Workspace database
Inspect PostgreSQL hosting, read SQL and configure the active workspace database.
Database operations belong to Platform operations. They use the active workspace's authenticated identity. Through MCP, discover them with oxygen_capabilities_search, inspect the selected schema, then use oxygen_capabilities_read for reads or oxygen_capabilities_call for configuration.
| CLI | MCP | Behavior |
|---|---|---|
oxygen db status | oxygen_workspace_database_status | Read hosting/provisioning status. Hosting is included in the plan; region is a recorded label, not verified physical location. |
oxygen db cost-policy | oxygen_database_cost_policy | Read retired Neon policy status. managed describes that retired policy, not database hosting. PostgreSQL has no per-workspace sleep control. |
oxygen db query | oxygen_database_query | Run one read-only SELECT, WITH or EXPLAIN statement under the customer SQL boundary. Writes and multiple statements are refused. Request a small max_rows (hard cap 1000); legacy native requests default to 100. rowCount is returned rows, and truncated describes that window. There is no query continuation cursor; narrow the SQL for another read. |
oxygen db attach | oxygen_database_attach | Immediately attach the supplied database_url, set up tenant isolation and apply the native migration frontier. |
oxygen db migrate | oxygen_database_migrate | Immediately apply pending migrations. Optional rotate_credentials rotates role passwords; routine migration leaves it false. |
oxygen db provision | oxygen_workspace_database_provision | Provision the active workspace database through its bounded native provisioning path. |
Attach, migrate and provision have no native preview, dry-run or approved input. Inspect status and the selected schema before a requested configuration change. Normal workspace identity/access rules apply. A restricted client can read status, cost-policy and SQL, but configuration writes are refused. Built-in Copilot and Agent approval policy is enforced separately; an absent HTTP approval flag does not waive that policy.
oxygen db reconcile-cost-policy / oxygen_database_cost_policy_reconcile remains a compatibility no-op for a ready tenant: applied: false, suspended: false, reason: "provider_retired" and no operations. Its historical suspend_idle input cannot restore Neon controls or change PostgreSQL. Staff-wide migrations, repair and reconciliation procedures are separate privileged operations.