Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

Local YDB MCP

NPM · @ASTANDRIK/LOCAL-YDB-MCP · SCANNED AUG 3

Operate local-ydb deployments through local or SSH-backed MCP tools.

+55 this week 81 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →

Supply Chain Security90
  • No malware found by supply-chain analysis.Pass
  • Only part of the dependency tree could be resolved (145 of 150), so this covers what we could see, not the whole tree.Partial
  • No install/post-install scripts declared.Pass
  • Only part of the dependency tree could be resolved (145 of 150), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency97
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to astandrik/local-ydb-toolkit). View diagnostics → Pass
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 0 days ago).Pass
  • Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability76
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 8091 tokens (~207/item across 39 items; 39 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

npm · @astandrik/local-ydb-mcp

# add to Claude Code
claude mcp add astandrik-local-ydb-mcp -- npx -y @astandrik/local-ydb-mcp
# add to Codex CLI
codex mcp add astandrik-local-ydb-mcp -- npx -y @astandrik/local-ydb-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "astandrik-local-ydb-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@astandrik/local-ydb-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add astandrik-local-ydb-mcp --command npx --arg -y --arg @astandrik/local-ydb-mcp
# ~/.hermes/config.yaml
mcp_servers:
  astandrik-local-ydb-mcp:
    command: "npx"
    args: ["-y", "@astandrik/local-ydb-mcp"]
// mcp.json
{
  "mcpServers": {
    "astandrik-local-ydb-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@astandrik/local-ydb-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 +1
    • Package version: 0.14.1 → 0.15.0 functional
  • 2 Aug 26 +29
    • Known CVEs: unverified → partial security
    • Provenance: unverified → pass security
    • Install scripts: unverified → pass security
    • The attested source repository moved: astandrik/local-ydb-toolkit security
    • Maintenance: unverified → pass functional
    • Dependency health: unverified → partial functional
    • Stability: unverified → 0.23 functional
    • License: unverified → pass functional
    • Licence: MIT functional
  • 1 Aug 26 +46
    • Malware scan: unverified → pass security
    • Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window). security
    • Schema quality: unverified → 100 functional
    • MCP protocol: unverified → pass functional
    • Tool coverage: unverified → 100 functional
  • 31 Jul 26 −70
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 −18
    • Malware scan: pass → unverified security
  • 29 Jul 26 +8
    • Schema quality: unverified → excellent functional
  • 28 Jul 26 +59
    • Known CVEs: unverified → partial security
    • Provenance: unverified → pass security
    • Install scripts: unverified → pass security
    • The attested source repository moved: astandrik/local-ydb-toolkit security
    • Security disclosure: unverified → fail functional
    • Maintenance: unverified → pass functional
    • Schema quality: unverified → 100 functional
    • License: unverified → pass functional
    • Tool coverage: unverified → 100 functional
    • First check of Tool coverage: 100 functional
    • First check of Schema quality: unverified functional
    • First check of Schema quality: fail functional
    • First check of Schema quality: fail functional
    • Licence: MIT functional
  • 26 Jul 26 26

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Analysed npm/@astandrik/[email protected]

Provenance verified

Ecosystem: npm · Outcome: verified

Reason: verified

Source repo:
astandrik/local-ydb-toolkit
Certificate issuer:
https://token.actions.githubusercontent.com
Certificate SAN:
https://github.com/astandrik/local-ydb-toolkit/.github/workflows/publish-mcp-server.yml@refs/heads/main
Rekor log index:
2336581121
Predicate type:
https://slsa.dev/provenance/v1
Subject digest:
sha512:562bcb2db5a4397a805d1ef2a04c10045dcdd9597d42d4865105dae6983b572bcd29008703bc8b81b4de90c608399ed2dad1e2e4f8c3bf27eb596a948
Discovery method:
attestation_endpoint
Dependencies 145 packages

145 packages in the resolved dependency tree · 123 deprecated · 40 stale.

