Overview

PostgreSQL

Configuration options for the PostgreSQL connector, and setup notes for the managed and compatible PostgreSQL services it connects to.

Configure the Connection

Tested with PostgreSQL 14 through 18. Every option on this page also applies to the managed and compatible services built on this connector, such as Supabase, Neon, and Amazon RDS.

Connection Parameters

ParameterTypeRequiredDefaultDescription
hoststringYes—Database server hostname or IP address
portnumberYes5432Database server port
userstringYes—Database username
passwordstringConditional—Database password. Required unless aws_iam is set
dbnamestringYes—Database name

Alternatively, paste a connection string to fill in the host, port, user, password, and database name, plus ssl.mode when the string includes sslmode:

Connection String
postgresql://user:password@host:5432/database

AWS IAM Authentication

Amazon RDS and Aurora instances can authenticate with AWS IAM instead of a database password. Set aws_iam on the connection and omit password — exactly one of the two must be present. Each connection mints a short-lived token; tokens are never reused across connections.

ParameterTypeRequiredDefaultDescription
aws_iam.regionstringYes—AWS region of the database instance, for example us-east-1
aws_iam.access_keystringNo—AWS access key ID. Must be paired with aws_iam.secret_key
aws_iam.secret_keystringNo—AWS secret access key. Must be paired with aws_iam.access_key
aws_iam.role_arnstringNo—IAM role to assume, for example arn:aws:iam::123456789012:role/my-role

Omit access_key and secret_key to use whatever credentials the runtime provides — an EC2 instance profile, an EKS/IRSA web identity token, an ECS task role, or a shared credentials profile. AWS IAM Identity Center (SSO) profiles are not supported.

The database user is still required, and must be granted IAM authentication on the instance.

Note
Setting aws_iam forces ssl.mode to verify-full, and the Amazon RDS certificate authority for aws_iam.region is trusted automatically — you do not need to download the RDS CA bundle and set ssl.ca_cert. An explicit ssl.ca_cert still takes precedence.

In the Studio, choose AWS IAM as the Authentication Method when adding the data source. It is offered on the PostgreSQL, MySQL, and MariaDB connectors and on the Amazon RDS and Aurora tiles.

SSL Configuration

ParameterTypeDescription
ssl.modestringSSL connection mode (see below)
ssl.ca_certstringCA certificate (base64-encoded PEM or DER)
ssl.client_certstringClient certificate for mutual TLS (base64-encoded)
ssl.client_keystringClient private key (base64-encoded)
ssl.client_key_passwordstringPassword for an encrypted client private key

SSL Modes

ModeDescription
disableNo TLS encryption
preferAttempt TLS, fall back to unencrypted if unavailable
requireRequire TLS without certificate verification. If ssl.ca_cert is provided, verifies the server certificate against it (same behavior as verify-ca)
verify-caRequire TLS and verify the server certificate chain. Does not check hostname. When ssl.ca_cert is omitted, validates against a bundled set of public root CAs (Mozilla's), not the operating system's trust store
verify-fullRequire TLS, verify the server certificate chain, and verify the hostname matches the certificate. When ssl.ca_cert is omitted, validates against a bundled set of public root CAs (Mozilla's), not the operating system's trust store
Tip
For production deployments, use verify-full. Without ssl.ca_cert, the connector trusts only the bundled public root CAs, or the Amazon RDS certificate authority when aws_iam is set. Provide ssl.ca_cert for a server whose certificate is signed by a private or self-signed CA.

Supported Key Formats

Client keys are accepted in the following formats, all normalized internally to PKCS#8:

  • PKCS#8 (PEM or DER)
  • Encrypted PKCS#8 PEM (requires ssl.client_key_password)
  • PKCS#1 RSA (PEM or DER)
  • SEC1 EC (PEM only)

Managed and Compatible Services

The Studio's connector picker has a tile for each service below. Every tile uses the PostgreSQL connector, so the options, SSL modes, and key formats above all apply. A tile only adapts the form to the service: it shows the service's connection string format, sets its default port where it differs from 5432, and displays its setup notes.

Only the Amazon RDS and Aurora tiles offer AWS IAM authentication. Every other tile connects with a username and password.

ServiceNotes
Aiven for PostgreSQL—
AlloyDB for PostgreSQLInstances expose a static IP address, not a DNS hostname. Use VPC peering or the AlloyDB Auth Proxy for external access
Amazon Aurora PostgreSQLOffers AWS IAM authentication
Amazon RDS for PostgreSQLOffers AWS IAM authentication
Azure Database for PostgreSQLFlexible Server. Use a plain username, without the legacy user@server suffix
Crunchy Bridge—
DigitalOcean Managed PostgreSQLDefault port 25060
EDB PostgresEDB Postgres AI Cloud Service
Google Cloud SQL for PostgreSQLAllowlist your client IP under Connections → Networking. Public IPs are numeric, so use the Cloud SQL Auth Proxy for hostname-based access
Heroku Postgres—
NeonOffers pooled (-pooler) and direct endpoints. Use the pooled endpoint for high-concurrency traffic, and the direct endpoint if PgBouncer compatibility causes issues
PlanetScale PostgreSQL—
Railway PostgreSQLOffers separate internal and public connection URLs. Use the internal URL for services in the same Railway project
Render PostgreSQL—
SupabaseSee Connect to Supabase
TimescaleDB—
YugabyteDBAlpha. Default port 5433

An Alpha badge on a tile marks a service that speaks the PostgreSQL protocol but that Monospace doesn't yet test first-party.

A service that runs standard PostgreSQL doesn't need its own tile: choose PostgreSQL. If you need a service that isn't listed, request it on the roadmap.

Connect to Supabase

  1. Open your Supabase project dashboard and navigate to Project Settings > Database.
  2. Enable Allow connections from anywhere in your Supabase project settings. The Supabase tile reminds you of this.
  3. Copy the connection string (direct connection or session pooler).
  4. In Monospace, add a new data source and select the Supabase tile.
  5. Paste the connection string — the host, port, user, password, and database name fields populate automatically.
  6. Replace [YOUR-PASSWORD] with your database password. The form warns you while the placeholder remains.

Supabase provides two connection string formats:

Direct Connection
postgresql://postgres:[YOUR-PASSWORD]@db.[PROJECT-REF].supabase.co:5432/postgres
Session Pooler
postgresql://postgres.[PROJECT-REF]:[YOUR-PASSWORD]@aws-0-[REGION].pooler.supabase.com:5432/postgres

See Also

MonospaceThe governed API layer for every app, person, and agent.

Copyright © 2026 Monospace Inc.