Ask your IBM i
in plain language.
Give Claude, Cursor and other AI assistants read-only access to Db2 for i. It connects through the host servers your IBM i already runs, or over SSH, so there is nothing new to install on the system.
npx mcp-server-db2i- Transport
- stdio · HTTP
- Auth
- OAuth 2.1
- Database
- Db2 for i
- Drivers
- ODBC · JT400 · Mapepire
- On the IBM i
- No server install
- Access
- READ ONLY
Example
One question, from plain language to rows.
Which customers have the most open orders right now?
Table note: STATUS = 'O' means open.
SELECT C.NAME, COUNT(*) AS OPEN_ORDERS
FROM MYLIB.ORDERHDR H
JOIN MYLIB.CUSTOMERS C ON C.CUSTNO = H.CUSTNO
WHERE H.STATUS = 'O'
GROUP BY C.NAME
ORDER BY OPEN_ORDERS DESC
FETCH FIRST 3 ROWS ONLYThree customers account for most of the open orders.
| Customer | Open orders |
|---|---|
| Acme Tools | 14 |
| Birch Supply | 9 |
| Harbor Parts | 7 |
Where to start
Two ways in, depending on your role.
What you get
Built for production IBM i systems.
The read-only checks are always on. The allowlist, masking and audit log are one setting each. Every control is documented, so your IBM i team can see exactly what is enforced and where.
Safety
Reads only, and only what you allow.
- Read-only by designA read-only database connection and a SQL validator that only accepts queries. A timeout also cancels runaway statements on the IBM i itself.→
- Library allowlist and maskingLimit queries and catalog browsing to the libraries you choose. Redact sensitive columns, or show only their last four characters.→
- IBM i checks the SQLvalidate_query parses a statement on the IBM i and checks every table and column against the catalog before anything runs.→
Connection
Fits the network you have.
Auth
Everyone signs in as themselves.
Context
Answers in your own terms.
Operations
Every call on the record.
How it fits together
From a question to Db2 for i and back.
The server sits between your AI assistant and the IBM i. Every request passes the same checks, whichever client or driver you use.
- Client
AI assistant
Claude, Cursor, Claude Code, or any client that speaks the Model Context Protocol.
- Server
mcp-server-db2i
stdio on your machine, or HTTP with OAuth for a team.
- Policy
Checks on every call
- Read-only SQL validation ON
- Library allowlist ON
- Column masking OPT
- Rate limits and audit log OPT
- Driver
ODBC, JT400 or Mapepire
Host server ports, or SSH only.
- System
Db2 for i
Runs with the user's own authority. Exit programs still apply.
Install
Pick how you run it.
The default ODBC driver needs unixODBC and the IBM i Access ODBC Driver on the machine that runs the server. Nothing is installed on the IBM i.
Add the server to your MCP client config. Claude Desktop, Cursor and Claude Code all use this shape.
{
"mcpServers": {
"db2i": {
"command": "npx",
"args": ["-y", "mcp-server-db2i@latest"],
"env": {
"DB2I_HOSTNAME": "ibmi.example.com",
"DB2I_USERNAME": "${env:DB2I_USERNAME}",
"DB2I_PASSWORD": "${env:DB2I_PASSWORD}",
"QUERY_ALLOWED_SCHEMAS": "MYLIB"
}
}
}
}Run it as a container: started by your MCP client over stdio, or as a shared HTTP server for your team.
git clone https://github.com/Strom-Capital/mcp-server-db2i
cd mcp-server-db2i
docker build -t mcp-server-db2i .
# stdio: your MCP client starts the container
docker run -i --rm --env-file .env mcp-server-db2i
# HTTP for a team: uncomment "ports" in docker-compose.yml
docker-compose up -dRun the server over HTTPS with OAuth. Everyone else adds one URL and signs in with their own IBM i profile. The same connector works in Claude for Excel.
MCP_TRANSPORT=http
MCP_OAUTH_ENABLED=true
MCP_PUBLIC_URL=https://mcp.example.com
MCP_OAUTH_SECRET=<a long random string>
# Then, in claude.ai: Settings > Connectors > Add custom connector
# URL: https://mcp.example.com/mcpOther options
Which MCP server fits you.
IBM maintains its own open-source MCP server for IBM i. Both are free, and they start from different places. Here is how to choose.
From the blog
What's new, and why.
All postsThe whole list as a spreadsheet
Ask for all the open orders for a customer and get a file you can open in Excel, not a summary in the chat.→Query exports and staying signed in (2.12)
export_query writes every row of a read-only query to a CSV or XLSX file, OAuth sign-ins survive restarts, and fixes for non-ASCII text, binary columns and the schema allowlist.→What "open order" means at your company
How your own business definitions, written down once, keep an AI assistant from guessing about your ERP data. Explained without the technical detail.→
Open source
Free, open source, and yours to run.
MIT licensed. It runs on your own machines and talks only to your IBM i. Questions, ideas and bug reports are welcome on GitHub.
If it saves your team time, sponsoring pays for testing against real IBM i systems and new features.