Query as the person asking.
A shared database credential can give an AI assistant more access than the person using it. pgwarden is an MCP gateway that maps an authenticated identity to a dedicated Postgres login. Each request runs with that person’s grants and row-level policies.
An OAuth authorization flow connects the client to an upstream OIDC identity provider. The gateway maintains a separate connection pool for each mapped person, so access stays tied to the database session.
Let Postgres enforce access.
Reads use prepared statements inside read-only transactions, with execution timeouts and limits on returned rows and bytes. Postgres enforces permissions; the gateway does not rely on parsing SQL to decide whether a query is safe.
Generated security-barrier views mask selected PII columns before results reach the assistant. Tool calls, sign-ins, approval decisions, and administrative changes enter a hash-chained audit log with an independent verifier.
Approve the exact write.
Writes follow a separate proposal and review process. An authorized human approver reviews the operation; execution is bound to the stored SQL, parameters, and writer role. The gateway claims an approval atomically to prevent repeated execution and rolls back writes that exceed the approved row limit.
The project includes a local Docker stack, an administration interface, and Terraform for Cloud Run and Cloud SQL. The Terraform configuration has been validated and scanned, but has not been applied to a live cloud deployment.
Measured against adversarial requests.
The recorded local red-team run blocked 133 attack cases and passed all 32 benign controls. The checks inspect database and protocol outcomes rather than matching error messages. Two additional cases document residual exposure of planner statistics and relation names; they are not counted as blocked attacks.
These results cover the bundled test environment. MCP Inspector and direct HTTP flows have been exercised; external identity-provider tenants and several AI clients remain unverified. The gateway cannot prevent disclosure of data a person is allowed to read. A database superuser can rewrite the audit chain; retaining a trusted checkpoint outside the database makes changes to the checkpointed history detectable.