Connect · DigitalOcean
Connect to DigitalOcean Managed PostgreSQL from your Mac
The cluster’s Overview page has a Connection Details section with the host, port 25060, user doadmin and database defaultdb. Add your Mac to the trusted sources and connect with TLS.
Updated 9 October 2026
What you need
- The cluster’s connection details from the DigitalOcean control panel, including the
doadminpassword (or another user’s). - Your Mac’s IP address in the cluster’s trusted sources, if you’ve set any.
- For certificate checks on a Standard Edition cluster, the cluster’s CA certificate.
Find your connection details
Go to the Databases page, select the cluster, and scroll to the Connection Details section on its Overview page. There you choose:
- Public network or VPC network. Only resources in the same VPC network can use the private host name, so from your Mac choose Public network.
- The database or pool, and the user.
- verify-full, a switch that makes the details check the server’s certificate (see TLS).
- The format: Connection parameters (separate fields), Connection string, or Flags (a
psqlcommand).
The password is hidden until you click show, or Copy to copy the details with it. Clusters
use port 25060; the default user is doadmin and the default database defaultdb.
Trusted sources limit which addresses can connect. When you add trusted sources, My current IP address (the Quick Add option) adds your machine’s current IP address. Trusted sources can’t hold IPv6 addresses.
Connection pools. DigitalOcean runs PgBouncer for the pools you create. A pool has its own
connection details: the same host, port 25061, and the pool name in place of the database
name. Pools default to transaction mode (session and statement modes also exist), and you can’t
change a pool’s mode after you create it. DigitalOcean warns that pg_dump fails through a
transaction-mode pool; connect to the cluster directly for backups.
Connection string
Direct to the cluster:
postgresql://doadmin:<password>@<host>:25060/defaultdb?sslmode=require
Through a pool named <pool>:
postgresql://doadmin:<password>@<host>:25061/<pool>?sslmode=require
See PostgreSQL connection strings and special characters in passwords.
TLS
Connection details use sslmode=require unless you turn on the verify-full switch;
require encrypts but doesn’t check the server’s certificate. What verify-full needs depends on
the cluster’s edition:
- Standard Edition: click Download CA certificate in Connection Details and point
sslrootcertat that file. - Advanced Edition: the certificate is checked against your system’s trusted roots, so there’s
nothing to download. With
psql, addsslrootcert=system, which needs libpq 16 or later (older versions treatsystemas a file name and fail).
Connect with Inlet
- In Connection Details, choose Public network and Connection string, copy it, and paste it into Inlet: Inlet fills in the connection form. Or choose New Connection and copy the separate fields across.
- Under TLS, choose
verify-full. On a Standard Edition cluster, select the downloaded CA certificate as the CA file. On Advanced Edition, leave the CA file empty: Inlet checks against the certificates macOS trusts. - Keep the password in the Keychain, or have Inlet ask each time.
- Tag the environment. A production connection opens read-only, with writes refused by the server until you unlock it for ten minutes.
Connect to port 25060, not a transaction-mode pool, for production. Inlet’s read-only mode is a session setting. Through a transaction pool each transaction can run on a different server connection, and PgBouncer doesn’t reset session state in transaction mode, so the setting isn’t guaranteed to hold. A session-mode pool or the direct port keeps it. To make a user read-only however it connects, set it on the server:
ALTER ROLE <user> SET default_transaction_read_only = on;
That’s a default a session can still switch off; for a hard limit, give that user only SELECT
privileges and keep doadmin for changes.
Connect from the command line
DigitalOcean notes that the Flags command in the control panel passes --set=sslmode=require,
which doesn’t configure TLS in psql; set PGSSLMODE instead:
PGPASSWORD=<password> PGSSLMODE=require psql -U doadmin -h <host> -p 25060 -d defaultdb
With certificate checks on a Standard Edition cluster:
psql "postgresql://doadmin:<password>@<host>:25060/defaultdb?sslmode=verify-full&sslrootcert=$HOME/Downloads/ca-certificate.crt"
Use the path and name of the file you downloaded. On Advanced Edition, use
sslrootcert=system instead. Homebrew’s libpq package includes a current psql
(/opt/homebrew/opt/libpq/bin/psql).
Troubleshooting
- Timed out or connection refused: your IP isn’t in the trusted sources, or you copied the VPC network address. Use Quick Add and the Public network details.
- password authentication failed: check the user and password in Connection Details. Through a pool, the database name must be the pool’s name.
pg_dumperrors through a pool: connect to port 25060 instead.- Too many connections: create a connection pool for your application, or close idle sessions.
sslrootcert=systemfails on an Advanced Edition cluster: yourpsqlis older than 16 and treatssystemas a file name. Use a newer one (Homebrew’slibpqis 18).
Related
Sources
- docs.digitalocean.com/products/databases/postgresql/how-to/connect/
- docs.digitalocean.com/products/databases/postgresql/how-to/secure/
- docs.digitalocean.com/products/databases/postgresql/how-to/manage-connection-pools/
- docs.digitalocean.com/products/databases/postgresql/how-to/migrate/
- docs.digitalocean.com/reference/pydo/reference/databases/get_connection_pool/
- www.pgbouncer.org/config.html