{"Entry":{"collection":"conn","key":"oauth-issuer","name":"oauth_issuer","aliases":["oauth_issuer"],"metadata":{"aliases":["oauth_issuer"],"category":"Authentication","content_hash":"4bf7411991e894cdddfbd8ddd85ecc54313ed982f5d0248011abf1b0da0d54fe","imported_at":"2026-09-30T00:40:34.991254+08:00","name":"oauth_issuer","name_zh":"","slug":"oauth-issuer","summary":"The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration ."}},"Definition":{"Collection":"conn","Key":"oauth-issuer","SourceDatabase":"center","Version":"18","SourceTable":"connection_parameter","SourceKey":"oauth-issuer","SourceRevision":"ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8","Facts":{"comparison_data":{"compiled_default_expression":"NULL","default_evidence":["You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:"],"definition":"The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration . As part of the standard authentication handshake, libpq will ask the server for a discovery document: a URL providing a set of OAuth configuration parameters. The server must provide a URL that is directly constructed from the components of the oauth_issuer , and this value must exactly match the issuer identifier that is declared in the discovery document itself, or the connection will fail. This is required to prevent a class of \"mix-up attacks\" on OAuth clients. You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints: /.well-known/openid-configuration /.well-known/oauth-authorization-server Warning Issuers are highly privileged during the OAuth connection handshake. As a rule of thumb, if you would not trust the operator of a URL to handle access to your servers, or to impersonate you directly, that URL should not be trusted as an oauth_issuer .","documented":true,"environment":"","keyword":"oauth_issuer"},"comparison_hash":"9afc5e8603b6a862d897284099f310b696b3365ecc6dbb724802de062d37fa13","default_evidence":["You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:"],"description":["The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration ."],"documented":true,"environment":[],"facts":[{"label":"Client library","value":"libpq 18.6"},{"label":"Manual definition","value":"Documented"},{"label":"Source environment fallback","value":"None declared in the option table"},{"label":"Compiled fallback expression","value":"NULL"}],"keyword":"oauth_issuer","manual_html":"\u003cdiv\u003e\u003cdl class=\"variablelist\"\u003e\u003cdt id=\"LIBPQ-CONNECT-OAUTH-ISSUER\"\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eoauth_issuer\u003c/code\u003e\u003c/span\u003e \u003c/dt\u003e\u003cdd\u003e\n\u003cp\u003eThe HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the \u003ccode class=\"literal\"\u003eissuer\u003c/code\u003e setting in \u003ca class=\"link\" href=\"/docs/18/auth-oauth.html\" title=\"20.15. OAuth Authorization/Authentication\"\u003ethe server's HBA configuration\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eAs part of the standard authentication handshake, \u003cspan class=\"application\"\u003elibpq\u003c/span\u003e will ask the server for a \u003cspan class=\"emphasis\"\u003e\u003cem\u003ediscovery document:\u003c/em\u003e\u003c/span\u003e a URL providing a set of OAuth configuration parameters. The server must provide a URL that is directly constructed from the components of the \u003ccode class=\"literal\"\u003eoauth_issuer\u003c/code\u003e, and this value must exactly match the issuer identifier that is declared in the discovery document itself, or the connection will fail. This is required to prevent a class of \u003ca class=\"ulink\" href=\"https://mailarchive.ietf.org/arch/msg/oauth/JIVxFBGsJBVtm7ljwJhPUm3Fr-w/\"\u003e\"mix-up attacks\"\u003c/a\u003e on OAuth clients.