Reference

Command reference

Every `si` command with its arguments and flags. Generated from the command line's source.

Run si help <command> for the same text in your terminal. Options that work with every command (--json, --org, --project, --yes, --cwd, --no-color) are listed under Command line.

si login

Sign in with your browser.

si login [options]
FlagNotes
--no-browserPrint the link instead of opening the browser
--step-upConfirm with a passkey or two-step sign-in, so a git key can be created in the next 10 minutes

si logout

Sign out on this machine and remove its git keys.

si logout

si whoami

Show who you're signed in as.

si whoami

si orgs

List your organizations.

si orgs

si switch

Change the current organization.

si switch <org>
ArgumentNotes
orgOrganization slug

si init

Create a Serverless App Service and repository from this folder, push and deploy.

si init [name] [options]
ArgumentNotes
nameServerless App Service name (default: the folder's name) Optional.
FlagNotes
-t, --template <nextjs|static>Start from a template (the folder must be empty)
--framework <nextjs|static|node>Framework preset (default: detected)
--root <dir>Root directory of the app inside the repository
--no-waitDon't wait for the first deployment

Link this folder to an existing Serverless App Service.

si link [project]
ArgumentNotes
projectServerless App Service slug (asks when omitted) Optional.

Remove this folder's Serverless App Service link.

si unlink

si clone

Clone a Serverless App Service's repository and link it.

si clone <project> [dir]
ArgumentNotes
projectServerless App Service slug
dirDirectory (default: the repository's name) Optional.

si deploy

Deploy the current branch, or upload the working tree.

In a clean checkout of the Serverless App Service's repository, pushes the current branch and follows its build.

Otherwise (no repository, uncommitted changes, or --upload) uploads the working tree as an archive.

Pushing the production branch deploys production; uploads are previews unless --prod.

si deploy [options]
FlagNotes
--prodDeploy to production
--uploadUpload the working tree even in a clean checkout
--forceBuild again even if this commit (or these uploaded files) was already deployed
--no-waitPrint the deployment and return without following the build

si deployments

List the Serverless App Service's deployments.

si deployments [options]

Also: si ls.

FlagNotes
--target <production|preview>Only production or preview deployments
--branch <value>Only this branch
-n, --limit <n>How many (default 20, at most 100)

si promote

Make a ready deployment production, without rebuilding.

si promote <deployment>
ArgumentNotes
deploymentDeployment id, its last 8 characters, or its URL

si rollback

Point production back at an earlier deployment.

si rollback [deployment]
ArgumentNotes
deploymentDeployment (default: the production deployment before the current one) Optional.

si redeploy

Build a deployment's source again.

si redeploy <deployment> [options]
ArgumentNotes
deploymentDeployment id, its last 8 characters, or its URL
FlagNotes
--no-waitDon't follow the build

si logs

Show runtime logs (or build logs) of a deployment.

si logs [deployment] [options]
ArgumentNotes
deploymentDeployment (default: production) Optional.
FlagNotes
-f, --followKeep printing new lines
-q, --query <text>Only lines containing this text (case-insensitive)
--level <error|warn|info|debug>Only lines at this level or above
--since <duration>Start this long ago, e.g. 30s, 10m, 1h (at most 1h)
--buildShow the build output instead

si env ls

List variables.

si env ls [options]

Also: si env list.

FlagNotes
-e, --environment <production|preview|development>Only variables for this environment

si env add

Add or replace a variable (the value is read from stdin when omitted).

si env add <key> [value] [options]

Also: si env set.

ArgumentNotes
keyVariable name
valueValue Optional.
FlagNotes
-e, --environment <production|preview|development>Environments (repeatable; default: all three) Repeatable.
--plainNot sensitive: the value can be read back (and pulled)
--dev-readableA development-only secret developers can read back (env pull, dev); implies -e development

si env rm

Remove a variable.

si env rm <key>

Also: si env remove.

ArgumentNotes
keyVariable name

si env pull

Write variables to a .env file (sensitive values are left out, except development secrets readable by developers).

si env pull [file] [options]
ArgumentNotes
fileFile (default: .env.local) Optional.
FlagNotes
-e, --environment <production|preview|development>Environment (default: development)

si env push

Add every variable in a .env file.

si env push [file] [options]
ArgumentNotes
fileFile (default: .env) Optional.
FlagNotes
-e, --environment <production|preview|development>Environments (repeatable; default: all three) Repeatable.
--plainNot sensitive: values can be read back

si secrets ls

List secrets (the Serverless App Service's and shared ones; never values).

si secrets ls [options]

Also: si secrets list.

FlagNotes
-e, --environment <production|preview|development>Only secrets for this environment

si secrets set

Set a secret: a new version (the value is read from stdin when omitted).

si secrets set <key> [value] [options]

Also: si secrets add.

ArgumentNotes
keySecret name
valueValue Optional.
FlagNotes
-e, --environment <production|preview|development>Environments (repeatable; default: all three) Repeatable.
--rotate-every <days>Remind owners and admins to rotate it after this many days

si secrets get

Print a secret's value, if its access rule lets you read it (audited).

si secrets get <key> [version]
ArgumentNotes
keySecret name
versionAn earlier version's number (secrets versions lists them) Optional.

si secrets versions

List a secret's kept versions.

si secrets versions <key>
ArgumentNotes
keySecret name

si secrets rm

Remove a secret and its versions.

si secrets rm <key>

Also: si secrets remove.

