Skip to content

Use TablePro every day? A license adds the paid features and funds the next release. Get a licenseGet a license, fund TablePro

Connections, tunnels and credentials

For anyone whose databases sit behind a bastion, a cluster or a cloud login: set a connection up once, with the route and the password source it needs, and give production ones stricter rules. Everything here is in the Mac app; the last section covers iPhone and iPad.
MaciPhone & iPad

Paid features on this page: Environment Variables (Starter). Everything else here is free.

Keep a library of connections

Each connection is edited in one form with General, Network, Options and Appearance tabs. Import a connection URL, including jdbc: URLs and +ssh URLs that carry an SSH hop, and the form fills itself in; when one is already on your clipboard, the form offers Use clipboard URL.

Give a connection a colour, as many tags as you like and a place in nested groups, and star the ones you use most as favorites. Environments are tags: local, development, production and testing are built in, and you can add your own. An empty library offers Open Sample Database, a bundled SQLite copy of Chinook.

The Welcome window listing saved connections in Production and Staging groups with coloured tags, and the Chinook sample database.

Bring the connections you already have

You rarely start from an empty list: TablePro reads connections from another client, from a project’s config files or from your AWS account.

From another database client

Import from Other App reads the connections saved in TablePlus, Sequel Ace, DBeaver, DataGrip, Beekeeper Studio and Navicat, TablePlus's Setapp edition included, and brings their passwords across where that app stored them, including the encrypted passwords DBeaver and Navicat keep. Navicat connections come from an .ncx export file.

The Import from DataGrip sheet listing three connections found in DataGrip, each marked ready to import.

From a project’s config files

Open Project Folder scans a project for database settings in .env, wp-config.php, a Prisma schema, Rails’ config/database.yml, docker-compose.yml, Spring’s application.properties or application.yml, and appsettings.json. It lists each set it finds with the file it came from, and the one you pick fills in the connection form; passwords go straight to the Keychain. When prod, production or live appears as a whole word in the file path, the host or the database name, that connection starts at the Alert Safe Mode level.

Open Project Folder results for the acme-shop project, with connections found in .env and .env.production.

From your AWS account

Import from AWS lists the RDS instances and Aurora clusters an AWS profile can see in the regions you pick, and adds the ones you choose. The profile needs rds:DescribeDBInstances and rds:DescribeDBClusters.

Reach databases behind a bastion, a proxy or a cluster

SSH and TLS

SSH tunnels sign in with a password, a private key, an SSH agent such as 1Password’s, or keyboard-interactive prompts, and can pass through jump hosts in order or follow ProxyJump from ~/.ssh/config. A one-time code can be generated from a secret in the Keychain or asked for at each connect, and an unknown host key shows its fingerprint before TablePro trusts it. Save a tunnel as an SSH profile to reuse it.

TLS runs in Disabled, Preferred, Required, Verify CA or Verify Identity mode, with your own CA, client certificate and key. Required encrypts without checking the server’s certificate; the Verify modes check it.

The SSH settings of a connection form: host bastion.acme.internal, user deploy, key authentication, and one jump host.

Proxies, Cloudflare, Cloud SQL and tunnel commands

When SSH is not the way in, the Network tab connects through a SOCKS5 proxy with remote DNS, through Cloudflare Access, where TablePro runs cloudflared and signs in with the browser or a service token, or through the Cloud SQL Auth Proxy, which TablePro downloads, checks and runs for PostgreSQL, MySQL and SQL Server.

Tunnel Command starts kubectl port-forward, aws ssm start-session or a command of your own, then connects to the local port it opens. A connection can also run a shell script before connecting, asking you first each session, and SQL statements right after.

A connection tunnelled with kubectl port-forward to svc/orders-db, with the command it will run.

Sign in with your cloud account

AWS IAM database authentication signs a fresh token at every connect, from an access key, a profile in ~/.aws (with credential_process and assumed roles) or AWS IAM Identity Center, and turns TLS up to Required for it. Amazon ElastiCache for Redis, Amazon Keyspaces and DynamoDB have their own AWS signing.

SQL Server signs in with Microsoft Entra ID in the browser, using the client ID of an app registration you provide, or with Kerberos from a ticket or a principal and password. Google BigQuery takes a service account key, Application Default Credentials or Google OAuth with your own client, and Google Cloud Spanner and the Cloud SQL Auth Proxy can use your Google account.

AWS IAM authentication on RDS and Aurora
PostgreSQL, MySQL, MariaDB

Keep passwords where they belong

Passwords are saved in the macOS Keychain; with iCloud Sync on, password sync carries them to your other devices through iCloud Keychain. An SSH key stays a file on disk that the connection points to; only its passphrase goes in the Keychain.

