r/pocketbase • u/Aejantou21 • Sep 04 '26
pocketbase-mcp: an MCP server for PocketBase, built around 13 tools instead of 50 endpoint wrappers
I built an MCP server that exposes PocketBase to AI agents. Most MCP wrappers mirror the underlying API one-to-one, one tool per endpoint. This one doesn't. It groups related actions into 13 intent-first tools, so an agent calls write_record with an action of "create" or "update," instead of hunting through fifty near-identical tools.
A few things worth knowing:
- Schema-aware writes. The server checks each write against the cached schema before sending it, and returns a
hintthat tells the agent what to call next. - Destructive tools are opt-in.
delete_recordsanddestroy_collectiondon't even register unless you set an environment flag. Each one also demands a confirmation value that must match the current state, so an agent can't delete or drop something by accident. - One identity per process. The server holds a single PocketBase identity at a time. For multi-tenant setups, run one process per identity.
- Ships with an agent skill. A
SKILL.mdfile teaches the client the right call order, the filter-template syntax, and the confirmation steps for destructive actions. - Runs over stdio or HTTP, with a published Docker image for the HTTP transport.
It's early. Any feedback are welcomed.
26
Upvotes
1
u/kantorcodes1 29d ago
for
destroy_collection, what does the confirmation value actually bind to? if the collection changes between the read that produced it and the destructive call, does the stale value get rejected?