Introducing the SQL MCP Server - Jerry Nixon - NDC Toronto 2026
Summary
SQL MCP Server, an open-source component from Microsoft's data API builder, provides a secure and standardized abstraction layer for modern applications, especially those powered by AI agents. It allows external models to interact with enterprise databases (including SQL Server, PostgreSQL, Cosmos DB, and MySQL) without requiring direct T-SQL knowledge or exposing sensitive connection strings. The solution standardizes database access into three endpoints—REST, GraphQL, and MCP—simplifying the development process and significantly enhancing security by enforcing policies at the API layer.
Key takeaways
-
Unified Data Access Layer
2:00
The SQL MCP Server acts as a single point of entry for all data interactions, supporting multiple database types (SQL, NoSQL) and exposing three standardized APIs: REST, GraphQL, and the specialized Model Control Protocol (MCP). This abstraction layer allows developers to write code against the API surface rather than directly against the underlying schema.
-
AI Agent Integration via MCP
8:00
For AI agents, which cannot speak directly to a database, the MCP endpoint is critical. It collapses the potential hundreds of CRUD tools (one per table) into a standardized set of seven tools (Describe Entities, Create, Read, Update, Delete, etc.), preventing model overload and ensuring reliable agentic workflows.
-
Simplified Development & CI/CD
3:00
The solution aims to eliminate the need for boilerplate CRUD API code in a codebase. By using data API builder, developers can significantly reduce complexity and potential errors, streamlining the CI/CD pipeline while maintaining high functionality.
-
Advanced Security & Policy Enforcement
10:50
Security policies (like Row-Level Security) can be enforced at the API layer, even if structural changes are impossible in the underlying database. Furthermore, it supports advanced authentication methods like OpenID Connect and On Behalf Of (OBO) pass-through authentication.
Technical details
-
Data API Builder Architecture
240s
The system is containerized, running as a cross-platform HTTP endpoint that accepts configuration via a JSON file. This configuration defines the data source connection string and explicitly lists which components (tables, views) are exposed to the API.
-
API Capabilities
300s
The platform supports three primary interaction methods: REST (JSON/HTTP), GraphQL (querying a schema using simple nested queries, allowing joins between tables automatically), and MCP. The configuration file allows these capabilities to be enabled or disabled independently.
-
Deployment & Scaling
580s
The solution is designed for enterprise scale, having been used by Microsoft Fabric (a large data application). It can run in various topologies (cloud/on-premises) and supports advanced patterns like CQRS (separating read/write concerns) and multi-database querying within a single payload.
-
Core Commands
360s
Key commands include `dab init` (to create the initial configuration file), `dab add [table]` (to register database entities), and `dab start`/`dab deploy` (for running or deploying the containerized service).
Mentioned resources
- data API builder
- SQL MCP Server
- Microsoft Fabric APIs
Channel & topics
Watch on YouTube · Back to latest
This independent, AI-assisted summary is provided for commentary and informational purposes. It may contain errors or omit important context. Please watch the original video for the creator's complete presentation. Video, thumbnail, and related copyrights belong to their respective owners.