> ## Documentation Index
> Fetch the complete documentation index at: https://help.the-meridian.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Database commands

`meridian db` manages the Meridian-managed MySQL developer database: reset it, seed it, or open a SQL shell against it. Every one of those subcommands brings the proxy up for the duration and sets `DATABASE_URL` first. `meridian db credential` is the exception: it manages credentials for a hosted environment's database. See [External credentials](#external-credentials).

## Resetting

```bash theme={null}
meridian db reset
```

Drops and recreates every table, keeping the MySQL user, so your credentials stay valid and only the data goes.

| Flag | Effect |
| - | - |
| `--migrate` | Run `npx prisma migrate deploy` afterwards, without asking |
| `--seed` | Run `npx prisma db seed` afterwards, without asking |

Without those flags the CLI asks whether to migrate and seed. Passing them is what makes the command usable in a script.

## Seeding

```bash theme={null}
meridian db seed
```

Runs `npx prisma db seed` with the proxy up and `DATABASE_URL` set. That is the whole command. It exists so your seed script does not need a tunnel of its own.

## The SQL shell

```bash theme={null}
meridian db shell
meridian db shell -e "select count(*) from Session"
```

Opens a shell against the developer database using the real `mysql` client when it is on your `PATH`, and a built-in REPL when it is not.

| Flag | Effect |
| - | - |
| `--repl` | Force the built-in REPL even when `mysql` is available |
| `-e`, `--execute <sql>` | Run one statement and exit |
| `--no-env` | Don't patch `DATABASE_URL` into the project's `.env` |

`-e` is the one to reach for in a script or a `Makefile`: it prints the result and exits rather than waiting for input.

`reset`, `seed` and `shell` also take `--port` and `--env-file`, with the same meaning as on [`meridian dev`](/cli-dev#the-database-url).

<Note>
  This is your **development** database. Your hosted environments' databases are managed from the dashboard, have their own SQL console with statement classification and escalation rules, and are documented under [Database](/database).
</Note>

## External credentials

```bash theme={null}
meridian db credential list --env production
meridian db credential revoke aws-backend --env production
```

`meridian db credential` lists and revokes the credentials a backend running outside Meridian (on AWS, a BI tool) uses to reach a **hosted environment's** database through the Meridian database gateway. See [External access](/database-external-access).

Create and rotate credentials in the dashboard, under **Hosting > Database > External access**. Each one grants access to a production database from anywhere, so issuing one needs a signed-in browser session, not a CLI token that lives for months on a laptop. Revoking only ever removes access, so you can do it from a terminal the moment a key or password may have leaked.

Each subcommand takes `--env <name>` with the environment's name or type (`production`, `staging`). Without it, the CLI uses the only environment with a database, or asks when there are several.

* `list` shows each credential's label, MySQL user, access mode, status, last connection and certificate expiry. It needs access to the app's hosting.
* `revoke <credential>` takes the label or the id `list` prints. It asks first unless you pass `--yes`, then drops the MySQL user, and open connections close within 30 seconds. It needs the **Credentials: Manage** permission on the app.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.