Docs
Hold the statement. Keep the undo.
Tablebelt is a self-hosted Postgres proxy. The agent connects to it. Safe SQL passes through. DROP, TRUNCATE, ALTER ... DROP and unscoped writes wait until you approve them. The proxy snapshots the affected tables first. tablebelt restore puts those tables back.
Sixty seconds
curl -fsSL https://tablebelt.com/install.sh | sh
tablebelt init
tablebelt run
- Install the binary, or run the Docker image.
tablebelt initwritestablebelt.yaml, an agent password, and an admin token file (mode 0600). It prints aDATABASE_URLthat contains no upstream credential.tablebelt runlistens on127.0.0.1:5439.- Give the agent only that URL. Keep the real DSN on the proxy host.
- When something is held,
tablebelt approveon Free, or the dashboard on Pro and Team.
On this site
- Install: script, Homebrew, Docker, Compose, systemd, checksums.
- Agents: Claude Code, Codex, Cursor, MCP, other.
- Hosts: DigitalOcean, RDS, Neon, Railway, Supabase, Render, self-hosted, other.
- Config, rules, restore, cloud, security, troubleshooting.
Free runs any number of local databases, with CLI approvals, and makes no outbound calls. Pro is $19 per database per month. Team is $79 per month. Prices are USD. Checkout shows local currency (GBP/EUR) where available. Hosted approvals are at app.tablebelt.com.