1
Create a role for the gateway, with SQL
In Neon, open SQL Editor, pick the branch and database, replace the
placeholder with a strong password, and run:This role can only read. To let agents write, see letting agents
write.
Create it here, not under Roles in the console: roles made there join
neon_superuser, which can do far more than read.2
Copy the direct connection string
Click Connect on the project’s dashboard, choose the branch and
database, and turn Connection pooling off. Copy the string; it looks
like:The gateway pools its own connections, so it doesn’t need Neon’s.
3
Write the gateway's connection string
Swap in the role and its password, and make the end Neon’s certificates come from a public CA, so nothing else is needed. Save
the line as
sslmode=verify-full:secrets/<database id>.dsn, such as secrets/shop.dsn.4
Check that it connects
Start or restart the gateway. Test connection on the Gateways page
shows your database’s id with
ok, such as shop ok, and the policy
editor lists your tables.Good to know
- Branches. Point the gateway at a branch instead of
main: agents get real data, and nothing they change reaches production. - Autosuspend. A compute that scaled to zero takes a moment to wake. If
that takes over 10 seconds, the first attempt fails with
TIMEOUTand the next one connects. - IP Allow. If it’s on, add the address the gateway connects from.