pgAdmin

Web administration for PostgreSQL

Databases & Storage PostgreSQL Intermediate ★ 3,857 stars

What is pgAdmin?

pgAdmin is the full-featured browser client for PostgreSQL: query tool, schema browser, ER diagrams, backup and restore, and server monitoring across multiple connections.

Best for

Working with PostgreSQL from a browser

Why choose pgAdmin

pgAdmin is the official browser client for PostgreSQL, and that provenance matters — it understands the server's features as they are released rather than trailing them. It covers the whole administration surface: a query tool with history and explain output, a schema browser that makes constraints and indexes legible, backup and restore through the native tools, server monitoring, and support for multiple connections in one interface. Because it runs as a web application, the same instance is reachable from any machine on the network, which is useful when the database lives on a server you do not sit at. The ability to generate a DDL script for any object means you can inspect how something is actually defined rather than guessing.

Replaces

  • TablePlus
  • DBeaver
  • DataGrip

Key features

  • Query editor with history and explain plans
  • Schema browser and ER diagram generation
  • Backup, restore and maintenance tasks
  • Manage many servers from one interface

What to watch out for

It is a heavyweight web application, and running it as a permanent service just to occasionally browse a table is more surface area than most people need. The container images have historically required care around the user context and volume permissions, and a misconfigured instance writes files it cannot later read. Exposing it to the internet is dangerous because it holds database credentials, and its own authentication is not designed for public exposure. Import and export operations run through the server's own tools, so the connection user needs appropriate privileges. Its UI changes between major versions, which makes saved links and habits less portable than they look.

How to deploy

  • Docker with server definitions in a config file
  • Set a strong login, this tool is powerful
  • Restrict network access to administrators

Getting started

Run it on an internal network only, behind a reverse proxy with authentication, and never publish the port directly. Configure the master password at startup rather than relying on the default behavior, and connect with an application user rather than the superuser where the work allows. Set the container's user and volume permissions correctly before first run, because these problems surface as opaque write failures later. Register your servers once with saved credentials inside the master password, and confirm a backup and restore cycle works before you need it under pressure. If you only need occasional queries, consider running it on demand instead of permanently.

Typical setup

It runs on an internal network behind a reverse proxy with its own authentication, with the port never published directly. A master password is set at startup, and connections use an application user rather than the superuser wherever the task permits. Container user and volume permissions are configured correctly before the first run, because mistakes there surface later as opaque write failures. Servers are registered with saved credentials, and a backup and restore cycle has been exercised so it is not being learned during an incident. Where use is occasional, it is started on demand rather than left running.

Who should look elsewhere

Do not run it as a public service — the credential exposure is a real risk and there is no reason to accept it. Skip it if your work is mostly automated, since a served admin UI adds an attack surface with no benefit when nobody logs in. And if you want a fast local client rather than a web application, a desktop tool connecting over SSH tunneling is both lighter and safer.

Project health

  • GitHub stars: 3,857
  • Last code push: 2026-10-01
  • Open issues: 341
  • Status: actively developed

Figures pulled from the GitHub API and refreshed periodically.

More in Databases & Storage