\u003c/p\u003e\n\u003cp\u003eYou may also explicitly set \u003ccode class=\"literal\"\u003eoauth_issuer\u003c/code\u003e to the \u003ccode class=\"literal\"\u003e/.well-known/\u003c/code\u003e URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a \u003ca class=\"link\" href=\"/docs/18/libpq-oauth.html#LIBPQ-OAUTH-AUTHDATA-HOOKS\" title=\"32.20.1. Authdata Hooks\"\u003ecustom OAuth flow\u003c/a\u003e may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that \u003ca class=\"xref\" href=\"/docs/18/libpq-connect.html#LIBPQ-CONNECT-OAUTH-SCOPE\"\u003eoauth_scope\u003c/a\u003e be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) \u003cspan class=\"application\"\u003elibpq\u003c/span\u003e currently supports the following well-known endpoints:\u003c/p\u003e\n\u003cdiv class=\"itemizedlist\"\u003e\n\u003cul class=\"itemizedlist compact\"\u003e\n\u003cli class=\"listitem\"\u003e\n\u003cp\u003e\u003ccode class=\"literal\"\u003e/.well-known/openid-configuration\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli class=\"listitem\"\u003e\n\u003cp\u003e\u003ccode class=\"literal\"\u003e/.well-known/oauth-authorization-server\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/div\u003e\n\u003cdiv class=\"warning\"\u003e\n\u003ch3 class=\"title\"\u003eWarning\u003c/h3\u003e\n\u003cp\u003eIssuers are highly privileged during the OAuth connection handshake. As a rule of thumb, if you would not trust the operator of a URL to handle access to your servers, or to impersonate you directly, that URL should not be trusted as an \u003ccode class=\"literal\"\u003eoauth_issuer\u003c/code\u003e.\u003c/p\u003e\n\u003c/div\u003e\n\u003c/dd\u003e\u003c/dl\u003e\u003c/div\u003e","manual_path":"libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER","precedence_evidence":["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.","Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .","Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."],"related":[{"label":"Connection service file","url":"/docs/18/libpq-pgservice.html"},{"label":"Password file","url":"/docs/18/libpq-pgpass.html"},{"label":"All libpq environment variables","url":"/docs/18/libpq-envars.html"}],"release":{"channel":"stable","evidence_kind":"English manual and source declarations","label":"18.6","major":"18","manifest":{"index":"index.html","major":"18","pages":1148,"pdf":{"A4":{"built_at":"2026-09-26","bytes":15865106,"pages":3154,"sha256":"19512c405da53f9f7fcf0abba359223aa65f021be025bf3411381918f92e3190","url":"/files/documentation/pdf/18/postgresql-18-A4.pdf"},"US":{"built_at":"2026-09-26","bytes":15748059,"pages":3328,"sha256":"facbe6c229e598b872d3d98bef53308f46e06746006fa4590de9a7de9dd46319","url":"/files/documentation/pdf/18/postgresql-18-US.pdf"}},"release":"18.6","source_mode":"en SGML built with pinned official archive","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","source_url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","svg_assets":3,"tree":"18"},"ref":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","revision":"ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"},"sections":[{"paragraphs":["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.","Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .","Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."],"title":"Default resolution and service-file precedence"},{"paragraphs":[],"title":"Environment variable evidence"}],"signature":"oauth_issuer","source_option":{"compiled_default_expression":"NULL","declaration":"\"oauth_issuer\", NULL, NULL, NULL, \"OAuth-Issuer\", \"\", 40, offsetof(struct pg_conn, oauth_issuer)","environment":"","keyword":"oauth_issuer","source_notes":[]},"sources":[{"anchor":"LIBPQ-CONNECT-OAUTH-ISSUER","file":"libpq-connect.html","label":"18.6 English manual · libpq-connect.html","sha256":"c26a7fc3dcda6066cfe540641ae2690faf3d3c03277f30b4dfc2328ab45c212f","url":"/docs/18/libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER"},{"archive_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","file":"src/interfaces/libpq/fe-connect.c","label":"18.6 libpq connection option declarations","sha256":"44a6e386cbfd67ebe768d6ef5493098119c2e6b4796239d53e5ed7b122b206a5","url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2"},{"anchor":"","file":"libpq-envars.html","label":"18.6 English manual · libpq-envars.html","sha256":"d64db73f3d48127bb984a5f775e77b7bcca2ba4bd218333cf24a45fcdd7c4363","url":"/docs/18/libpq-envars.html"},{"anchor":"","file":"libpq-pgservice.html","label":"18.6 English manual · libpq-pgservice.html","sha256":"6035a3f0ee1d0fd80db5bf58834390b884eecd23206659bdf6f07560deea5aa7","url":"/docs/18/libpq-pgservice.html"}],"tables":[]},"ManualEvidence":{"manual_path":"libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER","release":{"channel":"stable","evidence_kind":"English manual and source