Skip to content
Datablare

PostgreSQL MCP Server, Read-Only by Design

A hosted PostgreSQL MCP server for Claude, ChatGPT and Cursor. Sessions are read-only, agents see only the tables you choose, and every query is logged.

Setup

Connect PostgreSQL in 5 steps

  1. Step 1: Create a read-only role (recommended)

    Run the SQL below, or the version Datablare shows on the setup screen, to create datablare_reader with SELECT on the schemas you want to expose.

  2. Step 2: Add PostgreSQL as a data source

    In Datablare, go to Settings → Project → Data connection, add a data source and pick PostgreSQL. Enter host, port 5432, username, password and database, or paste a postgresql:// connection string.

  3. Step 3: Choose SSL and network access

    Turn on Use SSL if your server requires it. If the database is behind a firewall, allow the IP shown on the setup screen, or connect through an SSH tunnel.

  4. Step 4: Test and choose tables

    Test the connection — Datablare reports whether the login can only read — then select the tables agents may query. Hide sensitive columns later in Modeling.

  5. Step 5: Connect your AI agent

    Open Connect your AI agent, pick Claude, ChatGPT, Cursor, VS Code or Claude Code, and follow the sign-in steps.

Datablare is a hosted PostgreSQL MCP server that lets Claude, ChatGPT, Cursor, VS Code and Claude Code answer questions from your Postgres database without the risk of a raw connection. You connect the database once; every query an agent sends is checked, run in a read-only session, limited to the tables and columns you chose, and written to an audit log. Your team adds one link to their AI tool and signs in.

Why a plain Postgres MCP server is risky

Open-source PostgreSQL MCP servers are easy to start: give them a connection string and they run whatever SQL the model writes. The safety depends entirely on that login. In practice:

  • the login is often the application’s own, with write rights on every table;
  • public holds everything, including users with emails and password hashes;
  • functions like pg_read_file, dblink or pg_sleep are reachable from a plain SELECT;
  • nothing records which person’s question produced which query.

What Datablare adds on top of PostgreSQL

Read-only, enforced twice. Datablare’s SQL guard accepts only a single SELECT, WITH or VALUES statement and refuses write keywords, COPY, SET, DO, CALL and functions that read files, reach other servers, sleep, lock or change settings (including set_config). What passes runs on a connection opened with default_transaction_read_only=on, so Postgres refuses writes itself.

Tables and columns you choose. Pick tables per project; mark a table as not queryable while keeping it documented; hide columns such as email or phone. The column guard expands SELECT * and follows aliases, so a hidden column is refused wherever it appears.

Every query on record. Audit shows who asked, the question, the SQL, the outcome, rows returned and time taken.

Revoke at once. Removing a person or revoking a key switches off their access immediately. Datablare is hosted in India and passes result rows through without storing them. It helps you meet DPDP · GDPR · HIPAA · CCPA/CPRA · PDPL obligations for data you expose to AI tools. Read more on security and how it works.

PostgreSQL notes

Schemas and search_path

Datablare lists tables and views from every schema the role can see, except pg_catalog, information_schema and pg_toast, as schema.table. When an agent writes a bare name like orders, the guard matches it only against tables you exposed. For that query, Datablare puts the matched schema first in search_path, so orders means your exposed sales.orders — never an unexposed hr.orders earlier in the path. A bare name that exists in two exposed schemas is refused with a request to qualify it.

Timeouts and limits

Each query runs with a local statement_timeout: 30 seconds by default, 60 at most, or your role’s own timeout if it is stricter. Results are capped at 1,000 rows by default and 5,000 at most.

SSL and connection strings

With Use SSL on, Datablare connects with sslmode=require; otherwise it prefers SSL when the server offers it. Paste a connection string from your provider and Datablare fills in the fields for you to check.

Create a read-only login first

CREATE ROLE datablare_reader LOGIN PASSWORD 'choose-a-strong-password'
  CONNECTION LIMIT 5;
ALTER ROLE datablare_reader SET statement_timeout = '30s';
ALTER ROLE datablare_reader SET idle_in_transaction_session_timeout = '60s';

GRANT CONNECT ON DATABASE shop TO datablare_reader;
GRANT USAGE ON SCHEMA public TO datablare_reader;
GRANT SELECT ON ALL TABLES IN SCHEMA public TO datablare_reader;
ALTER DEFAULT PRIVILEGES IN SCHEMA public
  GRANT SELECT ON TABLES TO datablare_reader;

Repeat the USAGE and SELECT grants for each extra schema you want to expose.

Example questions

Try these on Datablare’s one-click e-commerce sample before you connect your own Postgres database:

  • What are our best-selling products this month?
  • Which colours sell best in each product category?
  • Which articles are out of stock in more than two sizes?
  • How many new customers placed a first order each week?

Connect PostgreSQL to your AI tool

Sign up free and add your database, then connect Claude, ChatGPT, Cursor or Claude Code. Plans are on pricing.

FAQ

PostgreSQL MCP server: questions

Is this an open-source PostgreSQL MCP server I run myself?

No. Datablare is a hosted, governed MCP server: you connect your PostgreSQL database once, and your team's AI tools reach it through one project link with sign-in, table and column rules, and an audit log.

Which PostgreSQL hosts work?

Any PostgreSQL server Datablare can reach: a managed database with a public address, or a private one through an SSH tunnel to a bastion you run. Pointing Datablare at a read replica keeps questions off your primary.

How does Datablare handle multiple schemas?

Tables are listed as schema.table across every non-system schema the role can see. Unqualified names are matched against the tables you exposed; if a name exists in two exposed schemas, the query is refused and the agent is asked to qualify it.

What happens if an agent tries to write?

The SQL guard refuses it before it reaches PostgreSQL, and the session is read-only anyway. The attempt is recorded in Audit as a refusal.

Can I keep a statement timeout I already set on the role?

Yes. If your role has a statement_timeout, Datablare keeps the stricter of yours and its own for each query.

Ask PostgreSQL from your AI tool

Other databases: MySQL · MariaDB · SQL Server · Oracle · ClickHouse · Snowflake

Give your team answers from PostgreSQL, read-only.

Start free with the e-commerce sample or your own database. Connect Claude in about two minutes.

30 minutes with the founder. Or WhatsApp / [email protected]