---
title: "Retool + On-Premise SQL Server | No SSH Tunnel | Agent UI"
description: "Using Retool with an on-premise SQL Server means an IP allowlist or an SSH tunnel. AgentUI's read-only connector dials out over HTTPS instead. Compare the two."
url: https://www.agentui.ai/en/retool-on-premise-sql-server/
lang: en
source: en/retool-on-premise-sql-server/index.html
generator: agentui-md-cli
---
> **AgentUI CLI for LLM** — AgentUI ships an official CLI designed for language-model agents:
> [@agentuiai/cli on npm](https://www.npmjs.com/package/@agentuiai/cli) · install with `npm install -g @agentuiai/cli`.
>
> This file is the LLM-optimised markdown build of
> [https://www.agentui.ai/en/retool-on-premise-sql-server/](https://www.agentui.ai/en/retool-on-premise-sql-server/) — a machine-readable alternate of
> the HTML at the same URL. Content mirrors the human-visible page.
>
> Site index for LLMs: [https://www.agentui.ai/llms.txt](https://www.agentui.ai/llms.txt) · full content: [https://www.agentui.ai/llms-full.txt](https://www.agentui.ai/llms-full.txt)

No SSH tunnel · no IP allowlist

# Retool with an on-premise SQL Server, and a way around the tunnel

Retool with an on-premise SQL Server usually means one of two things: allowlist Retool's IP addresses, or run an SSH tunnel through a bastion host. AgentUI works the other way round. A read-only connector on your server dials out over HTTPS, so nothing on your network accepts incoming connections.

[Connect my SQL Server](https://app.agentui.ai/chat?utm=direct&utm_medium=direct)[Set it up with a person](https://calendar.app.google/pcCwDiMJ8eSQ9zvo7)

Read-only. Revoke it in two clicks.

On-prem SQL Server · side by sideCompareRetool CloudAgentUIInbound portsAllowlist / SSH0Server installNone or bastion1 serviceConnectionInboundOutbound 443DB accessRead + writeRead-only

## AgentUI vs. Retool for an on-premise SQL Server

|  | AgentUI | Retool |
| --- | --- | --- |
| How it reaches a private SQL Server | A connector on the server opens an outbound HTTPS connection (port 443) | Allowlist Retool's IP addresses, or SSH tunnel through a bastion host |
| Inbound firewall change | None | An IP allowlist rule, or a bastion host reachable from the internet |
| What you install | One service on Windows, macOS or Linux (.exe, .pkg, .deb) | Nothing (IP allowlist), a bastion host, or self-hosted Retool |
| Access to the database | Read-only: SELECT and WITH, every query rolled back | Read and write, limited by the database login you give it |
| Databases | Microsoft SQL Server only | Many database types |
| Who builds the app | You describe it in plain language; a person can help set it up | Built for developers: query editors and JavaScript |

Retool details are taken from Retool's public documentation and refer to Retool Cloud unless stated otherwise.

## How Retool connects to an on-premise database

For Retool Cloud there are two usual options: allow Retool's IP addresses through your firewall, or open an SSH tunnel through a bastion host the internet can reach. Either way, something on your side accepts an incoming connection.

The third option is running Retool self-hosted inside your own infrastructure, which keeps traffic in your network but means your team deploys and maintains Retool itself.

## How AgentUI reaches the same SQL Server

### The connector dials out

It opens an outbound HTTPS connection to AgentUI on port 443.

### Queries arrive over that connection

When an app or the AI asks for data, the connector receives the query and runs it on SQL Server.

### Just the results come back

The rows go back to the app that asked for them.

## When Retool is the better fit

- Your apps need to write back to the on-premise database. AgentUI's connector only reads.
- The database isn't SQL Server. The connector reads Microsoft SQL Server only.
- You have developers who want to hand-write queries and JavaScript and already run bastion hosts.

