Skip to content

Audit Trail

Chris edited this page Jul 31, 2026 · 115 revisions

Secure Your Audit Trail

Tools Resources Prompts
OAuth Code Mode

Value Proposition Automate compliance workflows and enforce strict data governance with end-to-end visibility audit tracking. Capture pre-mutation snapshots to ensure end-to-end visibility into agent actions, seamlessly bridging AI autonomy with rigorous organizational security requirements. Read the full value proposition.

⚙️ Automate Compliance & Governance

Deliver strict data governance and streamline compliance workflows with our robust, automated audit tracking. Ensure complete operational visibility across all AI database interactions by capturing granular pre-mutation snapshots—empowering autonomous agents without sacrificing security.

Configure by passing the following flags during server initialization:

  • --audit-log <path>: Enables the audit log and specifies the file path (e.g., --audit-log logs/mcp-audit.jsonl).
  • --audit-backup: Enables pre-mutation snapshots for DML changes.
  • --audit-reads: Includes read-scope tool calls (like SELECTs) in the audit log.
  • --audit-redact: Automatically redacts sensitive parameters from the JSONL output.
  • --audit-log-max-size: Maximum size for the audit log file. Reaching this maximum triggers automatic log rotation (default: 10MB, Env: AUDIT_LOG_MAX_SIZE).
  • --audit-backup-data: Includes the original row data in pre-mutation snapshots.
  • --audit-backup-max-size: Maximum table size in bytes for data capture (default: 50MB, Env: AUDIT_BACKUP_MAX_SIZE).

See the Configuration guide for all audit options, including size limits and the redaction toggle.

Exporter Container Integration

When running the Prometheus metrics exporter in Docker, the container reads the IDE's audit log via a separate environment variable:

Variable Value Purpose
AUDIT_LOG_PATH /var/log/mysql-mcp/mcp-audit.jsonl Read-only path to the IDE's live audit JSONL, mounted from ../../logs

This separates the read path (metrics aggregation) from the write path (--audit-log for the exporter's own AuditLogger), preventing log rotation race conditions.

Note

V8 isolate internal data mutations (Code Mode) are not captured by the audit log; only database queries executed from the isolate are logged.

MySQL MCP Documentation

Unlock autonomous database orchestration with an enterprise-grade MySQL MCP server. Featuring blazing-fast sandboxed Code Mode, uncompromising schema enforcement, and seamless ecosystem integrations to power secure, intelligent AI workflows.

🏠 Home


Launch Your Setup


Connect Ecosystem Tools


Enforce Security & Compliance


Scale Your Operations


Explore External Links

Clone this wiki locally