Pod

Available as Markdown and JSON. Pod is also available over MCP.

Reported issues for Neon

Pod holds 22 of 33 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to Neon.

Most discussed

ChatGPT Neon connector broken after snake_case MCP migration in PR #324

After the recent snake_case migration in PR #324, the Neon integration currently exposed inside ChatGPT appears to be incompatible with the hosted Neon MCP server.

In ChatGPT, the Neon run_sql tool schema currently expects camelCase arguments such as:

projectId databaseName

However, the hosted Neon MCP server now expects:

project_id database_name

Calling the tool from ChatGPT with the schema ChatGPT exposes results in:

MCP error -32602: Input validation error

Required: project_id…

Read the thread · 2026-08-29 · closed · external user · 7 comments

Read only config for MCP

I wanna expose this to my non-tech colleagues; And if one of them types delete project.. well yeah need I say more..

Would love to have 'read only' permissions/setup.

Read the thread · 2025-06-11 · closed · external user · 6 comments

Bug: Only Seeing Read-Only scopes on https://mcp.neon.tech/api/authorize

Steps to reproduce

Running Neon MCP Authentication through Claude Code /mcp

Expected result

Full-access, write scopes available. This is the behavior I was getting up until today

Actual result

Read-only scopes show up for me only

Image

Environment

i've tried with both

"neon": {
      "type": "http",
      "url": "https://mcp.neon.tech/mcp"
    }
```…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/179) · 2026-01-16 · open · external user · 5 comments

### Project-scoped MCP exposes incompatible run_sql schema requiring project_id

Neon MCP tool-schema mismatch for project-scoped authentication.

The advertised run_sql JSON Schema requires:
required: ["sql", "project_id"]

Calling without project_id is blocked client-side:
'project_id' is a required property

Calling with project_id reaches Neon MCP but fails:
MCP error -32602
Unrecognized key(s): 'project_id'

Therefore no valid argument object can pass both the advertised client schema
and the actual project-scoped MCP runtime validation.

Related symptom:
list_projects…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/359) · 2026-09-19 · open · external user · 4 comments

### bug: revalidation spam

I'm using the mcp with Claude via the claue_desktop_config.json, which VS-code automatically taps into.

It seems that at random intervals (Usually around every five minutes, possibly), VS Code tries to re-auth with Neon. It opens up four new tabs in my browser.

It's especially frustrating if I walk away from my computer for a bit. I'll come back to 50 tabs opened.

<img width="2174" height="1938" alt="Image"…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/81) · 2025-07-05 · closed · external user · 3 comments

### State default organization id

Hi, I have a personal Neon account as well as being part of an organization within our company. Is it possible today to have the MCP server use by default a certain org id? Right now I need to specify the agent to target a particular Neon organization, but this is a very stable value. I think it would be better to just have it be a default that can be overriden by the agent. Is this possible today?

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/23) · 2025-03-03 · closed · external user · 3 comments

### Local MCP Server fails with 400 Bad Request when Organization API key is used

## Description

When running the local MCP server with an **Organization API key** (not a Personal API key), the server fails with a `400 Bad Request` error.

## Steps to Reproduce

1. Create an Organization API key in Neon Console (Settings → API Keys within an organization)
2. Run the local MCP server:
   ```bash
   npx -y @neondatabase/mcp-server-neon start <ORG_API_KEY>
  1. Server crashes with AxiosError: Request failed with status code 400

Expected Behavior

Server should start…

Read the thread · 2026-01-25 · closed · external user · 2 comments

MCP keeps disconnecting

I have the MCP server added to Cursor and it does work briefly but keeps disconnecting after a minute or two. Sometimes I switch it back on and Cursor is still making an execution plan before it switches off again.

Re-authorisation seems to be required once a day or so, I'm not talking about that. I'm talking about just switching off.

