MCPDBWizard

Documentation  ·  Oracle

Creating an Oracle user with minimal privileges

Every caller shares one Oracle account. The generated server authenticates to the database, not its callers — Oracle sees one service account no matter which agent called. Per-caller attribution lives in the proxy’s access records, not in V$SESSION.

That makes this account’s grants the real boundary. Curation decides what tools exist; the grant decides what those tools can do if anything ever goes wrong with the first answer. Use both.

The shape of it

CREATE USER mcp_agent IDENTIFIED BY "..." 
  DEFAULT TABLESPACE users
  QUOTA UNLIMITED ON users;      -- only if it writes

GRANT CREATE SESSION TO mcp_agent;

-- One line per object you actually exposed. Not an inherited role, not ANY privilege.
GRANT SELECT ON payroll.employee TO mcp_agent;
GRANT EXECUTE ON payroll.js_admin TO mcp_agent;
GRANT SELECT ON payroll.job_id_seq TO mcp_agent;

Rules worth keeping