The dependency tree was only partially resolved, so these counts may be incomplete.

MCP tools — 39 exposed · ~6,881 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
local_ydb_add_dynamic_nodes ~275

Add extra dynamic tenant nodes beyond the configured primary dynamic node, one at a time. Without confirm=true it returns container/port plans; with confirm=true it starts each node, verifies its IC port appears in viewer/json nodelist, and checks tenant metadata.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to execute planned commands. Omit or false for plan-only output.
countintegerNumber of additional dynamic nodes to add. Defaults to 1.
grpcPortStartintegergRPC port for the first added node. Defaults to profile.dynamicGrpc + startIndex - 1.
icPortStartintegerInterconnect port for the first added node. Defaults to profile.dynamicIc + startIndex - 1.
monitoringPortStartintegerMonitoring port for the first added node. Defaults to profile.dynamicMonitoring + startIndex - 1.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.
startIndexintegerSuffix for the first added container. Defaults to 2, producing <dynamicContainer>-2.

No output schema declared.

No examples provided.

local_ydb_add_storage_groups ~180

Increase NumGroups for one tenant storage pool using the current ReadStoragePool definition. Without confirm=true this returns the DefineStoragePool plan, rollback, target pool, and target count; when the update succeeds it verifies NumGroups and tenant metadata.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to execute planned commands. Omit or false for plan-only output.
countintegerNumber of storage groups to add. Defaults to 1.
poolNamestringExplicit storage pool name. Defaults to <tenantPath>:<storagePoolKind>.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_apply_auth_hardening ~168

Apply a reviewed hardened YDB config file and restart local-ydb so auth settings take effect. Use only after preparing and reviewing the config; without confirm=true this returns the apply/restart plan only.

NameTypeReqDescription
configHostPathstringReviewed config.yaml path on the selected target host. Defaults to profile.authConfigPath when present.
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to apply the auth hardening config and restart local-ydb. Omit or false for plan-only output.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_apply_schema ~291

Validate or apply YDB table DDL through the official YDB JS SDK. It accepts raw YQL DDL for PRAGMA plus CREATE TABLE, ALTER TABLE, and DROP TABLE; action=apply validates first and executes only with confirm=true.

NameTypeReqDescription
actionstringSchema operation to run. validate only checks the YQL DDL through the YDB SDK; apply validates first and executes only with confirm=true.
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to execute action=apply after SDK validation succeeds. Omit or false for validation plus plan-only output.
databasePathstringYDB database path for SDK validation/application. Defaults to the configured tenant root; root database paths use the static gRPC port.
maxOutputBytesintegerMaximum UTF-8 bytes returned per validation/execution issue stream. Defaults to 65536.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.
scriptstringyesYQL DDL script to validate or apply. Supports PRAGMA plus CREATE TABLE, ALTER TABLE, and DROP TABLE statements.
timeoutMsintegerSDK operation timeout in milliseconds. Defaults to 120000.

No output schema declared.

No examples provided.

local_ydb_auth_check ~110

Read-only auth audit that checks anonymous viewer whoami status and configured YDB CLI tenant access, using root credentials when rootPasswordFile is configured. Use after auth hardening or password rotation to verify the expected posture.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_bootstrap ~141

Bootstrap a tenant topology: static node with GraphShard flags, configured CMS tenant, and primary dynamic tenant node. Use only for tenant, GraphShard, dump/restore, or dynamic-node scenarios; without confirm=true this returns the full plan and creates nothing.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to execute planned commands. Omit or false for plan-only output.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_bootstrap_root_database ~152

Bootstrap a plain local YDB database at /local with only a static node. Use for generic local database requests that do not need a CMS tenant, GraphShard, or dynamic nodes; without confirm=true this returns the image preflight, Docker network/storage/static-node, and verification plan without executing it.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to execute planned commands. Omit or false for plan-only output.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_check_prerequisites ~149

