-
Notifications
You must be signed in to change notification settings - Fork 2
MySQL Router
Value Proposition Provide AI agents with reliable, real-time visibility into connection pools and route health. Seamlessly monitor InnoDB clusters. Optimize database traffic routing. This ensures high availability and resilient agent operations. Read the full value proposition.
- A recent version of MySQL Router with REST API enabled.
- Router REST API credentials (username/password)
- Network access to Router REST API endpoint (default: HTTPS on port 8443)
- For InnoDB Cluster mode: The cluster must be running for REST API authentication
Important
Router REST API typically authenticates against the InnoDB Cluster. Authentication fails with 401 errors if the cluster is down.
Includes, but is not limited to:
| Tool | Description | Parameters |
|---|---|---|
mysql_router_status |
Get Router process status and version | - |
mysql_router_routes |
List all configured routes | - |
mysql_router_route_status |
Get status of a specific route | routeName |
mysql_router_route_health |
Check health/liveness of a route | routeName |
mysql_router_route_connections |
List active connections on route | routeName |
mysql_router_route_destinations |
List backend MySQL server destinations | routeName |
mysql_router_route_blocked_hosts |
List blocked IP addresses for a route | routeName |
mysql_router_metadata_status |
InnoDB Cluster metadata cache status |
metadataName |
mysql_router_pool_status |
Connection pool statistics | poolName |
mysql_router_pool_status tool does not require an InnoDB Cluster. It only relies on the router's active connection pool configuration.
Bootstrapping Router against an InnoDB Cluster uses metadata_cache authentication. This authenticates API users against the metadata database.
1. Create REST API user in the cluster:
-- Connect to any cluster node
-- The user will be stored in mysql_innodb_cluster_metadata.router_rest_accounts# Use mysqlrouter_passwd to generate the password hash
mysqlrouter_passwd set /tmp/router_admin.pwd router_admin
# Manually read the generated hash from /tmp/router_admin.pwd and replace <hash_from_mysqlrouter_passwd> below
# Insert into cluster metadata (on PRIMARY node)
mysql -h localhost -P 3307 -u cluster_admin -p -e "INSERT INTO mysql_innodb_cluster_metadata.router_rest_accounts(cluster_id, user, authentication_method, authentication_string, description) SELECT cluster_id, 'router_admin', 'modular_crypt_format', '<hash_from_mysqlrouter_passwd>', 'REST API user' FROM mysql_innodb_cluster_metadata.clusters LIMIT 1;"2. Router config uses metadata_cache backend:
[http_auth_backend:default_auth_backend]
backend=metadata_cacheFor standalone Router deployments without InnoDB Cluster:
[http_server]
port=8443
ssl=1
ssl_cert=/path/to/router-cert.pem
ssl_key=/path/to/router-key.pem
[http_auth_realm:default_auth_realm]
backend=default_auth_backend
method=basic
name=default_realm
[http_auth_backend:default_auth_backend]
backend=file
filename=/path/to/mysqlrouter.pwd
[rest_router]
require_realm=default_auth_realm
[rest_routing]
require_realm=default_auth_realm# Generate password hash (prompts for password)
mysqlrouter_passwd set /path/to/mysqlrouter.pwd router_adminSecure MySQL Router operations using OAuth validation. See the OAuth page for setup instructions.
| Variable | Default | Description |
|---|---|---|
MYSQL_ROUTER_URL |
https://localhost:8443 |
Router REST API base URL |
MYSQL_ROUTER_USER |
- | Router API username |
MYSQL_ROUTER_PASSWORD |
- | Router API password |
MYSQL_ROUTER_API_VERSION |
/api/<version> |
API version path |
MYSQL_ROUTER_INSECURE |
false |
Skip TLS verification (for self-signed certs) |
Warning
Never commit Router credentials to version control. Use environment variables or secure secrets management.
{
"mcpServers": {
"mysql-mcp": {
"command": "npx",
"args": [
"-y",
"@neverinfamous/mysql-mcp",
"--transport",
"stdio",
"--mysql",
"mysql://user:password@localhost:3306/database"
],
"env": {
"MYSQL_ROUTER_URL": "https://router.example.com:8443",
"MYSQL_ROUTER_USER": "router_admin",
"MYSQL_ROUTER_PASSWORD": "router_password",
"MYSQL_ROUTER_INSECURE": "true"
}
}
}
}If you only want Router tools (e.g., for a dedicated monitoring agent):
{
"args": [
"--transport",
"stdio",
"--mysql",
"mysql://user:password@localhost:3306/database",
"--tool-filter",
"router"
]
}Cause: Router REST API is unreachable or TLS handshake failed.
Solutions:
- Verify Router is running:
docker ps | grep router - Check Router logs:
docker logs mysql-router - Test API manually:
curl -k -u router_admin:router_password https://localhost:8443/api/<version>/router/status - Ensure
MYSQL_ROUTER_INSECURE=trueis set for self-signed certificates
Cause: Authentication failed. This usually means the InnoDB Cluster is not running.
Solutions:
- Start the InnoDB Cluster:
docker compose -f test-server/infrastructure/innodb-cluster.yml up -d - Reboot cluster from outage if needed:
dba.rebootClusterFromCompleteOutage() - Restart Router to reconnect:
docker restart mysql-router - Verify credentials match the
router_rest_accountstable
Cause: Cluster nodes are running but Group Replication is not active.
Solution: Reboot cluster from complete outage using MySQL Shell:
mysqlsh --uri cluster_admin:password@localhost:3307 --js \
-e "dba.rebootClusterFromCompleteOutage('clusterName', {force: true})"Cause: The connection pool name doesn't exist or connection pooling is disabled.
Solution: This is expected if Router lacks connection pooling configuration. The tool works correctly.
- Tools - Complete tool list
- Tool Filtering - Custom tool filtering
- Configuration - General configuration
Value Proposition Enforce strict execution boundaries and maximize LLM context efficiency for secure, autonomous database interactions. Read the full value proposition
- Installation
- Configuration
- Architecture
- HTTP Transport
- Tool Filtering
- Code Mode
- Tools
- Prompts
- Resources
- Observability & Telemetry