CLI

The Depfloy CLI (depfloy) manages your servers, projects and deployments from the terminal — trigger a deployment and watch its output live, sync a project's .env, run a command on the server, and more, without opening the Console.

Install #

Install the latest version with one command:

curl -fsSL https://get.depfloy.com/cli/install.sh | bash

To pin a specific version, pass --version:

curl -fsSL https://get.depfloy.com/cli/install.sh | bash -s -- --version=1.3.0

The installer places the depfloy binary in /usr/local/bin (or ~/.local/bin if that is not writable) and works on macOS and Linux. Once installed, keep it current with:

depfloy self-update

Add --check to only report whether a newer version is available, without installing it.

Authenticate #

Log in once per machine:

depfloy login

By default this opens the API Tokens page in your browser and waits for you to paste a token back. You can also skip the browser:

depfloy login --token <your-token>
depfloy login --email [email protected] --password ...   # for scripted setups

Your token is stored in ~/.config/depfloy/config.yml. The token carries the permissions you gave it when creating it — see API Tokens for how to create and scope one.

In CI you don’t need to run login at all — set the DEPFLOY_TOKEN environment variable and every command picks it up. It always takes precedence over the token stored on disk.

Check who you are logged in as at any time:

depfloy whoami

Linking tells the CLI which Depfloy project a folder belongs to. Once a folder is linked, you can run depfloy deploy, depfloy logs, or depfloy ssh from inside it without naming the project every time.

Go into your project’s repository and run link:

cd ~/code/my-app
depfloy link

The CLI lists your projects and asks you to pick one. It then writes a small depfloy.yml file at the root of the repository:

project: 123
server: 45

That is all it does. From now on, commands you run in this folder use project 123 automatically — no --project flag needed:

depfloy deploy --follow
depfloy logs --follow
depfloy ssh

Commit depfloy.yml to your repository so everyone on the team shares the same link.

Linking is optional. Every command also accepts --project <id> directly, which is useful for a quick one-off or when you are not inside the repository:

depfloy deploy --project 123 --follow

If a folder is linked and you pass --project, the flag wins.

Don’t know a project’s id? List your projects — the id is the first column:

depfloy projects list

Update project settings #

Change the settings used by the next deployment with projects update:

depfloy projects update 14532 \
  --branch release \
  --install-command 'pnpm install' \
  --build-command 'pnpm build' \
  --max-memory 1GB \
  --auto-deploy=false

Inside a linked repository, leave the id out:

depfloy projects update --framework laravel --always-rebuild-frontend=false

Available flags are --framework, --branch, --install-command, --build-command, --post-deploy-command, --max-memory, --auto-deploy, and --always-rebuild-frontend. Boolean flags accept explicit false, which is useful in scripts. Pass an empty command or memory value to remove that override:

depfloy projects update --build-command= --max-memory=

The command changes only the flags you provide. It saves the settings without starting a deploy, so the running release stays in place and the next deployment uses the new values.

Deploy a project #

A deployment builds the latest commit on your project’s branch and puts it live. To deploy and watch the build happen line by line, add --follow:

depfloy deploy --follow

If the folder isn’t linked, name the project instead:

depfloy deploy --project 123 --follow

You’ll see the build output stream in as it runs, ending with a success or failure line:

Deployment queued for project 123.
Cloning repository…
Installing dependencies…
Compiling assets…
Running migrations…
Restarting application…
✓ Deployment succeeded.

Because --follow waits for the result, it exits 0 when the deploy succeeds and 1 when it fails. That makes it safe to drop straight into a script or a CI pipeline — the pipeline stops if the deploy breaks.

