Skip to main content
← Back to Articles
mcpsql servermssqldatabasecursorazure sqlsetup2026

SQL Server MCP Server Setup for Cursor IDE (2026): Query MSSQL from Chat

Connect Microsoft SQL Server to Cursor IDE with an MCP server so your AI can read schemas, write T-SQL, and debug queries without copy-pasting table structures. Covers the fragmented package landscape, a read-only login, and Azure SQL.

By Web MCP Guide•September 21, 2026•11 min read

To connect Microsoft SQL Server to Cursor, add an mcpServers entry pointing at an MSSQL MCP server package with your connection details in the env block, then restart Cursor. Once it's running, your AI can inspect table and stored-procedure definitions, write T-SQL against your real schema, and explain a slow execution plan — instead of you pasting sp_help output into chat by hand.

SQL Server is the one major relational database on this site without a single dominant, canonical MCP server package — unlike Postgres, which has an official @modelcontextprotocol/server-postgres reference implementation. The MSSQL ecosystem is served by several independently maintained npm packages, each with its own environment variable names. That's a real setup wrinkle worth understanding before you copy a config block from somewhere and it doesn't connect.

What a SQL Server MCP Server Actually Gives You

Once connected, Cursor can typically:

  • List databases, schemas, tables, and views on the connection

  • Describe column names, types, keys, and indexes for a table

  • Run SELECT queries and return results inline in chat

  • Read stored procedure and view definitions

  • Cross-reference schema with your application's ORM layer (Entity Framework, Dapper, Prisma, or similar)
  • Some packages also expose write tools (INSERT/UPDATE/DELETE, or even DDL) behind an explicit opt-in flag. Treat those as something you enable for a local dev database, not a shared or production instance, for the same reason you wouldn't hand an intern sysadmin on day one.

    The Package Landscape (Read This Before Picking One)

    Search npm for mssql-mcp or mcp-server-mssql and you'll find a handful of actively maintained options, none of them an Anthropic- or Microsoft-published reference server. Env var naming is not standardized across them — one package expects DB_SERVER/DB_DATABASE/DB_USER/DB_PASSWORD, another expects MSSQL_SERVER/MSSQL_DATABASE, and a third uses SERVER_NAME/DATABASE_NAME/SQL_USERNAME. Always check the specific package's README for its exact variable names before writing your config — the example below uses one common convention, but don't assume it's universal the way POSTGRES_URL effectively is for Postgres.

    What to check before standardizing on a package for a team:

  • Last commit date and open issue count on its repo

  • Whether it defaults to read-only or requires an explicit flag for write access

  • Whether it supports SQL Server authentication, Windows/AD auth, or both (many stdio packages only support SQL auth, since they're not running on a domain-joined host)

  • Whether it supports Azure SQL Database's connection requirements (see below) if that's your target
  • Prerequisites


  • Cursor IDE 0.43+

  • Node.js 18+ installed

  • A running SQL Server instance (local, Azure SQL Database, RDS for SQL Server, or on-prem) reachable from your machine

  • Connection details: server/host, port (default 1433), database name, and credentials for a dedicated MCP login — not your admin/sa account
  • Step 1: Create a Read-Only SQL Server Login

    Before touching mcp.json, create a scoped-down login and user with SELECT-only rights:

    CREATE LOGIN mcp_reader WITH PASSWORD = 'a-long-random-password';
    
    USE your_database;
    CREATE USER mcp_reader FOR LOGIN mcp_reader;
    ALTER ROLE db_datareader ADD MEMBER mcp_reader;
    

    db_datareader is a built-in fixed database role that grants SELECT across every table and view in the database without needing per-object grants — the SQL Server equivalent of the read-only-user pattern used for MySQL and Postgres MCP setups. If the AI only needs a subset of tables, grant SELECT on specific schemas or objects instead of the whole database.

    Step 2: Add the Server to Your MCP Config

    Open ~/.cursor/mcp.json (or Settings → MCP in Cursor) and add an entry. This example follows a DB_*-style convention that several packages use — confirm against your chosen package's README before relying on it:

    {
      "mcpServers": {
        "sqlserver": {
          "command": "npx",
          "args": ["-y", "mssql-mcp-server@latest"],
          "env": {
            "DB_SERVER": "127.0.0.1",
            "DB_DATABASE": "your_database",
            "DB_USER": "mcp_reader",
            "DB_PASSWORD": "a-long-random-password",
            "DB_ENCRYPT": "true",
            "DB_TRUST_SERVER_CERTIFICATE": "true"
          }
        }
      }
    }
    

    DB_ENCRYPT and DB_TRUST_SERVER_CERTIFICATE map to the underlying Node mssql driver's options.encrypt and options.trustServerCertificate connection settings — SQL Server 2022 and Azure SQL both expect encrypted connections by default, and a local dev instance without a trusted certificate needs the trust flag set so the driver doesn't reject the TLS handshake outright.

    Restart Cursor completely after saving the config.

    Step 3: Verify the Connection

    In Cursor chat, try:

    List the tables in this database
    

    Then follow up with something schema-specific:

    Describe the dbo.Orders table — columns, types, and any foreign keys
    

    If you get real table and column names back, the connection is live. A generic connection-refused or auth error at this point almost always traces back to Step 2's env var names not matching what the package actually expects — go back and check its README rather than assuming the config syntax itself is wrong.

