Neon MCP Server lets AI agents manage Neon Postgres databases directly, including creating and branching databases, running SQL queries, managing schemas, inspecting database structure, and working with projects and branches.
Encrypted at rest, isolated from the model
Resolved from an AES-256-GCM vault at the moment of the call and attached to the request — the model never sees the secrets.
Try asking
List all organizations the current user belongs to. Supports optional `search` parameter to filter by name or ID.
Execute one SQL statement on a Neon database. If a prior step created a temporary branch, pass that branch_id. NEVER run destructive SQL autonomously; always ask the user first.
Execute multiple SQL statements as one transaction. If a prior step created a temporary branch, pass that branch_id. NEVER run destructive SQL autonomously; always ask the user first.
Get column definitions, data types, and constraints for a specific table. Do not use when you need all tables in a database (use `get_database_tables` instead).
List all tables in a Neon database. Do not use when you need column-level detail for a specific table (use `describe_table_schema` instead).
Apply a schema change on a temporary branch and return a migration_id. Test with run_sql on that branch, ask the user, then complete_database_migration — even if they reject, so the temporary branch is deleted. Pass every field from the prepare response.
Apply or discard a prepared migration and delete the temporary branch. NEVER run autonomously; always ask the user first. Pass migration_id, migration_sql, database_name, project_id, temporary_branch_id, and parent_branch_id from prepare_database_migration. Set apply_changes false to discard; omitting it applies the migration.
Get a tree view of all objects in a branch, including databases, schemas, tables, views, and functions. Do not use when you only need table names (use `get_database_tables` instead) or column detail (use `describe_table_schema` instead).
Get a PostgreSQL connection string for a Neon database. The branch must have a compute endpoint. `create_project` and `create_branch` do not return one; call this after they succeed. Branch, compute, and database are optional and resolved automatically if not specified; `project_id` follows the connection scope. Requires write access: the connection string carries a privileged role password, so it is unavailable in read-only mode. A read-only caller who needs a DATABASE_URL must copy it from https://console.neon.tech manually.
Read Neon Auth config for a branch with OAuth and SMTP secrets redacted as "***redacted***". Requires provision_neon_auth first.
Generate the execution plan for a SQL statement. When `analyze` is true, PostgreSQL executes the statement and any side effects. Use `analyze: false` to inspect a statement without executing it. Never analyze potentially destructive SQL autonomously. Do not use when you need query results (use `run_sql` instead).
Analyze a slow query on a temporary branch and return a tuning_id. Apply suggested SQL with run_sql on that branch, re-run explain_sql_statement there, then complete_query_tuning with the tuning_id (not the branch id) — apply_changes true if they accept, omit it or pass false if they reject, so the temporary branch is deleted. Do not use prepare_database_migration.
Apply or discard query-tuning changes and delete the temporary branch. NEVER run autonomously. Before calling, apply suggested SQL with run_sql on the temporary branch and re-run explain_sql_statement. Pass the tuning_id from prepare_query_tuning, not the branch id, plus temporary_branch_id. Set apply_changes true to apply; omitting it discards. Call this even when the user rejects the changes. Do not use prepare_database_migration.
List queries from pg_stat_statements by execution time, slowest first. For sizes, indexes, locks, cache, bloat, or replication use inspect_database.
Run one read-only neon inspect db check (pick `check` from the input schema). Not for arbitrary SQL (`run_sql`), one statement's plan (`explain_sql_statement`), or applying indexes (`prepare_query_tuning`). Omit `database_name` to cover every database; some checks are compute-wide. If a check needs an extension, the tool names `CREATE EXTENSION`; ask before running it.
Search across all organizations, projects, and branches by keyword. Returns matching items with id, title, and URL. Query must be at least 3 characters. Do not use when you need all projects (use `list_projects` instead).
Fetch detailed information about a specific organization, project, or branch using the ID returned by the `search` tool.
List Neon documentation page slugs from neon.com/docs/llms.txt. Call this before get_doc_resource; do not guess slugs.
Fetch one Neon documentation page as markdown. Pass a slug from list_docs_resources (for example docs/guides/prisma.md).
