Support
Log In
Reference

Setting Up PostgreSQL

Connect a PostgreSQL database to Credible, including Supabase, and fix the common connection errors

Credible connects to any PostgreSQL database reachable over the public internet, including managed Postgres from Supabase, Amazon RDS, Cloud SQL, Azure Database, and Neon.

Connection Fields

Fill in either the individual fields or a connection string — not both. The form disables the individual fields once a connection string is present.

FieldExample
Hostdb.example.com
Port5432
Database Namepostgres
Usernamecredible_readonly
Passwordyour database password

A connection string takes the standard PostgreSQL URI form:

postgresql://user:password@host:5432/database

If your password contains @, /, : or #, URL-encode it or the connection string will not parse correctly.

Network Access

Credible queries your database from stable egress addresses over IPv4, so the host you give it needs to be reachable from the public internet on an IPv4 address.

  • Behind an IP allowlist? Add Credible's egress addresses to it. These are specific to the environment your organization runs in — ask your Credible administrator, or contact support, for the current addresses.
  • No public route at all? Use the Connect through an SSH bastion option in the connection form.
  • Host published only on IPv6? It cannot be reached. Most managed Postgres offers an IPv4 endpoint alongside it — on Supabase, that is the session pooler, covered below.

Supabase

Supabase's dashboard offers several connection strings, and shows Direct Connection first. Use the session pooler instead — the direct host is published only on IPv6, which Credible cannot reach.

SettingValue
Hostaws-0-<region>.pooler.supabase.com
Port5432
Database Namepostgres
Usernamepostgres.<project-ref>
Passwordyour database password

Find these under Connect in the Supabase dashboard, on the Session pooler tab.

The username needs the project-ref suffix — postgres.abcdefghijklmnop, not postgres. The pooler serves many projects and uses that suffix to route to yours, so a bare postgres fails authentication.

Supabase also offers a transaction pooler on port 6543. Prefer session mode on 5432: transaction mode does not support prepared statements or session-level state, which some queries rely on.

If your project enforces SSL

If your project has Enforce SSL on incoming connections enabled (Supabase dashboard: Database → Settings → SSL Configuration), use the connection string field and append ?sslmode=no-verify:

postgresql://postgres.<project-ref>:<password>@aws-0-<region>.pooler.supabase.com:5432/postgres?sslmode=no-verify

Supabase signs its certificates with its own authority rather than a public one, so verification fails without this. The connection stays encrypted — only the certificate check is skipped. Turning off Enforce SSL also clears the error, but allows an unencrypted connection.

Troubleshooting

ErrorCauseFix
self signed certificate in certificate chainThe database's certificate is signed by a private certificate authority, not a public one. Common on Supabase with Enforce SSL enabled, and on self-hosted Postgres.Use the connection string field and append ?sslmode=no-verify
connect ECONNREFUSED <ipv6 address>The host resolves only to IPv6, which Credible cannot reach.Use an IPv4-reachable host. On Supabase, the session pooler.
password authentication failed on a Supabase pooler hostThe username is missing the project-ref suffix.Use postgres.<project-ref>
connection timed out / ETIMEDOUTThe database is not reachable from the public internet, or an IP allowlist is blocking Credible.Add Credible's egress addresses to the allowlist (see Network Access), or connect through an SSH bastion
permission denied for schema ...The credentials work but the role lacks read access.Grant the role USAGE on the schema and SELECT on the tables you want to model

On this page