{"Entry":{"collection":"catalog","key":"pg_authid","name":"pg_authid","aliases":[],"metadata":{"changed_in":["9.0","9.1","9.5","12"],"changes":[{"added":[],"attributes":[],"description_changed":false,"descriptions":[],"from":"8.0","order":false,"removed":[],"status":"added","to":"8.1","types":[]},{"added":[],"attributes":[],"description_changed":false,"descriptions":[{"from":"Role may log in, that is, this role can be given as the initial session authorization identifier.","name":"rolcanlogin","to":"Role may log in. That is, this role can be given as the initial session authorization identifier"},{"from":"Role may update system catalogs directly. (Even a superuser may not do this unless this column is true.)","name":"rolcatupdate","to":"Role may update system catalogs directly. (Even a superuser may not do this unless this column is true)"},{"from":"For roles that can log in, this sets maximum number of concurrent connections this role can make. -1 means no limit.","name":"rolconnlimit","to":"For roles that can log in, this sets maximum number of concurrent connections this role can make. -1 means no limit"}],"from":"8.1","listing":[],"order":false,"removed":[],"status":"reworded","to":"8.2","types":[],"unlisted":[]},{"added":[],"attributes":[],"description_changed":true,"descriptions":[{"from":"Role may log in. That is, this role can be given as the initial session authorization identifier","name":"rolcanlogin","to":"Role can log in. That is, this role can be given as the initial session authorization identifier"},{"from":"Role may update system catalogs directly. (Even a superuser may not do this unless this column is true)","name":"rolcatupdate","to":"Role can update system catalogs directly. (Even a superuser cannot do this unless this column is true)"},{"from":"Role may create databases","name":"rolcreatedb","to":"Role can create databases"},{"from":"Role may create more roles","name":"rolcreaterole","to":"Role can create more roles"}],"from":"8.2","listing":[],"order":false,"removed":[],"status":"reworded","to":"8.3","types":[],"unlisted":[]},{"added":[],"attributes":[],"description_changed":true,"descriptions":[],"from":"8.3","listing":[],"order":false,"removed":[],"status":"reworded","to":"8.4","types":[],"unlisted":[]},{"added":[],"attributes":[],"description_changed":false,"descriptions":[{"from":"For roles that can log in, this sets maximum number of concurrent connections this role can make. -1 means no limit","name":"rolconnlimit","to":"For roles that can log in, this sets maximum number of concurrent connections this role can make. -1 means no limit."},{"from":"Password (possibly encrypted); NULL if none","name":"rolpassword","to":"Password (possibly encrypted); null if none. If the password is encrypted, this column will contain the string md5 followed by a 32-character hexadecimal MD5 hash. The MD5 hash will be of the user's password concatenated to their username (for example, if user joe has password xyzzy, PostgreSQL will store the md5 hash of xyzzyjoe)."},{"from":"Password expiry time (only used for password authentication); NULL if no expiration","name":"rolvaliduntil","to":"Password expiry time (only used for password authentication); null if no expiration"}],"from":"8.4","listing":[],"order":false,"removed":["rolconfig"],"status":"changed","to":"9.0","types":[],"unlisted":[]},{"added":["rolreplication"],"attributes":[],"description_changed":false,"descriptions":[{"from":"Password (possibly encrypted); null if none. If the password is encrypted, this column will contain the string md5 followed by a 32-character hexadecimal MD5 hash. The MD5 hash will be of the user's password concatenated to their username (for example, if user joe has password xyzzy, PostgreSQL will store the md5 hash of xyzzyjoe).","name":"rolpassword","to":"Password (possibly encrypted); null if none. If the password is encrypted, this column will begin with the string md5 followed by a 32-character hexadecimal MD5 hash. The MD5 hash will be of the user's password concatenated to their user name. For example, if user joe has password xyzzy, PostgreSQL will store the md5 hash of xyzzyjoe. A password that does not follow that format is assumed to be unencrypted."