Skip to content

PostgreSQL

Local package path declaredNo credentials listedRepository declared by sourceUpdated 2026-09-14

io.github.antonorlov/mcp-postgres-server · Registry status: active

Report data on this entry

At a glance

MCP server for PostgreSQL: local, Docker, RDS, Neon, Supabase, or behind an SSH bastion.

Vendor's own description, untranslated and unverified

Execution location
Local package path declared
Required secrets declared
No credentials listed
Declared version and change
0.3.1 · Source-reported change date 2026-09-14
Repository as declared
github.com/antonorlov/mcp-postgres-server
Configuration
can be built from the disclosed start template

Inspect connection paths and prerequisites

Related categories

6 of 15 categories. All categories in the segment catalogue

Page last changed:

Sources and collection
Runs
Local package path declared
Credentials
No credentials listed
Registry record changed
2026-09-14
Setup
Template available
Registry name
io.github.antonorlov/mcp-postgres-server
Package coordinate
npm:mcp-postgres-server
Declared version
0.3.1
Source-reported listing date
2026-09-14
Source-reported change date
2026-09-14
First seen by tracevero
2026-09-15
Vendor's website
https://github.com/antonorlov/mcp-postgres-server#readme

Evidence for this page · Source: MCP-Register · collected on 2026-09-15

Every value below comes from it. Where one differs, its origin is stated on its row. What the confidence levels mean

Measured values

Measured values
Required secrets declaredNo credentials listed no
Original data – Required secret variables (raw): confirmed absent
Original data – Required secret headers (raw): confirmed absent
Source: MCP-Register · collected on 2026-09-15 · derived
Execution locationLocal package path declared local
Original data – Transports (raw): stdio
Source: MCP-Register · collected on 2026-09-15 · derived
Path argument presentyes
Original data – Path arguments (raw): confirmed absent
Original data – Path environment variables (raw): PG_SSH_PRIVATE_KEY, PG_SSL_CA
Source: MCP-Register · collected on 2026-09-15 · derived
Repository URL listedRepository declared by source yes
Original data – Repository (raw): https://github.com/antonorlov/mcp-postgres-server
Source: MCP-Register · collected on 2026-09-15 · derived
Field of use, derived from the vendor descriptionDatabases
Original data – Description (raw): MCP server for PostgreSQL: local, Docker, RDS, Neon, Supabase, or behind an SSH bastion.
Source: MCP-Register · collected on 2026-09-15 · derived
Field of use, derived from the vendor descriptionInfrastructure
Original data – Description (raw): MCP server for PostgreSQL: local, Docker, RDS, Neon, Supabase, or behind an SSH bastion.
Source: MCP-Register · collected on 2026-09-15 · derived
Declared version0.3.1
Source: MCP-Register · collected on 2026-09-15 · self-declared

What is measured is what a manifest declares, not what a piece of software does. This registry fetches no repository URL, no endpoint and no package index; nothing here is verified. Which value comes from which source, and by which rule it was formed, is set out in the Methodology.

Source data25

All 25 values in this block: self-declared.

