PostgreSQL · MySQL · SQL Server · SQLite

The database client you can
trust with production.

Every grid edit is reviewed as SQL before it saves. Read-only is enforced by the database. Secrets stay in your keychain. No account, no telemetry.

14-day free trial, no card, no account · then $39 once · macOS, Windows, Linux

bzora showing the customers table of a production database, with one edited cell waiting to be reviewed
  • Reviewed. Edits are staged and shown as SQL before they run.
  • Enforced. Read-only connections are refused by the database itself on PostgreSQL, MySQL and SQLite, and blocked by the app on SQL Server.
  • Private. Secrets in the keychain. No telemetry. No account.

Safe by default

Production is safe to open

bzora is built on one rule: the app should not change your data in a way you did not see.

Reviewed

Review every edit as SQL before it saves

Edits wait in the grid until you save. You read the exact statements first, and the whole batch runs as one transaction.

  • Inserts, updates and deletes are staged and highlighted.
  • One transaction per save: all of it, or none.
  • Structure changes are previewed as SQL the same way.
The review dialog listing two UPDATE statements before they are saved to a production connection

Enforced

Read-only that the database enforces

Mark a connection read-only and PostgreSQL, MySQL and SQLite refuse the write themselves.

  • On SQL Server, which has no read-only session, bzora blocks writes itself.
  • Every editing control is hidden on a read-only connection.
  • Development, Staging and Production labels show where you are.
An UPDATE refused by PostgreSQL on a read-only connection

Browse

Filter and join without writing SQL

Every table opens as a paged, sortable grid. Add filters and joins by pointing, and see the exact SQL behind what you are looking at.

  • Filters with real operators. Values are always bound as parameters.
  • Joins suggested from your foreign keys.
  • One action opens the grid's query in the editor.
The orders table filtered by status and total, joined to customers

Private AI

An assistant that writes SQL and never runs it

Ask in plain language and it drafts a query for your schema. You decide whether it goes into the editor.

  • A local model through Ollama, an OpenAI-compatible server, or Anthropic with your own key.
  • Read-only MCP for Claude Desktop and Cursor, off until you turn it on per connection.
The assistant panel open beside the SQL editor

What the assistant is sent

  • Your question
  • The dialect and the database name
  • Table and column names, types and keys
  • Your rows. Never.

With a local model, nothing leaves your machine.

A script of three statements with one result tab per statement

SQL editor

Autocomplete for tables and columns, one result per statement, and cancel for a single query.

An ER diagram of six tables linked by their foreign keys

ER diagram

Tables as cards, foreign keys as lines. The quickest way into a database you did not build.

A query plan tree with the slowest step highlighted

Query plans

Explain shows the plan as a tree with the heavy steps highlighted. Analyze measures a real run, then rolls it back.

Connections
Many at once, each with its own tabs. SSH tunnels built in. Paste connection URLs to import them.
Data in and out
Export CSV, JSON or SQL. Import CSV with a preview. Dump and restore a whole database.
Structure
Add, rename, retype or drop columns and indexes. Create or duplicate a table.
History
Every query is kept per database. Star and name the ones you reuse.
JSON and long text
Open in a side panel, where JSON folds and long text wraps.
Session restore
Tabs, filters and query text come back when you reopen. Nothing runs by itself.
Keyboard
⌘P (Ctrl+P on Windows and Linux) finds any table or action. Every shortcut can be rebound.
Native
A Go core with your system's web view. No Electron. Light and dark themes.

Security

Nothing leaks

Keychain only

Passwords, SSH passphrases and API keys live in your OS keychain. The connections file contains no secret.

Verified TLS

Encryption is on by default and the certificate is verified. bzora never drops to a weaker mode silently.

Strict SSH host keys

Tunnels check the host against your known_hosts. An unknown or changed host is refused.

No telemetry

No analytics, no crash reports, no account. The app contacts only your databases, the license check and the update check.

Read the security model, limits included →

Why bzora exists

For years I opened production databases with the same small worry: did I just edit the right row? So I built a client around that worry. You see every edit as SQL before it runs, the database refuses writes when you say read-only, and your passwords never sit in a file.

Actively maintained — last updated 2026-06-23, see the changelog →. Questions? [email protected] — a real person answers.

One-time purchase

One payment. Every update through 1.x.

Try bzora free for 14 days. No card. No account.

$39 one time

Computers
Up to 2 of your own
Updates
Every update through 1.x
Platforms
macOS, Windows and Linux on the same key
Trial
14 days, everything unlocked, no card
Refund
30 days

Wondering how bzora fits next to other clients? See the honest comparisons.

Download bzora

Free for 14 days on any platform — no signup, no email — then unlock it with a one-time license.

Like it? Unlock the full version with one payment. Activate on 2 computers. Buy a license — $39

On Linux you may need gtk-3 and webkit2gtk installed.

By downloading or buying bzora you agree to the EULA & Terms and Privacy policy. Prices are in USD; VAT is added at checkout for EU customers. See your consumer rights — 14-day cancellation and dispute resolution.

Questions

Does bzora send my data anywhere?

No. There is no account and no telemetry. Your queries go only to the databases you connect to. The assistant is optional: with a cloud model it receives table and column names, never rows, and with a local model nothing leaves your machine.

Can I stop myself from changing data by accident?

Yes. Mark the connection read-only. PostgreSQL, MySQL and SQLite refuse the write themselves. SQL Server has no such mode, so bzora blocks it in the app. For a guarantee, connect with a database user that has read rights only.

How does licensing work?

14 days free, no card. Then one payment of $39 and a key for up to 2 of your computers, on any platform. Deactivate in the app to move a seat. It includes every update through 1.x.

What if I am offline, or bzora is discontinued?

After activation the app keeps working for 14 days without checking in, so a plane or a locked-down network is fine. If we ever wind the project down, our plan is to ship a final update that removes license checks entirely.

Can I get a refund?

Yes, within 30 days. bzora is sold through Lemon Squeezy, our merchant of record. Consumers in the EU also have a statutory 14-day right to cancel, described on the Consumer rights page.

Is the source code available?

No. bzora is closed source. The security page says exactly what the app stores, what leaves your computer, and where its limits are.

Is there a team or company plan?

Not as a separate product. Email [email protected] and tell us how many seats you need.

Is it Electron?

No. A Go backend with your system's own web view, and no bundled browser.

Try it free for 14 days

Everything unlocked, no card. Then one payment, with a 30-day refund.