Reference
Command reference
Every `si` command with its arguments and flags. Generated from the command line's source.
Run si help <command> for the same text in your terminal. Options that work with every command (--json, --org, --project, --yes, --cwd, --no-color) are listed under Command line.
si login
Sign in with your browser.
si login [options]| Flag | Notes |
|---|---|
--no-browser | Print the link instead of opening the browser |
--step-up | Confirm with a passkey or two-step sign-in, so a git key can be created in the next 10 minutes |
si logout
Sign out on this machine and remove its git keys.
si logoutsi whoami
Show who you're signed in as.
si whoamisi orgs
List your organizations.
si orgssi switch
Change the current organization.
si switch <org>| Argument | Notes |
|---|---|
org | Organization slug |
si init
Create a Serverless App Service and repository from this folder, push and deploy.
si init [name] [options]| Argument | Notes |
|---|---|
name | Serverless App Service name (default: the folder's name) Optional. |
| Flag | Notes |
|---|---|
-t, --template <nextjs|static> | Start from a template (the folder must be empty) |
--framework <nextjs|static|node> | Framework preset (default: detected) |
--root <dir> | Root directory of the app inside the repository |
--no-wait | Don't wait for the first deployment |
si link
Link this folder to an existing Serverless App Service.
si link [project]| Argument | Notes |
|---|---|
project | Serverless App Service slug (asks when omitted) Optional. |
si unlink
Remove this folder's Serverless App Service link.
si unlinksi clone
Clone a Serverless App Service's repository and link it.
si clone <project> [dir]| Argument | Notes |
|---|---|
project | Serverless App Service slug |
dir | Directory (default: the repository's name) Optional. |
si deploy
Deploy the current branch, or upload the working tree.
In a clean checkout of the Serverless App Service's repository, pushes the current branch and follows its build.
Otherwise (no repository, uncommitted changes, or --upload) uploads the working tree as an archive.
Pushing the production branch deploys production; uploads are previews unless --prod.
si deploy [options]| Flag | Notes |
|---|---|
--prod | Deploy to production |
--upload | Upload the working tree even in a clean checkout |
--force | Build again even if this commit (or these uploaded files) was already deployed |
--no-wait | Print the deployment and return without following the build |
si deployments
List the Serverless App Service's deployments.
si deployments [options]Also: si ls.
| Flag | Notes |
|---|---|
--target <production|preview> | Only production or preview deployments |
--branch <value> | Only this branch |
-n, --limit <n> | How many (default 20, at most 100) |
si promote
Make a ready deployment production, without rebuilding.
si promote <deployment>| Argument | Notes |
|---|---|
deployment | Deployment id, its last 8 characters, or its URL |
si rollback
Point production back at an earlier deployment.
si rollback [deployment]| Argument | Notes |
|---|---|
deployment | Deployment (default: the production deployment before the current one) Optional. |
si redeploy
Build a deployment's source again.
si redeploy <deployment> [options]| Argument | Notes |
|---|---|
deployment | Deployment id, its last 8 characters, or its URL |
| Flag | Notes |
|---|---|
--no-wait | Don't follow the build |
si logs
Show runtime logs (or build logs) of a deployment.
si logs [deployment] [options]| Argument | Notes |
|---|---|
deployment | Deployment (default: production) Optional. |
| Flag | Notes |
|---|---|
-f, --follow | Keep printing new lines |
-q, --query <text> | Only lines containing this text (case-insensitive) |
--level <error|warn|info|debug> | Only lines at this level or above |
--since <duration> | Start this long ago, e.g. 30s, 10m, 1h (at most 1h) |
--build | Show the build output instead |
si env ls
List variables.
si env ls [options]Also: si env list.
| Flag | Notes |
|---|---|
-e, --environment <production|preview|development> | Only variables for this environment |
si env add
Add or replace a variable (the value is read from stdin when omitted).
si env add <key> [value] [options]Also: si env set.
| Argument | Notes |
|---|---|
key | Variable name |
value | Value Optional. |
| Flag | Notes |
|---|---|
-e, --environment <production|preview|development> | Environments (repeatable; default: all three) Repeatable. |
--plain | Not sensitive: the value can be read back (and pulled) |
--dev-readable | A development-only secret developers can read back (env pull, dev); implies -e development |
si env rm
Remove a variable.
si env rm <key>Also: si env remove.
