Lazo Lab Sign up

Python Projects & Skills / The web and automation

Lesson 22 of 28

SQLite databases

SQLite stores data in a single file and comes built into Python. Always use ? placeholders for values, never string formatting, to avoid SQL injection.

Key points

  • sqlite3.connect('app.db')
  • Use ? placeholders
  • commit() saves changes
import sqlite3
db = sqlite3.connect("app.db")
db.execute("CREATE TABLE IF NOT EXISTS users (name TEXT)")
db.execute("INSERT INTO users VALUES (?)", (name,))
db.commit()
Watch a video on thisOpens YouTube search results for “SQLite databases” in a new tab

Quiz · +10 XP

What is the safe way to put user input into a SQL query?

Log in to save progress and earn XP.