Security and connections in PG Studio
Learn how PG Studio connects to your database and ensures safe, controlled access.
Database connection details
PG Studio connects to your PostgreSQL service using:
- Database user: The
avnadminuser account, which has full read and write access to your databases. You can run SQL statements through the SQL editor. - Access scope: Full database access with the same privileges as the
avnadminuser. This is not limited to read-only access.
Security safeguards
PG Studio ensures safe, controlled access:
For AI query generation scope, see How AI assistance works.
- Restricted unsafe requests: Requests for privilege escalation or malicious SQL are blocked.
- Timeouts and limits:
- Statement timeout: 30 seconds
- Lock timeout: 10 seconds
- Connection timeout: 10 seconds
- Result size: Large results are truncated. To see specific rows, add a
LIMITclause or refine your query.
- Encrypted connections: All database connections use SSL/TLS encryption.
- Rate limiting: 15 query executions every 10 seconds per user per service; one AI request every two seconds per user per service.
Network access requirements
Your IP address must be in the service's IP allowlist. PG Studio validates your browser's IP address, which must be allowed in the service's IP filter configuration.
If you get the Access is not allowed from the IP address error, add your IP address to
the allowlist.
Required permissions
To use PG Studio, you need the service:data:write and service:secrets:read
permissions at the organization, unit, or project level. These permissions are included
in the Admin, Developer, and Operator roles.
Manage PG Studio and AI features
PG Studio and its AI features are on by default for all organizations and apply to all projects in your organization. Aiven manages these controls, so you cannot change them yourself. The two controls are independent, so you can turn either one off or on without affecting the other. To change either setting, contact the Aiven support team.
Related pages