
PostgreSQL
Connects an agent to a PostgreSQL database: local, Docker, managed Postgres on RDS, Neon and Supabase, or a database that is only reachable through an SSH bastion. **Reaches the database you actually have.** Built-in SSH tunneling with a pinned host key, and eight named failure codes that say which phase broke. One `DATABASE_URL` is the whole setup. **Sees the whole database.** `list_schemas`, plus a schema argument on `list_tables` and `describe_table`, so it is not stuck in `public`. **Tells you what broke.** Failures come back carrying the SQLSTATE or SSH code with a hint, so the agent corrects itself instead of retrying blindly. **Respects the context window.** Results carry a byte budget with an explicit `truncated` flag, so a large table does not flood the model. **Writes are off by default**, and refused by PostgreSQL itself rather than by a client-side SQL filter: every read runs inside a `BEGIN READ ONLY` transaction, so the rule survives views, rules and functions. Turn them on with `PG_ALLOW_WRITE=true`. MIT, four runtime dependencies, Node 20 or newer. Also on npm as `mcp-postgres-server` and in the official MCP Registry as `io.github.antonorlov/mcp-postgres-server`.
First seen 2 Oct 2026. Evidence as of 5 Oct 2026.
Tools
No tool list captured yet.
Change history
No changes since the first observation. The first snapshot is the baseline.
| Source | Listing | First seen | Last seen | Versions |
|---|---|---|---|---|
| Smithery | antonorlov/mcp-postgres-server | 2 Oct 2026 | 5 Oct 2026 | 1 |