Retool with an on-premise SQL Server, and a way around the tunnel
Retool with an on-premise SQL Server usually means one of two things: allowlist Retool's IP addresses, or run an SSH tunnel through a bastion host. AgentUI works the other way round. A read-only connector on your server dials out over HTTPS, so nothing on your network accepts incoming connections.
Read-only. Revoke it in two clicks.
AgentUI vs. Retool for an on-premise SQL Server
| AgentUI | Retool | |
|---|---|---|
| How it reaches a private SQL Server | A connector on the server opens an outbound HTTPS connection (port 443) | Allowlist Retool's IP addresses, or SSH tunnel through a bastion host |
| Inbound firewall change | None | An IP allowlist rule, or a bastion host reachable from the internet |
| What you install | One service on Windows, macOS or Linux (.exe, .pkg, .deb) | Nothing (IP allowlist), a bastion host, or self-hosted Retool |
| Access to the database | Read-only: SELECT and WITH, every query rolled back | Read and write, limited by the database login you give it |
| Databases | Microsoft SQL Server only | Many database types |
| Who builds the app | You describe it in plain language; a person can help set it up | Built for developers: query editors and JavaScript |
Retool details are taken from Retool's public documentation and refer to Retool Cloud unless stated otherwise.
How Retool connects to an on-premise database
For Retool Cloud there are two usual options: allow Retool's IP addresses through your firewall, or open an SSH tunnel through a bastion host the internet can reach. Either way, something on your side accepts an incoming connection.
The third option is running Retool self-hosted inside your own infrastructure, which keeps traffic in your network but means your team deploys and maintains Retool itself.
How AgentUI reaches the same SQL Server
The connector dials out
It opens an outbound HTTPS connection to AgentUI on port 443.
Queries arrive over that connection
When an app or the AI asks for data, the connector receives the query and runs it on SQL Server.
Just the results come back
The rows go back to the app that asked for them.
When Retool is the better fit
- Your apps need to write back to the on-premise database. AgentUI's connector only reads.
- The database isn't SQL Server. The connector reads Microsoft SQL Server only.
- You have developers who want to hand-write queries and JavaScript and already run bastion hosts.
If it's you and a small IT team
If your ERP, accounting or stock data sits in SQL Server and it's an ops manager plus a small IT team, a bastion host is one more server to patch. With AgentUI, IT installs one service. You build the apps by describing them, and someone from our team can join the call if you want.
Where AgentUI's connector stops
- Each query returns up to 1,000 rows and runs for up to 30 seconds, on demand.
- Nothing is copied or synced into AgentUI; the data stays in your SQL Server.
- One workspace holds up to 20 connectors, so each server or site gets its own.
Related
Connect the SQL Server you already have
IT installs one service on the SQL Server, following a step-by-step Word guide. If they'd like company, one of us joins the call.
Read-only. Revoke it in two clicks.