Read-only PostgreSQL introspection for AI agents. 29 MCP tools for schema discovery, data exploration, query execution, and health monitoring. Pure pg_catalog, no extensions required.
Most Postgres MCP servers expose query and list_tables, and little else. Agents end up guessing column names, enum values, and join paths, burning several failed attempts before landing on working SQL.
pglens closes those gaps. The agent can check what values actually exist in a column, discover foreign-key relationships, preview sample data, and validate a query plan before running it.
column_valuesin particular: agents frequently writeWHERE status = 'active'when the real value is'Active'or'enabled'.column_valuesreturns the actual distinct values with counts, so the agent picks the right one instead of guessing.
AI agent (MCP client) ──► pglens ──► your PostgreSQL
Claude, etc. MCP server (read-only)
- Your MCP client (Claude Desktop, Claude Code, Zed, …) launches
pglensand connects over MCP. - pglens connects to PostgreSQL using standard libpq environment variables and opens a connection pool.
- The agent calls pglens tools to introspect the schema, sample data, run read-only queries, and inspect health, instead of guessing.
pglens opens read-only connections (default_transaction_read_only=on), quotes every identifier, and runs each statement under a timeout. It exposes no DDL tools. All introspection uses pg_catalog directly, so no PostgreSQL extensions are needed. See Safety.
| Tool | What it does |
|---|---|
database_info |
Server version, database name, current user, encoding, timezone, uptime, size, configured database aliases |
list_schemas |
Schemas with table and view counts |
list_tables |
Tables with row counts and descriptions |
list_views |
Views with their SQL definitions |
list_extensions |
Installed extensions and versions |
describe_table |
Columns, types, PKs, FKs (both directions), indexes, check constraints |
find_join_path |
Multi-hop join paths between two tables via foreign keys |
list_indexes |
All indexes across a schema with types, sizes, validity, and usage stats |
list_functions |
Stored functions/procedures with source code |
list_triggers |
Triggers on a table with definitions and status |
list_policies |
Row-level security policies on a table |
| Tool | What it does |
|---|---|
sample_rows |
Random rows from a table |
column_values |
Distinct values with frequency counts |
column_stats |
Min, max, null fraction, distinct count, common values |
search_data |
Case-insensitive search across text columns |
search_columns |
Find columns by name across all tables |
search_enum_values |
Enum types and their allowed values |
| Tool | What it does |
|---|---|
explain_query |
Query plan without execution |
query |
Read-only SQL with limit/offset pagination (default 500 rows) |
| Tool | What it does |
|---|---|
slow_queries |
Top statements by total execution time (needs pg_stat_statements) |
table_health |
Index hit rates, dead tuples, vacuum timestamps, wraparound risk |
table_sizes |
Disk usage per table, ranked by size |
unused_indexes |
Indexes that are never scanned, including invalid ones |
active_queries |
Currently running sessions and their queries |
blocking_locks |
Lock wait chains (who blocks whom) |
replication_status |
Standby lag and replication slots (inactive slots retain WAL) |
sequence_health |
Sequences approaching exhaustion |
matview_status |
Materialized view freshness and refresh eligibility |
All tools work on a stock PostgreSQL with no extensions. The one exception is slow_queries, which reads pg_stat_statements when it is installed and returns install instructions when it is not.
| Tool | What it does |
|---|---|
object_dependencies |
What depends on a given object (views, functions, constraints) |
There is also a query_guide prompt that describes a reasonable workflow for using these tools together.
uvx runs pglens straight from PyPI with no install step, always fetching the latest published version:
uvx pglensThere is nothing to upgrade; each launch resolves the newest release. Pin a version when you need: uvx pglens@1.1.0.
pip install pglens # install
pip install --upgrade pglens # upgrade laterRequirements: Python 3.11+ and a reachable PostgreSQL server.
pglens needs two things: PostgreSQL connection details (via libpq env vars) and an entry in your MCP client. A minimal Claude Desktop config:
{
"mcpServers": {
"pglens": {
"command": "uvx",
"args": ["pglens"],
"env": {
"PGHOST": "localhost",
"PGPORT": "5432",
"PGUSER": "myuser",
"PGPASSWORD": "mypassword",
"PGDATABASE": "mydb"
}
}
}
}pglens reads standard PostgreSQL environment variables (libpq). Connection strings (DSNs) are not supported. Credentials live entirely in PG* env vars, so they never appear in arguments or command lines.
| Variable | Required | Purpose |
|---|---|---|
PGHOST |
yes | Postgres host |
PGPORT |
no (default 5432) | Postgres port |
PGUSER |
yes | Username |
PGPASSWORD |
yes (or PGPASSFILE) |
Password |
PGDATABASE |
recommended | Primary dbname; also the default alias when a tool is called without database= |
PGSSLMODE |
no | disable, prefer, require, verify-ca, verify-full |
PGSERVICE, PGPASSFILE, PGAPPNAME, … |
no | Other libpq env vars, honored by asyncpg automatically |
PGLENS_DATABASES |
no | Comma-separated extra dbnames on the same host (see Multiple databases) |
PGLENS_STATEMENT_TIMEOUT |
no (default 60) | Per-statement timeout in seconds; 0 disables it |
pglens reads no connection-string env vars. Configuration goes through libpq env vars only.
