InletDownload

Connect · Render

Connect to Render Postgres from your Mac

Use the database’s external URL, from the Connect menu or its Info page. Render requires TLS on external connections and, by default, accepts them from any IP address with valid credentials.

Updated 9 October 2026

What you need

  • The database’s external URL. The internal URL only works from your other Render services in the same account and region.
  • Your IP address in the database’s allow list, if you’ve narrowed it.

Find your connection details

Open the database in the Render Dashboard. Both URLs are in the Connect menu at the top right of its page, and on its Info page, along with the separate host, port, user, password and database values and a ready-made PSQL Command.

From the Render CLI:

render pg get <database> --include-sensitive-connection-info

Render Postgres uses the standard port, 5432.

Access control. By default the database accepts external connections from any IP address (the allow list holds 0.0.0.0/0), as long as the credentials are valid. To narrow it, go to the database’s Info page, scroll to Networking, and list the address blocks you want to allow in CIDR notation. You can also turn external access off entirely; your Render services in the same region can still use the internal URL.

Connection pooling. On paid databases you can turn on Render’s integrated PgBouncer. Render then shows two more URLs on the Info page, internal and external, which are the direct ones with port 6432 instead of 5432. The pool works in transaction mode, so Render tells you to connect directly for anything that needs session state: SET SESSION, LISTEN/NOTIFY, session-level advisory locks.

Connection string

The external URL has this form:

postgresql://<user>:<password>@<external-host>:5432/<database>

Add ?sslmode=require so the client never falls back to an unencrypted connection. Always use the host name from the URL, never an IP address it resolved to; see Troubleshooting. More on the format in PostgreSQL connection strings.

TLS

External connections are always encrypted, with certificates Render manages. Render rejects external connections that set sslmode=disable, and asks you to set sslmode=require. Your client needs TLS 1.2 or later.

Render’s docs don’t say which authority signs those external certificates, so this page doesn’t promise that verify-full works. (Internal connections use self-signed certificates, and Render says they don’t support verify-ca or verify-full.) Keep in mind that require encrypts but doesn’t check who you’re talking to.

Connect with Inlet

  1. Copy the external URL from the Connect menu and paste it into Inlet; Inlet fills in the connection form. Or choose New Connection and enter the fields from the Info page. If your project’s .env has the URL as DATABASE_URL, Inlet can import it from there.
  2. Under TLS, choose require.
  3. Save the password in the Keychain, or have Inlet ask every time.
  4. Tag the environment. A production connection opens read-only: the server refuses writes until you unlock it, which lasts ten minutes.

Use the direct URL (port 5432) for production, not the pool. Inlet’s read-only mode is a session setting, and through PgBouncer in transaction mode each transaction can run on a different server connection. PgBouncer also doesn’t reset session state in that mode, so the setting isn’t guaranteed to hold. To make a user read-only on the server, whichever URL it uses:

ALTER ROLE <user> SET default_transaction_read_only = on;

It’s a default a session can turn off again; for a hard limit, browse with a user that only has SELECT privileges, not the one your app writes with.

Connect from the command line

Copy the PSQL Command from the Info page, or build it from the external URL:

psql "postgresql://<user>@<external-host>:5432/<database>?sslmode=require"

psql asks for the password. If you don’t have psql, Homebrew’s libpq package includes it (/opt/homebrew/opt/libpq/bin/psql).

Troubleshooting

  • FATAL: No SNI information found: the client connected to an IP address, or doesn’t send the host name during the TLS handshake. Use the full external host name from the URL.
  • TLS handshake errors: the client must support TLS 1.2 or later and one of Render’s cipher suites. Update the client.
  • Refused with sslmode=disable: external connections need TLS. Use require.
  • Timed out or connection refused: check the allow list under Networking includes your current IP, and that external access isn’t turned off.
  • password authentication failed: copy the credentials again from the Info page; percent-encode special characters in a URL.
  • Too many connections: the limit depends on the plan’s memory. Use connection pooling for your app or move to a larger plan.

Related

Sources