ClickHouse for AI agents

ClickHouse is an open-source, column-oriented database built for fast real-time analytics over large volumes of data using standard SQL queries. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Databases and spreadsheetsUsername and passwordMCP + RESTclickhouse.com
AUDIT LOG · CLICKHOUSEPOLICY: acme-support
09:41:07 · claude · u_8f2read
clickhouse.list_tables
List ClickHouse Tables✓ allowed · 212ms
09:41:08 · claude · u_8f2read
clickhouse.list_databases
List ClickHouse Databases✓ allowed · 164ms
09:41:09 · claude · u_8f2write
clickhouse.execute_query
Execute ClickHouse Query✓ approved · approved by user
EVERY CLICKHOUSE CALL, ON THE RECORD
01 · USE CASES

What agents do in ClickHouse.

01

Query a table's data

Run a SQL query against a table to pull aggregated numbers for a dashboard.

02

Check a table's schema

Check a table's schema before writing a query that depends on its column types.

03

List available databases

List the databases available on a cluster before deciding where a new table belongs.

02 · ACTIONS

6 ClickHouse actions, graded by risk.

Every ClickHouse action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

5

Look things up. Allowed by default.

  • clickhouse.list_tables
    List ClickHouse Tables
  • clickhouse.list_databases
    List ClickHouse Databases
  • clickhouse.get_table_schema
    Get Table Schema
  • clickhouse.get_play_interface
    Get ClickHouse Play Interface
  • clickhouse.get_database_schema
    Get Database Schema

write

1

Create and change things. Allow, or ask the user first.

  • clickhouse.execute_query
    Execute ClickHouse Query

destructive

0

Delete, cancel or archive. Ask first, or deny outright.

  • No destructive actions.
03 · HOW IT WORKS

ClickHouse in three steps.

  1. 01Your users connect ClickHouseThey add their ClickHouse username and password on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, and writes like “execute ClickHouse Query” can wait for the user to approve.
  3. 03Any agent can actYour agent calls ClickHouse through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('clickhouse', {
  read: 'allow',
  write: 'ask',        // execute_query
  destructive: 'deny',  
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How ClickHouse connects.

Users add their ClickHouse username and password on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same ClickHouse connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
Username and password
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use ClickHouse from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

ClickHouse and Arc0, answered.

Q01

Can I use ClickHouse with Claude, ChatGPT or Cursor?

Yes. Connect ClickHouse to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the ClickHouse actions you allow.

Q02

How do users connect ClickHouse?

Users add their ClickHouse username and password on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which ClickHouse actions can my agent take?

6 in total: 5 read, 1 write and 0 destructive, such as “execute ClickHouse Query”. Your policies decide which of them each agent may call.

Q04

Can I make my agent read-only in ClickHouse?

Yes. Allow read actions and deny writes in the ClickHouse policy. Your agent can still look things up, and any write it attempts is blocked and logged.

Q05

Can my own backend call ClickHouse too?

Yes. The same ClickHouse connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug ClickHouse into your agent.

Your users connect ClickHouse once, under your brand. Your agent gets 6 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan