Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ—„οΈ Databases
  3. Postgres (read Only)
P
Health: Not checked yetWe have not completed a health check for this listing yet.No health check has run yet.

Postgres (read Only)

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View Repository

Read-only Postgres: drop-in for the archived server-postgres, with schema context.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

One-click editor setup isn’t available for this listing yet β€” we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ
No confirmed setup config for this listing yet. We only publish a config block when the install details come from the project itself β€” its README, its docs, or a verified owner. We haven’t found those for Postgres (read-only), and we’d rather show nothing than a guess you’d paste into your client. Follow the project’s own setup instructions for the current steps.
Install Directory Badge Claim listing AlternativesπŸ—„οΈ More in Databases

Documentation Overview

@contextflo/postgres-mcp

The analytics MCP server for Postgres. Read-only by construction, with a context file you and the agent both write to, so the model answers the way your team would.

Built and maintained by Contextflo.

A drop-in replacement for the archived @modelcontextprotocol/server-postgres, which shipped with a SQL injection vulnerability that let COMMIT; DROP SCHEMA public CASCADE walk straight out of its read-only transaction.

Watch the 100-second demo: setup, the agent working out that an events table is not what it looks like and saving that as a note, and a DROP the server refuses.

Terminal
npx @contextflo/postgres-mcp postgresql://localhost/mydb

Why this one

Read-only that holds up. The archived server enforced read-only as a property of the SQL string. Here it is a property of the wire protocol, the connection, the Postgres parser, and the database role: four independent layers, each of which stops that payload on its own. The exploit is a test case in this repo.

Answers that make sense. A model that does not know fct_orders_v2 is the table your team actually uses, or that revenue is gross rather than net, writes confident, wrong SQL. .contextflo/context.md is a markdown file you edit and this server hands to the model, with nothing behind it but the file. The agent adds to it too: when it learns something the schema does not say, add_table_context appends a note, which you review in a diff like any other change.

Setup

1. Create a read-only role. Run this as the database owner, in psql or your provider's SQL editor. Use your database name and a real password, and repeat the schema lines for each schema the agent should see:

sql
CREATE ROLE mcp_readonly LOGIN PASSWORD 'change-me';
GRANT CONNECT ON DATABASE mydb TO mcp_readonly;
GRANT USAGE ON SCHEMA public TO mcp_readonly;
GRANT SELECT ON ALL TABLES IN SCHEMA public TO mcp_readonly;
ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT SELECT ON TABLES TO mcp_readonly;

This makes read-only a property of the database, not just of this server's code.

2. Put that role's connection string in .env in your project folder:

bash
DATABASE_URL='postgresql://mcp_readonly:change-me@db.example.com:5432/mydb'

Keep the quotes: hosted providers add ?sslmode=require&..., and the & needs them. The server reads DATABASE_URL from .env in the directory it starts in, so the connection string never appears on a command line.

Point it at a read replica or a branch rather than your primary if you can. Read-only stops writes, not load: an agent exploring your data can run a full-table scan or a heavy join, and on the primary that competes with your application. Neon and Supabase can branch or replicate a database in a few clicks, and RDS, Cloud SQL, and most other hosts offer read replicas. The statement timeout (30 seconds by default, --statement-timeout) and the row cap limit how long one query runs and how much it returns; they do not make it cheap.

3. Generate the context file:

Terminal
npx @contextflo/postgres-mcp init

That writes .contextflo/context.md, seeded from your COMMENT ON values. Edit it: the business definitions section is where the value is.

4. Add it to your client. Claude Code starts servers in your project folder, so it finds .env and the context file on its own:

Terminal
claude mcp add postgres --scope project -- npx -y @contextflo/postgres-mcp

--scope project writes .mcp.json into the folder instead of your global config.

Cursor, Claude Desktop, VS Code

Other clients may start servers outside your project folder (Claude Desktop starts them in /), so give them the connection string and the context file explicitly:

config.json
{
  "mcpServers": {
    "postgres": {
      "command": "npx",
      "args": ["-y", "@contextflo/postgres-mcp", "--context-file", "/path/to/project/.contextflo/context.md"],
      "env": { "DATABASE_URL": "postgresql://mcp_readonly:change-me@db.example.com:5432/mydb" }
    }
  }
}

Cursor uses .cursor/mcp.json. Claude Desktop uses claude_desktop_config.json (macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\). VS Code uses .vscode/mcp.json, with servers in place of mcpServers.

Tools

ToolWhat it does
queryRuns one read-only statement: SELECT, WITH ... SELECT, EXPLAIN, or SHOW.
list_tablesLists readable tables with descriptions. pattern matches anywhere in the name or description.
get_table_contextDescribes tables: columns, types, keys, foreign key targets, enum values, curated descriptions.
add_table_contextLets the agent write down a gotcha it found (amount is in cents, status has an undocumented value) in the context file.

There is no separate search tool, and that is deliberate. information_schema and pg_catalog are ordinary tables, so anything more specific, like finding every column named like %revenue% or listing tables with no primary key, is a query the model can write itself:

Dockerfile
SELECT table_schema, table_name, column_name
FROM information_schema.columns
WHERE column_name ILIKE '%revenue%';

Table schemas are also exposed as postgres://<host>/<table>/schema resources, matching the archived server, for anything pinned to those URIs. Most clients never fetch resources on their own, which is why discovery lives in the tools.

