Configure a Postgres role to authenticate agents with the MCP endpoint and to define what each agent may list and call. The MCP endpoint authenticates every agent as a Postgres login role, so provisioning an agent is ordinary Postgres administration: create a role with a password, allow it in pg_hba.conf, and grant it access to the profile roles and tools it needs. A profile role is an ordinary NOLOGIN Postgres role that holds privileges — group them by function (read-only, read-write, and so on) and grant them to agent roles instead of granting privileges directly.
Granting the role what it needs
Give it
LOGINand a password. The agent presents these in the HTTP Basic header on every call, and the endpoint opens a Postgres connection with them.CREATE ROLE <agent_role> LOGIN PASSWORD '<password>';
Add a matching
localline inpg_hba.conf. The endpoint connects over the server's Unix socket, solocallines apply (see How it works for the TCP fallback). Use a password method such asscram-sha-256, nevertrust.local all <agent_role> scram-sha-256
Grant membership in
aidb_users, which providesEXECUTEonaidb.get_mcp_tools()andaidb.run_tool(). Without it,tools/listfails with a permission error.GRANT aidb_users TO <agent_role>;
Grant the objects its tools touch. A tool runs as the agent, so it needs
USAGEon the schema and the table privileges its tools use.GRANT USAGE ON SCHEMA <schema> TO <agent_role>; GRANT SELECT ON <schema>.<table> TO <agent_role>;
Keep the agent role itself free of direct privileges and grant it profile roles instead. Revoking a profile role from an agent takes effect on the agent's next call, since every call opens a fresh connection.
See Provisioning example for a worked example that creates an agent role and profile roles together.
Revoking an agent
Revoke with ordinary role changes:
REVOKE <profile_role> FROM <agent_role>; -- narrows what the agent can do, takes effect on its next call ALTER ROLE <agent_role> NOLOGIN; -- the agent can't connect at all DROP ROLE <agent_role>; -- after reassigning or dropping anything the role owns
See Provisioning example for this applied to a specific agent.