Browse docs · Guides
Get started
Concepts
Guides
Security
Reference
Docs / Guides
Postgres
Run read-only queries for AI agents through temporary Postgres roles that expire automatically, with no database password in the agent.
For each query the broker creates a temporary login role that inherits a read-only base role and expires on its own, runs the query as that role, and returns the rows.
Action
| Action | Resource | Parameters |
|---|---|---|
DB_READ | database name | query: a single SELECT or WITH statement |
Anything else, including multiple statements, is refused before it reaches the database.
Setup
- Create a base role with only the read access agents need:
CREATE ROLE pastkeys_readonly NOLOGIN; GRANT CONNECT ON DATABASE analytics TO pastkeys_readonly; GRANT USAGE ON SCHEMA public TO pastkeys_readonly; GRANT SELECT ON ALL TABLES IN SCHEMA public TO pastkeys_readonly;
- Seal an admin DSN that can create roles and store it as the
postgrescredential:postgres://admin:[email protected]:5432/postgres
- Optionally set
POSTGRES_READ_ROLEif your base role has another name.
Lifetime and cleanup
Each role is VALID UNTIL 15 minutes after creation by default (set per rule with credential_ttl). A background reaper drops expired role objects; tune it with POSTGRES_REAP_INTERVAL.