# Db2 for i MCP Server > An open-source Model Context Protocol (MCP) server that lets Claude, Cursor and other AI assistants read IBM Db2 for i. It is read-only by design: a read-only connection, a SQL validator and a library (schema) allowlist, with column masking, OAuth sign-in with an IBM i user profile and an audit log. It connects through the host servers the IBM i already runs, or over SSH, so nothing is installed on the IBM i. - Package, CLI and repository name: `mcp-server-db2i` (npm, MIT license). Run it with `npx mcp-server-db2i`. - MCP Registry name: `io.github.Strom-Capital/mcp-server-db2i`. - Drivers: IBM i Access ODBC (the default, no Java), JT400 JDBC, or Mapepire over SSH. - Transports: stdio for local clients (Claude Desktop, Claude Code, Cursor) and Streamable HTTP for remote clients such as claude.ai connectors. - One server can reach several IBM i systems through connection profiles. - Teams can add their own business SQL tools and table notes in YAML. - It does not write to the database and does not replace governed financial reporting. ## Docs - [Documentation](https://docs.db2i-mcp.com): full docs, with their own index at https://docs.db2i-mcp.com/llms.txt - [Quickstart](https://docs.db2i-mcp.com/quickstart): install and connect a first client - [Client setup](https://docs.db2i-mcp.com/client-setup): Claude Desktop, Claude Code, Cursor, claude.ai and Claude for Excel - [Tools](https://docs.db2i-mcp.com/tools): the built-in MCP tools - [Configuration](https://docs.db2i-mcp.com/configuration): environment variables, drivers and several systems - [Security](https://docs.db2i-mcp.com/security): read-only enforcement, allowlist, masking and audit log - [HTTP transport and OAuth](https://docs.db2i-mcp.com/http-transport): remote clients and sign-in - [Custom tools](https://docs.db2i-mcp.com/custom-tools): business SQL tools in YAML - [Use cases](https://docs.db2i-mcp.com/use-cases): example questions for ERP data on IBM i ## Site - [Home](https://db2i-mcp.com/): what the server does and how it compares with other MCP servers for IBM i - [For business teams](https://db2i-mcp.com/business): example questions for sales, purchasing, service, manufacturing and finance - [Blog](https://db2i-mcp.com/blog): release write-ups (RSS: https://db2i-mcp.com/rss.xml) ## Blog posts - [The whole list as a spreadsheet](https://db2i-mcp.com/blog/the-whole-list-as-a-spreadsheet/): Ask for all the open orders for a customer and get a file you can open in Excel, not a summary in the chat. - [Query exports and staying signed in (2.12)](https://db2i-mcp.com/blog/query-exports-and-staying-signed-in/): export_query writes every row of a read-only query to a CSV or XLSX file, OAuth sign-ins survive restarts, and fixes for non-ASCII text, binary columns and the schema allowlist. - [What "open order" means at your company](https://db2i-mcp.com/blog/what-open-order-means-at-your-company/): How your own business definitions, written down once, keep an AI assistant from guessing about your ERP data. Explained without the technical detail. - [New questions for the ERP data you already have](https://db2i-mcp.com/blog/new-questions-for-the-erp-data-you-already-have/): How an AI assistant can answer the one-off questions between reports, against live ERP data on IBM i, alongside the screens, Excel workbooks and BI tools you already use. - [Services, timeouts and routines (2.10 and 2.11)](https://db2i-mcp.com/blog/services-timeouts-and-routines/): A query timeout that cancels on the IBM i, IBM i services search, SQL errors with cause and recovery text, index advice, and procedures and functions. - [Sign in with your IBM i profile](https://db2i-mcp.com/blog/sign-in-with-your-ibm-i-profile/): A built-in OAuth 2.1 server lets claude.ai, Cursor and Claude Code connect with one URL. Everyone signs in as themselves and queries run with their own authority. - [Mapepire is back, over SSH](https://db2i-mcp.com/blog/mapepire-is-back-over-ssh/): I dropped the Mapepire driver earlier. Its new SSH mode changes the trade-off, so it's back, for systems where only port 22 is open. - [No Java by default, and several systems from one server](https://db2i-mcp.com/blog/no-java-by-default-and-several-systems/): The IBM i Access ODBC driver is now the default, JT400 is optional, and one server can reach production, test and development side by side. - [Finding things and keeping control](https://db2i-mcp.com/blog/finding-things-and-keeping-control/): Search across libraries, profile a table, check journaling, read tables as MCP resources, and mask sensitive columns with every call written to an audit log. - [Teaching the model your schema with YAML](https://db2i-mcp.com/blog/teaching-the-model-your-schema-with-yaml/): Table notes and named business tools, written once in YAML, so the model uses your definitions instead of guessing. - [Let IBM i check the model's work](https://db2i-mcp.com/blog/let-ibm-i-check-the-models-work/): Three tools that push validation to the system itself, so the model finds out about a wrong column name before anything runs. - [2.0: the current MCP spec and stricter read-only guarantees](https://db2i-mcp.com/blog/2-0-current-mcp-spec-and-stricter-read-only/): The server now speaks the 2026-07-28 MCP spec, the database connection itself is read-only, and a library allowlist limits what the model can reach. - [Hardening 1.x, and an HTTP transport](https://db2i-mcp.com/blog/hardening-1x-and-http-transport/): A stricter SQL validator, rate limits and result limits, Docker secrets, and a way for web apps and agents to connect over HTTP. - [Open-sourcing an MCP server for Db2 for i](https://db2i-mcp.com/blog/open-sourcing-an-mcp-server-for-db2-for-i/): Why I built a way for Claude and Cursor to read IBM i databases directly, and what the first release does. ## Optional - [GitHub repository](https://github.com/Strom-Capital/mcp-server-db2i): source and issues - [Changelog](https://github.com/Strom-Capital/mcp-server-db2i/blob/main/CHANGELOG.md) - [npm package](https://www.npmjs.com/package/mcp-server-db2i)