ClickHouse for AI agents
ClickHouse is an open-source, column-oriented database built for fast real-time analytics over large volumes of data using standard SQL queries. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in ClickHouse.
Query a table's data
Run a SQL query against a table to pull aggregated numbers for a dashboard.
Check a table's schema
Check a table's schema before writing a query that depends on its column types.
List available databases
List the databases available on a cluster before deciding where a new table belongs.
6 ClickHouse actions, graded by risk.
Every ClickHouse action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
5Look things up. Allowed by default.
- clickhouse.list_tablesList ClickHouse Tables
- clickhouse.list_databasesList ClickHouse Databases
- clickhouse.get_table_schemaGet Table Schema
- clickhouse.get_play_interfaceGet ClickHouse Play Interface
- clickhouse.get_database_schemaGet Database Schema
write
1Create and change things. Allow, or ask the user first.
- clickhouse.execute_queryExecute ClickHouse Query
destructive
0Delete, cancel or archive. Ask first, or deny outright.
- No destructive actions.
ClickHouse in three steps.
- 01Your users connect ClickHouseThey add their ClickHouse username and password on Arc0 Connect, under your brand. It goes straight into the vault.
- 02You set the rulesReads run, and writes like “execute ClickHouse Query” can wait for the user to approve.
- 03Any agent can actYour agent calls ClickHouse through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('clickhouse', { read: 'allow', write: 'ask', // execute_query destructive: 'deny', }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How ClickHouse connects.
Users add their ClickHouse username and password on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
The same ClickHouse connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- Username and password
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use ClickHouse from any agent.
More databases and spreadsheets apps.
ClickHouse and Arc0, answered.
Can I use ClickHouse with Claude, ChatGPT or Cursor?
Yes. Connect ClickHouse to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the ClickHouse actions you allow.
How do users connect ClickHouse?
Users add their ClickHouse username and password on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
Which ClickHouse actions can my agent take?
6 in total: 5 read, 1 write and 0 destructive, such as “execute ClickHouse Query”. Your policies decide which of them each agent may call.
Can I make my agent read-only in ClickHouse?
Yes. Allow read actions and deny writes in the ClickHouse policy. Your agent can still look things up, and any write it attempts is blocked and logged.
Can my own backend call ClickHouse too?
Yes. The same ClickHouse connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug ClickHouse into your agent.
Your users connect ClickHouse once, under your brand. Your agent gets 6 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan