Naxas MCP Server
Provides a PostgreSQL MCP gateway for querying and controlled writing to configured PostgreSQL databases. Tools include db_read for SELECT/WITH/EXPLAIN queries, db_schema for schema metadata inspection, db_write_preview for non-executing write previews, and db_write for single INSERT/UPDATE/DELETE operations. Supports multiple PostgreSQL projects via server-side allowlist, enforces read-by-default access, separates read and write database roles, blocks DDL and other disallowed statements, and emits structured audit events.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Naxas MCP Servershow me the schema for the naxas project"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Naxas MCP Server
Open-source, self-hostable PostgreSQL MCP gateway for ChatGPT-compatible and other MCP clients.
It is designed around one rule: read by default; write only through a separately privileged database role and an approval-capable MCP client.
Why this exists
A single deployment can safely expose multiple PostgreSQL projects without accepting arbitrary database URLs from tool calls. Projects are configured only on the server through PROJECTS_JSON.
Example:
{
"naxas": {
"readUrl": "postgresql://reader:***@postgres:5432/naxas",
"writeUrl": "postgresql://writer:***@postgres:5432/naxas"
},
"another_app": {
"readUrl": "postgresql://reader:***@postgres:5432/another_app"
}
}Omit writeUrl to make a project permanently read-only.
Related MCP server: pgmcp
Tools
Tool | Purpose | Recommended client policy |
| SELECT / WITH / EXPLAIN | Read without write permission |
| Inspect schema metadata | Read without write permission |
| Non-executing EXPLAIN for a proposed write | Read/preview |
| One INSERT / UPDATE / DELETE | Ask for explicit confirmation |
The server blocks DDL, role/privilege changes, COPY, transaction-control statements, and multiple write statements.
Recommended write flow: inspect with db_read → preview with db_write_preview → ask the user for approval → execute with db_write → verify with db_read.
Security model
Security is layered:
MCP client permission/confirmation.
Server-side project allowlist.
SQL policy enforcement.
Separate PostgreSQL read/write roles.
PostgreSQL privileges remain the final authority.
Query and lock timeouts.
Structured audit events.
Do not grant the writer role superuser, owner, schema-management, or role-management capabilities.
Quick start
cp .env.example .env
# Edit .env with strong credentials and PROJECTS_JSON
docker compose up --buildHealth check:
GET http://127.0.0.1:3000/healthRemote MCP endpoint:
POST https://your-domain.example/mcpSee Coolify deployment and ChatGPT connection.
Development checks
npm install
npm run checkThis runs strict TypeScript checking, SQL-policy tests, and a production build.
PostgreSQL roles
sql/postgres-roles.sql contains a conservative starting point. Customize database name, credentials, and table-level writer grants before running it.
For public deployments, create your own roles rather than reusing the application owner/admin account.
Open source
Licensed under the MIT License. You can fork, self-host, modify, and redistribute this project subject to the license terms.
Current maturity
Pre-1.0. Review the code and security model before using it with production databases. Production operators remain responsible for PostgreSQL privileges, secrets, network isolation, and MCP client permissions.
This server cannot be deployed
Maintenance
Related MCP Connectors
Governed MCP gateway: one endpoint for your tools, with credential custody and audit log.
Guard AI agents' PostgreSQL/MySQL access via MCP: SQL audit, auth, masking, write approval
13Safe, read-only Postgres and MySQL access for AI agents. Audit log + column-level controls.
Paid remote MCP for governed database query review, SQL simulation, approvals, and audits.
Related MCP Servers
- FlicenseNot gradedqualityCmaintenanceEnables querying and modifying PostgreSQL databases through MCP tools with read/write operations, schema inspection, and write-safety constraints that limit modifications to the mcp schema.1-
- AlicenseNot gradedqualityCmaintenanceEnables safe, read-only querying of PostgreSQL databases with defense-in-depth protections including single-statement SELECT guard, row caps, and per-identity audit logging.1MIT
- AlicenseNot gradedqualityBmaintenanceProvides read-only access to PostgreSQL databases via MCP, enforcing least-privilege roles, row-level security, masked views, and SQL AST guardrails to prevent data leakage and unauthorized operations, enabling AI agents to safely query sensitive production data.MIT
- AlicenseNot gradedqualityBmaintenanceEnables MCP clients to safely query one or more PostgreSQL databases with read-only tools and explicitly approved write operations.154 npm1MIT