# Reported issues for Neon

Pod holds 22 of 33 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to [Neon](/mcp/neon).

## Most discussed

### ChatGPT Neon connector broken after snake_case MCP migration in PR #324

After the recent snake_case migration in PR #324, the Neon integration currently exposed inside ChatGPT appears to be incompatible with the hosted Neon MCP server.

In ChatGPT, the Neon run_sql tool schema currently expects camelCase arguments such as:

projectId
databaseName

However, the hosted Neon MCP server now expects:

project_id
database_name

Calling the tool from ChatGPT with the schema ChatGPT exposes results in:

MCP error -32602: Input validation error

Required: project_id…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/333) · 2026-08-29 · closed · external user · 7 comments

### Read only config for MCP

I wanna expose this to my non-tech colleagues; And if one of them types delete project.. well yeah need I say more.. 

Would love to have 'read only' permissions/setup.

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/71) · 2025-06-11 · closed · external user · 6 comments

### Bug: Only Seeing Read-Only scopes on https://mcp.neon.tech/api/authorize

## Steps to reproduce
Running Neon MCP Authentication through Claude Code `/mcp`

## Expected result
Full-access, write scopes available. This is the behavior I was getting up until today

## Actual result
Read-only scopes show up for me only

<img width="850" height="796" alt="Image" src="https://github.com/user-attachments/assets/10d3c7cf-9372-4a35-9f8f-8d2569eedd3a" />

## Environment
i've tried with both 
```
"neon": {
      "type": "http",
      "url": "https://mcp.neon.tech/mcp"
    }
```…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/179) · 2026-01-16 · open · external user · 5 comments

### Project-scoped MCP exposes incompatible run_sql schema requiring project_id

Neon MCP tool-schema mismatch for project-scoped authentication.

The advertised run_sql JSON Schema requires:
required: ["sql", "project_id"]

Calling without project_id is blocked client-side:
'project_id' is a required property

Calling with project_id reaches Neon MCP but fails:
MCP error -32602
Unrecognized key(s): 'project_id'

Therefore no valid argument object can pass both the advertised client schema
and the actual project-scoped MCP runtime validation.

Related symptom:
list_projects…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/359) · 2026-09-19 · open · external user · 4 comments

### bug: revalidation spam

I'm using the mcp with Claude via the claue_desktop_config.json, which VS-code automatically taps into.

It seems that at random intervals (Usually around every five minutes, possibly), VS Code tries to re-auth with Neon. It opens up four new tabs in my browser.

It's especially frustrating if I walk away from my computer for a bit. I'll come back to 50 tabs opened.

<img width="2174" height="1938" alt="Image"…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/81) · 2025-07-05 · closed · external user · 3 comments

### State default organization id

Hi, I have a personal Neon account as well as being part of an organization within our company. Is it possible today to have the MCP server use by default a certain org id? Right now I need to specify the agent to target a particular Neon organization, but this is a very stable value. I think it would be better to just have it be a default that can be overriden by the agent. Is this possible today?

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/23) · 2025-03-03 · closed · external user · 3 comments

### Local MCP Server fails with 400 Bad Request when Organization API key is used

## Description

When running the local MCP server with an **Organization API key** (not a Personal API key), the server fails with a `400 Bad Request` error.

## Steps to Reproduce

1. Create an Organization API key in Neon Console (Settings → API Keys within an organization)
2. Run the local MCP server:
   ```bash
   npx -y @neondatabase/mcp-server-neon start <ORG_API_KEY>
   ```
3. Server crashes with `AxiosError: Request failed with status code 400`

## Expected Behavior

Server should start…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/183) · 2026-01-25 · closed · external user · 2 comments

### MCP keeps disconnecting

I have the MCP server added to Cursor and it does work briefly but keeps disconnecting after a minute or two. Sometimes I switch it back on and Cursor is still making an execution plan before it switches off again.

Re-authorisation seems to be required once a day or so, I'm not talking about that. I'm talking  about just switching off.

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/107) · 2025-08-13 · closed · external user · 2 comments

## Most recent

### Project-scoped OAuth: metadata tools return HTTP 404 authorization internal error for a Vercel-managed project

## Summary

The official hosted Neon MCP server completes OAuth successfully and exposes its tool catalog in Codex, but read-only metadata calls against an existing Vercel-managed project consistently fail with:

```text
The request could not be authorized due to an internal error
[HTTP 404] The request could not be authorized due to an internal error
```

The same project and its test branch are accessible through the authenticated Neon Console. We have not established the root cause.