}],"from":"9.0","listing":[],"order":false,"removed":[],"status":"changed","to":"9.1","types":[],"unlisted":[]},{"added":["rolbypassrls"],"attributes":[],"description_changed":false,"descriptions":[{"from":"Role can log in. That is, this role can be given as the initial session authorization identifier","name":"rolcanlogin","to":"Role can log in. That is, this role can be given as the initial session authorization identifier."}],"from":"9.4","listing":[],"order":false,"removed":["rolcatupdate"],"status":"changed","to":"9.5","types":[],"unlisted":[]},{"added":[],"attributes":[],"description_changed":true,"descriptions":[{"from":"Role is a replication role. That is, this role can initiate streaming replication (see Section 25.2.5) and set/unset the system backup mode using pg_start_backup and pg_stop_backup","name":"rolreplication","to":"Role is a replication role. A replication role can initiate replication connections and create and drop replication slots."}],"from":"9.5","listing":[],"order":false,"removed":[],"status":"reworded","to":"9.6","types":[],"unlisted":[]},{"added":[],"attributes":[],"description_changed":true,"descriptions":[{"from":"Password (possibly encrypted); null if none. If the password is encrypted, this column will begin with the string md5 followed by a 32-character hexadecimal MD5 hash. The MD5 hash will be of the user's password concatenated to their user name. For example, if user joe has password xyzzy, PostgreSQL will store the md5 hash of xyzzyjoe. A password that does not follow that format is assumed to be unencrypted.","name":"rolpassword","to":"Password (possibly encrypted); null if none. The format depends on the form of encryption used."}],"from":"9.6","listing":[],"order":false,"removed":[],"status":"reworded","to":"10","types":[],"unlisted":[]},{"added":[],"attributes":[{"attribute":"hidden","from":true,"name":"oid","to":false}],"description_changed":false,"descriptions":[{"from":"Role bypasses every row level security policy, see Section 5.7 for more information.","name":"rolbypassrls","to":"Role bypasses every row level security policy, see Section 5.8 for more information."}],"from":"11","listing":[],"order":false,"removed":[],"status":"changed","to":"12","types":[],"unlisted":[]},{"added":[],"attributes":[],"description_changed":false,"descriptions":[{"from":"Password (possibly encrypted); null if none. The format depends on the form of encryption used.","name":"rolpassword","to":"Encrypted password; null if none. The format depends on the form of encryption used."}],"from":"12","listing":[],"order":false,"removed":[],"status":"reworded","to":"13","types":[],"unlisted":[]},{"added":[],"attributes":[],"description_changed":true,"descriptions":[{"from":"Role bypasses every row level security policy, see Section 5.8 for more information.","name":"rolbypassrls","to":"Role bypasses every row-level security policy, see Section 5.8 for more information."}],"from":"13","listing":[],"order":false,"removed":[],"status":"reworded","to":"14","types":[],"unlisted":[]},{"added":[],"attributes":[],"description_changed":true,"descriptions":[{"from":"Role bypasses every row-level security policy, see Section 5.8 for more information.","name":"rolbypassrls","to":"Role bypasses every row-level security policy, see Section 5.9 for more information."}],"from":"16","listing":[],"order":false,"removed":[],"status":"reworded","to":"17","types":[],"unlisted":[]},{"added":[],"attributes":[],"description_changed":false,"descriptions":[{"from":"Role bypasses every row-level security policy, see Section 5.9 for more information.","name":"rolbypassrls","to":"Role bypasses every row-level security policy, see Section 5.10 for more information."