Postgres MCP: SSL connection required by Supabase, Neon or RDS (add sslmode=require)
Fixes the Postgres MCP server failing against managed Postgres (Supabase, Neon, RDS) with an SSL-required error. Managed hosts refuse non-TLS connections. The fix is appending ?sslmode=require to the connection URL. Use when connecting to any managed Postgres from an MCP server; not for local dev databases or certificate errors.
TL;DR: Managed Postgres providers (Supabase, Neon, RDS) require TLS and your MCP server is connecting without it. Append ?sslmode=require to the connection URL in your client config. That is the whole fix.
Error: SSL connection is required. Please specify SSL options and retry.Variant phrasings you may see: SSL is required, server requires encryption, no pg_hba.conf entry for host ... SSL off.
Fix it
- Find the connection URL in your MCP client config (
envblock, e.g. DATABASE_URL or the server's first CLI arg).
- Append the SSL mode parameter:
postgresql://db.supabase.co:5432/postgres?sslmode=require If the URL already has query parameters, join with & instead: ...?connect_timeout=10&sslmode=require.
- Restart the MCP client so the server picks up the new URL.
Expected: the next tool call connects and returns rows. No SSL error.
When to use this
- Connecting an MCP Postgres server to Supabase, Neon, RDS, or any managed Postgres.
- The error mentions SSL, TLS, or encryption being required.
When NOT to use this
- Local dev Postgres (Docker, Homebrew). Forcing SSL there causes the opposite error. Use
sslmode=disablefor local dev if needed. - The error is a certificate verification failure (self-signed certificate). That needs the CA cert or a different sslmode, not just
require.
Compatibility
- All MCP Postgres servers that pass the URL to node-postgres/pg: @modelcontextprotocol/server-postgres, yawlabs/postgres-mcp, Tabulus, pgedge-postgres-mcp.
- Supabase, Neon, AWS RDS, Google Cloud SQL, Azure Database for PostgreSQL.
Why it happens
Managed Postgres fleets terminate plain connections as a security policy. The pg driver defaults to opportunistic SSL (prefer), which is not enough for providers that mandate it. sslmode=require tells the driver to always negotiate TLS, which is what the provider expects.
Edge cases
- Supabase pooler URLs (port 6543) also need
sslmode=require. - If you get a certificate error after adding it, your provider uses a custom CA. Either supply the CA (
sslrootcert) or check the provider docs for their recommended sslmode. - Some servers read the URL once at startup. A client restart is required, not just a new chat.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.