meridian db manages the Meridian-managed MySQL developer database: reset it, seed it, or open a SQL shell against it. Every one of those subcommands brings the proxy up for the duration and sets DATABASE_URL first. meridian db credential is the exception: it manages credentials for a hosted environment’s database. See External credentials.
Resetting
Without those flags the CLI asks whether to migrate and seed. Passing them is what makes the command usable in a script.
Seeding
npx prisma db seed with the proxy up and DATABASE_URL set. That is the whole command. It exists so your seed script does not need a tunnel of its own.
The SQL shell
mysql client when it is on your PATH, and a built-in REPL when it is not.
-e is the one to reach for in a script or a Makefile: it prints the result and exits rather than waiting for input.
reset, seed and shell also take --port and --env-file, with the same meaning as on meridian dev.
This is your development database. Your hosted environments’ databases are managed from the dashboard, have their own SQL console with statement classification and escalation rules, and are documented under Database.
External credentials
meridian db credential lists and revokes the credentials a backend running outside Meridian (on AWS, a BI tool) uses to reach a hosted environment’s database through the Meridian database gateway. See External access.
Create and rotate credentials in the dashboard, under Hosting > Database > External access. Each one grants access to a production database from anywhere, so issuing one needs a signed-in browser session, not a CLI token that lives for months on a laptop. Revoking only ever removes access, so you can do it from a terminal the moment a key or password may have leaked.
Each subcommand takes --env <name> with the environment’s name or type (production, staging). Without it, the CLI uses the only environment with a database, or asks when there are several.
listshows each credential’s label, MySQL user, access mode, status, last connection and certificate expiry. It needs access to the app’s hosting.revoke <credential>takes the label or the idlistprints. It asks first unless you pass--yes, then drops the MySQL user, and open connections close within 30 seconds. It needs the Credentials: Manage permission on the app.