Leave --follow off when you just want to kick off a deploy and get on with your work. The command queues the deployment and returns immediately, without streaming the output:

depfloy deploy

After a deploy #

Review past deployments, read a finished build’s log, or roll back:

depfloy deployments list          # recent deployments and their status
depfloy deployments logs <id>     # full output of a finished deployment
depfloy rollback --candidates     # releases you can roll back to
depfloy rollback <deployment-id>  # roll back to one (asks you to confirm)
depfloy rerun <deployment-id>     # deploy the same commit again

Everyday workflow #

Environment variables #

Pull the current .env to a file, edit it, and push it back:

depfloy env pull -o .env
depfloy env push -f .env
depfloy env set APP_DEBUG=false FEATURE_FLAG=on

env set merges the given keys across the linked project (or several with --projects 1,2,3). env push shows how many keys it is about to change and asks for confirmation.

Logs, SSH and commands #

depfloy logs --source application    # or nginx_access, nginx_error, octane, reverb…
depfloy logs --follow                # keep tailing new lines
depfloy ssh                          # open an SSH session to the project's server
depfloy run php artisan migrate --force   # run a command on the server, stream its output

run streams the command’s output and exits with the command’s own status. Flags after the command are passed straight through, so depfloy run php artisan migrate --force works as written.

Maintenance mode #

depfloy maintenance on
depfloy maintenance off
depfloy maintenance status

Command reference #

Every command targets the linked project or server unless you pass --project / --server. Read commands accept --json to print the raw API response instead of a table.

Servers & projects

depfloy servers list | show <id> | reboot <id> | pin <id> | update <id>
depfloy projects list | show <id> | update [id] [settings] | delete <id> | move <id> --to <server>

Domains & certificates

depfloy domains list | add <domain> | remove <id> | primary <id> | check-ns
depfloy certs list | show <id> | create | renew <id> | delete <id>

Server services

depfloy services config get <service> | services config set <service> --file conf
depfloy services restart <service>     # mysql, postgresql, redis, valkey, clickhouse, meilisearch, pgbouncer
depfloy db users | password <id> | replication-status
depfloy plugins list | setup <reverb|horizon|octane|nightwatch> | status | logs | restart | remove
depfloy lb show | apply | backends ... | domains ...

Scheduled tasks & background jobs

depfloy cron list | create | delete <id> | pause <id> | resume <id> | logs <id>
depfloy daemons list | create | delete <id> | start <id> | stop <id> | restart <id> | logs <id> | status <id>

Backups

depfloy backups destinations list | add | remove <id> | validate <id>
depfloy backups configs list | create | run <id> | pause <id> | resume <id>
depfloy backups list                 # backup runs
depfloy backups restore <id>         # asks you to retype the id to confirm
depfloy backups download <id>

Firewall, keys & monitoring

depfloy firewall list | add | remove <id> | sync
depfloy keys list | add | remove <id> [--server <id>]
depfloy monitoring show | install | alerts create | toggle <id> | delete <id>

Run depfloy <command> --help for the full flags of any command, and depfloy completion <bash|zsh|fish> to install shell completion.

Global flags & configuration #

FlagWhat it does
--jsonPrint the raw API response instead of a formatted table.
--project / --serverTarget a specific project/server, overriding depfloy.yml.
--no-interactionNever prompt — fail instead. For scripts and CI.

Configuration lives in two places:

  • ~/.config/depfloy/config.yml — your login token (created by login, written with owner-only permissions).
  • depfloy.yml — the per-project binding, committed to your repository.

The DEPFLOY_TOKEN environment variable overrides the stored token and always wins — the recommended way to authenticate the CLI in CI.

Which organization the CLI works in #

The CLI lists and acts on one organization at a time — whichever your account is currently in, the same one the Console shows you. With a single organization on the account, this changes nothing.

With several, depfloy servers and depfloy projects show only the current one. Switching organization in the Console changes what the next command returns; the CLI reads it fresh each time rather than caching it.

Any restriction on your membership applies too: if you are limited to specific servers, the CLI lists those and answers 404 for the rest, exactly as the Console does.

This narrowed in 2026. A token used to reach the whole account regardless of organization or of any per-server restriction. If a script of yours relied on listing everything at once, it now sees one organization’s worth — call the API with the X-Organization header to walk them deliberately.

For calling the API directly instead of through the CLI, see the API Reference.