- In Navicat Premium, Navicat for MySQL or the free Premium Lite, click Connection, choose MySQL, then fill in Connection Name, Host, Port (3306 by default), User Name and Password.
- Use the SSH tab when the MySQL port is not reachable from your desk: Navicat logs in to an SSH server (port 22 by default) and forwards the connection, and the Host on the General tab is then set relative to that SSH server.
- The SSL tab takes PEM files: client key, client certificate and CA certificate, with an option to verify the server certificate against the CA.
- A fresh MySQL server only accepts local connections, so a remote Navicat client needs an account for its host, created with CREATE USER and GRANT.
Create the Navicat MySQL connection
These steps apply to Navicat Premium 18, Navicat 18 for MySQL and the free Navicat Premium Lite 18; MariaDB connections use the same tabs. According to the Navicat manual:
- In the main window, click Connection.
- In the New Connection window, select MySQL as the server type and click Next.
- Fill in the General tab (table below).
- Add SSL or SSH settings if your server needs them.
- Click OK. The connection appears in the Navigation pane; double-click it to open it.
If you already have a Navicat URI for the server, New Connection with URI in the same window fills in the fields for you.
| Field | What to enter |
|---|---|
| Connection Name | Any friendly name, for example "orders-prod MySQL" |
| Host | Host name or IP address of the MySQL server (or, with an SSH tunnel, the address as seen from the SSH server, often localhost) |
| Endpoint | Shown for Amazon Web Services instances instead of a host name |
| Port | The TCP port; MySQL uses 3306 by default |
| User Name and Password | A MySQL account that is allowed to connect from your host |
Connect through an SSH tunnel
An SSH tunnel is the usual answer when a hosting company or firewall blocks port 3306 from outside. Navicat's Help Center notes that with SSH you can reach a remote MySQL server without changing its existing privileges. On the SSH tab, enable Use SSH tunnel and fill in:
- Host and Port of the SSH server (port 22 by default).
- User Name: a user on the SSH server machine, not a database user.
- Authentication Method: Password, Public Key, or Password & Public Key. For a key, give the Private Key file and its Passphrase.
Then set the General tab Host relative to the SSH server: if MySQL runs on the SSH machine itself, that is usually localhost. The SSH server must allow port forwarding (AllowTcpForwarding yes in /etc/ssh/sshd_config), or Navicat cannot tunnel. On Windows, Navicat can also use keys held in Pageant through an SSH agent configuration, as described in its Help Center.
If SSH is not available, the HTTP tab offers HTTP tunnelling: you upload the ntunnel_mysql.php script from the Navicat installation folder to the web server and enter its URL. SSH and HTTP tunnels cannot be used at the same time.
Encrypt the connection with SSL
The SSL tab is available for MySQL and MariaDB. To use client certificates, enable Use authentication and provide the files in PEM format:
- Client Key and Client Certificate: the key and certificate issued for this client.
- CA Certificate: the file listing the certificate authorities you trust.
- Verify server certificate against CA: checks the server's Common Name in the certificate it presents, which protects against connecting to the wrong server.
- Specified Cipher: optional list of permitted ciphers.
The manual adds that a secure connection relies on the OpenSSL library. For a managed cloud MySQL service, take the CA certificate from the provider's own documentation.
The MySQL account Navicat needs
Navicat's Help Center explains that after installation MySQL only allows connections from localhost, so client computers are blocked until an account exists for their host. The MySQL 8.4 manual describes the normal order: create the account with CREATE USER, then give it privileges with GRANT. (Some older Help Center examples combine the two in one GRANT ... IDENTIFIED BY statement; use the two-step form on current MySQL.) Run this as an administrator, replacing the IP address with your client's public address and granting only what the user needs:
CREATE USER 'app_user'@'203.0.113.25' IDENTIFIED BY '<your-password>';
GRANT SELECT, INSERT, UPDATE, DELETE ON mydb.* TO 'app_user'@'203.0.113.25';Common Navicat MySQL connection errors
To rule out problems on your own machine, the manual lists a read-only MySQL test server run by Navicat (host server1.navicat.com, port 4406, with the credentials given in the manual). If that connects but your server does not, the issue is on the server or network side.
| Error | What it means | What to check |
|---|---|---|
| 2003 - Can't connect to MySQL server on xxx (10061) | Nothing answered on that host and port | That mysqld is running and listening on the port you entered, that it was not started with --skip-networking, and that no firewall blocks the port. Or use an SSH tunnel. |
| 1044/1045 - Access denied for user | The server rejected the user, password or host | The password, and that an account exists for your client host with the privileges you need |
| 1130 - Host xxx is not allowed to connect | No account matches your client host | Create an account for your client host and user name, as in the SQL above |
Frequently asked questions
What port does Navicat use for MySQL?
The port you type on the General tab. MySQL's default is 3306, which is what Navicat's Help Center tells you to check first. With an SSH tunnel, Navicat connects to the SSH port (22 by default) and forwards to MySQL from there.
Can the free Navicat Premium Lite connect to MySQL?
Yes. Premium Lite connects to MySQL and MariaDB as well as the other engines Navicat supports; the limits of Lite are in features such as data transfer and modelling, not in connections.
Why does Navicat say access denied when the password is right?
MySQL matches accounts on user name and client host. If the account exists only for localhost, a remote Navicat client is refused. Create an account for your client host, or connect through an SSH tunnel so the connection comes from the server itself.
How do I connect Navicat to MySQL over SSH with a key file?
On the SSH tab, enable Use SSH tunnel, enter the SSH host, port and user, choose Public Key as the authentication method, and select the Private Key file and its passphrase. Then set the General tab Host as seen from the SSH server.
Sources
- Navicat 18 manual: Establish Connection
- Navicat 18 manual: General Settings
- Navicat 18 manual: SSL
- Navicat 18 manual: SSH Tunneling
- Navicat 18 manual: HTTP Tunneling
- Navicat Help Center: Why I cannot connect to my server?
- Navicat Help Center: 2003 - Can't connect to MySQL server
- Navicat Help Center: 1044/1045 - Access denied
- Navicat Help Center: 1130 - Host is not allowed to connect
- Navicat Help Center: SSH agent and Pageant on Windows
- Navicat Premium Lite product page
- Navicat 18 manual: Main UI
- MySQL 8.4 Reference Manual: CREATE USER
- MySQL 8.4 Reference Manual: GRANT
Checked 8 October 2026.
How we research tool guides: our editorial method. CodeWithSQL earns nothing from the vendors mentioned.