Reported issues for Neon
Pod holds 22 of 33 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.
Back to Neon.
Most discussed
ChatGPT Neon connector broken after snake_case MCP migration in PR #324
After the recent snake_case migration in PR #324, the Neon integration currently exposed inside ChatGPT appears to be incompatible with the hosted Neon MCP server.
In ChatGPT, the Neon run_sql tool schema currently expects camelCase arguments such as:
projectId databaseName
However, the hosted Neon MCP server now expects:
project_id database_name
Calling the tool from ChatGPT with the schema ChatGPT exposes results in:
MCP error -32602: Input validation error
Required: project_id…
Read the thread · 2026-08-29 · closed · external user · 7 comments
Read only config for MCP
I wanna expose this to my non-tech colleagues; And if one of them types delete project.. well yeah need I say more..
Would love to have 'read only' permissions/setup.
Read the thread · 2025-06-11 · closed · external user · 6 comments
Bug: Only Seeing Read-Only scopes on https://mcp.neon.tech/api/authorize
Steps to reproduce
Running Neon MCP Authentication through Claude Code /mcp
Expected result
Full-access, write scopes available. This is the behavior I was getting up until today
Actual result
Read-only scopes show up for me only
Environment
i've tried with both
"neon": {
"type": "http",
"url": "https://mcp.neon.tech/mcp"
}
```…
[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/179) · 2026-01-16 · open · external user · 5 comments
### Project-scoped MCP exposes incompatible run_sql schema requiring project_id
Neon MCP tool-schema mismatch for project-scoped authentication.
The advertised run_sql JSON Schema requires:
required: ["sql", "project_id"]
Calling without project_id is blocked client-side:
'project_id' is a required property
Calling with project_id reaches Neon MCP but fails:
MCP error -32602
Unrecognized key(s): 'project_id'
Therefore no valid argument object can pass both the advertised client schema
and the actual project-scoped MCP runtime validation.
Related symptom:
list_projects…
[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/359) · 2026-09-19 · open · external user · 4 comments
### bug: revalidation spam
I'm using the mcp with Claude via the claue_desktop_config.json, which VS-code automatically taps into.
It seems that at random intervals (Usually around every five minutes, possibly), VS Code tries to re-auth with Neon. It opens up four new tabs in my browser.
It's especially frustrating if I walk away from my computer for a bit. I'll come back to 50 tabs opened.
<img width="2174" height="1938" alt="Image"…
[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/81) · 2025-07-05 · closed · external user · 3 comments
### State default organization id
Hi, I have a personal Neon account as well as being part of an organization within our company. Is it possible today to have the MCP server use by default a certain org id? Right now I need to specify the agent to target a particular Neon organization, but this is a very stable value. I think it would be better to just have it be a default that can be overriden by the agent. Is this possible today?
[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/23) · 2025-03-03 · closed · external user · 3 comments
### Local MCP Server fails with 400 Bad Request when Organization API key is used
## Description
When running the local MCP server with an **Organization API key** (not a Personal API key), the server fails with a `400 Bad Request` error.
## Steps to Reproduce
1. Create an Organization API key in Neon Console (Settings → API Keys within an organization)
2. Run the local MCP server:
```bash
npx -y @neondatabase/mcp-server-neon start <ORG_API_KEY>
- Server crashes with
AxiosError: Request failed with status code 400
Expected Behavior
Server should start…
Read the thread · 2026-01-25 · closed · external user · 2 comments
MCP keeps disconnecting
I have the MCP server added to Cursor and it does work briefly but keeps disconnecting after a minute or two. Sometimes I switch it back on and Cursor is still making an execution plan before it switches off again.
Re-authorisation seems to be required once a day or so, I'm not talking about that. I'm talking about just switching off.
Read the thread · 2025-08-13 · closed · external user · 2 comments
Most recent
Project-scoped OAuth: metadata tools return HTTP 404 authorization internal error for a Vercel-managed project
Summary
The official hosted Neon MCP server completes OAuth successfully and exposes its tool catalog in Codex, but read-only metadata calls against an existing Vercel-managed project consistently fail with:
The request could not be authorized due to an internal error
[HTTP 404] The request could not be authorized due to an internal error
The same project and its test branch are accessible through the authenticated Neon Console. We have not established the root cause.
