Connection concepts and credentials security
Target Audience: Makers, developers, and security reviewers who need to understand what a database connection is in Toucan AI and how credentials are protected.
TL;DR
- A datasource is the configured link between Toucan AI and an external database or warehouse.
- Toucan AI uses that connection for read-only queries: schema discovery, previews, AI analysis, charts, and embedded analytics.
- Your business data stays in your database. Toucan AI does not copy your warehouse into a separate data lake.
- Connection credentials (passwords, keys, service-account secrets) are encrypted at rest on the platform and masked in the UI and API when you view or edit a connection.
- You remain responsible for who can create or edit connections, for using read-only database users, and for network allow-listing.
When to use this
Use this page before or while connecting a database, or when evaluating how Toucan AI handles secrets. For step-by-step setup, see Add a database. For encryption details across the platform, see Secrets & encryption.
What a connection is
A connection stores everything Toucan AI needs to reach your source system:
| Element | Role |
|---|---|
| Datasource type | PostgreSQL, MySQL, Google BigQuery, ClickHouse, Snowflake, or Oracle |
| Connection details | Host, port, database/warehouse, project, account, etc. (depends on connector) |
| Credentials | Username/password, private key, service-account JSON, wallet, or similar secrets |
| Optional settings | SSL/TLS, schema/owner, role, charset, variables on supported fields |
Once connected, Toucan AI can:
- Discover schemas and tables (read-only)
- Preview sample rows (read-only)
- Propose semantic metadata (descriptions, display names, type casts) stored on the Toucan AI platform, never written back to your database
- Run queries that power charts, dashboards, and the AI assistant
Read-only access: Toucan AI does not write to your connected database. Prefer a dedicated read-only database user or service account with the minimum privileges required.
How data access works
Toucan AI separates platform data from your connected data:
| Zone | What it is | Where it lives |
|---|---|---|
| Platform | Accounts, dashboards, chart configs, AI history, encrypted connection credentials | Toucan AI database |
| Your database | Tables and rows (system of record) | Your infrastructure |
| Request-time results | Rows returned for a chart or AI answer | Processed per request — not stored as a bulk Toucan copy |
At query time, Toucan AI decrypts credentials server-side, runs the query against your database (with RLS/CLS when configured), and uses the result only for that operation.
See Data access boundaries and Data storage & retention.
Credentials security
Storage and encryption
When you save a connection:
- Secrets are encrypted at rest in the Toucan AI platform database.
- Only authorized server-side operations (for example test connection, schema discovery, chart queries) can decrypt them.
- Sensitive fields are masked in the product UI and API responses when you view or edit a connection.
- Encryption keys can be rotated; older ciphertext may be re-encrypted when credentials are accessed with a newer key.
Credentials remain stored until you delete the connection in the product.
What encryption does not cover
- Encryption does not replace access control inside your Toucan organization — anyone who can create or edit connections can supply or replace credentials.
- Variable fields on connection forms: default values stored on the platform for testing are not encrypted as secrets in the current version. Runtime values supplied via the embed token (user attributes) are protected because the token itself is encrypted (JWE) (see Variable management).
- Query result rows are not kept in a dedicated encrypted cache; protection relies on TLS (as configured), access control, and not persisting bulk copies of your data.
Network and transport
- Allow-list Toucan AI static IPs on your firewall or security group (see Supported databases).
- Prefer TLS-enabled database endpoints where your connector supports them (SSL mode, wallets, cloud-managed TLS, etc.).
Shared responsibilities
| Responsibility | You | Toucan AI |
|---|---|---|
| Create and manage database users / service accounts | ✅ | — |
| Use least-privilege, preferably read-only credentials | ✅ | — |
| Allow-list Toucan AI IPs / network path | ✅ | — |
| Restrict who can create or edit connections in Toucan | ✅ | — |
| Encrypt connection secrets at rest | — | ✅ |
| Mask secrets in UI/API | — | ✅ |
| Decrypt only for authorized server-side query paths | — | ✅ |
| Enforce RLS/CLS on queries | You define rules | Toucan enforces at query time |
Best practices
- Create a dedicated read-only account for Toucan AI; avoid shared admin credentials.
- Rotate database passwords and keys on a regular schedule; update the connection after rotation.
- Limit Toucan roles so only trusted admins manage connections.
- Never commit connection strings, passwords, private keys, or service-account JSON to source control.
- Use TLS wherever the connector supports it.
- After deleting a connection in Toucan, revoke or rotate the corresponding credentials on your side if they are no longer needed.
Related pages
- Supported databases — connectors and network requirements
- Add a database — setup steps per connector
- Data readiness requirements — prepare data before connecting
- Secrets & encryption — platform-wide secret handling
- Data storage & retention — what is persisted vs queried on demand
- Variable management — dynamic values on connection fields
Constraints
- Toucan AI performs read-only operations on connected databases.
- Connection secrets are encrypted at rest; organization role hygiene remains your control for who can manage them.
- Authentication formats differ by connector (password, PEM private key, service-account JSON, Oracle wallet, etc.).
- Network connectivity must be opened on the database side; failed allow-listing blocks Test Connection and queries.