TypeDB
Tested with: TypeDB 3.13 on Databasezy · zb CLI 0.1
TypeDB is a database with a strongly typed schema of entities, relations and attributes, queried with its own language, TypeQL. It suits knowledge graphs and domains with many kinds of relationships.
Overview
Section titled “Overview”Each instance runs a single TypeDB Community Edition server. TypeDB drivers and the TypeDB Console talk to it over
gRPC (HTTP/2) on port 443, through TLS at the gateway. The instance starts with the admin user and a generated
password; create databases with the driver or the Console.
TypeDB’s separate HTTP API, which the TypeScript and JavaScript driver uses, is not exposed, so connect with the gRPC drivers below.
| Status | Available |
|---|---|
| Category | Typed graph |
| Versions | 3.13 (newest is the default) |
| Protocol and port | HTTPS on 443; also http on 443 (host typedb-7f3k-http.us-east.databasezy.com) |
| Runtime | Single-node engine (typedb/typedb) |
| Backups | data directory snapshot |
| Point-in-time recovery | No |
| Pause | Scale to zero |
| Free plan | Yes (size f0) |
| Licence | MPL-2.0 |
When to use it
Section titled “When to use it”- Knowledge graphs and domain models with many entity and relation types, where the schema should reject bad data at write time.
- Relations with more than two participants, or relations that themselves have attributes and take part in other relations.
- Access-control, lineage and dependency models that you query by pattern rather than by key.
Pick PostgreSQL for tabular application data and simple foreign keys, and a search or vector engine for text or similarity search.
Create an instance
Section titled “Create an instance”- Open the portal and choose New instance.
- Pick TypeDB and a version (3.13).
- Choose a size and region. On the Free plan the size is f0. Secure placement is listed only after your organization has signed the BAA.
- Check the hourly price and monthly estimate, then confirm. The Connect tab fills in when the instance is ready.
zb instances create --engine typedb --engine-version 3.13 \ --size s1 --region us-east --name typedb-demo --wait# On the Free plan, use --size f0
# Reveal the credentials once and store them in your secret managerzb instances credentials reveal typedb-democurl -sS https://api.databasezy.com/v1/orgs/$ZB_ORG/projects/$ZB_PROJECT/instances \ -H "Authorization: Bearer $ZB_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "engine": "typedb", "engine_version": "3.13", "size": "s1", "region": "us-east", "name": "typedb-demo"}'
The response is 201 with the instance in status requested, or 202 when a
team approval policy applies. See the REST API reference.
Connect
Section titled “Connect”Endpoint and credentials
Section titled “Endpoint and credentials”| Host | typedb-<id>.<region>.databasezy.com, for example typedb-7f3k.us-east.databasezy.com |
|---|---|
Port 443 | gRPC over HTTP/2 for the TypeDB 3 drivers and Console |
Port 443 | HTTP API: sign in at /v1/signin, then queries at /v1/query with the bearer token
, on host typedb-7f3k-http.us-east.databasezy.com |
| Single-IP regions |
Single-IP regions use 8443 for HTTP engines instead of 443. The
portal Connect page always shows the right port.
|
| TLS | Required on every port; plaintext is refused. Verify the server: https:// (or the driver's TLS flag) with normal certificate verification; the certificate is publicly trusted. |
| Credentials | Username admin and a generated password, presented as driver Credentials(username, password). Shown once at creation; reveal or rotate it from the Connect tab. |
TypeDB drivers take an address (host:port), not a URL. Turn TLS on in the driver options; the gateway certificate is
publicly trusted, so no CA path is needed.
Drivers and clients
Section titled “Drivers and clients”TypeDB listens on port 443 (gRPC over HTTP/2 for the TypeDB 3 drivers and Console); port 443 on typedb-7f3k-http.us-east.databasezy.com (HTTP API: sign in at /v1/signin, then queries at /v1/query with the bearer token). Versions: 3.13. Replace the example host with the one on your instance's Connect tab; credentials are shown once at creation.
