PostgreSQL MCP Server
by antonorlovio.github.antonorlov/mcp-postgres-serverv0.3.1
MCP server for PostgreSQL: local, Docker, RDS, Neon, Supabase, or behind an SSH bastion.
context tax
queued
security
queued
cold start
queued
freshness
Active24d ago
Install PostgreSQL MCP server
Install in Claude Code
claude mcp add postgres -e DATABASE_URL='<database-url>' -e PG_PASSWORD='<pg-password>' -e PG_SSH_PASSPHRASE='<pg-ssh-passphrase>' -e PG_SSH_PASSWORD='<pg-ssh-password>' -- npx -y mcp-postgres-serverInstall in Cursor
{
"mcpServers": {
"postgres": {
"command": "npx",
"args": [
"-y",
"mcp-postgres-server"
],
"env": {
"DATABASE_URL": "<database-url>",
"PG_PASSWORD": "<pg-password>",
"PG_SSH_PASSPHRASE": "<pg-ssh-passphrase>",
"PG_SSH_PASSWORD": "<pg-ssh-password>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"postgres": {
"command": "npx",
"args": [
"-y",
"mcp-postgres-server"
],
"env": {
"DATABASE_URL": "<database-url>",
"PG_PASSWORD": "<pg-password>",
"PG_SSH_PASSPHRASE": "<pg-ssh-passphrase>",
"PG_SSH_PASSWORD": "<pg-ssh-password>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"postgres": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"mcp-postgres-server"
],
"env": {
"DATABASE_URL": "<database-url>",
"PG_PASSWORD": "<pg-password>",
"PG_SSH_PASSPHRASE": "<pg-ssh-passphrase>",
"PG_SSH_PASSWORD": "<pg-ssh-password>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"postgres": {
"command": "npx",
"args": [
"-y",
"mcp-postgres-server"
],
"env": {
"DATABASE_URL": "<database-url>",
"PG_PASSWORD": "<pg-password>",
"PG_SSH_PASSPHRASE": "<pg-ssh-passphrase>",
"PG_SSH_PASSWORD": "<pg-ssh-password>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| DATABASE_URL | — | yes | Full connection string (preferred). Supports sslmode in the URL. |
| PG_HOST | — | — | Database host (fallback when DATABASE_URL is not set). |
| PG_PORT | — | — | Database port. |
| PG_USER | — | — | Database user. |
| PG_PASSWORD | — | yes | Database password. |
| PG_DATABASE | — | — | Database name. |
| PG_ALLOW_WRITE | — | — | When true, execute performs writes and reads are sent directly. Off (default) is read-only: execute refuses writes and each read runs in a READ ONLY transaction. |
| PG_SSLMODE | — | — | TLS mode. require/allow/prefer encrypt without verifying the certificate; verify-ca/verify-full verify it (supply a CA via PG_SSL_CA). Unlike libpq, allow/prefer do not fall back to plaintext, so a server without TLS needs disable. |
| PG_SSL_CA | — | — | Path to a CA certificate file. Setting it by itself implies verify-full. |
| PG_ENABLE_RUNTIME_CONNECT | — | — | Register the connect_db tool (runtime credential switching). |
| PG_MAX_RESULT_BYTES | — | — | Byte budget for a query result sent to the model. Whole rows are kept while they fit; over the budget returnedRows < rowCount and truncated is true. |
| PG_STATEMENT_TIMEOUT | — | — | Statement timeout in milliseconds, applied to every session. |
| PG_CONNECT_TIMEOUT | — | — | Timeout in milliseconds for a single connect attempt (raise it for slow links or SSH tunnels). |
| PG_SSH_HOST | — | — | SSH bastion host. Setting it enables tunneling: the server reaches the database only through an SSH tunnel to this host. Needs the ssh2 optional dependency. |
| PG_SSH_PORT | — | — | SSH bastion port. |
| PG_SSH_USER | — | — | SSH username. |
| PG_SSH_PRIVATE_KEY | — | — | Path to a private key file. If unset, auth falls back like ssh: a running agent (SSH_AUTH_SOCK), then a default key (~/.ssh/id_ed25519, id_rsa, id_ecdsa). |
| PG_SSH_PASSPHRASE | — | yes | Passphrase for the private key, if encrypted. |
| PG_SSH_AGENT | — | — | true to use the ambient agent (SSH_AUTH_SOCK), or an explicit socket path / Windows named pipe. |
| PG_SSH_PASSWORD | — | yes | SSH login password. Opt-in; a key or agent takes precedence. Prefer keys, a bastion often disables password auth. |
| PG_SSH_FINGERPRINT | — | — | Pinned host-key fingerprint (SHA256:...). Host-key verification is mandatory and set only this way: without it the tunnel refuses to connect. Get it with ssh-keygen -lF host. |
| PG_SSH_KEEPALIVE_INTERVAL | — | — | SSH keepalive interval in ms; the tunnel drops after 3 unanswered keepalives, and the next call reconnects. |
Freshness
Active — last maintenance signal 24d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-09-16 · 24d ago · GitHub
Latest release
2026-09-14 · 25d ago · GitHub · v0.3.1
Package published
no data · npm/PyPI
Registry entry updated
2026-09-14 · 25d ago · official registry · v0.3.1
FAQ
›How do I install the PostgreSQL MCP server in Claude Code?
Run: claude mcp add postgres -e DATABASE_URL='<database-url>' -e PG_PASSWORD='<pg-password>' -e PG_SSH_PASSPHRASE='<pg-ssh-passphrase>' -e PG_SSH_PASSWORD='<pg-ssh-password>' -- npx -y mcp-postgres-server. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does PostgreSQL require an API key?
Yes. It expects DATABASE_URL, PG_PASSWORD, PG_SSH_PASSPHRASE, PG_SSH_PASSWORD, of which 4 are secrets.
›Can I use PostgreSQL as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is PostgreSQL in the official MCP registry?
Yes, as io.github.antonorlov/mcp-postgres-server.
Alternatives to PostgreSQL
Other database MCP servers.