Connect · Render
Connect to Render Postgres from your Mac
Use the database’s external URL, from the Connect menu or its Info page. Render requires TLS on external connections and, by default, accepts them from any IP address with valid credentials.
Updated 9 October 2026
What you need
- The database’s external URL. The internal URL only works from your other Render services in the same account and region.
- Your IP address in the database’s allow list, if you’ve narrowed it.
Find your connection details
Open the database in the Render Dashboard. Both URLs are in the Connect menu at the top right of its page, and on its Info page, along with the separate host, port, user, password and database values and a ready-made PSQL Command.
From the Render CLI:
render pg get <database> --include-sensitive-connection-info
Render Postgres uses the standard port, 5432.
Access control. By default the database accepts external connections from any IP address
(the allow list holds 0.0.0.0/0), as long as the credentials are valid. To narrow it, go to the
database’s Info page, scroll to Networking, and list the address blocks you want to allow in
CIDR notation. You can also turn external access off entirely; your Render services in the same
region can still use the internal URL.
Connection pooling. On paid databases you can turn on Render’s integrated PgBouncer. Render
then shows two more URLs on the Info page, internal and external, which are the direct ones with
port 6432 instead of 5432. The pool works in transaction mode, so Render tells you to connect
directly for anything that needs session state: SET SESSION, LISTEN/NOTIFY, session-level
advisory locks.
Connection string
The external URL has this form:
postgresql://<user>:<password>@<external-host>:5432/<database>
Add ?sslmode=require so the client never falls back to an unencrypted connection. Always use the
host name from the URL, never an IP address it resolved to; see Troubleshooting. More on the format
in PostgreSQL connection strings.
TLS
External connections are always encrypted, with certificates Render manages. Render rejects
external connections that set sslmode=disable, and asks you to set sslmode=require. Your client
needs TLS 1.2 or later.
Render’s docs don’t say which authority signs those external certificates, so this page doesn’t
promise that verify-full works. (Internal connections use self-signed certificates, and Render
says they don’t support verify-ca or verify-full.) Keep in mind that require encrypts but
doesn’t check who you’re talking to.
Connect with Inlet
- Copy the external URL from the Connect menu and paste it into Inlet; Inlet fills in the
connection form. Or choose New Connection and enter the fields from the Info page. If your
project’s
.envhas the URL asDATABASE_URL, Inlet can import it from there. - Under TLS, choose
require. - Save the password in the Keychain, or have Inlet ask every time.
- Tag the environment. A production connection opens read-only: the server refuses writes until you unlock it, which lasts ten minutes.
Use the direct URL (port 5432) for production, not the pool. Inlet’s read-only mode is a session setting, and through PgBouncer in transaction mode each transaction can run on a different server connection. PgBouncer also doesn’t reset session state in that mode, so the setting isn’t guaranteed to hold. To make a user read-only on the server, whichever URL it uses:
ALTER ROLE <user> SET default_transaction_read_only = on;
It’s a default a session can turn off again; for a hard limit, browse with a user that only has
SELECT privileges, not the one your app writes with.
Connect from the command line
Copy the PSQL Command from the Info page, or build it from the external URL:
psql "postgresql://<user>@<external-host>:5432/<database>?sslmode=require"
psql asks for the password. If you don’t have psql, Homebrew’s libpq package includes it
(/opt/homebrew/opt/libpq/bin/psql).
Troubleshooting
FATAL: No SNI information found: the client connected to an IP address, or doesn’t send the host name during the TLS handshake. Use the full external host name from the URL.- TLS handshake errors: the client must support TLS 1.2 or later and one of Render’s cipher suites. Update the client.
- Refused with
sslmode=disable: external connections need TLS. Userequire. - Timed out or connection refused: check the allow list under Networking includes your current IP, and that external access isn’t turned off.
- password authentication failed: copy the credentials again from the Info page; percent-encode special characters in a URL.
- Too many connections: the limit depends on the plan’s memory. Use connection pooling for your app or move to a larger plan.