Give every customer their own analytics workspace
Try Draxlr free for 7 days

Full App Embedding for SQL Databases: What It Is & Top Tools

Full app embedding puts a query builder, SQL editor, and dashboards inside your SaaS app. Compare 6 tools on pricing, security, and setup for SQL databases.

Posted by Vivek on 09 Oct 2026
Full App Embedding for SQL Databases: What It Is & Top Tools

Sooner or later, a customer emails support asking for a report your dashboard doesn't have. A week later, another customer asks for a slightly different one. An embedded dashboard answers the questions you predicted. It can't answer the ones your customers come up with on their own.

Full app embedding solves that problem. Instead of embedding one read-only dashboard, you embed a complete analytics workspace inside your product, with a query builder, a SQL editor, and saved dashboards. Each customer only ever sees their own data.

A quick note on scope. This guide isn't about embedding a database engine like SQLite inside your application. It's about putting a self-service analytics app on top of the SQL database your product already runs on, whether that's Postgres, MySQL, SQL Server, or a warehouse. If you're still deciding whether you need embedded analytics at all, start with our roundup of the best embedded analytics tools in 2026.

Key takeaways

  • Full app embedding gives each customer a self-service analytics workspace inside your product, not just a dashboard to look at.
  • Once customers can write SQL or ask an AI assistant, tenant isolation has to apply to every query, not only to dashboard filters.
  • Pricing models vary widely. Metabase Pro charges $12 per user per month after the first 10 users, while flat-priced tools like Draxlr don't charge per embedded customer.

What is full app embedding?

Full app embedding means placing an entire self-service analytics application inside your product, usually through an iframe or SDK. Your customers can browse data, build their own queries and charts, and save their own dashboards. Each signed-in customer gets a workspace that's limited to their own rows in your database.

The term comes from vendor documentation, not from analysts. ThoughtSpot calls it "full application embedding," and Metabase calls it "full app embedding." Metabase renamed the feature in January 2026. Its Metabase 58 release notes say "Interactive Embedding (all of Metabase in an iframe) is now Full-app Embedding." So if an older guide talks about interactive embedding, it's describing the same thing.

Whatever the vendor calls it, a full app embed usually gives customers:

  • A way to explore data. A visual query builder, a SQL editor, and increasingly an AI assistant that turns plain-English questions into queries, like the ones in our roundup of AI tools for data analytics.
  • Their own saved work. Queries, folders, and dashboards that are still there on the next visit.
  • Shared dashboards you publish. The standard reports every customer gets, filtered to their own data.
  • The usual interactions. Drill-downs, chart type changes, and exports, if you allow them.

Demand for this kind of self-service is steady. In BARC's Data, BI and Analytics Trend Monitor 2026, published in November 2025, 1,579 respondents ranked self-service analytics sixth out of 20 trends. The same report says BI vendors surveyed by BARC reported that 65% of their customers already use embedded BI.


Full app embedding vs. dashboard embedding

The real difference is who answers new questions. With a dashboard embed, your team builds the reports, and customers view and filter them. With a full app embed, customers build their own. That one shift changes how you handle identity, security, and pricing.

Single dashboard embed Full app embed
What customers can do View, filter, and drill into dashboards you built Build their own queries, charts, and dashboards
Who handles a new report Your team The customer
Customer identity A short-lived signed token per view A persistent identity, so saved work survives between visits
Tenant isolation A locked filter on queries you wrote Needs row-level security on every query, including raw SQL and AI
Setup effort Quick, since you control every query Longer, since permissions need careful design
Best for Standard KPIs every customer shares Power users, ops teams, agencies, and data-heavy B2B products

If a single dashboard is all you need, start with our guide on how to create a dashboard from a Postgres or MySQL database.


When does your product need full app embedding?

You need it when reporting requests outrun your team, because analytics work competes directly with your roadmap. In Sisense's vendor-commissioned 2025 State of Analytics research, reported by IntelligentCIO, 56% of organizations said analytics bottlenecks delayed product releases in the past year. A full app embed moves custom reporting off your roadmap and into your customers' hands.

