Postgres MCP Pro: slow-query hunting and index advice
More than a SQL pipe to Postgres: agents run health checks, read EXPLAIN plans, simulate hypothetical indexes and get index advice, with a read-only mode.
Project and installation docs
View projecthttps://github.com/crystaldba/postgres-mcp
When AI-generated ORM code runs slowly, the cause is usually a missing index or a badly shaped query, and an agent reading only the code can’t see it. Postgres MCP Pro hands the agent the database’s own evidence: which queries cost the most, what their plans look like, and how a plan changes with a new index. It’s built by the Crystal DBA team and had about 3.4k stars as of 2026-10-06.
What it does
- Health checks:
analyze_db_healthcovers index health (duplicate, unused, invalid), connections, buffer cache hit rates, vacuum, sequence limits and replication lag. - Slow queries:
get_top_querieslists the most expensive SQL frompg_stat_statements. - Index tuning:
analyze_workload_indexesrecommends indexes for the whole workload,analyze_query_indexesfor up to 10 given queries, andexplain_querycan include hypothetical indexes to preview the new plan. - Schema and execution:
list_schemas,list_objectsandget_object_detailsread structure, andexecute_sqlruns statements.
Who it’s for
- Developers in Cursor or Claude Code who want the agent to fix slow queries and indexes while it’s in the code.
- Small teams without a DBA who need a regular Postgres checkup.
Setup
Needs a connection URI and Docker or Python 3.12+. Index tuning needs the pg_stat_statements and hypopg extensions. With uvx:
{
"mcpServers": {
"postgres": {
"command": "uvx",
"args": ["postgres-mcp", "--access-mode=unrestricted"],
"env": {
"DATABASE_URI": "postgresql://username:password@localhost:5432/dbname"
}
}
}
}
Our take
Plenty of Postgres servers run SQL; this one brings a DBA’s toolkit. Index advice comes from an algorithm that searches candidate index sets, checked with hypopg simulation, not from the model’s hunch. Access has two levels: unrestricted reads and writes and suits dev databases, while restricted is read-only with a time limit and parses SQL to reject COMMIT or ROLLBACK tricks that escape the read-only transaction. Use it for anything in production. The authors admit unsafe stored-procedure languages could still bypass that guard, so a read-only database role remains the safest bet. The last commit was in August 2026, so updates aren’t frequent. Licensed MIT.