Connect · PlanetScale
Connect to PlanetScale from your Mac
Click Connect on the database’s dashboard, pick a branch and create a password: you get a host, user name, password and database. TLS is required, and the certificate is signed by a CA your Mac already trusts.
Updated 9 October 2026
What you need
- Access to the database in the PlanetScale dashboard, or the
pscaleCLI. - A password for the branch you want. Each password belongs to one branch and can’t read any other branch.
This page covers PlanetScale’s Vitess databases, which speak the MySQL protocol. PlanetScale
Postgres databases work differently: you create role credentials and connect with a PostgreSQL
connection string (pscale connect doesn’t support them).
Find your connection details
- On the database’s dashboard page, click Connect.
- Pick the branch, a password role and a name, then click Create password.
- Under Select your language or framework, choose Other to see the details as a list: database name, host, user name and password.
Copy the password now: PlanetScale stores only a hash, so it can’t show it again.
Passwords from the Connect button get the Admin role. For other roles, go to the database’s Settings → Passwords → New password. The roles are:
| Role | Read rows | Change rows | Change schema |
|---|---|---|---|
| Read-only | Yes | No | No |
| Write-only | No | Yes | No |
| Read/Write | Yes | Yes | No |
| Admin | Yes | Yes | Yes |
A password’s role can’t be changed later, and on production branches with safe migrations turned on, nobody can run DDL directly, whatever the role.
Host and port. The host is a PlanetScale edge address such as aws.connect.psdb.cloud (an
optimised route) or a region’s own, such as us-east.connect.psdb.cloud. The port is 3306.
IP restrictions apply per password: on the Passwords page, open a password’s menu and choose Manage IP restrictions.
Connection string
mysql://<username>:<password>@aws.connect.psdb.cloud:3306/<database>
Use the host your password was created with. Each branch is a separate MySQL database as far as your client is concerned, so you need separate details per branch. See MySQL connection strings.
TLS
TLS is required. PlanetScale signs its server certificates with a CA that’s in the system root stores of common operating systems, and promises to keep using one that is, though it may change which. So check the certificate against your system’s roots, not a downloaded copy of today’s CA.
PlanetScale warns that if you don’t verify the certificate, your connection is open to
man-in-the-middle attacks. Clients built on libmysqlclient, including the mysql command, don’t
load the system roots by themselves; on macOS, point them at /etc/ssl/cert.pem.
Connect with Inlet
- Choose New Connection, pick MySQL, and enter the host, user name, password and database
from the Connect page. Or build a
mysql://URL as above and paste it; Inlet fills in the form. - Under TLS, choose
verify-fulland leave the CA file empty: Inlet checks the certificate against the certificates macOS trusts, which is what PlanetScale asks for. - Save the password in the Keychain, since PlanetScale can’t show it again, or have Inlet ask each time.
- Tag the environment. A production connection opens read-only until you unlock it, for ten minutes at a time.
For a production branch, also create a password with the Read-only role and use it in Inlet. That way PlanetScale itself refuses writes, independent of the client.
Connect from the command line
With the mysql client and full verification:
mysql -h aws.connect.psdb.cloud -P 3306 -u <username> -p <database> --ssl-mode=VERIFY_IDENTITY --ssl-ca=/etc/ssl/cert.pem
Homebrew’s mysql-client package has the client (keg-only: /opt/homebrew/opt/mysql-client/bin/mysql).
Or let the pscale CLI handle credentials. pscale shell opens the mysql client against a
branch; --role reader gives you a read-only session:
pscale shell <database> <branch> --role reader
pscale connect instead opens a secure local proxy, on 127.0.0.1:3306 by default, that other
tools can connect to:
pscale connect <database> <branch> --port 3309
Troubleshooting
- ERROR 1045: Access denied: the user name and password are a pair for one branch. Check you’re using the password for this branch, and that it hasn’t been deleted (deleting a password disconnects its clients, which can take up to five minutes).
Select command denied …orInsert command denied … (ACL check error): the password’s role doesn’t allow that. Create a password with a role that does.- ERROR 2003: Can’t connect, or refused from a new location: the password may have IP restrictions. Check them on the Passwords page.
- Connection fails without TLS: PlanetScale requires it; turn TLS on in your client.
- DDL refused on production: the branch has safe migrations on. Make schema changes on a development branch and deploy them with a deploy request.
Related
Sources
- planetscale.com/docs/vitess/connecting/connection-strings
- planetscale.com/docs/vitess/connecting/secure-connections
- planetscale.com/docs/vitess/tutorials/connect-mysql-gui
- planetscale.com/docs/vitess/tutorials/connect-any-application
- planetscale.com/docs/vitess/security/password-roles
- planetscale.com/docs/vitess/connecting/network-latency
- planetscale.com/docs/vitess/connecting/private-connections
- planetscale.com/docs/cli/connect
- planetscale.com/docs/cli/shell