KITFORMA · EDITORIAL ANSWER
Why does sqlite3 treat a string parameter as many bindings?
KitForma editorial guide. The parameter argument must be a sequence of values. A string is itself a sequence, and `(value)` is only parenthesized text, not a one-element tuple.
Step-by-step answer
(value) is only parenthesized text, not a one-element tuple.
Use cursor.execute("SELECT name FROM users WHERE id = ?", (value,)) or a one-element list. The comma creates the tuple. Test one-character and multi-character strings so accidental success cannot hide the error. Do not solve a binding-count error with string interpolation; parameter binding is what keeps values separate from SQL syntax. Placeholders represent data values, not table or column names, which require a separate allowlisted identifier strategy.
Minimal example:
import sqlite3
with sqlite3.connect(":memory:") as db:
assert db.execute("SELECT ?", ("hello",)).fetchone() == ("hello",)Sources and verification
Sources checked:
Scope: This editorial guide is based on the cited sources and tool behavior. A forum question or a query observed for our site does not establish market search volume, low competition, guaranteed rankings or inadequate answers elsewhere.
This editorial answer was prepared by KitForma with AI assistance. It is not presented as a real member question or an independent user review. Check the sources and the result with your own file; report corrections in the discussion.