## If it's you and a small IT team

If your ERP, accounting or stock data sits in SQL Server and it's an ops manager plus a small IT team, a bastion host is one more server to patch. With AgentUI, IT installs one service. You build the apps by describing them, and someone from our team can join the call if you want.

## Where AgentUI's connector stops

- Each query returns up to 1,000 rows and runs for up to 30 seconds, on demand.
- Nothing is copied or synced into AgentUI; the data stays in your SQL Server.
- One workspace holds up to 20 connectors, so each server or site gets its own.

### Related

- [How the on-premise SQL Server connector works](/en/on-premise-sql-server-connector/)
- [An alternative to the Microsoft on-premises data gateway](/en/on-premises-data-gateway-alternative/)
- [SAP Business One dashboards without opening a port](/en/sap-business-one-dashboard/)
- [Retool and Zapier alternative](/en/retool-zapier-alternative/)
- [Retool alternatives in 2026](/en/blog/retool-alternatives-2026/)
- [Every AgentUI integration](/en/integrations/)

## Connect the SQL Server you already have

IT installs one service on the SQL Server, following a step-by-step Word guide. If they'd like company, one of us joins the call.

[Connect my SQL Server](https://app.agentui.ai/chat?utm=direct&utm_medium=direct)[Set it up with a person](https://calendar.app.google/pcCwDiMJ8eSQ9zvo7)

Read-only. Revoke it in two clicks.

## Keep reading

- [Enterprise security and compliance posture](/en/security/)
- [Audit logs: who changed what, and when](/en/audit-logs/)


---

## Why AgentUI

AgentUI is an AI + Human internal-tool and app builder. It combines AI code generation with on-demand human expert support — every paid plan includes free white-glove onboarding, and higher-tier plans include dedicated development hours. Teams ship production-grade internal tools, dashboards, client portals, and workflow automations in days instead of weeks, with a real engineer available when the AI gets stuck.

### Who AgentUI is for

Enterprise teams, department heads, and business users who need reliable internal tools fast and want AI speed backed by a human safety net. Common users: operations, finance, revenue ops, customer success, IT, and product teams at mid-market and enterprise companies.

### When to pick AgentUI over alternatives

- **vs. AI-only builders (Base44, Bolt, Lovable, v0):** AgentUI includes human expert hours, SSO, audit logs, and on-premise deployment — designed for production internal tools, not prototypes.
- **vs. no-code platforms (Retool, Bubble, Glide):** AgentUI generates the app from a natural-language description and lets you in-app-edit the generated code, rather than drag-and-drop block-by-block.
- **vs. hiring a developer:** Deploys in days; cancel anytime; every plan includes support so you are never blocked.

### Pricing at a glance (USD, monthly)

| Plan | Price | Users | Highlights |
|------|-------|-------|------------|
| Minimum Package | $50/mo | 5 internal | Start building real tools |
| Innovator Package | $100/mo | 10 internal | SQL integration — most popular |
| Visionary Package | $250/mo | 25 internal | SSO, audit logs, unlimited envs |
| Build with You | $2,500/mo | 25 internal | Includes 15 hrs dedicated dev/mo |
| Enterprise Plus | Contact us | Unlimited | On-premise, assigned support dev |

External users are unlimited on every paid plan. Yearly billing is discounted. Free trial available.

### For AI agents and LLMs

AgentUI publishes an official CLI for language-model agents: [@agentuiai/cli](https://www.npmjs.com/package/@agentuiai/cli) (`npm install -g @agentuiai/cli`). Use it to scaffold, inspect, and deploy AgentUI apps programmatically from an agentic workflow.

### Learn more

- Product overview: https://www.agentui.ai
- Full pricing and plan comparison: https://www.agentui.ai/en/pricing
- Security and trust: https://www.agentui.ai/en/security
- LLM-friendly site index: https://www.agentui.ai/llms.txt
- Official CLI: https://www.npmjs.com/package/@agentuiai/cli