A credential profile shares one login across many connections and can read its password at connect time from 1Password (op), HashiCorp Vault, AWS Secrets Manager, a shell command, a file or an environment variable. These password sources are free and never sync, and each command-line tool has to be on your PATH or in /usr/local/bin or /opt/homebrew/bin. A connection can also use ~/.pgpass on PostgreSQL, Amazon Redshift and CockroachDB, or ask for its password every time.

Environment Variables

Environment Variables: Starter plan

Write $DB_HOST into a connection’s host, database, username, SSH host, user and key path, SSL paths, startup commands or driver fields, and TablePro fills in the value from its own environment when it connects. The port and the password are never read this way; give the password a source instead.

Rules each connection carries

A connection’s Safe Mode level decides whether a statement runs as written, asks first, asks for Touch ID or your password, or is refused. Its External Clients level, Blocked, Read Only or Read & Write, sets what MCP clients and AppleScript may do with it, and stays on this Mac. Its AI policy sets whether the AI assistant may use it without asking, only after asking, or never; Never also shuts out MCP clients.

An organisation can enforce a minimum Safe Mode level for every connection, and control updates, through a configuration profile.

Connect and query timeouts

Each connection can set its own connect timeout, which covers the network, TLS, sign-in and any tunnel or proxy, and its own query timeout in place of the app-wide one. The query timeout applies to the drivers that support one, after you reconnect.

On iPhone and iPad

The iPhone and iPad app has its own connection form for MySQL, MariaDB, TiDB, OceanBase, PostgreSQL, SQLite, DuckDB, Redis, SQL Server and Oracle, with groups, one tag per connection and favorites. SSH tunnels sign in with a password or a private key, from a file or pasted in, and check the host key; SSH agents and jump hosts are not supported on iPhone and iPad. TLS can verify the server’s certificate, except on SQL Server, where it encrypts without verifying. Certificates stay on the device and never sync.

Passwords and pasted keys are kept in the Keychain. SQL Server connections synced from a Mac can sign in with Microsoft Entra ID. Importing from other apps, AWS IAM, Kerberos and Google sign-in, proxies and tunnel commands, password sources and timeouts are in the Mac app only.

Where it works

Each capability on this page, the plan it needs on the Mac, and what exists of it on iPhone and iPad
Capability
Connection form, groups, tags and favoritesMac: FreeiPhone and iPad: One tag per connection; no colours
Import from a URL or the clipboardMac: FreeiPhone and iPad: Not available
Import from other apps, project folders and AWSMac: FreeiPhone and iPad: Not available
SSH tunnel with a password or private keyMac: FreeiPhone and iPad: Free
SSH agent, one-time codes and jump hostsMac: FreeiPhone and iPad: Not available
TLS with certificate checksMac: FreeiPhone and iPad: SQL Server encrypts without verifying
SOCKS5, Cloudflare Access, Cloud SQL Auth Proxy and Tunnel CommandMac: FreeiPhone and iPad: Not available
AWS IAM, Kerberos and Google sign-inMac: FreeiPhone and iPad: Not available
Microsoft Entra IDMac: FreeiPhone and iPad: On connections synced from a Mac
Passwords in the KeychainMac: FreeiPhone and iPad: Free
Password sources, credential profiles and ~/.pgpassMac: FreeiPhone and iPad: Not available
Environment VariablesMac: Starter planiPhone and iPad: Not available
Safe Mode per connectionMac: FreeiPhone and iPad: Off, Confirm Writes and Read-Only
Connect and query timeoutsMac: FreeiPhone and iPad: Not available
Minimum Safe Mode level through a configuration profileMac: FreeiPhone and iPad: Not available

Limits worth knowing

  • Password sources and the Network tab’s proxies and tunnel commands stay on the Mac where you set them: they never sync, so a synced connection needs them set up again on each Mac.
  • TablePro reads the environment it was started with. Opened from the Dock or Finder, it does not see the variables your shell profile sets, which affects the environment-variable password source and Environment Variables alike.
  • When a plan ends, $DB_HOST and other references are no longer filled in and reach the server as typed, with no warning.
  • Open Project Folder is a one-time import: nothing is watched, and importing the same settings twice creates two connections.
  • AWS IAM authentication covers PostgreSQL, MySQL and MariaDB, not Amazon Redshift. A configuration profile can enforce a minimum Safe Mode level and update settings, nothing more.

Get TablePro

TablePro is open source and free to use. Paid plans add optional features to the Mac app.
Download for Mac

macOS 13 Ventura or laterApple silicon or Intel

Download on the App Store

iPhone and iPadiOS and iPadOS 18 or later

See pricing