PRODSovereign European BaaS platformOpen Dashboard →

Native AI

Native AI on Postgres: NL2SQL, RAG & Agents

NL2SQL and RAG built directly into the Aurabase backend — not external connectors added as an afterthought. Breaking down precisely what "native" means, capability by capability.

Key Takeaways

Aurabase embeds NL2SQL (natural language to SQL, validated and bounded) and RAG (pgvector search, HNSW embeddings) directly into the backend, with 3 native LLM providers (OpenAI, Anthropic/Claude, Gemini). Mistral, Scaleway AI, and Ollama remain accessible via an OpenAI-compatible endpoint, rather than a bespoke native client.

#
Natural Language to SQL

NL2SQL — a natural language prompt, safe SQL output

Aurabase's NL2SQL engine validates every generated query before execution: AST parsing via sqlparser, a strict SQL function allowlist, and a bounded LIMIT enforced on every executed query. This is not an unconstrained LLM call — it is a strict syntax validator that denies anything beyond a simple SELECT.

01
Prompt
Natural language query, e.g. "Monthly revenue by tier"
02
Native LLM
OpenAI, Anthropic, or Gemini translates into SQL
03
AST Validation
sqlparser: SELECT only, function allowlist
04
Bounded LIMIT
Configurable ceiling, never silently uncapped
05
Execution
Read-only, schema-isolated per project

The validator explicitly rejects CTEs/WITH clauses, subqueries, UNION statements, non-whitelisted functions (count, sum, avg, min, max, lower, upper, coalesce, date_trunc, now), and any system catalog access. The row ceiling is server-side configurable and can be restricted per query — never expanded beyond the tenant limit.

#
Vector Search

Native RAG and pgvector — zero external dependencies

pgvector 0.8.6 is pre-installed in every Aurabase tenant Postgres image, coupled with an ingestion pipeline featuring automatic network retries and HNSW vector search across 3 dimension classes (768, 1536, and 3072) — well within pgvector's 16,000 dimension limit.

01
Ingestion
Project documents with automated network retries
02
Embeddings
768 / 1536 / 3072 dimensions matching the model
03
pgvector Storage
Built directly into tenant Postgres image
04
HNSW Search
Ultra-fast approximate vector similarity search
05
LLM Context
Relevant document passages injected into prompt

No extra steps to "install" pgvector: the extension is baked into the standard tenant image. The ingestion pipeline itself is an application-level capability engineered directly into Aurabase.

Storage is structured by namespace: each ingested document (POST /v1/ai//rag/ingest) is chunked, embedded, and mapped to the matching vector dimension column. The query endpoint (POST /v1/ai//rag/query) combines retrieval and generation; a dedicated endpoint (GET /v1/ai//search) exposes vector similarity search on its own, without triggering an LLM call. Switching embedding models never breaks your dataset: a namespace can be re-indexed (POST /v1/ai//rag//reindex) under a new model without re-uploading documents.

Technical nuance rarely documented elsewhere: beyond 2,000 dimensions, HNSW cannot index pgvector's standard vector type. For 3072 dimensions, Aurabase automatically leverages halfvec(3072) (reduced precision, indexable) rather than silently degrading queries into full table scans. By default, retrieval returns 5 passages (top_k) above a 0.3 similarity threshold — both parameters can be overridden per query.

#
LLM Providers

3 native providers, and what "native" excludes

OpenAI, Anthropic (Claude), and Google Gemini have dedicated native client integrations inside the Aurabase codebase. Mistral, Scaleway AI, and Ollama remain accessible via an OpenAI-compatible endpoint — an important operational distinction if your stack relies on bespoke provider primitives.

ProviderIntegrationImpact
OpenAIDedicated native clientDirect project API key configuration
Anthropic (Claude)Dedicated native clientDirect project API key configuration
Google GeminiDedicated native clientDirect project API key configuration
MistralOpenAI-compatible endpointFunctional via standard endpoint, without custom client
Scaleway AIOpenAI-compatible endpointFunctional via standard endpoint, without custom client
Ollama (self-hosted)OpenAI-compatible endpointIdeal for local LLMs or on-premises deployments
#
Comparison

Why Supabase bets on connectors rather than native NL2SQL

Supabase launched an official Claude connector in February 2026, followed by a ChatGPT integration. Both allow querying a Supabase database from a third-party chat interface — an external orchestration pattern, distinctly different from an NL2SQL engine embedded directly in the backend itself. See also our comprehensive Aurabase vs Supabase comparison.

#
Security

What stops an LLM from running arbitrary or destructive queries

Three safety guardrails apply prior to any execution: strict syntax validation (SELECT only, function allowlist), bounded result limit via LIMIT, and isolation of the target schema to the calling project alone. The introspected schema is never supplied by the client — it originates from the project database, the sole authoritative source.

Strict read-only access
The validator only accepts SELECT queries. Any attempt at INSERT, UPDATE, DELETE, DROP, CREATE, or ALTER emitted by the model is rejected at the AST level — before execution, not merely via a prompt instruction.

Beyond SELECT-only restrictions, the validator also blocks CTEs/WITH, subqueries, UNION/INTERSECT/EXCEPT statements, table-valued functions (generate_series, pg_sleep…), window functions, dollar-quoting, and locking clauses (FOR UPDATE). A thorough security walk traverses the entire abstract syntax tree — including DISTINCT ON, OFFSET, FETCH, and aggregate clauses — ensuring no forbidden function slips through an uninspected AST node.

#
Agents

AI agents on Postgres — function calling, not unconstrained SQL

Agents built with frameworks such as LangChain or LlamaIndex can call Aurabase REST endpoints — NL2SQL, RAG, database queries — as native tools invoked from their own function calling loop. NL2SQL plays a precise role: transforming the agent's sub-query into validated, safe SQL, rather than granting the agent unrestricted SQL execution.

In practice, the tool exposed to the agent wraps a standard HTTP call to the NL2SQL endpoint — the SDK executes the request without requiring custom framework plugins:

tools/nl2sql-tool.ts
TYPESCRIPT
// Custom tool called by your agent's function calling loop
export async function nl2sqlTool(question: string) {
const { data, error } = await aura.ai.nl2sql(question, undefined, { limit: 20 })
if (error) throw error
return { sql: data.sql, tables: data.tables }
}
Direct HTTP API integration
Aurabase integrates seamlessly via standard HTTP API and TypeScript SDK endpoints, providing predictable performance without wrapping multiple abstraction layers.
#
FAQ

Frequently Asked Questions

Can NL2SQL modify data (UPDATE, DELETE)?+
No. The AST validator only permits SELECT queries: any INSERT, UPDATE, DELETE, DROP, CREATE, or ALTER statement produced by the model is rejected at the syntax tree level before execution — not merely through prompt instructions.
Is pgvector sufficient, or is a dedicated vector database required?+
According to industry benchmarks, pgvector matches or outperforms dedicated vector stores below approximately 10 million vectors; the divergence only becomes significant beyond 50 million vectors. For the vast majority of application RAG workloads, native pgvector provides superior performance and transaction consistency without operating a separate cluster.
Is Aurabase MCP server production-ready for autonomous AI agents?+
Yes. The Aurabase MCP server is built directly on the standard JSON-RPC protocol over SSE and stdio, with native schema introspections, parameterized queries, and strict Row-Level Security tenant isolation.

TAKE THE NEXT STEP

Connect NL2SQL and native RAG directly to your Postgres database.

Zero third-party plumbing, built directly into the backend engine.

No credit card required · 500 MB free · 50,000 MAU