##…
Read the thread · 2026-09-26 · open · external user · 0 comments
Project-scoped OAuth in ChatGPT strips project_id from tool schema but backend still requires it
Summary
When using the hosted Neon MCP integration in ChatGPT with OAuth access scoped to a single Neon project, project-scoped tools are unusable.
The tool schemas exposed to ChatGPT correctly omit project_id, but calls fail on the Neon MCP side because project_id is still required by backend validation.
This appears to be a mismatch between the project-scoped OAuth context and the runtime tool handler.
Environment
- Client: ChatGPT (official Neon plugin / hosted MCP)
- Date…
Read the thread · 2026-09-24 · open · external user · 1 comment
Tool input schemas use strict validation, rejecting client-injected keys (breaks agent platforms)
Summary
The hosted Neon MCP server (https://mcp.neon.tech/mcp) validates tool inputs with strict object schemas. Any key not declared in a tool's inputSchema causes the call to fail validation before the tool executes. This breaks agent platforms that inject their own context keys into tool arguments — a common pattern in practice.
Request: use .strip() (or .passthrough()) instead of .strict() for tool input schemas, so unknown keys are ignored rather than fatal.
What we're seeing
Calls to…
Read the thread · 2026-09-11 · open · external user · 0 comments
Allow run_sql / run_sql_transaction to execute as a specified PostgreSQL role without exposing credentials
Allow run_sql / run_sql_transaction to execute as a specified PostgreSQL role without exposing credentials Summary Add optional role_name and compute_id parameters to the Neon MCP run_sql and run_sql_transaction tools.
The hosted MCP server already resolves PostgreSQL connection URIs internally before executing SQL, and the underlying connection-string resolver already supports selecting a PostgreSQL role and compute endpoint.
The requested change is to expose those selectors to the…
Read the thread · 2026-09-08 · open · external user · 1 comment
ChatGPT Neon plugin run_sql schema mismatch: projectId passed but MCP expects project_id
Bug description
The Neon Postgres plugin in ChatGPT can successfully authenticate, list organizations, list projects, and identify the correct Neon project, but database-level tools such as run_sql fail before SQL execution because of an apparent parameter-schema mismatch.
Environment
- Client: ChatGPT
- Integration: Neon Postgres plugin / Neon MCP
- Authentication: OAuth
- Project: PostgreSQL 17
- Neon MCP endpoint/integration is otherwise authenticated and working
- Plugin was…
Read the thread · 2026-09-02 · open · external user · 0 comments
Add --access-mode flag to restrict destructive tools (read-only / write / full)
Problem
Today the server exposes the full set of tools (including delete_project, delete_branch, run_sql writes, reset_from_parent, etc.) whenever it's started with a Neon API key. There's no way for the operator to opt into a less-privileged mode.
This is awkward for editor/agent integrations (Claude Desktop, Zed, Cursor, etc.) where:
- Users often want to give an agent broad read access to inspect projects, branches, schemas, slow queries, etc., without granting the ability to…
Read the thread · 2026-05-28 · closed · external user · 0 comments
create_branch MCP tool: schema is incomplete and silently drops unknown params; no way to set expires_at
Summary
The hosted Neon MCP server at mcp.neon.tech exposes create_branch with a JSON schema declaring only branchName + projectId and additionalProperties: false. In practice the server:
- Accepts an undeclared
parentId(camelCase) parameter and honors it. - Silently drops several other undeclared parameters without erroring:
parent_id,expiresAt,expires_at,expiration,autoDeleteAt. - Has no working way to set a branch expiration via MCP — the underlying REST…
Read the thread · 2026-05-22 · closed · external user · 0 comments
Support run_sql and data-plane tools when project password storage is disabled
Summary
When a Neon project has "Store role passwords" disabled, all MCP tools that need a Postgres connection (run_sql, run_sql_transaction, get_database_tables, describe_table_schema, get_connection_string, etc.) fail with HTTP 412 from the Neon control plane:
storing passwords is not enabled for the project [Precondition Failed] Request failed with status code 412
Control-plane-only tools like describe_project still work fine over OAuth — so the MCP itself is…
Read the thread · 2026-05-18 · open · 0 comments
Exposing inputSchema + read-only metadata in /api/list-tools
Hi @vadim2404 (cc @pffigueiredo @Shridhad)
I was looking at the public /api/list-tools response while exploring how external tools
could integrate with MCP servers. Three observations that might be useful — small
contract clarifications, not bugs.
