All Products
Search
Document Center

Data Transmission Service:Prepare the database accounts for data synchronization

Last Updated:Aug 26, 2026

Before you configure a data synchronization task, create and authorize database accounts for the source and destination databases. Different databases and synchronization types require different permissions.

Permissions required for the source database account

Database

Required permissions

References

ApsaraDB for RDS for MySQL

Read permissions on the objects to synchronize.

Create accounts and databases and Modify the permissions of an account.

self-managed MySQL

  • The SELECT permission on the objects to be synchronized.

  • The REPLICATION CLIENT, REPLICATION SLAVE, and SHOW VIEW permissions.

  • The permissions to create databases and tables. These permissions allow DTS to create a database named test to advance the binary log position.

Create an account for a self-managed MySQL database and configure binary logging.

PolarDB for MySQL

Read permissions on the objects to synchronize.

Create and manage a database account.

PolarDB for PostgreSQL (Oracle compatible)

Permissions of a privileged account.

Create a database account.

PolarDB-X 1.0

Read permissions on the objects to synchronize.

Manage database accounts

ApsaraDB for RDS for SQL Server

Owner permission on the database that contains the objects to synchronize.

Note

A privileged account has the required permissions.

Modify the permissions of an account.

self-managed SQL Server

The sysadmin permission.

CREATE USER and Manage users and permissions.

ApsaraDB for RDS for PostgreSQL

A privileged account that owns the selected database.

Note

If the source database is an ApsaraDB for RDS for PostgreSQL 9.4 instance and you synchronize only DML operations, the account needs only the replication permission.

Create an account and Create a database.

self-managed PostgreSQL

The superuser permission.

CREATE USER and GRANT syntax.

ApsaraDB for Redis

Read and write permissions on the objects to synchronize.

Create and manage accounts.

self-managed Redis

Redis does not use users or permissions. You only need to ensure the database can run the psync or sync command.

None

ApsaraDB for MongoDB

  • For full data migration: the read permission on the source database.

  • For incremental data migration: the read permission on the source database, the admin database, and the local database.

Manage MongoDB database users by using DMS.

self-managed MongoDB

  • For full data migration: the read permission on the source database.

  • For incremental data migration: the read permission on the source database, the admin database, and the local database.

db.createUser().

self-managed TiDB

The SHOW VIEW and SELECT permissions on the objects to migrate.

Privilege Management

Permissions required for the destination database account

Database

Required permissions

References

ApsaraDB for RDS for MySQL

Read and write permissions on the destination database.

Create accounts and databases and Modify the permissions of an account.

self-managed MySQL

The ALL permission on the destination database.

Create an account for a self-managed MySQL database and configure binary logging.

PolarDB for MySQL

The ALL permission on the destination database.

Create and manage a database account.

PolarDB for PostgreSQL (Oracle compatible)

Permissions of the database owner.

You specify the database owner when you create the database.

PolarDB-X 1.0

Write permissions on the database that contains the objects to synchronize.

Manage database accounts

Tair

If you use the instance password, no authorization is required.

None

If you use a custom account, read and write permissions are required.

Create and manage accounts.

self-managed Redis

Redis does not use users or permissions. You only need to provide the correct database password.

None

ApsaraDB for MongoDB

The dbAdminAnyDatabase permission, readWrite permission on the destination database, and read permission on the local database.

Manage MongoDB database users by using DMS.

self-managed MongoDB

The dbAdminAnyDatabase permission, readWrite permission on the destination database, and read permission on the local database.

db.createUser().

AnalyticDB for MySQL

  • Version 2.0: You do not need to provide account information. DTS automatically creates an account and grants it permissions.

  • Version 3.0: Read and write permissions are required.

Version 3.0: Create a database account

AnalyticDB for PostgreSQL instance

The initial account or an account with RDS_SUPERUSER permissions.

Message Queue for Apache Kafka

Not required.

Note

If the Kafka instance is a VPC instance, you do not need to configure a Database Account or Database Password.

None

self-managed Kafka

Not required.

Note

If authentication is disabled for the Kafka cluster, you do not need to provide credentials.

None

DataHub

You do not need to configure a Database Account.

None

Elasticsearch

The username (default: elastic) and password configured when you create the cluster.

Create an Elasticsearch cluster.

MaxCompute

The CREATE TABLE, CREATE INSTANCE, CREATE RESOURCE, CREATE JOB, and List permissions on the project to synchronize.

The system automatically grants permissions when you configure the data synchronization task.

Tablestore

You do not need to configure a Database Account.

None

Permissions required for the database accounts in two-way data synchronization tasks

In two-way synchronization tasks, DTS creates a database named dts in both the source and destination databases to prevent circular replication. The following table lists the required permissions.

Database

Required permissions

References

ApsaraDB for RDS for MySQL

Permissions of a privileged account.

Create accounts and databases.

self-managed MySQL

The SELECT permission on the objects to synchronize

The REPLICATION CLIENT, REPLICATION SLAVE, and SHOW VIEW permissions

The permissions to create databases and tables, which allow DTS to create a database named dts to prevent circular replication.

Create an account for a self-managed MySQL database and configure binary logging.

ApsaraDB for RDS for PostgreSQL

A privileged account that owns the selected database.

Create an account and Create a database.

self-managed PostgreSQL

The superuser permission.

CREATE USER and GRANT syntax.

PolarDB for MySQL

Permissions of a privileged account.

Create and manage a database account.

Tair

If you use the instance password, no authorization is required.

None

If you use a custom account, read and write permissions are required.

Create and manage accounts.

self-managed Redis

Redis does not use users or permissions. You only need to ensure the database can run the psync or sync command.

None