PostgreSQL
Configure the Connection
Tested with PostgreSQL 14 through 18. Every option on this page also applies to the managed and compatible services built on this connector, such as Supabase, Neon, and Amazon RDS.
Connection Parameters
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
host | string | Yes | — | Database server hostname or IP address |
port | number | Yes | 5432 | Database server port |
user | string | Yes | — | Database username |
password | string | Conditional | — | Database password. Required unless aws_iam is set |
dbname | string | Yes | — | Database name |
Alternatively, paste a connection string to fill in the host, port, user, password, and database name, plus ssl.mode when the string includes sslmode:
postgresql://user:password@host:5432/database
AWS IAM Authentication
Amazon RDS and Aurora instances can authenticate with AWS IAM instead of a database password. Set aws_iam on the connection and omit password — exactly one of the two must be present. Each connection mints a short-lived token; tokens are never reused across connections.
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
aws_iam.region | string | Yes | — | AWS region of the database instance, for example us-east-1 |
aws_iam.access_key | string | No | — | AWS access key ID. Must be paired with aws_iam.secret_key |
aws_iam.secret_key | string | No | — | AWS secret access key. Must be paired with aws_iam.access_key |
aws_iam.role_arn | string | No | — | IAM role to assume, for example arn:aws:iam::123456789012:role/my-role |
Omit access_key and secret_key to use whatever credentials the runtime provides — an EC2 instance profile, an EKS/IRSA web identity token, an ECS task role, or a shared credentials profile. AWS IAM Identity Center (SSO) profiles are not supported.
The database user is still required, and must be granted IAM authentication on the instance.
aws_iam forces ssl.mode to verify-full, and the Amazon RDS certificate authority for aws_iam.region is trusted automatically — you do not need to download the RDS CA bundle and set ssl.ca_cert. An explicit ssl.ca_cert still takes precedence.In the Studio, choose AWS IAM as the Authentication Method when adding the data source. It is offered on the PostgreSQL, MySQL, and MariaDB connectors and on the Amazon RDS and Aurora tiles.
SSL Configuration
| Parameter | Type | Description |
|---|---|---|
ssl.mode | string | SSL connection mode (see below) |
ssl.ca_cert | string | CA certificate (base64-encoded PEM or DER) |
ssl.client_cert | string | Client certificate for mutual TLS (base64-encoded) |
ssl.client_key | string | Client private key (base64-encoded) |
ssl.client_key_password | string | Password for an encrypted client private key |
SSL Modes
| Mode | Description |
|---|---|
disable | No TLS encryption |
prefer | Attempt TLS, fall back to unencrypted if unavailable |
require | Require TLS without certificate verification. If ssl.ca_cert is provided, verifies the server certificate against it (same behavior as verify-ca) |
verify-ca | Require TLS and verify the server certificate chain. Does not check hostname. When ssl.ca_cert is omitted, validates against a bundled set of public root CAs (Mozilla's), not the operating system's trust store |
verify-full | Require TLS, verify the server certificate chain, and verify the hostname matches the certificate. When ssl.ca_cert is omitted, validates against a bundled set of public root CAs (Mozilla's), not the operating system's trust store |
verify-full. Without ssl.ca_cert, the connector trusts only the bundled public root CAs, or the Amazon RDS certificate authority when aws_iam is set. Provide ssl.ca_cert for a server whose certificate is signed by a private or self-signed CA.Supported Key Formats
Client keys are accepted in the following formats, all normalized internally to PKCS#8:
- PKCS#8 (PEM or DER)
- Encrypted PKCS#8 PEM (requires
ssl.client_key_password) - PKCS#1 RSA (PEM or DER)
- SEC1 EC (PEM only)
Managed and Compatible Services
The Studio's connector picker has a tile for each service below. Every tile uses the PostgreSQL connector, so the options, SSL modes, and key formats above all apply. A tile only adapts the form to the service: it shows the service's connection string format, sets its default port where it differs from 5432, and displays its setup notes.
Only the Amazon RDS and Aurora tiles offer AWS IAM authentication. Every other tile connects with a username and password.
| Service | Notes |
|---|---|
| Aiven for PostgreSQL | — |
| AlloyDB for PostgreSQL | Instances expose a static IP address, not a DNS hostname. Use VPC peering or the AlloyDB Auth Proxy for external access |
| Amazon Aurora PostgreSQL | Offers AWS IAM authentication |
| Amazon RDS for PostgreSQL | Offers AWS IAM authentication |
| Azure Database for PostgreSQL | Flexible Server. Use a plain username, without the legacy user@server suffix |
| Crunchy Bridge | — |
| DigitalOcean Managed PostgreSQL | Default port 25060 |
| EDB Postgres | EDB Postgres AI Cloud Service |
| Google Cloud SQL for PostgreSQL | Allowlist your client IP under Connections → Networking. Public IPs are numeric, so use the Cloud SQL Auth Proxy for hostname-based access |
| Heroku Postgres | — |
| Neon | Offers pooled (-pooler) and direct endpoints. Use the pooled endpoint for high-concurrency traffic, and the direct endpoint if PgBouncer compatibility causes issues |
| PlanetScale PostgreSQL | — |
| Railway PostgreSQL | Offers separate internal and public connection URLs. Use the internal URL for services in the same Railway project |
| Render PostgreSQL | — |
| Supabase | See Connect to Supabase |
| TimescaleDB | — |
| YugabyteDB | Alpha. Default port 5433 |
An Alpha badge on a tile marks a service that speaks the PostgreSQL protocol but that Monospace doesn't yet test first-party.
A service that runs standard PostgreSQL doesn't need its own tile: choose PostgreSQL. If you need a service that isn't listed, request it on the roadmap.
Connect to Supabase
- Open your Supabase project dashboard and navigate to Project Settings > Database.
- Enable Allow connections from anywhere in your Supabase project settings. The Supabase tile reminds you of this.
- Copy the connection string (direct connection or session pooler).
- In Monospace, add a new data source and select the Supabase tile.
- Paste the connection string — the host, port, user, password, and database name fields populate automatically.
- Replace
[YOUR-PASSWORD]with your database password. The form warns you while the placeholder remains.
Supabase provides two connection string formats:
postgresql://postgres:[YOUR-PASSWORD]@db.[PROJECT-REF].supabase.co:5432/postgres
postgresql://postgres.[PROJECT-REF]:[YOUR-PASSWORD]@aws-0-[REGION].pooler.supabase.com:5432/postgres
See Also
- Connectors — every way to connect a data source
- Custom Connectors — connect APIs and other systems without a built-in connector
- Introspection — how Monospace discovers your database schema
- Configuration — environment variables for the system database and SSL