##…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/366) · 2026-09-26 · open · external user · 0 comments

### Project-scoped OAuth in ChatGPT strips project_id from tool schema but backend still requires it

## Summary

When using the hosted Neon MCP integration in ChatGPT with OAuth access scoped to a single Neon project, project-scoped tools are unusable.

The tool schemas exposed to ChatGPT correctly omit `project_id`, but calls fail on the Neon MCP side because `project_id` is still required by backend validation.

This appears to be a mismatch between the project-scoped OAuth context and the runtime tool handler.

## Environment

-   Client: ChatGPT (official Neon plugin / hosted MCP)
-   Date…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/362) · 2026-09-24 · open · external user · 1 comment

### Tool input schemas use strict validation, rejecting client-injected keys (breaks agent platforms)

Summary

The hosted Neon MCP server (https://mcp.neon.tech/mcp) validates tool inputs with strict object schemas. Any key not declared in a tool's inputSchema causes the call to fail validation before the tool executes. This breaks agent platforms that inject their own context keys into tool arguments — a common pattern in practice.

Request: use .strip() (or .passthrough()) instead of .strict() for tool input schemas, so unknown keys are ignored rather than fatal.

What we're seeing

Calls to…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/353) · 2026-09-11 · open · external user · 0 comments

### Allow run_sql / run_sql_transaction to execute as a specified PostgreSQL role without exposing credentials

Allow run_sql / run_sql_transaction to execute as a specified PostgreSQL role without exposing credentials
Summary
Add optional role_name and compute_id parameters to the Neon MCP run_sql and run_sql_transaction tools.

The hosted MCP server already resolves PostgreSQL connection URIs internally before executing SQL, and the underlying connection-string resolver already supports selecting a PostgreSQL role and compute endpoint.

The requested change is to expose those selectors to the…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/347) · 2026-09-08 · open · external user · 1 comment

### ChatGPT Neon plugin run_sql schema mismatch: projectId passed but MCP expects project_id

### Bug description

The Neon Postgres plugin in ChatGPT can successfully authenticate, list organizations, list projects, and identify the correct Neon project, but database-level tools such as `run_sql` fail before SQL execution because of an apparent parameter-schema mismatch.

### Environment

* Client: ChatGPT
* Integration: Neon Postgres plugin / Neon MCP
* Authentication: OAuth
* Project: PostgreSQL 17
* Neon MCP endpoint/integration is otherwise authenticated and working
* Plugin was…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/339) · 2026-09-02 · open · external user · 0 comments

### Add --access-mode flag to restrict destructive tools (read-only / write / full)

## Problem

Today the server exposes the full set of tools (including `delete_project`, `delete_branch`, `run_sql` writes, `reset_from_parent`, etc.) whenever it's started with a Neon API key. There's no way for the operator to opt into a less-privileged mode.

This is awkward for editor/agent integrations (Claude Desktop, Zed, Cursor, etc.) where:

- Users often want to give an agent broad read access to inspect projects, branches, schemas, slow queries, etc., without granting the ability to…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/276) · 2026-05-28 · closed · external user · 0 comments

### create_branch MCP tool: schema is incomplete and silently drops unknown params; no way to set expires_at

## Summary

The hosted Neon MCP server at `mcp.neon.tech` exposes `create_branch` with a JSON schema declaring only `branchName` + `projectId` and `additionalProperties: false`. In practice the server:

1. Accepts an undeclared `parentId` (camelCase) parameter and honors it.
2. Silently drops several other undeclared parameters without erroring: `parent_id`, `expiresAt`, `expires_at`, `expiration`, `autoDeleteAt`.
3. Has no working way to set a branch expiration via MCP — the underlying REST…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/273) · 2026-05-22 · closed · external user · 0 comments

### Support run_sql and data-plane tools when project password storage is disabled

## Summary

When a Neon project has **\"Store role passwords\"** disabled, all MCP tools that need a Postgres connection (`run_sql`, `run_sql_transaction`, `get_database_tables`, `describe_table_schema`, `get_connection_string`, etc.) fail with HTTP 412 from the Neon control plane:

> storing passwords is not enabled for the project [Precondition Failed] Request failed with status code 412

Control-plane-only tools like `describe_project` still work fine over OAuth — so the MCP itself is…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/267) · 2026-05-18 · open · 0 comments

### Exposing inputSchema + read-only metadata in /api/list-tools

Hi @vadim2404 (cc @pffigueiredo @Shridhad)

  I was looking at the public `/api/list-tools` response while exploring how external tools
   could integrate with MCP servers. Three observations that might be useful — small
  contract clarifications, not bugs.

