Retool now blocks Microsoft SQL Server resources that use Windows Authentication with custom ODBC connection parameters outside an approved allowlist. Previously, unsupported parameters were logged as warnings but still applied. They now cause resource setup to fail.
Who is affectedβ
Self-hosted deployments using Microsoft SQL Server resources with Connect using Windows Auth enabled and one or more custom entries in Connection options (or equivalent resource JSON) whose keys are not on the allowlist. Windows Authentication is not available on Retool Cloud.
How to check if you are affected before upgradingβ
Search your Retool deployment logs (dbconnector / backend) for this exact string from the prior log-only release:
MSSQL Windows Auth ODBC connection string parameter not on allowlist
Each matching log line includes the parameter key (parameterKey in structured logs). Resources that logged this message will fail to connect or save after upgrading until those parameters are removed or replaced.
What you will see after upgradingβ
Resource setup or test connection fails with an error like:
Unsupported MSSQL ODBC connection string parameter "<key>". Only a fixed set of ODBC attributes may be supplied via connection params.
Remediationβ
- Open each affected MSSQL Windows Auth resource.
- Remove unsupported keys from
paramsFromConnectionString. - Use Retool's built-in resource fields where possible. For example, use SSL/TLS for encryption and certificate verification.
- If you need an ODBC attribute that is not listed below, contact Retool Support before upgrading.
Allowed paramsFromConnectionString keysβ
| ODBC attribute | Alternate spellings accepted |
|---|---|
| APP | app |
| ApplicationIntent | applicationintent |
| ColumnEncryption | columnencryption |
| ConnectRetryCount | connectretrycount |
| ConnectRetryInterval | connectretryinterval |
| Connect Timeout | ConnectTimeout, connecttimeout |
| Failover_Partner | failoverpartner |
| FailoverPartnerSPN | failoverpartnerspn |
| HostnameInCertificate | hostnameincertificate |
| IpAddressPreference | ipaddresspreference |
| KeepAlive | keepalive |
| Language | language |
| LoginTimeout | logintimeout |
| MARS_Connection | marsconnection |
| MultiSubnetFailover | multisubnetfailover |
| Packet Size | PacketSize, packetsize |
| QueryLog_On | querylogon |
| QueryLogTime | querylogtime |
| Regional | regional |
| ServerSPN | serverspn, Server_SPN |
| Workstation ID | WorkstationID, workstationid |
| WSID | wsid |
Security-sensitive attributes (Driver, Encrypt, Trusted_Connection, credentials, Server, Database, and similar) are set by Retool and cannot be supplied via connection params.
Common parameters that are blockedβ
- Encryption and certificate trust settings such as
EncryptandTrustServerCertificateβ use the resource SSL/TLS settings instead. LoginRetryCount/LoginRetryIntervalβ useConnectRetryCount/ConnectRetryInterval.- Credential keys such as
Uid,Pwd,User, orPassword. - Keys containing
;or crafted to inject additional ODBC attributes.