Connect · Amazon RDS
Connect to Amazon RDS for MySQL from your Mac
Copy the endpoint and port from the Connectivity & security tab and the master user name from Configuration. Your Mac needs a network path: a publicly accessible instance and a security group rule for your IP, or a bastion host.
Updated 9 October 2026
What you need
- The instance’s endpoint, port, and the master user name and password (or another MySQL user).
- A network path from your Mac. To connect from outside its VPC, AWS says the instance must be publicly accessible and its security group must allow you in. Otherwise, go through a host inside the VPC.
- The RDS certificate bundle,
global-bundle.pem, to check the server’s certificate.
Find your connection details
- Open the Amazon RDS console and choose Databases.
- Choose the MySQL instance. On the Connectivity & security tab, copy the Endpoint and note the Port (3306 by default).
- For the user name, open the Configuration tab and look at Master username (
adminin AWS’s examples).
Or from the AWS CLI:
aws rds describe-db-instances \
--filters "Name=engine,Values=mysql" \
--query "*[].[DBInstanceIdentifier,Endpoint.Address,Endpoint.Port,MasterUsername]"
Network access. The instance’s VPC security group needs an inbound rule for its port from your address; the console’s My IP source fills in the address your browser has. For an instance that isn’t publicly accessible, AWS recommends a VPN or AWS Direct Connect, or else a bastion host: an EC2 instance in the same VPC that you tunnel through over SSH. An RDS Proxy can’t be made publicly accessible, so from a Mac you use the instance endpoint (or reach the proxy from inside the VPC).
Connection string
mysql://<user>:<password>@<instance>.<id>.<region>.rds.amazonaws.com:3306/<database>
The database part is optional. Percent-encode special characters in the password; see special characters in passwords and MySQL connection strings.
TLS
Every RDS for MySQL instance supports TLS, but it isn’t required unless you set the
require_secure_transport parameter to ON in the instance’s DB parameter group (it’s OFF by
default, and the change needs no reboot). With it on, an unencrypted client gets:
MySQL Error 3159 (HY000): Connections using insecure transport are prohibited while --require_secure_transport=ON.
The server certificate comes from an Amazon RDS certificate authority, which macOS doesn’t trust by default. Download the bundle that covers every commercial Region:
curl -O https://truststore.pki.rds.amazonaws.com/global/global-bundle.pem
Use it with full verification, which also checks the endpoint name against the certificate
(--ssl-mode=VERIFY_IDENTITY in the MySQL client).
Connect with Inlet
- Choose New Connection, pick MySQL, and enter the endpoint, port, user and password. Or paste
a
mysql://URL and Inlet fills in the form. - Under TLS, choose
verify-fulland selectglobal-bundle.pemas the CA file. That checks both the certificate and the endpoint name. - For a private instance, turn on the SSH tunnel and give the bastion host. Inlet uses the system
ssh, so your~/.ssh/config, the SSH agent and the 1Password SSH agent work. Keep the instance endpoint as the database host. - Keep the password in the Keychain, or have Inlet ask each time.
- Tag the environment. A production connection opens read-only: the server refuses writes until you unlock it for ten minutes.
Connect from the command line
AWS’s example with full verification (MySQL 5.7 client or later):
mysql -h <instance>.<id>.<region>.rds.amazonaws.com --ssl-ca=global-bundle.pem --ssl-mode=VERIFY_IDENTITY -P 3306 -u <user> -p
The MariaDB client takes --ssl-ca=global-bundle.pem --ssl instead of --ssl-mode. Check which one
you have with mysql --version. Homebrew’s mysql-client package has the MySQL client; it’s
keg-only, so run /opt/homebrew/opt/mysql-client/bin/mysql.
IAM database authentication. The password is a token valid for 15 minutes, sent as clear text, so TLS is required:
RDSHOST="<instance>.<id>.<region>.rds.amazonaws.com"
TOKEN="$(aws rds generate-db-auth-token --hostname $RDSHOST --port 3306 --region <region> --username <user>)"
mysql --host=$RDSHOST --port=3306 --ssl-ca=global-bundle.pem --enable-cleartext-plugin --user=<user> --password=$TOKEN
The MariaDB client doesn’t need --enable-cleartext-plugin. The token only matters while signing
in; an open session continues after it expires.
Troubleshooting
- ERROR 2003: Can’t connect to MySQL server or a timeout: check the endpoint and port, that Publicly accessible is Yes, and that the security group allows your current IP. Some company firewalls block the database port.
- ERROR 1045: Access denied: wrong user or password, or a user that isn’t allowed from your address. With IAM, the token may be stale or made for a different host, port or user.
- Error 3159, insecure transport prohibited:
require_secure_transportis on. Turn on TLS. - Certificate verify failed: you connected by IP address or your own DNS name. Use the endpoint, and the bundle from AWS (only register the root CAs; AWS warns that adding intermediate certificates can break connections when RDS rotates server certificates).
Related
Sources
- docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_ConnectToInstance.html
- docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_ConnectToInstance.EndpointAndPort.html
- docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_ConnectToInstanceSSL.CLI.html
- docs.aws.amazon.com/AmazonRDS/latest/UserGuide/mysql-ssl-connections.require-ssl.html
- docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.SSL.html
- docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.IAMDBAuth.html
- docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.IAMDBAuth.Connecting.AWSCLI.html
- docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_ConnectToPostgreSQLInstance.Troubleshooting.html
- docs.aws.amazon.com/AmazonRDS/latest/UserGuide/rds-proxy.html
- repost.aws/knowledge-center/rds-connect-ec2-bastion-host