API and MCP
Build on it, or let your assistant drive
Everything the portal does goes through the public /v1 API. The same API powers the CLI and an MCP server, so tools like Claude Code and Cursor can manage databases with your permissions and nothing more.
How it works
API and MCP, step by step
- Step 01
Create a key
Create an org-scoped API key in the portal or with zb api-keys create. Restrict it with scopes and an expiry; the secret is shown once.
- Step 02
Call /v1
Send it as a bearer token. Every path lives under your org, and other orgs' resources return 404.
- Step 03
Listen for events
Register webhooks for instance, backup and migration events. Deliveries are signed and the secret rotates.
- Step 04
Or add the MCP server
Run zb-mcp locally over stdio or use the hosted endpoint. It calls the same API with the same key.
What you get
-
OpenAPI 3.1
The document is generated from the API source and drives the typed client, the CLI and the MCP server.
-
Safe retries
Send an Idempotency-Key on POST and a retry within 24 hours returns the original response instead of a duplicate.
-
Signed webhooks
Deliveries carry an HMAC signature and a timestamp. Rotate the secret and inspect recent deliveries through the API.
-
MCP server
Tools to list engines and plans, create, pause, resume and delete instances, get connection details and search the docs.
-
No credentials to assistants
The MCP server never reveals database credentials, and delete needs an explicit confirmation flagged as destructive.
-
llms.txt
A machine-readable summary of engines, sizes, plans and prices at /llms.txt, generated from the same catalogue as this site.
Try it
curl -sS https://api.databasezy.com/v1/orgs/org_01J9.../projects/prj_01J9.../instances \
-H "Authorization: Bearer $ZB_API_KEY" \
-H "Idempotency-Key: $(uuidgen)" \
-H "Content-Type: application/json" \
-d '{"engine":"postgres","size":"s1","name":"orders-db"}'claude mcp add databasezy -e ZB_API_KEY=zb_... -e ZB_ORG_ID=org_... -- npx -y zb-mcpPlan availability
Generated from the same plan catalogue that billing and the API use.
- Included
Free
$0 /moREST API, webhooks and MCP server
- Included
Solo
$25 /moREST API, webhooks and MCP server
- Included
Team
$599 /moREST API, webhooks and MCP server
- Included
Enterprise
CustomREST API, webhooks and MCP server
Rate limits are 600 requests per minute per key. API keys inherit their owner's role, so an assistant can be read-only.
Questions
Can an AI assistant delete my databases?
Only if its API key's role and scopes allow it, and delete_instance requires confirm: true and is marked destructive so the client asks you first. A key with instances:read gives a read-only assistant.
Does the MCP server see my database passwords?
No. get_connection_info returns a connection-string template with placeholders. Credential reveal stays in the portal and CLI.
Are some MCP tools still coming?
The backups, usage and migration tools return a not-available error until those endpoints are published in the OpenAPI document the server is built from. No configuration change is needed when they arrive.
What do errors look like?
application/problem+json with a type, title, status, detail and a request id you can quote to support.
Related features
-
CLI
The zb command line: create, connect, back up, restore, migrate and report on usage from your terminal or CI.
Learn more about CLI -
Teams and roles
Roles that mean something, project-scoped access, budgets, approval requests and SSO on Team and Enterprise.
Learn more about Teams and roles -
Network security
TLS on every connection, per-instance IP allow-lists, optional mTLS and support access only with your grant.
Learn more about Network security
Start today
Create your first database
A free instance, no card. Upgrade when you outgrow it; nothing converts silently.