npm · @valv/mcp
DATABASE_URL (required) · secret — Database connection string. PostgreSQL, MySQL, SQLite, CockroachDB, or a ClickHouse HTTP URL.
VALV_PROVIDER — Datasource provider: postgresql, mysql, sqlite, or clickhouse. Inferred from DATABASE_URL when omitted.
VALV_DATABASE — Database name. Required for ClickHouse, whose URL does not carry one.
VALV_TABLES — Comma-separated allow-list of tables. When set, only these are exposed to the agent.
VALV_EXCLUDE — Comma-separated deny-list of tables, applied after the allow-list.
VALV_POLICY_FILE — Path to a policy module that takes full control of access. Without it, the server is read-only across all tables.
VALV_CONTEXT — JSON context object the policy reads, e.g. {"tenant":{"id":"acme"}}.
VALV_HTTP_PORT — Serve over Streamable HTTP on this port instead of stdio.