Support
Questions, bugs, ideas: [email protected].
FAQ
How do I restore my purchase?
On a Mac, choose Unlock Caracal Pro in the Caracal menu. On iPhone and iPad, open the More menu on the connection list and choose Unlock Caracal Pro. Then choose Restore Purchases. Pro is tied to your Apple Account.
What is free, and what does Pro unlock?
Caracal is free for one saved server connection. SQLite files are always free and never count. Caracal Pro is a one-time purchase that unlocks unlimited connections on Mac, iPhone and iPad.
Does Family Sharing work?
Yes. Caracal Pro supports Family Sharing: if Purchase Sharing is on for your family group, everyone in it gets Pro. If it doesn't appear on another device, choose Restore Purchases.
Where are my connections and passwords stored?
The connection list is in Caracal's iCloud Drive container, or on the device if iCloud isn't available. Passwords, SSH keys and passphrases are in your Keychain, synced by iCloud Keychain if you have it turned on. History of the statements you ran stays on this device only. See the privacy policy.
Can I rely on read-only mode?
Read-only mode prevents accidental writes: it refuses statements that would switch it off, and puts the setting back if a function changes it. It is not a hard guarantee. For one, connect with a read-only database role.
Why did Caracal not ask before my destructive statement?
On a production connection, Caracal asks before DROP, TRUNCATE, and an UPDATE or DELETE with no WHERE. It reads the SQL text only. A filter that keeps every row, such as WHERE true, counts as a WHERE, and a function that deletes (SELECT purge()) looks like a SELECT.
Why is my table read-only?
Caracal edits a row by its primary or unique key. A table without a usable key is read-only, and the reason is shown. Views and Postgres tables without a key show their first 10,000 rows.
Can an edit overwrite someone else's change?
Yes, in one case. Editing matches a row by its key only, and Caracal doesn't check that a cell still holds the value it loaded. If another session changed a cell you also edited, your value replaces theirs without a warning. Cells you didn't edit aren't touched. If the row is gone or its key changed, the commit fails and rolls back.
Which SSH keys does Caracal accept?
Ed25519, ECDSA and RSA private keys, including passphrase-protected OpenSSH keys. It refuses encrypted PEM keys (ssh-keygen -p -f converts one), keys using other ciphers such as gcm or chacha20, DSA keys, sk- security-key files, certificates and PuTTY .ppk files (in PuTTYgen, use Conversions > Export OpenSSH key). RSA keys sign with SHA-2 only, which needs OpenSSH 7.2 or later on the server.
Is my connection secure without verified TLS?
With TLS set to Disable or Require, Caracal still accepts MD5 password logins, because many servers use md5. On such a connection an attacker in the middle can downgrade a SCRAM login to MD5 and capture a response that can be cracked offline. Cleartext passwords are sent only over verified TLS (Verify CA or Verify Full).
My query hangs over an SSH tunnel.
The SSH keepalive covers only the leg from your device to the SSH host. If the leg between that host and the database goes silent, a running statement waits until its statement timeout gives up, which is 60 seconds by default for Postgres.
Does EXPLAIN ANALYZE change my data?
EXPLAIN ANALYZE runs in a transaction that is rolled back. Sequence changes, session-level advisory locks and writes through dblink still happen.
Privacy
Read the privacy policy.