pREST in 10 Minutes: Docker Compose to REST API to MCP Endpoint
Run pREST v2.4.2 with Docker Compose, query a Postgres table over REST, turn on JWT auth and a table ACL, add a bound custom query and call /_mcp.
PostgreSQL & pREST
pREST is an open-source Go server that turns PostgreSQL into a REST API and a read-only MCP endpoint. Every v2 release, the advisories, and where to start.
PostgreSQL & pRESTpREST v2.1.0 MCP server exposes read-only PostgreSQL queries over HTTP — connect from Cursor, Claude Desktop, or curl with permission-aware ACL and no separate MCP process.
Run pREST v2.4.2 with Docker Compose, query a Postgres table over REST, turn on JWT auth and a table ACL, add a bound custom query and call /_mcp.
pREST v2.4.1 closes an 8.6 SQL injection in _QUERIES templates and an /_mcp catalog-exposure bypass — then its SQL-keyword blacklist silently blanked 17.5% of one production catalog. v2.4.2 replaces screening with real parameter binding, adds script path-traversal containment, and enforces RFC 7518 minimum JWT key sizes.
pREST v2.4.0 adds pgvector nearest-neighbor search and distance filtering, opt-in OpenTelemetry tracing/metrics/logs with a local SigNoz stack, and closes six SQL-injection-adjacent security gaps found via advisory review — including a sibling of the v2.3.0 _select fix living in _groupby.
pREST v2.3.0 closes an unauthenticated SQL injection in the _select parameter (CVSS 9.8), migrates JWKS handling to jwx v3, and completes the multi-adapter registry that isolates TimescaleDB features from the base Postgres adapter.
pREST 2.2.0 ships an embedded Studio UI, database-backed custom queries, and first-class TimescaleDB support—making instant Postgres APIs easier to explore and operate.
pREST and PostgREST both turn PostgreSQL into a REST API. PostgREST is Haskell and RLS-first; pREST is Go with config ACL, multi-database routing and MCP.
pREST AI tooling ships prest-mcp stdio adapter, Cursor plugin rules/skills, and OpenClaw ClawHub skills — read-only PostgreSQL access for agents via the /_mcp endpoint.
pREST v2 is a Go PostgreSQL REST API with multi-database registry in v2.0.0 GA and a read-only MCP server in v2.1.0 — permission-aware Postgres queries for agents and API clients.
pREST v2.0.0-rc6 splits the monolithic Adapter into port interfaces, wires HTTP controllers through dependency injection, and keeps a backward-compatible composite Adapter for Go teams running Postgres REST APIs.