/app/tools.yaml": error parsing environment v
Read the thread · 2026-08-08 · closed · external user · 1 comment
Add create_merge_query to Looker MCP
Prerequisites
- Search the current open issues
What are you trying to do that currently feels hard or impossible?
I want to merge different explores, this could be done through: create_merge_query
Suggested Solution(s)
No response
Alternatives Considered
No response
Additional Details
No response
Read the thread · 2026-07-31 · open · outside contributor · 0 comments
Starburst Ranger Policies
Prerequisites
- Search the current open issues
Question
Hi Team,
How can we integrate Starburst ranger policies. Before each statement execution, we have to call set session. Is it possible.
Code
No response
Additional Details
No response
Read the thread · 2026-07-30 · open · external user · 4 comments
bigquery-get-table-info: schema serialization emits ~250KB for a single wide table (mostly zero-valued fields), overflowing agent context
Summary
bigquery-get-table-info serializes the full BigQuery schema struct including every zero-valued attribute for every field. On wide or nested tables this produces responses large enough to blow past an MCP client's token limit, for information that compresses to a small fraction of the size. Since the tool's purpose is to let an agent learn a table's shape, a response the agent cannot ingest defeats the tool.
Environment
- MCP Toolbox
v1.8.0+binary.darwin.arm64(via `@toolbo
Read the thread · 2026-07-29 · open · external user · 1 comment
bigquery: allowedDatasets startup verification (datasets.get) makes datasets reachable only via authorized views impossible to allowlist
Summary
The BigQuery source verifies every entry in allowedDatasets with datasets.get during Initialize(), and aborts startup if any entry is unreadable. Because the runtime enforcement is only a name comparison against the dry run's referenced datasets, this startup check requires a permission the feature does not actually need — and it makes it impossible to allowlist datasets that are reachable only through authorized views.
Environment
- MCP Toolbox `v1.8.0+binary.
Read the thread · 2026-07-29 · open · external user · 1 comment
bigquery-execute-sql: run allowedDatasets check before dry-run (non-existent foreign datasets return BQ 404)
Summary
With allowedDatasets set, bigquery-execute-sql documents that queries accessing tables outside the list are rejected. In practice the allowlist check runs only after a successful BigQuery dry-run, so a query against a non-existent foreign dataset returns a BQ 404 Not Found (via ProcessGcpError → AgentError) instead of the clear AgentError:
query accesses dataset 'PROJECT.DATASET', which is not in the allowed list
Security is usually still fail-safe (no data retu
Read the thread · 2026-07-27 · open · external user · 0 comments
The remaining reports are on the project's issue tracker.