  ---

  ### 1. No `inputSchema` per tool in the response

  The 6 tools (run_sql, run_sql_transaction, explain_sql_statement, list_slow_queries,
  search, fetch) come back with name, title, scope, readOnlySafe, and description, but no…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/257) · 2026-05-12 · closed · external user · 1 comment

### Stdio package deprecation breaks headless/gateway deployments — need API key auth for hosted MCP

## Problem

The deprecation of `@neondatabase/mcp-server-neon` has broken headless and gateway-based MCP deployments with no migration path.

### What worked before

We run an MCP gateway that spawns MCP servers as stdio subprocesses and proxies tool calls through a single authenticated HTTP endpoint. This provides centralised access control, tool filtering, and token-based routing for 17+ users. The old stdio package worked perfectly:

```json
{
  "command": "npx",
  "args": ["-y",…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/214) · 2026-04-07 · open · external user · 1 comment

### [Security Audit] AgentWard Permission Analysis — Neon Postgres MCP Server

Hey Neon team — I reviewed mcp-server-neon and wanted to share a few security observations. I see you've already put thought into this (tool annotations, read-only mode, migration safety workflow) — these findings are about gaps in the current implementation.

## TL;DR

`run_sql` accepts arbitrary SQL with no server-side statement validation. Destructive project operations execute immediately. Connection strings with embedded passwords flow into the LLM context.

## Findings

### 1.…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/207) · 2026-03-11 · closed · external user · 1 comment

### setup-neon-auth prompt 404: references deleted GitHub file

## Bug Description

The `setup-neon-auth` prompt fails with:
```
McpError: MCP error -32603: Failed to fetch GitHub content: 404 Not Found
```

## Root Cause

The prompt in `landing/mcp-src/prompts.ts` calls `fetchRawGithubContent()` with the path:
```
/neondatabase-labs/ai-rules/main/mcp-prompts/neon-auth-setup.md
```

This file was **deleted on 2025-12-16** (commit `7c983fdf` in `neondatabase-labs/ai-rules`) and moved to:
```
/neondatabase-labs/ai-rules/main/references/neon-auth-setup.md
```…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/205) · 2026-03-06 · closed · external user · 1 comment

### prepare_database_migration fails on dollar-quoted strings ($$)

## Bug

`prepare_database_migration` fails when the migration SQL contains `$$` dollar-quoted strings (e.g., PL/pgSQL trigger functions).

## Error

```
NeonDbError: unterminated dollar-quoted string at or near "$$
BEGIN
  NEW.updated_at = NOW()"
```

## Cause

`splitSqlStatements` in `landing/mcp-src/tools/utils.ts` does a naive `sql.split(';')`:

```typescript
export const splitSqlStatements = (sql: string) => {
  return sql.split(';').filter(Boolean);
};
```

This has no awareness of SQL…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/201) · 2026-02-24 · open · external user · 1 comment

### describe_branch leaves show_db_tree function in user's database

## Description

The `describe_branch` tool creates a `public.show_db_tree()` function in the user's database via `DESCRIBE_DATABASE_STATEMENTS` in `landing/mcp-src/tools/utils.ts`, but never cleans it up afterward. The function persists in the database indefinitely.

## Impact

For projects that use schema introspection tools to generate types from the live database (e.g., [Kanel](https://github.com/kristiandupont/kanel)), the leftover `show_db_tree` function gets picked up and generates…

[Read the thread](https://github.com/neondatabase/mcp-server-neon/issues/196) · 2026-02-12 · open · external user · 0 comments

The remaining reports are on [the project's issue tracker](https://github.com/neondatabase/mcp-server-neon/issues).
