Supported versions
Bytebase supports PostgreSQL 12 and later, including Amazon Aurora PostgreSQL and AlloyDB. It connects through a built-in driver, so there is nothing to install.Create a user for Bytebase
Bytebase applies schema changes and reads the catalog of every database it manages, so give it a dedicated user with broad privileges instead of an application’s account. The examples name the userbytebase.
On a self-managed server, connect as a superuser and run:
SUPERUSER. Connect as the admin account the service gives you, create the user the same way, and grant the service’s admin role instead:
These admin roles still can’t change objects that another role owns. To let Bytebase change them, grant it the owning role, such as
GRANT app_owner TO bytebase;.
For a read-only connection on PostgreSQL 14 or later, create a separate user:
Connection details
Authentication
How Bytebase signs in:- Plain Password: the Username and Password below.
- AWS RDS IAM: an IAM authentication token for Amazon RDS or Aurora. See AWS.
- Google Cloud SQL IAM: an IAM service account for Cloud SQL. See GCP.
Hostname
The host name or IP address of the PostgreSQL server, such asdb.example.com. With Verify server certificate on, it must be one of the names in the server’s certificate.
Port
The server port. PostgreSQL’s default is5432.
Username
The PostgreSQL role Bytebase connects as.Password
The role’s password. You can also read it from a secret manager.Connection database
The database Bytebase connects to when it isn’t working in a specific database, such as when it tests the connection or lists databases. If you leave it empty, Bytebase usespostgres. Set it when the role can’t connect to postgres.
Bytebase lists every database on the server except template0 and template1 as a Bytebase database, whichever connection database you choose. Schemas such as public appear inside each one. See Database.
TLS
TLS mode decides whether Bytebase encrypts the connection:- Disabled: Bytebase adds no TLS settings, so the driver’s default applies. It uses TLS when the server offers it, without verifying the server, and connects unencrypted when the server doesn’t.
- TLS: Bytebase always encrypts the connection, and fails if the server doesn’t offer TLS.
- Mutual TLS: the same as TLS, and Bytebase also presents a client certificate, for servers that require one.
- System trust: the CAs that the machine running Bytebase already trusts.
- Paste PEM: a CA certificate you paste in PEM format, for a private CA or a self-signed certificate.
- File path: a CA certificate file on the Bytebase server. Not available in Bytebase Cloud.
SSH tunnel
Connects through a bastion host. See SSH Tunnel.Extra Parameters
Connection parameters that Bytebase passes to the driver as key-value pairs, using libpq names such asconnect_timeout. With TLS mode set to Disabled, sslmode controls encryption, so sslmode with the value disable keeps the connection unencrypted even when the server offers TLS.
Supabase
Bytebase connects to Supabase as a regular PostgreSQL server. To find the connection details, open your project in the Supabase dashboard and click Connect at the top of the page. Supabase offers three connection types:
Copy the connection string for the type you chose. A session pooler string looks like this:
- Hostname: the host from the string. Copy it rather than building it from your region, because the number after
aws-varies. - Port:
5432. - Username:
postgresfor a direct connection, orpostgres.<project_ref>for the session pooler. - Password: the database password you set when you created the project.
- Connection database: leave it empty to use
postgres.
Neon
In the Neon Console, open your project and click Connect. In Connect to your branch, choose the branch, database, and role, then turn off Connection pooling to get the direct connection string. Neon recommends direct connections for schema migrations, and its pooler doesn’t keep session state between transactions.- Hostname: the host from the string, without
-poolerin it. - Port:
5432. - Username: the role. Create it in the Neon Console so that it has
neon_superuser. - Password: the role’s password.
- Connection database: the database from the string, such as
neondb.