typedb-7f3k.us-east.databasezy.com:443 (gRPC over TLS; drivers take host:port, not a URL)import osfrom typedb.driver import Credentials, DriverOptions, TypeDB
driver = TypeDB.driver( "typedb-7f3k.us-east.databasezy.com:443", Credentials("admin", os.environ["ZB_PASSWORD"]), DriverOptions(is_tls_enabled=True), # TLS is required by the gateway)if not driver.databases.contains("app"): driver.databases.create("app")print([db.name for db in driver.databases.all()])driver.close()Tested with: TypeDB 3.13 · typedb-driver 3.x (Python)
use typedb_driver::{Credentials, DriverOptions, TypeDBDriver};
#[tokio::main]async fn main() -> Result<(), Box<dyn std::error::Error>> { let driver = TypeDBDriver::new( "typedb-7f3k.us-east.databasezy.com:443", Credentials::new("admin", &std::env::var("ZB_PASSWORD")?), DriverOptions::new(true, None)?, // TLS on, system trust store ) .await?; for db in driver.databases().all().await? { println!("{}", db.name()); } Ok(())}Tested with: TypeDB 3.13 · typedb-driver 3.x (Rust)
import com.typedb.driver.TypeDB;import com.typedb.driver.api.Credentials;import com.typedb.driver.api.DriverOptions;
public final class Graph { public static void main(String[] args) { try (var driver = TypeDB.driver("typedb-7f3k.us-east.databasezy.com:443", new Credentials("admin", System.getenv("ZB_PASSWORD")), new DriverOptions(true, null))) { // TLS on, system trust store driver.databases().all().forEach(db -> System.out.println(db.name())); } }}Tested with: TypeDB 3.13 · typedb-driver 3.x (Java)
# TLS is on by default in Console 3.x; never pass --tls-disabled to a Databasezy instancetypedb console --address=typedb-7f3k.us-east.databasezy.com:443 --username=adminTested with: TypeDB 3.13 · TypeDB Console 3.x
# The HTTP API has its own hostname: sign in for a bearer token, then queryTOKEN=$(curl -s https://typedb-7f3k-http.us-east.databasezy.com:443/v1/signin \ -H 'Content-Type: application/json' \ -d "{\"username\":\"admin\",\"password\":\"$ZB_PASSWORD\"}" | jq -r .token)curl -s https://typedb-7f3k-http.us-east.databasezy.com:443/v1/databases \ -H "Authorization: Bearer $TOKEN"Tested with: TypeDB 3.13 · curl 8 · TypeDB 3 HTTP API
Use a TypeDB driver or Console 3.11 or newer. TypeDB 3.11 changed the protocol: the server rejects drivers older than 3.11, and 2.x drivers never connect to a 3.x server. Official gRPC drivers exist for Python, Rust and Java, among others.
The admin password is managed by Databasezy: rotate it from the portal or API. If you change it inside TypeDB, the
generated password is set again the next time the instance restarts (a pause and resume, a resize, a rotation). Create
your own TypeDB users for applications; their passwords are yours.
See Connecting to Databasezy for the CA bundle, the IP allow-list and credential rotation, which work the same for every engine.
Migrate in
Section titled “Migrate in”| Source | How | Continuous sync | Guide status |
|---|---|---|---|
| Self-hosted server | Connection string, Local tools (zb migrate --from local) | No | Available |
| Another Databasezy instance | Instance to instance | No | Coming soon · phase 2 |
You can migrate from a self-hosted TypeDB 3.x server (3.11 or newer, TypeDB Cloud included) or from another Databasezy
TypeDB instance. The migration exports the database with TypeDB’s database export (schema and data), imports it into
the new instance with database import, and compares the schema of both. It is a one-time copy: writes made on the
source during the export are not carried over, so stop writes or plan a short cutover.
You can do the same by hand with TypeDB Console 3.11 or newer: run database export <database> schema.tql data.typedb
against the source and database import <database> schema.tql data.typedb against the new instance. A source older than
3.11 needs a Console of its own version for the export.
How migrations work explains preflight, verification and cutover, and engine conversions covers moves between compatible engines.
Backups and restore
Section titled “Backups and restore”A backup is a copy of the server’s data directory, taken while the server runs, so it is crash-consistent rather than quiesced.
TypeDB backups use data directory snapshot. They run inside the instance's namespace, stream straight to the cell's object storage and are checksummed on upload. How often they run and how long they are kept follows your plan's backup policy. A backup is always taken before a resize or a version upgrade.
Point-in-time recovery is not available for TypeDB. A restore returns the data as of a scheduled or manual backup. Restores create a new instance by default and leave the original untouched; an in-place restore asks you to type the instance name and takes a pre-change backup first.
zb backups create typedb-demo --label before-release # manual snapshotzb backups list typedb-demozb backups restore typedb-demo <backup-id> --name typedb-demo-restorePause and scale to zero
Section titled “Pause and scale to zero”TypeDB can scale to zero. A paused instance has no running pods and bills no compute; its storage and backups are kept and billed as usual. Connections are refused until you resume it. On the Free plan an instance pauses by itself after 15 minutes without connections and wakes on the next one; the gateway holds that connection for up to 30 seconds while it starts.
zb instances pause typedb-demozb instances resume typedb-demoSee Pause and resume for schedules, wake times and billing while paused.
Limits, versions and lifecycle
Section titled “Limits, versions and lifecycle”Versions and lifecycle
Section titled “Versions and lifecycle”- Supported versions:
3.13. New instances default to3.13, the only version offered. - Minor and patch releases are applied for you in the maintenance window, always after a pre-change backup.
- New majors are added within 60 days of the upstream release. A major reaches end of life on Databasezy six months after upstream ends support, with notices 90, 30 and 7 days ahead.
Sizes and limits
Section titled “Sizes and limits”TypeDB runs on every size, including the Free plan's f0. The size sets the CPU, memory, storage ceiling and connection limit; the gateway refuses connections over the limit with a protocol error. Storage grows in steps up to the ceiling, and you can resize at any time.
| Size | vCPU | Memory | Max storage | Max connections | ≈ $ / month |
|---|---|---|---|---|---|
f0 | 0.063 | 512 MiB | 1 GB | 20 | Free |
s0 | 0.25 | 1 GiB | 20 GB | 60 | $10 |
s1 | 0.5 | 2 GiB | 50 GB | 100 | $15 |
s2 | 1 | 4 GiB | 200 GB | 200 | $60 |
m2 | 2 | 8 GiB | 500 GB | 400 | $110 |
m4 | 4 | 16 GiB | 1 TB | 800 | $210 |
l8 | 8 | 32 GiB | 4 TB | 1,500 | $410 |
l16 | 16 | 64 GiB | 8 TB | 3,000 | $960 |
xl32 | 32 | 128 GiB | 16 TB | 5,000 | $1,870 |
Full details, including hourly prices and burst CPU, are in the size catalogue; plan quotas are in limits and quotas.
TypeDB keeps a lot of its working set in memory; start on a size with at least 2 GiB for real datasets and watch query latency as data grows. Each database is independent; there is no cross-database query.
Licence
Section titled “Licence”Databasezy runs TypeDB under the MPL-2.0 licence, as listed in the engine catalogue. Your data and schemas are yours whatever the server's licence; the licence governs the server software we run.
TypeDB Community Edition is MPL-2.0. Clustered TypeDB (TypeDB Cloud and Enterprise) is a separate commercial product and is not offered: instances are single-node.
Security
Section titled “Security”- TLS on every connection. TLS 1.2 is the minimum and TLS 1.3 is preferred; plaintext is never
offered. Verify the server, not just the encryption: use
HTTPS with certificate verification. See TLS and the CA bundle. - IP allow-list. The gateway checks the client address before authentication, on every plan.
Manage it under Network → Allow-list in the portal or with
PUT /v1/orgs/{org}/instances/{id}/network. - Credentials. Generated inside the cell, shown once, never stored by the control plane. Rotate them with an overlap window so nothing breaks.
- Secure hosting. Secure placement (HIPAA-ready) is a per-instance option once your organization has signed the BAA: dedicated nodes, customer-managed keys and immutable backups. See Secure hosting and the BAA.
- Staff access. Databasezy staff cannot read your data without a grant you issue. See data confidentiality.
Can I run a TypeDB cluster?
Section titled “Can I run a TypeDB cluster?”No. Databasezy offers the single-node Community Edition server only.
Which drivers can I use?
Section titled “Which drivers can I use?”The official TypeDB gRPC drivers (such as Python, Rust and Java) and TypeDB Console, version 3.11 or newer, with TLS on. The HTTP API and the TypeScript driver that uses it are not available.
Is TypeDB on the Free plan?
Section titled “Is TypeDB on the Free plan?”Yes, on the f0 size.