> ## Documentation Index
> Fetch the complete documentation index at: https://docs.supaboard.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# MySQL

Connect Supaboard to a MySQL database for direct querying, schema discovery, and AI-powered analysis.

Open **Data sources → Connect Data Source → MySql** to use this guide. For the overall workflow and the check after setup, see [Connect a data source](/data-sources/connect-a-data-source).

## Before you connect

**Network access** — Supaboard connects from a fixed set of egress IPs. Add them to your database firewall allow-list before attempting a connection. The current IP list is shown inside the connector form under **Whitelist IPs**.

**Database user permissions** — The user you provide needs at minimum:

* `SELECT` on the target database
* `SHOW DATABASES` to enable database auto-discovery

See [Recommended database user permissions](#recommended-database-user-permissions) for the exact SQL.

## Connection fields

| Field | Default | Required | Description |
| - | - | - | - |
| **Display Name** | — | Yes | Label shown in the Supaboard UI |
| **Host** | — | Yes | Hostname or IP of your MySQL server |
| **Port** | `3306` | Yes | MySQL port |
| **Database** | `mysql` | No | Database name; Supaboard auto-discovers if left blank |
| **Username** | — | Yes | Database user |
| **Password** | — | Yes | Password for the database user |
| **Additional JDBC Parameters** | — | No | Extra key=value pairs appended to the JDBC URL |

> **Boolean columns** — MySQL's `TINYINT(1)` type is interpreted as a boolean by many JDBC drivers. If your queries return `true`/`false` instead of `0`/`1` unexpectedly, add `tinyInt1isBit=false` to **Additional JDBC Parameters**.

## SSH Tunnel fields

Shown when the **SSH Tunnel** toggle is enabled.

| Field | Default | Required | Description |
| - | - | - | - |
| **SSH Host** | — | Yes | Hostname or IP of the SSH bastion server |
| **SSH Port** | `22` | Yes | SSH port on the bastion server |
| **SSH Username** | — | Yes | SSH login username |
| **SSH Connection Type** | `Private Key` | Yes | `Private Key` or `Password` |
| **SSH Private Key** | — | If Private Key | PEM-encoded private key |
| **SSH Passphrase** | — | No | Passphrase for an encrypted private key |
| **SSH Password** | — | If Password | Password for SSH password authentication |

## Finding your connection details

### Amazon RDS for MySQL

1. Open the [RDS Console](https://console.aws.amazon.com/rds/) and select your DB instance.
2. Under **Connectivity & security**, copy the **Endpoint** — this is your **Host**.
3. The default **Port** is `3306`.
4. Ensure the instance's security group allows inbound TCP on port 3306 from Supaboard's egress IPs, or route through an SSH tunnel.

**Documentation:** [Connecting to a MySQL DB instance](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_ConnectToInstance.html) · [RDS for MySQL overview](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/CHAP_MySQL.html)

### Amazon Aurora (MySQL-compatible)

1. In the RDS Console, open your Aurora cluster.
2. Use the **Writer endpoint** as your **Host** for read/write access; use a **Reader endpoint** for read-only.
3. Default port is `3306`.
4. Add Supaboard IPs to the cluster's VPC security group.

**Documentation:** [Connecting to an Aurora MySQL cluster](https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/Aurora.Connecting.html) · [Aurora MySQL overview](https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/Aurora.AuroraMySQL.html)

### Google Cloud SQL for MySQL

1. Open the [Cloud SQL Console](https://console.cloud.google.com/sql) and select your instance.
2. Under **Connect to this instance**, copy the **Public IP address** as your **Host**.
3. Under **Connections → Authorized networks**, add each Supaboard egress IP.
4. Alternatively, use the Cloud SQL Auth Proxy via an SSH tunnel.

**Documentation:** [Cloud SQL for MySQL overview](https://cloud.google.com/sql/docs/mysql) · [Connecting overview](https://cloud.google.com/sql/docs/mysql/connect-overview) · [Authorizing with IP addresses](https://cloud.google.com/sql/docs/mysql/authorize-networks)

### Azure Database for MySQL

1. Open your server in the [Azure Portal](https://portal.azure.com).
2. On the **Overview** page, copy **Server name** — this is your **Host** (format: `server.mysql.database.azure.com`).
3. Under **Settings → Connection security**, add a firewall rule for each Supaboard egress IP.
4. SSL enforcement is enabled by default on Azure — enable the SSL toggle in Supaboard.

