postgres-mcp-server
Allows querying and interacting with PostgreSQL databases, providing read-only queries by default, transaction management, and optional write/DDL support.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@postgres-mcp-serverPing the local Postgres and list its tables."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
postgres-mcp-server
An MCP server for safely querying PostgreSQL from an LLM. Read-only by default, multi-connection with named aliases, Postgres-session-enforced safety.
Quickstart
Create ~/.config/postgres-mcp/config.json:
{
"connections": {
"local": {
"url_env": "LOCAL_DATABASE_URL",
"mode": "read"
}
}
}Add to your MCP client config (Claude Desktop, Cursor, Windsurf, Zed):
{
"mcpServers": {
"postgres": {
"command": "npx",
"args": ["-y", "@arieffian/postgres-mcp-server"],
"env": { "LOCAL_DATABASE_URL": "postgres://user:pw@localhost/db" }
}
}
}Restart the client and ask: "Ping the local Postgres and list its tables."
Related MCP server: mcp-enterprise-starter
Modes
Every connection declares its mode statically in config. Escalation requires editing config and restarting.
Mode | SELECT | INSERT/UPDATE/DELETE | DDL | Notes |
read | ✓ | ✗ | ✗ | Default. |
write | ✓ | ✓ | ✗ | Writes must go through |
admin | ✓ | ✓ | ✓ | Same tx flow as write; DDL also permitted. |
Tools
Meta
ping,list_connections
SQL
query— read-only SELECT via server-side cursorbegin_transaction,commit,rollback— tx lifecycleexecute— INSERT/UPDATE/DELETE/DDL inside an open tx
Schema introspection (Phase 2, new in 0.2.0)
list_databases,list_schemaslist_tables— includes regular, partitioned, and foreign tables (viakindfield); row count is clamped to 0 for never-analyzed tableslist_indexes,list_constraints— per-table catalog listingslist_functions— excludes functions installed by extensionsdescribe_table— composite: columns, PK, FKs, indexes, constraints in one call
Observability — ships in Phase 3.
Safety
Five layers — see docs/safety.md. Highlights:
Read-only enforced by the Postgres session, not by parsing SQL — we do not trust our own parser.
Statement timeout per connection (default 30s).
Every SELECT wrapped in a server-side cursor; results capped by row count and byte size.
Writes require an explicit transaction; no autocommit.
Bound parameter values are never logged. Credentials in URLs are redacted.
Configuration
Discovery order (first hit wins):
--config <path>CLI flag$POSTGRES_MCP_CONFIGenv var$XDG_CONFIG_HOME/postgres-mcp/config.json(fallback~/.config/postgres-mcp/config.json)./postgres-mcp.config.json
Contributing
Requires Node ≥ 20. Local dev: npm install, npm test. Integration tests use testcontainers and need a working Docker daemon.
Publishing
Set NPM_TOKEN in the repo's GitHub Actions secrets. Changesets automatically opens a release PR on push to main; merging it publishes to npm with provenance.
License
MIT
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Flicense-qualityCmaintenanceAn MCP server that gives an AI agent scoped, safe access to your Postgres databases with per-connection access control, row caps, timeouts, and defense-in-depth read-only enforcement.
- AlicenseAqualityDmaintenanceA production-grade MCP server that gives AI agents safe, authenticated access to a PostgreSQL database.3MIT
- Alicense-qualityDmaintenanceA read-only MCP server for PostgreSQL that enables safe database introspection and querying via natural language.727MIT
- Alicense-qualityAmaintenanceA hardened, read-only Postgres MCP server that enables LLMs to safely query databases without write, DDL, shell, or credential exposure.MIT
Related MCP Connectors
Query PostgreSQL databases in plain English — LLM-generated, safety-validated SQL.
MCP server for managing Prisma Postgres.
Analytical memory for AI agents: a real Postgres queried in plain English over MCP. One command.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/arieffian/postgres-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server