Builds internal tools by dragging components onto a canvas and binding them to queries against your own databases and APIs, with permissions and audit logs around them.
Build me internal tools that replace Retool — and know exactly what the verdict means. The honest difference is **that a colleague can build the screen**. If the people who need internal tools are not developers, a builder earns its price. If you are building them anyway, four screens written directly are less code than the configuration describing them, faster, and impossible to break by dragging. Decide which situation you are in before starting. STACK - Node 20+ with Fastify, server-rendered HTML with a little vanilla JS - Your existing database through its own driver; SQLite through better-sqlite3 for this tool's state - No client-side framework - Caddy in front THE DATA MODEL, MEANING THIS TOOL'S OWN - users, roles, permissions, sessions - queries: id, name, sql, params_json, is_mutation, requires_role, timeout_ms, row_limit, description — every query named, parameterised, reviewed like code - screens: id, key, kind, config_json — list, detail, form, action. Four kinds cover almost everything - audit_log: id, actor_id, action, resource, target_id, before_json, after_json, ip_hash, at — append-only, enforced by a trigger - exports: id, actor_id, query_id, row_count, at — an internal tool is how data walks out of a company, and every export is a row - approvals: id, action_key, requester_id, payload_json, status, approver_id, decided_at — for the mutations that deserve a second pair of eyes SAFETY, WHICH IS WHAT AN INTERNAL TOOL IS ACTUALLY ABOUT - **No free-form query box in production.** That is the single most common way internal tools become a breach. Queries are files, parameterised, reviewed - Read queries against a replica or a read-only connection where one exists; writes are a separate, explicitly permissioned path - A statement timeout and a row limit on everything. One unbounded query on a large table takes the production database down and the company with it - Default deny: a new screen is invisible until a role is granted it, checked on the server for every screen and every query - Row-level scope where the data needs it, expressed as a predicate joined into the query rather than filtered afterwards - Every destructive action confirmed with an explicit count — 'this will refund 214 orders' — and logged with before and after values - Single sign-on through OIDC, no shared accounts, and sessions revocable centrally. An audit log with a shared login in it answers nothing THE SCREENS - List: filters, sorting, pagination, a defined column set, a hard row limit - Detail: fields, related records, and the actions this role may take here - Form: typed fields, server-side validation, a clear error path that keeps what was typed - Action: a named mutation with its own permission, confirmation and audit entry - Written as files. Adding a screen is a small pull request, which is also a review — and that review is a feature, not friction IF A COLLEAGUE MUST BUILD THEM - Then the screens become rows: a screen references a named query and a column configuration, edited through a simple form - The queries stay files, reviewed by a developer. The configuration is what a colleague edits — which column, which label, which order - That split gives most of the builder's value without opening a query box to the whole company. It is the design worth copying THE INTERFACE - Dense and plain: tables that align, a header saying who you are and what you can do, keyboard navigation on lists - Fast on a laptop over a poor connection — no bundle, no spinner - Works on a phone, because half of internal-tool use is somebody away from a desk - Dark and light OPERATIONS - .env: DATABASE_PATH, TARGET_DATABASE_URL, BASE_URL, OIDC_*, SESSION_SECRET, HASH_SALT - Migrations on boot, each once - Reachable only behind whatever the company already uses — a VPN or an identity-aware proxy. Public exposure is a deliberate decision, not a default - Nightly backup of this tool's own database - Health endpoint WHAT MATTERS MOST Deny-by-default, the audit log, and no query box. An internal tool is a permanent standing route into the company's data, and everything else here is a table.
What you lose
- A drag-and-drop editor that reaches a working admin screen in minutes
- Connectors to every database and API, with credentials held outside your codebase
- Permissions and audit logs on who ran which query against production
- Version history and staging environments for internal tools
- The ability to hand an internal tool to a colleague who is not a developer
If you would rather not build
- Forest Admin — paid, generated admin panels over an existing database
What it costs
as published on their pricing page
| Plan | Billed monthly | Billed yearly | Last read |
|---|---|---|---|
| — | $10/mo | — | — |
Their pricing page is where these came from. Seeing a different price? Tell us.
The escape hatch
open source · no votes, no paid placement
Appsmith
$0Drag-and-drop internal tools over your own databases and APIs, self-hosted.
appsmithorg/appsmithfree · open source
Budibase
$0Builds internal apps and admin panels over existing data, runs on your server.
Budibase/budibasefree · open source
Why this verdict
our own opinion · changed only by a person
52/100
Verdict kinda at 52: a config-driven admin panel is a strong weekend and is safer than a canvas, because arbitrary queries are impossible by construction. The trade is who can build a screen — with Retool it is anybody, and here it is whoever can open a pull request.
History
tracked since 9 Aug 2026 · nothing is ever overwritten
Questions about Retool
answered from the record above
Is Retool free?
No — the plan we track is $10 a month. Team at $10 per standard user per month, with end users billed separately; Business is roughly $50 per user and adds environments and audit logs.
Can you replace Retool by building your own?
ALMOST. A weekend of work, and real gaps remain. Replacement score 52 out of 100, build time a weekend. Read what you lose before you decide.
How much does Retool cost?
$10 a month on Team — $120 a year. Recorded 9 Aug 2026.
What do you lose by replacing Retool?
A drag-and-drop editor that reaches a working admin screen in minutes; Connectors to every database and API, with credentials held outside your codebase; Permissions and audit logs on who ran which query against production; Version history and staging environments for internal tools; The ability to hand an internal tool to a colleague who is not a developer. If any of those carry weight for you, keep paying.
Is there an open-source alternative to Retool?
Yes: Appsmith, Budibase. The prompt on this page is for when you want it your way instead.
Related entries
same category first, most replaced first
Every week, something stops being worth paying for.
New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.
free forever · no tracking pixel · stored here, never passed to anyone

