Mycelium SQL
macOS 13+ · window
One tunnel, one connection, one window for the query, the result and the history.
Download the DMG, drag Mycelium SQL to Applications, open it.
Mycelium SQL is a client for MySQL servers that sit behind an ssh bastion. Targets are named in a config file, the tunnel is raised with your own ssh, and a connection is pinned rather than juggled — one editor, one results grid, one run log, a searchable history and a schema browser, all in the same window.
It ships with no connection targets: a fresh install connects to nothing and names the file to create. Passwords live in the login Keychain and nowhere else — never in a file the app writes.
It is free, with no account and no checkout, and it updates itself in the background once it is running.
How it works
- 01
Name a target
Add an environment to a plain config file — the bastion, the database, the account. Mycelium SQL connects to nothing until this file exists.
- 02
Raise the tunnel
The app shells out to your own ssh against your own ~/.ssh/config to open the forward, then opens one pinned MySQL connection through it.
- 03
Work in one window
An editor, a results grid, a run log, searchable history and a schema browser share the same pinned connection until you switch it.
Privacy
Talks to your bastion, and nothing else
Mycelium SQL talks to exactly the bastion and the database you configured, and — only if update checks are on — to its own update feed. There is no account, no server of this app's own, and no telemetry.
Passwords live in the login Keychain, under the service com.mycelium.sql, never in a file this app writes.
What it does
- One pinned connection
- A connection is chosen and held rather than juggled across tabs — the editor, the grid, the log and the history all follow the one you pinned.
- Your own ssh, your own bastion
- The tunnel is raised by executing your own ssh against your own ~/.ssh/config. Mycelium SQL never stores or reimplements a host key, a jump host, or a credential ssh already manages.
- Nothing to connect to on first launch
- A fresh install ships with no environments file. It names the file it would create and waits for you to write one, rather than guessing at a target.
- History that stays local
- Every executed statement lands in a local log, searchable later, and it never leaves the machine.
What it needs
- macOS 13 or later
- Apple silicon or Intel
- Your own ssh access to the bastion you want to reach
- An environments file naming at least one target — the app shows you where to create it
Under the hood
A Go core owns the connection, the tunnel and the history; a Swift/AppKit window sits on top of it.
Update checks fetch a fixed Sparkle feed at myceliumtools.com/sql/appcast.xml. The check fetches only the feed itself — no system profile, hardware information, or usage data is sent with it.