psql connection guide
psql PostgreSQL Connection String
Connect with a PostgreSQL URI or individual psql flags, avoid leaking passwords into shell history, and test SSL.
Use the connection value generated by psql, keep it in an environment variable, and test it before changing application code. The URI shape below is a template, not a credential to paste unchanged.
- URI scheme
- postgresql://
- Default PostgreSQL port
- 5432
- Credential handling
- Environment variable or secret manager
- First test
- psql "$DATABASE_URL" -c "\conninfo"
Connection string template
postgresql://USER@HOST:5432/DB_NAME?sslmode=requireReplace every uppercase placeholder. Percent-encode reserved characters in URI usernames and passwords.
Environment variable
PGPASSWORD='your-password' psql 'postgresql://USER@HOST:5432/DB_NAME?sslmode=require'Where to get the psql values
psql accepts a URI after the command name or individual -h, -p, -U, and -d flags. The URI form is easiest to copy between a hosted database dashboard and a local terminal.
The failure mode worth checking first
Putting the password directly in a command can save it in shell history and expose it to process inspection. Prefer a password file, a secret manager, or a short-lived PGPASSWORD value.
Test the connection
Run a cheap read-only command before migrations or application startup. That separates network, TLS, and authentication errors from framework configuration problems.
Connection check
psql "$DATABASE_URL" -c "\conninfo"Open it in PostgresGUI
Paste the PostgreSQL URI into PostgresGUI or enter the same host, port, database, user, password, and SSL mode as separate fields. A desktop connection is useful for checking the visible schemas and role permissions before debugging the application layer.
Questions that come up
Should the connection string be committed to Git?
No. Commit an example with placeholders and load the real value from an environment variable or secret manager.
Why does a password with @ or # break the URI?
Those characters have meaning inside a URL. Percent-encode the username and password, or use a structured connection API instead of assembling a URL by hand.
Do I need sslmode=require?
Most hosted PostgreSQL services require TLS. For strict certificate and hostname verification, use sslmode=verify-full with the provider's trusted root certificate when the client supports it.