Writing ·
Are you looking for an alternative to Oracle’s MCP server?
If you searched for an alternative to Oracle’s MCP server, you have probably already met one of them. Oracle does not have an MCP server any more: it has four, and they do different jobs. Before we get to how ours differs, it is worth being clear about what you are comparing against, because “Oracle’s MCP server” can mean a developer tool on a laptop or a managed cloud service, and the answer changes with it.
What MCP DB Wizard is
MCP DB Wizard generates an MCP server from your Oracle schema. You connect it to a database, tick the things you are willing to let an AI agent use, and it writes, compiles and runs a server that exposes exactly those things as tools, and nothing else.
What you can tick is deliberately narrow: PL/SQL packages, procedures and functions, tables, chosen per operation (read, insert, update, delete), sequences, and SQL statements you wrote and tested yourself. Each one becomes a named tool with a typed input schema derived from the object’s real signature. A procedure with three OUT parameters, a record argument and a ref cursor becomes a tool that takes a JSON object and returns all of it.
There is no run-sql tool, and there cannot be one. An object you did not select has no tool, no
method and no class in the generated server. It is absent from the binary rather than refused at run
time, so no prompt, however clever, can reach it. Your selection is saved as a config file you can
review, version and diff, and that file is the security model.
Around the generated servers sits a web console and a proxy. People and agents get accounts and tokens, each config is granted to the accounts that may use it, calls are rate-limited, and both the proxy and the server write an audit trail. It ships as one Docker image, runs anywhere Docker does, and supports Oracle 12c through 26ai. It is regression-tested against six live instances spanning that range.
Oracle’s four MCP routes
Oracle’s own MCP page names three deployment models, and Autonomous Database adds a fourth. In brief:
| Where it runs | What the agent gets | Who it is for | |
|---|---|---|---|
| SQLcl MCP Server | Locally, over stdio, with connections saved on your machine | run-sql, run-sqlcl, connection tools | Developers and DBAs |
| ORDS MCP endpoint (ORDS 26.2) | ORDS standalone, wherever you run it; OAuth2/JWT from your identity provider | database_list, schema_information, sql_run | Teams that already run ORDS |
| OCI Database Tools managed MCP | Managed in OCI, for 19c and 26ai databases in OCI or on Oracle Database@AWS, @Azure and @Google Cloud | run-sql, parameterised SQL Reports, custom tools defined in the OCI console | Business users on Oracle-hosted databases |
| Autonomous Database managed MCP | One server per Autonomous Database | Built-in Select AI tools, plus PL/SQL functions you register with DBMS_CLOUD_AI_AGENT.CREATE_TOOL | Autonomous Database customers |
All four are free of any MCP-specific charge, and all four are supported by Oracle. That matters, and we will come back to it.
Where Oracle’s offering is the right answer
For exploration, use SQLcl. A developer asking questions of a database they can already reach, with their own credentials, watching what the agent does, is exactly the situation an unrestricted SQL tool is built for. We say so at more length in a fair comparison of SQLcl’s MCP server, and we use it ourselves.
If your databases already live on OCI, look hard at Database Tools. It plugs into OCI identity, it has sensible MCP roles out of the box, and its SQL Reports are a real step towards governed access: parameterised queries somebody approved, instead of SQL a model derived. If your estate is Autonomous Database, the managed MCP server lets you register PL/SQL functions as tools inside the database itself, which is a model we agree with.
If you already run ORDS and want natural-language querying behind your own identity provider, its
/mcp endpoint gives you that with very little new infrastructure.
Where we differ
A SQL tool you can switch off, or no SQL tool at all
SQLcl and ORDS give the agent a general SQL tool. ORDS’s own documentation is plain about it:
statements “run with the privileges of the underlying ORDS database connection pool”, and sql_run
“can run statements that modify database state”. The boundary is the account’s grants, which is a
description of what the agent might do rather than a list of what it can do.
Database Tools lets you give some users only reports and custom tools, and keep run-sql for others.
That is a real control, but it is a switch on a server that has the capability. In MCP DB Wizard the
capability is not there to switch. When a security reviewer asks what the agent can do to the data,
the answer is the config file, line by line.
Who writes the tools
Oracle’s curated routes, the custom tools in Database Tools and CREATE_TOOL in Autonomous Database,
are written by hand, one at a time. In Autonomous Database the pattern is a PL/SQL function,
usually returning JSON, registered with a description you write.
That is fine for ten tools. It is the wrong shape for the PL/SQL you already have: packages that take
records, collections and %ROWTYPEs, return several OUT parameters, and hand back ref cursors. MCP DB
Wizard reads those signatures from Oracle’s data dictionary and generates the tool, the JSON schema
and the conversion code. You tick the package; you do not write a wrapper for it.
What an agent actually sees when your PL/SQL becomes tools
shows the result on real procedures.
Where it runs, and which versions
Oracle’s curated options are tied to Oracle’s cloud: Database Tools reaches databases on OCI and the Oracle Database@ services, on 19c or 26ai, and the Autonomous Database server exists only on Autonomous Database.
MCP DB Wizard is a container. It runs on your own servers, on a laptop, on AWS against RDS for Oracle, anywhere Docker runs, and it talks to Oracle 12c, 18c, 19c, 21c, 23ai and 26ai. If your most valuable PL/SQL is on a 12c or 19c database in your own data centre, that is the difference that decides it.
How much of your own code it relies on
Nothing in a generated server composes SQL at run time. Every table operation and statement is fixed when the server is generated, and every argument is a bind value. Calling a tool is the same as calling a typed Java method with the SQL already written, which is a considerably easier thing to explain to an auditor than a model that writes SQL within limits.
Side by side
| Oracle (SQLcl / ORDS) | Oracle (Database Tools / Autonomous DB) | MCP DB Wizard | |
|---|---|---|---|
| General SQL tool | Yes | Optional, per role | None generated |
| Curated tools | No | Yes, hand-written | Yes, generated from signatures |
| PL/SQL records, collections, ref cursors, many OUTs | Via SQL the model writes | If you write a wrapper | Directly |
| Runs on-premises or on RDS | Yes | No | Yes |
| Oracle versions | Per product | 19c and 26ai | 12c to 26ai |
| Identity | Local credentials / your IdP | OCI IAM | Accounts, tokens and a grant matrix |
| Cost | Free | Free (pay for the database) | Free for one running server |
| Supported by Oracle | Yes | Yes | No |
So which do you need?
Ask two questions.
Is a person watching? If a developer is at the keyboard with their own credentials, use SQLcl. Nothing here will beat it for that job.
Where is the database, and what is on it? If it is on OCI and your use is natural-language reporting, start with Database Tools. If it is anywhere else, or on an older release, or the thing you want an agent to use is a body of PL/SQL that already encodes your business rules, that is what MCP DB Wizard was built for.
Many teams will end up with both: SQLcl on laptops, and a curated, generated server for anything an application or a customer touches.
How do I get MCP DB Wizard?
It is a single Docker image, available from our GitHub repository, and free for one running server with no expiry. The quickstart goes from nothing to an agent calling your first tool, and if you want to see what it refuses to do, it has a section on exactly that.