> ## Documentation Index
> Fetch the complete documentation index at: https://ngquct-fix-surrealdb-filters-and-edges.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Trino

> Catalogs and schemas, type mapping, EXPLAIN variants, and the auth a Trino cluster accepts

export const name_0 = "Trino"

export const plugin_0 = "Trino Driver"

What a write does depends on the catalog's connector, not on TablePro. A statement built correctly here can still come back as `NOT_SUPPORTED` because the connector behind that catalog is read-only or implements only part of SQL.

<Frame caption="The Trino connection form with a catalog set">
  <img className="block dark:hidden" src="https://mintcdn.com/ngquct-fix-surrealdb-filters-and-edges/fahIVTyXnw8Vu4Yv/images/trino-connection-form.png?fit=max&auto=format&n=fahIVTyXnw8Vu4Yv&q=85&s=559981fbd50c03f1ee89e24abe3693f1" alt="Trino connection form" width="1560" height="960" data-path="images/trino-connection-form.png" />

  <img className="hidden dark:block" src="https://mintcdn.com/ngquct-fix-surrealdb-filters-and-edges/fahIVTyXnw8Vu4Yv/images/trino-connection-form-dark.png?fit=max&auto=format&n=fahIVTyXnw8Vu4Yv&q=85&s=4a3279b6ca05ad4ef4ae86769261e082" alt="Trino connection form" width="1560" height="960" data-path="images/trino-connection-form-dark.png" />
</Frame>

## Quick setup

Click **New Connection…**, select **Trino**, enter the coordinator host and port, set **Username**, and click **Save & Connect**. A cluster with no authentication needs nothing else, and **Catalog** and **Schema** are optional starting points.

The {name_0} driver is not in the app. Picking {name_0} in the **Choose a Database** sheet offers the
download before the form opens, and opening a saved {name_0} connection installs it without asking.
**Settings > Plugins > Browse > {plugin_0}** installs it up front. See [Plugins](/features/plugins).

## Connection settings

| Field | Description |
| - | - |
| **Host** | Trino coordinator hostname |
| **Port** | Default `8080`, or `8443` when the coordinator serves HTTPS. Port `443` sets **SSL Mode** to **Verify Identity** |
| **Username** | The user the query runs as |
| **Catalog** | Default catalog for unqualified table names. Optional; empty browses every catalog |
| **Schema** | Default schema. Optional |
| **Auth Method** | Authentication pane. `Username & Password` or `JWT Access Token` |
| **Password / Access Token** | The credential the chosen method needs: the account password, or the JWT in **Access Token** |
| **Time Zone** | Options section. Optional IANA zone (`America/New_York`) for the session |

## Connection URL

```text theme={null}
trino://user@host:8080/catalog
```

**Import from URL…** accepts the scheme; macOS does not route `trino://` links. See [Connection URL Reference](/connections/urls).

## Authentication

A password or an access token goes only over TLS, as with the Trino JDBC driver. With **SSL Mode** Disabled, a connection that has either is refused before anything is sent. Leave both empty to connect to a cluster without authentication.

| Method | What is sent |
| - | - |
| **Username & Password** | HTTP Basic auth, for LDAP or password-file authentication |
| **JWT Access Token** | The token as a bearer credential |
| Client certificate | The **Client Certificate** and **Client Key** from the SSL pane, for mutual TLS. PEM or DER, with an unencrypted RSA or EC (P-256, P-384, P-521) key, and the certificate file may carry its chain. Works with any SSL mode other than Disabled. A key with no certificate is ignored |

## Catalogs, schemas, and tables

A connection opens on a catalog and schema, and every query can still name objects in full as `catalog.schema.table`:

```sql theme={null}
SELECT * FROM hive.web.clicks JOIN postgres.public.users USING (user_id);
```

Expand a catalog in the sidebar for its schemas, then a schema for its tables, with materialized views alongside tables and views. Row counts come from `SHOW STATS`. A tab bound to a second catalog keeps the same session; the catalog rides on each request.

Identifiers are quoted with double quotes. Results page with `OFFSET n ROWS FETCH NEXT m ROWS ONLY`, the order Trino's grammar requires.

## Types

* `bigint` and `decimal` are read as exact text, not floating point.
* `varbinary` is shown as hex.
* `array`, `map`, and `row` are shown as JSON, and `json` opens in the JSON viewer.
* `timestamp`, `time`, and their `with time zone` forms keep the value the server returned.

## Editing rows and schema

Cell edits become `INSERT`, `UPDATE`, and `DELETE`. Values carry their Trino type, so a `varchar` holding digits stays quoted, and columns that cannot be compared with `=` (`array`, `map`, `row`) stay out of the `WHERE` clause.

<Danger>
  Editing one of two identical rows changes both, and deleting one deletes both. With no primary keys reported, a row edit matches on every column of the row as it was read, and there is no transaction to roll it back. Check for duplicates before editing a table with no unique column.
</Danger>

The Structure tab creates tables and adds, drops, renames, and retypes columns, in autocommit. A type change is the operation fewest connectors accept.

