> ## Documentation Index
> Fetch the complete documentation index at: https://docs.forge.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# MySQL

> Protect MySQL connections, commands, and supported results.

Direct clients connect to the Resource gateway on TCP `3306`. Use the Resource
access name as the client username and enter a short-lived Forge token as the
password.

```sh theme={"system"}
mysql --ssl-mode=VERIFY_IDENTITY \
  --ssl-ca=forge-resource-ca.pem \
  --host resources.example.com \
  --port 3306 \
  --user production-mysql \
  --password
```

With automatic routing, keep the destination hostname and ordinary client
command.

## Policy fields and actions

Forge can match database, destination user, command, tables, and a literal-free
query pattern. Ordinary and prepared commands and bounded multi-statement
admission are supported. Connections and commands can be allowed, flagged,
approved, or blocked.

Forge can redact exact result columns or remove matching rows. Filtering runs
before redaction and preserves framing and `NULL`. Text-protocol values support
the shared redaction strategies and scalar comparisons. Binary results can
always be nullified; other strategies require a supported textual column.

## Destination authentication

The gateway can use an assigned username and password or generate a temporary
AWS IAM database password from its workload identity for RDS and Aurora.
Destination TLS and hostname verification are always required.

## Current limits

Local infile, compression, change-user, replication, MySQL X Protocol, and
arbitrary binary value rewriting are not supported. Missing, duplicate,
malformed, or incompatible targeted columns fail closed before the original
targeted value is released.

See [Credentials and identity](/resources/credentials-and-identity) and
[Resource Policies](/secure/resource-policies).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.