# Ognom: full description > Ognom is a free, open-source (MIT) desktop client for MongoDB on macOS, Windows and Linux. You use it to browse, query, edit and manage MongoDB databases, including MongoDB Atlas, replica sets and sharded clusters. It is a native Tauri app (Rust backend, system webview), needs no account, sends no telemetry and has no AI features. Website: https://ognom.dev/ Source code: https://github.com/sunilksamanta/ognom Latest release: https://github.com/sunilksamanta/ognom/releases/latest Current version: 2.1.0 (September 2026) License: MIT Author: Sunil Kr. Samanta Product Hunt: https://www.producthunt.com/products/ognom ## At a glance - Category: MongoDB GUI, database client, developer tool. - Platforms: macOS on Apple Silicon and Intel, Windows x64, Linux x64. - Price: free. There is no paid edition, no account and no license key. - Built with: Rust and the official MongoDB Rust driver for the backend, Tauri 2 for the desktop shell, React for the interface, Monaco for the code editors. - Network: Ognom connects to the MongoDB servers you add (directly or through an SSH host you configure) and to GitHub to check for updates. Nothing else. - Similar tools: MongoDB Compass, Studio 3T, NoSQLBooster, Robo 3T. Ognom is a free, open-source option in the same space. ## Connections - Paste a `mongodb://` or `mongodb+srv://` connection string, or fill in host, port, username and password. Ognom converts between the two forms. - Works with MongoDB Atlas, self-hosted servers, replica sets (with replica set name and read preference) and sharded clusters. - Authentication: SCRAM-SHA-1, SCRAM-SHA-256, X.509 client certificates, LDAP (PLAIN), or none. - TLS: on or off, custom CA file, client certificate and key, option to allow invalid certificates for test setups. - SSH tunnels: connect through a bastion or jump host with a private key file (with optional passphrase), a password, or the running ssh-agent. Host keys are checked against `~/.ssh/known_hosts`. A host seen for the first time is remembered in Ognom's own known_hosts file, and a changed host key is refused. The tunnel forwards to one MongoDB host and connects to it directly. - Advanced options: default database, auth source, extra hosts, direct connection, connect timeout, pool size and any extra URI options. - "Test" opens a short-lived connection and reports latency, topology and server version. - Each saved connection has a name, a colour tag and a session mode: Read & write, Read-only, or Production. - Several connections can be open at the same time. Each is a workspace with its own tabs, picker and query state, and switching between them is instant. Open workspaces reconnect on the next launch. - Connections can be exported and imported: either without passwords (safe to share) or as a full backup where credentials are encrypted with a passphrase you choose (Argon2id key derivation, AES-256-GCM). - Copy any connection string, with or without its password. ## Browsing and querying - Views per collection: Table, Documents, Schema, Indexes, plus Aggregate and Shell in the query dock. - Table view with BSON types in the column headers, multi-select and bulk delete. Documents view with type-coloured, collapsible JSON. - The picker lists databases and collections with document counts, pinned collections, open tabs and saved queries. The same collection can be open in several tabs, numbered #1, #2 and so on. - Query box accepts mongosh syntax: `{ status: "paid", total: { $gt: 100 } }`, `ObjectId("...")`, `ISODate("...")`, `new Date()`, `/regex/i`, unquoted keys. - Sort and projection fields, pagination with a configurable page size, and a visual query builder (field, operator, value rows). - Every query shows the matched count, the execution time and the winning plan (for example IXSCAN or COLLSCAN). - Explain shows index usage, documents and keys examined, timing, and suggests an index when the query scans the whole collection. - Saved queries per collection. - Find anything with ⌘K (Ctrl+K on Windows and Linux): collections, databases, connections and actions. ## Editing documents - Click a row to open the document drawer. - Fields tab: edit values inline. BSON types are preserved (an ObjectId stays an ObjectId, a date stays a date). - JSON tab: edit the whole document in shell syntax in a code editor. - Diff tab: see exactly what will change before saving. - Insert new documents (⌘N), save with ⌘S. - Bulk update with update operators, and bulk delete by filter. ## Aggregation - Stage-by-stage pipeline builder with snippets for common stages. - Enable, disable and reorder stages. Preview the output up to any stage. - Per-stage statistics: documents out, drop-off and cumulative time. - Explain a pipeline, copy it as shell code, or open it in the shell. - Pipelines without a limiting stage get a safety `$limit` that is shown in the interface. ## Schema view and interface builder - Schema view: samples a collection (100 to 10,000 documents) and lists every field with its types, how often it appears and example values. - Interface builder ("Export types" in the Schema view or a collection's right-click menu) turns the sampled schema into code: - Output: TypeScript interfaces (or type aliases) or Zod schemas with `z.infer` types. - Target: Node.js backend, where ObjectId, Date, Decimal128, Binary and Timestamp use the driver classes, imported from `mongodb`, `bson` or `mongoose` (`Types.ObjectId`). Or frontend, where the same values are typed as the strings they become in JSON. - Structure: the first version is one nested interface. Any nested object, or the objects inside an array, can be extracted into its own named interface with one click, and renamed. The parent then refers to it by name. - Per field: switch ObjectId or Date between the native type and string, turn a string field with a few repeated values into a literal union (for example `"RED" | "AMBER" | "GREEN"`, or `z.enum` in Zod), and mark fields optional or required. Fields missing from some sampled documents are optional