MySQL · MariaDB · MCP

Give your agent the database. Keep the undo button.

OwlSQL lets Claude Code, Cursor and Codex query and fix your real MySQL database themselves, instead of asking you to paste from phpMyAdmin. It's read-only until you say so, every write can be undone, and anything risky waits for your yes.

$ npm i -g owlsql

Works on shared hosting too: Hostinger, HostGator, Bluehost, GoDaddy, SiteGround, any cPanel box, or your own server.

claude code · my-shop
› some category names have "Jewlery" in them, fix it

⏺ owlsql_query(sql: "SELECT id, name FROM categories WHERE name LIKE '%Jewlery%'")
  3 rows, 38 ms
  id | name
  14 | Jewlery & Watches
  22 | Kids Jewlery
  31 | Jewlery Boxes

⏺ owlsql_query(sql: "UPDATE categories SET name = REPLACE(name, 'Jewlery', 'Jewelry') WHERE name LIKE '%Jewlery%'")
  Done: UPDATE on categories, 3 rows affected (41 ms).
  Undo: owlsql_undo reverts it (write id mux8k2a1).

› wait, the SEO plugin keys off those. put them back

⏺ owlsql_undo()
  Undone: write mux8k2a1 (UPDATE on categories)
  - restore 3 changed rows in categories

The owl's rules

An agent that can run SQL on a live site can also wipe it with one bad WHERE. OwlSQL sits between them and checks every statement before it runs.

Read-only until you say so

Reads run in a read-only transaction that is always rolled back. Writes stay off until you run owlsql db write shop on. No agent tool can flip that switch.

Every write can be undone

Before an UPDATE, DELETE, INSERT, ALTER, DROP or TRUNCATE runs, OwlSQL saves exactly what it will change, including rows a foreign key cascades into. owlsql undo puts it back.

Undo never clobbers your site

Before undoing, OwlSQL checks whether anything touched that data since. If customers placed orders in the meantime, it stops and shows you instead of wiping them.

Risky writes ask first

No WHERE, more rows than your limit, dropping or emptying a table, or anything that can't be undone: the agent gets a preview and has to ask you.

Server-level damage is off the table

User and privilege changes, DROP DATABASE, reading or writing files on the server, global settings and multi-statement tricks are refused outright.

A history of who did what

Every write is logged with the statement, the rows it touched, which agent ran it and whether it can still be undone. owlsql history shows it.

When it matters, the owl asks.

Say an agent tries to clear a table without a WHERE. OwlSQL doesn't run it. The agent gets back the reason, the row count and a sample, and the instructions to ask you. It can only go ahead with your answer.

  • Preview anything with a dry run: rows affected, sample rows, whether it can be undone. Works even while writes are off.
  • Your limits: set how many rows a write may touch before it asks, per database.
  • Honest about gaps: if a change can't be snapshotted, you hear "no undo" before it runs, not after.
claude code · my-shop
› clear out the old sessions

⏺ owlsql_query(sql: "DELETE FROM sessions")
  NOT RUN: this needs the user's confirmation first.
  Needs confirmation because:
  - It has no WHERE clause, so it deletes every
    row in sessions (18,442).
  Undo available: OwlSQL snapshots the 18442 affected rows first.

⏺ That would delete all 18,442 sessions, including
  people who are logged in right now. Only expired
  ones? DELETE FROM sessions WHERE expires < NOW()
  touches 17,906.

› yes, just the expired ones

Three ways in. One works on your host.

Most shared hosts block MySQL connections from outside. OwlSQL has a way around that for every kind of host. Your password goes into a hidden prompt, is encrypted with your Windows account, and is never shown to the agent.

Remote MySQL

Direct connection

If your hosting panel has a "Remote MySQL" page, add your IP address there and connect straight in.

owlsql db add shop \
  --host mysql.example.com \
  --user shop_user --database shop_db
SSH

SSH tunnel

Have SSH access? The database never has to be reachable from the internet. Uses your existing SSH key and pins the server's host key.

owlsql db add shop \
  --ssh me@example.com --host localhost \
  --user shop_user --database shop_db
PHP bridge

One small file

Neither allowed? Your host still runs PHP. OwlSQL writes one token-protected file to upload next to your site. It has a random name, and without its token it only answers "404 Not Found".

owlsql bridge shop \
  --url https://example.com \
  --user shop_user --database shop_db

Works with MySQL 5.7, 8 and 9, and MariaDB 10.3 and newer, including the database behind WordPress, WooCommerce, Laravel and plain PHP sites.

