Connecting a database
MySQL or PostgreSQL, with tools written from your schema and SQL checked before it runs.
On this page
Caterfli reads your schema and writes the tools for you. Every visible table gets a read tool and a count tool, with the real column list baked into each tool's argument schema — so an agent can only filter and sort on columns that exist.
What you need
- •Host and port. MySQL defaults to
3306, PostgreSQL to5432. - •The database name, and a schema if it is not the default.
- •A username and password, encrypted before they are stored.
Make an account for this and grant it the least it needs. The platform's own restrictions are a second line of defence, not a substitute for database permissions — if the account cannot write, nothing here can write, whatever any agent proposes.
Choosing which tables an agent can see
Every table is included by default, and one added later is picked up automatically. Untick a table and it goes out of reach.
On a large schema this is the setting that matters most. Four hundred tables is eight hundred tools, and a model choosing between eight hundred tools chooses worse than one choosing between twenty. Maximum tables caps the total as a backstop; the checklist is where you actually decide.
Writes are off until you turn them on
A new connection is read-only. Allow write operations adds create, update and delete tools for the tables you selected.
Even with writes on, two things are always refused: schema changes of any kind, and an UPDATE or DELETE with no WHERE clause. A statement that would empty a table is not one the platform will run.
Ad-hoc SQL
Allow ad-hoc SQL adds a single tool that runs a statement the agent composes. It is useful for analysis — the joins and grouping no generated tool covers — and it is off by default because it is the widest thing on the page.
Every statement, generated or ad-hoc, passes the same check first: one statement only, an allow-listed leading keyword, no schema changes, and no unrestricted update or delete. Values are always bound parameters, never pasted into the SQL text. Reads are capped by row count and payload size, and a timeout is set on the session so a runaway query is cancelled at the database rather than holding a worker open.
When the schema changes
Re-run discovery from the connection page. New tables and columns are picked up and tools for dropped tables are removed.