Tabellum
Your databases. One client.

A database client whose AI agent asks before it writes.

Tabellum opens PostgreSQL, MySQL and MariaDB, SQL Server, and BigQuery in one window: browse schemas, run queries in tabs, edit rows, back up and restore. Its agent — and any agent you connect over MCP — can read freely and can change nothing until you click Run on the exact SQL.

Get a key and a build

Registration is free. Your key is valid for 180 days, verified offline — the app never calls home.

Already registered and your key expired? Request a fresh one.

What you get

Downloads

Loading the current release…

Every desktop build's SHA-256 is listed above and in version.json, which is also what the app checks for updates. Phones and tablets install from the store, and ask for no key.

In a browser

The same app runs in a tab, served by tabellum-worker: the engine as a service on a machine of yours that reaches the databases. One container, one origin, your token — there is no Tabellum server in the path, ever.

docker run -d --name tabellum-worker -p 8788:8788   -e TABELLUM_WORKER_TOKEN=<at least 32 random characters>   -v tabellum-data:/data   ghcr.io/dudko-dev/tabellum-worker:latest

Open http://<host>:8788, paste the token, and work: connections, queries, tunnels, and backups run on the worker; passwords and provider keys stay in the browser's encrypted vault and travel only inside the authenticated connection. Put a TLS reverse proxy in front for anything beyond a LAN. The key gates connecting as on the desktop download. The desktop app can point at the same worker through Engine… in its menu. How the worker works.

Agents — inside the app, and outside it

The built-in agent uses your own OpenAI, Anthropic, or Gemini key and talks to that provider directly. It sees schema metadata by default and row data only for connections where you switch that on. On desktop the app also hosts a local MCP server, so Claude Code and friends can draft queries that appear live in your editor:

npx @dudko.dev/tabellum-mcp

One rule for both: a read runs, a write waits for you. The engine classifies the statement — never the model.

Commercial licensing for the npm package beyond the small-entity thresholds: siarhei@dudko.dev.