postgres-mcp-server
An MCP server for safely querying PostgreSQL from an LLM, with read-only default mode, multi-connection aliases, and session-enforced safety.
README
postgres-mcp-server
An MCP server for safely querying PostgreSQL from an LLM. Read-only by default, multi-connection with named aliases, Postgres-session-enforced safety.
Quickstart
Create ~/.config/postgres-mcp/config.json:
{
"connections": {
"local": {
"url_env": "LOCAL_DATABASE_URL",
"mode": "read"
}
}
}
Add to your MCP client config (Claude Desktop, Cursor, Windsurf, Zed):
{
"mcpServers": {
"postgres": {
"command": "npx",
"args": ["-y", "@arieffian/postgres-mcp-server"],
"env": { "LOCAL_DATABASE_URL": "postgres://user:pw@localhost/db" }
}
}
}
Restart the client and ask: "Ping the local Postgres and list its tables."
Modes
Every connection declares its mode statically in config. Escalation requires editing config and restarting.
| Mode | SELECT | INSERT/UPDATE/DELETE | DDL | Notes |
|---|---|---|---|---|
| read | ✓ | ✗ | ✗ | Default. SET default_transaction_read_only = on at the session level. |
| write | ✓ | ✓ | ✗ | Writes must go through begin_transaction → execute → commit. |
| admin | ✓ | ✓ | ✓ | Same tx flow as write; DDL also permitted. |
Tools
Meta
ping,list_connections
SQL
query— read-only SELECT via server-side cursorbegin_transaction,commit,rollback— tx lifecycleexecute— INSERT/UPDATE/DELETE/DDL inside an open tx
Schema introspection (Phase 2, new in 0.2.0)
list_databases,list_schemaslist_tables— includes regular, partitioned, and foreign tables (viakindfield); row count is clamped to 0 for never-analyzed tableslist_indexes,list_constraints— per-table catalog listingslist_functions— excludes functions installed by extensionsdescribe_table— composite: columns, PK, FKs, indexes, constraints in one call
Observability — ships in Phase 3.
Safety
Five layers — see docs/safety.md. Highlights:
- Read-only enforced by the Postgres session, not by parsing SQL — we do not trust our own parser.
- Statement timeout per connection (default 30s).
- Every SELECT wrapped in a server-side cursor; results capped by row count and byte size.
- Writes require an explicit transaction; no autocommit.
- Bound parameter values are never logged. Credentials in URLs are redacted.
Configuration
Discovery order (first hit wins):
--config <path>CLI flag$POSTGRES_MCP_CONFIGenv var$XDG_CONFIG_HOME/postgres-mcp/config.json(fallback~/.config/postgres-mcp/config.json)./postgres-mcp.config.json
Contributing
Requires Node ≥ 20. Local dev: npm install, npm test. Integration tests use testcontainers and need a working Docker daemon.
Publishing
Set NPM_TOKEN in the repo's GitHub Actions secrets. Changesets automatically opens a release PR on push to main; merging it publishes to npm with provenance.
License
MIT
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。
mcp-server-qdrant
这个仓库展示了如何为向量搜索引擎 Qdrant 创建一个 MCP (Managed Control Plane) 服务器的示例。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。