Raw values
Description (raw)MCP server for PostgreSQL: local, Docker, RDS, Neon, Supabase, or behind an SSH bastion.
Environment variables (raw)DATABASE_URL, PG_HOST, PG_PORT, PG_USER, PG_PASSWORD, PG_DATABASE, PG_ALLOW_WRITE, PG_SSLMODE, PG_SSL_CA, PG_ENABLE_RUNTIME_CONNECT, PG_MAX_RESULT_BYTES, PG_STATEMENT_TIMEOUT, PG_CONNECT_TIMEOUT, PG_SSH_HOST, PG_SSH_PORT, PG_SSH_USER, PG_SSH_PRIVATE_KEY, PG_SSH_PASSPHRASE, PG_SSH_AGENT, PG_SSH_PASSWORD, PG_SSH_FINGERPRINT, PG_SSH_KEEPALIVE_INTERVAL
Required secret variables (raw)confirmed absent
Transports (raw)stdio
Path arguments (raw)confirmed absent
Repository (raw)https://github.com/antonorlov/mcp-postgres-server
Package registries (raw)npm
Required secret headers (raw)confirmed absent
Path environment variables (raw)PG_SSH_PRIVATE_KEY, PG_SSL_CA
Remote URLs (raw)confirmed absent
Remote hosts (raw)confirmed absent
Registry status message (raw)confirmed absent
First listed in the registry (raw)2026-09-14
Last changed in the registry (raw)2026-09-14
Schema version of the raw record (raw)https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json
Delivery form (raw)package
Repository platform (raw)github
Repository subfolder (raw)confirmed absent
Package identifiers (raw)mcp-postgres-server
Package versions (raw)0.3.1
Runtime hints (raw)npx
Environment variable formats (raw)boolean, filepath, number, string
Environment variable descriptions (raw)DATABASE_URL=Full connection string (preferred). Supports sslmode in the URL. · PG_ALLOW_WRITE=When true, execute performs writes and reads are sent directly. Off (default) is read-only: execute refuses writes and each read runs in a READ ONLY transaction. · PG_CONNECT_TIMEOUT=Timeout in milliseconds for a single connect attempt (raise it for slow links or SSH tunnels). · PG_DATABASE=Database name. · PG_ENABLE_RUNTIME_CONNECT=Register the connect_db tool (runtime credential switching). · PG_HOST=Database host (fallback when DATABASE_URL is not set). · PG_MAX_RESULT_BYTES=Byte budget for a query result sent to the model. Whole rows are kept while they fit; over the budget returnedRows < rowCount and truncated is true. · PG_PASSWORD=Database password. · PG_PORT=Database port. · PG_SSH_AGENT=true to use the ambient agent (SSH_AUTH_SOCK), or an explicit socket path / Windows named pipe. · PG_SSH_FINGERPRINT=Pinned host-key fingerprint (SHA256:...). Host-key verification is mandatory and set only this way: without it the tunnel refuses to connect. Get it with ssh-keygen -lF host. · PG_SSH_HOST=SSH bastion host. Setting it enables tunneling: the server reaches the database only through an SSH tunnel to this host. Needs the ssh2 optional dependency. · PG_SSH_KEEPALIVE_INTERVAL=SSH keepalive interval in ms; the tunnel drops after 3 unanswered keepalives, and the next call reconnects. · PG_SSH_PASSPHRASE=Passphrase for the private key, if encrypted. · PG_SSH_PASSWORD=SSH login password. Opt-in; a key or agent takes precedence. Prefer keys, a bastion often disables password auth. · PG_SSH_PORT=SSH bastion port. · PG_SSH_PRIVATE_KEY=Path to a private key file. If unset, auth falls back like ssh: a running agent (SSH_AUTH_SOCK), then a default key (~/.ssh/id_ed25519, id_rsa, id_ecdsa). · PG_SSH_USER=SSH username. · PG_SSLMODE=TLS mode. require/allow/prefer encrypt without verifying the certificate; verify-ca/verify-full verify it (supply a CA via PG_SSL_CA). Unlike libpq, allow/prefer do not fall back to plaintext, so a server without TLS needs disable. · PG_SSL_CA=Path to a CA certificate file. Setting it by itself implies verify-full. · PG_STATEMENT_TIMEOUT=Statement timeout in milliseconds, applied to every session. · PG_USER=Database user.
Icon formats (raw)confirmed absent
Connection paths (source structure){"packages":[{"registryType":"npm","identifier":"mcp-postgres-server","version":"0.3.1","runtimeHint":"npx","transport":"stdio","environment":[{"name":"DATABASE_URL","description":"Full connection string (preferred). Supports sslmode in the URL.","format":"string","required":false,"secret":true},{"name":"PG_HOST","description":"Database host (fallback when DATABASE_URL is not set).","format":"string","required":false,"secret":false},{"name":"PG_PORT","description":"Database port.","format":"number","required":false,"secret":false},{"name":"PG_USER","description":"Database user.","format":"string","required":false,"secret":false},{"name":"PG_PASSWORD","description":"Database