1. No inputSchema per tool in the response
The 6 tools (run_sql, run_sql_transaction, explain_sql_statement, list_slow_queries, search, fetch) come back with name, title, scope, readOnlySafe, and description, but no…
Read the thread · 2026-05-12 · closed · external user · 1 comment
Stdio package deprecation breaks headless/gateway deployments — need API key auth for hosted MCP
Problem
The deprecation of @neondatabase/mcp-server-neon has broken headless and gateway-based MCP deployments with no migration path.
What worked before
We run an MCP gateway that spawns MCP servers as stdio subprocesses and proxies tool calls through a single authenticated HTTP endpoint. This provides centralised access control, tool filtering, and token-based routing for 17+ users. The old stdio package worked perfectly:
{
"command": "npx",
"args": ["-y",…
[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/214) · 2026-04-07 · open · external user · 1 comment
### [Security Audit] AgentWard Permission Analysis — Neon Postgres MCP Server
Hey Neon team — I reviewed mcp-server-neon and wanted to share a few security observations. I see you've already put thought into this (tool annotations, read-only mode, migration safety workflow) — these findings are about gaps in the current implementation.
## TL;DR
`run_sql` accepts arbitrary SQL with no server-side statement validation. Destructive project operations execute immediately. Connection strings with embedded passwords flow into the LLM context.
## Findings
### 1.…
[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/207) · 2026-03-11 · closed · external user · 1 comment
### setup-neon-auth prompt 404: references deleted GitHub file
## Bug Description
The `setup-neon-auth` prompt fails with:
McpError: MCP error -32603: Failed to fetch GitHub content: 404 Not Found
## Root Cause
The prompt in `landing/mcp-src/prompts.ts` calls `fetchRawGithubContent()` with the path:
/neondatabase-labs/ai-rules/main/mcp-prompts/neon-auth-setup.md
This file was **deleted on 2025-12-16** (commit `7c983fdf` in `neondatabase-labs/ai-rules`) and moved to:
/neondatabase-labs/ai-rules/main/references/neon-auth-setup.md
[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/205) · 2026-03-06 · closed · external user · 1 comment
### prepare_database_migration fails on dollar-quoted strings ($$)
## Bug
`prepare_database_migration` fails when the migration SQL contains `$$` dollar-quoted strings (e.g., PL/pgSQL trigger functions).
## Error
NeonDbError: unterminated dollar-quoted string at or near "$$ BEGIN NEW.updated_at = NOW()"
## Cause
`splitSqlStatements` in `landing/mcp-src/tools/utils.ts` does a naive `sql.split(';')`:
```typescript
export const splitSqlStatements = (sql: string) => {
return sql.split(';').filter(Boolean);
};
This has no awareness of SQL…
Read the thread · 2026-02-24 · open · external user · 1 comment
describe_branch leaves show_db_tree function in user's database
Description
The describe_branch tool creates a public.show_db_tree() function in the user's database via DESCRIBE_DATABASE_STATEMENTS in landing/mcp-src/tools/utils.ts, but never cleans it up afterward. The function persists in the database indefinitely.
Impact
For projects that use schema introspection tools to generate types from the live database (e.g., Kanel), the leftover show_db_tree function gets picked up and generates…
Read the thread · 2026-02-12 · open · external user · 0 comments
The remaining reports are on the project's issue tracker.