Skip to main content
Updated October 11, 2026 Every database starts with one admin user, raffadmin. Give each app or person its own user instead, read-only or read-write, so you can rotate or remove one without touching the others.

Before you start

  • A running PostgreSQL, MySQL or ClickHouse database. Valkey and Kafka have the admin user only.

Add a user

1

Open Access

Open the database and go to the Access tab. Users lists every user, what it Can do and who uses it.
2

Create the user

Click Add user, enter a name (lowercase letters, digits and _, 3 to 31 characters) and pick:
  • Read only: SELECT on all tables. For reports, BI and dashboards.
  • Read & write: SELECT, INSERT, UPDATE, DELETE. For application traffic.
Click Create user.
3

Save the password

The password is shown once. Copy it; you can reveal or rotate it later from Users.
Up to 20 users per database. Names used by the engine or by Raff (raffadmin, postgres, root, admin and others) cannot be taken. On PostgreSQL, users get access to the public schema, including tables created later by raffadmin. On MySQL, to defaultdb.

Rotate a user’s password

In Users, click New password on the user’s row. The new password is shown once; the old one stops working at once, so update your app first or right after.

Rotate the admin password

In Access, Credentials card, click Rotate password, then click again to confirm. The old password stops working now; every app using raffadmin must reconnect with the new one.

Remove a user

Click Remove on the user’s row and confirm. The user loses access at once; what it created stays in the database.

Do it from your tools

Next steps

Connect to a database

Connect as the new user with As user.

Networking and security

TLS, the allowlist and certificates.
Last modified on October 11, 2026