Every connection goes through the same steps, in order, and saferow reports each one as it happens. When one fails, it says which step, in one plain sentence, with the fixes that apply to it. The same steps appear in Add a Database, in Connection Settings (⌘I) and in Diagnose (⌥⌘D).
The steps
| Step | What it checks |
|---|---|
| SSH settings | What ssh -G makes of the host, from your ~/.ssh/config |
| SSH sign-in | That ssh can sign in to the server |
| Tunnel | That the tunnel to the database port opens |
| Reach the server | Without SSH: that something answers at the host and port |
| Server answers | That it greets saferow as MySQL or PostgreSQL |
| Sign in | That the user and password are accepted |
| Database | That the database exists and the user may use it |
| Safe reads | That reads can run safely: as your user, or a SELECT-only user |
| Agent access | Whether the agent and saferow mcp may see it |
A SQLite connection has three: the file, Safe reads and Agent access.
When a step fails
- The sentence names what went wrong, such as “Nothing is listening on db.example.com:3306.”
- The buttons under it are the fixes for that case: “Use port 53306”, “Connect through SSH”, “Trust this key…”, “Open in Terminal”.
- Show details shows the driver’s or ssh’s own words, for a search or a support message.
Nothing is saved until a connection has worked once, and Cancel always cancels. A test of an edited connection runs on its own, so a mistake never breaks the one you have.