scribase
Security and secretsversion 17.1preloaded

pgaudit

Write detailed audit lines for the statements you choose.

What it is for

pgaudit writes structured audit records to the database log for the classes of statements you pick (read, write, ddl, role, function). Standard statement logging records text; pgaudit records which objects a statement touched, which is what compliance reviews usually ask for.

Enable it

sql
create extension if not exists pgaudit with schema extensions;

Its library is preloaded when the database starts (shared_preload_libraries), so CREATE EXTENSION is all you need.

Example

sql
-- audit every write and schema change made through the API roles
alter role authenticated set pgaudit.log = 'write, ddl';

-- or only one table: object auditing through a dedicated role
create role auditor nologin;
grant select, update on payments to auditor;
alter role authenticated set pgaudit.role = 'auditor';

Questions

How do I enable pgaudit?

Run create extension if not exists pgaudit with schema extensions; in the SQL editor, or switch it on from the Extensions page in the console. You do not need superuser access.

Which version of pgaudit is installed?

17.1, on Postgres 17.6, as read from the running engine on 2026-10-08. Check yours with: select extversion from pg_extension where extname = 'pgaudit';

Upstream project: github.com/pgaudit/pgaudit

More security and secrets extensions

  • supabase_vault Store secrets encrypted with a key only the server can read.
  • pgcrypto Hashing, password hashing and encryption functions.