Features ›

The library

Every database, server, bucket and repository you work with, in one place, grouped the way your work is actually grouped.

Workspaces hold what belongs together

A workspace is a client, a product or a project. One customer's database, its web server, its storage and its repository sit side by side, carry the same colour, and are one search away from each other.

A tag on a workspace is inherited by everything inside it, so marking a workspace Production marks every connection in it. The sidebar groups by kind as well: all your databases, all your file servers, all your repositories, across every workspace.

  • Status by shape as well as colour: connected, connecting, idle, warning and error each look different, so the list reads without relying on colour
  • Favourites and a Recent list above it all
  • Search within a workspace or across the whole library
  • Test Connection works for every kind before you save
A workspace named Bluebird Coffee: a PostgreSQL database, an SSH server, an SFTP web server and a Git repository, each tagged Production, followed by the two credentials and two secrets that belong to it

Credentials, secrets and notes

A credential is its own object. One deploy account can sign in to the web server, the SSH shell and the staging box, so rotating its password is one edit rather than a hunt through every connection that uses it.

Each workspace also keeps secrets (API keys, tokens) and notes (runbooks, deploy checklists, on-call contacts), next to the connections they are about.

Passwords and keys live in the keychain, never in the library itself. SSH tunnels are shared the same way: one bastion definition, attached to any database or file server that has to go through it.

All Connections: databases, servers, file servers and cloud storage from three workspaces, each row showing its host, workspace and tag

Point it at a project folder and it finds the rest

Give a new workspace its project folder and Hydra walks it once, then shows you what it found before anything is imported: Git repositories, plus database connections and cloud storage parsed out of the config files already in the tree, and the credentials sitting in them.

  • Reads .env, docker-compose.yml, Rails database.yml, Django settings, appsettings.json, PHP and Node config, .properties, AWS shared credentials, Firebase and GCP config and more
  • An on-device model judges whether a found secret is real or a placeholder, so nothing is sent anywhere to be classified
  • The walk is bounded and skips node_modules and vendor trees
  • Nothing is imported until you tick it, and secret values are never displayed
Scan results for a project folder: its Git repository, three databases found in config/database.yml, .env and docker-compose.yml, an S3 bucket, and two secrets, one left unticked as a placeholder

The Stripe key in .env reads like a placeholder, so it starts unticked.

Your library, on all your Macs

The library syncs through your own private iCloud database. Passwords and keys go to iCloud Keychain instead, so they sync between your Macs without ever entering the sync store. Without iCloud, Hydra runs local-only and says so in the status bar rather than failing quietly.

The whole library also exports to a single file and imports on another Mac. The export carries every connection, workspace, credential reference and tag, and never a secret: passwords are entered once on the other side.

A library this build cannot open is never deleted. It is moved aside and you are told, so a problem costs you a launch, not your connections.

Try it on your own servers

Fourteen days, everything unlocked, no account required.

Download for macOS