Skip to content

Reference

ClickHouse

Connect ClickHouse to Alter Vault for secure API access

Use ClickHouse credentials to make authenticated API calls through Alter Vault without exposing API keys in code.

PropertyValue
Provider IDclickhouse
CategoryDatabase
Credential TypeBase64 Credentials

Log in to ClickHouse Cloud

Log in to the ClickHouse Cloud Console and open the service.

Note the connection details

Open Connect and note the HTTPS endpoint, username, and password (or create a dedicated database user).

Encode the credentials

Base64-encode the credentials: echo -n 'username:password' | base64 and paste the result into the credential field.

Open the Developer Portal

Go to portal.alterauth.com and navigate to the application.

Add ClickHouse

Go to Managed Secrets > Add Provider > ClickHouse.

Enter credentials

Paste your Base64 Credentials into the credential field.

Save

Click Save. You’ll receive a grant_id to use with the SDK.

response = await alter_app.request(
HttpMethod.POST,
"https://YOUR-SERVICE.clickhouse.cloud:8443",
grant_id="YOUR_GRANT_ID",
query_params={"query": "SELECT event, count() FROM events GROUP BY event LIMIT 5"},
)
  • The HTTPS interface accepts SQL in the request body and listens on port 8443 on ClickHouse Cloud.

Alter policy rules can target these attested operations and families for operation-level and parameter-aware controls.

Operation IDFamiliesMethodProvider path
query/getreadGET/
query/postadmin, delete, read, writePOST/
pingreadGET/ping
replicas_statusreadGET/replicas_status
dashboardreadGET/dashboard
playreadGET/play

Report an issue with this page

Necessary

Required for sign-in, security, authorization, and remembering your choices.

Always active

Analytics

Helps us understand which product and documentation features are useful.

Performance diagnostics

Uses performance tracing and privacy-masked session replay to diagnose problems.

You can change these choices at any time from Cookie settings.