Check target-host prerequisites for Docker, curl, ruby, and the configured rootPasswordFile when present. Without confirm=true it returns checks, missing items, manual actions, and any apt-get install plan; with confirm=true it may install only supported curl/ruby packages and never installs Docker.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to execute planned commands. Omit or false for plan-only output.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_cleanup_storage ~184

Delete only the explicitly supplied local-ydb host paths or Docker volumes. Use after inspecting local_ydb_storage_leftovers; without confirm=true this returns the cleanup plan and removes nothing.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to remove the explicitly supplied storage paths or Docker volumes. Omit or false for plan-only output.
pathsarrayExplicit host filesystem paths to remove. Nothing is deleted unless each path is supplied here and confirm=true.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.
volumesarrayExplicit Docker volume names to remove. Nothing is deleted unless each volume is supplied here and confirm=true.

No output schema declared.

No examples provided.

local_ydb_container_logs ~146

Read recent Docker logs from the configured static or primary dynamic local-ydb container. Use when bootstrap, restart, or readiness checks fail; target selects the container role and lines controls the tail length.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
linesintegerNumber of recent log lines to read. Defaults to 200.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.
targetstringyesContainer role to read logs from: static node or primary dynamic tenant node.

No output schema declared.

No examples provided.

local_ydb_create_tenant ~131

Create the configured CMS tenant when the static node is already running. Use before local_ydb_start_dynamic_node for tenant topologies; without confirm=true this returns the planned status/create command and creates nothing.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to execute planned commands. Omit or false for plan-only output.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_database_status ~116

Read-only YDB admin database status for the configured tenant path. Returns the command, stdout, stderr, and ok flag; use this for tenant state before bootstrap/restart troubleshooting, and use local_ydb_tenant_check for scheme reachability.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_destroy_stack ~194

Remove tenant metadata, local-ydb containers, network, and storage for a profile, with optional host-path cleanup.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to execute planned commands. Omit or false for plan-only output.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.
removeAuthArtifactsbooleanDelete explicit authConfigPath, dynamicNodeAuthTokenFile, and rootPasswordFile when configured. Defaults to false.
removeBindMountPathbooleanDelete profile.bindMountPath when the profile uses a bind mount. Defaults to false.
removeDumpHostPathbooleanDelete profile.dumpHostPath. Defaults to false because it may be shared.

No output schema declared.

No examples provided.

local_ydb_dump_tenant ~195

Dump the configured tenant or a tenant-relative path using a local-ydb helper container on the static container network. It creates profile.dumpHostPath/dumpName, excludes .sys objects, writes the dump under dumpName/tenant, and without confirm=true returns the mkdir/helper-container plan only.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to dump the tenant. Omit or false for plan-only output.
dumpNamestringOptional dump directory name under profile.dumpHostPath.
pathstringRelative YDB object or directory path to dump inside the configured tenant. Defaults to . for tenant-wide dump semantics.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_generate_schema ~244

Read-only structured YDB table DDL generator. It renders strict JSON specs for CREATE TABLE, ALTER TABLE, DROP TABLE, and secondary indexes, returns the generated script with official references and warnings, and can optionally validate through the YDB JS SDK without applying changes.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
databasePathstringYDB database path to use when validate=true. Defaults to the configured tenant root.
maxOutputBytesintegerMaximum UTF-8 bytes returned per validation issue stream when validate=true. Defaults to 65536.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.
statementsarrayyesStructured schema statement specs to render into YDB table DDL.
timeoutMsintegerSDK validation timeout in milliseconds when validate=true. Defaults to 120000.
validatebooleanIf true, validate the generated DDL through local_ydb_apply_schema action=validate. This tool never applies DDL.

No output schema declared.