| Argument | Notes |
|---|---|
key | Variable name |
si env pull
Write variables to a .env file (sensitive values are left out, except development secrets readable by developers).
si env pull [file] [options]| Argument | Notes |
|---|---|
file | File (default: .env.local) Optional. |
| Flag | Notes |
|---|---|
-e, --environment <production|preview|development> | Environment (default: development) |
si env push
Add every variable in a .env file.
si env push [file] [options]| Argument | Notes |
|---|---|
file | File (default: .env) Optional. |
| Flag | Notes |
|---|---|
-e, --environment <production|preview|development> | Environments (repeatable; default: all three) Repeatable. |
--plain | Not sensitive: values can be read back |
si secrets ls
List secrets (the Serverless App Service's and shared ones; never values).
si secrets ls [options]Also: si secrets list.
| Flag | Notes |
|---|---|
-e, --environment <production|preview|development> | Only secrets for this environment |
si secrets set
Set a secret: a new version (the value is read from stdin when omitted).
si secrets set <key> [value] [options]Also: si secrets add.
| Argument | Notes |
|---|---|
key | Secret name |
value | Value Optional. |
| Flag | Notes |
|---|---|
-e, --environment <production|preview|development> | Environments (repeatable; default: all three) Repeatable. |
--rotate-every <days> | Remind owners and admins to rotate it after this many days |
si secrets get
Print a secret's value, if its access rule lets you read it (audited).
si secrets get <key> [version]| Argument | Notes |
|---|---|
key | Secret name |
version | An earlier version's number (secrets versions lists them) Optional. |
si secrets versions
List a secret's kept versions.
si secrets versions <key>| Argument | Notes |
|---|---|
key | Secret name |
si secrets rm
Remove a secret and its versions.
si secrets rm <key>Also: si secrets remove.
| Argument | Notes |
|---|---|
key | Secret name |
si keys ls
List keys.
si keys lsAlso: si keys list.
si keys encrypt
Encrypt text (read from stdin when omitted) and print the ciphertext.
si keys encrypt <key> [text] [options]| Argument | Notes |
|---|---|
key | Key id or name |
text | Text to encrypt Optional. |
| Flag | Notes |
|---|---|
-c, --context <name=value> | Bind the ciphertext to name=value (repeatable; decrypting needs the same) Repeatable. |
--base64 | The input is base64 (binary data) |
si keys decrypt
Decrypt a ciphertext (read from stdin when omitted) and print the text.
si keys decrypt <key> [ciphertext] [options]| Argument | Notes |
|---|---|
key | Key id or name |
ciphertext | Ciphertext (k1.…) Optional. |
| Flag | Notes |
|---|---|
-c, --context <name=value> | The context it was encrypted with (repeatable) Repeatable. |
--base64 | Print the plaintext as base64 |
si keys sign
Sign a message (read from stdin when omitted) and print the signature.
si keys sign <key> [message] [options]| Argument | Notes |
|---|---|
key | Key id or name |
message | Message Optional. |
| Flag | Notes |
|---|---|
--base64 | The message is base64 (binary data) |
si keys verify
Check a signature (exit status 1 when it doesn't match).
si keys verify <key> <signature> [message] [options]| Argument | Notes |
|---|---|
key | Key id or name |
signature | Signature (k1s.…) |
message | Message (read from stdin when omitted) Optional. |
| Flag | Notes |
|---|---|
--base64 | The message is base64 (binary data) |
si domains ls
List the Serverless App Service's domains and their DNS records.
si domains lsAlso: si domains list.
si domains add
Add a domain to the Serverless App Service.
si domains add <hostname> [options]| Argument | Notes |
|---|---|
hostname | e.g. www.example.com |
| Flag | Notes |
|---|---|
--move | It already serves a site: get the certificate first (one extra DNS record), then switch DNS without downtime |
si domains verify
Check DNS and the certificate.
si domains verify <hostname>| Argument | Notes |
|---|---|
hostname | The domain |
si domains cloudflare
Create the DNS records with the organization's Cloudflare connection.
si domains cloudflare <hostname>| Argument | Notes |
|---|---|
hostname | The domain |
si domains rm
Remove a domain.
si domains rm <hostname>Also: si domains remove.
| Argument | Notes |
|---|---|
hostname | The domain |
si open
Open the production URL (or a deployment) in the browser.
si open [deployment] [options]| Argument | Notes |
|---|---|
deployment | Deployment to open instead Optional. |
| Flag | Notes |
|---|---|
--cloud | Open the Serverless App Service in Cloud instead |
si dev
Run the dev server with the Serverless App Service's environment variables.
