MCP Commerce Server
Enables natural-language querying of e-commerce data (products, users, orders) from a PostgreSQL database, using a Hugging Face model for safe intent extraction and parameterized SQL execution.
README
MCP Commerce Server (PostgreSQL + Hugging Face)
This project provides a deployment-ready MCP server that can be invoked from a LangGraph orchestration flow.
It accepts natural-language input, uses an open-source Hugging Face model to derive query intent, and safely fetches data from PostgreSQL.
What is implemented
- MCP tools:
query_commerce(query, user_context?, limit?)get_product_price(product_name, limit?)get_user_orders(user_id?, email?, limit?)
- PostgreSQL schema for:
- Product prices (
products) - Users (
users) - Orders (
orders,order_items)
- Product prices (
- Hugging Face model integration (open-source text-to-text model default:
google/flan-t5-base) - SQL-injection-safe query layer (no model SQL execution; only parameterized, pre-approved SQL templates)
- Docker + docker-compose setup for deployment
Why this is SQL-injection safe
- LLM output is treated as intent only, not executable SQL.
- The server maps intent to a fixed set of SQL templates.
- All runtime values are passed as query parameters via psycopg (
%splaceholders). limitis bounded server-side to prevent abuse.
Project structure
.
├── db/init.sql
├── docker-compose.yml
├── Dockerfile
├── examples/langgraph_client.py
├── pyproject.toml
├── requirements.txt
└── src/mcp_commerce_server
├── config.py
├── db.py
├── hf_intent.py
├── main.py
├── query_service.py
└── server.py
1. Local development setup
- Create and activate a virtual environment:
python -m venv .venv source .venv/bin/activate - Install dependencies:
pip install -r requirements.txt - Create env file:
cp .env.example .env - Start PostgreSQL and seed schema:
- Option A: Use your own DB and run
db/init.sql. - Option B: Use docker-compose (recommended below).
- Option A: Use your own DB and run
2. Run with docker-compose (deployment-ready local)
- Ensure
.envexists and hasHF_API_KEY. - Start services:
docker compose up --build - MCP server is exposed at:
http://localhost:8000/mcp(streamable-http transport)
3. Run MCP server directly (stdio for local MCP clients)
python -m mcp_commerce_server.main
Set MCP_TRANSPORT=stdio in .env for this mode.
4. LangGraph orchestration usage
- See
examples/langgraph_client.pyfor end-to-end invocation. - Configure your LangGraph runtime to connect to:
transport:streamable_httpurl:http://<host>:8000/mcp
5. Environment variables
| Variable | Description | Required |
|---|---|---|
POSTGRES_HOST |
PostgreSQL host | Yes |
POSTGRES_PORT |
PostgreSQL port | Yes |
POSTGRES_DB |
Database name | Yes |
POSTGRES_USER |
Database user | Yes |
POSTGRES_PASSWORD |
Database password | Yes |
HF_API_KEY |
Hugging Face API key | Yes (for model inference) |
HF_MODEL_ID |
Open-source HF model id | No (google/flan-t5-base) |
MCP_TRANSPORT |
stdio or streamable-http |
No (stdio) |
MCP_HOST |
HTTP host for streamable MCP | No (0.0.0.0) |
MCP_PORT |
HTTP port for streamable MCP | No (8000) |
6. Deployment steps (production-oriented)
- Build image:
docker build -t commerce-mcp-server:latest . - Push image to your registry:
docker tag commerce-mcp-server:latest <registry>/<namespace>/commerce-mcp-server:latest docker push <registry>/<namespace>/commerce-mcp-server:latest - Provision managed PostgreSQL (AWS RDS / Azure Database / Cloud SQL).
- Apply
db/init.sqlonce (or convert to migration pipeline). - Deploy container to your platform (Kubernetes, ECS, App Service, Cloud Run, etc.) with:
MCP_TRANSPORT=streamable-http- DB connection variables
HF_API_KEYsecret
- Expose HTTP endpoint and allow only trusted callers (VPC/ingress ACL, auth gateway, or service mesh policy).
- Configure LangGraph to call deployed MCP URL.
7. Hardening recommendations before go-live
- Use DB least-privilege user (read-only if writes are unnecessary).
- Add request auth in front of MCP endpoint (API gateway/JWT/mTLS).
- Add query logging + tracing.
- Add circuit breakers/timeouts for HF and DB.
- Add schema migrations (Alembic/Flyway/liquibase) for controlled releases.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.