GetMCP/Blog/Build with MCP

Connect PostgreSQL or Supabase to Your AI as an MCP Server

InfiWebs · · 5 min read
Connect PostgreSQL or Supabase to Your AI as an MCP Server

If your application runs on Supabase, Neon, Amazon RDS or a PostgreSQL server of your own, the data your AI keeps asking about is already in one place. GetMCP’s Database connector turns that database into an MCP server: install a template, enter the connection details, and Claude, ChatGPT or Cursor can list your tables, describe them and answer questions with real queries — read-only until you say otherwise, with no API to write.

PostgreSQL is straightforward. Supabase adds exactly one wrinkle — which of its three connection strings you pick — so this guide covers both, Supabase first.

Supabase: get the right connection string

Open your project in the Supabase dashboard and click Connect in the top bar. You’ll be offered three ways in. Choose the Session pooler tab — not Direct connection and not Transaction pooler. You’ll see a string like this:

postgresql://postgres.abcdefghijklmnop:[YOUR-PASSWORD]@aws-0-ap-south-1.pooler.supabase.com:5432/postgres

Read the settings out of it: the host is the part after @ and before the colon (aws-0-ap-south-1.pooler.supabase.com), the port is 5432, the database name is postgres, and the username is postgres. followed by your project reference. Plain postgres does not work on the pooler — the test would say “Tenant or user not found”. The password is the database password you set when creating the project; if you no longer have it, reset it under Project Settings → Database.

Why the session pooler? The direct connection is only reachable over IPv6 unless you buy Supabase’s IPv4 add-on, so from most web hosts it simply times out. The transaction pooler is built for serverless functions and drops per-session settings between statements, which breaks the read-only lock and the query timeout GetMCP relies on. The session pooler on port 5432 supports both and is reachable over ordinary IPv4.

Plain PostgreSQL: create a read-only role

On your own PostgreSQL server (or Neon, RDS, DigitalOcean), give GetMCP its own role rather than the owner account:

CREATE ROLE getmcp_reader LOGIN PASSWORD 'a-strong-password';
GRANT USAGE ON SCHEMA public TO getmcp_reader;
GRANT SELECT ON ALL TABLES IN SCHEMA public TO getmcp_reader;
ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT SELECT ON TABLES TO getmcp_reader;

Managed databases usually keep an allow-list of IP addresses; add the address of the server that runs GetMCP. Your PHP needs the pdo_pgsql extension, which nearly every host provides — the connection test tells you if it’s missing.

Install the template and connect

In GetMCP go to Templates, find Database (MySQL / PostgreSQL), click Install and name the server after the project — “Acme App Database”. Open it, go to Settings → Database, and fill it in:

  1. Engine: PostgreSQL. The port fills in with 5432.
  2. Host, Database name, Username, Password: from the connection string, or your own server’s details.
  3. Encryption: leave it on TLS (don’t verify certificate). Supabase always offers TLS. If you also want the certificate verified, choose TLS, verify certificate and paste the CA certificate from Project Settings → Database → SSL Configuration.
  4. Schema: leave it empty. Your application’s tables live in public, which is the default.
  5. Leave Read-only connection ticked and click Test connection.

You should see “Connected to PostgreSQL 15.x. Found N tables and views in postgres.public.” and your table names. Testing saves the settings, so there’s nothing else to click. Set the server to Active, then use Connect to Claude or Connect to Cursor at the top of the page — or How to connect for ChatGPT and the rest.

Then ask

  • “What tables are in my Supabase database?”
  • “Describe the profiles table.”
  • “How many rows are in orders, and how many of them are from this month?”
  • “Show me the five most recent rows in messages.”
  • “Which users signed up last week but never created a project?”

The AI calls list_tables and describe_table to learn your schema, then get_rows, count_rows or run_query to answer. Every call is on the server’s Logs tab with the SQL it sent.

Row Level Security changes what the AI sees

Supabase tables usually have Row Level Security on, and it matters which user GetMCP connects as. The postgres user bypasses RLS and sees every row in every table — combined with GetMCP’s read-only connection, that’s the simplest setup: full read access, no writes possible. A custom role does not bypass RLS: if you create getmcp_reader and a table has RLS enabled with no policy for it, the AI sees zero rows from that table. No error, just nothing. Either add a SELECT policy for the role, or stick with postgres.

Supabase also keeps its own data in schemas like auth and storage. GetMCP lists tables from one schema, public by default. You can point the Schema field elsewhere, but think before aiming an AI at auth — it holds your users’ personal data. If you do, enable PII redaction on the server so email addresses and phone numbers are masked before they reach the model.

Nothing writes until you say so

Nine tools come with the template. The five that read are on from the start. The four that change data — insert_row, update_rows, delete_rows, execute_sql — install switched off, and the connection itself is opened read-only at the PostgreSQL session level while the box is ticked, so the database refuses a write no matter which tools are on. To allow changes you enable the tool and untick Read-only connection. Writes made that way go straight to the table, exactly like a query in Supabase’s SQL Editor: RLS policies apply to custom roles, and triggers and constraints run as usual.

If something doesn’t connect

  • “Tenant or user not found” — the username is missing the project reference. On the pooler it’s postgres.<project-ref>.
  • “password authentication failed” — that’s the database password, not your Supabase account password.
  • A timeout — you’re probably on the direct-connection host. Switch to the session pooler.
  • “prepared statement already exists” — you’re on the transaction pooler (port 6543). Use the session pooler on 5432.
  • Tables show but return no rows — Row Level Security is hiding them from a custom role.
  • A paused free-tier project refuses connections; restore it from the dashboard and the server works again without any change in GetMCP.

The step-by-step reference is Creating a Supabase database MCP server, with Connect a database for the connector itself. Your password stays on your server, encrypted with your installation’s own key, and query results never pass through getmcp.com.

InfiWebs
← All posts

Leave a reply

Try GetMCP

Ship MCP for your product, in days.

Install the plugin, import your API, share one URL. Your users will start calling your tools from Claude tonight.