Send anonymous feedback about Neon or this MCP server to the Neon team. Only call this when the user asks to give feedback. Sends only the feedback text, not account, project, or connection details.
List Neon projects you own. Returns every page. Pass limit to cap how many. There is no `cursor` argument. `org_id` is optional: organization API keys use their organization; personal API keys auto-select when unambiguous and otherwise return the IDs to choose from.
Retrieves the project record (settings, compute, usage). Call `list_branches` for branches.
Creates a Neon project and waits until the default compute is ready. `org_id` is optional: organization API keys use their organization; personal API keys auto-select when unambiguous and otherwise return the IDs to choose from. Does not return a connection string; call `get_connection_string` with the project id.
Updates the specified project.
Delete a Neon project and all its data. NEVER run autonomously; always ask the user first. For a single branch, use `delete_branch`.
Recovers a deleted project within the 7-day deletion recovery period.
Retrieves details about users who have access to the project, including the permission `id`, the granted-to email address, and the date project access was granted.
Lists organization members and their per-project roles for an org-owned project. Returns every page. Pass limit to cap how many.
Lists Neon regions available to the authenticated account.
Lists operations for a project. Omitting `limit` returns every remaining page. There is no `cursor` argument.
Retrieves details for the specified operation.
Retrieves a list of branches for the specified project. Returns every page. Pass limit to cap how many.
Retrieves information about the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Creates a branch with a read-write compute and waits until it is ready. Pass `no_compute: true` to skip the endpoint. Does not return a connection string; call `get_connection_string` with the project and branch id. Copies the parent at HEAD; point-in-time restore is `restore_snapshot`.
Updates the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Delete a branch and all its data. NEVER run autonomously; always ask the user first. For the whole project, use `delete_project`. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Resolve the project's default branch by the default flag, not by name.
Sets the specified branch as the project's default branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Reset a branch to its parent's current HEAD. Discards every change the branch has written since it diverged. NEVER run autonomously; always ask the user first. `preserve_under_name` saves the current state first and is required when the branch has children; those children move to the new branch. Point-in-time restore is `restore_snapshot`. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Compare one database's SQL schema on a branch to another. `database_name` is required. Omit `base_branch_id` to compare against the parent; it is a branch id (`br-...`), not a name. Pass `lsn`, `timestamp`, `base_lsn`, or `base_timestamp` only for a point-in-time comparison. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Finalize a branch created with `restore_snapshot` and `finalize: false`: reassign computes (this restarts them) and swap names so it replaces the original branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Retrieves a list of Postgres roles from the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Retrieves details about the specified role. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Creates a Postgres role in the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Deletes the specified Postgres role from the branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Resets the password for the specified Postgres role. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Retrieves a list of databases for the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Retrieves information about the specified database. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Creates a database in the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Updates the specified database in the branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Deletes the specified database from the branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Retrieves a list of compute endpoints for the specified project.
Retrieves a list of compute endpoints for the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Retrieves information about the specified compute endpoint.
Creates a compute endpoint on a branch. Does not return a connection string; call `get_connection_string`.
Updates the specified compute endpoint.
Deletes the specified compute endpoint.
Starts a compute endpoint.
Suspends the specified compute endpoint.
Restarts the specified compute endpoint by immediately suspending it and then starting it again.
Lists the snapshots for the specified project.
Returns the backup schedule for the specified branch, including the configured snapshot frequencies. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Replace a branch's automatic snapshot schedule. Frequency must be daily, weekly, or monthly. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Creates a snapshot from the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Updates the specified snapshot.
Deletes the specified snapshot.
Restore a snapshot onto a new or existing branch. The call waits until the branch is ready. Pass `target_branch_id` to restore onto an existing branch; omit it to create one. Pass `finalize: false` then call `finalize_branch_restore` to swap names later.
