Connect · Heroku Postgres
Connect to Heroku Postgres from your Mac
Get the current connection URL with heroku pg:credentials:url (or the Credentials tab) and connect with TLS, which Heroku requires. The credentials can change, so fetch them again when a saved connection stops working.
Updated 9 October 2026
What you need
- The Heroku CLI, signed in, or access to the app in the Heroku Dashboard.
- A database on the Essential, Advanced, Standard or Premium tier. Private and Shield databases can’t be reached directly from outside their Private or Shield space; Heroku has a separate guide for those (mutual TLS and trusted IP ranges).
Find your connection details
From the CLI (use heroku data:pg:credentials:url for Advanced databases):
heroku pg:credentials:url DATABASE -a <app>
Heroku’s example output, with the values replaced:
Connection information for default credential.
Connection info string:
"dbname=<database> host=<host> port=5432 user=<user> password=... sslmode=require"
Connection URL:
postgres://<user>:<password>@<host>:5432/<database>
From the Dashboard: open the database from the Datastores tab or your app’s Resources list, select the Credentials tab, click Edit on a credential, and copy the string from the URI section.
Heroku also puts the URL in your app’s config vars (DATABASE_URL, or a HEROKU_POSTGRESQL_…_URL
name); heroku config | grep postgres lists them.
The values can change at any time, for example after a failover or a credential rotation, so don’t treat a copied URL as permanent.
Credentials and privileges. The default credential owns the database and sits one step below a superuser. You can create custom credentials with fewer privileges, which is a good choice for browsing production.
Connection pooling (Standard, Premium, Private and Shield tiers): attaching it with
heroku pg:connection-pooling:attach DATABASE_URL --as DATABASE_CONNECTION_POOL -a <app> adds
DATABASE_CONNECTION_POOL_URL, which points at PgBouncer on port 5433 in transaction mode.
The pool runs on the database server, so external clients can share it.
Connection string
postgres://<user>:<password>@<host>:5432/<database>?sslmode=require
Heroku’s URLs use the postgres:// scheme, which PostgreSQL clients accept like postgresql://.
See PostgreSQL connection strings.
TLS
Heroku Postgres requires TLS 1.2 or later on every connection: use sslmode=require at least.
Essential and Advanced databases use certificates issued by AWS RDS. To verify them from your Mac,
download the AWS RDS global CA bundle (macOS doesn’t include it) and use sslmode=verify-full, or
verify-ca if you only want the certificate checked, not the host name:
curl -O https://truststore.pki.rds.amazonaws.com/global/global-bundle.pem
Heroku’s connection article covers verification only for Essential and Advanced databases; for the
classic tiers it asks for sslmode=require.
Connect with Inlet
- Run
heroku pg:credentials:urland paste the URL into Inlet: it fills in the connection form. If your project’s.envfile has aDATABASE_URL, Inlet can import the connection from it. Or choose New Connection and enter the fields. - Under TLS, choose
verify-fulland selectglobal-bundle.pemas the CA file (Essential and Advanced). On classic tiers,require. - Keep the password in the Keychain, or have Inlet ask every time. If Heroku rotates the credentials, Inlet’s connection window asks for the new password when the old one is refused; if the host or user changed too, paste the new URL.
- Tag the environment. A production connection opens read-only, so the server refuses writes until you unlock it for ten minutes.
Connect on port 5432 for production, not the pool on 5433. Inlet’s read-only mode is a session setting, and through PgBouncer in transaction mode each transaction can use a different server connection; PgBouncer doesn’t reset session state in that mode either. So the setting isn’t guaranteed to hold through the pool. A custom credential with read-only privileges is the server-side way to make sure nothing gets written.
Connect from the command line
The Heroku CLI opens psql for you (it needs PostgreSQL installed locally; use
heroku data:pg:psql for Advanced databases):
heroku pg:psql -a <app>
Heroku’s example output, with the database name replaced:
--> Connecting to <database>
psql (17.2 (Postgres.app), server 16.9 (Ubuntu 16.9-1.pgdg20.04+1))
SSL connection (protocol: TLSv1.3, cipher: TLS_AES_256_GCM_SHA384, compression: off, ALPN: none)
Type "help" for help.
Or connect with the URL and certificate checks:
psql "postgres://<user>:<password>@<host>:5432/<database>?sslmode=verify-full&sslrootcert=global-bundle.pem"
Troubleshooting
- password authentication failed on a connection that used to work: the credentials changed. Fetch the URL again.
- Refused without TLS: Heroku requires it. Set
sslmode=requireor stricter. The authentication type 10 is not supportedorSCRAM authentication is not supported by this driveron an Essential database: your driver doesn’t support SCRAM password authentication. Update it; Heroku has a help article on this.- A Private or Shield database is unreachable: it can’t be reached directly from outside its space. Follow Heroku’s guide for external access to those tiers.
- Too many connections: each plan has a connection limit. Attach connection pooling for your app (Standard tier and up).
Related
Sources
- devcenter.heroku.com/articles/connecting-heroku-postgres
- devcenter.heroku.com/articles/heroku-postgresql
- devcenter.heroku.com/articles/provisioning-heroku-postgres
- devcenter.heroku.com/articles/managing-heroku-postgres-using-cli
- devcenter.heroku.com/articles/postgres-connection-pooling
- docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.SSL.html
- www.pgbouncer.org/config.html
- www.postgresql.org/docs/current/libpq-connect.html