Guide
Use the CLI to sign in to Helix Cloud, link a project to a Cloud database, and run
queries against it. You need a Helix Cloud account and at least one database; see
Get started with Helix Cloud.
1
Authenticate with WorkOS
2
Link a project and database
production database link to
helix.toml. To link another database later, run helix add cloud --name <name>.3
Run a query through the broker
4
Inspect the linked resources
helix database list --project <project> or helix query tenant:<id> --file request.json. In
scripts, add --json for machine-readable output; commands then never prompt. See
Cloud resource resolution.
How Cloud queries are authorized
helix auth logincreates a WorkOS session that identifies you. The CLI never uses database API keys.- Cloud queries go through the Helix Cloud backend (the broker), not directly to the database gateway. The broker forwards each authorized request with its own gateway credentials, which the CLI never receives.
- Reads require the
database.query.readscope and writes requiredatabase.query.writeon the selected database. Project-management access does not imply query access. - Owners and admins have both query scopes by default. Members have neither unless explicitly granted.
- Local queries are unaffected and run without authentication.
Keys and credentials are not logins
helix database keycreates application keys for your own services that call the gateway directly.helix service-credentialmanages headless HTTP API and unified MCP credentials. MCP tool access follows the credential’s project grants, and these sessions do not get Cloud discovery or observability tools.
Next steps
CLI configuration
How
helix.toml stores project and database links.helix query
Request formats and Cloud query behavior.