The signals usually look like this:

  • Support and success teams spend hours each week building one-off reports and exports.
  • Customers download CSVs so they can rebuild your reports in Excel or Google Sheets.
  • Your buyers have analysts or ops people who already know SQL.
  • Enterprise prospects keep asking for "custom reporting" in RFPs.
  • You sell to agencies that need to slice data differently for every client.

And when don't you need it? If your customers want three KPIs and a trend line, a single dashboard embed is simpler and cheaper, and it gives you full control over what customers see. Full app embedding pays off when the variety of questions is the problem, not the number of viewers.

Not sure which camp you're in? Count last quarter's custom report requests. If most of them were different from each other, that's a strong sign customers need to build their own.


How does full app embedding work on a SQL database?

Most full app embeds follow the same flow. The customer signs in to your product, and your backend requests a signed embed URL or token. Your frontend then renders the analytics workspace, and the tool should apply row-level security to every query it sends to your database. The details differ by vendor, but the overall flow doesn't.

Diagram of how full app embedding works on a SQL database: customer signs in, backend signs the embed, workspace loads, row-level security applies to every query, then the SQL database is queried

Setting one up comes down to five decisions.

Connect a read replica, not production

Customers will write queries you never planned for, and some of them will be slow. Point the analytics tool at a read replica with a dedicated read-only database user, and grant it only the tables customers should see. Then set a query timeout, such as statement_timeout in Postgres or max_execution_time in MySQL, so one runaway query can't slow things down for everyone else.

Give each user a persistent identity

A full app embed has to know who's who, so a customer's saved queries are still there next week. Some tools handle this through SSO. Metabase, for example, recommends SSO with JWT. Others take a user ID in the signed embed request and create a workspace for that user automatically.

Define row-level security once

Write a rule like account_id = {accountId} and attach it to a group. When your backend requests the embed, it passes the customer's attribute value, such as accountId: 42, and the tool adds the filter to every query that customer runs.

Sign the embed on your server

The request that creates the embed URL or token includes your API secret, so it has to run on your backend. Luzmo's embedding docs put it plainly: the token request "needs to happen server-side." The same rule applies to every tool on this list.

Render it in your frontend

This is usually the easy part. Most tools give you an iframe, a small script tag, or a React or Vue component that takes the signed URL or token.


Why is tenant isolation harder when customers can write SQL?

With a dashboard embed, a hidden filter is usually enough, because customers can only run the queries you wrote. Once customers can open a SQL editor or ask an AI assistant, a hidden filter no longer protects you. Isolation has to happen at the query layer, on every query, including ones you've never seen.

Vendors handle this differently, and the fine print matters. Metabase's row and column security docs warn that "Groups with native query permissions (access to the SQL editor) can bypass row and column security." Metabase offers two other routes on its Pro and Enterprise plans. Connection impersonation maps each user to a role in your database, and Metabase says it "sets permissions for questions written in both the SQL editor and the query builder." Database routing sends each customer's queries to their own database with the same schema. Both work, but they move tenant isolation into your database, where you manage the roles or the separate databases.

GoodData has a caveat of its own. Its docs say users with the Workspace.MANAGE permission can change the logical data model and bypass workspace data filters.

What you want is isolation at the query layer, so one rule covers everything a customer does in the embed: shared dashboards, exports, saved queries, the query builder, the SQL editor, and the AI assistant.

Whichever tool you pick, test this yourself before launch. Sign in as a test customer, open the SQL editor or AI assistant, and run something like SELECT * FROM orders with no WHERE clause. If you see another tenant's rows, you have your answer.


What to look for in a full app embedding tool

Six things separate a full app embed you can live with from one that turns into its own project. They are how isolation works, how users sign in, how pricing scales, how the tool connects to your database, how much of the interface you can switch off, and which devices it supports.

Isolation that covers SQL and AI. Ask exactly how row-level security applies to raw SQL and AI-generated queries, not just to dashboards. The previous section explains why.

Sign-in model. Metabase's full app embed signs people in with cookies, and its docs note that Safari users need to allow cross-site tracking. ThoughtSpot and Looker both offer cookieless options for browsers that block third-party cookies. Test the embed in the browsers your customers actually use.