}],"from":"18","listing":[],"order":false,"removed":[],"status":"reworded","to":"19","types":[],"unlisted":[]}],"column_count":12,"content_hash":"0635a076f5366d0dbc0aed5b6ddd99df9ad1d23fa2fac4d40a6c763d8733a1d6","first_version":"8.1","imported_at":"2026-09-30T00:40:55.37468+08:00","kind":"catalog","last_version":"20","name":"pg_authid","position":8,"present_in":["8.1","8.2","8.3","8.4","9.0","9.1","9.2","9.3","9.4","9.5","9.6","10","11","12","13","14","15","16","17","18","19","20"],"relation_oid":null,"relkind":"r","shared":false,"source_rev":"english-manuals:94044086a436950d19e247c1dba5cdcee0d425e806f67cdf1ddf5d84ac1515a3","summary":"The catalog pg_authid contains information about database authorization identifiers (roles).","summary_zh":""}},"Definition":{"Collection":"catalog","Key":"pg_authid","SourceDatabase":"center","Version":"18","SourceTable":"catalog","SourceKey":"pg_authid","SourceRevision":"english-manuals:94044086a436950d19e247c1dba5cdcee0d425e806f67cdf1ddf5d84ac1515a3","Facts":{"columns":[{"array_dimensions":0,"attnum":1,"description":"Row identifier","description_zh":"","documented":true,"documented_name":"oid","hidden":false,"name":"oid","not_null":true,"references":"","type":"oid","type_modifier":-1,"type_oid":26},{"array_dimensions":0,"attnum":2,"description":"Role name","description_zh":"","documented":true,"documented_name":"rolname","hidden":false,"name":"rolname","not_null":true,"references":"","type":"name","type_modifier":-1,"type_oid":19},{"array_dimensions":0,"attnum":3,"description":"Role has superuser privileges","description_zh":"","documented":true,"documented_name":"rolsuper","hidden":false,"name":"rolsuper","not_null":true,"references":"","type":"bool","type_modifier":-1,"type_oid":16},{"array_dimensions":0,"attnum":4,"description":"Role automatically inherits privileges of roles it is a member of","description_zh":"","documented":true,"documented_name":"rolinherit","hidden":false,"name":"rolinherit","not_null":true,"references":"","type":"bool","type_modifier":-1,"type_oid":16},{"array_dimensions":0,"attnum":5,"description":"Role can create more roles","description_zh":"","documented":true,"documented_name":"rolcreaterole","hidden":false,"name":"rolcreaterole","not_null":true,"references":"","type":"bool","type_modifier":-1,"type_oid":16},{"array_dimensions":0,"attnum":6,"description":"Role can create databases","description_zh":"","documented":true,"documented_name":"rolcreatedb","hidden":false,"name":"rolcreatedb","not_null":true,"references":"","type":"bool","type_modifier":-1,"type_oid":16},{"array_dimensions":0,"attnum":7,"description":"Role can log in. That is, this role can be given as the initial session authorization identifier.","description_zh":"","documented":true,"documented_name":"rolcanlogin","hidden":false,"name":"rolcanlogin","not_null":true,"references":"","type":"bool","type_modifier":-1,"type_oid":16},{"array_dimensions":0,"attnum":8,"description":"Role is a replication role. A replication role can initiate replication connections and create and drop replication slots.","description_zh":"","documented":true,"documented_name":"rolreplication","hidden":false,"name":"rolreplication","not_null":true,"references":"","type":"bool","type_modifier":-1,"type_oid":16},{"array_dimensions":0,"attnum":9,"description":"Role bypasses every row-level security policy, see Section 5.9 for more information.","description_zh":"","documented":true,"documented_name":"rolbypassrls","hidden":false,"name":"rolbypassrls","not_null":true,"references":"","type":"bool","type_modifier":-1,"type_oid":16},{"array_dimensions":0,"attnum":10,"description":"For roles that can log in, this sets maximum number of concurrent connections this role can make. -1 means no limit.","description_zh":"","documented":true,"documented_name":"rolconnlimit","hidden":false,"name":"rolconnlimit","not_null":true,"references":"","type":"int4","type_modifier":-1,"type_oid":23},{"array_dimensions":0,"attnum":11,"description":"Encrypted password; null if none. The format depends on the form of encryption used.","description_zh":"","documented":true,"documented_name":"rolpassword","hidden":false,"name":"rolpassword","not_null":false,"references":"","type":"text","type_modifier":-1,"type_oid":25},{"array_dimensions":0,"attnum":12,"description":"Password expiry time (only used for password authentication); null if no expiration","description_zh":"","documented":true,"documented_name":"rolvaliduntil","hidden":false,"name":"rolvaliduntil","not_null":false,"references":"","type":"timestamptz","type_modifier":-1,"type_oid":1184}],"description":"The catalog pg_authid contains information about database authorization identifiers (roles). A role subsumes the concepts of “users” and “groups”. A user is essentially just a role with the rolcanlogin flag set. Any role (with or without rolcanlogin) can have other roles as members; see pg_auth_members.