No examples provided.

local_ydb_graphshard_check ~115

Read-only GraphShard check through viewer/json capabilities and tabletinfo for the configured tenant. Returns graphShardExists, tablet ids, and viewer status details; use after tenant bootstrap when GraphShard support or tablet visibility is the specific question.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_healthcheck ~285

Read-only YDB monitoring healthcheck for the configured tenant or root database. Uses the official YDB CLI SelfCheck path, returns selfCheckResult, issue counts, issue types, capped raw output, and whether the database is healthy; use after local_ydb_status_report for database-level diagnostics.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
databasePathstringYDB database path to check. Defaults to the configured tenant path; only the configured tenant path or root database path are accepted.
maxIssuesintegerMaximum number of issue_log entries returned in the issues field. Counts still cover the full response. Defaults to 100.
maxOutputBytesintegerMaximum UTF-8 bytes returned per raw stdout/stderr stream. Defaults to 65536.
noCachebooleanPass --no-cache to force YDB to bypass cached healthcheck results.
noMergebooleanPass --no-merge to keep individual YDB healthcheck issue records separate.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.
timeoutMsintegerServer-side YDB healthcheck timeout in milliseconds. Defaults to 120000.

No output schema declared.

No examples provided.

local_ydb_inventory ~116

Read-only Docker inventory for a local-ydb target profile. Returns the public profile, Docker containers and volumes visible on the selected target, and inspect data for the configured static and primary dynamic containers; use before mutating tools to capture current stack state.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_list_dumps ~105

Read-only list of available tenant dumps under profile.dumpHostPath. Use before restore to choose a dumpName; it only reports top-level dump directories that contain the existing tenant dump folder.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_list_versions ~126

List published registry tags for a local-ydb container image, with numeric version tags sorted newest first. Use before local_ydb_upgrade_version to choose a target tag; pageSize and maxPages bound registry pagination and the response reports truncation.

NameTypeReqDescription
imagestringContainer image name to inspect. Defaults to ghcr.io/ydb-platform/local-ydb.
maxPagesintegerMaximum number of registry pages to fetch before truncating the result. Defaults to 10.
pageSizeintegerRequested tags per registry page. Defaults to 100.

No output schema declared.

No examples provided.

local_ydb_nodes_check ~107

Read-only check of dynamic node registration through viewer/json nodelist. Use after starting, adding, or removing dynamic nodes; use local_ydb_tenant_check first when tenant reachability is unknown.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_permissions ~270

Inspect or change YDB scheme permissions for a path. The default list action is read-only; grant, revoke, set, clear, chown, and inheritance changes return a plan unless confirm=true.

NameTypeReqDescription
actionstringPermissions operation to run. Defaults to list, which is read-only and does not require confirm.
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to execute mutating actions. Omit or false for plan-only output. Not required for action=list.
maxOutputBytesintegerFor action=list, maximum UTF-8 bytes returned per stdout/stderr stream. Defaults to 65536.
ownerstringNew owner for action=chown.
pathstringScheme path to manage. Defaults to the configured tenant root.
permissionsarrayPermission names for grant, revoke, and set actions. Each item is passed as its own -p argument.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.
subjectstringUser or group subject for grant, revoke, and set actions.

No output schema declared.

No examples provided.

local_ydb_prepare_auth_config ~196

Generate a hardened YDB config from the current static-node config. Use before local_ydb_write_dynamic_auth_config and local_ydb_apply_auth_hardening; without confirm=true this returns the planned write only.

NameTypeReqDescription
configHostPathstringHost path for the generated hardened config. Defaults to profile.authConfigPath when present.
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to write the hardened config file. Omit or false for plan-only output.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.
sidstringSID to place into viewer, monitoring, administration, and register_dynamic_node_allowed_sids. Defaults to profile.dynamicNodeAuthSid or root@builtin.

No output schema declared.

No examples provided.

local_ydb_pull_image ~160

Plan or start a background Docker pull for a local-ydb image on the selected target. Without confirm=true it returns inspect and pull commands only; with confirm=true it returns a jobId for local_ydb_pull_status unless the image is already present.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to start the background Docker pull. Omit or false for plan-only output.
imagestringContainer image to pull. Defaults to the selected profile image.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_pull_status ~47

Check the status of a background Docker image pull started by local_ydb_pull_image.