    Step 4: Practical Workflows

    Understand an unfamiliar schema

    Look at the Customers, Orders, and OrderLines tables and explain
    how they relate to each other, including any foreign keys
    

    Write a migration by describing the change in English

    The Orders table needs a CancelledAt datetime2 column and a
    non-clustered index on (Status, CancelledAt). Write the T-SQL
    in the style of the other scripts in /db/migrations.
    

    Debug a slow query

    This query takes 6 seconds: [paste query]. Look at the table
    definitions and tell me what index would help, and show me
    the CREATE INDEX statement.
    

    Read a stored procedure before changing it

    Show me the definition of dbo.usp_CalculateInvoiceTotals and
    explain what it does before I modify it
    

    Connecting to Azure SQL Database

    Azure SQL Database is SQL Server-compatible but has a few connection differences worth calling out separately from a self-hosted instance:

    {
      "mcpServers": {
        "azuresql-readonly": {
          "command": "npx",
          "args": ["-y", "mssql-mcp-server@latest"],
          "env": {
            "DB_SERVER": "your-server.database.windows.net",
            "DB_DATABASE": "your_database",
            "DB_USER": "mcp_reader",
            "DB_PASSWORD": "a-long-random-password",
            "DB_ENCRYPT": "true",
            "DB_TRUST_SERVER_CERTIFICATE": "false"
          }
        }
      }
    }
    

    The two differences: the hostname ends in .database.windows.net, and DB_TRUST_SERVER_CERTIFICATE should be false rather than true — Azure SQL presents a certificate signed by a trusted authority, so there's no reason to skip validation the way you might for a local instance without one. You'll also need Azure SQL's firewall to allow your machine's IP, configured separately in the Azure portal or via az sql server firewall-rule create.

    If your team runs infrastructure primarily on Azure rather than connecting to one database in isolation, the Azure MCP server setup guide covers the broader Azure resource-management server, which is a different tool than this database-specific connection.

    Name the connection entry to signal its blast radius (azuresql-readonly, not just sql) — when you have both a local and an Azure connection configured at once, an ambiguous name is how someone runs a prompt against the wrong environment.

    Troubleshooting

    "Login failed for user" error
    Double-check the login name and password in your env block match exactly what you created in Step 1. Also confirm the login has CONNECT permission on the database and hasn't been created as a login only, without a corresponding database user (the CREATE USER ... FOR LOGIN step is easy to skip).

    "A network-related or instance-specific error occurred"
    This is SQL Server's generic can't-reach-the-server error. Verify SQL Server is configured to accept TCP/IP connections (not just named pipes) via SQL Server Configuration Manager, and that port 1433 (or your custom port) isn't blocked by a firewall.

    SSL/TLS handshake failure
    If you're on a local instance without a proper certificate, set DB_TRUST_SERVER_CERTIFICATE (or your package's equivalent) to true. If you're on Azure SQL and still seeing this, the problem is more likely an outdated Node mssql driver version bundled in the package than the certificate itself.

    Server doesn't appear in Cursor after editing mcp.json
    Fully quit and reopen Cursor — a window reload isn't always enough to pick up new MCP entries. Then check View → Output → MCP for startup errors.

    Env vars look right but connection still fails
    Confirm you're using the exact variable names your chosen package expects. This is the most common failure mode for SQL Server specifically, because — unlike Postgres or MySQL — there's no single dominant package whose naming convention everyone else copied.

    Frequently Asked Questions

    Q: Is there an official Microsoft-maintained MCP server for SQL Server?
    A: Not a single canonical one publicly documented at the time of writing, unlike Postgres's official reference server. The space is served by several independently maintained npm packages. Check activity and open issues on GitHub before standardizing on one for a team, and revisit that choice periodically.

    Q: Does this work with Windows Authentication / Active Directory login instead of a SQL login?
    A: Support varies by package — many Node-based MSSQL MCP servers only implement SQL Server authentication (username/password), since they're typically run from a non-domain-joined machine or container where AD auth isn't practical. If you specifically need AD/Entra ID auth, check the package's README before assuming it's supported.

    Q: Can the AI accidentally modify data through this?
    A: Only if the login you configured has write privileges, or the package explicitly enables write tools. Granting the db_datareader role (Step 1) and nothing else makes write statements fail at the database layer regardless of what the model attempts — a more reliable boundary than trusting the MCP server's own confirmation logic.

    Q: How is Azure SQL Database different from SQL Server for this setup?
    A: The MCP server and query behavior are the same — Azure SQL speaks the same TDS wire protocol. The differences are operational: a .database.windows.net hostname, mandatory encrypted connections with a trusted certificate, and a portal-managed firewall that needs your IP allow-listed before any connection (local or MCP) will succeed.

    Q: My queries return truncated results — why?
    A: Some MSSQL MCP packages cap result rows by default to avoid flooding the chat context window. Narrow the query with a WHERE clause or TOP instead of requesting an entire large table at once.

    Related Guides


  • MySQL MCP Server Setup for Cursor IDE (2026)

  • PostgreSQL MCP Server Setup Guide

  • MongoDB MCP Server: Cursor IDE Setup (2026)

  • Azure MCP Server: Cursor IDE Setup (2026)

  • DynamoDB MCP Server: Cursor IDE Setup (2026)

  • How to Authenticate MCP Servers: OAuth & API Keys

  • MCP Security Best Practices




  • Related guides