TL;DR: `ECONNREFUSED` means nothing is listening where the MCP server is looking. Start MySQL, then make sure `MYSQL_HOST` and `MYSQL_PORT` in the client config match where it actually listens. The defaults (`YOUR_HOST:3306`) are wrong for Docker and remote setups.

```text
Error: connect ECONNREFUSED the loopback address:3306
```

## Fix it

1. Check MySQL is running:

```bash
# Linux
sudo systemctl status mysql
# macOS (Homebrew)
brew services list
# Docker
docker ps | grep mysql
```

2. Check what it listens on:

```bash
sudo netstat -tlnp | grep 3306
```

   Expected: a line showing mysqld on 3306 (or your configured port).

3. Set the real address in the client config `env` block. Docker on the host: `host.YOUR_HOST`. Docker Compose service: the service name. Remote: the hostname or IP.

```json
{
  "env": {
    "MYSQL_HOST": "host.YOUR_HOST",
    "MYSQL_PORT": "3306"
  }
}
```

4. Restart the MCP client.

   Expected: the refused error is gone. Next failure, if any, will be auth, which is progress.

## When to use this

- The error is `ECONNREFUSED` mentioning the MySQL host and port.
- `mysql -h [host]` from a terminal also fails to connect.

## When NOT to use this

- The error is `ER_ACCESS_DENIED_ERROR`. The server is reachable; credentials are wrong.
- The error is a timeout (ETIMEDOUT). That is firewall or routing, not a refused connection.

## Compatibility

- benborla/mcp-server-mysql.
- MySQL 5.7, 8.x, MariaDB, in Docker or on the host.

## Why it happens

Connection refused is the OS telling you the SYN packet arrived but no process accepted it. Either MySQL is down, or it is up but bound to a different interface or port than the config says. MCP defaults assume a local MySQL on 3306, which breaks the moment MySQL lives in Docker or on another machine.

## Edge cases

- MySQL in Docker without a published port is unreachable from the host. Add `-p 3306:3306`.
- `bind-address = the loopback address` in my.cnf blocks remote connections even when the port is open. Set it to `the all-interfaces address` for remote access (with proper grants).
- Skip-networking enabled means TCP is off entirely. The MCP server needs TCP; use a socket only if the server supports it.