Query Streams
Query Streams lets Claude query the databases behind your firewall without a VPN, an inbound port, or a database credential ever leaving your network. How it works: install the Query Streams Network Agent next to your database on Windows, Linux or macOS. Install takes a couple of minutes. The agent opens one outbound TLS connection to Query Streams and holds it. When Claude asks a question, the request travels down that connection, the agent runs the query locally, and the rows travel back up the same way. Nothing dials in. Your firewall rules do not change. The database connection string stays on the agent and is never shown to Claude. That means a corporate SQL Server in the office can answer questions from Claude on a laptop at home, on another continent, with no network changes at all. The agent is read-only by design: only SELECT, WITH and EXPLAIN statements are accepted, and the check happens on your side of the connection, not in the cloud. Sources: SQL Server, PostgreSQL, MySQL, MariaDB, Oracle, BigQuery, Snowflake, SQLite, DuckDB, Microsoft Access, folders of CSV, Parquet, Excel and log files, and API sources such as Stripe, Shopify, HubSpot, Google Analytics, Google Ads and Google Search Console. Schema Intelligence gives Claude the semantics. Query Streams profiles your tables and writes a description for every table and column, tags each column by meaning, decodes status codes with labels, and discovers joins where no foreign keys are declared, so Claude writes correct SQL on the first try. Your saved, parameterized queries, including federated queries across several sources, are available to Claude by name. Access is per user and per organization, with read, analyze and execute scopes, optional connector restrictions, instant revocation from the Portal, and a full log of every call. Requires a Query Streams account on a Business or Enterprise plan or the 30-day trial, and the Network Agent installed next to your data.
Details
https://mcp.querystreams.com/mcp · streamable-http
