> ## Documentation Index
> Fetch the complete documentation index at: https://docs.thanx.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Oracle

> Configuring your Oracle destination.

## Prerequisites

* [ ] If your Oracle database is protected by security groups or other firewall settings, you will need to have the data-syncing service's static IP available to complete Step 1.

## Step 1: Allow access

Create a rule in a security group or firewall settings to whitelist:

* incoming connections to your host and port (usually `1521`) from the static IP.
* outgoing connections from ports `1024` to `65535` to the static IP.

<Note>
  **Connecting through a bastion host**

  If your database is not publicly accessible, SSH tunneling through a bastion host is supported instead. Allow inbound SSH (port `22`) from the data-syncing service's egress IP on the bastion host, and add the service's public key to `~/.ssh/authorized_keys`; contact support to obtain the public key.
</Note>

## Step 2: Create writer user

Create a database user to perform the writing of the source data.

1. Open a connection to your Oracle database.
2. Create a user for the data transfer by executing the following SQL command.

```sql theme={null}
CREATE USER <username> IDENTIFIED BY '<some-password>';
GRANT CREATE SESSION TO <username>;
```

3. Grant user required privileges on the database.

```sql theme={null}
GRANT CREATE SESSION, ALTER USER, CREATE ANY TABLE, CREATE ANY INDEX,
SELECT ANY TABLE, INSERT ANY TABLE, UPDATE ANY TABLE, DELETE ANY TABLE,
DROP ANY TABLE, COMMENT ANY TABLE TO <username>;
```

<Warning>
  **If the `schema` already exists**

  By default, the service creates a new schema (*in Oracle, `schema` is synonymous with `user`*). If you prefer to create the schema yourself before connecting the destination, you must ensure that the writer user has the proper permissions on it.
</Warning>

## Step 3: Add your destination

Securely share your **host name**, **database name**, **port**, your chosen **schema name**, **username**, and **password** with us to complete the connection.

## Permissions checklist

* User has `CREATE SESSION`.
* User has `CREATE ANY TABLE`, `CREATE ANY INDEX`, `SELECT ANY TABLE`, `INSERT ANY TABLE`, `UPDATE ANY TABLE`, `DELETE ANY TABLE`, `DROP ANY TABLE`, and `COMMENT ANY TABLE`.
* Firewall or security group allows the data-syncing service's egress IP on port `1521`, or SSH tunneling access on port `22` if connecting through a bastion host.

## FAQ

<AccordionGroup>
  <Accordion title="How is the Oracle connection secured?">
    We connect using the credentials you provide (host, port, username, password) over TCP. For databases that are not publicly accessible, SSH tunneling through a bastion host is supported with public key authentication.
  </Accordion>

  <Accordion title="Do I need to pre-create the schema?">
    No. The schema is created automatically during the first sync. If you pre-create it, ensure the writer user has the proper permissions on the existing schema.
  </Accordion>
</AccordionGroup>