How read-only is enforced

Four layers. Each one stops the archived server's exploit by itself.

1. Extended query protocol. User SQL goes through pg-cursor, which always issues Parse/Bind/Execute, so Postgres itself rejects multi-statement input. The archived server called client.query(sql) with a bare string; node-postgres only prepares a statement when there are bind values, so that took the simple protocol path, where ; separates statements. That is the whole bug.

2. Connection-level read-only. default_transaction_read_only=on is set in the startup packet, and every statement runs inside an explicit BEGIN READ ONLY that always ends in ROLLBACK, never COMMIT. The rollback also undoes any SET made inside the transaction, so a statement cannot leave a pooled connection weakened for whoever gets it next.

3. A statement allowlist on the real Postgres parser. libpg-query is the actual Postgres C parser compiled to WASM, not a JavaScript approximation of SQL. The whole parse tree is walked rather than just the top-level node, which is what catches a data-modifying CTE:

Dockerfile
WITH x AS (INSERT INTO users VALUES (1) RETURNING *) SELECT * FROM x

That parses as a SelectStmt. A validator checking only the statement type runs it. Unknown node types fail closed.

Functions are checked against the database's own catalog. Postgres labels every function immutable, stable, or volatile, and only volatile ones can have side effects, so a volatile function is refused unless it is on a short list of harmless ones analysis needs (random(), clock_timestamp(), the table size functions). That covers dblink, pg_logical_emit_message (which writes to the WAL even in a read-only transaction), advisory locks, statistics resets, and whatever a future Postgres adds, without anyone having to name them. SECURITY DEFINER functions, which run with their owner's privileges, are refused whatever their label. A fixed list of known escapes is checked as well.

4. A read-only database role. The layers above are code, and code has bugs. A role that cannot write is enforced by Postgres regardless, which is why creating one is the first step of Setup. The server warns on startup if you connect as a superuser, and init prints the role snippet if the role it connects as can write.

What this does not protect against. The function check sees the functions a query calls directly, and it trusts how each is labelled. A user-defined function declared STABLE that writes anyway is allowed, and so is a function reached indirectly: inside a view, behind an operator, or through a type cast. The read-only transaction still refuses anything that changes table data that way; what can slip through is the rarer kind of side effect, such as a message written to the WAL. Layer 4 is what stops those, which is why the read-only role is the recommended setup rather than an optional extra. Read-only is also not confidentiality: anything the connected role can read, a model can read, so grant it only what you want an agent to see.

Migrating from @modelcontextprotocol/server-postgres

Swap the package name. The tool is still called query, still takes sql, still returns JSON rows, and the connection string is still the first argument.

Four deliberate differences:

  1. Multi-statement SQL and SET/RESET are rejected with a clear error. On the archived server these "worked", and that was the vulnerability.
  2. Results are capped at 1000 rows and 50,000 characters by default, and single values over 2,000 characters are shortened. Truncation is stated in the output, never silent. Rows come back one per line rather than pretty-printed, which roughly halves their token cost; it is still a JSON array. Dates and timestamps are exactly what Postgres sent, not re-rendered in the server's timezone.
  3. Schema discovery is a tool, not just a resource. Most clients do not auto-attach resources, which is why models using the old server so often did not know the schema.
  4. All non-system schemas are visible, not only public, and column descriptions come through from COMMENT ON.

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Databases View all alternatives
  • M
    MCP Toolbox for Databases

    MCP Toolbox for Databases enables your agent to connect to your database.

    πŸ—„οΈ Databases1 views
    Compare vs MCP Toolbox for Databases β†’
  • M
    MCP Server Mysql

    MySQL database integration in NodeJS with configurable access controls and schema inspection

    πŸ—„οΈ Databases3 views
    Compare vs MCP Server Mysql β†’
  • P
    Postgres MCP

    All-in-one MCP server for Postgres development and operations, with tools for performance analysis, tuning, and health checks

    πŸ—„οΈ Databases1 views
    Compare vs Postgres MCP β†’
  • S
    Supabase

    MCP server for interacting with the Supabase platform

    πŸ—„οΈ Databases1 views
    Compare vs Supabase β†’

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about Postgres (read Only)

We don't have a confirmed install command for Postgres (read-only) yet, so we don't publish a generated one β€” a guessed package name would point at the wrong package or none at all. Follow the project's own README or setup instructions (https://github.com/contextflo/postgres-mcp) for the current steps.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewPostgres (read Only) AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/postgres-read-only?style=directory)](https://allmcps.com/mcp/postgres-read-only)
HTML Embed
<a href="https://allmcps.com/mcp/postgres-read-only"><img src="https://allmcps.com/api/badge/postgres-read-only?style=directory" alt="Postgres (read Only) on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ—„οΈDatabases
More technical detailsExpand β–Ύ
Last updatedSep 28, 2026
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
27Quality signal: Emerging Β· 27/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership8/20
Documentation & tools11/30
Adoption & activity1/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… Featured
M

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge and attach your website β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ—„οΈ Databases β†’Best MCP servers for Databases β†’Best PostgreSQL MCP servers β†’Alternatives to Postgres (read Only) β†’Install in Claude DesktopInstall in CursorInstall in VS CodeSetup guides for all 13 MCP clients