No SSH tunnel · no IP allowlist

Retool with an on-premise SQL Server, and a way around the tunnel

Retool with an on-premise SQL Server usually means one of two things: allowlist Retool's IP addresses, or run an SSH tunnel through a bastion host. AgentUI works the other way round. A read-only connector on your server dials out over HTTPS, so nothing on your network accepts incoming connections.

Read-only. Revoke it in two clicks.

On-prem SQL Server · side by side
Compare
Retool CloudAgentUI
Inbound portsAllowlist / SSH0
Server installNone or bastion1 service
ConnectionInboundOutbound 443
DB accessRead + writeRead-only

AgentUI vs. Retool for an on-premise SQL Server

AgentUIRetool
How it reaches a private SQL ServerA connector on the server opens an outbound HTTPS connection (port 443)Allowlist Retool's IP addresses, or SSH tunnel through a bastion host
Inbound firewall changeNoneAn IP allowlist rule, or a bastion host reachable from the internet
What you installOne service on Windows, macOS or Linux (.exe, .pkg, .deb)Nothing (IP allowlist), a bastion host, or self-hosted Retool
Access to the databaseRead-only: SELECT and WITH, every query rolled backRead and write, limited by the database login you give it
DatabasesMicrosoft SQL Server onlyMany database types
Who builds the appYou describe it in plain language; a person can help set it upBuilt for developers: query editors and JavaScript

Retool details are taken from Retool's public documentation and refer to Retool Cloud unless stated otherwise.

How Retool connects to an on-premise database

For Retool Cloud there are two usual options: allow Retool's IP addresses through your firewall, or open an SSH tunnel through a bastion host the internet can reach. Either way, something on your side accepts an incoming connection.

The third option is running Retool self-hosted inside your own infrastructure, which keeps traffic in your network but means your team deploys and maintains Retool itself.

How AgentUI reaches the same SQL Server

The connector dials out

It opens an outbound HTTPS connection to AgentUI on port 443.

Queries arrive over that connection

When an app or the AI asks for data, the connector receives the query and runs it on SQL Server.

Just the results come back

The rows go back to the app that asked for them.

When Retool is the better fit

  • Your apps need to write back to the on-premise database. AgentUI's connector only reads.
  • The database isn't SQL Server. The connector reads Microsoft SQL Server only.
  • You have developers who want to hand-write queries and JavaScript and already run bastion hosts.

If it's you and a small IT team

If your ERP, accounting or stock data sits in SQL Server and it's an ops manager plus a small IT team, a bastion host is one more server to patch. With AgentUI, IT installs one service. You build the apps by describing them, and someone from our team can join the call if you want.

Where AgentUI's connector stops

  • Each query returns up to 1,000 rows and runs for up to 30 seconds, on demand.
  • Nothing is copied or synced into AgentUI; the data stays in your SQL Server.
  • One workspace holds up to 20 connectors, so each server or site gets its own.

Related

Connect the SQL Server you already have

IT installs one service on the SQL Server, following a step-by-step Word guide. If they'd like company, one of us joins the call.

Read-only. Revoke it in two clicks.