**Documentation:** [Azure Database for MySQL documentation](https://learn.microsoft.com/en-us/azure/mysql/) · [Firewall rules](https://learn.microsoft.com/en-us/azure/mysql/flexible-server/concepts-firewall-rules)

## SSL

Enable the **SSL** toggle when your database requires encrypted connections (recommended for all cloud-hosted instances).

* **SSL Certificate** — paste the server's CA certificate in PEM format if your database uses a self-signed or private CA certificate. Leave blank for certificates signed by a public CA.

## SSH Tunnel

An SSH tunnel routes the database connection through a bastion host, keeping your database off the public internet entirely.

**When to use it:**

* Your database has no public IP
* You want to avoid adding Supaboard IPs to your database firewall
* Your security policy requires all external connections to go through a jump server

**Checklist:**

* [ ] The bastion server can reach the database host on port 3306
* [ ] Supaboard's egress IPs are allowed on the bastion server's SSH port (default 22)
* [ ] The SSH user has permission to forward connections (no `no-port-forwarding` in `authorized_keys`)
* [ ] If using a private key, it is in PEM format (OpenSSH format may need conversion with `ssh-keygen -p -m PEM`)

## IPsec Site-to-Site VPN

If your database lives on a private network, you can peer your VPN gateway with Supaboard over IKEv2 IPsec instead of exposing the database or running a bastion host. Enable the **Use IPsec site-to-site VPN** toggle in the connector form.

| Field | Required | Description |
| - | - | - |
| **VPN Gateway Address** | Yes | Public IP of your VPN gateway — or a per-server mapping for providers with one tunnel endpoint per peer (OCI/AWS managed VPN), e.g. `<supaboard-ip>=<tunnel-ip>,…` |
| **Pre-Shared Key** | Yes | The PSK configured on your gateway for the Supaboard tunnels |
| **Remote Subnet** | No | CIDR the tunnel should route. Defaults to your database host `/32` |

**Checklist:**

* [ ] Your VPN gateway has one IKEv2 + pre-shared-key tunnel per Supaboard IP (the IPs shown under **Whitelist IPs**)
* [ ] The gateway allows UDP 500, UDP 4500, and ESP (IP protocol 50) from those IPs
* [ ] The **Host** field is the database's **private IP address** — private DNS names don't resolve from Supaboard
* [ ] Enter the database name manually — auto-discovery doesn't run through the VPN before the connection is saved

Gateway settings, supported ciphers, a strongSwan example, and troubleshooting: [IPsec Site-to-Site VPN guide](/data-sources/security/ipsec-vpn).

## Recommended database user permissions

```sql theme={null}
-- Create a dedicated read-only user (accessible from any host)
CREATE USER 'supaboard'@'%' IDENTIFIED BY 'strong_password_here';

-- Grant SELECT on the target database
GRANT SELECT ON your_database.* TO 'supaboard'@'%';

-- Allow database discovery
GRANT SHOW DATABASES ON *.* TO 'supaboard'@'%';

FLUSH PRIVILEGES;
```

Replace `your_database` with the name of your database. To expose multiple databases, repeat the `GRANT SELECT` line for each one.

## Troubleshooting

| Error | Likely cause | Fix |
| - | - | - |
| `Access denied for user` | Wrong username or password | Verify credentials; confirm the user exists with `SELECT user FROM mysql.user` |
| `Can't connect to MySQL server` | Wrong host/port or firewall blocking | Check host/port; add Supaboard IPs to firewall allow-list |
| `Unknown database` | Database name doesn't exist | Verify the database name with `SHOW DATABASES` |
| `SSL connection required` | Server requires SSL but toggle is off | Enable the SSL toggle |
| `Host is not allowed to connect` | MySQL's `bind-address` or user host restriction | Ensure the user is created with `'%'` host, not `'localhost'` |
| `tinyInt1isBit` confusion | TINYINT(1) returned as boolean | Add `tinyInt1isBit=false` to Additional JDBC Parameters |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.