VectleSkillsPostgres MCP: SSL connection required by Supabase, Neon or RDS (add sslmode=require)

Postgres MCP: SSL connection required by Supabase, Neon or RDS (add sslmode=require)

Export

Fixes the Postgres MCP server failing against managed Postgres (Supabase, Neon, RDS) with an SSL-required error. Managed hosts refuse non-TLS connections. The fix is appending ?sslmode=require to the connection URL. Use when connecting to any managed Postgres from an MCP server; not for local dev databases or certificate errors.

TL;DR: Managed Postgres providers (Supabase, Neon, RDS) require TLS and your MCP server is connecting without it. Append ?sslmode=require to the connection URL in your client config. That is the whole fix.

Error: SSL connection is required. Please specify SSL options and retry.

Variant phrasings you may see: SSL is required, server requires encryption, no pg_hba.conf entry for host ... SSL off.

Fix it

  1. Find the connection URL in your MCP client config (env block, e.g. DATABASE_URL or the server's first CLI arg).
  1. Append the SSL mode parameter:
postgresql://db.supabase.co:5432/postgres?sslmode=require

If the URL already has query parameters, join with & instead: ...?connect_timeout=10&sslmode=require.

  1. Restart the MCP client so the server picks up the new URL.

Expected: the next tool call connects and returns rows. No SSL error.

When to use this

  • Connecting an MCP Postgres server to Supabase, Neon, RDS, or any managed Postgres.
  • The error mentions SSL, TLS, or encryption being required.

When NOT to use this

  • Local dev Postgres (Docker, Homebrew). Forcing SSL there causes the opposite error. Use sslmode=disable for local dev if needed.
  • The error is a certificate verification failure (self-signed certificate). That needs the CA cert or a different sslmode, not just require.

Compatibility

  • All MCP Postgres servers that pass the URL to node-postgres/pg: @modelcontextprotocol/server-postgres, yawlabs/postgres-mcp, Tabulus, pgedge-postgres-mcp.
  • Supabase, Neon, AWS RDS, Google Cloud SQL, Azure Database for PostgreSQL.

Why it happens

Managed Postgres fleets terminate plain connections as a security policy. The pg driver defaults to opportunistic SSL (prefer), which is not enough for providers that mandate it. sslmode=require tells the driver to always negotiate TLS, which is what the provider expects.

Edge cases

  • Supabase pooler URLs (port 6543) also need sslmode=require.
  • If you get a certificate error after adding it, your provider uses a custom CA. Either supply the CA (sslrootcert) or check the provider docs for their recommended sslmode.
  • Some servers read the URL once at startup. A client restart is required, not just a new chat.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=Postgres+MCP%3A+SSL+connection+required+by+Supabase%2C+Neon+or+RDS+%28add+sslmode%3Drequire%29&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.