Read the thread · 2025-08-13 · closed · external user · 2 comments

Most recent

Project-scoped OAuth: metadata tools return HTTP 404 authorization internal error for a Vercel-managed project

Summary

The official hosted Neon MCP server completes OAuth successfully and exposes its tool catalog in Codex, but read-only metadata calls against an existing Vercel-managed project consistently fail with:

The request could not be authorized due to an internal error
[HTTP 404] The request could not be authorized due to an internal error

The same project and its test branch are accessible through the authenticated Neon Console. We have not established the root cause.

##…

Read the thread · 2026-09-26 · open · external user · 0 comments

Project-scoped OAuth in ChatGPT strips project_id from tool schema but backend still requires it

Summary

When using the hosted Neon MCP integration in ChatGPT with OAuth access scoped to a single Neon project, project-scoped tools are unusable.

The tool schemas exposed to ChatGPT correctly omit project_id, but calls fail on the Neon MCP side because project_id is still required by backend validation.

This appears to be a mismatch between the project-scoped OAuth context and the runtime tool handler.

Environment

Read the thread · 2026-09-24 · open · external user · 1 comment

Tool input schemas use strict validation, rejecting client-injected keys (breaks agent platforms)

Summary

The hosted Neon MCP server (https://mcp.neon.tech/mcp) validates tool inputs with strict object schemas. Any key not declared in a tool's inputSchema causes the call to fail validation before the tool executes. This breaks agent platforms that inject their own context keys into tool arguments — a common pattern in practice.

Request: use .strip() (or .passthrough()) instead of .strict() for tool input schemas, so unknown keys are ignored rather than fatal.

What we're seeing

Calls to…

Read the thread · 2026-09-11 · open · external user · 0 comments

Allow run_sql / run_sql_transaction to execute as a specified PostgreSQL role without exposing credentials

Allow run_sql / run_sql_transaction to execute as a specified PostgreSQL role without exposing credentials Summary Add optional role_name and compute_id parameters to the Neon MCP run_sql and run_sql_transaction tools.

The hosted MCP server already resolves PostgreSQL connection URIs internally before executing SQL, and the underlying connection-string resolver already supports selecting a PostgreSQL role and compute endpoint.

The requested change is to expose those selectors to the…

Read the thread · 2026-09-08 · open · external user · 1 comment

ChatGPT Neon plugin run_sql schema mismatch: projectId passed but MCP expects project_id

Bug description

The Neon Postgres plugin in ChatGPT can successfully authenticate, list organizations, list projects, and identify the correct Neon project, but database-level tools such as run_sql fail before SQL execution because of an apparent parameter-schema mismatch.

Environment

Read the thread · 2026-09-02 · open · external user · 0 comments

Add --access-mode flag to restrict destructive tools (read-only / write / full)

Problem

Today the server exposes the full set of tools (including delete_project, delete_branch, run_sql writes, reset_from_parent, etc.) whenever it's started with a Neon API key. There's no way for the operator to opt into a less-privileged mode.

This is awkward for editor/agent integrations (Claude Desktop, Zed, Cursor, etc.) where:

Read the thread · 2026-05-28 · closed · external user · 0 comments

create_branch MCP tool: schema is incomplete and silently drops unknown params; no way to set expires_at

Summary

The hosted Neon MCP server at mcp.neon.tech exposes create_branch with a JSON schema declaring only branchName + projectId and additionalProperties: false. In practice the server:

  1. Accepts an undeclared parentId (camelCase) parameter and honors it.
  2. Silently drops several other undeclared parameters without erroring: parent_id, expiresAt, expires_at, expiration, autoDeleteAt.
  3. Has no working way to set a branch expiration via MCP — the underlying REST…

Read the thread · 2026-05-22 · closed · external user · 0 comments

Support run_sql and data-plane tools when project password storage is disabled

Summary

When a Neon project has "Store role passwords" disabled, all MCP tools that need a Postgres connection (run_sql, run_sql_transaction, get_database_tables, describe_table_schema, get_connection_string, etc.) fail with HTTP 412 from the Neon control plane:

storing passwords is not enabled for the project [Precondition Failed] Request failed with status code 412

Control-plane-only tools like describe_project still work fine over OAuth — so the MCP itself is…

Read the thread · 2026-05-18 · open · 0 comments

Exposing inputSchema + read-only metadata in /api/list-tools

Hi @vadim2404 (cc @pffigueiredo @Shridhad)

I was looking at the public /api/list-tools response while exploring how external tools could integrate with MCP servers. Three observations that might be useful — small contract clarifications, not bugs.


