Wiki / Connection Parameters / Authentication
passfile
Specifies the name of the file used to store passwords (see Section 32.16 ). Defaults to ~/.pgpass , or %APPDATA%\postgresql\pgpass.conf on Microsoft Windows. (No error is reported if this file does not exist.)
Reading PostgreSQL 18.6.
Description
Specifies the name of the file used to store passwords (see Section 32.16 ). Defaults to ~/.pgpass , or %APPDATA%\postgresql\pgpass.conf on Microsoft Windows. (No error is reported if this file does not exist.)
- Client library
- libpq 18.6
- Manual definition
- Documented
- Source environment fallback
- PGPASSFILE
- Compiled fallback expression
- NULL
Usage
passfileDefault resolution and service-file precedence
The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.
Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\postgresql\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .
Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.
Environment variable evidence
PGPASSFILE behaves the same as the passfile connection parameter.
Environment fallback
| Variable | Documented behavior |
|---|---|
| PGPASSFILE | PGPASSFILE behaves the same as the passfile connection parameter. |
Manual definition
passfile-
Specifies the name of the file used to store passwords (see Section 32.16). Defaults to
~/.pgpass, or%APPDATA%\postgresql\pgpass.confon Microsoft Windows. (No error is reported if this file does not exist.)
32.16. The Password File
The file .pgpass in a user's home directory can contain passwords to be used if the connection requires a password (and no password has been specified otherwise). On Unix systems, the directory can be specified by the HOME environment variable, or if undefined, the home directory of the effective user. On Microsoft Windows the file is named %APPDATA%\postgresql\pgpass.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). Alternatively, the password file to use can be specified using the connection parameter passfile or the environment variable PGPASSFILE.
This file should contain lines of the following format:
hostname:port:database:username:password
(You can add a reminder comment to the file by copying the line above and preceding it with #.) Each of the first four fields can be a literal value, or *, which matches anything. The password field from the first line that matches the current connection parameters will be used. (Therefore, put more-specific entries first when you are using wildcards.) If an entry needs to contain : or \, escape this character with \. The host name field is matched to the host connection parameter if that is specified, otherwise to the hostaddr parameter if that is specified; if neither are given then the host name localhost is searched for. The host name localhost is also searched for when the connection is a Unix-domain socket connection and the host parameter matches libpq's default socket directory path. In a standby server, a database field of replication matches streaming replication connections made to the primary server. The database field is of limited usefulness otherwise, because users have the same password for all databases in the same cluster.
On Unix systems, the permissions on a password file must disallow any access to world or group; achieve this by a command such as chmod 0600 ~/.pgpass. If the permissions are less strict than this, the file will be ignored. On Microsoft Windows, it is assumed that the file is stored in a directory that is secure, so no special permissions check is made.
Related entries
Documentation and source
- 18.6 English manual · libpq-connect.html
- 18.6 libpq connection option declarations
- 18.6 English manual · libpq-envars.html
- 18.6 English manual · libpq-pgservice.html
- 18.6 English manual · libpq-pgpass.html
Source build
- Version
- 18.6
- Build
- https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2
- Source fingerprint
ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8
Compare versions
PostgreSQL 10 → 11: changed.
--- PostgreSQL 10
+++ PostgreSQL 11
@@ -1,7 +1,7 @@
{
"compiled_default_expression": "NULL",
"default_evidence": [],
- "definition": "Specifies the name of the file used to store passwords (see Section 33.15 ). Defaults to ~/.pgpass , or %APPDATA%\\postgresql\\pgpass.conf on Microsoft Windows. (No error is reported if this file does not exist.)",
+ "definition": "Specifies the name of the file used to store passwords (see Section 34.15 ). Defaults to ~/.pgpass , or %APPDATA%\\postgresql\\pgpass.conf on Microsoft Windows. (No error is reported if this file does not exist.)",
"documented": true,
"environment": "PGPASSFILE",
"keyword": "passfile"
Compares recorded interfaces and attributes. Source fingerprints and build metadata are excluded; an absent sample is not proof of the introduction or removal release.
Related entries
Export JSON · Back to Connection Parameters · Recorded in PostgreSQL 10 through 20; the first sample is not necessarily its introduction.