DBX MCP Security Settings Environment Variables: Complete Configuration Guide
The DBX MCP (Managed Compute Platform) relies on five critical environment variables—DBX_MCP_ALLOW_WRITES, DBX_MCP_ALLOW_DANGEROUS_SQL, DBX_WEB_PASSWORD, DBX_DISABLE_PASSWORD, and DBX_WEB_URL—to control write permissions, dangerous command execution, authentication requirements, and server connectivity.
The DBX MCP security settings environment variables provide a secure-by-default foundation for the t8y2/dbx open-source platform. These variables govern whether SQL sessions allow data modifications, which high-risk commands are permitted, and how the Web backend authenticates incoming MCP client requests.
Core Security Variables for DBX MCP
DBX_MCP_ALLOW_WRITES: Enabling Write Operations
The DBX_MCP_ALLOW_WRITES variable controls whether the MCP session permits write-capable statements such as INSERT, UPDATE, or DDL operations.
- Default value:
0(read-only mode) - Behavior when unset: All write operations are blocked and the system throws: "MCP SQL execution is read-only for this session. Set DBX_MCP_ALLOW_WRITES=1 to allow write statements."
- Source location:
packages/node-core/src/sql-safety.tsat lines 75 and 76
Set this variable to 1 when you need to perform data modifications through the MCP interface.
DBX_MCP_ALLOW_DANGEROUS_SQL: Permitting High-Risk Commands
The DBX_MCP_ALLOW_DANGEROUS_SQL variable provides an additional safety layer for destructive operations beyond standard writes.
- Default value:
0(blocked) - Blocked commands:
DROP,DELETE,UNSET, and MongoDB aggregation stages$mergeand$out - Error message: "Set DBX_MCP_ALLOW_DANGEROUS_SQL=1 to allow it."
- Source location:
packages/node-core/src/sql-safety.tsat lines 76 and 77
This requires explicit opt-in even when DBX_MCP_ALLOW_WRITES is enabled, preventing accidental data loss.
DBX_WEB_PASSWORD: Web Mode Authentication
The DBX_WEB_PASSWORD variable establishes password protection for MCP Web mode connections.
- Default value: None (must be explicitly set)
- Requirement: Mandatory when using MCP Web mode; if unset, the server rejects requests with: "DBX Web authentication is required. Set DBX_WEB_PASSWORD for MCP Web mode."
- Source location:
packages/node-core/src/web-backend.tsat line 71
This variable ensures that remote Web-based MCP sessions require credential validation before executing queries.
DBX_DISABLE_PASSWORD: Bypassing Authentication
The DBX_DISABLE_PASSWORD variable allows operators to disable password protection entirely, primarily for local development scenarios.
- Accepted values: Any truthy value (
1,true, etc.) - Default behavior: When unset, password enforcement remains active
- Source location:
crates/dbx-web/src/main.rsat line 185
Warning: According to the t8y2/dbx source code, this should only be used for local testing environments.
DBX_WEB_URL: Configuring the Server Endpoint
The DBX_WEB_URL variable specifies the base URL that MCP clients use to reach the DBX Web server.
- Default value: None (must be supplied for remote Web mode)
- Usage: Read by the Web backend to establish client-server communication
- Source location:
packages/node-core/src/web-backend.tsat line 33
If omitted, the client raises a default-construction error preventing connection establishment.
Implementation Details in the Source Code
The security checks are implemented across TypeScript and Rust source files in the t8y2/dbx repository:
| Variable | Source File | Implementation Details |
|---|---|---|
DBX_MCP_ALLOW_WRITES |
packages/node-core/src/sql-safety.ts |
Boolean check at lines 75-76; returns false when unset or "0" |
DBX_MCP_ALLOW_DANGEROUS_SQL |
packages/node-core/src/sql-safety.ts |
Evaluated at lines 76-77 alongside write permissions |
DBX_WEB_PASSWORD |
packages/node-core/src/web-backend.ts |
Validated at line 71 before Web mode initialization |
DBX_DISABLE_PASSWORD |
crates/dbx-web/src/main.rs |
Rust environment variable check at line 185 |
DBX_WEB_URL |
packages/node-core/src/web-backend.ts |
Parsed at line 33 for client configuration |
Practical Configuration Examples
Enable full write capabilities for an MCP session:
export DBX_MCP_ALLOW_WRITES=1
export DBX_MCP_ALLOW_DANGEROUS_SQL=1
Configure Web mode with authentication:
export DBX_WEB_PASSWORD=super_secret
export DBX_WEB_URL=http://127.0.0.1:4224
Disable password protection for local testing only:
export DBX_DISABLE_PASSWORD=1
Check security flags programmatically in Node.js:
import { sqlSafetyFromEnv } from "@dbx/node-core";
const safety = sqlSafetyFromEnv(process.env);
if (!safety.allowWrites) {
throw new Error("Writes are blocked – set DBX_MCP_ALLOW_WRITES=1");
}
if (dangerous && !safety.allowDangerous) {
throw new Error("Dangerous SQL blocked – set DBX_MCP_ALLOW_DANGEROUS_SQL=1");
}
Handle password configuration in the Rust Web server:
// Rust side – disabling the password in the DBX web server
let password_disabled = std::env::var("DBX_DISABLE_PASSWORD").is_ok();
if password_disabled {
println!("⚠️ Password protection is disabled");
}
Summary
- DBX_MCP_ALLOW_WRITES controls whether write operations are permitted (default: blocked)
- DBX_MCP_ALLOW_DANGEROUS_SQL restricts destructive commands like DROP and DELETE (default: blocked)
- DBX_WEB_PASSWORD is required for MCP Web mode authentication; no default value exists
- DBX_DISABLE_PASSWORD bypasses authentication when set to a truthy value (local testing only)
- DBX_WEB_URL specifies the MCP client connection endpoint and must be set for remote Web mode
- Security checks are implemented in
packages/node-core/src/sql-safety.tsandpackages/node-core/src/web-backend.ts(TypeScript) andcrates/dbx-web/src/main.rs(Rust)
Frequently Asked Questions
What happens if I don't set DBX_MCP_ALLOW_WRITES?
When DBX_MCP_ALLOW_WRITES is unset or set to 0, the MCP session operates in read-only mode. Any attempt to execute write operations or DDL statements triggers the error: "MCP SQL execution is read-only for this session. Set DBX_MCP_ALLOW_WRITES=1 to allow write statements." This default behavior is enforced in packages/node-core/src/sql-safety.ts at line 75.
Is DBX_WEB_PASSWORD required for all MCP modes?
No, DBX_WEB_PASSWORD is only required when running MCP in Web mode. According to the implementation in packages/node-core/src/web-backend.ts at line 71, the server throws "DBX Web authentication is required. Set DBX_WEB_PASSWORD for MCP Web mode" only when a Web backend client attempts authentication without this variable configured.
Can I use DBX_DISABLE_PASSWORD in production?
No. The DBX_DISABLE_PASSWORD variable is designed exclusively for local testing environments. As implemented in crates/dbx-web/src/main.rs at line 185, setting this variable to any truthy value completely removes password protection from the DBX Web server, creating a security vulnerability in production deployments.
Where are the SQL security checks enforced in the codebase?
The SQL security validations are centralized in packages/node-core/src/sql-safety.ts. Lines 75-76 handle the DBX_MCP_ALLOW_WRITES check, while lines 76-77 implement the DBX_MCP_ALLOW_DANGEROUS_SQL validation. These functions return boolean values that determine whether the query executor permits the requested operation type.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →