Adobe Customer Journey Analytics
Run cross-channel reports and build segments in Adobe Customer Journey Analytics.
Query a serverless DuckDB warehouse.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The MotherDuck MCP server connects a serverless DuckDB data warehouse to Claude, ChatGPT and any MCP-compatible agent. It runs SQL against your databases, explores schemas, searches the catalogue and builds Dives — interactive saved visualisations. Two of its tools execute arbitrary SQL, one of them read-write, which sets the risk profile for everything else.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
query and query_rw the read/write distinction is a property of the SQL string, not of the tool. query_rw will run DROP as readily as SELECT.read:databases is the only non-identity scope either the resource or its authorization server advertises, on a connector Anthropic's directory labels "Read and write". A consent screen cannot express read-only here.search_catalog returns at most 100 results.tools/list response was seen and no safety annotation is reported here. Tool names come from Anthropic's directory and MotherDuck's reference; parameters come from the reference.motherduckdb/mcp-server-motherduck is theYes, through two tools. `query` takes a raw DuckDB SQL string and MotherDuck restricts it to read-only statements, rejecting anything that modifies data with a ForbiddenQueryError. `query_rw` takes the same free-text SQL with no verb restriction, so INSERT, UPDATE, DELETE, DROP TABLE and CREATE DATABASE all run through it. Neither tool constrains which tables you touch.
No. MotherDuck documents three ways to restrict it and none is a server mode, so the tool list never changes. You either block `query_rw` in your MCP client, authenticate with a read-scaling token whose replicas reject writes at the database, or filter tool calls in your own proxy. Only the read-scaling token enforces anything server-side.
Yes, through SQL. A SELECT issued via `query` or `query_rw` returns real table rows, capped at 2,048 rows and 50,000 characters per call. The catalogue tools do not: `list_tables`, `list_columns` and `search_catalog` return names, types and comments only. Reading customer data always goes through one of the two SQL tools.
MotherDuck documents 39 and Anthropic's directory lists 15. The 15 are an exact subset of the 39, with no renamed or invented names in either direction. The 24 the directory omits are the Flight tools, which create schedule and run Python jobs on MotherDuck compute, the Guide tools, and three catalogue tools. Both figures were retrieved on 2026-08-21.
Three things, and one of them is unbounded. `delete_dive` permanently removes a saved Dive and MotherDuck states it cannot be recovered. Undocumented in the directory listing, `delete_flight` and `delete_guide` remove scheduled jobs and Guide documents. Beyond those, `query_rw` accepts DROP TABLE and DROP DATABASE as ordinary SQL, so its blast radius is whatever your token can reach.
No. MotherDuck's prerequisites are a MotherDuck account and an MCP-compatible client, and the free Lite plan includes 10 compute-unit hours and 10 GB of storage per month. Dives carry no additional charge on any plan. Compute and storage beyond the included allowance are billed pay-as-you-go, so an agent running many queries has a cost consequence rather than a hard cap.
Five, of which only one is an application scope. The resource descriptor at api.motherduck.com advertises `openid`, `profile`, `email`, `offline_access` and `read:databases`. Four of those are OIDC identity and refresh scopes. That leaves a single coarse application grant on a connector that also writes, so the consent screen offers nothing meaningful to narrow.
www-authenticate challenge, and the RFC 9728 descriptor at api.motherduck.com/.well-known/oauth-protected-resource/mcp returned 200 (2026-08-21) · retrieved 2026-08-21motherduckdb/mcp-server-motherduck tag v1.0.8 (retrieved 2026-08-21) · retrieved 2026-08-21motherduck.com/robots.txt carries Content-Signal: ai-train=yes, search=yes, ai-input=yes — synthesis is expressly permitted (retrieved 2026-08-21) · retrieved 2026-08-21Connect MotherDuck once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.