## Session and query control

`SET SESSION` in the editor holds for the rest of the connection: the properties the coordinator reports back are sent with every later request, and `RESET SESSION` clears one. **Query > Cancel Query** (`Cmd+.`) tells the coordinator to kill the running query, which matters where a runaway query burns real compute.

## EXPLAIN variants

Click the Explain dropdown in the query editor to choose:

| Variant | Statement |
| - | - |
| **Explain (Logical)** | `EXPLAIN`, the logical plan |
| **Explain (Distributed)** | `EXPLAIN (TYPE DISTRIBUTED)`, the plan split into stages |
| **Explain (IO)** | `EXPLAIN (TYPE IO)`, the tables and columns the query reads |
| **Explain (Validate)** | `EXPLAIN (TYPE VALIDATE)`, parses and validates without running the query |
| **Explain Analyze** | `EXPLAIN ANALYZE`, runs the query and reports actual timings |

## SSL/TLS

**Disabled** is the default and speaks plain HTTP. There is no plaintext fallback, so every other mode forces TLS. Port `443` turns on **Verify Identity**. See [Ports that mean TLS](/connections/ssl#ports-that-mean-tls).

| Mode | Certificate check |
| - | - |
| **Preferred** | None |
| **Required (skip verify)** | None |
| **Verify CA** | Certificate chain, against the file under **CA Certificate**. Without that file the connection is refused |
| **Verify Identity** | Chain and hostname, against the CA file or, with none set, the system trust store |

## Limitations

* No primary keys, indexes, or foreign keys are reported. The Structure tab's Indexes view is always empty.
* Import is not available. Export works; see [Import and Export](/features/import-export).
* Kerberos and OAuth 2.0 authentication are not supported.
* The **Query timeout** in [settings](/customization/general-settings#query-timeout) does not reach Trino. A long query runs until you cancel it or the cluster ends it.
* Presto is not supported. It speaks the same protocol under an `X-Presto-` header prefix, and this driver always sends `X-Trino-`.

## Troubleshooting

### Cannot reach the coordinator

Confirm the host and that the coordinator port is open. Trino serves HTTP on `8080` and HTTPS on `8443` by default, and a load balancer in front of it usually serves HTTPS on `443`.

### "The server requires an encrypted connection"

The port serves HTTPS, usually `443` behind a load balancer, and **SSL Mode** is Disabled. The server's reply, often `400 The plain HTTP request was sent to HTTPS port` or `301 redirect to https://…`, is printed underneath. Set **Verify Identity**. A cluster whose certificate comes from a private authority also needs its CA file under **CA Certificate**, or **Required (skip verify)**.

### "The network connection was lost"

A coordinator that serves HTTPS itself, on `8443`, drops a plain HTTP request without answering. Set an SSL mode. A server that demands a client certificate can drop the connection the same way when **Client Certificate** is empty.

### Authentication failed

The coordinator rejected the user, password or access token it was sent, and its reply is printed. Check **Username** and the credential for the chosen **Auth Method**, or ask the cluster's administrator which method it accepts.

### "A password is sent only over TLS"

**SSL Mode** is Disabled and the connection has a password, so it was not sent over plain HTTP. Set **SSL Mode** to **Verify Identity**, or clear the password if the cluster has no authentication.

### "An access token is sent only over TLS"

**SSL Mode** is Disabled and the connection has an **Access Token**, so it was not sent over plain HTTP. A coordinator on plain HTTP ignores the token and trusts the user name alone. Set **SSL Mode** to **Verify Identity**, or clear the **Access Token** if the cluster has no authentication.

### "Verify CA needs a CA certificate"

**SSL Mode** is Verify CA and **CA Certificate** is empty, as on a connection imported from a URL or synced from another Mac. Choose the CA certificate that signed the server's certificate, or set **Verify Identity** to check it against the system trust store.

### "The server redirected the request to …"

Trino never redirects, so a proxy or load balancer in front of it sent this, and the redirect is not followed. A redirect to `https://` on the same host means the proxy serves HTTPS: set **Port** to the one named, usually `443`, and **SSL Mode** to **Verify Identity**. Any other address, often a sign-in page, means the host and port reach the proxy instead of Trino.

### "The server requires a client certificate for TLS mutual authentication"

The server asked for a client certificate and **Client Certificate** is empty. A proxy that demands one fails the TLS handshake, and a coordinator with certificate authentication answers `Unauthorized`, printed underneath. Choose **Client Certificate** and **Client Key** on the SSL pane.

### "The server did not accept the client certificate"

The server asked for a client certificate and refused the one sent. Check that **Client Certificate** chains to the CA the server trusts and has not expired.

### "The client key at … is encrypted"

The key needs a passphrase, and Trino connections have no **Key Passphrase**. A first line of `BEGIN ENCRYPTED PRIVATE KEY`, or a `Proc-Type: 4,ENCRYPTED` line, marks an encrypted key. Write a decrypted copy with `openssl pkey -in encrypted.key -out client.key` and choose that file.

### "The client key at … does not belong to the certificate at …"

**Client Key** is not the private key of **Client Certificate**. Choose the key the certificate was issued for.

### NOT\_SUPPORTED

The catalog's connector does not implement that operation, whatever Trino's grammar allows. Check the connector's own documentation for what it supports.
