- Click Connection, choose PostgreSQL, and fill in Host, Port, Initial Database, User Name and Password on the General tab.
- The SSL tab sets the SSL Mode; verify-full is the strictest, checking both the certificate authority and the host name. Root Certificate takes the CA file.
- For a server you cannot reach directly, enable Use SSH tunnel on the SSH tab and set the General tab host relative to the SSH server.
- By default PostgreSQL listens only on localhost, so a remote connection also needs listen_addresses changed (restart required) and a host line in pg_hba.conf (reload is enough).
Create the Navicat PostgreSQL connection
The same steps apply in Navicat Premium 18, Navicat 18 for PostgreSQL and the free Navicat Premium Lite 18. According to the Navicat manual:
- In the main window, click Connection.
- In the New Connection window, select PostgreSQL and click Next.
- Fill in the General tab (table below).
- Set the SSL or SSH tab if needed.
- Click OK.
| Field | What to enter |
|---|---|
| Connection Name | A friendly name for the connection |
| Host | Host name or IP address of the server (relative to the SSH server if you tunnel) |
| Endpoint | Shown for Amazon Web Services instances |
| Port | The server port; PostgreSQL listens on 5432 by default |
| Initial Database | The database to connect to first, for example postgres or your application database |
| User Name and Password | A PostgreSQL role allowed by pg_hba.conf to log in from your address |
SSL mode for a PostgreSQL connection in Navicat
The SSL tab works with PostgreSQL 8.4 and later. Choose an SSL Mode:
| Mode | Behaviour |
|---|---|
| allow (macOS manual) | First tries a non-SSL connection; if that fails, tries SSL |
| prefer (macOS manual) | First tries SSL; if that fails, tries a non-SSL connection |
| require | Only tries an SSL connection |
| verify-ca | SSL only, and verifies that the server certificate is issued by a trusted CA |
| verify-full | SSL only, verifies the CA and that the server host name matches the certificate |
Certificates
The Windows manual lists require, verify-ca and verify-full; the macOS manual also lists allow and prefer. For verify-ca or verify-full, enable Use authentication and set Root Certificate to the CA file. If the server requires client certificates, add Client Key and Client Certificate; Certificate Revocation List is optional. In our view, verify-full is the right default for anything outside a private network, because require alone does not prove which server you reached.
Connect through an SSH tunnel
On the SSH tab, enable Use SSH tunnel, then enter the SSH Host, Port (22 by default) and User Name (a user on the SSH machine, not a PostgreSQL role). Choose Password, Public Key, or Password & Public Key as the Authentication Method, and for a key give the Private Key and Passphrase. The General tab host is then set relative to the SSH server, typically localhost when PostgreSQL runs on that machine.
The SSH server must permit TCP forwarding (AllowTcpForwarding set to yes). Navicat's Help Center notes that, where SSH is available, you can connect to a remote PostgreSQL server through the tunnel. HTTP tunnelling is the fallback when SSH is not available: upload ntunnel_pgsql.php from the Navicat installation folder to the web server. SSH and HTTP tunnels cannot be combined.
PostgreSQL server settings for remote Navicat clients
Navicat's Help Center points out that PostgreSQL accepts only local TCP/IP connections by default. Two settings change that, per the PostgreSQL 18 documentation:
- listen_addresses in
postgresql.conf: the default islocalhost. Set it to the server's address, or*for all interfaces. It can only be set at server start, so restart PostgreSQL after changing it. - pg_hba.conf: add a
hostline for your client address. The file is re-read on a reload (for exampleSELECT pg_reload_conf();), so no restart is needed for this part.
listen_addresses = '*'# TYPE DATABASE USER ADDRESS METHOD
host mydb app_user 203.0.113.25/32 scram-sha-256SELECT pg_reload_conf();Common Navicat PostgreSQL connection errors
- FATAL: password authentication failed for user. Navicat's Help Center lists four causes: a wrong password, a user that does not exist, a pg_hba.conf line with the wrong authentication method for your address or connection type, and network problems such as a blocked port.
- Connection refused or timed out. The server is not listening on a reachable address or a firewall blocks 5432. Check
listen_addresses, the port, and any firewall, or use an SSH tunnel. - Rejected by pg_hba.conf. If no line matches your address, user and database, add a
hostline as shown above and reload.
To separate client problems from server problems, the Navicat manual lists a read-only PostgreSQL test server (host server1.navicat.com, port 5432, initial database HR, credentials in the manual).
Frequently asked questions
What is the default port for a Navicat PostgreSQL connection?
5432, the PostgreSQL default. Enter a different port on the General tab if your server or provider uses one.
Which SSL mode should I choose in Navicat for PostgreSQL?
verify-full if you have the server's CA certificate, because it checks both the certificate authority and the host name. require encrypts the connection but does not verify the certificate.
Why does Navicat show "password authentication failed" with the correct password?
The pg_hba.conf line that matches your address may use a different authentication method, or the role may not exist in that cluster. Navicat's Help Center lists these alongside a wrong password and network problems.
Do I have to restart PostgreSQL after editing pg_hba.conf?
No. A reload, for example SELECT pg_reload_conf();, makes the server re-read pg_hba.conf. Changing listen_addresses does need a restart.
Sources
- Navicat 18 manual: Establish Connection
- Navicat 18 manual: General Settings
- Navicat 18 manual (Windows): SSL
- Navicat 18 manual (macOS): SSL
- Navicat 18 manual: SSH Tunneling
- Navicat 18 manual: HTTP Tunneling
- Navicat Help Center: Why I cannot connect to my server?
- Navicat Help Center: configure the privilege system for remote access
- Navicat Help Center: FATAL: password authentication failed
- PostgreSQL 18 documentation: Connection Settings
- PostgreSQL 18 documentation: The pg_hba.conf File
Checked 8 October 2026.
How we research tool guides: our editorial method. CodeWithSQL earns nothing from the vendors mentioned.