---
summary: Endpoint, TLS requirements, connection strings per language, and pool settings.
title: Connecting
path: using/connecting
status: published
---

# Connecting

Each cluster has one endpoint, `db.<cluster>.scuttle.scailabs.ai`, port `3306`. It always points at a healthy server; you never address individual servers.

## TLS is required

Plaintext connections are refused, and so is TLS below 1.2. The certificate is issued by a public CA for the endpoint name, so verification works with the system trust store — turn verification **on**; there is no ScaiLabs CA to install.

## Connection strings

| Stack | Connection string |
|---|---|
| CLI | `mariadb --host=<endpoint> --ssl-verify-server-cert --user=<account> -p <database>` |
| JDBC | `jdbc:mariadb://<endpoint>:3306/<database>?sslMode=verify-full` |
| Go | `<account>:<password>@tcp(<endpoint>:3306)/<database>?tls=true` |
| .NET | `Server=<endpoint>;Port=3306;Database=<database>;User ID=<account>;Password=...;SslMode=VerifyFull` |
| Python | `mariadb.connect(host=..., ssl=True, ssl_verify_cert=True, ...)` |
| Node (`mysql2`) | `createPool({host, ssl: {rejectUnauthorized: true}, ...})` |

Use the physical names: account `acme_shop_app`, database `acme_shop_orders`. The console and `GET .../databases/<name>` show these strings filled in.

## Pool settings

Keep the pool small and let it reconnect. An account may hold 100 connections by default. Set a connection lifetime below eight hours, enable a validation query or keep-alive, and make sure the pool replaces a broken connection instead of failing the request.

Open connections at a steady pace rather than in bursts. One source address may open at most 300
new connections in 10 seconds; beyond that, new connections are refused for a moment (see
[Limitations](/docs/scuttle/concepts/limitations)). A pool that opens its minimum size on start-up
is fine. Hundreds of short-lived processes that each open their own connection at once aren't.

## Restricting where an account connects from

An account can be limited to the networks it may connect from. A connection from anywhere else
is refused as if the password were wrong.

| Family | What you can list |
|---|---|
| IPv4 | any network, e.g. `203.0.113.0/24`, or a single address `203.0.113.7/32` |
| IPv6 | single addresses only, e.g. `2001:db8::7/128`; ranges are refused because MariaDB cannot match them |

To find the address your application connects from, run this on that host:

```bash
curl -4 https://scuttle.scailabs.ai/api/v1/myip
curl -6 https://scuttle.scailabs.ai/api/v1/myip
```

Each answer contains the entry to add, for example `"allowed_networks_entry": "203.0.113.7/32"`.
`?format=text` returns just the address.

**Dual-stack hosts need both entries.** The endpoints answer over IPv4 and IPv6, and many hosts
prefer IPv6. An account that lists only the IPv4 address refuses the same host when it connects
over IPv6, and the other way round.
