MySQL · 8.0
Managed MySQL 8.0
The database comes up with host, a port unique to that database, user and certificates ready. Authentication is X509: every connection presents a client certificate, and the platform is what issues the files for you to download.
MySQL was built to be fast and practical
Michael “Monty” Widenius and his collaborators created a database that was light, portable, and easy to integrate — a beginning that still shows in its focus on simplicity.

Michael “Monty” Widenius
Dan Strömberg · CC BY-SA 4.0
A concrete need
The team first tried to use mSQL, but needed more speed and flexibility for their tables.
A familiar API
Instead of abandoning the existing ecosystem, they built a new SQL interface while keeping nearly the same mSQL API, making migration easier.
A family name
MySQL was named after Monty’s daughter, My — a personal detail from a project that became global infrastructure.
What a MySQL here ships with
The tedious part of a fresh MySQL — certificates, user, TLS — is already done by the time the instance shows up in the dashboard.
Version 8.0, already configured
The platform starts the container and hands you the host as id-without-hyphens.db.usa1.vertraweb.app with a port unique to that database. There is no my.cnf to edit and no server to install on your machine.
X509 required
A password alone will not connect: the server demands a client certificate. The CA, the server certificate and the client certificate are generated automatically and are available for download in the dashboard or through the API.
Tables and a SQL console in the dashboard
The Data tab opens schemas, tables, columns, indexes and rows — 200 per page — plus a SQL console with a 10 s timeout enforced by the engine itself. It is the everyday phpMyAdmin, with nothing to install. From the Intermediary plan up.
Snapshots, restores and resets
Start, stop, restart, reset the password, reset the certificates, take a snapshot with a ZIP download and restore an earlier one — all from the dashboard, with 30 seconds between restores.
Where MySQL usually fits
It is the relational database most web applications already expect to find — drivers, ORMs and migration tools exist for every language on the platform.
PHP web applications
PDO and mysqli talk to this instance like to any MySQL 8.0 — the difference is that you have to point the driver's SSL options at the CA and the client certificate, because the server requires X509.
Projects that already assume MySQL
Laravel, Prisma, Sequelize, Hibernate and Django all ship a MySQL dialect. Moving from a local MySQL to here means changing the host, the port and the TLS options in the connection string.
Catalogs, orders and sign-ups
Products, customers and orders are stable-shaped data, and InnoDB handles transactions and foreign keys without application code. To check a query before shipping it, use the SQL console in the Data tab.
The database for the app already running here
Application and database live in the same dashboard and the same plan: one deploy, one account, and the connection goes out over the database host with TLS instead of crossing the open internet to another provider.
Connection details
These values show up on the database page as soon as it finishes starting. The id is the database identifier with the hyphens removed.
| Version | 8.0 |
|---|---|
| Port | <port> |
| TLS | Required |
| Authentication | X509 required |
| Host | <id>.db.usa1.vertraweb.app |
Connecting with the mysql client
That is three files, not one: certificate.pem to validate the server, certificate.crt and certificate.key so the server can validate you. Without the last two, X509 refuses the connection even with the right password.
mysql -h <id>.db.usa1.vertraweb.app -P <port> -u root -p default --ssl-mode=VERIFY_IDENTITY --ssl-ca=certificate.pem --ssl-cert=certificate.crt --ssl-key=certificate.keyA plan for every stage of the project
Memory and storage change with the plan; the engine does not. Compare the plans and pick the one that fits today.
Compare plansOther managed databases
Same dashboard, same certificates, a different engine.
Frequently asked questions about managed MySQL
The questions support gets most often about MySQL databases.
How do I connect over TLS?
TLS is mandatory and authentication is X509, so the client needs all three files: --ssl-ca=certificate.pem, --ssl-cert=certificate.crt and --ssl-key=certificate.key. In drivers it is the same trio under the SSL options (ssl.ca, ssl.cert, ssl.key).
Where do I download the certificates?
On the database page in the dashboard, or through the API. The CA, the server certificate and the client certificate are generated automatically when the database is created and can be downloaded whenever you need them.
What does the destructive reset erase?
The contents of the database: reset returns the instance to its initial state and there is no undo. Resetting the password and resetting the certificates are two other operations — they swap credentials and preserve the data. Take a snapshot first.
How do I restore a snapshot?
From the database's snapshot list: pick the point and confirm the restore. There is a 30 second cooldown between one restore and the next, and the snapshot contents can also be downloaded as a ZIP.
How many databases can I have, and what changes per plan?
On paid plans, there is no fixed number of databases: each instance is created with the RAM you choose and must fit in the plan's available memory. This MySQL instance requires at least 1,024 MB. Free ("suspended") allows 1 app + 1 database, but the Free plan's RAM is still pending definition. Manual snapshots start on Scale; the Data tab, on Intermediary.
Create your MySQL now
Choose the memory, wait for the database to start and download the certificates in the dashboard for the first connection.
Create account