ArgumentNotes
keySecret name

si keys ls

List keys.

si keys ls

Also: si keys list.

si keys encrypt

Encrypt text (read from stdin when omitted) and print the ciphertext.

si keys encrypt <key> [text] [options]
ArgumentNotes
keyKey id or name
textText to encrypt Optional.
FlagNotes
-c, --context <name=value>Bind the ciphertext to name=value (repeatable; decrypting needs the same) Repeatable.
--base64The input is base64 (binary data)

si keys decrypt

Decrypt a ciphertext (read from stdin when omitted) and print the text.

si keys decrypt <key> [ciphertext] [options]
ArgumentNotes
keyKey id or name
ciphertextCiphertext (k1.…) Optional.
FlagNotes
-c, --context <name=value>The context it was encrypted with (repeatable) Repeatable.
--base64Print the plaintext as base64

si keys sign

Sign a message (read from stdin when omitted) and print the signature.

si keys sign <key> [message] [options]
ArgumentNotes
keyKey id or name
messageMessage Optional.
FlagNotes
--base64The message is base64 (binary data)

si keys verify

Check a signature (exit status 1 when it doesn't match).

si keys verify <key> <signature> [message] [options]
ArgumentNotes
keyKey id or name
signatureSignature (k1s.…)
messageMessage (read from stdin when omitted) Optional.
FlagNotes
--base64The message is base64 (binary data)

si domains ls

List the Serverless App Service's domains and their DNS records.

si domains ls

Also: si domains list.

si domains add

Add a domain to the Serverless App Service.

si domains add <hostname> [options]
ArgumentNotes
hostnamee.g. www.example.com
FlagNotes
--moveIt already serves a site: get the certificate first (one extra DNS record), then switch DNS without downtime

si domains verify

Check DNS and the certificate.

si domains verify <hostname>
ArgumentNotes
hostnameThe domain

si domains cloudflare

Create the DNS records with the organization's Cloudflare connection.

si domains cloudflare <hostname>
ArgumentNotes
hostnameThe domain

si domains rm

Remove a domain.

si domains rm <hostname>

Also: si domains remove.

ArgumentNotes
hostnameThe domain

si open

Open the production URL (or a deployment) in the browser.

si open [deployment] [options]
ArgumentNotes
deploymentDeployment to open instead Optional.
FlagNotes
--cloudOpen the Serverless App Service in Cloud instead

si dev

Run the dev server with the Serverless App Service's environment variables.

Runs the package.json dev script (or the command after --) with the Serverless App Service's variables in its environment.

Nothing is written to disk. Sensitive variables are left out, except development secrets readable by developers.

si dev [-- <command>...] [options]
FlagNotes
-e, --environment <production|preview|development>Environment to take variables from (default: production)

si runs ls

List runs, newest first.

si runs ls [options]

Also: si runs list.

FlagNotes
-R, --repo <org/name>Repository, org/name (default: this clone's)
-w, --workflow <file>Only this workflow's file, e.g. ci.yml
-b, --branch <value>Only this branch
-s, --status <queued|in_progress|waiting|completed|success|failure|cancelled|startup_failure>Only runs in this state
--event <push|pull_request|schedule|workflow_dispatch>Only runs started by this event
-n, --limit <n>How many (default 20, at most 100)

si runs view

Show a run: its jobs, reviews waiting, annotations and artifacts.

si runs view <run> [options]
ArgumentNotes
runRun number
FlagNotes
-R, --repo <org/name>Repository, org/name (default: this clone's)
--attempt <n>An earlier attempt
--webOpen it in the browser

si runs logs

Print a job's log (the failed job's by default).

si runs logs <run> [job] [options]
ArgumentNotes
runRun number
jobJob name or id Optional.
FlagNotes
-R, --repo <org/name>Repository, org/name (default: this clone's)
-f, --followKeep printing until the job ends

si runs rerun

Run a finished run again as a new attempt.

si runs rerun <run> [options]
ArgumentNotes
runRun number
FlagNotes
-R, --repo <org/name>Repository, org/name (default: this clone's)
--failedOnly the failed jobs and what needs them
--job <key>Only this job (and what needs it)

si runs cancel

Cancel a run.

si runs cancel <run> [options]
ArgumentNotes
runRun number
FlagNotes
-R, --repo <org/name>Repository, org/name (default: this clone's)

si runs start

Run a workflow by hand (workflow_dispatch).

si runs start <workflow> [options]
ArgumentNotes
workflowWorkflow file, e.g. deploy.yml
FlagNotes
-R, --repo <org/name>Repository, org/name (default: this clone's)
--ref <value>Branch (default: the default branch)
-f, --field <name=value>An input, name=value (repeatable) Repeatable.

si mcp

Print the MCP server configuration for AI clients.

si mcp

si git setup

Use this CLI as git's credential helper for the git host.

si git setup [options]
FlagNotes
--removeRemove the helper again

si git promote

Fast-forward a protected branch to another branch (for pushes over 5 MB).

si git promote <branch> <from> [options]
ArgumentNotes
branchThe protected branch, e.g. main
fromThe branch whose tip it moves to
FlagNotes
-R, --repo <org/name>Repository, org/name (default: this clone's)

si git allow-secret

Allow findings a push was refused for, for an hour, when they aren't secrets.

si git allow-secret <repo> <fingerprint...> [options]
ArgumentNotes
repoRepository, org/name
fingerprintFingerprints the refused push printed
FlagNotes
--reason <text>Why these aren't secrets (required)

si upgrade

Update to the latest version.

si upgrade [options]
FlagNotes
--checkOnly check

si completion

Print a shell completion script.

bash: si completion bash >> ~/.bashrc

zsh: si completion zsh > "${fpath[1]}/_si"

fish: si completion fish > ~/.config/fish/completions/si.fish

PowerShell: si completion powershell >> $PROFILE

si completion <shell>
ArgumentNotes
shellbash, zsh, fish, powershell (bash, zsh, fish, powershell)

si version

Show the version.

si version

si help

Show help for a command.

si help [command...]
ArgumentNotes
commandCommand Optional.