\n\nSince this catalog contains passwords, it must not be publicly readable. pg_roles is a publicly readable view on pg_authid that blanks out the password field.\n\nChapter 21 contains detailed information about user and privilege management.\n\nBecause user identities are cluster-wide, pg_authid is shared across all databases of a cluster: there is only one copy of pg_authid per cluster, not one per database.","description_zh":"","doc":{"anchor":"id-1.10.4.10.7","file":"catalog-pg-authid.html","lang":"en","sha256":"2c52e24c0da6a23767077e3d11cf82452128ae34c8389f7385caa9c4441a71de","slug":"18"},"kind":"catalog","lang":"en","measured_attributes":true,"metadata_release":"18.6","runtime_columns":["oid","rolname","rolsuper","rolinherit","rolcreaterole","rolcreatedb","rolcanlogin","rolreplication","rolbypassrls","rolconnlimit","rolpassword","rolvaliduntil"],"runtime_verified":false,"source":"english-manual"},"ManualEvidence":{"doc":{"anchor":"id-1.10.4.10.7","file":"catalog-pg-authid.html","lang":"en","sha256":"2c52e24c0da6a23767077e3d11cf82452128ae34c8389f7385caa9c4441a71de","slug":"18"}},"MeasuredEvidence":{"measured_attributes":true,"metadata_release":"18.6","runtime_columns":["oid","rolname","rolsuper","rolinherit","rolcreaterole","rolcreatedb","rolcanlogin","rolreplication","rolbypassrls","rolconnlimit","rolpassword","rolvaliduntil"],"runtime_verified":false}},"Text":{"Collection":"catalog","Key":"pg_authid","SourceDatabase":"pgweb","Version":"18","Locale":"zh-Hans","Title":"pg_authid","Summary":"目录pg_authid包含关于数据库授权标识符（角色）的信息。角色涵盖了“用户”和“组”这两个概念。用户本质上只是设置了rolcanlogin标志的角色。任何角色（无论是否设置了rolcanlogin）都可以拥有其他角色作为成员；参见pg_auth_members。\n\n由于这个目录包含密码，不得允许对它进行公开读取。pg_roles是建立在pg_authid之上的公开可读视图，它会隐藏密码字段。\n\n第 21 章包含关于用户和权限管理的详细信息。\n\n由于用户身份是集簇范围的，pg_authid在一个集簇的所有数据库之间共享：在一个集簇中只有一份pg_authid拷贝，而不是每个数据库一份。","BodyHTML":"\u003cp\u003e目录pg_authid包含关于数据库授权标识符（角色）的信息。角色涵盖了“用户”和“组”这两个概念。用户本质上只是设置了rolcanlogin标志的角色。任何角色（无论是否设置了rolcanlogin）都可以拥有其他角色作为成员；参见pg_auth_members。\n\n由于这个目录包含密码，不得允许对它进行公开读取。pg_roles是建立在pg_authid之上的公开可读视图，它会隐藏密码字段。\n\n第 21 章包含关于用户和权限管理的详细信息。\n\n由于用户身份是集簇范围的，pg_authid在一个集簇的所有数据库之间共享：在一个集簇中只有一份pg_authid拷贝，而不是每个数据库一份。\u003c/p\u003e","SourceRevision":"2026-09-27@419045e","ContentHash":"f93e4958eb6df472832429a451bfa956f854a7805a2974d40d1b81eaa028f8ca","Payload":{"columns":[{"description_zh":"行标识符","name":"oid","type":"oid","zh_from":"doc"},{"description_zh":"角色名","name":"rolname","type":"name","zh_from":"doc"},{"description_zh":"角色有超级用户权限","name":"rolsuper","type":"boolean","zh_from":"doc"},{"description_zh":"该角色是否会自动继承其所属角色的权限","name":"rolinherit","type":"boolean","zh_from":"doc"},{"description_zh":"角色能创建更多角色","name":"rolcreaterole","type":"boolean","zh_from":"doc"},{"description_zh":"角色能创建数据库","name":"rolcreatedb","type":"boolean","zh_from":"doc"},{"description_zh":"角色是否能登录。即该角色是否能够作为初始会话授权标识符","name":"rolcanlogin","type":"boolean","zh_from":"doc"},{"description_zh":"角色是一个复制角色。复制角色可以启动复制连接并且创建和删除复制槽。","name":"rolreplication","type":"boolean","zh_from":"doc"},{"description_zh":"角色是否可以绕过所有的行级安全策略，详见第 5.9 节。","name":"rolbypassrls","type":"boolean","zh_from":"doc"},{"description_zh":"对于可以登录的角色，本列设置该角色能够建立的最大并发连接数。-1 表示无限制。","name":"rolconnlimit","type":"integer","zh_from":"doc"},{"description_zh":"加密后的密码；如果未设置则为 NULL。其格式取决于所使用的加密方式。","name":"rolpassword","type":"text","zh_from":"doc"},{"description_zh":"密码过期时间（仅用于密码认证）；不设过期时间时为 NULL","name":"rolvaliduntil","type":"timestamp with time zone","zh_from":"doc"}],"description_zh":"目录pg_authid包含关于数据库授权标识符（角色）的信息。角色涵盖了“用户”和“组”这两个概念。用户本质上只是设置了rolcanlogin标志的角色。任何角色（无论是否设置了rolcanlogin）都可以拥有其他角色作为成员；参见pg_auth_members。\n\n由于这个目录包含密码，不得允许对它进行公开读取。pg_roles是建立在pg_authid之上的公开可读视图，它会隐藏密码字段。\n\n第 21 章包含关于用户和权限管理的详细信息。\n\n由于用户身份是集簇范围的，pg_authid在一个集簇的所有数据库之间共享：在一个集簇中只有一份pg_authid拷贝，而不是每个数据库一份。","zh_from":"doc"}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["10","11","12","13","14","15","16","17","18","19","20","8.1","8.2","8.3","8.4","9.0","9.1","9.2","9.3","9.4","9.5","9.6"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
