Passwords and keychain
- PostgreSQL
- MySQL
- MariaDB
- MongoDB
- Redis / Valkey
- Elasticsearch
- CLI
Querybara never stores a password in the connection profile itself. Each secret of a profile (the database password, an API key or token, SSH passwords and key passphrases, the proxy password) has its own storage choice, and the value goes to the app’s main process only. The connection dialog never shows a saved secret again.
Storage choices
Section titled “Storage choices”Each secret has a storage field next to it in the connection dialog:
| Field | Tab |
|---|---|
| Password storage | General (API key storage or Token storage for those Elasticsearch sign-ins) |
| SSH password storage | SSH, for each SSH server and jump host |
| Passphrase storage | SSH, for an encrypted private key |
| Proxy password storage | Proxy |
| Choice | What happens |
|---|---|
| Save in the OS keychain | The secret is encrypted with the operating system’s secure storage and kept in Querybara’s store. |
| Remember for this session | The secret stays in memory until Querybara quits. If you leave it empty, Querybara asks for it on connect. |
| Ask every time | Nothing is kept. Querybara asks for the secret each time it connects. |
| No password | For optional secrets only: the connection uses none. |
Save in the OS keychain uses the Keychain on macOS, DPAPI on Windows and the secret service (libsecret) on Linux.
Change a saved password
Section titled “Change a saved password”- Open the connection’s actions menu in the side bar (right-click it, or choose Actions) and choose Edit….
- On the tab that holds the secret, type the new value in its field. Leave it empty to keep the stored one (“Leave empty to keep the stored password”).
- Choose Save.
Switching a secret to Ask every time deletes the saved copy. Deleting a profile deletes its saved passwords.
When Querybara asks
Section titled “When Querybara asks”With Ask every time, or Remember for this session before the first connect, Querybara shows a dialog titled Connect to and the connection’s name, with a field for each missing secret. The value is used for this connection only. Choose Connect to go on. While the dialog is open, the connection’s row in the side bar shows a spinner.
If a saved password can no longer be read on this computer, the same dialog asks for it with “The saved password cannot be read on this system any more; enter it again.”
From the command line
Section titled “From the command line”The querybara tool cannot use the desktop app’s keychain. It looks for a password in this order:
- a password in a URI target (used for that run only, never stored);
- a secret the CLI saved itself, sealed with the passphrase in
QUERYBARA_PASSPHRASE; QUERYBARA_PASSWORD_<PROFILE>(the profile name upper-cased, other characters as_), thenQUERYBARA_PASSWORD;- a hidden prompt, when it runs in a terminal.
| Variable | What it holds |
|---|---|
QUERYBARA_PASSPHRASE |
Seals and unseals secrets the CLI saves in the store. |
QUERYBARA_PASSWORD |
The password for targets without one. |
QUERYBARA_PASSWORD_<NAME> |
The password for one profile. |
QUERYBARA_SSH_PASSWORD |
The SSH password. |
QUERYBARA_SSH_KEY_PASSPHRASE |
The passphrase of an encrypted SSH key. |
QUERYBARA_PROXY_PASSWORD |
The proxy password. |
QUERYBARA_PASSPHRASE=… querybara profiles add shop-prod "postgres://app:[email protected]/shop" --password-policy saveQUERYBARA_PASSWORD_SHOP_DEV=… querybara test shop-devWithout QUERYBARA_PASSPHRASE, the CLI cannot save secrets. A secret the desktop app saved in the
keychain reads as unavailable to the CLI, which then falls back to the variables or the prompt.
Related
Section titled “Related”Documents Querybara 0.1.1 · built frombc9f5aa