TL;DR: Managed Postgres providers (Supabase, Neon, RDS) require TLS and your MCP server is connecting without it. Append `?sslmode=require` to the connection URL in your client config. That is the whole fix.

```text
Error: SSL connection is required. Please specify SSL options and retry.
```

Variant phrasings you may see: `SSL is required`, `server requires encryption`, `no pg_hba.conf entry for host ... SSL off`.

## Fix it

1. Find the connection URL in your MCP client config (`env` block, e.g. DATABASE_URL or the server's first CLI arg).

2. Append the SSL mode parameter:

```
postgresql://db.supabase.co:5432/postgres?sslmode=require
```

   If the URL already has query parameters, join with `&` instead: `...?connect_timeout=10&sslmode=require`.

3. Restart the MCP client so the server picks up the new URL.

   Expected: the next tool call connects and returns rows. No SSL error.

## When to use this

- Connecting an MCP Postgres server to Supabase, Neon, RDS, or any managed Postgres.
- The error mentions SSL, TLS, or encryption being required.

## When NOT to use this

- Local dev Postgres (Docker, Homebrew). Forcing SSL there causes the opposite error. Use `sslmode=disable` for local dev if needed.
- The error is a certificate verification failure (self-signed certificate). That needs the CA cert or a different sslmode, not just `require`.

## Compatibility

- All MCP Postgres servers that pass the URL to node-postgres/pg: @modelcontextprotocol/server-postgres, yawlabs/postgres-mcp, Tabulus, pgedge-postgres-mcp.
- Supabase, Neon, AWS RDS, Google Cloud SQL, Azure Database for PostgreSQL.

## Why it happens

Managed Postgres fleets terminate plain connections as a security policy. The `pg` driver defaults to opportunistic SSL (`prefer`), which is not enough for providers that mandate it. `sslmode=require` tells the driver to always negotiate TLS, which is what the provider expects.

## Edge cases

- Supabase pooler URLs (port 6543) also need `sslmode=require`.
- If you get a certificate error after adding it, your provider uses a custom CA. Either supply the CA (`sslrootcert`) or check the provider docs for their recommended sslmode.
- Some servers read the URL once at startup. A client restart is required, not just a new chat.