Skip to main content

Security and connections in PG Studio

Learn how PG Studio connects to your database and ensures safe, controlled access.

Database connection details​

PG Studio connects to your PostgreSQL service using:

  • Database user: The avnadmin user account, which has full read and write access to your databases. You can run SQL statements through the SQL editor.
  • Access scope: Full database access with the same privileges as the avnadmin user. This is not limited to read-only access.

Security safeguards​

PG Studio ensures safe, controlled access:

For AI query generation scope, see How AI assistance works.

  • Restricted unsafe requests: Requests for privilege escalation or malicious SQL are blocked.
  • Timeouts and limits:
    • Statement timeout: 30 seconds
    • Lock timeout: 10 seconds
    • Connection timeout: 10 seconds
    • Result size: Large results are truncated. To see specific rows, add a LIMIT clause or refine your query.
  • Encrypted connections: All database connections use SSL/TLS encryption.
  • Rate limiting: 15 query executions every 10 seconds per user per service; one AI request every two seconds per user per service.

Network access requirements​

Your IP address must be in the service's IP allowlist. PG Studio validates your browser's IP address, which must be allowed in the service's IP filter configuration.

If you get the Access is not allowed from the IP address error, add your IP address to the allowlist.

Required permissions​

To use PG Studio, you need the service:data:write and service:secrets:read permissions at the organization, unit, or project level. These permissions are included in the Admin, Developer, and Operator roles.

Manage PG Studio and AI features​

PG Studio and its AI features are on by default for all organizations and apply to all projects in your organization. Aiven manages these controls, so you cannot change them yourself. The two controls are independent, so you can turn either one off or on without affecting the other. To change either setting, contact the Aiven support team.

Related pages