Caracal: Postgres & SQL Client
A native Postgres and SQLite client for Mac, iPhone and iPad. Mark a connection as production, and Caracal asks before DROP, TRUNCATE, or an UPDATE or DELETE with no WHERE. There's no account, and one purchase covers every device.
Screenshot coming soon
Coming soon to the App Store
Features
Safe on production
- A production connection carries a red "Production" badge, a word as well as a color.
- On production it also asks before
DO,CALLandEXECUTE, whose effects it can't read, and it checks every statement of a script. - Read-only mode refuses statements that would switch it off, and puts the setting back if a function changes it. It prevents accidental writes; for a hard guarantee, connect with a read-only database role.
- Table edits are staged. Review lists every statement, with its values, before anything runs, and they run in one transaction.
- Without a usable key, a table is read-only, and Caracal says why.
- Each connection has a statement timeout, 60 seconds by default for Postgres.
Postgres in depth
- Browse schemas, tables, views, materialized views, functions, sequences and enum types.
- See a table's columns, indexes, constraints and foreign keys, with the definitions Postgres gives.
- Values are shown as Postgres sends them: numerics, timestamps and intervals are never rounded or reformatted. NULL never looks like empty text.
- JSON and JSONB indented with their key order kept, arrays, and bytea as its size and hex.
- Sort, filter, and follow a foreign key to the row it points to. Tables load page by page along their key.
- The query editor runs the statement under the cursor, the selection, or the whole script, with a result for each statement. Cancel stops a running query.
- Errors show their SQLSTATE, detail and hint, and the failing position is marked in your SQL.
EXPLAINandEXPLAIN ANALYZE.- Autocomplete for keywords, schemas, tables and columns, including after an alias.
- History keeps the last 1,000 statements of each connection, on this device only. Save the queries you want to keep as
.sqlfiles. - Export results as CSV, TSV, JSON or SQL
INSERTstatements, with NULL kept apart from empty text.
Connect
- Fill in host, port and database, or paste a
postgres://URL. - TLS: Disable, Require, Verify CA or Verify Full, with your own CA file.
- SSH tunnels with a password or a private key: Ed25519, ECDSA and RSA, including passphrase-protected OpenSSH keys.
- The SSH server's host key is saved the first time you trust it. If it changes, Caracal refuses to connect and shows both fingerprints.
- Open any SQLite file, or create a new one.
- One app for Mac, iPhone and iPad.
Limits
What Caracal does not do, so you can judge it before you rely on it.
- Read-only mode prevents accidental writes. It is not a hard guarantee: connect with a read-only database role for that.
- The production prompt reads the SQL text. A filter that keeps every row (
WHERE true) counts as aWHERE, and a function that deletes (SELECT purge()) looks like aSELECT. - Caracal accepts MD5 password logins on connections without verified TLS (Disable and Require), because many servers still use
md5. On such a connection an attacker in the middle can downgrade a SCRAM login to MD5 and capture a response that can be cracked offline. Cleartext passwords are sent only over verified TLS. - The SSH keepalive covers only the leg from your device to the SSH host. If the leg between that host and the database goes silent, a running statement waits until its statement timeout gives up.
EXPLAIN ANALYZEruns in a transaction that is rolled back. Sequence changes, session-level advisory locks and writes throughdblinkstill happen.- Views, and Postgres tables without a key, show their first 10,000 rows.
- SSH keys Caracal refuses: encrypted PEM keys, keys using other ciphers (such as gcm or chacha20), DSA,
sk-security-key files, certificates and PuTTY.ppkfiles. RSA keys sign with SHA-2 only, which needs OpenSSH 7.2 or later on the server. - Editing matches a row by its key only. Caracal doesn't check that a cell still holds the value it loaded, so if another session changed a cell you also edited, your value replaces theirs without a warning. Cells you didn't edit aren't touched. If the row is gone or its key changed, the commit fails and rolls back.
Price
- Free
- 1 server connection
- Pro
- One-time purchase
SQLite files are always free and never count. Caracal Pro unlocks unlimited connections on Mac, iPhone and iPad with one purchase. No subscription. Family Sharing is supported.
Privacy
No account. No analytics. Caracal connects straight from your device to your database or SSH host, and collects no data. Read the full privacy policy.
Changelog
- 1.0
- Coming soon.