Meilisearch
Tested with: Meilisearch 1.54 on Databasezy · zb CLI 0.1
Meilisearch is a fast, typo-tolerant search engine with filters, facets and sorting out of the box. Push JSON documents in over HTTPS and query them from your backend or, with a scoped key, straight from the browser.
Overview
Section titled “Overview”Each instance runs Meilisearch Community Edition as a single node in production mode, with telemetry turned off. The
revealed credential is the instance’s master key. Use it only on your servers, to manage indexes and to create
scoped API keys; Meilisearch also creates a default search key and a default admin key, which you can list with
GET /keys.
| Status | Available |
|---|---|
| Category | Search |
| Versions | 1.54 (newest is the default) |
| Protocol and port | HTTPS on 443 |
| Runtime | Single-node engine (getmeili/meilisearch) |
| Backups | native snapshots |
| Point-in-time recovery | No |
| Pause | Scale to zero |
| Free plan | Yes (size f0) |
| Licence | MIT |
When to use it
Section titled “When to use it”- Site, documentation and help-centre search.
- Product catalogues with faceted navigation and filters.
- Search-as-you-type, where typo tolerance matters more than exact matching.
Meilisearch is not your system of record: keep the source data in a database and index it into Meilisearch. For nearest-neighbour search over your own embeddings at scale, look at Qdrant or Weaviate.
Create an instance
Section titled “Create an instance”- Open the portal and choose New instance.
- Pick Meilisearch and a version (1.54).
- Choose a size and region. On the Free plan the size is f0. Secure placement is listed only after your organization has signed the BAA.
- Check the hourly price and monthly estimate, then confirm. The Connect tab fills in when the instance is ready.
zb instances create --engine meilisearch --engine-version 1.54 \ --size s1 --region us-east --name meilisearch-demo --wait# On the Free plan, use --size f0
# Reveal the credentials once and store them in your secret managerzb instances credentials reveal meilisearch-democurl -sS https://api.databasezy.com/v1/orgs/$ZB_ORG/projects/$ZB_PROJECT/instances \ -H "Authorization: Bearer $ZB_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "engine": "meilisearch", "engine_version": "1.54", "size": "s1", "region": "us-east", "name": "meilisearch-demo"}'
The response is 201 with the instance in status requested, or 202 when a
team approval policy applies. See the REST API reference.
Connect
Section titled “Connect”Endpoint and credentials
Section titled “Endpoint and credentials”| Host | meili-<id>.<region>.databasezy.com, for example meili-7f3k.us-east.databasezy.com |
|---|---|
Port 443 | REST API |
| Single-IP regions |
Single-IP regions use 8443 for HTTP engines instead of 443. The
portal Connect page always shows the right port.
|
| TLS | Required on every port; plaintext is refused. Verify the server: https:// (or the driver's TLS flag) with normal certificate verification; the certificate is publicly trusted. |
| Credentials | One generated API key (token) with no username, presented as Authorization: Bearer <key>; the revealed key is the master key. Shown once at creation; reveal or rotate it from the Connect tab. |
Send the key as Authorization: Bearer <key>. Use the master key or an admin key on servers, and a search-only key,
limited to the indexes it needs, in browsers and mobile apps.
Drivers and clients
Section titled “Drivers and clients”Meilisearch listens on port 443 (REST API). Versions: 1.54. Replace the example host with the one on your instance's Connect tab; credentials are shown once at creation.
https://meili-7f3k.us-east.databasezy.com:443import { Meilisearch } from "meilisearch"; // older releases export MeiliSearch
const client = new Meilisearch({ host: "https://meili-7f3k.us-east.databasezy.com:443", apiKey: process.env.ZB_TOKEN, // master key on the server, a scoped key in browsers});
const movies = client.index("movies");// Writes are queued as tasks and indexed asynchronouslyawait movies.updateFilterableAttributes(["year"]);await movies.addDocuments([{ id: 1, title: "Space Adventure Club", year: 2014 }]);console.log(await movies.search("spase", { filter: "year > 2000" }));Tested with: Meilisearch 1.54 · meilisearch-js 0.5x
import osimport meilisearch
client = meilisearch.Client("https://meili-7f3k.us-east.databasezy.com:443", os.environ["ZB_TOKEN"])movies = client.index("movies")
task = movies.add_documents([{"id": 1, "title": "Space Adventure Club", "year": 2014}])client.wait_for_task(task.task_uid)print(movies.search("spase"))Tested with: Meilisearch 1.54 · meilisearch-python 0.3x
curl -sS https://meili-7f3k.us-east.databasezy.com:443/healthcurl -sS https://meili-7f3k.us-east.databasezy.com:443/indexes -H "Authorization: Bearer $ZB_TOKEN"
# A search-only key for a browser, limited to one indexcurl -sS https://meili-7f3k.us-east.databasezy.com:443/keys -H "Authorization: Bearer $ZB_TOKEN" \ -H "Content-Type: application/json" \ -d '{"name": "web-search", "actions": ["search"], "indexes": ["movies"], "expiresAt": null}'Tested with: Meilisearch 1.54 · curl 8
Writes (adding documents, changing settings) are queued as tasks and processed asynchronously; poll GET /tasks/<uid>
or use your SDK’s wait helper before relying on the result. Official SDKs exist for JavaScript, Python, PHP, Ruby,
Go, Rust, Java, .NET, Swift and Dart, and the InstantSearch adapter works with the same scoped keys.
See Connecting to Databasezy for the CA bundle, the IP allow-list and credential rotation, which work the same for every engine.