declarations","label":"18.6","major":"18","manifest":{"index":"index.html","major":"18","pages":1148,"pdf":{"A4":{"built_at":"2026-09-26","bytes":15865106,"pages":3154,"sha256":"19512c405da53f9f7fcf0abba359223aa65f021be025bf3411381918f92e3190","url":"/files/documentation/pdf/18/postgresql-18-A4.pdf"},"US":{"built_at":"2026-09-26","bytes":15748059,"pages":3328,"sha256":"facbe6c229e598b872d3d98bef53308f46e06746006fa4590de9a7de9dd46319","url":"/files/documentation/pdf/18/postgresql-18-US.pdf"}},"release":"18.6","source_mode":"en SGML built with pinned official archive","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","source_url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","svg_assets":3,"tree":"18"},"ref":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","revision":"ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"},"sources":[{"anchor":"LIBPQ-CONNECT-OAUTH-ISSUER","file":"libpq-connect.html","label":"18.6 English manual · libpq-connect.html","sha256":"c26a7fc3dcda6066cfe540641ae2690faf3d3c03277f30b4dfc2328ab45c212f","url":"/docs/18/libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER"},{"archive_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","file":"src/interfaces/libpq/fe-connect.c","label":"18.6 libpq connection option declarations","sha256":"44a6e386cbfd67ebe768d6ef5493098119c2e6b4796239d53e5ed7b122b206a5","url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2"},{"anchor":"","file":"libpq-envars.html","label":"18.6 English manual · libpq-envars.html","sha256":"d64db73f3d48127bb984a5f775e77b7bcca2ba4bd218333cf24a45fcdd7c4363","url":"/docs/18/libpq-envars.html"},{"anchor":"","file":"libpq-pgservice.html","label":"18.6 English manual · libpq-pgservice.html","sha256":"6035a3f0ee1d0fd80db5bf58834390b884eecd23206659bdf6f07560deea5aa7","url":"/docs/18/libpq-pgservice.html"}]},"MeasuredEvidence":{}},"Text":{"Collection":"conn","Key":"oauth-issuer","SourceDatabase":"center","Version":"18","Locale":"en","Title":"oauth_issuer","Summary":"The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration .","BodyHTML":"\u003cdiv\u003e\u003cdl\u003e\u003cdt id=\"LIBPQ-CONNECT-OAUTH-ISSUER\"\u003e\u003cspan\u003e\u003ccode\u003eoauth_issuer\u003c/code\u003e\u003c/span\u003e \u003c/dt\u003e\u003cdd\u003e\n\u003cp\u003eThe HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the \u003ccode\u003eissuer\u003c/code\u003e setting in \u003ca href=\"/docs/18/auth-oauth.html\" rel=\"nofollow\"\u003ethe server\u0026#39;s HBA configuration\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eAs part of the standard authentication handshake, \u003cspan\u003elibpq\u003c/span\u003e will ask the server for a \u003cspan\u003e\u003cem\u003ediscovery document:\u003c/em\u003e\u003c/span\u003e a URL providing a set of OAuth configuration parameters. The server must provide a URL that is directly constructed from the components of the \u003ccode\u003eoauth_issuer\u003c/code\u003e, and this value must exactly match the issuer identifier that is declared in the discovery document itself, or the connection will fail. This is required to prevent a class of \u003ca href=\"https://mailarchive.ietf.org/arch/msg/oauth/JIVxFBGsJBVtm7ljwJhPUm3Fr-w/\" rel=\"nofollow\"\u003e\u0026#34;mix-up attacks\u0026#34;\u003c/a\u003e on OAuth clients.\u003c/p\u003e\n\u003cp\u003eYou may also explicitly set \u003ccode\u003eoauth_issuer\u003c/code\u003e to the \u003ccode\u003e/.well-known/\u003c/code\u003e URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a \u003ca href=\"/docs/18/libpq-oauth.html#LIBPQ-OAUTH-AUTHDATA-HOOKS\" rel=\"nofollow\"\u003ecustom OAuth flow\u003c/a\u003e may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that \u003ca href=\"/docs/18/libpq-connect.html#LIBPQ-CONNECT-OAUTH-SCOPE\" rel=\"nofollow\"\u003eoauth_scope\u003c/a\u003e be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) \u003cspan\u003elibpq\u003c/span\u003e currently supports the following well-known endpoints:\u003c/p\u003e\n\u003cdiv\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003e/.well-known/openid-configuration\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003e/.well-known/oauth-authorization-server\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/div\u003e\n\u003cdiv\u003e\n\u003ch3\u003eWarning\u003c/h3\u003e\n\u003cp\u003eIssuers are highly privileged during the OAuth connection handshake. As a rule of thumb, if you would not trust the operator of a URL to handle access to your servers, or to impersonate you directly, that URL should not be trusted as an \u003ccode\u003eoauth_issuer\u003c/code\u003e.