pREST
Instant REST and MCP over PostgreSQL: the agent reads an existing database through an MCP endpoint with no backend to write
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Exposes PostgreSQL data through a network service
- The full REST API can modify data with wrong permissions
Install
Manual install
docker run -e PREST_PG_URL=postgres://user:pass@host:5432/dbname -p 3000:3000 prest/prestRuns pREST over your database. The connection can also be set via pg.* or DATABASE_URL. Enable MCP per the MCP over HTTP guide.
This is third-party code. Review the repository files before installing.
What it does
pREST stands up a ready API over an existing or new PostgreSQL database: table CRUD, custom SQL routes, auth, ACL and an MCP endpoint, all without hand-writing a backend. For agents there is MCP over HTTP that gives read access to the database, so an AI client can query tables and data through a standard protocol. Values in SQL templates can be passed by binding, so they travel to Postgres out of band from the query text and are never parsed as SQL. It installs via Docker, Homebrew or Go and points at the database through a connection variable.
Who it is for. For backend developers and data engineers who want fast PostgreSQL access through an API and MCP without their own service.
Good fit when
- You want the agent to read PostgreSQL data over MCP
- You want an instant REST API over an existing database
- You want custom SQL routes with auth and ACL without a backend
Not a fit when
- The database is not PostgreSQL
- You cannot deploy and run a separate gateway service to the database
Example request
Through MCP show the orders table structure and select the last week's recordsLimitations
pREST is a separate service in front of PostgreSQL that you deploy and configure: connection, auth and ACL. The MCP endpoint gives read access, while the full REST API can change data, so set permissions and ACL for the agent's access. It needs PostgreSQL 9.5 or newer.
How to disable. Remove the pREST MCP endpoint address from the agent config and stop the pREST service.
MCP
- Transport
- http
- Authentication
- not required
| Environment variables | |
|---|---|
| PREST_PG_URL required, secret | PostgreSQL connection string; pg.* or DATABASE_URL also work |
Security check
- Exposes PostgreSQL data through a network service
- The full REST API can modify data with wrong permissions
README in short
The README describes pREST as a ready API that delivers REST and MCP over an existing or new PostgreSQL database: CRUD, custom SQL routes, auth, ACL and a read-only MCP endpoint. Install via Docker, Homebrew or Go, with the connection set through PREST_PG_URL or DATABASE_URL. It also covers safe value passing by binding rather than interpolation, MCP over HTTP, multi-database support and connecting AI clients such as Cursor and Claude. It includes Kubernetes deployment and one-click deploy. MIT licensed.
FAQ
What does the agent get through MCP?
The MCP endpoint gives read access to database data through a standard protocol; changes go through the REST API with auth and ACL.
Which database is needed?
PostgreSQL 9.5 or newer, existing or new; pREST works on top of it.
Related
The official FastAPI skill, bundled with the package, teaching agents to write code for the installed version
Official skills and agents from the .NET team: performance, MSBuild, NuGet, upgrades, testing, ASP.NET Core, Blazor and MAUI
Firebase MCP Server
Firebase CLI and MCP Server
Official Firebase MCP server from the Firebase CLI: projects, Firestore, Auth, Crashlytics, Remote Config and function logs
Laravel's official MCP server, guidelines and skills: the agent sees the DB schema, logs and package versions and searches ecosystem docs