# Pt-show-grants with user and password file

**URL:** https://forums.percona.com/t/pt-show-grants-with-user-and-password-file/25388
**Category:** Percona XtraDB Cluster 5.x
**Created:** [September 23, 2023, 10:57am UTC](https://forums.percona.com/t/pt-show-grants-with-user-and-password-file/25388 "2023-09-23T10:57:54Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![soprano](https://avatars.discourse-cdn.com/v4/letter/s/b3f665/32.png) [@soprano](https://forums.percona.com/u/soprano)
#### Post date: [September 23, 2023, 10:57am UTC](https://forums.percona.com/t/pt-show-grants-with-user-and-password-file/25388/1 "2023-09-23T10:57:54Z")

</div>

Hi all,

i would like to save all grants of a server when i do the DBs backup (it runs every night)

While mysql and mysqldump commands have an extrafile option that permit to use a file like this

[mysqldump]  
user=DUMPSER  
password=dumppassword

[client]  
user=CLIENTUSER  
password=clientpassword

that automatically pass the user/password information if using mysql (client) or nysqldump command

This is not available on pt-show-grants it has only -p option or i don’t find the right option to specify a file with credentials inside.

I know it can be a security issue put credentials on a file, but in this case i prefer to have it.

I know also that these information are on the information\_schema DB that i backup every night, but it would be easier to recover from a SQL file if i need anyway.

Let me know if it is possible also with pt-show-grants command.

Thanks in advance  
Claudio

---

<div class="post-metadata">

### Author: ![kedarpercona](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/kedarpercona/32/809_2.png) [@kedarpercona](https://forums.percona.com/u/kedarpercona)
#### Post date: [September 23, 2023, 11:09am UTC](https://forums.percona.com/t/pt-show-grants-with-user-and-password-file/25388/2 "2023-09-23T11:09:49Z")

</div>

Hi @soprano,

Our tool `pt-show-grant` will be able to read the credentials from `[client]` section and produce to result for you.  
You can thus create a backup as  
`pt-show-grants > backup_mysql_grants.sql`

Thanks,  
K

---

<div class="post-metadata">

### Author: ![soprano](https://avatars.discourse-cdn.com/v4/letter/s/b3f665/32.png) [@soprano](https://forums.percona.com/u/soprano)
#### Post date: [September 23, 2023, 12:10pm UTC](https://forums.percona.com/t/pt-show-grants-with-user-and-password-file/25388/3 "2023-09-23T12:10:02Z")

</div>

[client] section in the my.cnf ? or in another file ?

if another file how i specify it ?

Thanks in advance  
Claudio

---

<div class="post-metadata">

### Author: ![kedarpercona](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/kedarpercona/32/809_2.png) [@kedarpercona](https://forums.percona.com/u/kedarpercona)
#### Post date: [September 23, 2023, 12:35pm UTC](https://forums.percona.com/t/pt-show-grants-with-user-and-password-file/25388/4 "2023-09-23T12:35:43Z")

</div>

in `my.cnf` or `.my.cnf`…  
If you want you can keep those things in variable like:

```auto
read -s pw
ENTER PWD
pt-show-grants -uUSER -p$pw > backup_mysql_grants.sql

```

Thanks,  
K

---

<div class="post-metadata">

### Author: ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)
#### Post date: [September 26, 2023, 4:02pm UTC](https://forums.percona.com/t/pt-show-grants-with-user-and-password-file/25388/5 "2023-09-26T16:02:47Z")

</div>

> [@soprano](#):
>
> [client] section in the my.cnf ?

Yes. The `client` section of .my.cnf or my.cnf are automatically read by all programs that use the libmysqlclient library, which is about 99% of apps that connect to MySQL. You don’t need any extra flags to get this functionality.
