CLI Reference
This is a snapshot of canopy --help’s own output, organized by area. If
it drifts, the CLI itself is the source of truth - run canopy --help
or check host/cli/src/main.ts.
Global flags on any command: --json (machine-readable output),
--profile <name> (switch config profile for this call). login also
accepts --manual, --api-key, --api-url, --app-url, --payload.
Some command groups below are gated behind a Platform Feature and marked accordingly - if a feature is disabled on your account, the command fails fast with an explanatory error rather than a confusing API error.
Auth & session
canopy login [--manual] [--api-key <key>] [--api-url <url>] [--app-url <url>]canopy logoutcanopy whoamicanopy profile listcanopy profile use <name>canopy profile rm <name>canopy account totp status|enroll|confirm|disable [code]canopy account change-password <current_password> <new_password>Projects & environments
canopy projects listcanopy projects create <name> [--team <slug>]
canopy environments list --project <slug>canopy environments create <branch> --project <slug> [--repository <repo>] [--template <template_id>] [--var NAME=value] [--parent <environment_id>] [--name <name>] [--build-path <dir>] [--build-command <cmd>] [--migrate-command <cmd>] [--host <dokku_host_id>]canopy environments show <environment_id>canopy environments update <environment_id> [--build-path <dir>] [--build-command <cmd>] [--migrate-command <cmd>] [--uses-artifact-deploy true|false] [--start-command <cmd>]canopy environments rm <environment_id>canopy environments logs --env <environment_id> [--access|--error]Templates
canopy templates listcanopy templates show <template_id>canopy templates save <environment_id> --name <name> [--slug <slug>] [--description <text>] [--visibility private|team|global] [--var NAME]canopy templates create <name> [--slug <slug>] [--repository <repo>] [--visibility <v>] [--description <text>] [--team <slug>]canopy templates set-services <template_id> --file <services.json>canopy templates update <template_id> [--name <name>] [--description <text>] [--build-path <dir>] [--build-command <cmd>]canopy templates rm <template_id>canopy templates resync <template_id>canopy templates admin-pendingcanopy templates admin-approve <template_id>canopy templates admin-reject <template_id> [--description <note>]Domains, webhooks, storage, databases, variables, build steps
canopy domains list --env <environment_id>canopy domains add <domain> --env <environment_id>canopy domains rm <domain_id> --env <environment_id>canopy domains ssl-enable --env <environment_id>
canopy webhooks list --env <environment_id>canopy webhooks create --env <environment_id>canopy webhooks secure --env <environment_id>canopy webhooks rm <hook_id> --env <environment_id>canopy webhooks deliveries --env <environment_id> [--limit <n>]
canopy storage list --env <environment_id>canopy storage mount <host_path> <container_path> --env <environment_id>canopy storage unmount <storage_mount_id> --env <environment_id>Forest environments use volumes instead of host storage mounts:
canopy volumes list --env <environment_id>canopy volumes create <name> --mount <path> --env <environment_id> [--size-gb <n>] [--process <name>] [--retention-days <n>] [--no-apply]canopy volumes update <volume> --env <environment_id> [--mount <path>] [--process <name>] [--retention-days <n>] [--no-apply]canopy volumes detach <volume> --env <environment_id> [--no-apply]canopy volumes attach <volume> --env <environment_id> [--no-apply]canopy volumes purge <volume> --env <environment_id> --confirm <volume name>canopy volumes retained --env <environment_id>canopy volumes adopt <volume_id> --mount <path> --env <environment_id> [--name <name>] [--process <name>] [--no-apply]Checking, running and seeing how an app is doing:
canopy compose import <docker-compose.yml> --project <slug> [--apply]canopy check --env <environment_id>canopy state --env <environment_id>canopy pods --env <environment_id>canopy jobs list --env <environment_id> [--kind cron|run|release] [--limit <n>]canopy run --env <environment_id> [--process <name>] [--with-volumes] -- <command...>canopy services create <name> --engine <postgres|redis|external> --env <environment_id> [--size-gb <n>] [--replicas <n>]canopy services restore <service_id> --backup <backup_id> --name <new_name> --env <environment_id> [--target-time <ISO 8601>]canopy environments update <environment_id> --predeploy-backup <true|false>canopy registries add --team <team_id> --host <registry_host> --credential-file <path>Image environments, application configuration and deleting an environment that holds state:
canopy environments create <name> --project <slug> --image <reference>canopy environments create <branch> --project <slug> --image <reference> --repository <owner/repo>canopy environments update <environment_id> --health-mode <auto|tcp|http|legacy_root_2xx> [--backup-consistency <stopped|online>]canopy deploys create --env <environment_id> --image <reference>canopy config get|revisions --env <environment_id>canopy config apply -f <canopy.yml> --env <environment_id> [--no-apply]canopy environments rm <environment_id> [--plan] [--confirm <slug>] [--volumes <retain|delete>] [--databases <retain|delete>]Databases and variables:
canopy database show --env <environment_id>canopy database create <type> --env <environment_id> [--image <image>] [--image-version <tag>]canopy database rm --env <environment_id>canopy test-database show|create <type>|rm --env <environment_id>
canopy variables list --env <environment_id> [--reveal]canopy variables set <NAME> <VALUE> --env <environment_id>canopy variables rm <NAME> --env <environment_id>
canopy build-steps list --env <environment_id>canopy build-steps add <command> --env <environment_id>canopy build-steps rm <step_id> --env <environment_id>canopy build-steps mv <step_id> --direction up|down --env <environment_id><type> is psql, mariadb, or mongo - see Databases.