Pricing as you grow. Per-user pricing looks cheap at 10 users. Model it at 100 and 500 before you sign anything, and check whether your own team counts toward the same user total. Flat, per-user, per-workspace, and usage-based plans can look similar at launch and very different a year later.

Direct SQL connection or semantic model. Looker needs a LookML model, GoodData needs a logical data model, and ThoughtSpot's onboarding includes creating a Model. Metabase, Luzmo, and Draxlr query your database directly. A semantic model gives you governed metrics, but it also means real modeling work before customers see anything.

Control over the toolset. Can you offer the query builder but hide the SQL editor? Turn off exports for some customers? Limit which tables appear? The answers vary more than you'd expect.

Device support. Some full app embeds only support desktop screens for now. Draxlr's, for example, shows a "use a larger screen" message below 640px wide. If your customers live on phones, check this early.


Full app embedding tools at a glance

A quick disclosure: Draxlr is an Inkoop product. To keep the comparison fair, every detail below comes from each vendor's own docs and pricing pages, linked in each section.

Tool What customers get Full app embed starting price Pricing model Semantic model required
Draxlr Query builder, SQL editor, AI assistant, own dashboards $250/month (Power) Flat, unlimited embedded customers No
Metabase Entire Metabase app in an iframe $575/month (Pro) 10 users included, then $12/user/month No
ThoughtSpot Entire app or individual pages (AppEmbed) Free Developer tier, then custom Custom Enterprise pricing Yes (Model)
Looker Explores, dashboards, and Looks with self-service permissions Not published Embed edition, through sales Yes (LookML)
GoodData Dashboards and Analytical Designer via iframe Not published Platform fee plus per-workspace Yes (LDM)
Luzmo Embedded drag-and-drop dashboard editor €1,995/month, billed annually One plan, based on customer usage No

1. Draxlr

Draxlr Full App Embed customer workspace showing the query builder, saved queries, shared dashboards, and a customer's own dashboards

Draxlr connects straight to your SQL database and lets you embed either a single dashboard or a full analytics workspace for each customer. Its Full App Embed gives every customer the shared dashboards you publish, plus their own queries and dashboards, a query builder, a SQL editor, and an AI assistant.

How full app embedding works in Draxlr

Your backend calls Draxlr's Generate Embed URL API with your API key and secret, the signed-in user's ID, and any settings. Each userIdentifier gets its own workspace with saved queries, folders, and dashboards, and the same ID always returns to the same workspace. The returned URL is valid for 24 hours, and your frontend renders it with a div and a script tag.

{
  "apiKey": "YOUR_API_KEY",
  "apiSecret": "YOUR_API_SECRET",
  "databaseId": "YOUR_DATABASE_ID",
  "userIdentifier": "user_1234",
  "browseDataModules": ["ai", "sql", "visual"],
  "rlsGroup": "Customers",
  "attributes": { "accountId": 42 }
}

Pricing

Full App Embedding is included on the Power plan at $250 per month and on Enterprise at $500 per month. Draxlr's pricing page says customers using Full App Embedding don't count as users, and there's no cap on how many you embed, so the plan price doesn't grow with your customer base. The one usage-based cost is the AI assistant. Each question uses one AI credit, the Power plan includes 300, and extra credits cost $10 per month for 200. The 7-day free trial includes Power plan access, with no credit card required.

Here's how that compares with Metabase Pro's per-user pricing as the number of embedded users grows.

Bar chart comparing monthly list price as embedded users grow: Metabase Pro rises from $575 at 10 users to $6,455 at 500 users, while Draxlr Power stays at $250

Standout features

  • Row-level security that applies to shared dashboards, exports, saved queries, the query builder, the SQL editor, and the AI assistant
  • Per-embed control over which tools appear (ai, sql, visual) and whether customers can save queries or create dashboards
  • Brand colors, background colors, and export options set per embed URL
  • Direct connections to PostgreSQL, MySQL, SQL Server, MariaDB, Supabase, BigQuery, Snowflake, ClickHouse, Redshift, and more

Worth knowing

  • The full app embed only supports desktop screens for now. Below 640px wide, it asks the user for a larger screen.
  • If you don't pass an rlsGroup, the embedded user gets full access to the database you embed, so always send one for customer-facing embeds.
  • Embed URLs stay valid for 24 hours and can't be revoked individually. Generate a fresh URL on each visit, and remember that a customer who loses access can keep using an already-issued URL until it expires.