NameTypeReqDescription
jobIdstringyesBackground pull job id returned by local_ydb_pull_image.

No output schema declared.

No examples provided.

local_ydb_reduce_storage_groups ~194

Reduce NumGroups for a tenant storage pool by dumping the tenant, rebuilding the profile stack with a smaller storagePoolCount, restoring the dump, and reapplying auth when needed.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to execute planned commands. Omit or false for plan-only output.
countintegerNumber of storage groups to remove from the current tenant pool. Defaults to 1.
dumpNamestringOptional dump directory name under profile.dumpHostPath to preserve before rebuild.
poolNamestringExplicit storage pool name. Defaults to <tenantPath>:<storagePoolKind>.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_remove_dynamic_nodes ~205

Remove extra dynamic tenant nodes one at a time and verify nodelist disappearance when the node IC port can be resolved.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to execute planned commands. Omit or false for plan-only output.
containersarrayExplicit extra dynamic-node container names to remove.
countintegerNumber of extra dynamic nodes to remove. Defaults to 1.
nodeIdsarrayExplicit YDB dynamic-node IDs to remove. IDs must resolve to extra dynamic-node containers; the profile's base dynamic node is not removable through this option.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.
startIndexintegerMinimum suffix to consider removable. Defaults to 2.

No output schema declared.

No examples provided.

local_ydb_restart_stack ~134

Restart the selected profile by stopping dynamic and static containers, starting the static node, ensuring the configured tenant, then starting the dynamic node. Use after config or runtime changes; without confirm=true this returns the restart plan only.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to execute planned commands. Omit or false for plan-only output.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_restore_tenant ~246

Restore the configured tenant or destination path from a dump under profile.dumpHostPath, with optional post-restore scheme describe and bounded count-query verification. Use after bootstrap or rebuild when the target tenant is ready; without confirm=true this returns the restore plan and does not write data.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to restore the tenant from the selected dump. Omit or false for plan-only output.
countQueriesarrayOptional bounded whole-table SELECT COUNT(*) or COUNT(1) queries to verify restored data after the restore command.
describePathsarrayOptional tenant-relative paths to verify with scheme describe after the restore command.
dumpNamestringyesDump directory name under profile.dumpHostPath.
pathstringDestination directory path for YDB tools restore -p, relative to the configured tenant. Defaults to . for tenant root.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_scheme ~250

Read-only YDB scheme list or describe with capped stdout/stderr. It uses the root database for rootDatabase paths and the tenant database otherwise; list supports recursive/long/onePerLine flags, describe supports stats, and incompatible flag combinations are rejected.

NameTypeReqDescription
actionstringScheme operation to run. Defaults to list.
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
longbooleanFor action=list, pass -l for detailed object attributes.
maxOutputBytesintegerMaximum UTF-8 bytes returned per stdout/stderr stream. Defaults to 65536.
onePerLinebooleanFor action=list, pass -1 to print one object per line.
pathstringScheme path to inspect. Defaults to the configured tenant root.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.
recursivebooleanFor action=list, pass -R to recursively list subdirectories.
statsbooleanFor action=describe, pass --stats.

No output schema declared.

No examples provided.

local_ydb_set_root_password ~201

Rotate the runtime root password with ALTER USER and sync the host auth config and root password file to match. YDB may reject passwords that violate auth_config.password_complexity; this tool requires a non-empty password value.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to rotate and persist the root password. Omit or false for plan-only output.
passwordstringyesNew non-empty root password without carriage returns or newlines to apply to the runtime root user and then persist into the host auth config and root password file. YDB defaults to no password compl…
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_sql ~456

Run managed YQL v1 against the configured local-ydb target through Query Service. query uses SnapshotRO, explain returns plan/AST, and execute always runs EXPLAIN first and sends one NoTx execution only with confirm=true.

