PluginBench
MCP Server
Active
MIT

PostgreSQL (hardened, read-only) MCP Server

io.github.Eszetael/postgres-mcp-hardened

What is the PostgreSQL (hardened, read-only) MCP server?

Read-only PostgreSQL over MCP. Writes refused at the parsed SQL, plus a READ ONLY transaction.

How to install PostgreSQL (hardened, read-only)

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • DATABASE_URL
    required
    secret

    Connection string for the role the server connects as. Use a role that cannot write — the server refuses writes twice, but a read-only role is the layer that does not depend on us being correct. `--print-setup-sql` prints the SQL that creates one.

  • MCP_STATEMENT_TIMEOUT

    Server-side statement timeout, e.g. `5s`. A question that would pin the database is cancelled by PostgreSQL, not by hope.

  • MCP_ALLOW_TABLES

    Comma-separated allowlist. A table off the list is refused by name, and hiding it inside a CTE, a view or a join does not help.

  • MCP_AUDIT_LOG

    Path to the tamper-evident audit log. Entries are chained by hash and survive a restart; `--verify-audit` checks the chain against an off-host anchor.

  • MCP_ADDR

    Address to bind, default 127.0.0.1:8080.

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "postgres-mcp-hardened": {
      "command": "npx",
      "args": [
        "-y",
        "postgres-mcp-hardened",
        "--stdio"
      ],
      "env": {
        "DATABASE_URL": "<YOUR_DATABASE_URL>",
        "MCP_STATEMENT_TIMEOUT": "<YOUR_MCP_STATEMENT_TIMEOUT>",
        "MCP_ALLOW_TABLES": "<YOUR_MCP_ALLOW_TABLES>",
        "MCP_AUDIT_LOG": "<YOUR_MCP_AUDIT_LOG>",
        "MCP_ADDR": "<YOUR_MCP_ADDR>"
      }
    }
  }
}

Related MCP servers

ETEterna MCP logo

No-KYC managed MCP for AI agents: sandboxed TypeScript trading SDK, isolated sub-accounts, futures.

8
MIT
View repository →
APApplyGenie logo

Autonomous job application copilot, ATS form filler, and AI mock interview engine.

1
Python
MIT
View repository →

Bilingual financial news sentiment (English + Traditional Chinese) scored by Claude.

0
JavaScript
MIT
View repository →

57 tools for AI-powered iOS Simulator automation — tap, swipe, type, screenshots, and more.

0
TypeScript
MIT
View repository →

Feishu/Lark MCP server + CLI tool. 85 tools, 3 auth layers. Send as user via cookie+protobuf.

4
JavaScript
MIT
View repository →

Trust gate for AI agents: multi-model adversarial consensus, signed and verifiable verdicts.

2
TypeScript
MIT
View repository →