Where it fits

SaaS teams on a SQL database who want customers to self-serve, including in SQL, without paying per embedded user.

Connect your Database

2. Metabase

Metabase query builder and dashboard interface

Metabase is the tool most people think of when they hear "full app embedding," since that has been the exact name of its feature since the January 2026 rename. Its full app embedding docs describe it simply: "Full app embedding lets you embed the entire Metabase app in an iframe." Your permissions and SSO decide what each person can query and drill into.

How full app embedding works in Metabase

You enable full app embedding in the admin settings, add your app's URL as an allowed origin, set up SSO with JWT or SAML, and point an iframe at your Metabase instance. Row and column security, which Metabase used to call data sandboxing, uses user attributes to limit each tenant to their own rows.

Pricing

Full app embedding requires a Pro or Enterprise plan. According to Metabase's pricing page, Pro costs $575 per month with the first 10 users included, then $12 per user per month. Both your internal team and the people using your embeds count as users. Enterprise starts at $20,000 per year.

Worth knowing

  • Row and column security doesn't cover the SQL editor. To let customers write SQL, you'll need connection impersonation or database routing, which push tenant isolation into your database setup.
  • Embedded sessions rely on cookies, and Metabase's docs say Safari users need to allow cross-site tracking.
  • Metabase itself suggests that teams new to embedding consider Modular embedding, which embeds individual components such as dashboards, the query builder, AI chat, and a collection browser, instead of the whole app.

Where it fits

Teams that already run Metabase internally and want to extend it to customers, and that have modeled per-user costs at their expected scale.


3. ThoughtSpot

ThoughtSpot's AppEmbed component, documented under full app embedding, lets you "embed the entire ThoughtSpot application or individual application pages in your app." Customers get ThoughtSpot's natural-language search and Liveboards inside your product.

How it works

Your backend authenticates users through trusted authentication, with a cookieless option for browsers that block third-party cookies. Multi-tenancy uses Orgs, which isolate each tenant's data. ThoughtSpot's docs say Orgs require the Analytics Enterprise Edition or a ThoughtSpot Embedded license.

Pricing

The Embedded Developer tier is free for one year, for up to 10 users and 25 million rows of data. Beyond that, Enterprise pricing is custom.

Worth knowing

The Admin settings, Develop, and Analyst Studio pages aren't available in the full application embed. ThoughtSpot also says the layout and feature set are "relatively fixed." It recommends against mixing full app embedding with its SearchEmbed and LiveboardEmbed components. Onboarding includes creating a Model on top of your database connection.

Where it fits

Products where natural-language search is the main experience, backed by budget for an enterprise contract.


4. Looker

Looker doesn't embed its entire interface in one go. Instead, signed embedding lets you embed Explores, dashboards, and Looks, and permissions make the embed self-service. The explore permission opens Explore pages, save_content lets users save changes, and embed_browse_spaces turns on a content browser with a personal embed folder for each user.

How it works

Your app authenticates the user and signs the embed URL with a secret key from Looker, passing user attributes that drive access_filter rules in your LookML. Cookieless embedding is available for browsers that block third-party cookies.

Pricing

Signed and cookieless embedding are only available in Looker's Embed edition. We couldn't find a public price for it, so expect a conversation with Google Cloud sales.

Worth knowing

Looker builds every query from a LookML model, so someone on your team has to write and maintain LookML before customers can explore anything. That's the trade-off for Looker's governed metrics.

Where it fits

Teams that want a governed semantic layer, already run on Google Cloud, and can invest in modeling upfront.


5. GoodData

GoodData Cloud lets you embed dashboards and Analytical Designer through an iframe, so customers can build and edit visualizations inside your app. Multi-tenancy is built around workspaces, and workspace data filters limit what each child workspace can see.

How it works

The iframe authenticates with an API token that your app sends through a postMessage command. Its React SDK covers dashboards and visualizations, but Analytical Designer is iframe-only. GoodData queries your database in real time and caches the results, but you need to build a logical data model first.

