A connection in Schemity is both a database target and a diagram. Each connection lives inside a workspace and is saved as one JSON file. You can design entirely offline, or attach connection details so Schemity can read a real database and turn its structure into an ERD. Either way, nothing leaves your machine - this is database design software with no cloud.

What do the fields in the connection form mean?

Click + above the diagram list to open the New diagram form. It starts design-only, with just four fields:

  • ID - read-only, derived from the name.
  • Name - a label such as Production DB or Local dev.
  • DB type - the engine: PostgreSQL, MySQL, SQL Server, or SQLite. It decides the data types and the SQL Schemity generates, even with no database behind the diagram.
  • Naming - the naming convention Schemity uses for generated names: snake_case or camelCase.

That is a complete diagram: fill those in, click Create, and start drawing. No live database is involved.

To attach one, click Connect to a database. The form grows a connection section, and a Design only link takes you back:

  • Connect via - how Schemity reaches the database:
    • Direct connection - connect over an accessible host and port.
    • SSH Tunnel - connect through a jump/bastion server. Not offered for SQLite, which is a local file.
  • ENV type - an optional label: Local, Staging, or Production. It is a tag shown next to the connection in the connection list to help you tell environments apart; it has no effect on how Schemity connects. Choosing Production turns on the next setting by default.
  • Ask for the database name before applying a migration - with this on, Apply in the migration dialog stays disabled until you type the database name, so a change meant for staging cannot land on production by a slip. It is per connection, and on by default for Production.

Below them, Database configuration holds the host and port, username, credential, database name, schema, and encryption, described field by field in each engine’s guide. SSH Tunnel adds an Over SSH configuration block for the jump server’s host, port, username, password, and SSH key. A Test button next to Create checks the connection before you save it.

The New diagram form in its design-only state: ID, Name, DB type, Naming, and a Connect to a database link

The New diagram form with Connect via set to Direct connection, showing the database configuration fields and a Test button

The New diagram form with Connect via set to SSH Tunnel, adding the Over SSH configuration fields for the jump server

Can I paste a connection string instead of filling in the form?

Yes. Click Paste connection URL above the database fields, paste the string, and choose Fill the form. Schemity accepts:

  • URIs - postgresql://, postgres://, mysql://, mariadb://, sqlserver://, and mssql://, for example postgresql://user:pass@host:5432/dbname?sslmode=verify-full.
  • A jdbc: prefix - jdbc:postgresql://..., and the jdbc:sqlserver://host:1433;databaseName=... form.
  • The ADO.NET key/value form that the Azure portal hands out, such as Server=...;Database=...;User Id=....

It fills the host, port, username, password, database name, and engine, plus the encryption mode from sslmode or ssl-mode, the root CA from sslrootcert or ssl-ca, and the schema from schema, currentSchema, or a libpq options=-c search_path=.... Anything it did not use is listed in the confirmation, so nothing is silently dropped. A string it cannot read fills nothing and tells you why. The pasted string is only used to fill the form and is never saved.

sslmode=allow and prefer are filled as Require rather than Disable: both quietly fall back to an unencrypted link, and a clear failure at connect time is better than sending production credentials in plain text.

How do I encrypt the connection and verify the server certificate?

Set Encryption in the database configuration block. There are four modes:

  • Disable - no encryption, for local development only.
  • Require - encrypt, but do not check the server certificate.
  • Verify CA - encrypt and check that the certificate was signed by a trusted certificate authority.
  • Verify full (recommended) - encrypt, check the authority, and check that the certificate belongs to the host you are connecting to.

The two verify modes show extra fields. Root CA is the certificate authority file to check against; leave it blank to use your system’s trusted roots, or pick the CA file your provider gives you (AWS RDS, Azure, Google Cloud SQL, or a private CA). PostgreSQL and MySQL also take a Client cert and Client key for servers that authenticate clients by certificate; the two go together, so setting one requires the other. SQL Server does not support client certificates.

Can the password come from a command instead of being stored?

Yes. Set Credential to Command and enter a shell command whose output is the password. Use it for credentials that expire or should never sit on disk:

  • AWS RDS IAM tokens - aws rds generate-db-auth-token ...
  • HashiCorp Vault - vault kv get -field=password ...
  • A password manager - op read op://... for 1Password, or your manager’s CLI.

Click Test command to run it once and see that it returns a credential; it reports the length, never the value. The command runs through your login shell, so the tools on your usual PATH are found even when Schemity was opened from the Dock or Start menu. It gets 30 seconds, which leaves room for a Touch ID prompt or an SSO refresh.

The result is kept in memory for five minutes, so opening a connection runs the command once rather than on every query, and it is never written to disk or to the keychain. Editing the command discards the cached value.

Because a connection file travels with its workspace through Git or a shared folder, a command you did not write never runs on its own: Schemity asks you to approve that exact command for that connection on this machine before its first run. Approvals are stored outside every workspace, so a synced file cannot approve itself. Keep secrets out of the command text itself, since it is saved in the connection file.

Do I need a license to connect to a live database?

Designing a diagram with no database behind it is free. Connecting to a live database with Direct connection or SSH Tunnel - and the reverse-engineering, migrations, and SQL import that depend on it - is unlocked by a one-time desktop license.

Which database engines does Schemity support?

Where are my database passwords stored?

Connections run from your machine directly to your database, so a host on localhost, a private VPN, or an isolated network all work. Passwords are never written into the JSON file - Schemity stores them in your operating system’s keychain. This is what keeps it usable on an air-gapped machine.

How do I open a database read-only?

To browse a database without any risk of changes, right-click a saved connection and choose Open read-only. Schemity opens the diagram in a view that blocks edits and migrations.

Next

Pick your engine and follow its field-by-field guide, starting with Connect to PostgreSQL.