Skip to main content
What a write does depends on the catalog’s connector, not on TablePro. A statement built correctly here can still come back as NOT_SUPPORTED because the connector behind that catalog is read-only or implements only part of SQL.
Trino connection formTrino connection form

The Trino connection form with a catalog set

Quick setup

Click New Connection…, select Trino, enter the coordinator host and port, set Username, and click Save & Connect. A cluster with no authentication needs nothing else, and Catalog and Schema are optional starting points. The Trino driver is not in the app. Picking Trino in the Choose a Database sheet offers the download before the form opens, and opening a saved Trino connection installs it without asking. Settings > Plugins > Browse > Trino Driver installs it up front. See Plugins.

Connection settings

Connection URL

Import from URL… accepts the scheme; macOS does not route trino:// links. See Connection URL Reference.

Authentication

A password or an access token goes only over TLS, as with the Trino JDBC driver. With SSL Mode Disabled, a connection that has either is refused before anything is sent. Leave both empty to connect to a cluster without authentication.

Catalogs, schemas, and tables

A connection opens on a catalog and schema, and every query can still name objects in full as catalog.schema.table:
Expand a catalog in the sidebar for its schemas, then a schema for its tables, with materialized views alongside tables and views. Row counts come from SHOW STATS. A tab bound to a second catalog keeps the same session; the catalog rides on each request. Identifiers are quoted with double quotes. Results page with OFFSET n ROWS FETCH NEXT m ROWS ONLY, the order Trino’s grammar requires.

Types

  • bigint and decimal are read as exact text, not floating point.
  • varbinary is shown as hex.
  • array, map, and row are shown as JSON, and json opens in the JSON viewer.
  • timestamp, time, and their with time zone forms keep the value the server returned.

Editing rows and schema

Cell edits become INSERT, UPDATE, and DELETE. Values carry their Trino type, so a varchar holding digits stays quoted, and columns that cannot be compared with = (array, map, row) stay out of the WHERE clause.
Editing one of two identical rows changes both, and deleting one deletes both. With no primary keys reported, a row edit matches on every column of the row as it was read, and there is no transaction to roll it back. Check for duplicates before editing a table with no unique column.
The Structure tab creates tables and adds, drops, renames, and retypes columns, in autocommit. A type change is the operation fewest connectors accept.

Session and query control

SET SESSION in the editor holds for the rest of the connection: the properties the coordinator reports back are sent with every later request, and RESET SESSION clears one. Query > Cancel Query (Cmd+.) tells the coordinator to kill the running query, which matters where a runaway query burns real compute.

EXPLAIN variants

Click the Explain dropdown in the query editor to choose:

SSL/TLS

Disabled is the default and speaks plain HTTP. There is no plaintext fallback, so every other mode forces TLS. Port 443 turns on Verify Identity. See Ports that mean TLS.

Limitations

  • No primary keys, indexes, or foreign keys are reported. The Structure tab’s Indexes view is always empty.
  • Import is not available. Export works; see Import and Export.
  • Kerberos and OAuth 2.0 authentication are not supported.
  • The Query timeout in settings does not reach Trino. A long query runs until you cancel it or the cluster ends it.
  • Presto is not supported. It speaks the same protocol under an X-Presto- header prefix, and this driver always sends X-Trino-.

Troubleshooting

Cannot reach the coordinator

Confirm the host and that the coordinator port is open. Trino serves HTTP on 8080 and HTTPS on 8443 by default, and a load balancer in front of it usually serves HTTPS on 443.

”The server requires an encrypted connection”

The port serves HTTPS, usually 443 behind a load balancer, and SSL Mode is Disabled. The server’s reply, often 400 The plain HTTP request was sent to HTTPS port or 301 redirect to https://…, is printed underneath. Set Verify Identity. A cluster whose certificate comes from a private authority also needs its CA file under CA Certificate, or Required (skip verify).

”The network connection was lost”

A coordinator that serves HTTPS itself, on 8443, drops a plain HTTP request without answering. Set an SSL mode. A server that demands a client certificate can drop the connection the same way when Client Certificate is empty.

Authentication failed

The coordinator rejected the user, password or access token it was sent, and its reply is printed. Check Username and the credential for the chosen Auth Method, or ask the cluster’s administrator which method it accepts.

”A password is sent only over TLS”

SSL Mode is Disabled and the connection has a password, so it was not sent over plain HTTP. Set SSL Mode to Verify Identity, or clear the password if the cluster has no authentication.

”An access token is sent only over TLS”

SSL Mode is Disabled and the connection has an Access Token, so it was not sent over plain HTTP. A coordinator on plain HTTP ignores the token and trusts the user name alone. Set SSL Mode to Verify Identity, or clear the Access Token if the cluster has no authentication.

”Verify CA needs a CA certificate”

SSL Mode is Verify CA and CA Certificate is empty, as on a connection imported from a URL or synced from another Mac. Choose the CA certificate that signed the server’s certificate, or set Verify Identity to check it against the system trust store.

”The server redirected the request to …”

Trino never redirects, so a proxy or load balancer in front of it sent this, and the redirect is not followed. A redirect to https:// on the same host means the proxy serves HTTPS: set Port to the one named, usually 443, and SSL Mode to Verify Identity. Any other address, often a sign-in page, means the host and port reach the proxy instead of Trino.

”The server requires a client certificate for TLS mutual authentication”

The server asked for a client certificate and Client Certificate is empty. A proxy that demands one fails the TLS handshake, and a coordinator with certificate authentication answers Unauthorized, printed underneath. Choose Client Certificate and Client Key on the SSL pane.

”The server did not accept the client certificate”

The server asked for a client certificate and refused the one sent. Check that Client Certificate chains to the CA the server trusts and has not expired.

”The client key at … is encrypted”

The key needs a passphrase, and Trino connections have no Key Passphrase. A first line of BEGIN ENCRYPTED PRIVATE KEY, or a Proc-Type: 4,ENCRYPTED line, marks an encrypted key. Write a decrypted copy with openssl pkey -in encrypted.key -out client.key and choose that file.

”The client key at … does not belong to the certificate at …”

Client Key is not the private key of Client Certificate. Choose the key the certificate was issued for.

NOT_SUPPORTED

The catalog’s connector does not implement that operation, whatever Trino’s grammar allows. Check the connector’s own documentation for what it supports.