1. No inputSchema per tool in the response

The 6 tools (run_sql, run_sql_transaction, explain_sql_statement, list_slow_queries, search, fetch) come back with name, title, scope, readOnlySafe, and description, but no…

Read the thread · 2026-05-12 · closed · external user · 1 comment

Stdio package deprecation breaks headless/gateway deployments — need API key auth for hosted MCP

Problem

The deprecation of @neondatabase/mcp-server-neon has broken headless and gateway-based MCP deployments with no migration path.

What worked before

We run an MCP gateway that spawns MCP servers as stdio subprocesses and proxies tool calls through a single authenticated HTTP endpoint. This provides centralised access control, tool filtering, and token-based routing for 17+ users. The old stdio package worked perfectly:

{
  "command": "npx",
  "args": ["-y",…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/214) · 2026-04-07 · open · external user · 1 comment

### [Security Audit] AgentWard Permission Analysis — Neon Postgres MCP Server

Hey Neon team — I reviewed mcp-server-neon and wanted to share a few security observations. I see you've already put thought into this (tool annotations, read-only mode, migration safety workflow) — these findings are about gaps in the current implementation.

## TL;DR

`run_sql` accepts arbitrary SQL with no server-side statement validation. Destructive project operations execute immediately. Connection strings with embedded passwords flow into the LLM context.

## Findings

### 1.…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/207) · 2026-03-11 · closed · external user · 1 comment

### setup-neon-auth prompt 404: references deleted GitHub file

## Bug Description

The `setup-neon-auth` prompt fails with:

McpError: MCP error -32603: Failed to fetch GitHub content: 404 Not Found


## Root Cause

The prompt in `landing/mcp-src/prompts.ts` calls `fetchRawGithubContent()` with the path:

/neondatabase-labs/ai-rules/main/mcp-prompts/neon-auth-setup.md


This file was **deleted on 2025-12-16** (commit `7c983fdf` in `neondatabase-labs/ai-rules`) and moved to:

/neondatabase-labs/ai-rules/main/references/neon-auth-setup.md


[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/205) · 2026-03-06 · closed · external user · 1 comment

### prepare_database_migration fails on dollar-quoted strings ($$)

## Bug

`prepare_database_migration` fails when the migration SQL contains `$$` dollar-quoted strings (e.g., PL/pgSQL trigger functions).

## Error

NeonDbError: unterminated dollar-quoted string at or near "$$ BEGIN NEW.updated_at = NOW()"


## Cause

`splitSqlStatements` in `landing/mcp-src/tools/utils.ts` does a naive `sql.split(';')`:

```typescript
export const splitSqlStatements = (sql: string) => {
  return sql.split(';').filter(Boolean);
};

This has no awareness of SQL…

Read the thread · 2026-02-24 · open · external user · 1 comment

describe_branch leaves show_db_tree function in user's database

Description

The describe_branch tool creates a public.show_db_tree() function in the user's database via DESCRIBE_DATABASE_STATEMENTS in landing/mcp-src/tools/utils.ts, but never cleans it up afterward. The function persists in the database indefinitely.

Impact

For projects that use schema introspection tools to generate types from the live database (e.g., Kanel), the leftover show_db_tree function gets picked up and generates…

Read the thread · 2026-02-12 · open · external user · 0 comments

The remaining reports are on the project's issue tracker.