Connections, tunnels and credentials
Paid features on this page: Environment Variables (Starter). Everything else here is free.
Keep a library of connections
Each connection is edited in one form with General, Network, Options and Appearance tabs. Import a connection URL, including jdbc: URLs and +ssh URLs that carry an SSH hop, and the form fills itself in; when one is already on your clipboard, the form offers Use clipboard URL.
Give a connection a colour, as many tags as you like and a place in nested groups, and star the ones you use most as favorites. Environments are tags: local, development, production and testing are built in, and you can add your own. An empty library offers Open Sample Database, a bundled SQLite copy of Chinook.


Bring the connections you already have
You rarely start from an empty list: TablePro reads connections from another client, from a project’s config files or from your AWS account.
From another database client
Import from Other App reads the connections saved in TablePlus, Sequel Ace, DBeaver, DataGrip, Beekeeper Studio and Navicat, TablePlus's Setapp edition included, and brings their passwords across where that app stored them, including the encrypted passwords DBeaver and Navicat keep. Navicat connections come from an .ncx export file.


From a project’s config files
Open Project Folder scans a project for database settings in .env, wp-config.php, a Prisma schema, Rails’ config/database.yml, docker-compose.yml, Spring’s application.properties or application.yml, and appsettings.json. It lists each set it finds with the file it came from, and the one you pick fills in the connection form; passwords go straight to the Keychain. When prod, production or live appears as a whole word in the file path, the host or the database name, that connection starts at the Alert Safe Mode level.


From your AWS account
Import from AWS lists the RDS instances and Aurora clusters an AWS profile can see in the regions you pick, and adds the ones you choose. The profile needs rds:DescribeDBInstances and rds:DescribeDBClusters.
Reach databases behind a bastion, a proxy or a cluster
SSH and TLS
SSH tunnels sign in with a password, a private key, an SSH agent such as 1Password’s, or keyboard-interactive prompts, and can pass through jump hosts in order or follow ProxyJump from ~/.ssh/config. A one-time code can be generated from a secret in the Keychain or asked for at each connect, and an unknown host key shows its fingerprint before TablePro trusts it. Save a tunnel as an SSH profile to reuse it.
TLS runs in Disabled, Preferred, Required, Verify CA or Verify Identity mode, with your own CA, client certificate and key. Required encrypts without checking the server’s certificate; the Verify modes check it.
- Network engines without an SSH tunnel
- PGlite, Amazon DynamoDB, Google BigQuery, Snowflake, Cloudflare D1, Turso, libSQL, Elasticsearch, Google Cloud Spanner, Typesense, Weaviate, Cloudflare R2 SQL, SAP HANA


Proxies, Cloudflare, Cloud SQL and tunnel commands
When SSH is not the way in, the Network tab connects through a SOCKS5 proxy with remote DNS, through Cloudflare Access, where TablePro runs cloudflared and signs in with the browser or a service token, or through the Cloud SQL Auth Proxy, which TablePro downloads, checks and runs for PostgreSQL, MySQL and SQL Server.
Tunnel Command starts kubectl port-forward, aws ssm start-session or a command of your own, then connects to the local port it opens. A connection can also run a shell script before connecting, asking you first each session, and SQL statements right after.