Pricing

The Professional plan is priced per workspace, as a platform fee plus the number of workspaces, and Enterprise pricing is custom. Both include white labeling. Neither plan lists a public dollar price.

Worth knowing

Users with the Workspace.MANAGE permission can change the logical data model and bypass workspace data filters, so keep that permission away from customer accounts.

Where it fits

Products with many tenants that map cleanly to workspaces, built by teams comfortable modeling data before launch.


6. Luzmo

Luzmo embedded dashboard editor interface

Luzmo's embedded dashboard editor lets customers create and edit dashboards from inside your application. You choose the mode per user: view, editLimited to create variants or edit a dashboard, or editFull to create, edit, duplicate, and make variants of dashboards.

How it works

Your server requests an embed token, which expires after 24 hours by default. Multi-tenancy uses parameter filters on the dataset that you override in each token, and placing the filter at the dataset level means customers can't remove it in the editor. By default, Luzmo sends queries to your database in real time.

Pricing

Luzmo has one plan, starting at €1,995 per month billed annually, with pricing based on customer usage.

Worth knowing

The editor is drag-and-drop, not SQL. That works well for business users, but it's limiting if your customers' analysts want to write their own queries.

Where it fits

Products whose customers are business users who want to build dashboards without touching SQL.


Other options worth knowing

Power BI Embedded lets customers create and edit reports inside an embed when you set allowEdit: true. It works on Power BI semantic models you build first, so it's closer to embedded report authoring than a full app.


How to choose the right tool

  • Choose Draxlr if your product runs on a SQL database, you want customers to use a query builder, SQL editor, and AI assistant with row-level security on all three, and you want a flat price that doesn't grow per customer.
  • Choose Metabase if you already use it internally, you're comfortable managing tenant isolation through Metabase permissions or your database, and per-user pricing works at your scale.
  • Choose ThoughtSpot if search-first analytics is your differentiator and you're buying at the enterprise level.
  • Choose Looker if governed LookML metrics matter more to you than setup speed.
  • Choose GoodData if your tenants map naturally to workspaces and per-workspace pricing suits your model.
  • Choose Luzmo if your customers want drag-and-drop dashboard building and never need SQL.

Frequently asked questions

1. Is full app embedding the same as an embedded database?

No. An embedded database, like SQLite, runs inside your application's own process. Full app embedding puts an analytics application inside your product's interface, on top of a SQL database you already have, so customers can query and visualize their own data without leaving your app.

2. Is full app embedding the same as interactive embedding?

For Metabase, yes. Metabase renamed Interactive Embedding to Full-app Embedding in Metabase 58, released in January 2026. Other vendors use similar names, like ThoughtSpot's full application embedding, or different ones, like Luzmo's embedded dashboard editor.

3. Can customers see each other's data if they can write SQL?

They can if row-level security doesn't cover raw SQL. Metabase's docs warn that SQL editor access can bypass its row and column security, so it relies on database roles or separate databases instead. Check how your tool handles SQL and AI queries, then run an unfiltered query as a test customer.

4. Do customers need a separate login for a full app embed?

They don't type in a separate login, but they do need an identity in the analytics tool. Metabase handles this through SSO with JWT or SAML. Draxlr and Luzmo take a user ID or token generated by your backend, so customers stay signed in through your app.

5. How much does full app embedding cost?

It depends on the pricing model. Metabase Pro starts at $575 per month with 10 users, then $12 per user. Draxlr includes it from $250 per month with unlimited embedded customers. Luzmo starts at €1,995 per month. ThoughtSpot, Looker, and GoodData quote custom prices.

Bottom line

If your product already runs on Postgres, MySQL, or another SQL database and customers keep asking for reports you haven't built, a full app embed lets them answer those questions themselves. Try Draxlr free for 7 days and set up a Full App Embed against your own database.


Sources

Pricing and product details were checked against these pages on October 9, 2026.


Give every customer their own analytics workspace
Try Draxlr free for 7 days

Related Services.



Hire ReactJS Developers
Hire Gatsby Developers
Hire NextJS Developers

Have a Project in mind?