MCP server for read-only PostgreSQL database queries in Claude Desktop
A Model Context Protocol (MCP) server that enables Claude Desktop to interact with PostgreSQL databases through natural language queries.
READ ONLY transactionsclaude mcp add postgres -s user -- npx -y @hovecapital/read-only-postgres-mcp-server
Then set your database environment variables:
export DB_HOST=localhost
export DB_PORT=5432
export DB_DATABASE=your_database_name
export DB_USERNAME=your_username
export DB_PASSWORD=your_password
Done! Restart Claude Code and ask: "What tables are in my database?"
1. Open your config file:
# macOS
open ~/Library/Application\ Support/Claude/claude_desktop_config.json
# Windows
notepad %APPDATA%\Claude\claude_desktop_config.json
2. Add this configuration:
{
"mcpServers": {
"postgres": {
"command": "npx",
"args": ["-y", "@hovecapital/read-only-postgres-mcp-server"],
"env": {
"DB_HOST": "localhost",
"DB_PORT": "5432",
"DB_DATABASE": "your_database_name",
"DB_USERNAME": "your_username",
"DB_PASSWORD": "your_password"
}
}
}
}
3. Save, restart Claude Desktop, and test!
This server is published in the Model Context Protocol Registry as capital.hove/read-only-local-postgres-mcp-server.
claude mcp add postgres -s user -- npx -y @hovecapital/read-only-postgres-mcp-server
Then configure your database credentials using environment variables. Restart Claude Code and you're done!
Benefits:
For Claude Desktop:
Edit ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):
{
"mcpServers": {
"postgres": {
"command": "npx",
"args": ["-y", "@hovecapital/read-only-postgres-mcp-server"],
"env": {
"DB_HOST": "localhost",
"DB_PORT": "5432",
"DB_DATABASE": "your_database_name",
"DB_USERNAME": "your_username",
"DB_PASSWORD": "your_password"
}
}
}
}
For Claude Code:
Edit ~/.config/claude-code/settings.json (macOS/Linux) or %APPDATA%\claude-code\settings.json (Windows):
{
"mcp": {
"servers": {
"postgres": {
"command": "npx",
"args": ["-y", "@hovecapital/read-only-postgres-mcp-server"],
"env": {
"DB_HOST": "localhost",
"DB_PORT": "5432",
"DB_DATABASE": "your_database_name",
"DB_USERNAME": "your_username",
"DB_PASSWORD": "your_password"
}
}
}
}
}
npm install -g @hovecapital/read-only-postgres-mcp-server
If you're using Claude Code, you can easily install this MCP server:
# Clone the repository
git clone https://github.com/hovecapital/read-only-local-postgres-mcp-server.git
cd read-only-local-postgres-mcp-server
# Install dependencies and build
npm install
npm run build
Then configure Claude Code by adding to your MCP settings.
Save the repository to a directory on your system:
mkdir ~/mcp-servers/postgres
cd ~/mcp-servers/postgres
git clone https://github.com/hovecapital/read-only-local-postgres-mcp-server.git .
npm install
npm run build
Note: If you installed via Option 1 (MCP Registry with npx), you've already configured everything! This section is for users who chose Options 2, 3, or 4 (npm or manual installation).
If you're using Claude Code with a manual installation, add the PostgreSQL server to your MCP settings:
Open your Claude Code settings (typically in ~/.config/claude-code/settings.json on macOS/Linux or %APPDATA%\claude-code\settings.json on Windows)
Add the PostgreSQL MCP server configuration:
{
"mcp": {
"servers": {
"postgres": {
"command": "node",
"args": ["/absolute/path/to/read-only-local-postgres-mcp-server/dist/index.js"],
"env": {
"DB_HOST": "localhost",
"DB_PORT": "5432",
"DB_DATABASE": "your_database_name",
"DB_USERNAME": "your_username",
"DB_PASSWORD": "your_password"
}
}
}
}
}
If you're using Claude Desktop with a manual installation, open your Claude Desktop configuration file:
macOS:
~/Library/Application Support/Claude/claude_desktop_config.json
Windows:
%APPDATA%\Claude\claude_desktop_config.json
Add the PostgreSQL server configuration:
{
"mcpServers": {
"postgres": {
"command": "node",
"args": ["/absolute/path/to/read-only-local-postgres-mcp-server/dist/index.js"],
"env": {
"DB_HOST": "localhost",
"DB_PORT": "5432",
"DB_DATABASE": "your_database_name",
"DB_USERNAME": "your_username",
"DB_PASSWORD": "your_password"
}
}
}
}
If you're using mise for Node.js version management, make sure to use the full path to the Node.js executable in your configuration.
