Skip to content
mcp/skillhub

Cost Guard MCP Server

by mcpsmithsio.github.mcpsmiths/cost-guard-mcpv0.3.2

Pre-flight query cost and result-size guardrails for AI agents on BigQuery, Snowflake, Databricks

1Pythonstdioofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Active11d ago

Install Cost Guard MCP server

Install in Claude Code

claude mcp add cost-guard -e GOOGLE_APPLICATION_CREDENTIALS='<google-application-credentials>' -e SNOWFLAKE_PRIVATE_KEY_PATH='<snowflake-private-key-path>' -e SNOWFLAKE_PRIVATE_KEY_PASSPHRASE='<snowflake-private-key-passphrase>' -e SNOWFLAKE_PASSWORD='<snowflake-password>' -e DATABRICKS_TOKEN='<databricks-token>' -e DATABRICKS_CLIENT_SECRET='<databricks-client-secret>' -- uvx cost-guard-mcp

Configuration

VariableRequiredSecretDescription
GOOGLE_APPLICATION_CREDENTIALS—yesBigQuery: path to a service-account key file (Application Default Credentials). Required to use the bigquery engine.
SNOWFLAKE_ACCOUNT——Snowflake: account identifier. Required to use the snowflake engine.
SNOWFLAKE_USER——Snowflake: username. Required to use the snowflake engine.
SNOWFLAKE_ROLE——Snowflake: role to assume. Required to use the snowflake engine; has no default and must never be ACCOUNTADMIN.
SNOWFLAKE_PRIVATE_KEY_PATH—yesSnowflake: path to an RSA private key file for key-pair auth (preferred over SNOWFLAKE_PASSWORD). Either this or SNOWFLAKE_PASSWORD is required to use the snowflake engine.
SNOWFLAKE_PRIVATE_KEY_PASSPHRASE—yesSnowflake: passphrase for an encrypted SNOWFLAKE_PRIVATE_KEY_PATH key file, if the key is encrypted.
SNOWFLAKE_PASSWORD—yesSnowflake: password (discouraged; prefer SNOWFLAKE_PRIVATE_KEY_PATH). Either this or SNOWFLAKE_PRIVATE_KEY_PATH is required to use the snowflake engine.
DATABRICKS_SERVER_HOSTNAME——Databricks: SQL warehouse server hostname (e.g. my-workspace.cloud.databricks.com, no scheme, no trailing slash). Required to use the databricks engine.
DATABRICKS_HTTP_PATH——Databricks: SQL warehouse HTTP path (from the warehouse's Connection Details tab, e.g. /sql/1.0/warehouses/<warehouse-id>). Required to use the databricks engine.
DATABRICKS_TOKEN—yesDatabricks: personal access token (simplest auth option). Either this or DATABRICKS_CLIENT_ID + DATABRICKS_CLIENT_SECRET is required to use the databricks engine.
DATABRICKS_CLIENT_ID——Databricks: OAuth machine-to-machine service-principal client ID (preferred for automated use). Requires DATABRICKS_CLIENT_SECRET as well.
DATABRICKS_CLIENT_SECRET—yesDatabricks: OAuth machine-to-machine service-principal client secret. Requires DATABRICKS_CLIENT_ID as well.

Freshness

Active — last maintenance signal 11d ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-09-23 · 16d ago · GitHub

  2. Latest release

    2026-09-22 · 17d ago · GitHub · v0.3.2

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-09-28 · 11d ago · official registry · v0.3.2

FAQ

›How do I install the Cost Guard MCP server in Claude Code?

Run: claude mcp add cost-guard -e GOOGLE_APPLICATION_CREDENTIALS='<google-application-credentials>' -e SNOWFLAKE_PRIVATE_KEY_PATH='<snowflake-private-key-path>' -e SNOWFLAKE_PRIVATE_KEY_PASSPHRASE='<snowflake-private-key-passphrase>' -e SNOWFLAKE_PASSWORD='<snowflake-password>' -e DATABRICKS_TOKEN='<databricks-token>' -e DATABRICKS_CLIENT_SECRET='<databricks-client-secret>' -- uvx cost-guard-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does Cost Guard require an API key?

Yes. It expects GOOGLE_APPLICATION_CREDENTIALS, SNOWFLAKE_PRIVATE_KEY_PATH, SNOWFLAKE_PRIVATE_KEY_PASSPHRASE, SNOWFLAKE_PASSWORD, DATABRICKS_TOKEN, DATABRICKS_CLIENT_SECRET, of which 6 are secrets.

›Can I use Cost Guard as a remote (hosted) MCP server?

No hosted endpoint is published; it runs locally over stdio.

›Is Cost Guard in the official MCP registry?

Yes, as io.github.mcpsmiths/cost-guard-mcp.

Alternatives to Cost Guard

Other database MCP servers.

View all