Skip to content

Connect to PostgreSQL

Tested with: PostgreSQL 17.6 on Databasezy · drivers listed per tab · zb CLI 0.1

  1. Open the instance in the portal, go to Connect, and copy the host and port. Credentials were shown once at creation; if you lost them, rotate them.
  2. Download the CA bundle from the same tab (or run zb api GET /v1/orgs/{org}/ca.pem > databasezy-ca.pem). The gateway presents a publicly trusted certificate, but libpq-based drivers do not read the OS trust store, so pass the bundle explicitly.
  3. Add your application’s egress IPs to Network → Allow-list. Connections from other addresses are refused at the gateway before authentication.
  4. Use one of the snippets below. Every one of them runs sslmode=verify-full or the driver’s equivalent: the chain is verified and the hostname must match.

PostgreSQL listens on port 5432 (PostgreSQL wire protocol). Versions: 18, 17, 16, 15. Replace the example host with the one on your instance's Connect tab; credentials are shown once at creation.

Connection URI
postgresql://app:<password>@pg-7f3k.us-east.databasezy.com:5432/app?sslmode=verify-full&sslrootcert=databasezy-ca.pem
db.js
import { readFileSync } from "node:fs";
import { Pool } from "pg";
const host = "pg-7f3k.us-east.databasezy.com";
export const pool = new Pool({
host,
port: 5432,
database: "app",
user: "app",
password: process.env.ZB_PASSWORD,
ssl: {
ca: readFileSync("databasezy-ca.pem", "utf8"),
rejectUnauthorized: true, // verify chain
servername: host, // verify hostname (verify-full)
},
max: 10, // keep well under the size's max_connections
idleTimeoutMillis: 30_000,
});
const { rows } = await pool.query("select version()");
console.log(rows[0]);

Tested with: PostgreSQL 18 · node-postgres (pg) 8.13

  • The minimum is TLS 1.2; TLS 1.3 is negotiated by every driver above. Plaintext is never offered; a client that refuses TLS is disconnected with a clear error.
  • sslmode=require encrypts but does not verify the server. Use verify-full in production; it is the default in all snippets here.
  • Certificates are rotated automatically every 60 days. Pin the CA (intermediate), never the leaf; rotation dates are published twelve months ahead on the mTLS and pinning page.
  • Each size has a hard max_connections (see the size catalogue). Keep the sum of your application pools under it and leave headroom for migrations and psql.
  • Serverless and edge runtimes open a connection per invocation. Enable the built-in transaction-mode pooler on Connect → Pooler and use the pooled endpoint; see Connection pooling for the trade-offs (no session state, no LISTEN, prepared statements per transaction).
  • Idle connections do not keep a free-tier instance awake; it sleeps after 15 minutes without traffic and wakes on the next connection (the first query after wake takes a few seconds).

The allow-list is enforced by the gateway for every plan, including Free. Add CIDRs, not single addresses, for platforms with rotating egress IPs, or use the platform’s static-egress feature (documented per platform under Platforms). 0.0.0.0/0 is allowed but flagged in the portal and in the audit log.