| Variable | Description | Default |
|---|---|---|
DB_HOST | PostgreSQL server hostname | localhost |
DB_PORT | PostgreSQL server port | 5432 |
DB_DATABASE | Database name | postgres |
DB_USERNAME | PostgreSQL username | postgres |
DB_PASSWORD | PostgreSQL password | (empty) |
DB_SSL | Enable SSL connection | false |
DB_ALLOWED_HOSTS | Comma-separated host:port pairs that runtime connection strings may target, in addition to DB_HOST:DB_PORT | (empty) |
This MCP server exposes three tools that Claude can use to interact with PostgreSQL databases.
connectConnect to a PostgreSQL database using a connection string. The connection persists for subsequent queries until changed or disconnected. The target must be DB_HOST:DB_PORT or listed in DB_ALLOWED_HOSTS.
Parameters:
| Parameter | Type | Required | Description |
|---|---|---|---|
connectionString | string | Yes | PostgreSQL connection string |
Connection String Format:
postgres://username:password@host:port/database?sslmode=require
postgresql://username:password@host:port/database
SSL Modes Supported:
sslmode=require - Require SSL (recommended for remote connections)sslmode=verify-full - Require SSL with certificate verificationExample Usage (natural language):
"Connect to postgres://myuser:mypass@db.example.com:5432/production"
"Connect to this database: postgres://admin:secret@localhost/analytics"
Response:
{
"status": "connected",
"host": "db.example.com",
"port": 5432,
"database": "production",
"user": "myuser",
"ssl": true
}
disconnectDisconnect from the current runtime database and revert to the default environment-configured connection.
Parameters: None
Example Usage (natural language):
"Disconnect from the current database"
"Go back to the default database"
Response:
{
"status": "disconnected",
"message": "Reverted to default environment connection",
"host": "localhost",
"database": "postgres"
}
queryRun a read-only SQL query against the currently connected database. Optionally override the connection for a single query.
Parameters:
| Parameter | Type | Required | Description |
|---|---|---|---|
sql | string | Yes | SQL query to execute (SELECT only) |
connectionString | string | No | Override connection for this query only |
Example Usage (natural language):
"Show me all tables in the database"
"SELECT * FROM users LIMIT 10"
"Run this query on postgres://other:pass@host/db: SELECT count(*) FROM orders"
Response:
[
{ "id": 1, "name": "Alice", "email": "alice@example.com" },
{ "id": 2, "name": "Bob", "email": "bob@example.com" }
]
When using this MCP server, Claude can:
Query the default database (configured via environment variables):
User: "What tables are in my database?"
Claude: [Uses query tool with SQL: "SELECT table_name FROM information_schema.tables WHERE table_schema = 'public'"]
Connect to a different database dynamically:
User: "Connect to postgres://user:pass@newhost/newdb and show me the users table"
Claude: [Uses connect tool first, then query tool]
One-off query to a different database (without switching active connection):
User: "How many records are in the orders table on postgres://user:pass@analytics/warehouse?"
Claude: [Uses query tool with connectionString parameter]
Revert to default connection:
User: "Go back to my local database"
Claude: [Uses disconnect tool]
Basic queries (uses default/active connection):
"Show me all tables in my database"
"What's the structure of the users table?"
"Get the first 10 records from the products table"
"How many orders were placed last month?"
"Show me users with email addresses ending in @gmail.com"
Dynamic connection examples:
"Connect to postgres://analyst:password@analytics.example.com:5432/warehouse"
"Now show me all the tables"
"What's the total revenue in the sales table?"
