MCPDBWizard

Writing  · 

Are you looking for an alternative to Oracle’s MCP server?

If you searched for an alternative to Oracle’s MCP server, you have probably already met one of them. Oracle does not have an MCP server any more: it has four, and they do different jobs. Before we get to how ours differs, it is worth being clear about what you are comparing against, because “Oracle’s MCP server” can mean a developer tool on a laptop or a managed cloud service, and the answer changes with it.

What MCP DB Wizard is

MCP DB Wizard generates an MCP server from your Oracle schema. You connect it to a database, tick the things you are willing to let an AI agent use, and it writes, compiles and runs a server that exposes exactly those things as tools, and nothing else.

What you can tick is deliberately narrow: PL/SQL packages, procedures and functions, tables, chosen per operation (read, insert, update, delete), sequences, and SQL statements you wrote and tested yourself. Each one becomes a named tool with a typed input schema derived from the object’s real signature. A procedure with three OUT parameters, a record argument and a ref cursor becomes a tool that takes a JSON object and returns all of it.

There is no run-sql tool, and there cannot be one. An object you did not select has no tool, no method and no class in the generated server. It is absent from the binary rather than refused at run time, so no prompt, however clever, can reach it. Your selection is saved as a config file you can review, version and diff, and that file is the security model.

Around the generated servers sits a web console and a proxy. People and agents get accounts and tokens, each config is granted to the accounts that may use it, calls are rate-limited, and both the proxy and the server write an audit trail. It ships as one Docker image, runs anywhere Docker does, and supports Oracle 12c through 26ai. It is regression-tested against six live instances spanning that range.

Oracle’s four MCP routes

Oracle’s own MCP page names three deployment models, and Autonomous Database adds a fourth. In brief:

Where it runsWhat the agent getsWho it is for
SQLcl MCP ServerLocally, over stdio, with connections saved on your machinerun-sql, run-sqlcl, connection toolsDevelopers and DBAs
ORDS MCP endpoint (ORDS 26.2)ORDS standalone, wherever you run it; OAuth2/JWT from your identity providerdatabase_list, schema_information, sql_runTeams that already run ORDS
OCI Database Tools managed MCPManaged in OCI, for 19c and 26ai databases in OCI or on Oracle Database@AWS, @Azure and @Google Cloudrun-sql, parameterised SQL Reports, custom tools defined in the OCI consoleBusiness users on Oracle-hosted databases
Autonomous Database managed MCPOne server per Autonomous DatabaseBuilt-in Select AI tools, plus PL/SQL functions you register with DBMS_CLOUD_AI_AGENT.CREATE_TOOLAutonomous Database customers

All four are free of any MCP-specific charge, and all four are supported by Oracle. That matters, and we will come back to it.

Where Oracle’s offering is the right answer

For exploration, use SQLcl. A developer asking questions of a database they can already reach, with their own credentials, watching what the agent does, is exactly the situation an unrestricted SQL tool is built for. We say so at more length in a fair comparison of SQLcl’s MCP server, and we use it ourselves.

If your databases already live on OCI, look hard at Database Tools. It plugs into OCI identity, it has sensible MCP roles out of the box, and its SQL Reports are a real step towards governed access: parameterised queries somebody approved, instead of SQL a model derived. If your estate is Autonomous Database, the managed MCP server lets you register PL/SQL functions as tools inside the database itself, which is a model we agree with.

If you already run ORDS and want natural-language querying behind your own identity provider, its /mcp endpoint gives you that with very little new infrastructure.

Where we differ

A SQL tool you can switch off, or no SQL tool at all

SQLcl and ORDS give the agent a general SQL tool. ORDS’s own documentation is plain about it: statements “run with the privileges of the underlying ORDS database connection pool”, and sql_run “can run statements that modify database state”. The boundary is the account’s grants, which is a description of what the agent might do rather than a list of what it can do.

Database Tools lets you give some users only reports and custom tools, and keep run-sql for others. That is a real control, but it is a switch on a server that has the capability. In MCP DB Wizard the capability is not there to switch. When a security reviewer asks what the agent can do to the data, the answer is the config file, line by line.

Who writes the tools

Oracle’s curated routes, the custom tools in Database Tools and CREATE_TOOL in Autonomous Database, are written by hand, one at a time. In Autonomous Database the pattern is a PL/SQL function, usually returning JSON, registered with a description you write.

That is fine for ten tools. It is the wrong shape for the PL/SQL you already have: packages that take records, collections and %ROWTYPEs, return several OUT parameters, and hand back ref cursors. MCP DB Wizard reads those signatures from Oracle’s data dictionary and generates the tool, the JSON schema and the conversion code. You tick the package; you do not write a wrapper for it. What an agent actually sees when your PL/SQL becomes tools shows the result on real procedures.

Where it runs, and which versions

Oracle’s curated options are tied to Oracle’s cloud: Database Tools reaches databases on OCI and the Oracle Database@ services, on 19c or 26ai, and the Autonomous Database server exists only on Autonomous Database.

MCP DB Wizard is a container. It runs on your own servers, on a laptop, on AWS against RDS for Oracle, anywhere Docker runs, and it talks to Oracle 12c, 18c, 19c, 21c, 23ai and 26ai. If your most valuable PL/SQL is on a 12c or 19c database in your own data centre, that is the difference that decides it.

How much of your own code it relies on

Nothing in a generated server composes SQL at run time. Every table operation and statement is fixed when the server is generated, and every argument is a bind value. Calling a tool is the same as calling a typed Java method with the SQL already written, which is a considerably easier thing to explain to an auditor than a model that writes SQL within limits.

Side by side

Oracle (SQLcl / ORDS)Oracle (Database Tools / Autonomous DB)MCP DB Wizard
General SQL toolYesOptional, per roleNone generated
Curated toolsNoYes, hand-writtenYes, generated from signatures
PL/SQL records, collections, ref cursors, many OUTsVia SQL the model writesIf you write a wrapperDirectly
Runs on-premises or on RDSYesNoYes
Oracle versionsPer product19c and 26ai12c to 26ai
IdentityLocal credentials / your IdPOCI IAMAccounts, tokens and a grant matrix
CostFreeFree (pay for the database)Free for one running server
Supported by OracleYesYesNo

So which do you need?

Ask two questions.

Is a person watching? If a developer is at the keyboard with their own credentials, use SQLcl. Nothing here will beat it for that job.

Where is the database, and what is on it? If it is on OCI and your use is natural-language reporting, start with Database Tools. If it is anywhere else, or on an older release, or the thing you want an agent to use is a body of PL/SQL that already encodes your business rules, that is what MCP DB Wizard was built for.

Many teams will end up with both: SQLcl on laptops, and a curated, generated server for anything an application or a customer touches.

How do I get MCP DB Wizard?

It is a single Docker image, available from our GitHub repository, and free for one running server with no expiry. The quickstart goes from nothing to an agent calling your first tool, and if you want to see what it refuses to do, it has a section on exactly that.