Retrieves the Neon Auth integration details for the specified branch, including the auth provider type and integration status. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Enables Neon Auth for the specified branch by connecting it to an authentication provider. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Disables the Neon Auth integration for the specified branch, removing the connection to the authentication provider. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Updates the auth configuration for the branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Lists the OAuth providers configured for the specified branch's Neon Auth integration. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Adds an OAuth provider configuration to the specified branch's Neon Auth integration. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Updates an OAuth provider for the specified project. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Deletes an OAuth provider from the specified project. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Lists the trusted domains in the redirect URI whitelist for the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Adds a domain to the redirect URI whitelist for the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Removes a domain from the redirect URI whitelist for the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Creates a new user in the Neon Auth user directory for the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Deletes the specified user from the Neon Auth user directory for the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Updates the role of a user in the Neon Auth user directory for the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Retrieves the Neon Data API configuration for the specified branch, including endpoint URL, enabled state, and database settings. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Creates a new instance of Neon Data API in the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Updates the Neon Data API configuration for the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Deletes the Neon Data API for the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Returns logs for a branch. Pass `limit` to cap how many. There is no `cursor` argument. Filters combine with AND. Pass `logql` instead of structured filters, not with them. Give the window as `since` or `start_time`, not both; default is the previous hour, max seven days; `end_time` is exclusive. Private beta; a branch without logs access returns HTTP 404 with reason "telemetry_not_enabled". branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Lists the low-cardinality log fields observed on this branch. Call `list_log_field_values` with `field_name` to list distinct values. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Lists distinct values for a low-cardinality log field. Call `list_log_fields` first for `field_name`; a field the branch has never emitted returns `unknown_field`. Pass `since` or `start_time`, not both; default is the previous six hours, max seven days. Private beta. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Returns the AI Gateway endpoint host for the specified branch, used to render code-snippet base URLs. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Lists functions on the specified branch. Returns every page. Pass limit to cap how many. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Returns the function identified by its slug. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Updates the function's mutable metadata — currently only the display `name`. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Deletes the function identified by its slug. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Creates a deployment for the function. Supply at least one of `zip`, `environment`, or `runtime`; omitted fields inherit the latest version. The first deployment must include `zip`. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Lists all custom domains registered on the branch, across every target entity. Returns every page. Pass limit to cap how many. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Registers a hostname on the branch and routes it to a function. Pass `entity_type: "function"` and `entity_id` as the slug from `list_functions`. Point a CNAME at the returned `cname_target`. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Removes a custom domain registered on the branch and stops routing it. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Lists the complete project-bounded set of triggers visible on the branch, ordered by `trigger_id`. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Returns the trigger visible on the branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Creates a trigger for a Function visible on the branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Applies a partial update. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Deletes a branch-local trigger or writes a branch-local tombstone for an inherited trigger so it does not reappear. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Returns metadata for customer-issued credentials on the branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Issues a new scoped service credential anchored to the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Soft-deletes the credential. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Replaces the secret material on an existing scoped credential in place. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Returns whether branchable object storage is usable for the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Lists branchable object storage buckets visible on the specified branch, including those inherited from ancestor branches. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Creates a new branchable object storage bucket on the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Deletes the named bucket from the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Lists objects visible in the named bucket on the specified branch, including those inherited from ancestor branches. Returns every page. Pass limit to cap how many. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Deletes the named object from the bucket on the specified branch. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Soft-deletes every object on the specified branch whose key starts with `prefix`, in a single call. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
Returns a presigned URL that transfers bytes directly to or from the object's bucket on the specified branch, without the caller ever handling S3 credentials. branch_id is a branch id (br-...), not a branch name. Call list_branches to resolve a name.
One endpoint, the same key, whichever client you use.
~/Library/Application Support/Claude/claude_desktop_config.json (Mac) · %APPDATA%\Claude\claude_desktop_config.json (Windows)
Replace API_KEY with your own key.
Already have an "mcpServers" section in your config? Just add the server entry inside it.
Discovery, routing, credentials, tool scoping and execution logs all happen at the gateway→connections stay ACTIVE with no work from you
Neon MCP runs through a gateway that holds the credentials, scopes the access and records every call.
Managed auth, hosted MCP servers, and every Gmail tool your agent needs.
Free to start.