"Disconnect and go back to my local database"
One-off queries to different databases:
"Run SELECT count(*) FROM users on postgres://admin:secret@prod.example.com/app"
"Check the orders table on my staging database: postgres://dev:dev@staging/app"
Claude will automatically convert your natural language requests into appropriate SQL queries and execute them against your database.
The server enforces read-only access on all connections (both environment-configured and runtime dynamic connections) in three layers:
BEGIN READ ONLY, and the connection is closed afterwards, so nothing is ever committed. PostgreSQL itself rejects INSERT, UPDATE, DELETE, MERGE, DDL, SELECT INTO, nextval(), large-object writes and any write hidden in a CTE (WITH x AS (INSERT ...) SELECT ...) or a function body, regardless of how the statement is spelled.SELECT 1; DROP TABLE ... is rejected by the server.INSERT, UPDATE, DELETE, TRUNCATE, COPY, MERGECREATE, ALTER, DROP, COMMENT, RENAME, REASSIGNGRANT, REVOKE, SECURITYSET, RESET, DISCARD, LOADCALL, DO, EXECUTE, PREPARE, DEALLOCATEDECLARE, FETCH, MOVE, CLOSEBEGIN, START, COMMIT, ROLLBACK, SAVEPOINT, RELEASE, LOCKVACUUM, ANALYZE, REINDEX, CLUSTER, REFRESH, CHECKPOINTNOTIFY, LISTEN, UNLISTENOnly statements beginning with read verbs (e.g. SELECT, WITH, EXPLAIN, SHOW, TABLE, VALUES) are allowed through. Because EXPLAIN ANALYZE executes the statement it wraps, its inner statement is validated too.
A read-only transaction does not stop functions that touch the server filesystem, run arbitrary SQL, or change process state, so a query is also rejected if it mentions any of these anywhere in its text: pg_read_file, pg_read_binary_file, pg_stat_file, pg_ls_*, pg_file_*, pg_logdir_ls, pg_logfile_rotate, lo_import, lo_export, dblink*, query_to_xml*, crosstab*, connectby, set_config, pg_terminate_backend, pg_cancel_backend, pg_reload_conf, pg_rotate_logfile, pg_sleep*. Unicode-escaped identifiers (U&"...") are rejected because they could spell one of these names another way.
Function-name matching is a denylist and cannot be complete. The dedicated read-only role below removes the underlying privileges (pg_write_server_files, pg_read_server_files, superuser) that file operations need, and is the recommended setup.
When using the connect tool or connectionString parameter:
DB_HOST:DB_PORT or a host:port pair listed in DB_ALLOWED_HOSTS. Other targets are rejected before any socket is opened, so the tools cannot be used to scan ports on the host or its network.connect tool response excludes passwordsFor enhanced security, create a dedicated read-only user for the MCP server:
-- Create a read-only user
CREATE USER claude_readonly WITH PASSWORD 'secure_password';
-- Grant only SELECT permissions on your specific schema
GRANT USAGE ON SCHEMA public TO claude_readonly;
GRANT SELECT ON ALL TABLES IN SCHEMA public TO claude_readonly;
-- Grant permissions for future tables (optional)
ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT SELECT ON TABLES TO claude_readonly;
dist/index.js is correctclaude_desktop_config.json formatTo see server logs, you can run the server manually:
node dist/index.js
~/mcp-servers/postgres/
├── src/
│ └── index.ts
├── dist/
│ ├── index.js
│ └── index.d.ts
├── package.json
├── tsconfig.json
└── node_modules/
Feel free to submit issues and enhancement requests!
This project is open source and available under the MIT License.
If you encounter issues:
Note: This server is designed for development and analysis purposes. For production use, consider additional security measures and monitoring.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y @hovecapital/read-only-postgres-mcp-serverMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"capital-hove-read-only-local-postgres-mcp-server": {
"command": "npx",
"args": [
"-y",
"@hovecapital/read-only-postgres-mcp-server"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referencecapital.hove/read-only-local-postgres-mcp-server works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.