Toucan AI Docs

Connection concepts and credentials security

Target Audience: Makers, developers, and security reviewers who need to understand what a database connection is in Toucan AI and how credentials are protected.

TL;DR

  • A datasource is the configured link between Toucan AI and an external database or warehouse.
  • Toucan AI uses that connection for read-only queries: schema discovery, previews, AI analysis, charts, and embedded analytics.
  • Your business data stays in your database. Toucan AI does not copy your warehouse into a separate data lake.
  • Connection credentials (passwords, keys, service-account secrets) are encrypted at rest on the platform and masked in the UI and API when you view or edit a connection.
  • You remain responsible for who can create or edit connections, for using read-only database users, and for network allow-listing.

When to use this

Use this page before or while connecting a database, or when evaluating how Toucan AI handles secrets. For step-by-step setup, see Add a database. For encryption details across the platform, see Secrets & encryption.


What a connection is

A connection stores everything Toucan AI needs to reach your source system:

ElementRole
Datasource typePostgreSQL, MySQL, Google BigQuery, ClickHouse, Snowflake, or Oracle
Connection detailsHost, port, database/warehouse, project, account, etc. (depends on connector)
CredentialsUsername/password, private key, service-account JSON, wallet, or similar secrets
Optional settingsSSL/TLS, schema/owner, role, charset, variables on supported fields

Once connected, Toucan AI can:

  • Discover schemas and tables (read-only)
  • Preview sample rows (read-only)
  • Propose semantic metadata (descriptions, display names, type casts) stored on the Toucan AI platform, never written back to your database
  • Run queries that power charts, dashboards, and the AI assistant

Read-only access: Toucan AI does not write to your connected database. Prefer a dedicated read-only database user or service account with the minimum privileges required.


How data access works

Toucan AI separates platform data from your connected data:

ZoneWhat it isWhere it lives
PlatformAccounts, dashboards, chart configs, AI history, encrypted connection credentialsToucan AI database
Your databaseTables and rows (system of record)Your infrastructure
Request-time resultsRows returned for a chart or AI answerProcessed per request — not stored as a bulk Toucan copy

At query time, Toucan AI decrypts credentials server-side, runs the query against your database (with RLS/CLS when configured), and uses the result only for that operation.

See Data access boundaries and Data storage & retention.


Credentials security

Storage and encryption

When you save a connection:

  1. Secrets are encrypted at rest in the Toucan AI platform database.
  2. Only authorized server-side operations (for example test connection, schema discovery, chart queries) can decrypt them.
  3. Sensitive fields are masked in the product UI and API responses when you view or edit a connection.
  4. Encryption keys can be rotated; older ciphertext may be re-encrypted when credentials are accessed with a newer key.

Credentials remain stored until you delete the connection in the product.

What encryption does not cover

  • Encryption does not replace access control inside your Toucan organization — anyone who can create or edit connections can supply or replace credentials.
  • Variable fields on connection forms: default values stored on the platform for testing are not encrypted as secrets in the current version. Runtime values supplied via the embed token (user attributes) are protected because the token itself is encrypted (JWE) (see Variable management).
  • Query result rows are not kept in a dedicated encrypted cache; protection relies on TLS (as configured), access control, and not persisting bulk copies of your data.

Network and transport

  • Allow-list Toucan AI static IPs on your firewall or security group (see Supported databases).
  • Prefer TLS-enabled database endpoints where your connector supports them (SSL mode, wallets, cloud-managed TLS, etc.).

Shared responsibilities

ResponsibilityYouToucan AI
Create and manage database users / service accounts✅—
Use least-privilege, preferably read-only credentials✅—
Allow-list Toucan AI IPs / network path✅—
Restrict who can create or edit connections in Toucan✅—
Encrypt connection secrets at rest—✅
Mask secrets in UI/API—✅
Decrypt only for authorized server-side query paths—✅
Enforce RLS/CLS on queriesYou define rulesToucan enforces at query time

Best practices

  • Create a dedicated read-only account for Toucan AI; avoid shared admin credentials.
  • Rotate database passwords and keys on a regular schedule; update the connection after rotation.
  • Limit Toucan roles so only trusted admins manage connections.
  • Never commit connection strings, passwords, private keys, or service-account JSON to source control.
  • Use TLS wherever the connector supports it.
  • After deleting a connection in Toucan, revoke or rotate the corresponding credentials on your side if they are no longer needed.


Constraints

  • Toucan AI performs read-only operations on connected databases.
  • Connection secrets are encrypted at rest; organization role hygiene remains your control for who can manage them.
  • Authentication formats differ by connector (password, PEM private key, service-account JSON, Oracle wallet, etc.).
  • Network connectivity must be opened on the database side; failed allow-listing blocks Test Connection and queries.

On this page