> ## Documentation Index
> Fetch the complete documentation index at: https://helix-isolate-failing-index-entities.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# helix database

> Discover and manage Helix Cloud databases and application keys

<div className="flex flex-wrap gap-2"><Badge color="gray" size="sm">Reference</Badge></div>

List, inspect, create, and delete Helix Cloud databases, list their active indexes, and manage the
application keys your software uses to reach them. Cloud only.

## Usage

```bash theme={null}
helix database [list] [--workspace <workspace>] [--project <project>]
helix database get [DATABASE]
helix database indexes [DATABASE]
helix database create <NAME> [--slug <slug>] [--plan <plan> | --cluster <cluster>]
helix database delete [DATABASE] [--yes]

helix database key create --access read-only|read-write [--name <name>] [--database <database>]
helix database key list [--database <database>]
helix database key revoke <KEY> [--database <database>] [--yes]
```

Every subcommand also accepts `--workspace` and `--project`.

## Subcommands

| Subcommand | Description |
| - | - |
| `list` | List the dedicated-cluster and tenant databases in a project. The default when no subcommand is given. |
| `get` | Show one database. |
| `indexes` | List the database's active indexes. Alias: `indices`. |
| `create` | Create a tenant database and print its default read-write application key once. |
| `delete` | Delete a tenant database. |
| `key create` | Create an application key and print its token once. |
| `key list` | List application keys. Tokens are never returned. |
| `key revoke` | Revoke an application key. |

## Arguments

| Argument | Description |
| - | - |
| `DATABASE` | Database ID, slug, or name, or `tenant:<id>` / `cluster:<id>`. Defaults to the one database linked in `helix.toml`, then the project's only database. `delete` accepts tenants only. |
| `NAME` | `create`: database display name. Required. |
| `KEY` | `key revoke`: key ID or name. Required. |

## Options

| Flag | Description | Default |
| - | - | - |
| `--workspace <WORKSPACE>` | Workspace ID, slug, or name to search in. | Linked workspace, then the only workspace |
| `--project <PROJECT>` | Project ID, slug, or name that owns the database. | Project linked in `helix.toml` |
| `--database <DATABASE>` | `key create`, `key list`, `key revoke`: the database, in the same forms as `DATABASE`. | Same as `DATABASE` |
| `--slug <SLUG>` | `create`: URL-safe database slug. | Derived from `NAME` |
| `--plan <PLAN>` | `create`: plan code for a shared tenant database. Not allowed with `--cluster`. | Prompted in a terminal; required otherwise |
| `--cluster <CLUSTER>` | `create`: dedicated cluster ID, slug, or name to create the tenant on. | — |
| `--access <ACCESS>` | `key create`: `read-only` or `read-write`. Required. | — |
| `--name <NAME>` | `key create`: optional key name. | — |
| `-y`, `--yes` | `delete`, `key revoke`: skip the confirmation prompt. Required without a terminal or with `--json`. | Off |
| `--json` | Print the result as JSON on stdout and never prompt. | Off |

## Behavior

* Arguments and defaults resolve as described in [Cloud resource resolution](/cli/command-reference#cloud-resource-resolution). When `helix.toml` links several databases, the CLI picks among them in a terminal.
* `list` includes dedicated clusters and tenants in the project and marks linked databases; shared clusters are not listed.
* `create` always creates a tenant database, either on a shared plan (`--plan`) or inside a dedicated cluster (`--cluster`).
* Creating a database creates a default read-write application key and prints its raw token once on stdout. With `--json`, the full create response, including the token, is printed instead. The session-authenticated CLI never stores or uses the key.
* Additional key creation is explicit, and each new raw token is also printed once. `key create` prints only the token on stdout, so you can capture it in a script.
* Application keys are for software that calls the gateway (the Cloud database endpoint your application connects to) directly.
* `delete` and `key revoke` ask for confirmation in a terminal. Without one, or with `--json`, they fail before any request unless you pass `--yes`. `delete` removes the named or linked database only; it never picks a project's only database on its own.
* `delete` removes tenant databases only. Dedicated-cluster create/delete lifecycle is not supported by this CLI.

## Examples

```bash theme={null}
# List databases in the linked project
helix database

# Create a tenant database on a shared plan
helix database create orders --plan <plan>

# Create a read-only application key for the linked database and save the token
helix database key create --access read-only --name reporting > reporting.key

# Revoke a key by name without a prompt
helix database key revoke reporting --database orders --yes
```

## Related

* [`helix cluster`](/cli/command-reference/cluster) — inspect dedicated clusters.
* [`helix project`](/cli/command-reference/project) — find the owning project.
* [`helix query`](/cli/command-reference/query) — query a database with your login session.
* [Helix Cloud workflow](/cli/workflows/helix_cloud) — end-to-end Cloud usage.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.