\u003c/p\u003e\n\u003c/div\u003e\n\u003c/dd\u003e\u003c/dl\u003e\u003c/div\u003e","SourceRevision":"ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8","ContentHash":"15e0c1b4efcaa2594c6947f8fb830e1582a79c995b975fbb640d9a20862513ba","Payload":{"description":["The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration ."],"manual_html":"\u003cdiv\u003e\u003cdl class=\"variablelist\"\u003e\u003cdt id=\"LIBPQ-CONNECT-OAUTH-ISSUER\"\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eoauth_issuer\u003c/code\u003e\u003c/span\u003e \u003c/dt\u003e\u003cdd\u003e\n\u003cp\u003eThe HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the \u003ccode class=\"literal\"\u003eissuer\u003c/code\u003e setting in \u003ca class=\"link\" href=\"/docs/18/auth-oauth.html\" title=\"20.15. OAuth Authorization/Authentication\"\u003ethe server's HBA configuration\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eAs part of the standard authentication handshake, \u003cspan class=\"application\"\u003elibpq\u003c/span\u003e will ask the server for a \u003cspan class=\"emphasis\"\u003e\u003cem\u003ediscovery document:\u003c/em\u003e\u003c/span\u003e a URL providing a set of OAuth configuration parameters. The server must provide a URL that is directly constructed from the components of the \u003ccode class=\"literal\"\u003eoauth_issuer\u003c/code\u003e, and this value must exactly match the issuer identifier that is declared in the discovery document itself, or the connection will fail. This is required to prevent a class of \u003ca class=\"ulink\" href=\"https://mailarchive.ietf.org/arch/msg/oauth/JIVxFBGsJBVtm7ljwJhPUm3Fr-w/\"\u003e\"mix-up attacks\"\u003c/a\u003e on OAuth clients.\u003c/p\u003e\n\u003cp\u003eYou may also explicitly set \u003ccode class=\"literal\"\u003eoauth_issuer\u003c/code\u003e to the \u003ccode class=\"literal\"\u003e/.well-known/\u003c/code\u003e URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a \u003ca class=\"link\" href=\"/docs/18/libpq-oauth.html#LIBPQ-OAUTH-AUTHDATA-HOOKS\" title=\"32.20.1. Authdata Hooks\"\u003ecustom OAuth flow\u003c/a\u003e may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that \u003ca class=\"xref\" href=\"/docs/18/libpq-connect.html#LIBPQ-CONNECT-OAUTH-SCOPE\"\u003eoauth_scope\u003c/a\u003e be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) \u003cspan class=\"application\"\u003elibpq\u003c/span\u003e currently supports the following well-known endpoints:\u003c/p\u003e\n\u003cdiv class=\"itemizedlist\"\u003e\n\u003cul class=\"itemizedlist compact\"\u003e\n\u003cli class=\"listitem\"\u003e\n\u003cp\u003e\u003ccode class=\"literal\"\u003e/.well-known/openid-configuration\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli class=\"listitem\"\u003e\n\u003cp\u003e\u003ccode class=\"literal\"\u003e/.well-known/oauth-authorization-server\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/div\u003e\n\u003cdiv class=\"warning\"\u003e\n\u003ch3 class=\"title\"\u003eWarning\u003c/h3\u003e\n\u003cp\u003eIssuers are highly privileged during the OAuth connection handshake. As a rule of thumb, if you would not trust the operator of a URL to handle access to your servers, or to impersonate you directly, that URL should not be trusted as an \u003ccode class=\"literal\"\u003eoauth_issuer\u003c/code\u003e.\u003c/p\u003e\n\u003c/div\u003e\n\u003c/dd\u003e\u003c/dl\u003e\u003c/div\u003e","related":[{"label":"Connection service file","url":"/docs/18/libpq-pgservice.html"},{"label":"Password file","url":"/docs/18/libpq-pgpass.html"},{"label":"All libpq environment variables","url":"/docs/18/libpq-envars.html"}],"sections":[{"paragraphs":["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.","Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .","Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."],"title":"Default resolution and service-file precedence"},{"paragraphs":[],"title":"Environment variable evidence"}],"tables":[]}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["18","19","20"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
