Command reference
Use this reference for the exact drift-cli command interface. Global options may appear before or after a subcommand.
Global options
--profile <name> Select a named configuration profile.
--config <path> Read a specific TOML configuration file.
--endpoint <url> Override the Drift base URL.
--json Emit the versioned JSON envelope.
--key-stdin Read the bearer key from standard input.
There is no secret-bearing command-line option. See configuration and environment variables for resolution rules.
Status
drift status
Requests GET /health and GET /v1/openapi.json. Success means Drift reports status: ok and publishes non-empty OpenAPI title and version fields. It does not prove backup freshness, storage capacity, or graph correctness.
Key administration
drift key list
drift key create --label <label> --scope <read|write|admin> [--scope ...]
drift key revoke <id> --yes
drift key rotate <id> --label <label> --scope <scope> [--scope ...] --yes
All key commands operate inside the tenant derived from the bearer key.
listreturns key metadata and never a raw secret.createrequires an explicit label and at least one scope. It prints the new secret once.revokeis immediate and irreversible;--yesis mandatory.rotateimmediately revokes the old key and returns its replacement secret once;--yesis mandatory.
The CLI never automatically retries these mutations.
Recovery
drift recovery show <vertex|edge> <id>
drift recovery restore <vertex|edge> <id> --version <positive-integer>
show requests the known record with includeDeleted=true and reports whether it is active or soft-deleted. restore sends the supplied optimistic-concurrency version.
Restoring a vertex does not restore its incident edges. An edge can be restored only after both endpoint vertices are active.
There is no recovery-list command because Drift v1 cannot filter its paginated list to deleted records only.
Task guides
Use the how-to guides for procedures and verification: