# Connect Base44, Replit and ChatGPT to Your Database

Source: https://wiki.faucetdb.ai/ai-app-builders

**Can a cloud AI tool use a database that isn't on the internet?** Yes. Run Faucet next to the database, give the AI tool an API key with a read-only role, and expose only Faucet over HTTPS. The tool then reaches your data through Faucet's MCP endpoint (`/mcp`) or its REST API and OpenAPI 3.1 spec (`/openapi.json`). The database itself stays private.

This works for any tool that can call an MCP server or an HTTP API: ChatGPT, Base44, Replit, and your own apps. Desktop and IDE agents (Claude Code, Claude Desktop, Cursor, VS Code, Windsurf) that run on the same network as Faucet don't need any of this; see [MCP Server](https://wiki.faucetdb.ai/mcp-server#connect-claude-code).

::: info
Faucet is independent and is not affiliated with or endorsed by OpenAI, Base44, Replit or the other companies named here. "Works with" means the tool connects through MCP or REST/OpenAPI. Check each tool's own documentation for where its settings live, because those screens change.
:::

## 1. Create a read-only role and key

Start with read-only access. You can grant writes later, table by table.

```bash
faucet role create --name ai-readonly --verbs GET --service mydb \
  --description "Read-only access for cloud AI tools"
faucet key create --role ai-readonly --label "Cloud AI tools"   # prints the key once
```

`--verbs GET` allows reading rows and schemas and nothing else. In the admin UI, create a role with **Read only** access on the database, then create a key for it under **API keys**. See [RBAC](https://wiki.faucetdb.ai/rbac) for per-table rules, and mark the service read-only for an extra guard.

::: warning
Row-level filters on roles are not enforced yet, so a key can read every row in the tables its role allows. To share only part of a table, expose a database view instead. See [RBAC → Row-level filters](https://wiki.faucetdb.ai/rbac#row-level-filters-stored-not-yet-enforced).
:::

## 2. Expose Faucet over HTTPS

Cloud tools run on their providers' servers, so they need a public HTTPS URL. Expose Faucet, never the database port. Choose one:

- **Reverse proxy.** Put nginx or Caddy in front of Faucet with a TLS certificate. Configurations are in [Deployment → Reverse Proxy](https://wiki.faucetdb.ai/deployment#reverse-proxy).
- **Cloudflare Tunnel.** `cloudflared tunnel --url http://localhost:8080` prints a temporary `https://*.trycloudflare.com` URL for testing. For a permanent hostname, create a named tunnel in your Cloudflare account.
- **ngrok.** `ngrok http 8080` prints a public `https://` URL that forwards to Faucet.

Then check the URL from outside your network:

```bash
curl https://your-faucet.example.com/healthz
curl "https://your-faucet.example.com/api/v1/mydb/_table?limit=5" \
  -H "X-API-Key: faucet_YOUR_KEY"
```

Every request to `/api/v1/{service}` and `/mcp` needs a valid API key (or an admin session token, which you should never give to a tool). Revoke a key at any time with `faucet key revoke <prefix>` or from the **API keys** page.

## 3. Connect the tool

### Base44, Replit and other AI app builders

If the tool lets you add a custom MCP server, use:

- **URL:** `https://your-faucet.example.com/mcp`
- **Header:** `X-API-Key: faucet_YOUR_KEY`

The tool's agent can then call `faucet_list_tables`, `faucet_describe_table` and `faucet_query` (see [MCP tools](https://wiki.faucetdb.ai/mcp-server#available-tools)).

If it doesn't support MCP, have the generated app call the REST API instead, for example `GET https://your-faucet.example.com/api/v1/mydb/_table/orders?limit=25` with the `X-API-Key` header, or import the OpenAPI spec from `https://your-faucet.example.com/openapi.json`. Keep the key in the platform's secrets store rather than in client-side code.

### ChatGPT

ChatGPT connectors sign in with OAuth, which Faucet does not offer yet. Use a Custom GPT Action instead:

1. Create a GPT and add an **Action**.
2. Import the schema from `https://your-faucet.example.com/openapi.json`.
3. Set authentication to **API key**, auth type **Custom**, header name `X-API-Key`, and paste your key.

If you call OpenAI's Responses API from your own code, you can pass Faucet as an MCP tool instead. See [MCP Server → Use Faucet from ChatGPT](https://wiki.faucetdb.ai/mcp-server#use-faucet-from-chatgpt).

## Checklist

- The key's role is read-only unless the tool truly needs to write.
- Only Faucet is reachable from the internet, over HTTPS. The database port is not.
- Raw SQL (`raw_sql_allowed`) stays off for services that AI tools can reach.
- Each tool gets its own key, so you can revoke one without breaking the others.

## Related

- [MCP Server](https://wiki.faucetdb.ai/mcp-server): transports, tools and per-client setup
- [LLM Integration Guide](https://wiki.faucetdb.ai/llm-guide): how agents should query through Faucet
- [Deployment](https://wiki.faucetdb.ai/deployment): TLS, reverse proxies and the production checklist
- [RBAC](https://wiki.faucetdb.ai/rbac): roles, verbs and API keys
