PostgreSQL (hardened, read-only) MCP Server
io.github.Eszetael/postgres-mcp-hardened
What is the PostgreSQL (hardened, read-only) MCP server?
Read-only PostgreSQL over MCP. Writes refused at the parsed SQL, plus a READ ONLY transaction.
How to install PostgreSQL (hardened, read-only)
Copy-paste configuration for popular MCP clients.
DATABASE_URLrequiredsecretConnection string for the role the server connects as. Use a role that cannot write — the server refuses writes twice, but a read-only role is the layer that does not depend on us being correct. `--print-setup-sql` prints the SQL that creates one.
MCP_STATEMENT_TIMEOUTServer-side statement timeout, e.g. `5s`. A question that would pin the database is cancelled by PostgreSQL, not by hope.
MCP_ALLOW_TABLESComma-separated allowlist. A table off the list is refused by name, and hiding it inside a CTE, a view or a join does not help.
MCP_AUDIT_LOGPath to the tamper-evident audit log. Entries are chained by hash and survive a restart; `--verify-audit` checks the chain against an off-host anchor.
MCP_ADDRAddress to bind, default 127.0.0.1:8080.
Related MCP servers

Eterna MCP
No-KYC managed MCP for AI agents: sandboxed TypeScript trading SDK, isolated sub-accounts, futures.

ApplyGenie
Autonomous job application copilot, ATS form filler, and AI mock interview engine.
Bilingual financial news sentiment (English + Traditional Chinese) scored by Claude.

57 tools for AI-powered iOS Simulator automation — tap, swipe, type, screenshots, and more.
Feishu/Lark MCP server + CLI tool. 85 tools, 3 auth layers. Send as user via cookie+protobuf.
Trust gate for AI agents: multi-model adversarial consensus, signed and verifiable verdicts.


