Databases

Connecting a database

Add a connection, test it, reach it through an SSH tunnel, and keep your connections in order in the Databases panel.

mxds starts with one database already connected: mxds, a built-in DuckDB that lives in memory. Everything else is a connection you add once. Connections are shared by all your projects, and their passwords and tokens are kept in the macOS Keychain.

The connection form with PostgreSQL selectedThe connection form with PostgreSQL selected
The connection form with PostgreSQL selected

Adding a connection

Click + at the top of the Databases panel (⌘B), or open Settings ▸ Connections (⌘,) and click Add Connection.

The form has the list of databases on the left, grouped into warehouses, transactional databases, files and query engines; type in Search drivers… to narrow it. Pick one, give the connection a name, and fill in what that database needs:

Database What the form asks for
PostgreSQL, Redshift host, port, database, schema, username, password
MySQL, MariaDB, SQL Server, ClickHouse host, port, database, username, password
Trino host, port, catalog, schema, username, and a password or a JWT when the server needs one
Snowflake account identifier, username, a password or a key pair, warehouse, database, schema, role
Databricks workspace host, warehouse id, catalog, schema, personal access token
BigQuery GCP project id, a service-account key file (.json) and an optional location
MotherDuck MotherDuck database and your personal token
DuckDB, SQLite the database file

A new PostgreSQL connection starts with the database postgres filled in, and a Redshift one with dev — the database every server of that kind has; change it if yours is another. Grey text in an empty field is only a hint: e.g. is an example, Default: names what mxds uses when you leave the field empty, Optional means the connection works without it and Required means it does not.

For ClickHouse you can paste a whole URL such as https://host:8443 into Host; mxds takes the port and HTTPS from it. Supported databases has the details for each engine.

A DuckDB or SQLite file has an Allow writes switch. Off, the file is opened read-only and no query can change it.

The SSL tab shows only what the engine uses:

Database SSL tab
PostgreSQL, Redshift SSL mode, root certificate, client certificate, client key
MySQL, MariaDB SSL mode: Disabled, Preferred, Required, Verify CA or Verify identity
SQL Server Encrypt, Trust server certificate
ClickHouse HTTPS, Verify certificate, root certificate, client certificate, client key
Trino HTTPS

Snowflake, Databricks, BigQuery and MotherDuck always use HTTPS and have no SSL tab; DuckDB and SQLite files have none either.

Editing a connection keeps every setting the form does not show, such as one an agent made through MCP.

Testing the connection

Test connection connects with what is in the form and runs one trivial query. It shows Connected with the time it took, or Connection failed with the database's own message and a Copy button. A missing required field, such as the connection name or the host, is caught before anything is sent: the field is outlined in red with the reason under it, and the cursor is moved into it — on the SSH tab when the field is there. Testing saves nothing: the passwords you typed are not stored, and testing an edit does not replace the saved password until you click Save.

Save adds the connection to the Databases panel. It does not connect yet: a connection opens the first time you expand it or a tab runs on it.

SSH tunnels

PostgreSQL, Redshift, MySQL, MariaDB, SQL Server, ClickHouse and Trino can be reached through a bastion host. On the SSH tab, turn on Enable SSH tunneling and fill in:

  • Bastion host and Port — the SSH server.
  • SSH user.
  • Authentication — a Private key file with an optional passphrase, a Password, or ssh-agent, which uses the keys your agent already holds.

mxds checks the bastion's host key the way ssh does. A key recorded for that host in ~/.ssh/known_hosts or in ~/.mxds/known_hosts is accepted. The first time you connect to a new bastion, its key is remembered in ~/.mxds/known_hosts; mxds never writes to ~/.ssh/known_hosts. If a known bastion presents a different key, the connection is refused before any password is sent, and the message names the file that holds the old key and the ssh-keygen -R command that removes it.

With a tunnel on, Host and Port on the General tab are resolved from the bastion, not from your Mac. If you used to run ssh -L by hand and pointed the connection at 127.0.0.1, change it to the database's real address.

A tunnel that dropped while idle, after sleep or a VPN change, reconnects by itself on the next query.

Passwords and the Keychain

Passwords, tokens, SSH passphrases and Snowflake key passphrases are stored in the macOS Keychain, never in mxds's settings files. When you edit a connection the password field is empty; leave it empty to keep the stored password, or type a new one to replace it.

Editing and removing

Right-click a connection in the Databases panel and choose Properties, or click Edit next to it in Settings ▸ Connections. A change to the tunnel or to Allow writes takes effect at once; open tabs reconnect.

To remove a connection, click Delete next to it in Settings ▸ Connections and confirm. Removing cannot be undone. It also deletes every secret the connection kept in the Keychain.

Groups and order

The Databases panel lists connections in your order. Drag a connection to move it; the editor's connection menu and the command palette follow the same order.

Groups keep long lists manageable. Right-click a connection, a group header or the empty space under the list and choose New group. Drag connections into a group, or use Move to group on a connection's menu. A group's menu has Rename and Delete group; deleting a group keeps its connections and puts them back where they were before.

The first group, In-Memory DBs, is always there. It holds the built-in mxds database and the local DuckDB and SQLite files you connect; it cannot be renamed or deleted.

The Databases panel with the In-Memory DBs group and a group of production connectionsThe Databases panel with the In-Memory DBs group and a group of production connections
The Databases panel with the In-Memory DBs group and a group of production connections

The built-in database

mxds is a DuckDB that needs no setup. It is where imported files land, and it comes with a sample schema, jaffle_shop, with six small tables to try queries on. Turn the sample off in Settings ▸ Database ▸ Sample data.

Everything in it lives in memory, so tables you create or load there are gone when you quit mxds. It cannot be edited or removed.