Wiki / Authentication Methods
Authentication Methods
Compare versionsClient authentication methods, configuration, requirements and version-specific behavior.
Reading PostgreSQL 18.6.
15 entries; 15 recorded in PostgreSQL 18.6.
-
bsd Authentication and access control
Authenticate using the BSD Authentication service provided by the operating system. See Section 20.14 for details.
-
cert Authentication and access control
Authenticate using SSL client certificates. See Section 20.12 for details.
-
gss Authentication and access control
Use GSSAPI to authenticate the user. This is only available for TCP/IP connections. See Section 20.6 for details. It can be used in conjunction with GSSAPI encryption.
-
ident Authentication and access control
Obtain the operating system user name of the client by contacting the ident server on the client and check if it matches the requested database user name. Ident authentication can only be used on TCP/IP connections. When specified for local connecti…
-
ldap Authentication and access control
Authenticate using an LDAP server. See Section 20.10 for details.
-
oauth Authentication and access control
Authorize and optionally authenticate using a third-party OAuth 2.0 identity provider. See Section 20.15 for details.
-
pam Authentication and access control
Authenticate using the Pluggable Authentication Modules (PAM) service provided by the operating system. See Section 20.13 for details.
-
peer Authentication and access control
Obtain the client's operating system user name from the operating system and check if it matches the requested database user name. This is only available for local connections. See Section 20.9 for details.
-
radius Authentication and access control
Authenticate using a RADIUS server. See Section 20.11 for details.
-
reject Authentication and access control
Reject the connection unconditionally. This is useful for “ filtering out ” certain hosts from a group, for example a reject line could block a specific host from connecting, while a later line allows the remaining hosts in a specific network to con…
-
sspi Authentication and access control
Use SSPI to authenticate the user. This is only available on Windows. See Section 20.7 for details.
-
trust Authentication and access control
Allow the connection unconditionally. This method allows anyone that can connect to the PostgreSQL database server to login as any PostgreSQL user they wish, without the need for a password or any other authentication. See Section 20.4 for details.
-
md5 Password authentication
Perform SCRAM-SHA-256 or MD5 authentication to verify the user's password. See Section 20.5 for details. Warning Support for MD5-encrypted passwords is deprecated and will be removed in a future release of PostgreSQL . Refer to Section 20.5 for deta…
-
password Password authentication
Require the client to supply an unencrypted password for authentication. Since the password is sent in clear text over the network, this should not be used on untrusted networks. See Section 20.5 for details.
-
scram-sha-256 Password authentication
Perform SCRAM-SHA-256 authentication to verify the user's password. See Section 20.5 for details.
RecordedFirst recordedInterface or attribute changeNo longer recorded
Squares indicate presence in sampled builds, not first introduction. Select a square for the same-version definition and sources.
Changes in PostgreSQL 18.6 · Export JSON
Reading this collection
Authentication methods are reconciled with same-version server source and HBA documentation. Availability, transport requirements and credential handling depend on the method and build.