DBeaver dbvr · Command Line

The database client for things that aren't people.

Your pipelines, cron jobs, containers, and AI agents all connect to production. None of them go through the controls you built for humans. dbvr is the CLI those workloads use — and the place to put the governance back.

What We Build With It Capability & Editions
The Gap

Most of Your Database Traffic Isn't Human Anymore.

Human access is ticketed, reviewed, and recertified every quarter. Non-human access was provisioned once, by someone who has since changed teams, and has never been looked at again.

Credentials that never expire

Static database passwords sit in CI secret stores because rotating them breaks the pipeline. Nobody rotates them.

Grants nobody removed

A reporting account that only reads still holds INSERT, UPDATE, and DELETE from a migration three years ago.

Agents, now

An MCP endpoint takes ten minutes to enable and gives a model schema discovery and SQL execution. It is a database client wearing an AI label.

Capability

One Client. Every Engine. No Interface.

dbvr runs SQL, inspects metadata, manages connections, and exports data across relational, NoSQL, and cloud databases — from a terminal, a container, or a pipeline stage.

dbvr Community

Free · Apache 2.0

Connections, SQL execution, metadata inspection, driver and project management. Commercial use permitted.

Covers: access audits, CI verification, backup validation

dbvr PRO

Licensed

Adds the secret manager, native AWS, GCP, and Azure authentication, cloud storage export destinations, and the MCP server.

Covers: credential migration, governed export, agent access

Practical Notes

Ships with its own Java runtime — no JDK to install. Around 164 MB extracted, so it is a governance and consistency choice rather than a way to slim down a container image. JDBC drivers resolve on first connect.

Returns a non-zero exit code on SQL failure, which is what makes it usable as a pipeline gate. Over 40 database providers supported.

What We Build With It

The Tool Is Free. The Governance Is the Work.

Six engagements, each scoped and deliverable on its own. Most clients start with the audit, because its findings decide which of the other five matter.

Start here · No license required

Non-human access audit

A register of every pipeline, job, service account, and agent endpoint touching your databases — what each can reach, what each can change, and which hold credentials that never expire. Read-only, two weeks.

Pipeline credential migration

Move CI and scheduled jobs off static database passwords onto native cloud identity, so the pipeline authenticates as itself and there is nothing left to rotate.

CI data verification stage

Pre-flight schema checks and post-deploy data assertions wired into your existing pipeline, so a bad migration fails the build instead of failing in production.

Backup validation

Your backup is a hypothesis until something restores it. Nightly cross-engine restore and consistency checks across the fleet, reported. Available as an ongoing service.

Governed export

Replace the ad-hoc CSV in someone's downloads folder with scheduled, logged, destination-controlled extracts that write straight to object storage.

Agent access provisioning

Least-privilege database roles and MCP endpoint topology for AI workloads. The blast radius of an agent is the grant behind its connection — so we design the grant, not the prompt.

Further Reading

The Thinking Behind These Engagements.

Pillar

You Inventoried Your Non-Human Identities. You Never Asked What They Could Reach.

The NHI tools inventory the credential — who owns it, whether it is stale. None of them answer what it can read and change once it is inside your database. That is where your access review stops.

Agents

The MCP Endpoint Is a Database Client. Treat It Like One.

Enabling it takes ten minutes. What you created is a new connection into production with no session, no ticket, and no reviewer — and the only control surface it offers is the connection itself.

Start With the Audit

What Can Your Pipelines Already Do in Production?

If that takes more than a day to answer, the answer is that you don't know. The audit is read-only, takes two weeks, and requires no license purchase.

Request the Audit

Infozense is an official DBeaver reseller. dbvr and DBeaver are trademarks of DBeaver Corporation. Licensing terms are governed by the vendor's agreements.