Sign in with your cloud account
AWS IAM database authentication signs a fresh token at every connect, from an access key, a profile in ~/.aws (with credential_process and assumed roles) or AWS IAM Identity Center, and turns TLS up to Required for it. Amazon ElastiCache for Redis, Amazon Keyspaces and DynamoDB have their own AWS signing.
SQL Server signs in with Microsoft Entra ID in the browser, using the client ID of an app registration you provide, or with Kerberos from a ticket or a principal and password. Google BigQuery takes a service account key, Application Default Credentials or Google OAuth with your own client, and Google Cloud Spanner and the Cloud SQL Auth Proxy can use your Google account.
- AWS IAM authentication on RDS and Aurora
- PostgreSQL, MySQL, MariaDB
Keep passwords where they belong
Passwords are saved in the macOS Keychain; with iCloud Sync on, password sync carries them to your other devices through iCloud Keychain. An SSH key stays a file on disk that the connection points to; only its passphrase goes in the Keychain.
A credential profile shares one login across many connections and can read its password at connect time from 1Password (op), HashiCorp Vault, AWS Secrets Manager, a shell command, a file or an environment variable. These password sources are free and never sync, and each command-line tool has to be on your PATH or in /usr/local/bin or /opt/homebrew/bin. A connection can also use ~/.pgpass on PostgreSQL, Amazon Redshift and CockroachDB, or ask for its password every time.
Environment Variables
Environment Variables: Starter plan
Write $DB_HOST into a connection’s host, database, username, SSH host, user and key path, SSL paths, startup commands or driver fields, and TablePro fills in the value from its own environment when it connects. The port and the password are never read this way; give the password a source instead.
Rules each connection carries
A connection’s Safe Mode level decides whether a statement runs as written, asks first, asks for Touch ID or your password, or is refused. Its External Clients level, Blocked, Read Only or Read & Write, sets what MCP clients and AppleScript may do with it, and stays on this Mac. Its AI policy sets whether the AI assistant may use it without asking, only after asking, or never; Never also shuts out MCP clients.
An organisation can enforce a minimum Safe Mode level for every connection, and control updates, through a configuration profile.
Connect and query timeouts
Each connection can set its own connect timeout, which covers the network, TLS, sign-in and any tunnel or proxy, and its own query timeout in place of the app-wide one. The query timeout applies to the drivers that support one, after you reconnect.
On iPhone and iPad
The iPhone and iPad app has its own connection form for MySQL, MariaDB, TiDB, OceanBase, PostgreSQL, SQLite, DuckDB, Redis, SQL Server and Oracle, with groups, one tag per connection and favorites. SSH tunnels sign in with a password or a private key, from a file or pasted in, and check the host key; SSH agents and jump hosts are not supported on iPhone and iPad. TLS can verify the server’s certificate, except on SQL Server, where it encrypts without verifying. Certificates stay on the device and never sync.
Passwords and pasted keys are kept in the Keychain. SQL Server connections synced from a Mac can sign in with Microsoft Entra ID. Importing from other apps, AWS IAM, Kerberos and Google sign-in, proxies and tunnel commands, password sources and timeouts are in the Mac app only.
Where it works
| Capability |
|---|
| Connection form, groups, tags and favoritesMac: FreeiPhone and iPad: One tag per connection; no colours |
| Import from a URL or the clipboardMac: FreeiPhone and iPad: Not available |
| Import from other apps, project folders and AWSMac: FreeiPhone and iPad: Not available |
| SSH tunnel with a password or private keyMac: FreeiPhone and iPad: Free |
| SSH agent, one-time codes and jump hostsMac: FreeiPhone and iPad: Not available |
| TLS with certificate checksMac: FreeiPhone and iPad: SQL Server encrypts without verifying |
| SOCKS5, Cloudflare Access, Cloud SQL Auth Proxy and Tunnel CommandMac: FreeiPhone and iPad: Not available |
| AWS IAM, Kerberos and Google sign-inMac: FreeiPhone and iPad: Not available |
| Microsoft Entra IDMac: FreeiPhone and iPad: On connections synced from a Mac |
| Passwords in the KeychainMac: FreeiPhone and iPad: Free |
| Password sources, credential profiles and ~/.pgpassMac: FreeiPhone and iPad: Not available |
| Environment VariablesMac: Starter planiPhone and iPad: Not available |
| Safe Mode per connectionMac: FreeiPhone and iPad: Off, Confirm Writes and Read-Only |
| Connect and query timeoutsMac: FreeiPhone and iPad: Not available |
| Minimum Safe Mode level through a configuration profileMac: FreeiPhone and iPad: Not available |
Limits worth knowing
- Password sources and the Network tab’s proxies and tunnel commands stay on the Mac where you set them: they never sync, so a synced connection needs them set up again on each Mac.
- TablePro reads the environment it was started with. Opened from the Dock or Finder, it does not see the variables your shell profile sets, which affects the environment-variable password source and Environment Variables alike.
- When a plan ends,
$DB_HOSTand other references are no longer filled in and reach the server as typed, with no warning. - Open Project Folder is a one-time import: nothing is watched, and importing the same settings twice creates two connections.
- AWS IAM authentication covers PostgreSQL, MySQL and MariaDB, not Amazon Redshift. A configuration profile can enforce a minimum Safe Mode level and update settings, nothing more.
Get TablePro
macOS 13 Ventura or laterApple silicon or Intel