password.","format":"string","required":false,"secret":true},{"name":"PG_DATABASE","description":"Database name.","format":"string","required":false,"secret":false},{"name":"PG_ALLOW_WRITE","description":"When true, execute performs writes and reads are sent directly. Off (default) is read-only: execute refuses writes and each read runs in a READ ONLY transaction.","format":"boolean","required":false,"secret":false},{"name":"PG_SSLMODE","description":"TLS mode. require/allow/prefer encrypt without verifying the certificate; verify-ca/verify-full verify it (supply a CA via PG_SSL_CA). Unlike libpq, allow/prefer do not fall back to plaintext, so a server without TLS needs disable.","format":"string","required":false,"secret":false},{"name":"PG_SSL_CA","description":"Path to a CA certificate file. Setting it by itself implies verify-full.","format":"filepath","required":false,"secret":false},{"name":"PG_ENABLE_RUNTIME_CONNECT","description":"Register the connect_db tool (runtime credential switching).","format":"boolean","required":false,"secret":false},{"name":"PG_MAX_RESULT_BYTES","description":"Byte budget for a query result sent to the model. Whole rows are kept while they fit; over the budget returnedRows < rowCount and truncated is true.","format":"number","required":false,"secret":false},{"name":"PG_STATEMENT_TIMEOUT","description":"Statement timeout in milliseconds, applied to every session.","format":"number","required":false,"secret":false},{"name":"PG_CONNECT_TIMEOUT","description":"Timeout in milliseconds for a single connect attempt (raise it for slow links or SSH tunnels).","format":"number","required":false,"secret":false},{"name":"PG_SSH_HOST","description":"SSH bastion host. Setting it enables tunneling: the server reaches the database only through an SSH tunnel to this host. Needs the ssh2 optional dependency.","format":"string","required":false,"secret":false},{"name":"PG_SSH_PORT","description":"SSH bastion port.","format":"number","required":false,"secret":false},{"name":"PG_SSH_USER","description":"SSH username.","format":"string","required":false,"secret":false},{"name":"PG_SSH_PRIVATE_KEY","description":"Path to a private key file. If unset, auth falls back like ssh: a running agent (SSH_AUTH_SOCK), then a default key (~/.ssh/id_ed25519, id_rsa, id_ecdsa).","format":"filepath","required":false,"secret":false},{"name":"PG_SSH_PASSPHRASE","description":"Passphrase for the private key, if encrypted.","format":"string","required":false,"secret":true},{"name":"PG_SSH_AGENT","description":"true to use the ambient agent (SSH_AUTH_SOCK), or an explicit socket path / Windows named pipe.","format":"string","required":false,"secret":false},{"name":"PG_SSH_PASSWORD","description":"SSH login password. Opt-in; a key or agent takes precedence. Prefer keys, a bastion often disables password auth.","format":"string","required":false,"secret":true},{"name":"PG_SSH_FINGERPRINT","description":"Pinned host-key fingerprint (SHA256:...). Host-key verification is mandatory and set only this way: without it the tunnel refuses to connect. Get it with ssh-keygen -lF host.","format":"string","required":false,"secret":false},{"name":"PG_SSH_KEEPALIVE_INTERVAL","description":"SSH keepalive interval in ms; the tunnel drops after 3 unanswered keepalives, and the next call reconnects.","format":"number","required":false,"secret":false}],"additional_arguments_declared":false}],"remotes":[]}
Embed this badge

Paste this line into a README of your own. The badge states how many values the registry holds for the entry and when it last looked, and it links back to this page.

tracevero: number of measured values and date of collection for this registry entry

[![tracevero: number of measured values and date of collection for this registry entry](https://tracevero.com/badge/mcp/io-github-antonorlov-mcp-postgres-server.svg)](https://tracevero.com/mcp/io-github-antonorlov-mcp-postgres-server)

The image is drawn again on every request, so it always reports the current state while the pasted line stays as it is. It carries no rating and no traffic light – only the two measured figures.

Changes

Changes
2026-09-15Declared version: – → 0.3.1
2026-09-15Field of use, derived from the vendor description: – → Databases, Infrastructure
2026-09-15Repository URL listed: – → yes

These are the 3 most recent changes to this entry. Full history

tracevero · https://tracevero.com/mcp/io-github-antonorlov-mcp-postgres-server