Skip to main content
Glama
87,293 servers. Updated
20 Best PostgreSQL MCP Servers: compared and ranked, September 2026Ranked from 1,150 matching servers on stars, growth, downloads and maintenance. Updated .

Matching MCP tools:

Matching MCP Connectors:

"postgres" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • F
    license
    A
    quality
    B
    maintenance
    An MCP server that enables AI agents to securely interact with PostgreSQL databases with least-privilege scopes, PII masking, and human approval for writes.
    4
    -
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI agents to safely query PostgreSQL by intercepting and auditing every generated SQL statement before it reaches the database, blocking destructive commands like DROP/TRUNCATE, unbounded DELETE/UPDATE statements, stacked queries, and SQL injection probes. It exposes tools for validating query safety and enforcing a strict read-only (SELECT/EXPLAIN) policy.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    A read-only MCP server for PostgreSQL that serves multiple databases from one process, enforcing read-only access via PostgreSQL grants rather than SQL string matching, and supports both local stdio and remote HTTP transports.
    Apache 2.0
  • A
    license
    A
    quality
    A
    maintenance
    A drop-in Model Context Protocol (MCP) server that lets an AI agent query PostgreSQL — read-only, enforced at the database level, with real SQL validation, timeouts, cost limits, OAuth 2.1, and an audit trail.
    10
    2
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    A PostgreSQL MCP server that automatically detects and obfuscates personally identifiable information (PII) in query results using column-name heuristics and NLP analysis. It enables AI agents to interact securely with databases by masking sensitive data by default while allowing selective unmasking under user control.
    4
    -
  • A
    license
    Not graded
    quality
    C
    maintenance
    MCP server that provides secure PostgreSQL access with LIME agent identity verification, whitelist-based authorization, and audit events.
    Academic Free v1.1
  • F
    license
    Not graded
    quality
    D
    maintenance
    Hardened C# Model Context Protocol (MCP) server for MS SQL Server and PostgreSQL databases featuring read-only transaction safeguards, command security filters, and path traversal protection.
    -
  • A
    license
    A
    quality
    B
    maintenance
    SchemaBrain is an MCP server that sits between AI agents (Claude, Cursor, Windsurf) and your SQL database as a read-only trust + intelligence layer. The agent never writes SQL — 12 tools compile it from definitions you control, PII and secret categories are refused before the query runs, and every call lands in a tamper-evident (SHA-256-chained) audit log. Postgres today.
    12
    9
    Apache 2.0
  • A
    license
    A
    quality
    B
    maintenance
    Read-only Postgres access with a policy gate that blocks writes and restricts visible tables and columns.
    6
    5 npm
    MIT
  • F
    license
    A
    quality
    B
    maintenance
    A security-hardened Postgres MCP server that enables LLM agents to run safe, read-only SQL queries with enforcement via SQL-AST inspection and read-only transactions.
    1
    -
  • F
    license
    A
    quality
    B
    maintenance
    Enables MCP clients to safely inspect and query an explicitly allowlisted subset of a Postgres database through four read-only tools: a readiness check, table listing, column description, and typed row selection with filters, ordering, and paging. It runs over stdio for local clients or Streamable HTTP for separately managed ones, with bound parameters, bounded reads, and read-only transactions.
    4
    -
  • A
    license
    A
    quality
    B
    maintenance
    Enables governed access to corporate Postgres databases via MCP, supporting read-only queries, confirmed data and schema changes, query explanation, audit trail retrieval, and role-based policies with optional Vault secret integration.
    10
    MIT
  • A
    license
    B
    quality
    C
    maintenance
    MCP server exposing Forcepoint Data Security Cloud configuration APIs for managing users, groups, credentials, and access tokens via Vault and Postgres.
    25
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    SQL guardrails for AI agents, sitting between the agent and Postgres to enforce policies, block destructive queries, and audit all access.
    4
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI agents to query Postgres databases read-only over the Model Context Protocol through three narrow tools, validating every statement as a single SELECT with an enforced row limit before it reaches the database. Guards against destructive statements, banned functions, system catalogs, and runaway queries via AST parsing plus a SELECT-only Postgres role.
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Access control, conflict resolution, and audit for shared agent memory. Policy-gated memory tools over Postgres + pgvector, exposed via MCP.
    Apache 2.0