NameTypeReqDescription
actionstringManaged YQL action. query uses SnapshotRO, explain returns plan/AST without execution, and execute always EXPLAIN-preflights before optional confirmed NoTx execution.
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanConsidered only for action=execute. Must be true to send one NoTx execution after successful EXPLAIN; query remains SnapshotRO even when true.
databasePathstringConfigured tenant or root database path. Defaults to the selected profile tenant path; root paths use the static gRPC port.
maxOutputBytesintegerShared retained-output budget for issues, plan/AST, columns, and rows.
maxRowsintegerMaximum retained rows per result set. The first limit hit stops all further result capture: read-only execution is cancelled, while confirmed NoTx execution drains without capturing later output.
parametersobjectTyped YQL parameters keyed by bare name. The request is limited to 100 parameters, 1,000 descriptor nodes, 10,000 value nodes, and 1 MiB of serialized parameter data. Struct field names must be well-…
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.
scriptstringyesWell-formed-Unicode YQL v1 script; lone UTF-16 surrogates are rejected. Parameter DECLARE statements are generated from parameters and prepended before execution.
timeoutMsintegerSingle deadline in milliseconds shared by connection, session, preflight, execution, and cancellation.

No output schema declared.

No examples provided.

local_ydb_start_dynamic_node ~142

Start the configured primary dynamic tenant node for an existing CMS tenant. Use after local_ydb_create_tenant or when admin status is PENDING_RESOURCES; use local_ydb_add_dynamic_nodes for extra nodes. Without confirm=true this returns a plan only.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to execute planned commands. Omit or false for plan-only output.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_status_report ~135

Read-only aggregate report for quick diagnosis. Runs local_ydb_inventory, local_ydb_auth_check, local_ydb_tenant_check, local_ydb_nodes_check, and local_ydb_healthcheck, returning each result; use this first for broad stack health, then run focused checks for database status, GraphShard, storage, or logs.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_storage_leftovers ~118

Read-only search for candidate leftover local-ydb Docker volumes, dumps, and PDisk/data paths. It scans Docker volume names plus profile.storageSearchPaths and deletes nothing; use before local_ydb_cleanup_storage to decide exact paths or volumes to remove.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_storage_placement ~98

Read-only storage inspection that returns ReadStoragePool output and BSC physical placement. Use before adding or reducing storage groups to confirm the exact pool shape.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_tenant_check ~102

Read-only check that uses the YDB CLI to verify the configured tenant path is reachable. Use after bootstrap or restore to confirm tenant metadata before node or GraphShard checks.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.

No output schema declared.

No examples provided.

local_ydb_upgrade_version ~213

Upgrade a file-backed, volume-backed local-ydb profile to a target image tag. Use only for version upgrades on profiles without bindMountPath; it preflights source and target images, dumps, rebuilds, restores, reapplies auth when configured, recreates extra nodes, verifies container images, and persists the profile image after successful confirmed execution.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to execute the version upgrade plan. Omit or false for plan-only output.
dumpNamestringOptional dump directory name under profile.dumpHostPath for the upgrade backup.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.
versionstringyesTarget image tag such as 26.1.1.6, 26.1, latest, or nightly.

No output schema declared.

No examples provided.

local_ydb_write_dynamic_auth_config ~184

Write the text-proto dynamic-node auth token file needed for mandatory-auth startup. Use after choosing the SID for auth hardening; without confirm=true this returns the planned file write only.

NameTypeReqDescription
configPathstringExplicit local-ydb config file path to load for this tool call. Useful when the MCP server should pick up a different config without restart.
confirmbooleanMust be true to write the dynamic-node auth token file. Omit or false for plan-only output.
profilestringNamed profile from local-ydb.config.json. Defaults to config.defaultProfile.
sidstringSID to store in both StaffApiUserToken and NodeRegistrationToken.
tokenHostPathstringHost path for the generated text-proto auth token file. Defaults to profile.dynamicNodeAuthTokenFile when present.

No output schema declared.

No examples provided.