How undo works

Before a write runs, OwlSQL saves exactly what it is about to change, in the same transaction. Undo puts it back, but only after checking that nothing else has touched those rows since.

The writeWhat OwlSQL saves firstWhat undo does
UPDATE / DELETEThe rows its WHERE matches, locked so nothing else can change them firstPuts the old values back by primary key; re-inserts deleted rows
INSERTThe new rowsRemoves exactly those rows
REPLACE, upserts, key changesThe table, keeping only the rows that changedApplies the reverse of the change
Foreign-key cascadesThe rows in other tables that cascade with itRestores them in the same transaction, parents first
ALTER, DROP, TRUNCATEThe table's full definition and every rowRebuilds the table and reloads it
CREATE TABLE / RENAMEThe namesDrops the new table / renames back

Undo first re-reads the affected rows and compares them with their state right after the write. If your site changed them since, undo stops and lists the conflicts. It only overwrites them if you say so. Some writes can't be snapshotted: statements across several tables, tables with no primary key (except deletes), and changes over 100,000 rows. OwlSQL tells you before running those.

Before a big change, owlsql dump saves a full backup to a .sql file you can import with phpMyAdmin. It works even while writes are off.

Quickstart

About five minutes: install it, connect your database, tell your agent about it.

  1. Install

    Needs Node 18 or newer.

    npm i -g owlsql
  2. Connect your database

    Use whichever of the three ways your host allows. You'll be asked for the password, then OwlSQL tests the connection.

    owlsql db add shop --host mysql.example.com --user shop_user --database shop_db
    # Connected to mysql: 8.0.36, user shop_user@%, database shop_db, 24 tables. Writes off.
  3. Hand it to your agent

    Claude Code shown. Codex, Cursor and Claude Desktop use the same command: owlsql mcp. Link your project folder once, and your agent always knows which database to use.

    claude mcp add owlsql -- owlsql mcp
    cd my-shop && owlsql init shop
  4. Let it write, when you're ready

    Until then, your agent can look but not touch. Turn writes on for one database, and back off whenever you like.

    owlsql db write shop on

Things the owl will never do

Some statements aren't about your data. They're about the server. OwlSQL refuses them however they're phrased, with a short explanation so the agent stops trying.

DROP DATABASEGRANTCREATE USERLOAD DATAINTO OUTFILELOAD_FILE()SET GLOBALKILLSHUTDOWN/*! hidden SQL */two statements; at once

Tools your agent gets

  • owlsql_query: one statement, with placeholders, dry run and confirmation
  • owlsql_undo and owlsql_history: revert any recent write
  • owlsql_tables and owlsql_describe: the schema, foreign keys and triggers
  • owlsql_dump: a full local backup
  • owlsql_status: connection, version, privileges, write mode

FAQ

Is it safe to let an AI agent near my production database?

With raw credentials, not really: one bad statement and the data is gone. OwlSQL is built for exactly that worry. The agent never gets your credentials, writes are off until you turn them on, every write is saved first so it can be undone, and anything destructive needs you to say yes. And before the agent does anything big, ask it to run owlsql dump.

Does my database password reach the AI?

No. You type it at a hidden prompt. It is stored encrypted with your Windows account and used only to connect. The agent's tools never return passwords or bridge tokens.

Is the PHP bridge a security risk?

It only answers HTTPS POST requests that carry a 256-bit token. The file stores just a SHA-256 hash of that token, and anything without it just gets "404 Not Found". The file name is random too, so nobody finds it by guessing. Treat the token like your database password: OwlSQL keeps it encrypted locally. You can limit the bridge to your IP address, and deleting the file revokes access instantly.

What can't be undone?

A single statement that changes several tables, an UPDATE on a table with no primary key, cascades more than one level deep, and changes larger than the snapshot limit (100,000 rows, adjustable). OwlSQL says "no undo" and asks before running any of these. Changes made by triggers in other tables aren't captured either, and owlsql_describe lists a table's triggers.

Does it work with WordPress?

Yes. WordPress runs on MySQL or MariaDB, so point OwlSQL at the database named in wp-config.php. It's handy for fixing options, posts and WooCommerce data without clicking through phpMyAdmin.

Which agents does it work with?

Anything that speaks MCP: Claude Code, Claude Desktop, Cursor, Codex, Windsurf and more. There's also a regular command-line tool, owlsql query, for you or for scripts.

What does it cost?

Nothing. OwlSQL is free and open source under the MIT license.

From the makers of coolFTP. Your agent changed the database with OwlSQL. Now let it ship the code: coolFTP deploys to any SFTP or FTP host, checks the site is live, and undoes a bad deploy.