Runs the package.json dev script (or the command after --) with the Serverless App Service's variables in its environment.
Nothing is written to disk. Sensitive variables are left out, except development secrets readable by developers.
si dev [-- <command>...] [options]| Flag | Notes |
|---|---|
-e, --environment <production|preview|development> | Environment to take variables from (default: production) |
si runs ls
List runs, newest first.
si runs ls [options]Also: si runs list.
| Flag | Notes |
|---|---|
-R, --repo <org/name> | Repository, org/name (default: this clone's) |
-w, --workflow <file> | Only this workflow's file, e.g. ci.yml |
-b, --branch <value> | Only this branch |
-s, --status <queued|in_progress|waiting|completed|success|failure|cancelled|startup_failure> | Only runs in this state |
--event <push|pull_request|schedule|workflow_dispatch> | Only runs started by this event |
-n, --limit <n> | How many (default 20, at most 100) |
si runs view
Show a run: its jobs, reviews waiting, annotations and artifacts.
si runs view <run> [options]| Argument | Notes |
|---|---|
run | Run number |
| Flag | Notes |
|---|---|
-R, --repo <org/name> | Repository, org/name (default: this clone's) |
--attempt <n> | An earlier attempt |
--web | Open it in the browser |
si runs logs
Print a job's log (the failed job's by default).
si runs logs <run> [job] [options]| Argument | Notes |
|---|---|
run | Run number |
job | Job name or id Optional. |
| Flag | Notes |
|---|---|
-R, --repo <org/name> | Repository, org/name (default: this clone's) |
-f, --follow | Keep printing until the job ends |
si runs rerun
Run a finished run again as a new attempt.
si runs rerun <run> [options]| Argument | Notes |
|---|---|
run | Run number |
| Flag | Notes |
|---|---|
-R, --repo <org/name> | Repository, org/name (default: this clone's) |
--failed | Only the failed jobs and what needs them |
--job <key> | Only this job (and what needs it) |
si runs cancel
Cancel a run.
si runs cancel <run> [options]| Argument | Notes |
|---|---|
run | Run number |
| Flag | Notes |
|---|---|
-R, --repo <org/name> | Repository, org/name (default: this clone's) |
si runs start
Run a workflow by hand (workflow_dispatch).
si runs start <workflow> [options]| Argument | Notes |
|---|---|
workflow | Workflow file, e.g. deploy.yml |
| Flag | Notes |
|---|---|
-R, --repo <org/name> | Repository, org/name (default: this clone's) |
--ref <value> | Branch (default: the default branch) |
-f, --field <name=value> | An input, name=value (repeatable) Repeatable. |
si mcp
Print the MCP server configuration for AI clients.
si mcpsi git setup
Use this CLI as git's credential helper for the git host.
si git setup [options]| Flag | Notes |
|---|---|
--remove | Remove the helper again |
si git promote
Fast-forward a protected branch to another branch (for pushes over 5 MB).
si git promote <branch> <from> [options]| Argument | Notes |
|---|---|
branch | The protected branch, e.g. main |
from | The branch whose tip it moves to |
| Flag | Notes |
|---|---|
-R, --repo <org/name> | Repository, org/name (default: this clone's) |
si git allow-secret
Allow findings a push was refused for, for an hour, when they aren't secrets.
si git allow-secret <repo> <fingerprint...> [options]| Argument | Notes |
|---|---|
repo | Repository, org/name |
fingerprint | Fingerprints the refused push printed |
| Flag | Notes |
|---|---|
--reason <text> | Why these aren't secrets (required) |
si upgrade
Update to the latest version.
si upgrade [options]| Flag | Notes |
|---|---|
--check | Only check |
si completion
Print a shell completion script.
bash: si completion bash >> ~/.bashrc
zsh: si completion zsh > "${fpath[1]}/_si"
fish: si completion fish > ~/.config/fish/completions/si.fish
PowerShell: si completion powershell >> $PROFILE
si completion <shell>| Argument | Notes |
|---|---|
shell | bash, zsh, fish, powershell (bash, zsh, fish, powershell) |
si version
Show the version.
si versionsi help
Show help for a command.
si help [command...]| Argument | Notes |
|---|---|
command | Command Optional. |