Skip to content

Connect to Valkey

Tested with: Valkey 8.1.3 on Databasezy · drivers listed per tab · zb CLI 0.1

  1. Copy the host and port from Connect. Valkey on Databasezy uses ACL users, so you connect with a username and a password, never with requirepass alone.
  2. Download the CA bundle (zb api GET /v1/orgs/{org}/ca.pem > databasezy-ca.pem) if your client does not read the OS trust store.
  3. Add your egress IPs under Network → Allow-list.
  4. Use rediss:// (two s) or the driver’s TLS option with hostname verification, as in every snippet below.

Valkey listens on port 6379 (RESP (Redis protocol)). Versions: 9.1, 8.1, 8.0. Replace the example host with the one on your instance's Connect tab; credentials are shown once at creation.

Connection URI
rediss://default:<password>@valkey-7f3k.us-east.databasezy.com:6379/0
cache.js
import { readFileSync } from "node:fs";
import Redis from "ioredis";
const host = "valkey-7f3k.us-east.databasezy.com";
export const redis = new Redis({
host,
port: 6379,
username: "app",
password: process.env.ZB_PASSWORD,
tls: {
ca: readFileSync("databasezy-ca.pem", "utf8"),
servername: host, // hostname verification
rejectUnauthorized: true,
},
maxRetriesPerRequest: 3,
});
await redis.set("hello", "world", "EX", 60);
console.log(await redis.get("hello"));

Tested with: Valkey 9.1 · ioredis 5.4

The RESP endpoint is TLS-only. Clients that try plaintext get a RESP error explaining that TLS is required. Any Redis client from the 7.x era works; the Redis and Valkey client libraries are interchangeable on the wire.

  • Valkey handles thousands of connections cheaply, but the size’s max_connections still applies. Use a single multiplexed client per process (ioredis, StackExchange.Redis and valkey-go do this by default) rather than a pool.
  • Pub/Sub and blocking commands (BLPOP, XREAD BLOCK) hold a connection each; count them.
  • Free instances sleep after 15 idle minutes; a client with reconnect-on-error handles the wake transparently.

RDB snapshots plus AOF are shipped to object storage. There is no point-in-time recovery for key-value engines; restores land on the last snapshot boundary. FLUSHALL and DEBUG are restricted to the app ACL user’s own keyspace and audited.