> ## Documentation Index
> Fetch the complete documentation index at: https://docs.forge.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# PostgreSQL

> Protect PostgreSQL connections, commands, and supported results.

Direct clients connect to the Resource gateway on TCP `5432`. Append the
Resource access name to the requested database; the short-lived Forge token is
consumed by the gateway and never sent upstream.

```sh theme={"system"}
PGPASSWORD="$(forge resources token production-database)" \
  psql 'host=resources.example.com port=5432 dbname=app@production-database user=app sslmode=verify-full sslrootcert=forge-resource-ca.pem'
```

With automatic routing, keep the destination hostname, database, and ordinary
client command.

## Policy fields and actions

Forge can match database, requested database user, command, schemas, tables,
and a literal-free query pattern. It supports simple and prepared commands.
Connections and commands can be allowed, flagged, approved, or blocked.

For query results, Forge can redact exact columns or remove rows matching a
predicate. Filtering runs before redaction, preserves `NULL`, and corrects
delivered-row counts for `SELECT` and `FETCH`. Nullification supports text and
binary fields; other transformations require a text-compatible value.

## Destination authentication

The gateway can use an assigned username and password or generate a temporary
AWS IAM database password from its workload identity for RDS and Aurora.
Destination TLS and hostname verification are always required.

## Current limits

COPY transformation, suspended extended-protocol portals, lineage-based column
discovery, database-semantic query rewriting, and arbitrary binary value
rewriting are not supported. Missing or ambiguous targeted columns, malformed
messages, and incompatible formats fail closed before an original targeted
value is released.

See [Credentials and identity](/resources/credentials-and-identity) and
[Resource Policies](/secure/resource-policies).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.