Migrate in
Section titled “Migrate in”| Source | How | Continuous sync | Guide status |
|---|---|---|---|
| Algolia | Connection string | No | Coming soon · phase 3 |
| Self-hosted server | Connection string, Local tools (zb migrate --from local) | No | Available |
| Another Databasezy instance | Instance to instance | No | Coming soon · phase 2 |
Coming from Algolia or another Meilisearch server, export your records as JSON and add them to an index with the documents API in batches, then apply your index settings (searchable, filterable and sortable attributes, ranking rules, synonyms). Remember to rotate any keys that were embedded in front-end code.
How migrations work explains preflight, verification and cutover, and engine conversions covers moves between compatible engines.
Backups and restore
Section titled “Backups and restore”Backups use Meilisearch’s snapshot API: a consistent copy of every index, its settings and the API keys, written by
Meilisearch itself and copied to object storage. A restore loads the snapshot before the server starts. API key values
derive from the master key, so after a restore into a new instance every key has a new value: fetch them with
GET /keys. There is no point-in-time recovery.
Meilisearch backups use native snapshots. They run inside the instance's namespace, stream straight to the cell's object storage and are checksummed on upload. How often they run and how long they are kept follows your plan's backup policy. A backup is always taken before a resize or a version upgrade.
Point-in-time recovery is not available for Meilisearch. A restore returns the data as of a scheduled or manual backup. Restores create a new instance by default and leave the original untouched; an in-place restore asks you to type the instance name and takes a pre-change backup first.
zb backups create meilisearch-demo --label before-release # manual snapshotzb backups list meilisearch-demozb backups restore meilisearch-demo <backup-id> --name meilisearch-demo-restorePause and scale to zero
Section titled “Pause and scale to zero”Meilisearch can scale to zero. A paused instance has no running pods and bills no compute; its storage and backups are kept and billed as usual. Connections are refused until you resume it. On the Free plan an instance pauses by itself after 15 minutes without connections and wakes on the next one; the gateway holds that connection for up to 30 seconds while it starts.
zb instances pause meilisearch-demozb instances resume meilisearch-demoSee Pause and resume for schedules, wake times and billing while paused.
Limits, versions and lifecycle
Section titled “Limits, versions and lifecycle”Versions and lifecycle
Section titled “Versions and lifecycle”- Supported versions:
1.54. New instances default to1.54, the only version offered. - Minor and patch releases are applied for you in the maintenance window, always after a pre-change backup.
- New majors are added within 60 days of the upstream release. A major reaches end of life on Databasezy six months after upstream ends support, with notices 90, 30 and 7 days ahead.
Sizes and limits
Section titled “Sizes and limits”Meilisearch runs on every size, including the Free plan's f0. The size sets the CPU, memory, storage ceiling and connection limit; the gateway refuses connections over the limit with a protocol error. Storage grows in steps up to the ceiling, and you can resize at any time.
| Size | vCPU | Memory | Max storage | Max connections | ≈ $ / month |
|---|---|---|---|---|---|
f0 | 0.063 | 512 MiB | 1 GB | 20 | Free |
s0 | 0.25 | 1 GiB | 20 GB | 60 | $10 |
s1 | 0.5 | 2 GiB | 50 GB | 100 | $15 |
s2 | 1 | 4 GiB | 200 GB | 200 | $60 |
m2 | 2 | 8 GiB | 500 GB | 400 | $110 |
m4 | 4 | 16 GiB | 1 TB | 800 | $210 |
l8 | 8 | 32 GiB | 4 TB | 1,500 | $410 |
l16 | 16 | 64 GiB | 8 TB | 3,000 | $960 |
xl32 | 32 | 128 GiB | 16 TB | 5,000 | $1,870 |
Full details, including hourly prices and burst CPU, are in the size catalogue; plan quotas are in limits and quotas.
Indexing is memory- and CPU-heavy. Each instance limits indexing to half of the size’s memory and one thread per
whole CPU of the size, so a bulk import on a small size takes longer. The f0 size suits small indexes (thousands of
documents); a large import there can still run out of memory, in which case Meilisearch retries the batch at every
restart until you cancel the task (POST /tasks/cancel) and resize. Request bodies are capped
by Meilisearch’s payload limit (100 MB by default), so send large imports in batches. Embedders that call an external
API (for AI-powered or hybrid search) need outbound network access from the instance; bring your own vectors if that is
not available to you.
Licence
Section titled “Licence”Databasezy runs Meilisearch under the MIT licence, as listed in the engine catalogue. Your data and schemas are yours whatever the server's licence; the licence governs the server software we run.
Meilisearch Community Edition is MIT-licensed. Enterprise Edition features are not included.
Security
Section titled “Security”- TLS on every connection. TLS 1.2 is the minimum and TLS 1.3 is preferred; plaintext is never
offered. Verify the server, not just the encryption: use
HTTPS with certificate verification. See TLS and the CA bundle. - IP allow-list. The gateway checks the client address before authentication, on every plan.
Manage it under Network → Allow-list in the portal or with
PUT /v1/orgs/{org}/instances/{id}/network. - Credentials. Generated inside the cell, shown once, never stored by the control plane. Rotate them with an overlap window so nothing breaks.
- Secure hosting. Secure placement (HIPAA-ready) is a per-instance option once your organization has signed the BAA: dedicated nodes, customer-managed keys and immutable backups. See Secure hosting and the BAA.
- Staff access. Databasezy staff cannot read your data without a grant you issue. See data confidentiality.
Can I query Meilisearch from the browser?
Section titled “Can I query Meilisearch from the browser?”Yes, with a search-only API key limited to the indexes the page needs. Never put the master key or an admin key in front-end code.
Which key do I get when the instance is created?
Section titled “Which key do I get when the instance is created?”The master key. Use it to create scoped keys with POST /keys, and use those keys in your applications.
Is Meilisearch on the Free plan?
Section titled “Is Meilisearch on the Free plan?”Yes, on the f0 size. The f0 size suits small indexes and prototypes.