by default, and `null` is included when it was observed. - Objects keyed by ids or dates are typed as `Record`. - The generated code is read-only and updates as you change options. Clicking a field in the structure highlights its line in the code, and the other way round. - Copy all the code, copy a single interface, or save it as a `.ts` file. Choices are remembered per collection. ## Indexes - List of indexes with size, usage count since server start and a hint when an index is unused. - Create indexes with templates: single field, compound, text, 2dsphere (geo), hashed, TTL, plus unique, sparse and partial options. - Drop indexes. ## Database overview - One table for a whole database: documents, average document size, data size, storage size, index count and index size for every collection, with totals. - Flags collections that have only the `_id` index but many documents, collections whose indexes are larger than their data, and empty collections. - Sort, filter, and export the table as CSV or JSON. ## Moving data - Import and export JSON, NDJSON, CSV and BSON (compatible with mongodump), streamed, with progress and a cancel button. - Copy a collection to another open connection. - Diff two collections and sync the differences. - Duplicate, clear or drop a collection. ## Shell - An advanced-mode shell that runs one statement at a time in mongosh syntax, with history and completions for collection and field names. ## Server and operations - Server details: version, topology, host information and connection status. - Operations panel: current operations with the option to kill one, the database profiler, and live server statistics. - The picker footer shows live round-trip latency to the active server. ## Safety - Production and Read-only connections open with writes blocked. The status bar shows the mode; switching to edit mode is explicit, and Production asks for confirmation first. - The write block is enforced in the backend, so no menu, shortcut, shell statement or `$out` stage can write to a read-only workspace. - Dropping or clearing a collection requires typing its name and offers an export first. Deleting several documents offers a JSON backup of exactly those documents. - Deleting a saved connection requires typing its name. ## Security model - Connection profiles are stored as JSON in the OS app-data directory. Passwords, connection strings and SSH secrets are encrypted with AES-256-GCM. - The 256-bit master key is created on first run and kept in a private key file (permissions 0600). Optionally it can live in the macOS Keychain, Windows Credential Manager or Linux Secret Service instead. If the keychain is unavailable, Ognom falls back to the key file and says so in the status bar. - Stored passwords are never sent back to the interface. Editing a connection keeps the saved password unless you type a new one. - The interface runs under a strict Content Security Policy with no remote content. Fonts, the editor and all assets are bundled, so the app works offline. - No telemetry, no analytics, no account. ## Interface - Eight themes (Mongo dark, Mongo light, Bloom, Bloom noir, Midnight, Mono, Contrast, Solar) plus Follow OS, and three densities (compact, comfortable, roomy). - Keyboard shortcuts (⌘ on macOS, Ctrl elsewhere): ⌘K find anything, ⌘O open a collection, ⌘N insert a document, ⌘⏎ run the query or pipeline, ⌘S save the document, ⌘W close the tab, ⌘B toggle the picker, ⌘, settings, ⌘⇧T cycle themes, Esc close overlays. ## Installation - macOS: download the `aarch64` .dmg for Apple Silicon or the `x64` .dmg for Intel, drag Ognom to Applications, then run `xattr -dr com.apple.quarantine /Applications/Ognom.app` once. The app is not signed with a paid Apple Developer certificate, so Apple Silicon Macs otherwise report it as damaged. On Intel Macs, right-click and Open also works. - Windows: run `Ognom_x.y.z_x64-setup.exe` (or the .msi). If SmartScreen shows "Windows protected your PC", choose More info, then Run anyway. - Linux: AppImage (`chmod +x` then run), .deb (`sudo apt install ./Ognom_x.y.z_amd64.deb`) or .rpm (`sudo dnf install ./Ognom-x.y.z-1.x86_64.rpm`). Needs `libwebkit2gtk-4.1` and `libgtk-3`, which most desktops already have. - Updates: installed copies check GitHub releases on launch and update themselves. Updates are signature-verified. ## Frequently asked questions Is Ognom free? Yes. It is MIT-licensed open source, with no paid tier, account or license key. Does Ognom work with MongoDB Atlas? Yes. Paste the `mongodb+srv://` connection string from Atlas. Can Ognom connect through an SSH tunnel? Yes, since version 2.1.0. Use a private key, a password or ssh-agent. Host keys are verified. Can Ognom generate TypeScript types from a MongoDB collection? Yes, since version 2.1.0. The interface builder produces TypeScript interfaces or Zod schemas from a sample of the collection, for a Node.js backend (ObjectId, Date) or a frontend (strings). Is it safe to use on a production database? Mark the connection as Production. It then opens read-only, and writes stay blocked until you switch to edit mode and confirm. Does Ognom have AI or chat features? No. Earlier 1.x versions had an AI assistant. It was removed in 2.0, and Ognom does not send data to any AI service. Does Ognom collect data about me? No. There is no telemetry, analytics or account. It talks only to your MongoDB servers, your SSH hosts and GitHub for updates. Where are my passwords stored? Encrypted with AES-256-GCM on your computer. The key is in a local key file or, if you choose, the OS keychain. Why does macOS say the app is damaged? The builds are not signed with a paid Apple certificate. Run `xattr -dr com.apple.quarantine /Applications/Ognom.app` once after installing. How is Ognom different from MongoDB Compass? Both are desktop MongoDB clients. Ognom is MIT-licensed, uses a native Tauri shell instead of Electron, keeps several connections open at once, has per-connection production and read-only modes, SSH tunnels and TypeScript or Zod type export.