To run pglens directly from a shell (e.g. for testing):
export PGHOST=localhost
export PGUSER=myuser
export PGPASSWORD=mypassword
export PGDATABASE=mydb
uvx pglensCheck the installed version with pglens --version.
If you installed pglens with pip instead of using uvx, replace "command": "uvx", "args": ["pglens"] with "command": "pglens" in any of the configs below.
{
"mcpServers": {
"pglens": {
"command": "uvx",
"args": ["pglens"],
"env": {
"PGHOST": "localhost",
"PGPORT": "5432",
"PGUSER": "myuser",
"PGPASSWORD": "mypassword",
"PGDATABASE": "mydb"
}
}
}
}{
"mcpServers": {
"pglens": {
"command": "uvx",
"args": ["pglens"],
"env": {
"PGHOST": "localhost",
"PGDATABASE": "mydb"
}
}
}
}{
"context_servers": {
"pglens": {
"command": {
"path": "uvx",
"args": ["pglens"]
}
}
}
}Every tool accepts an optional database argument to target an alternate connection. This is useful for Postgres setups that expose system metrics in a separate database. Azure Database for PostgreSQL Flexible Server, for example, keeps server metrics in azure_sys.
PGDATABASE is the primary alias and the default target when a tool is called without database=. List any additional dbnames on the same host in PGLENS_DATABASES; each becomes its own alias with its own pool. Host, user, password, and TLS mode come from the standard libpq env vars and are shared across every pool:
{
"mcpServers": {
"pglens": {
"command": "uvx",
"args": ["pglens"],
"env": {
"PGHOST": "myhost.postgres.database.azure.com",
"PGPORT": "5432",
"PGUSER": "admin",
"PGPASSWORD": "...",
"PGSSLMODE": "require",
"PGDATABASE": "app",
"PGLENS_DATABASES": "azure_sys"
}
}
}
}- Names are used verbatim as Postgres dbnames, which are case-sensitive (e.g.
PGDATABASE=MyAppconnects toMyApp, notmyapp). - If
PGDATABASEis unset butPGLENS_DATABASESis set, the first listed alias becomes the default. - If both are unset, a single
defaultalias relies on libpq's own default behavior. - If the databases you need live on different hosts or require different credentials, run a separate
pglensserver per host with its ownPG*env block.
Discover what is configured via database_info (the available_databases key), then pass the alias as the database argument:
database_info() -> {..., "available_databases": ["app", "azure_sys"]}
table_sizes(schema="public", database="azure_sys")
query(sql="SELECT * FROM query_store.qs_view LIMIT 10", database="azure_sys")
Omit database (or pass None) to use PGDATABASE (the primary alias).
By default the server uses stdio transport (what every MCP client config above expects). To run as an HTTP server for remote use:
uvx pglens --transport streamable-http| Flag | Choices | Default | Description |
|---|---|---|---|
--transport |
stdio, streamable-http |
stdio |
MCP transport type |
- Every connection sets
default_transaction_read_only=on, so the server itself refuses writes. User-influenced queries also run inside explicitreadonly=Truetransactions. - pglens parses SQL for
queryandexplain_querywith PostgreSQL's own parser (via pglast) and accepts only a single SELECT statement. It rejectsSELECT INTO, data-modifying CTEs likeWITH x AS (DELETE ...), and multi-statement input before anything reaches the database. - The same validation rejects parameter placeholders (
$1,$2). Inline literal values instead. - A statement timeout (
PGLENS_STATEMENT_TIMEOUT, default 60 s) bounds every query, so a runawayCOUNT(*)orEXPLAIN ANALYZEcannot hog the server. - pglens always quotes table and column identifiers; internal values go through bind parameters.
- Connections set
application_name = 'pglens', which makes them easy to spot inpg_stat_activity. - pglens exposes no DDL tools.
adapters/tools/*.py (MCP tool definitions, organized by category)
│
adapters/mcp_adapter.py (MCPServer, lifespan, pool management)
│
adapters/asyncpg_adapter.py (SQL queries, asyncpg pool)
│
PostgreSQL
AsyncpgDatabase holds the asyncpg pool and all query methods. Tool modules in adapters/tools/ are thin wrappers that register MCP tools via decorators and delegate to it. All queries use pure pg_catalog introspection, so no PostgreSQL extensions are required.
Adding a tool:
- Add a method to
AsyncpgDatabaseinadapters/asyncpg_adapter.py. - Add a
@mcp.tool()function in the appropriateadapters/tools/*.pymodule.
MIT