DBX MCP Security Settings Environment Variables: Complete Configuration Guide

The DBX MCP (Managed Compute Platform) relies on five critical environment variables—DBX_MCP_ALLOW_WRITES, DBX_MCP_ALLOW_DANGEROUS_SQL, DBX_WEB_PASSWORD, DBX_DISABLE_PASSWORD, and DBX_WEB_URL—to control write permissions, dangerous command execution, authentication requirements, and server connectivity.

The DBX MCP security settings environment variables provide a secure-by-default foundation for the t8y2/dbx open-source platform. These variables govern whether SQL sessions allow data modifications, which high-risk commands are permitted, and how the Web backend authenticates incoming MCP client requests.

Core Security Variables for DBX MCP

DBX_MCP_ALLOW_WRITES: Enabling Write Operations

The DBX_MCP_ALLOW_WRITES variable controls whether the MCP session permits write-capable statements such as INSERT, UPDATE, or DDL operations.

  • Default value: 0 (read-only mode)
  • Behavior when unset: All write operations are blocked and the system throws: "MCP SQL execution is read-only for this session. Set DBX_MCP_ALLOW_WRITES=1 to allow write statements."
  • Source location: packages/node-core/src/sql-safety.ts at lines 75 and 76

Set this variable to 1 when you need to perform data modifications through the MCP interface.

DBX_MCP_ALLOW_DANGEROUS_SQL: Permitting High-Risk Commands

The DBX_MCP_ALLOW_DANGEROUS_SQL variable provides an additional safety layer for destructive operations beyond standard writes.

  • Default value: 0 (blocked)
  • Blocked commands: DROP, DELETE, UNSET, and MongoDB aggregation stages $merge and $out
  • Error message: "Set DBX_MCP_ALLOW_DANGEROUS_SQL=1 to allow it."
  • Source location: packages/node-core/src/sql-safety.ts at lines 76 and 77

This requires explicit opt-in even when DBX_MCP_ALLOW_WRITES is enabled, preventing accidental data loss.

DBX_WEB_PASSWORD: Web Mode Authentication

The DBX_WEB_PASSWORD variable establishes password protection for MCP Web mode connections.

  • Default value: None (must be explicitly set)
  • Requirement: Mandatory when using MCP Web mode; if unset, the server rejects requests with: "DBX Web authentication is required. Set DBX_WEB_PASSWORD for MCP Web mode."
  • Source location: packages/node-core/src/web-backend.ts at line 71

This variable ensures that remote Web-based MCP sessions require credential validation before executing queries.

DBX_DISABLE_PASSWORD: Bypassing Authentication

The DBX_DISABLE_PASSWORD variable allows operators to disable password protection entirely, primarily for local development scenarios.

  • Accepted values: Any truthy value (1, true, etc.)
  • Default behavior: When unset, password enforcement remains active
  • Source location: crates/dbx-web/src/main.rs at line 185

Warning: According to the t8y2/dbx source code, this should only be used for local testing environments.

DBX_WEB_URL: Configuring the Server Endpoint

The DBX_WEB_URL variable specifies the base URL that MCP clients use to reach the DBX Web server.

  • Default value: None (must be supplied for remote Web mode)
  • Usage: Read by the Web backend to establish client-server communication
  • Source location: packages/node-core/src/web-backend.ts at line 33

If omitted, the client raises a default-construction error preventing connection establishment.

Implementation Details in the Source Code

The security checks are implemented across TypeScript and Rust source files in the t8y2/dbx repository:

Variable Source File Implementation Details
DBX_MCP_ALLOW_WRITES packages/node-core/src/sql-safety.ts Boolean check at lines 75-76; returns false when unset or "0"
DBX_MCP_ALLOW_DANGEROUS_SQL packages/node-core/src/sql-safety.ts Evaluated at lines 76-77 alongside write permissions
DBX_WEB_PASSWORD packages/node-core/src/web-backend.ts Validated at line 71 before Web mode initialization
DBX_DISABLE_PASSWORD crates/dbx-web/src/main.rs Rust environment variable check at line 185
DBX_WEB_URL packages/node-core/src/web-backend.ts Parsed at line 33 for client configuration

Practical Configuration Examples

Enable full write capabilities for an MCP session:

export DBX_MCP_ALLOW_WRITES=1
export DBX_MCP_ALLOW_DANGEROUS_SQL=1

Configure Web mode with authentication:

export DBX_WEB_PASSWORD=super_secret
export DBX_WEB_URL=http://127.0.0.1:4224

Disable password protection for local testing only:

export DBX_DISABLE_PASSWORD=1

Check security flags programmatically in Node.js:

import { sqlSafetyFromEnv } from "@dbx/node-core";

const safety = sqlSafetyFromEnv(process.env);
if (!safety.allowWrites) {
  throw new Error("Writes are blocked – set DBX_MCP_ALLOW_WRITES=1");
}
if (dangerous && !safety.allowDangerous) {
  throw new Error("Dangerous SQL blocked – set DBX_MCP_ALLOW_DANGEROUS_SQL=1");
}

Handle password configuration in the Rust Web server:

// Rust side – disabling the password in the DBX web server
let password_disabled = std::env::var("DBX_DISABLE_PASSWORD").is_ok();
if password_disabled {
    println!("⚠️  Password protection is disabled");
}

Summary

  • DBX_MCP_ALLOW_WRITES controls whether write operations are permitted (default: blocked)
  • DBX_MCP_ALLOW_DANGEROUS_SQL restricts destructive commands like DROP and DELETE (default: blocked)
  • DBX_WEB_PASSWORD is required for MCP Web mode authentication; no default value exists
  • DBX_DISABLE_PASSWORD bypasses authentication when set to a truthy value (local testing only)
  • DBX_WEB_URL specifies the MCP client connection endpoint and must be set for remote Web mode
  • Security checks are implemented in packages/node-core/src/sql-safety.ts and packages/node-core/src/web-backend.ts (TypeScript) and crates/dbx-web/src/main.rs (Rust)

Frequently Asked Questions

What happens if I don't set DBX_MCP_ALLOW_WRITES?

When DBX_MCP_ALLOW_WRITES is unset or set to 0, the MCP session operates in read-only mode. Any attempt to execute write operations or DDL statements triggers the error: "MCP SQL execution is read-only for this session. Set DBX_MCP_ALLOW_WRITES=1 to allow write statements." This default behavior is enforced in packages/node-core/src/sql-safety.ts at line 75.

Is DBX_WEB_PASSWORD required for all MCP modes?

No, DBX_WEB_PASSWORD is only required when running MCP in Web mode. According to the implementation in packages/node-core/src/web-backend.ts at line 71, the server throws "DBX Web authentication is required. Set DBX_WEB_PASSWORD for MCP Web mode" only when a Web backend client attempts authentication without this variable configured.

Can I use DBX_DISABLE_PASSWORD in production?

No. The DBX_DISABLE_PASSWORD variable is designed exclusively for local testing environments. As implemented in crates/dbx-web/src/main.rs at line 185, setting this variable to any truthy value completely removes password protection from the DBX Web server, creating a security vulnerability in production deployments.

Where are the SQL security checks enforced in the codebase?

The SQL security validations are centralized in packages/node-core/src/sql-safety.ts. Lines 75-76 handle the DBX_MCP_ALLOW_WRITES check, while lines 76-77 implement the DBX_MCP_ALLOW_DANGEROUS_SQL validation. These functions return boolean values that determine whether the query executor permits the requested operation type.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →