Skip to content

CLI

Tested with: zb CLI 0.1 · Windows 11 · Ubuntu 24.04

zb is a single Rust binary that talks to the public API. It is published on GitHub Releases for Linux (x86_64, arm64), macOS (Apple silicon, Intel) and Windows (x86_64), with a Homebrew formula and a Scoop manifest.

install
brew install zerobase-io/tap/zb # macOS / Linux
scoop bucket add zerobase https://github.com/zerobase-io/scoop-bucket
scoop install zerobase/zb # Windows
# or download zb-<version>-<target>.tar.gz / .zip from GitHub Releases and put `zb` on PATH

Shell completion: zb completion bash|zsh|fish|powershell|elvish prints a script, for example zb completion zsh > "${fpath[1]}/_zb" or zb completion powershell | Out-String | Invoke-Expression.

shell
zb login # prompts for an API key (create one in the portal or with `zb api-keys create`)
zb login --key zb_live_... # non-interactive; or set ZB_API_KEY (CI)
zb orgs list ; zb orgs use org_01J8...
zb projects use prj_01J8... # default for `instances create` and `migrate --create`
zb logout

zb login verifies the key against GET /v1/orgs and saves it, with the API URL and the default org and project, in config.json under the OS config directory (%APPDATA%\zerobase on Windows, ~/.config/zerobase on Linux, ~/Library/Application Support/zerobase on macOS; override with ZB_CONFIG_PATH). On Linux and macOS the file is created with mode 0600. Precedence is flag, then environment (ZB_API_KEY, ZB_API_URL, ZB_ORG, ZB_PROJECT), then the saved file.

zb connect <instance> asks the API for a one-time reveal URL (POST .../credentials/reveal, which needs the credentials:reveal team permission, and a completed second factor if you turned on two-factor authentication or your organization requires it; it is rate limited and audited), fetches the credential directly from your instance’s cell and starts the matching shell with TLS verification on:

Engine wireClientTLSWhere the password goes
Postgres (postgres, timescaledb, questdb)psqlsslmode=verify-full, sslrootcert=system (libpq 16+, else pass --ca)PGPASSWORD in the child environment
MySQL (mysql, mariadb)mysql / mariadb--ssl-mode=VERIFY_IDENTITY --tls-sni-servername=<host> / --ssl-verify-server-certMYSQL_PWD in the child environment
RESP (valkey, redis)valkey-cli / redis-cli--tlsREDISCLI_AUTH in the child environment
MongoDB (ferretdb, mongodb)mongoshtls=truecommand-line argument (mongosh has no variable; zb warns)

The credential is never written to disk and never appears in what you typed, so it does not reach your shell history. HTTP engines have no shell: zb connect <id> --print prints the endpoint, and zb instances credentials reveal <id> prints the token once. --print never reveals anything; it prints the URI with the password masked. Arguments after -- go to the client (zb connect inst_1 -- -c "select 1").

The API does not expose engine logs yet. zb logs <instance> -f streams the instance’s events (status changes, pauses, backups, migrations) from the server-sent events endpoint GET /v1/orgs/{org}/instances/{id}/events and says so on stderr; --json prints one event envelope per line.

0 ok · 1 error · 2 usage error, or the API rejected the request as invalid (400, 409, 422) · 3 zb migrate verification found mismatches · 4 cancelled at a confirmation prompt · 5 the API was unreachable · 6 a local prerequisite of zb migrate is missing (dump tool, docker, wrangler, a running container).

.github/workflows/preview-db.yaml
- name: install zb
run: |
curl -fsSL -o zb.tgz \
https://github.com/zerobase-io/zerobase/releases/download/zb-v0.1.0/zb-0.1.0-x86_64-unknown-linux-gnu.tar.gz
tar -xzf zb.tgz && sudo install zb /usr/local/bin/zb
- run: zb instances create --engine postgres --size s1 --region us-east --name "pg-pr-${{ github.event.number }}" --wait --json > inst.json
env: { ZB_API_KEY: ${{ secrets.ZB_API_KEY }} }

--json prints the raw API response for every command, so jq works on all output.

Generated from zb dev.

Accepted by every command.

ArgumentDescription
--api-url <API_URL>API base URL (default: the one saved by zb login, else https://api.databasezy.com). Env ZB_API_URL.
--org <ORG>Organization id (default: zb orgs use, else your first org). Env ZB_ORG.
--project <PROJECT>Project id (default: zb projects use, else the org’s first project). Env ZB_PROJECT.
--jsonPrint raw JSON API responses instead of tables.
-y, --yesSkip confirmation prompts (never skips typing the name for erase / in-place restore).
-v, --verboseLog each request (method, URL, status, request id) to stderr.
CommandWhat it does
zb apiRaw call to the REST API with your credentials
zb api-keysControl-plane API keys
zb approvalsApproval requests for instances that exceed a team’s policy
zb appsApps: run a container image next to your databases, with releases, rollback, scaling, env, domains and jobs
zb backupsBackups, restores and point-in-time recovery
zb completionPrint a shell completion script
zb connectOpen the engine’s shell (psql, mysql, valkey-cli, mongosh) with TLS and a one-time credential. The credential is passed through the child’s environment where the client supports it and is never written to disk or shell history
zb cost-reportMonthly cost allocation per team and cost centre
zb dbDeclarative schemas: pull, diff and push schema-as-code migrations (PostgreSQL)
zb docsGenerate the CLI reference (Markdown or a man page) from this binary
zb functionsEdge functions: deploy, list, invoke, logs, versions, triggers (Deno / TypeScript, Supabase compatible)
zb genGenerate code from a project (types)
zb instancesManage database instances
zb loginSave an API key (and API URL) in the OS config directory
zb logoutRemove the saved API key
zb logsStream an instance’s events (status changes, backups, migrations)
zb membersOrg members and invites
zb migrateMove a database into Databasezy
zb orgsOrganizations you belong to; use sets the default
zb projectsProjects in the org; use sets the default
zb realtimeProject realtime: broadcast, presence and database changes over WebSockets, database webhooks
zb sandboxSandboxes: short-lived isolated containers to run code in (exec, files, snapshots)
zb secretsFunction secrets of the project (names only are ever shown)
zb ssh-keySSH public keys on your account (workspace SSH through the bastion)
zb storageProject storage: buckets, files (ss:///bucket/path), signed transfers and S3 credentials
zb teamsTeams, their members and budgets
zb usageUsage and list-price cost for the current month (or —from/—to), grouped
zb wsCloud dev workspaces: create, start, stop, and connect over SSH (VS Code / Cursor Remote-SSH)

Raw call to the REST API with your credentials.

zb api [OPTIONS] <METHOD> <PATH>
ArgumentDescription
<METHOD>HTTP method (GET, POST, PATCH, PUT, DELETE).
<PATH>Path starting with /v1/...; {org} is replaced by the current org id.
-d, --data <DATA>JSON body, @file or - for stdin.

Control-plane API keys.

SubcommandWhat it does
zb api-keys createCreate a key; the secret is printed once
zb api-keys listList API keys (the secret is never shown again)
zb api-keys revokeRevoke a key

Create a key; the secret is printed once.

zb api-keys create [OPTIONS] --name <NAME>
ArgumentDescription
--expires <EXPIRES>Expiry (RFC 3339).
--name <NAME>Required.
--role <ROLE>Org role for the key (default: member).
--scope <SCOPE>Restrict to these permissions (comma separated).

List API keys (the secret is never shown again).

zb api-keys list [OPTIONS]

Revoke a key.

zb api-keys revoke [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.

Approval requests for instances that exceed a team’s policy.

SubcommandWhat it does
zb approvals approveApprove (creates the instance)
zb approvals denyDeny with a reason
zb approvals getShow one approval request
zb approvals listList approval requests

Approve (creates the instance).

zb approvals approve [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.
--reason <REASON>

Deny with a reason.

zb approvals deny [OPTIONS] --reason <REASON> <ID>
ArgumentDescription
<ID>Resource id.
--reason <REASON>Required.

Show one approval request.

zb approvals get [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.

List approval requests.

zb approvals list [OPTIONS]
ArgumentDescription
--mineOnly requests you made.
--status <STATUS>pending, approved, denied, expired.
--team <TEAM>

Apps: run a container image next to your databases, with releases, rollback, scaling, env, domains and jobs.

SubcommandWhat it does
zb apps buildsGit builds of an app: list, get, create, cancel and logs
zb apps createCreate an app from a container image (—image; the tag is pinned to its digest) or a GitHub repository (—repo: built in the cell and redeployed on every push); prints its URL, or the approval request when a team policy needs one
zb apps deleteDelete an app with its releases, environment, domains and jobs. Irreversible; asks first unless —yes
zb apps deployDeploy a new release: a new image, or the current reference again (a moved tag is resolved to its new digest); replicas roll one at a time
zb apps domainsCustom domains of an app: add one, create its two CNAME records, verify
zb apps envAn app’s environment: plain values, project secrets and instance credentials (resolved in the cell)
zb apps getShow one app: status, URL, current release, scaling, port and health check
zb apps jobsJobs: one-off and cron commands in the app’s image with its environment
zb apps listList the project’s apps (the global —project, else the default project)
zb apps logsPrint an app’s container logs, each line prefixed with its replica (-f follows them; —job-run shows a job run’s); —json prints the single-use stream URL instead
zb apps metricsShow an app’s replicas, restarts, limits and recent CPU / memory samples
zb apps releasesList an app’s releases, newest first (* marks the release the app runs)
zb apps restartRestart every replica with a rolling restart (recorded as a release)
zb apps rollbackRoll back to an earlier release (default: the one before the current), pinned to that release’s digest
zb apps scaleChange an app’s scaling: size, min/max replicas, CPU target and scale to zero
zb apps startStart a stopped app: its current release runs again
zb apps stopStop an app: replicas go to zero and compute stops billing; releases, env, domains and jobs are kept
zb apps updateChange an app’s settings: scaling, port, protocol, health check, command, args or registry secret (rolls the running release)

Git builds of an app: list, get, create, cancel and logs.

SubcommandWhat it does
zb apps builds cancelCancel a queued or running build
zb apps builds createBuild the app now: its branch (or —ref / —commit), deployed when it succeeds unless —no-deploy
zb apps builds getShow one build: status, commit, image digest, release and duration
zb apps builds listList an app’s builds, newest first
zb apps builds logsPrint a build’s log (secrets are masked by the cell); -f follows a running build

Cancel a queued or running build.

zb apps builds cancel [OPTIONS] <APP> <BUILD>
ArgumentDescription
<APP>App name or id (app_…).
<BUILD>Build id (bld_…).

Build the app now: its branch (or —ref / —commit), deployed when it succeeds unless —no-deploy.

zb apps builds create [OPTIONS] <APP>
ArgumentDescription
<APP>App name or id (app_…).
--commit <SHA>Commit to build (40 hex characters).
--no-deployBuild the image without releasing it.
--ref <BRANCH>Branch to build (default: the app’s branch).
--timeout <TIMEOUT>Give up waiting after this many seconds (with —wait). Default 1800.
--waitWait until the build ends (or failed).

Show one build: status, commit, image digest, release and duration.

zb apps builds get [OPTIONS] <APP> <BUILD>
ArgumentDescription
<APP>App name or id (app_…).
<BUILD>Build id (bld_…).

List an app’s builds, newest first.

zb apps builds list [OPTIONS] <APP>
ArgumentDescription
<APP>App name or id (app_…).

Print a build’s log (secrets are masked by the cell); -f follows a running build.

zb apps builds logs [OPTIONS] <APP> <BUILD>
ArgumentDescription
<APP>App name or id (app_…).
<BUILD>Build id (bld_…).
-f, --followKeep streaming while the build runs.

Create an app from a container image (—image; the tag is pinned to its digest) or a GitHub repository (—repo: built in the cell and redeployed on every push); prints its URL, or the approval request when a team policy needs one.

zb apps create [OPTIONS] <NAME>
ArgumentDescription
<NAME>App name: 1-30 lower-case letters, digits and -, starting with a letter; unique in the project.
--arg <ARG>Override the image arguments, one per flag (repeat it).
--branch <BRANCH>Branch to build and follow (with —repo; default main).
--builder <BUILDER>dockerfile (default: BuildKit) or buildpacks (no Dockerfile needed). One of dockerfile, buildpacks.
--command <ARG>Override the image entrypoint, one argument per flag (repeat it).
--context <DIR>Build context directory in the repository (default the root).
--cpu-target <PERCENT>Average CPU percent the autoscaler keeps replicas at (default 70).
--dedicated-nodesRun on the org’s own nodes.
--dockerfile <PATH>Dockerfile path in the repository (default Dockerfile).
--env <KEY=VALUE>Plain environment variable KEY=VALUE (repeat it).
--env-instance <KEY=INSTANCE[:ROLE[:FIELD]]>Variable from a project instance’s credential KEY=INSTANCE[:ROLE[:FIELD]] (role default app; field uri, host, port, username, password or database; default uri).
--env-secret <KEY=SECRET>Variable from a project secret KEY=SECRET, resolved in the cell (repeat it).
--health-path <PATH>HTTP readiness and liveness path, e.g. /healthz (default: a TCP check).
--idle-minutes <MINUTES>Idle minutes before scaling to zero (default 15).
--image <IMAGE>Container image (ghcr.io/org/web:1, nginx@sha256:…); a tag is resolved to its digest now.
--max <N>Maximum replicas; above —min the app autoscales on CPU (default 1).
--min <N>Minimum replicas (default 1).
--no-auto-deployDo not build and deploy on every push to the branch.
--placement <PLACEMENT>shared (default) or secure (the hipaa cell; needs a signed BAA).
--port <PORT>Container port the app listens on (default 8080).
--protocol <PROTOCOL>http (default), tcp (TLS with SNI on the app host) or none (no ingress). One of http, tcp, none.
--region <REGION>Region (default: the org’s default region).
--registry-secret <SECRET>Project secret with the registry credentials, for a private image (docker config JSON or user:token).
--repo <OWNER/NAME>Build from this GitHub repository (owner/name) of the org’s GitHub App installation instead of —image.
--scale-to-zeroScale to zero replicas when idle; the next request wakes it (paid plans).
--size <SIZE>Size of each replica: c0 (default), c1, c2, c3 (zb api GET /v1/sizes lists them).
--timeout <TIMEOUT>Give up waiting after this many seconds (with —wait). Default 600.
--waitWait until the app is running (or failed).

Delete an app with its releases, environment, domains and jobs. Irreversible; asks first unless —yes.

zb apps delete [OPTIONS] <APP>
ArgumentDescription
<APP>App name or id (app_…).

Deploy a new release: a new image, or the current reference again (a moved tag is resolved to its new digest); replicas roll one at a time.

zb apps deploy [OPTIONS] <APP>
ArgumentDescription
<APP>App name or id (app_…).
--image <IMAGE>New image reference (default: the app’s current reference).
--registry-secret <SECRET>Change the registry secret with this deploy.
--timeout <TIMEOUT>Give up waiting after this many seconds (with —wait). Default 600.
--waitWait until the release serves (or failed).

Custom domains of an app: add one, create its two CNAME records, verify.

SubcommandWhat it does
zb apps domains addAdd a custom domain and print the two CNAME records to create before verify
zb apps domains listList an app’s custom domains and the DNS records each one needs
zb apps domains removeRemove a custom domain from an app (asks first unless —yes)
zb apps domains verifyCheck a domain’s DNS records now; once verified the cell issues its certificate

Add a custom domain and print the two CNAME records to create before verify.

zb apps domains add [OPTIONS] <APP> <HOSTNAME>
ArgumentDescription
<APP>App name or id (app_…).
<HOSTNAME>Hostname, e.g. www.example.com.

List an app’s custom domains and the DNS records each one needs.

zb apps domains list [OPTIONS] <APP>
ArgumentDescription
<APP>App name or id (app_…).

Remove a custom domain from an app (asks first unless —yes).

zb apps domains remove [OPTIONS] <APP> <DOMAIN>
ArgumentDescription
<APP>App name or id (app_…).
<DOMAIN>Domain hostname or id (adom_…).

Check a domain’s DNS records now; once verified the cell issues its certificate.

zb apps domains verify [OPTIONS] <APP> <DOMAIN>
ArgumentDescription
<APP>App name or id (app_…).
<DOMAIN>Domain hostname or id (adom_…).

An app’s environment: plain values, project secrets and instance credentials (resolved in the cell).

SubcommandWhat it does
zb apps env listList an app’s variables (secrets and credentials show their reference, never a value)
zb apps env setSet variables (KEY=VALUE, —secret, —instance); the others are kept
zb apps env unsetRemove variables (repeat the key: zb apps env unset web FOO BAR)

List an app’s variables (secrets and credentials show their reference, never a value).

zb apps env list [OPTIONS] <APP>
ArgumentDescription
<APP>App name or id (app_…).

Set variables (KEY=VALUE, —secret, —instance); the others are kept.

zb apps env set [OPTIONS] <APP> [KEY=VALUE]
ArgumentDescription
<APP>App name or id (app_…).
<KEY=VALUE>Plain variables to set (repeat: FOO=1 BAR=2).
--instance <KEY=INSTANCE[:ROLE[:FIELD]]>Variable from a project instance’s credential KEY=INSTANCE[:ROLE[:FIELD]] (role default app; field uri, host, port, username, password or database; default uri).
--secret <KEY=SECRET>Variable from a project secret KEY=SECRET, resolved in the cell (repeat it).

Remove variables (repeat the key: zb apps env unset web FOO BAR).

zb apps env unset [OPTIONS] <APP> <KEY>
ArgumentDescription
<APP>App name or id (app_…).
<KEY>Variable names to remove.

Show one app: status, URL, current release, scaling, port and health check.

zb apps get [OPTIONS] <APP>
ArgumentDescription
<APP>App name or id (app_…).

Jobs: one-off and cron commands in the app’s image with its environment.

SubcommandWhat it does
zb apps jobs createCreate a job: zb apps jobs create web migrate --schedule "0 3 * * *" -- node migrate.js
zb apps jobs deleteDelete a job and its run history (asks first unless —yes)
zb apps jobs getShow one job: schedule, command, limits and last run
zb apps jobs listList an app’s jobs with their schedule and last run
zb apps jobs runRun a job now; —wait waits for it to finish
zb apps jobs runsList a job’s recent runs: state, exit code and duration
zb apps jobs updateChange a job: schedule, command (after --), concurrency, limits, size, enabled

Create a job: zb apps jobs create web migrate --schedule "0 3 * * *" -- node migrate.js.

zb apps jobs create [OPTIONS] <APP> <NAME> [-- <COMMAND>...]
ArgumentDescription
<APP>App name or id (app_…).
<NAME>Job name, unique in the app.
--backoff-limit <N>Retries of a failed run.
--concurrency <CONCURRENCY>When a run is due while one is running: forbid (default), replace or allow. One of forbid, replace, allow.
--disabledCreate it disabled (a schedule does not fire until update --enable).
--schedule <CRON>Cron schedule, 5 fields in UTC (“0 3 * * *”; default: on request only).
--size <SIZE>Size: c0..c3 (default: the app’s).
--timeout-seconds <SECONDS>Stop a run after this many seconds.
-- <COMMAND>...The command and its arguments, after -- (runs in the app’s image).

Delete a job and its run history (asks first unless —yes).

zb apps jobs delete [OPTIONS] <APP> <JOB>
ArgumentDescription
<APP>App name or id (app_…).
<JOB>Job name or id (job_…).

Show one job: schedule, command, limits and last run.

zb apps jobs get [OPTIONS] <APP> <JOB>
ArgumentDescription
<APP>App name or id (app_…).
<JOB>Job name or id (job_…).

List an app’s jobs with their schedule and last run.

zb apps jobs list [OPTIONS] <APP>
ArgumentDescription
<APP>App name or id (app_…).

Run a job now; —wait waits for it to finish.

zb apps jobs run [OPTIONS] <APP> <JOB>
ArgumentDescription
<APP>App name or id (app_…).
<JOB>Job name or id (job_…).
--timeout <TIMEOUT>Give up waiting after this many seconds (with —wait). Default 3600.
--waitWait until the run finishes (or failed).

List a job’s recent runs: state, exit code and duration.

zb apps jobs runs [OPTIONS] <APP> <JOB>
ArgumentDescription
<APP>App name or id (app_…).
<JOB>Job name or id (job_…).

Change a job: schedule, command (after --), concurrency, limits, size, enabled.

zb apps jobs update [OPTIONS] <APP> <JOB> [-- <COMMAND>...]
ArgumentDescription
<APP>App name or id (app_…).
<JOB>Job name or id (job_…).
--backoff-limit <N>Retries of a failed run.
--concurrency <CONCURRENCY>When a run is due while one is running: forbid (default), replace or allow. One of forbid, replace, allow.
--disableDisable the job (its schedule stops firing; manual runs still work).
--enableEnable the job.
--schedule <CRON>Cron schedule, 5 fields in UTC; "" makes the job on request only.
--size <SIZE>Size: c0..c3; "" uses the app’s.
--timeout-seconds <SECONDS>Stop a run after this many seconds.
-- <COMMAND>...The command and its arguments, after -- (runs in the app’s image).

List the project’s apps (the global —project, else the default project).

zb apps list [OPTIONS]

Print an app’s container logs, each line prefixed with its replica (-f follows them; —job-run shows a job run’s); —json prints the single-use stream URL instead.

zb apps logs [OPTIONS] <APP>
ArgumentDescription
<APP>App name or id (app_…).
-f, --followFollow the stream until interrupted (the cell ends it after 30 minutes).
--job-run <RUN>Logs of one job run (jrun_…, from zb apps jobs runs) instead of the app’s replicas.
--previousThe previous container’s logs (after a crash or an OOM kill).
--since <DURATION>Only lines from the last DURATION (seconds, or 90s, 10m, 2h).
--tail <N>Last N lines per replica (default 500, max 5000).

Show an app’s replicas, restarts, limits and recent CPU / memory samples.

zb apps metrics [OPTIONS] <APP>
ArgumentDescription
<APP>App name or id (app_…).

List an app’s releases, newest first (* marks the release the app runs).

zb apps releases [OPTIONS] <APP>
ArgumentDescription
<APP>App name or id (app_…).

Restart every replica with a rolling restart (recorded as a release).

zb apps restart [OPTIONS] <APP>
ArgumentDescription
<APP>App name or id (app_…).

Roll back to an earlier release (default: the one before the current), pinned to that release’s digest.

zb apps rollback [OPTIONS] <APP>
ArgumentDescription
<APP>App name or id (app_…).
--timeout <TIMEOUT>Give up waiting after this many seconds (with —wait). Default 600.
--to <RELEASE>Release to restore: its id (rel_…) or its number from zb apps releases.
--waitWait until the restored release serves (or failed).

Change an app’s scaling: size, min/max replicas, CPU target and scale to zero.

zb apps scale [OPTIONS] <APP>
ArgumentDescription
<APP>App name or id (app_…).
--cpu-target <PERCENT>Average CPU percent the autoscaler keeps replicas at (default 70).
--idle-minutes <MINUTES>Idle minutes before scaling to zero (default 15).
--max <N>Maximum replicas; above —min the app autoscales on CPU (default 1).
--min <N>Minimum replicas (default 1).
--no-scale-to-zeroKeep at least —min replicas running.
--scale-to-zeroScale to zero replicas when idle; the next request wakes it (paid plans).
--size <SIZE>Size of each replica: c0 (default), c1, c2, c3 (zb api GET /v1/sizes lists them).

Start a stopped app: its current release runs again.

zb apps start [OPTIONS] <APP>
ArgumentDescription
<APP>App name or id (app_…).

Stop an app: replicas go to zero and compute stops billing; releases, env, domains and jobs are kept.

zb apps stop [OPTIONS] <APP>
ArgumentDescription
<APP>App name or id (app_…).

Change an app’s settings: scaling, port, protocol, health check, command, args or registry secret (rolls the running release).

zb apps update [OPTIONS] <APP>
ArgumentDescription
<APP>App name or id (app_…).
--arg <ARG>Override the image arguments, one per flag (repeat it).
--command <ARG>Override the image entrypoint, one argument per flag (repeat it); "" restores the image’s.
--cpu-target <PERCENT>Average CPU percent the autoscaler keeps replicas at (default 70).
--health-path <PATH>HTTP readiness and liveness path, e.g. /healthz (default: a TCP check); "" clears it.
--idle-minutes <MINUTES>Idle minutes before scaling to zero (default 15).
--max <N>Maximum replicas; above —min the app autoscales on CPU (default 1).
--min <N>Minimum replicas (default 1).
--no-scale-to-zeroKeep at least —min replicas running.
--port <PORT>Container port the app listens on (default 8080).
--protocol <PROTOCOL>http (default), tcp (TLS with SNI on the app host) or none (no ingress). One of http, tcp, none.
--registry-secret <SECRET>Project secret with the registry credentials, for a private image (docker config JSON or user:token); "" clears it.
--scale-to-zeroScale to zero replicas when idle; the next request wakes it (paid plans).
--size <SIZE>Size of each replica: c0 (default), c1, c2, c3 (zb api GET /v1/sizes lists them).

Backups, restores and point-in-time recovery.

SubcommandWhat it does
zb backups createTake a manual backup
zb backups getShow one backup
zb backups healthBackup health across the org
zb backups listList an instance’s backups
zb backups pitr-windowShow the point-in-time recovery window
zb backups restoreRestore a backup into a new instance (default) or in place
zb backups restoresList restores of an instance
zb backups settingsShow backup settings, or change them with flags

Take a manual backup.

zb backups create [OPTIONS] <INSTANCE>
ArgumentDescription
<INSTANCE>Instance id.
--label <LABEL>

Show one backup.

zb backups get [OPTIONS] <INSTANCE> <BACKUP>
ArgumentDescription
<INSTANCE>Instance id.
<BACKUP>Backup id.

Backup health across the org.

zb backups health [OPTIONS]

List an instance’s backups.

zb backups list [OPTIONS] <INSTANCE>
ArgumentDescription
<INSTANCE>Instance id.

Show the point-in-time recovery window.

zb backups pitr-window [OPTIONS] <INSTANCE>
ArgumentDescription
<INSTANCE>Instance id.

Restore a backup into a new instance (default) or in place.

zb backups restore [OPTIONS] <INSTANCE> <BACKUP>
ArgumentDescription
<INSTANCE>Instance id.
<BACKUP>Backup id.
--at <AT>Point in time (RFC 3339) inside the PITR window.
--confirm <CONFIRM>The instance name, typed as confirmation for —in-place.
--in-placeRestore over the source instance (asks you to type its name).
--name <NAME>Name of the new instance.
--size <SIZE>Size of the new instance.

List restores of an instance.

zb backups restores [OPTIONS] <INSTANCE>
ArgumentDescription
<INSTANCE>Instance id.

Show backup settings, or change them with flags.

zb backups settings [OPTIONS] <INSTANCE>
ArgumentDescription
<INSTANCE>Instance id.
--cross-region-target <CROSS_REGION_TARGET>Region to copy backups to.
--frequency <FREQUENCY>hourly, daily or weekly (capped by the plan).
--pitr <PITR>Continuous archiving for point-in-time recovery.
--retention-days <RETENTION_DAYS>
--time <SCHEDULE_TIME_UTC>Backup window start, HH:MM UTC.

Print a shell completion script.

zb completion [OPTIONS] <SHELL>
ArgumentDescription
<SHELL>Target shell [possible values: bash, elvish, fish, powershell, zsh].

Open the engine’s shell (psql, mysql, valkey-cli, mongosh) with TLS and a one-time credential. The credential is passed through the child’s environment where the client supports it and is never written to disk or shell history.

zb connect [OPTIONS] <ID> [-- <EXTRA>...]
ArgumentDescription
<ID>Instance id.
--ca <CA>CA bundle to verify the server with (default: the system trust store).
--client <CLIENT>Client binary to run instead of the engine default.
--db <DB>Database name (Postgres default postgres, MySQL none).
--printPrint a masked connection URI instead of spawning a client (no credential is revealed).
-- <EXTRA>...Extra arguments passed to the client after --.

Monthly cost allocation per team and cost centre.

zb cost-report [OPTIONS]
ArgumentDescription
--csvPrint the server’s CSV export.
--month <MONTH>YYYY-MM (UTC); default: the current month.

Declarative schemas as code (Supabase CLI layout and history table): zb db pull writes the live schema to supabase/schemas/SCHEMA.sql (edit those files: add a column, an index, a policy, …) zb db diff -f N writes the migration that brings a database to them, supabase/migrations/TIMESTAMP_N.sql zb db push applies the pending migrations, recorded in supabase_migrations.schema_migrations Branch-aware: a branch is its own instance with its own data, so try a change there first: zb api POST /v1/orgs/{org}/instances/INSTANCE/branches -d ’{“name”:“dev”}’ zb db diff INSTANCE —branch dev -f add_col # plan against the branch zb db push INSTANCE —branch dev # apply it there and verify zb db push INSTANCE # then promote the same migration file The diff loads the declared files into a shadow Postgres and validates the plan there: an embedded Postgres of the live server’s major (15-18) started for the command, or —shadow-url / ZB_SHADOW_DB_URL (a scratch server where you may CREATE DATABASE; needed for extensions the embedded build lacks: vector, postgis, …). PostgreSQL instances only.

SubcommandWhat it does
zb db diffPlan the migration from the database to the declared schema; -f writes it as a migration file
zb db migrationsLocal migration files against the database’s history
zb db pullWrite the live schema as declared SQL files (supabase/schemas/SCHEMA.sql)
zb db pushApply pending migrations (supabase/migrations) in filename order, each in its own transaction

Diff the database against the declared schema (<dir>/schemas/*.sql) and print the SQL that migrates it, each statement’s hazards as -- hazard: comments. With -f <name> it is written to <dir>/migrations/<UTC timestamp>_<name>.sql instead. The plan is validated on the shadow database. Index builds are plain (the migration stays transactional) unless —concurrent-indexes.

zb db diff [OPTIONS] [INSTANCE]
ArgumentDescription
<INSTANCE>Instance id; with —branch, the instance whose branch to use.
--branch <BRANCH>Branch to use: a branch name, git branch or instance id of INSTANCE’s branches (alone: a branch instance id).
--ca <PATH>CA bundle to verify the instance with (default: the system trust store).
--concurrent-indexesBuild and drop indexes CONCURRENTLY (the migration then runs outside a transaction).
--db <NAME>Database name on the instance (default postgres).
--db-url <URL>Connect to this Postgres URL instead of an instance (local development; no credential reveal).
--dir <DIR>Project directory holding schemas/ and migrations/. Default supabase.
-f, --file <NAME>Write the plan as a new migration file with this name.
--schema <SCHEMA>Schema to manage; repeat or comma-separate (default public).
--shadow-url <URL>Scratch Postgres for loading the declared schema and validating plans (default: an embedded Postgres started for the command). Env ZB_SHADOW_DB_URL.

Local migration files against the database’s history.

SubcommandWhat it does
zb db migrations listList local and applied migrations side by side

List local and applied migrations side by side.

zb db migrations list [OPTIONS] [INSTANCE]
ArgumentDescription
<INSTANCE>Instance id; with —branch, the instance whose branch to use.
--branch <BRANCH>Branch to use: a branch name, git branch or instance id of INSTANCE’s branches (alone: a branch instance id).
--ca <PATH>CA bundle to verify the instance with (default: the system trust store).
--db <NAME>Database name on the instance (default postgres).
--db-url <URL>Connect to this Postgres URL instead of an instance (local development; no credential reveal).
--dir <DIR>Project directory holding schemas/ and migrations/. Default supabase.

Read the database’s schema (each —schema) and write it as DDL to <dir>/schemas/<schema>.sql, the declared schema zb db diff compares against. Refuses to overwrite existing files without —force.

zb db pull [OPTIONS] [INSTANCE]
ArgumentDescription
<INSTANCE>Instance id; with —branch, the instance whose branch to use.
--branch <BRANCH>Branch to use: a branch name, git branch or instance id of INSTANCE’s branches (alone: a branch instance id).
--ca <PATH>CA bundle to verify the instance with (default: the system trust store).
--db <NAME>Database name on the instance (default postgres).
--db-url <URL>Connect to this Postgres URL instead of an instance (local development; no credential reveal).
--dir <DIR>Project directory holding schemas/ and migrations/. Default supabase.
--forceOverwrite existing declared-schema files.
--schema <SCHEMA>Schema to manage; repeat or comma-separate (default public).
--shadow-url <URL>Scratch Postgres for loading the declared schema and validating plans (default: an embedded Postgres started for the command). Env ZB_SHADOW_DB_URL.

Apply the local migrations the database has not recorded in supabase_migrations.schema_migrations, in filename order. Each runs in its own transaction with its history row; a migration using CONCURRENTLY runs statement by statement outside a transaction. Versions the database has but the directory lacks are reported, not touched. —dry-run lists what would run.

zb db push [OPTIONS] [INSTANCE]
ArgumentDescription
<INSTANCE>Instance id; with —branch, the instance whose branch to use.
--branch <BRANCH>Branch to use: a branch name, git branch or instance id of INSTANCE’s branches (alone: a branch instance id).
--ca <PATH>CA bundle to verify the instance with (default: the system trust store).
--db <NAME>Database name on the instance (default postgres).
--db-url <URL>Connect to this Postgres URL instead of an instance (local development; no credential reveal).
--dir <DIR>Project directory holding schemas/ and migrations/. Default supabase.
--dry-runList the migrations that would run, change nothing.

Generate the CLI reference (Markdown or a man page) from this binary.

zb docs [OPTIONS]
ArgumentDescription
--checkWith —mdx: fail instead of writing when the file is out of date.
--format <FORMAT>One of markdown, man. Default markdown.
--mdx <MDX>Write the generated reference between the markers in this .mdx file (apps/docs/src/content/docs/reference/cli.mdx).

Edge functions: deploy, list, invoke, logs, versions, triggers (Deno / TypeScript, Supabase compatible).

SubcommandWhat it does
zb functions cronCron triggers of a function
zb functions deleteDelete a function, its versions and triggers
zb functions deployBundle (esbuild; npm:/jsr:/URL imports stay external) and deploy functions; —all deploys every directory
zb functions getShow a function, its active version and triggers
zb functions invokeRun a function once through its cell (verify_jwt does not apply; limits do) and print the response
zb functions listList the project’s functions
zb functions logsInvocation logs from the project’s cell (—follow streams)
zb functions newCreate <dir>/<NAME>/index.ts from a template (hello-world, stripe-webhook, openai-proxy, cron-job)
zb functions rollbackMake an earlier version active again
zb functions setChange a function’s settings (—verify-jwt / —no-verify-jwt, —memory, —timeout, —enable / —disable)
zb functions triggersCron, database, storage, auth and queue triggers of a function
zb functions versionsList a function’s deployed versions

Cron triggers of a function.

SubcommandWhat it does
zb functions cron addRun NAME on a schedule (5-field crontab or @hourly, … in —timezone)
zb functions cron listList NAME’s cron triggers
zb functions cron rmRemove a cron trigger

Run NAME on a schedule (5-field crontab or @hourly, … in —timezone).

zb functions cron add [OPTIONS]
ArgumentDescription
--body <BODY>JSON body of each run.
--missed-runs <MISSED_RUNS>After downtime: latest, all or skip. Default latest.
--schedule <SCHEDULE>Crontab, e.g. ”*/5 * * * *”.
--timezone <TIMEZONE>IANA time zone. Default UTC.

List NAME’s cron triggers.

zb functions cron list [OPTIONS]

Remove a cron trigger.

zb functions cron rm [OPTIONS]

Delete a function, its versions and triggers.

zb functions delete [OPTIONS]

Bundle (esbuild; npm:/jsr:/URL imports stay external) and deploy functions; —all deploys every directory.

zb functions deploy [OPTIONS] [NAME...]
ArgumentDescription
<NAME...>
--allDeploy every function directory.
--dir <DIR>Functions directory (default supabase/functions, else functions).
--entrypoint <ENTRYPOINT>Entrypoint file (default <dir>/<name>/index.ts).
--import-map <IMPORT_MAP>Import map (default <dir>/<name>/deno.json, else <dir>/import_map.json).
--memory <MEMORY>Memory per isolate (MiB, within the plan).
--no-activateUpload the version without making it active.
--no-verify-jwtLet anyone call the function (webhooks); default: config.toml, else on.
--timeout <TIMEOUT>Wall-clock limit (ms, within the plan).
--verify-jwtRequire a project JWT or key (the default for a new function).

Show a function, its active version and triggers.

zb functions get [OPTIONS]

Run a function once through its cell (verify_jwt does not apply; limits do) and print the response.

zb functions invoke [OPTIONS]
ArgumentDescription
-d, --data <DATA>Request body (JSON text).
-H, --header <HEADER>Request header Name: value (repeatable).
-X, --method <METHOD>HTTP method. Default POST.
--path <PATH>Path and query after the function name (/sub?x=1).

List the project’s functions.

zb functions list [OPTIONS]

Invocation logs from the project’s cell (—follow streams).

zb functions logs [OPTIONS] [NAME]
ArgumentDescription
<NAME>
-f, --followStream new lines.
--insecureSkip TLS verification of the cell (private CA).
--level <LEVEL>Only debug, info, warn or error.
--limit <LIMIT>Lines (newest). Default 100.

Create <dir>/<NAME>/index.ts from a template (hello-world, stripe-webhook, openai-proxy, cron-job).

zb functions new [OPTIONS]
ArgumentDescription
--dir <DIR>Functions directory.
-t, --template <TEMPLATE>Template. Default hello-world.

Make an earlier version active again.

zb functions rollback [OPTIONS]

Change a function’s settings (—verify-jwt / —no-verify-jwt, —memory, —timeout, —enable / —disable).

zb functions set [OPTIONS]
ArgumentDescription
--disableDisable the function (403).
--enableEnable the function.
--memory <MEMORY>Memory per isolate (MiB, 0 = plan default).
--no-verify-jwtLet anyone call the function.
--timeout <TIMEOUT>Wall-clock limit (ms, 0 = plan maximum).
--verify-jwtRequire a project JWT or key.

Cron, database, storage, auth and queue triggers of a function.

SubcommandWhat it does
zb functions triggers addAdd a trigger to NAME (—kind cron|database|storage|auth|queue)
zb functions triggers deliveriesDeliveries of a storage or auth trigger, read from the project’s cell (—status dead: the dead letters)
zb functions triggers disableDisable a trigger
zb functions triggers enableEnable a trigger
zb functions triggers listList NAME’s triggers
zb functions triggers replayQueue a failed storage or auth delivery again
zb functions triggers rmRemove a trigger (a database trigger’s webhook goes with it)

Add a trigger to NAME (—kind cron|database|storage|auth|queue).

zb functions triggers add [OPTIONS]
ArgumentDescription
--batch-size <BATCH_SIZE>queue: messages read at a time (default 5).
--body <BODY>cron: JSON body of each run.
--bucket <BUCKET>storage: bucket id.
--dead-letter-queue <DEAD_LETTER_QUEUE>queue: where failed messages go (default <queue>_dlq).
--disabledCreate the trigger disabled.
--events <EVENTS>database: insert,update,delete; storage: created,updated,deleted; auth: signup,login,user_updated,user_deleted.
--kind <KIND>cron, database, storage, auth or queue.
--max-retries <MAX_RETRIES>storage, auth, queue: retries before the dead letter (default 3). Default -1.
--missed-runs <MISSED_RUNS>cron: after downtime latest, all or skip. Default latest.
--prefix <PREFIX>storage: only object names starting with it.
--queue <QUEUE>queue: pgmq queue of the primary database.
--schedule <SCHEDULE>cron: crontab, e.g. ”*/5 * * * *”.
--table <TABLE>database: [schema.]table.
--timezone <TIMEZONE>cron: IANA time zone. Default UTC.
--visibility <VISIBILITY>queue: visibility timeout in seconds (default the function’s timeout + 30).

Deliveries of a storage or auth trigger, read from the project’s cell (—status dead: the dead letters).

zb functions triggers deliveries [OPTIONS]
ArgumentDescription
--insecureSkip TLS verification of the cell (private CA).
--status <STATUS>pending, retrying, delivered or dead.

Disable a trigger.

zb functions triggers disable [OPTIONS]

Enable a trigger.

zb functions triggers enable [OPTIONS]

List NAME’s triggers.

zb functions triggers list [OPTIONS]

Queue a failed storage or auth delivery again.

zb functions triggers replay [OPTIONS]

Remove a trigger (a database trigger’s webhook goes with it).

zb functions triggers rm [OPTIONS]

List a function’s deployed versions.

zb functions versions [OPTIONS]

Generate code from a project: zb gen types prints supabase-js compatible TypeScript types of the data API’s schemas.

SubcommandWhat it does
zb gen typesTypeScript types of the data API’s schemas (supabase-js Database)

Print the Database type supabase-js uses (createClient<Database>(url, key)) for the schemas the project’s data API exposes: tables and views (Row / Insert / Update / Relationships), functions, enums and composite types. Reads the primary database’s catalog through the API; —secret-key reads it through /query/v1 on the project endpoint instead, —db-url from any Postgres you can reach.

zb gen types [OPTIONS]
ArgumentDescription
--db-url <DB_URL>Read the catalog from this Postgres URL instead of the project.
--lang <LANG>Output language (typescript). Default typescript.
-o, --output <OUTPUT>Write to this file instead of stdout.
--schema <SCHEMA>Comma-separated schemas (default: the schemas the data API exposes, or public with —db-url).
--secret-key <SECRET_KEY>Project secret key: read the catalog through /query/v1 (env ZB_PROJECT_SECRET_KEY).

Manage database instances.

SubcommandWhat it does
zb instances createCreate an instance (status starts at requested)
zb instances credentialsOne-time credential reveal and rotation
zb instances deleteDelete an instance (data retained per plan policy)
zb instances eraseDelete an instance and every backup, and issue an erasure certificate. Irreversible
zb instances getShow one instance
zb instances listList instances in the org (only the project’s with an explicit —project)
zb instances pausePause an instance: compute stops, storage is kept and billed
zb instances resizeChange an instance’s size
zb instances resumeResume a paused instance

Create an instance (status starts at requested).

zb instances create [OPTIONS] --engine <ENGINE>
ArgumentDescription
--cost-centre <COST_CENTRE>Cost-centre tag for chargeback.
--engine <ENGINE>Engine id (postgres, mysql, valkey, ferretdb, libsql, …). Required.
--engine-version <ENGINE_VERSION>
--haHigh availability (standby replica).
--name <NAME>
--placement <PLACEMENT>shared (default), dedicated-node or secure.
--region <REGION>
--replicas <REPLICAS>Read replicas.
--size <SIZE>Size id (f0 on the free plan, s1, s2, m2, …). Default: f0 on free orgs, s1 otherwise.
--storage-gb <STORAGE_GB>
--timeout <TIMEOUT>Give up waiting after this many seconds (with —wait). Default 900.
--waitWait until the instance is ready (or failed).

One-time credential reveal and rotation.

SubcommandWhat it does
zb instances credentials revealReveal the instance credentials once (rate limited and audited; needs MFA if you turned it on or your org requires it)
zb instances credentials rotateRotate the credentials; old and new stay valid for a short overlap window

Reveal the instance credentials once (rate limited and audited; needs MFA if you turned it on or your org requires it).

zb instances credentials reveal [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.

Rotate the credentials; old and new stay valid for a short overlap window.

zb instances credentials rotate [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.

Delete an instance (data retained per plan policy).

zb instances delete [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.

Delete an instance and every backup, and issue an erasure certificate. Irreversible.

zb instances erase [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.
--confirm <CONFIRM>The instance name, typed as confirmation (prompted when omitted).

Show one instance.

zb instances get [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.

List instances in the org (only the project’s with an explicit —project).

zb instances list [OPTIONS]

Pause an instance: compute stops, storage is kept and billed.

zb instances pause [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.

Change an instance’s size.

zb instances resize [OPTIONS] --size <SIZE> <ID>
ArgumentDescription
<ID>Resource id.
--size <SIZE>New size id (see zb api GET /v1/sizes). Required.

Resume a paused instance.

zb instances resume [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.

Save an API key (and API URL) in the OS config directory.

zb login [OPTIONS]
ArgumentDescription
--default-org <DEFAULT_ORG>Default org id to use.
--default-project <DEFAULT_PROJECT>Default project id to use.
--key <KEY>API key (zb_...); prompted on stdin when omitted. Alias --api-key. Env ZB_API_KEY.

Remove the saved API key.

zb logout [OPTIONS]

Stream an instance’s events (status changes, backups, migrations).

zb logs [OPTIONS] <INSTANCE>
ArgumentDescription
<INSTANCE>Instance id.
-f, --followFollow the stream until interrupted.

Org members and invites.

SubcommandWhat it does
zb members inviteInvite someone by email
zb members invitesList pending invites
zb members listList org members
zb members removeRemove a member from the org
zb members set-roleChange a member’s org role

Invite someone by email.

zb members invite [OPTIONS] <EMAIL>
ArgumentDescription
<EMAIL>Email address.
--role <ROLE>

List pending invites.

zb members invites [OPTIONS]

List org members.

zb members list [OPTIONS]

Remove a member from the org.

zb members remove [OPTIONS] <USER>
ArgumentDescription
<USER>User id.

Change a member’s org role.

zb members set-role [OPTIONS] <USER> <ROLE>
ArgumentDescription
<USER>User id.
<ROLE>Role name.

Move a database into Databasezy.

zb migrate [OPTIONS] [COMMAND]
ArgumentDescription
--container <NAME|ID>With --from local: run the dump tool inside this running Docker container (name or id) with docker exec, using the tool in its image and the container’s own credentials (override with ZB_DB_USER / ZB_DB_PASSWORD, forwarded by name, never on the command line).
--createCreate a new target instance first (in the global —project).
--db <DB>Database name for --from local (also PGDATABASE / MYSQL_DATABASE). With —container it defaults to the container’s POSTGRES_DB / MYSQL_DATABASE.
--drop-targetDrop existing objects in the target first.
--dry-runPrint the plan and preflight checklist without starting anything.
--engine <ENGINE>Engine hint when it cannot be inferred (.sql files, local, http sources).
--exclude <EXCLUDE>Tables / collections / key patterns to skip.
--from <FROM>Source: a connection URL, a file (.sql/.dump/.sql.gz/.rdb/.sqlite/.db/.duckdb/.bson.tar/.csv/.parquet), local (dump a server on this machine, or inside a Docker container with —container), d1:<database> (export a Cloudflare D1 database with wrangler) or another instance id.
--include <INCLUDE>Tables / collections / key patterns to copy (comma separated, repeatable).
--mode <MODE>copy (default) or copy_and_sync. Default copy.
--name <NAME>Name of the created instance (with —create).
--no-waitReturn right after the migration is accepted instead of following progress.
--provider <PROVIDER>Provider preset when the hostname does not say which (netlify, cloud-sql, vercel-postgres, vercel-kv, …). A line pasted from an env file (--from 'KV_URL=rediss://...') also hints it by the variable name.
--reverse-syncAfter cutover, replicate the new instance back to the source so you can roll back (Postgres, --mode copy_and_sync).
--size <SIZE>Size of the created instance (with —create).
--to <TO>Target instance id.
SubcommandWhat it does
zb migrate cancelCancel a running migration
zb migrate cutoverDrain the last writes, copy sequences, stop continuous sync and report the downtime (copy_and_sync migrations). Waits for the cutover to finish unless —no-wait
zb migrate statusShow status and progress of a migration
zb migrate supabaseImport a Supabase project’s users (with their passwords), storage and functions into the current project

Cancel a running migration.

zb migrate cancel [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.

Drain the last writes, copy sequences, stop continuous sync and report the downtime (copy_and_sync migrations). Waits for the cutover to finish unless —no-wait.

zb migrate cutover [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.
--no-waitReturn once the cutover is accepted.
--timeout <TIMEOUT>Give up waiting after this many seconds (the cutover keeps running). Default 600.

Show status and progress of a migration.

zb migrate status [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.

Imports auth users with their ids, password hashes and identities, storage buckets and objects, and the Edge Functions in supabase/functions into the current project (—project), and reports row-level security policies that call Supabase-only functions. Supabase credentials come from the environment only: SUPABASE_DB_URL, SUPABASE_SERVICE_ROLE_KEY, SUPABASE_ACCESS_TOKEN (optional: deployed functions and secret names), SUPABASE_S3_ACCESS_KEY_ID / SUPABASE_S3_SECRET_ACCESS_KEY (optional). They stay on this machine. Run with —dry-run first. Afterwards move the database with zb migrate --from "$SUPABASE_DB_URL" --to <primary instance>.

zb migrate supabase [OPTIONS]
ArgumentDescription
--dry-runRead and report what would move; change nothing.
--functions-dir <FUNCTIONS_DIR>Functions source (default supabase/functions, else functions).
--only <ONLY>Import only these parts (auth, storage, functions, policies; comma separated).
--report <REPORT>Write the JSON report to this file.
--s3-endpoint <S3_ENDPOINT>Read objects through Supabase’s S3 endpoint (https://<ref>.supabase.co/storage/v1/s3) instead of the Storage API.
--s3-region <S3_REGION>Region of the S3 endpoint (Project settings → Storage).
--supabase-url <SUPABASE_URL>The Supabase project URL, https://<ref>.supabase.co (default: $SUPABASE_URL).

Organizations you belong to; use sets the default.

SubcommandWhat it does
zb orgs createCreate an organization (you become its owner)
zb orgs getShow one organization (default: the current one)
zb orgs listList organizations you are a member of
zb orgs useSave the default org in the config file

Create an organization (you become its owner).

zb orgs create [OPTIONS] --name <NAME>
ArgumentDescription
--name <NAME>Required.
--region <REGION>Default region for new instances.
--slug <SLUG>

Show one organization (default: the current one).

zb orgs get [OPTIONS] [ID]
ArgumentDescription
<ID>Resource id.

List organizations you are a member of.

zb orgs list [OPTIONS]

Save the default org in the config file.

zb orgs use [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.

Projects in the org; use sets the default.

SubcommandWhat it does
zb projects createCreate a project
zb projects deleteDelete an empty project
zb projects getShow one project
zb projects jwt-keysThe project’s JWT signing keys (public halves; private keys stay in the cell)
zb projects keysProject API keys: publishable (browsers, role anon) and secret (servers, role service_role)
zb projects listList projects in the org
zb projects showShow a project’s ref, endpoint and JWKS URL (default: the current project)
zb projects useSave the default project in the config file

Create a project.

zb projects create [OPTIONS] --name <NAME>
ArgumentDescription
--name <NAME>Required.
--slug <SLUG>
--team <TEAM>Owning team id.

Delete an empty project.

zb projects delete [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.

Show one project.

zb projects get [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.

The project’s JWT signing keys (public halves; private keys stay in the cell).

SubcommandWhat it does
zb projects jwt-keys listList the signing keys and the JWKS URL
zb projects jwt-keys rotateRotate the signing key: the old key keeps verifying, the one before it is retired

List the signing keys and the JWKS URL.

zb projects jwt-keys list [OPTIONS]

Rotate the signing key: the old key keeps verifying, the one before it is retired.

zb projects jwt-keys rotate [OPTIONS]

Project API keys: publishable (browsers, role anon) and secret (servers, role service_role).

SubcommandWhat it does
zb projects keys createCreate a project key; the key is printed once
zb projects keys listList the project’s active keys (the key itself is never shown again)
zb projects keys revokeRevoke a project key; requests with it are refused within seconds

Create a project key; the key is printed once.

zb projects keys create [OPTIONS] --name <NAME>
ArgumentDescription
--expires <EXPIRES>Expiry (RFC 3339; default: never).
--kind <KIND>publishable (safe in browsers) or secret (servers only, bypasses row-level security). One of publishable, secret. Default publishable.
--name <NAME>Name, e.g. web-app. Required.
--scope <SCOPE>Scopes recorded with the key (comma separated; default: *).

List the project’s active keys (the key itself is never shown again).

zb projects keys list [OPTIONS]

Revoke a project key; requests with it are refused within seconds.

zb projects keys revoke [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.

List projects in the org.

zb projects list [OPTIONS]

Show a project’s ref, endpoint and JWKS URL (default: the current project).

zb projects show [OPTIONS] [ID]
ArgumentDescription
<ID>Resource id.

Save the default project in the config file.

zb projects use [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.

Project realtime: broadcast, presence and database changes over WebSockets, database webhooks.

SubcommandWhat it does
zb realtime disableDisable realtime (connections close, the replication slot is dropped)
zb realtime enableEnable realtime on the project (/realtime/v1)
zb realtime publishSet the tables whose changes reach postgres_changes subscribers (none = publish nothing)
zb realtime showShow realtime settings, the limits in force and the WebSocket URL
zb realtime webhooksDatabase webhooks: POST table changes to a URL or a project function

Disable realtime (connections close, the replication slot is dropped).

zb realtime disable [OPTIONS]

Enable realtime on the project (/realtime/v1).

zb realtime enable [OPTIONS]
ArgumentDescription
--private-onlyRefuse public channels (RLS on realtime.messages decides).

Set the tables whose changes reach postgres_changes subscribers (none = publish nothing).

zb realtime publish [OPTIONS]
ArgumentDescription
--events <EVENTS>Events: INSERT, UPDATE, DELETE or *. Default [*].

Show realtime settings, the limits in force and the WebSocket URL.

zb realtime show [OPTIONS]

Database webhooks: POST table changes to a URL or a project function.

SubcommandWhat it does
zb realtime webhooks createCreate a webhook; the signing secret is printed once
zb realtime webhooks deleteDelete a webhook (queued deliveries are dead-lettered)
zb realtime webhooks deliveriesRecent deliveries of a webhook (—dead for the dead letters)
zb realtime webhooks listList the project’s database webhooks
zb realtime webhooks replayQueue a failed or dead-lettered delivery again

Create a webhook; the signing secret is printed once.

zb realtime webhooks create [OPTIONS] --name <NAME> --table <TABLE>
ArgumentDescription
--events <EVENTS>INSERT, UPDATE, DELETE or *. Default [INSERT].
--function <FUNCTION>Project function to call instead of a URL.
--name <NAME>Name. Required.
--table <TABLE>Table (schema.table; public when no schema). Required.
--url <URL>HTTPS URL to POST to.

Delete a webhook (queued deliveries are dead-lettered).

zb realtime webhooks delete [OPTIONS]

Recent deliveries of a webhook (—dead for the dead letters).

zb realtime webhooks deliveries [OPTIONS]
ArgumentDescription
--deadOnly dead-lettered deliveries.

List the project’s database webhooks.

zb realtime webhooks list [OPTIONS]

Queue a failed or dead-lettered delivery again.

zb realtime webhooks replay [OPTIONS]

Sandboxes: short-lived isolated containers to run code in (exec, files, snapshots).

SubcommandWhat it does
zb sandbox cpCopy a file into a sandbox (zb sandbox cp ./data.csv sbx_...:data.csv) or out of it (zb sandbox cp sbx_...:out.png .)
zb sandbox createCreate a sandbox; prints its id (no network unless —egress allows it)
zb sandbox deleteStop a sandbox and remove it from the list
zb sandbox execRun a command (-- python3 main.py) or code (--code file.py) in a sandbox; streams its output and exits with its code
zb sandbox getShow a sandbox: status, template, size, egress, timeouts and price
zb sandbox killStop a sandbox now (its files are gone unless snapshotted)
zb sandbox listList the project’s sandboxes (running ones; —all includes ended ones)
zb sandbox lsList a directory of a sandbox (default /workspace)
zb sandbox snapshotSnapshot a sandbox’s /workspace (restore with zb sandbox create --from-snapshot)

Copy a file into a sandbox (zb sandbox cp ./data.csv sbx_...:data.csv) or out of it (zb sandbox cp sbx_...:out.png .).

zb sandbox cp [OPTIONS] <SRC> <DST>
ArgumentDescription
<SRC>Local file (- = stdin) or SANDBOX:PATH.
<DST>SANDBOX:PATH or a local file / directory (- = stdout).

Create a sandbox; prints its id (no network unless —egress allows it).

zb sandbox create [OPTIONS]
ArgumentDescription
--allow <ALLOW>Allowlist rule (host[:ports] or public CIDR[:ports]); implies —egress allowlist (repeat it).
--egress <EGRESS>Network: none (default), internet or allowlist. One of none, internet, allowlist.
--env <KEY=VALUE>Environment variable KEY=VALUE (repeat it).
--from-snapshot <FROM_SNAPSHOT>Restore /workspace from a snapshot (snap_…).
--idle-timeout <SECONDS>Stop after this many seconds without exec (default 120).
--name <NAME>Optional label.
--secret <ENV=SECRET@HOSTS>Cloaked project secret ENV=SECRET@host[,host]: the sandbox sees a placeholder, the proxy adds the value for those hosts only.
--size <SIZE>Size: x1 (default), x2 or x4.
--template <TEMPLATE>Template: python (default), node or base.
--timeout <SECONDS>Hard lifetime in seconds (default 300; 0 with —idle-timeout = until idle).

Stop a sandbox and remove it from the list.

zb sandbox delete [OPTIONS] <ID>
ArgumentDescription
<ID>Sandbox id (sbx_…).

Run a command (-- python3 main.py) or code (--code file.py) in a sandbox; streams its output and exits with its code.

zb sandbox exec [OPTIONS] <ID> [-- <COMMAND>...]
ArgumentDescription
<ID>Sandbox id (sbx_…).
--code <FILE>Run this file (- = stdin) with —language instead of a command.
--cwd <CWD>Working directory (default /workspace).
--env <KEY=VALUE>Variable for this run KEY=VALUE (repeat it).
--language <LANGUAGE>Interpreter of —code: python (default), node or bash. One of python, node, bash.
--stdin <FILE>Send this file (- = this terminal’s stdin) as the command’s standard input.
--timeout <SECONDS>Kill the run after this many seconds (default 60).
-- <COMMAND>...The command and its arguments after -- (an argv: no shell unless you run sh -c).

Show a sandbox: status, template, size, egress, timeouts and price.

zb sandbox get [OPTIONS] <ID>
ArgumentDescription
<ID>Sandbox id (sbx_…).

Stop a sandbox now (its files are gone unless snapshotted).

zb sandbox kill [OPTIONS] <ID>
ArgumentDescription
<ID>Sandbox id (sbx_…).

List the project’s sandboxes (running ones; —all includes ended ones).

zb sandbox list [OPTIONS]
ArgumentDescription
--allInclude stopped, killed and expired sandboxes.

List a directory of a sandbox (default /workspace).

zb sandbox ls [OPTIONS] <ID> [PATH]
ArgumentDescription
<ID>Sandbox id (sbx_…).
<PATH>Directory (default /workspace).

Snapshot a sandbox’s /workspace (restore with zb sandbox create --from-snapshot).

zb sandbox snapshot [OPTIONS] <ID>
ArgumentDescription
<ID>Sandbox id (sbx_…).
--retention-days <RETENTION_DAYS>Keep the snapshot this many days (default 7).

Function secrets of the project (names only are ever shown).

SubcommandWhat it does
zb secrets listList the secret names
zb secrets setSet secrets (NAME=VALUE, —env-file .env, —ref NAME=instance:<id>:app)
zb secrets unsetRemove secrets

List the secret names.

zb secrets list [OPTIONS]

Set secrets (NAME=VALUE, —env-file .env, —ref NAME=instance:<id>:app).

zb secrets set [OPTIONS] [NAME=VALUE...]
ArgumentDescription
<NAME=VALUE...>
--env-file <ENV_FILE>Read NAME=VALUE lines from a file.
--ref <REF>NAME=instance:<id>:app (repeatable).

Remove secrets.

zb secrets unset [OPTIONS]

SSH public keys on your account (workspace SSH through the bastion).

SubcommandWhat it does
zb ssh-key addRegister a public key (default: the first of ~/.ssh/id_ed25519.pub, id_ecdsa.pub, id_rsa.pub)
zb ssh-key listList the SSH keys on your account
zb ssh-key rmRemove an SSH key from your account; new sessions with it are refused

Register a public key (default: the first of ~/.ssh/id_ed25519.pub, id_ecdsa.pub, id_rsa.pub).

zb ssh-key add [OPTIONS] [PATH]
ArgumentDescription
<PATH>Public key file (.pub); private keys are refused.
--name <NAME>Label (default: the key’s comment, else the file name).

List the SSH keys on your account.

zb ssh-key list [OPTIONS]

Remove an SSH key from your account; new sessions with it are refused.

zb ssh-key rm [OPTIONS] <KEY>
ArgumentDescription
<KEY>Key id, name or fingerprint (SHA256:…).

Project storage: buckets, files (ss:///bucket/path), signed transfers and S3 credentials.

SubcommandWhat it does
zb storage bucketsCreate, list, change and delete buckets
zb storage cpCopy files: local -> ss:///bucket/path (upload), ss:// -> local (download), ss:// -> ss:// (server side)
zb storage disableTurn storage off (files stay; /storage/v1 answers 404)
zb storage enableTurn storage on for the project (/storage/v1 on the project endpoint)
zb storage lsList buckets, or the files of a bucket folder
zb storage mvMove or rename an object (ss:///bucket/a ss:///bucket/b; across buckets too)
zb storage rmDelete objects (with -r every object under a prefix)
zb storage s3-credentialsPrint the S3 access key of a project secret key (aws, rclone, Cyberduck)
zb storage settingsShow the project’s storage settings, limits and URLs

Create, list, change and delete buckets.

SubcommandWhat it does
zb storage buckets createCreate a bucket (private unless —public)
zb storage buckets deleteDelete an empty bucket
zb storage buckets emptyDelete every file of a bucket
zb storage buckets listList the project’s buckets
zb storage buckets updateChange a bucket (flags given replace the stored values)

Create a bucket (private unless —public).

zb storage buckets create [OPTIONS]
ArgumentDescription
--allowed-mime <ALLOWED_MIME>Allowed MIME types, e.g. image/*,application/pdf (update: "" clears them).
--file-size-limit <FILE_SIZE_LIMIT>Largest file, e.g. 5MB (update: 0 clears it).
--publicFiles are readable without a key at the public URL.
--versioningKeep prior versions of overwritten and deleted files (paid plans).

Delete an empty bucket.

zb storage buckets delete [OPTIONS]

Delete every file of a bucket.

zb storage buckets empty [OPTIONS]

List the project’s buckets.

zb storage buckets list [OPTIONS]

Change a bucket (flags given replace the stored values).

zb storage buckets update [OPTIONS]
ArgumentDescription
--allowed-mime <ALLOWED_MIME>Allowed MIME types, e.g. image/*,application/pdf (update: "" clears them).
--file-size-limit <FILE_SIZE_LIMIT>Largest file, e.g. 5MB (update: 0 clears it).
--privateMake the bucket private.
--publicFiles are readable without a key at the public URL.
--versioningKeep prior versions of overwritten and deleted files (paid plans).

Copy files: local -> ss:///bucket/path (upload), ss:// -> local (download), ss:// -> ss:// (server side).

zb storage cp [OPTIONS]
ArgumentDescription
-r, --recursiveCopy a directory or a prefix.

Turn storage off (files stay; /storage/v1 answers 404).

zb storage disable [OPTIONS]

Turn storage on for the project (/storage/v1 on the project endpoint).

zb storage enable [OPTIONS]
ArgumentDescription
--no-s3Keep the S3 protocol off.

List buckets, or the files of a bucket folder.

zb storage ls [OPTIONS] [ss:///bucket[/prefix]
ArgumentDescription
<ss:///bucket[/prefix>
-r, --recursiveList every file under the prefix.

Move or rename an object (ss:///bucket/a ss:///bucket/b; across buckets too).

zb storage mv [OPTIONS]

Delete objects (with -r every object under a prefix).

zb storage rm [OPTIONS]
ArgumentDescription
-r, --recursiveDelete every object under the prefix.

Print the S3 access key of a project secret key (aws, rclone, Cyberduck).

zb storage s3-credentials [OPTIONS]
ArgumentDescription
--secret-key <SECRET_KEY>Project secret key (env ZB_PROJECT_SECRET_KEY).

Show the project’s storage settings, limits and URLs.

zb storage settings [OPTIONS]

Teams, their members and budgets.

SubcommandWhat it does
zb teams add-memberAdd a member to a team (or change their role)
zb teams budgetShow a team’s budget and month-to-date spend
zb teams createCreate a team
zb teams deleteDelete a team
zb teams getShow one team
zb teams listList teams
zb teams membersList a team’s members
zb teams remove-memberRemove a member from a team

Add a member to a team (or change their role).

zb teams add-member [OPTIONS] <TEAM> <USER>
ArgumentDescription
<TEAM>Team id.
<USER>User id.
--role <ROLE>admin, operator or viewer. Default operator.

Show a team’s budget and month-to-date spend.

zb teams budget [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.

Create a team.

zb teams create [OPTIONS] --name <NAME>
ArgumentDescription
--budget-cents <BUDGET_CENTS>Monthly budget in USD cents.
--cost-centre <COST_CENTRE>
--name <NAME>Required.
--slug <SLUG>

Delete a team.

zb teams delete [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.

Show one team.

zb teams get [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.

List teams.

zb teams list [OPTIONS]

List a team’s members.

zb teams members [OPTIONS] <ID>
ArgumentDescription
<ID>Resource id.

Remove a member from a team.

zb teams remove-member [OPTIONS] <TEAM> <USER>
ArgumentDescription
<TEAM>Team id.
<USER>User id.

Usage and list-price cost for the current month (or —from/—to), grouped.

zb usage [OPTIONS]
ArgumentDescription
--by <BY>Grouping. One of team, cost-centre, instance, metric. Default team.
--csvPrint CSV.
--from <FROM>Start (RFC 3339); default: start of the current month.
--to <TO>End (RFC 3339, exclusive); default: now.

Cloud dev workspaces: create, start, stop, and connect over SSH (VS Code / Cursor Remote-SSH).

SubcommandWhat it does
zb ws allowanceHow many workspaces each member may own (owners and admins): list, set, reset to the plan default
zb ws codeOpen a running workspace in VS Code, Cursor or Zed over SSH (writes its Host block to ~/.ssh/config first)
zb ws createCreate a workspace (attach it to a project with the global —project <id|slug>); prints its ssh command, or the approval request when a team policy needs one
zb ws deleteDelete a workspace and its home volume. Irreversible; asks first unless —yes
zb ws exportExport a running workspace’s home directory as .tar.gz into a bucket of its project (another project’s bucket with the global —project)
zb ws exportsList exports of a workspace’s home directory
zb ws getShow one workspace: status, size, idle stop, estimate and its ssh command
zb ws instructionsA project’s shared agent instructions (AGENTS.md / CLAUDE.md synced into every repository of its workspaces; the global —project <id|slug>)
zb ws listList your workspaces (—all: every workspace in the org you can see)
zb ws logsPrint the workspace container’s log (entrypoint, zb-wsd, dockerd); -f follows it until Ctrl-C
zb ws port-forwardForward local ports to a running workspace through the bastion (3000, 8080:3000; repeat for more) until Ctrl-C
zb ws restoreCreate a new workspace from a snapshot (size and disk default to the snapshot’s; the global —project attaches it)
zb ws revoke-sessionsClose every open SSH and web-terminal session of a workspace now (a lost laptop, a leaked key); asks first unless —yes
zb ws seatsWorkspace hours per member this month (or —from/—to): live workspaces, allowance and usage (Team seat report)
zb ws sessionsList the open SSH, web-terminal and port-forward sessions of a workspace (—all: the last 7 days)
zb ws snapshotSnapshots of a workspace’s home volume: take one now, list, delete (restore with zb ws restore)
zb ws sshOpen an SSH session to a running workspace through the bastion (the system ssh, with the keys from zb ssh-key add)
zb ws ssh-configPrint the workspace’s Host block for ~/.ssh/config, or keep it there with —write (VS Code / Cursor Remote-SSH, Zed, scp, rsync)
zb ws startStart a stopped workspace (the home volume is kept across stops)
zb ws stopStop a workspace: compute stops billing, the home volume is kept
zb ws updateChange a workspace: name, idle stop, disk (grow only), repositories, agents, or its project (the global —project <id|slug>, —detach-project)
zb ws usageCompute, disk and snapshot usage and cost of one workspace this month (or —from/—to)

How many workspaces each member may own (owners and admins): list, set, reset to the plan default.

SubcommandWhat it does
zb ws allowance listList per-member workspace allowances and the plan default
zb ws allowance resetRemove a member’s allowance override (back to the plan default)
zb ws allowance setSet how many workspaces a member may own (0..100, or unlimited)

List per-member workspace allowances and the plan default.

zb ws allowance list [OPTIONS]

Remove a member’s allowance override (back to the plan default).

zb ws allowance reset [OPTIONS] <USER_ID>
ArgumentDescription
<USER_ID>Member’s user id (usr_…; zb members list).

Set how many workspaces a member may own (0..100, or unlimited).

zb ws allowance set [OPTIONS] <USER_ID> <MAX>
ArgumentDescription
<USER_ID>Member’s user id (usr_…; zb members list).
<MAX>Workspaces the member may own: 0..100 or unlimited.

Open a running workspace in VS Code, Cursor or Zed over SSH (writes its Host block to ~/.ssh/config first).

zb ws code [OPTIONS] <WORKSPACE>
ArgumentDescription
<WORKSPACE>Workspace name or id (ws_…).
--editor <EDITOR>Editor to open. One of code, cursor, zed. Default code.
--path <PATH>Folder to open (default: /home/dev, or /home/dev/dev/<repo> with exactly one repo).
--printPrint the command instead of running it (writes nothing).
--ssh-config <FILE>SSH config file for the Host block (default: ~/.ssh/config).

Create a workspace (attach it to a project with the global —project <id|slug>); prints its ssh command, or the approval request when a team policy needs one.

zb ws create [OPTIONS] --size <SIZE> <NAME>
ArgumentDescription
<NAME>Workspace name: lower-case letters, digits and -, unique in the org.
--agent <AGENT>Agent to install at first start (claude-code, codex, opencode, gemini, cursor, devin, grok; repeat or comma separate).
--disk-gb <DISK_GB>Home volume in GiB (default: the size’s included disk).
--idle-stop-minutes <IDLE_STOP_MINUTES>Stop after this many idle minutes (default 120; 0 = never).
--owner <OWNER>Member who owns it (user id; admins only, required with an API key; default: you).
--placement <PLACEMENT>shared (default) or secure: the org’s dedicated nodes on a HIPAA cell (needs a signed BAA). One of shared, secure.
--region <REGION>Region (default: the org’s default region).
--repo <OWNER/NAME>GitHub repository to clone under ~/dev (owner/name; repeat or comma separate).
--restore <SNAPSHOT_ID>Restore the home volume from this snapshot (wss_…; zb ws snapshot list).
--size <SIZE>Workspace size (w1, w2, w3; zb api GET /v1/sizes lists them). Required.
--timeout <TIMEOUT>Give up waiting after this many seconds (with —wait). Default 900.
--waitWait until the workspace is running (or failed).

Delete a workspace and its home volume. Irreversible; asks first unless —yes.

zb ws delete [OPTIONS] <WORKSPACE>
ArgumentDescription
<WORKSPACE>Workspace name or id (ws_…).

Export a running workspace’s home directory as .tar.gz into a bucket of its project (another project’s bucket with the global —project).

zb ws export [OPTIONS] --bucket <BUCKET> <WORKSPACE>
ArgumentDescription
<WORKSPACE>Workspace name or id (ws_…).
--bucket <BUCKET>Bucket of the workspace’s project. Required.
--key <KEY>Object key (default: workspaces/<name>/<timestamp>.tar.gz).

List exports of a workspace’s home directory.

zb ws exports [OPTIONS] <WORKSPACE>
ArgumentDescription
<WORKSPACE>Workspace name or id (ws_…).

Show one workspace: status, size, idle stop, estimate and its ssh command.

zb ws get [OPTIONS] <WORKSPACE>
ArgumentDescription
<WORKSPACE>Workspace name or id (ws_…).

A project’s shared agent instructions (AGENTS.md / CLAUDE.md synced into every repository of its workspaces; the global —project <id|slug>).

SubcommandWhat it does
zb ws instructions getPrint the project’s agent instructions (Markdown)
zb ws instructions setReplace the project’s agent instructions from a Markdown file (or - for stdin; an empty file removes them)

Print the project’s agent instructions (Markdown).

zb ws instructions get [OPTIONS]

Replace the project’s agent instructions from a Markdown file (or - for stdin; an empty file removes them).

zb ws instructions set [OPTIONS] --file <PATH>
ArgumentDescription
--file <PATH>Markdown file to upload, or - to read stdin (at most 64 KiB). Required.

List your workspaces (—all: every workspace in the org you can see).

zb ws list [OPTIONS]
ArgumentDescription
--allList every workspace in the org, not only yours.

Print the workspace container’s log (entrypoint, zb-wsd, dockerd); -f follows it until Ctrl-C.

zb ws logs [OPTIONS] <WORKSPACE>
ArgumentDescription
<WORKSPACE>Workspace name or id (ws_…).
-f, --followKeep streaming new lines until Ctrl-C.
--previousThe previous container’s log (after a restart or crash).
--tail <N>Lines from the end of the log to start with. Default 200.

Forward local ports to a running workspace through the bastion (3000, 8080:3000; repeat for more) until Ctrl-C.

zb ws port-forward [OPTIONS] <WORKSPACE> <PORT>
ArgumentDescription
<WORKSPACE>Workspace name or id (ws_…).
<PORT>PORT (same port both ends) or LOCAL_PORT:REMOTE_PORT; repeat for more.
--bind <ADDR>Local address to listen on. Default 127.0.0.1.
--printPrint the ssh command instead of running it.

Create a new workspace from a snapshot (size and disk default to the snapshot’s; the global —project attaches it).

zb ws restore [OPTIONS] <SNAPSHOT_ID> <NEW_NAME>
ArgumentDescription
<SNAPSHOT_ID>Snapshot id (wss_…; zb ws snapshot list).
<NEW_NAME>Name of the new workspace.
--disk-gb <DISK_GB>Home volume in GiB, at least the snapshot’s (default: the snapshot’s).
--region <REGION>Region (default: the org’s default region).
--size <SIZE>Workspace size (default: the snapshot’s).
--timeout <TIMEOUT>Give up waiting after this many seconds (with —wait). Default 900.
--waitWait until the workspace is running (or failed).

Close every open SSH and web-terminal session of a workspace now (a lost laptop, a leaked key); asks first unless —yes.

zb ws revoke-sessions [OPTIONS] <WORKSPACE>
ArgumentDescription
<WORKSPACE>Workspace name or id (ws_…).

Workspace hours per member this month (or —from/—to): live workspaces, allowance and usage (Team seat report).

zb ws seats [OPTIONS]
ArgumentDescription
--from <FROM>Window start (YYYY-MM-DD or RFC 3339; default: the start of the month, UTC).
--to <TO>Window end (YYYY-MM-DD or RFC 3339; default: now).

List the open SSH, web-terminal and port-forward sessions of a workspace (—all: the last 7 days).

zb ws sessions [OPTIONS] <WORKSPACE>
ArgumentDescription
<WORKSPACE>Workspace name or id (ws_…).
--allInclude ended and revoked sessions of the last 7 days.

Snapshots of a workspace’s home volume: take one now, list, delete (restore with zb ws restore).

SubcommandWhat it does
zb ws snapshot createSnapshot a workspace’s home volume now (paid plans)
zb ws snapshot deleteDelete a snapshot (also a retained one). Irreversible; asks first unless —yes
zb ws snapshot listList snapshots of one workspace, or of every workspace in the org

Snapshot a workspace’s home volume now (paid plans).

zb ws snapshot create [OPTIONS] <WORKSPACE>
ArgumentDescription
<WORKSPACE>Workspace name or id (ws_…).
--timeout <TIMEOUT>Give up waiting after this many seconds (with —wait). Default 1800.
--waitWait until the snapshot is ready (or failed).

Delete a snapshot (also a retained one). Irreversible; asks first unless —yes.

zb ws snapshot delete [OPTIONS] <SNAPSHOT_ID>
ArgumentDescription
<SNAPSHOT_ID>Snapshot id (wss_…).

List snapshots of one workspace, or of every workspace in the org.

zb ws snapshot list [OPTIONS] [WORKSPACE]
ArgumentDescription
<WORKSPACE>Workspace name or id (ws_…); omit for the whole org.

Open an SSH session to a running workspace through the bastion (the system ssh, with the keys from zb ssh-key add).

zb ws ssh [OPTIONS] <WORKSPACE> [-- <ARGS>...]
ArgumentDescription
<WORKSPACE>Workspace name or id (ws_…).
--printPrint the ssh command instead of running it.
-- <ARGS>...Extra ssh arguments or a remote command, after --.

Print the workspace’s Host block for ~/.ssh/config, or keep it there with —write (VS Code / Cursor Remote-SSH, Zed, scp, rsync).

zb ws ssh-config [OPTIONS] <WORKSPACE>
ArgumentDescription
<WORKSPACE>Workspace name or id (ws_…).
--alias <NAME>Host alias to use instead of zb-<name>.
--file <PATH>SSH config file to write (default: ~/.ssh/config, on Windows %USERPROFILE%.ssh\config).
--removeRemove the workspace’s managed block from the SSH config.
--writeAdd or update a managed block for the workspace in ~/.ssh/config (idempotent).

Start a stopped workspace (the home volume is kept across stops).

zb ws start [OPTIONS] <WORKSPACE>
ArgumentDescription
<WORKSPACE>Workspace name or id (ws_…).
--timeout <TIMEOUT>Give up waiting after this many seconds (with —wait). Default 600.
--waitWait until the workspace is running (or failed).

Stop a workspace: compute stops billing, the home volume is kept.

zb ws stop [OPTIONS] <WORKSPACE>
ArgumentDescription
<WORKSPACE>Workspace name or id (ws_…).
--timeout <TIMEOUT>Give up waiting after this many seconds (with —wait). Default 600.
--waitWait until the workspace is stopped (or failed).

Change a workspace: name, idle stop, disk (grow only), repositories, agents, or its project (the global —project <id|slug>, —detach-project).

zb ws update [OPTIONS] <WORKSPACE>
ArgumentDescription
<WORKSPACE>Workspace name or id (ws_…).
--agent <AGENT>Replace the agents installed at start (repeat or comma separate; —agent "" clears).
--detach-projectDetach the workspace from its project.
--disk-gb <DISK_GB>Grow the home volume to this many GiB (never shrinks).
--idle-stop-minutes <IDLE_STOP_MINUTES>Stop after this many idle minutes (0 = never).
--name <NAME>New name (the ssh-config alias zb-<name> changes with it).
--repo <OWNER/NAME>Replace the GitHub repositories (owner/name; repeat or comma separate; —repo "" clears).

Compute, disk and snapshot usage and cost of one workspace this month (or —from/—to).

zb ws usage [OPTIONS] <WORKSPACE>
ArgumentDescription
<WORKSPACE>Workspace name or id (ws_…).
--from <FROM>Window start (YYYY-MM-DD or RFC 3339; default: the start of the month, UTC).
--to <TO>Window end (YYYY-MM-DD or RFC 3339; default: now).