
SQLPad may be configured via environment variables or an .env config file.

Config file path may be specified passing command line option --config or environment variable SQLPAD_CONFIG. For example:

node server.js --config path/to/.env
# or
env SQLPAD_CONFIG=path/to/.env node server.js

Application Configuration (General)

# IP address to bind to. By default SQLPad will listen from all available addresses (

# Port to listen on. Used for both HTTP and HTTPS.
# Defaults to 80 in code, 3000 in Docker Hub Image

# Public URL used for various authentication setups. Protocol is expected.
# This value will be sent with webhook payloads as well.
# Example:

# Path to mount SQLPad app following domain.
# Example:
# If SQLPAD_BASE_URL = "/sqlpad" and PUBLIC_URL = "",
# the queries page would be ``

# Passphrase to encrypt sensitive connection information (like user & password) when stored in backing database.
SQLPAD_PASSPHRASE = "At least the sensitive bits won't be plain text?"

# HTTP server timeout as number of seconds.

# HTTP server maximum payload size.
# Defaults to `1mb`
# Uses bytes.js syntax (
# If no unit is given it is assumed the value is in bytes
# Useful valid units are `kb`, `mb` in base 2 (1mb = 1024kb)

# Minutes to keep a session active. Session will be extended by this amount each request.

# Store to use for user session
# Valid values are `file` (default), `database`, `redis`, `memory`
# `file` uses files in the sessions directory under SQLPAD_DB_PATH
# `memory` may be used for single sqlpad instances, and works well for no-auth setups
# `redis` offers best performance and is most commonly used. SQLPAD_REDIS_URI must also be set.
# `database` will use whatever backend database is used (or SQLite if SQLPAD_DB_PATH is set)

# The the SameSite restriction for the Session cookie
# You may need to switch this to 'Lax' for proper login routing in browsers e.g. oidc does not work in firefox with 'strict'.
# any login routing dependent on redirects requires 'Lax' to work for more info read

# Similar to session storage, query result storage may also be configured.
# Valid values are `file` (default), `database`, `redis`, `memory`
# If set to `memory`, store is limited to 1000 entries with a max age of 1 hour
# Other storage mechanisms fall back to SQLPAD_QUERY_HISTORY_RETENTION_PERIOD_IN_DAYS
# If `redis` is used, SQLPAD_REDIS_URI must also be set.

# Name used for cookie. If running multiple SQLPads on same domain, set to different values.
SQLPAD_COOKIE_NAME = "sqlpad.sid"

# Secret used to sign cookies
SQLPAD_COOKIE_SECRET = "secret-used-to-sign-cookies-please-set-and-make-strong"

# Set secure cookie attribute

# Acquire socket from systemd if available

# Allows pre-approval of email domains for variety of authentication mechanisms.
# Delimit multiple domains by empty space.

# Path to root of seed data directories. See Seed Data documentation.

# Trust proxy

Application Behavior

# Enable word wrapping in SQL editor

# By default query results are limited to 10,000 records

# Enable csv, json and xlsx downloads

# Allows access on every connection to every user.

# Query history entries created before the retention period will be deleted automatically.

# By default query history results are limited to 1,000 records.

# Default connection to select on SQLPad load if connection not previously selected.
# Once selected, connection selections are cached locally in the browser.


# URI for redis instance to use when SQLPAD_SESSION_STORE or SQLPAD_QUERY_RESULT_STORE are set to `redis`
# Format should be [redis[s]:]//[[user][:password@]][host][:port][/db-number][?db=db-number[&password=bar[&option=value]]]
# More info at

Backend Database Management

SQLPad may be configured to use SQLite, PostgreSQL, MySQL, MariaDB, or SQL Server as a backing database.

To use SQLite, all that must be set is SQLPAD_DB_PATH, and a sqlite file will be created on application start. In the official docker image, this path is set to /var/lib/sqlpad.

To use a different backend database, set SQLPAD_BACKEND_DB_URI to the desired target database.

# Directory to store SQLPad disk-backed resources.
# Depending on configuration this could include SQLite file, query result cache files, and session storage.
# In the official docker image, this path is set to `/var/lib/sqlpad`.

# You can specify an external database to be used instead of the local sqlite database,
# by specifying a [Sequelize]( connection string.
# Supported databases are: mysql, mariadb, sqlite3, mssql.
# Some options can be provided in the connection string.
# Example: `mariadb://username:password@host:port/databasename?ssl=true`

# If enabled, runs SQLite in memory
# In this case, the database contents will be lost when the application stops.
# SQLPAD_DB_PATH is still required if SQLPAD_SESSION_STORE or SQLPAD_QUERY_RESULT_STORE are set to file.

Database Migrations

By default, migrations are run on service start up. This behavior can be disabled, and migrations can instead be run on demand. This is particularly of use when running multiple instances of SQLPad.

When run on demand, the SQLPad process will exit after migrations complete.

This option is most likely useful as a cli flag, but it can be specified via environment variable as well.


node server.js --config path/to/file.ext --migrate
# or via environment variable
env SQLPAD_MIGRATE = "true" node server.js --config path/to/file.env
# If set to true, SQLPad process will exit after database migration is performed

# Enable/disable automigration on SQLPad process start. Disable by setting to `false`

Service Tokens

Secret to sign the generated Service Tokens.

To generate a service token, log into SQLPad as an admin user and click Service Tokens. A service token can be scoped to a certain role (admin or editor) and limited to a window of time.

The generated Bearer token may be used by passing it via the Authorization header:

curl -X GET -H 'Accept: application/json' -H "Authorization: Bearer the.generated.token" http://localhost:3010/api/users

# Secret to sign the generated Service Tokens


Minimum level for logs. Should be one of fatal, error, warn, info, debug, trace or silent. App logs contain log messages taken by application (running queries, creating users, general errors, etc.) while web logs are used for logging web requests made and related information, like time taken to serve them.


See logging for log examples.


HTTPS may be configured to be used by SQLPad directly. However if performance becomes an issue, consider using a reverse proxy.

# Absolute path to where SSL certificate is stored
# Absolute path to where SSL certificate key is stored
# Passphrase for your SSL certification file


React App Build Configuration

The React build of the sqlpad client directory can be customized via .env files or build-time process environment variables.

# React App API/SPA Base URL Override
# By default, the client-side sqlpad React app expects to be able to call GET api/app to get the baseUrl of the API.  This could be a problem if there is a proxy or API gateway munging URL paths between users' browsers and the sqlpad API server.
# If you're building the React app yourself and hosting the single-page app's index.html at a different URL path from the API, you can set these environment variables at build time to specify the base URL paths of the front-end static content versus API.
# For example, with the following settings, the React app will expect the API to be hosted behind the same domain, but under the /api/sqlpad path; the index.html will be served from /ui; and all single-page app routing will retain /ui as the root path.