A successful deploy enables SSL automatically for any custom domain
without it yet; domains ssl-enable just forces an immediate retry.
Deploys & builds
canopy deploys list --env <environment_id> [--page <n>]canopy deploys create --env <environment_id>canopy deploys logs <build_id> [--follow]canopy deploys cancel <build_id>canopy deploys rollback <build_id>canopy deploys unlock --env <environment_id> [--force]canopy builds trace <build_id> --env <environment_id>Deploys also trigger automatically on a push to a linked branch.
Teams, billing, repositories, keys
canopy teams listcanopy teams create <name> [--member <email> ...]canopy teams rm <team_id>canopy teams billing <team_id>canopy teams invite <team_id> --email <email> [--role developer|owner]canopy teams uninvite <team_id> <invite_id>canopy teams set-role <team_id> <user_id> --role <role>canopy teams remove-member <team_id> <user_id>canopy teams failure-signature-sharing <team_id> [--enable|--disable]canopy teams failure-signatures <team_id>canopy teams debt-benchmark-sharing <team_id> [--enable|--disable]
canopy repositories list [--q <search>]
canopy billing planscanopy billing plancanopy billing checkout <plan> --success-url <url> --cancel-url <url>canopy billing portal [--return-url <url>]
canopy keys listcanopy keys create <name>canopy keys revoke <key_id>Releases, artifacts, promotions, policies, audit
canopy releases list --project <id>canopy releases show <release_id> --project <id>canopy releases create --project <id> --version <v> --artifact <artifact_id> [repeatable] [--notes <text>]canopy releases promote <release_id> --environment <id>canopy releases approve <promotion_id> --environment <id>
canopy artifacts list --team <id>canopy artifacts show <artifact_id>canopy artifacts impact <digest|commit|package> --team <id> [--by digest|commit|package]canopy artifacts passport <artifact_id>
canopy policies list --team <id>canopy policies show <policy_id> --team <id>canopy policies simulate <policy_id> --team <id> [--limit <n>]canopy policies enable|disable <policy_id> --team <id>
canopy audit list --team <id>canopy audit verify --team <id>canopy audit export --team <id> [--out <file>]Gated behind host.releases/host.promotion_policies respectively.
SSO, SCIM, agents
canopy sso status --team <team_id>canopy sso test --team <team_id>canopy scim token rotate --team <team_id>canopy scim token revoke --team <team_id>SAML connection setup itself (IdP entity ID, SSO URL, certificate) is
done once in the dashboard (Team settings → Security), which shows
the metadata/ACS URLs to give your IdP. sso test checks the connection
is enabled and complete, without driving a real IdP login. scim token rotate prints the new plaintext provisioning token exactly once and
invalidates the previous one immediately. Gated behind host.sso.
canopy agents list --team <id>canopy agents create <name> --team <id> --kind maintenance|review|docs|custom [--permission <action> ...]canopy agents enable|disable <agent_id> --team <id>canopy agents key <agent_id> --team <id> [--expires-in-ms <ms>]canopy agents runs <agent_id> --team <id>Scoped agent identities for automation - not feature-gated (rides a
per-team enabled column instead).
Marketplace & MCP hosting
canopy catalog search [--q <query>]canopy catalog listcanopy catalog show <workflow_id>canopy catalog create <name> --namespace <id> --slug <slug> [--description <text>]canopy catalog publish <workflow_id> --version <v> --steps-json <json>canopy catalog verify <workflow_id> --verified <bool>canopy catalog metrics <workflow_id>canopy catalog install <workflow_id> [--granted-permission <perm> ...]canopy catalog uninstall <workflow_id>canopy catalog installationscanopy catalog run <installation_id>Gated behind host.marketplace.
canopy mcp listcanopy mcp show <server_id>canopy mcp create <name> --namespace <id> --slug <slug> [--visibility <v>]canopy mcp publish <server_id> --version <v> --artifact <id> --tools-json <json> [--required-credential <name> ...]canopy mcp start|stop <server_id>canopy mcp set-credential <server_id> <key> --value <v>canopy mcp install <namespace_scope>/<slug>canopy mcp invoke <server_id> <tool_name>Gated behind host.mcp.hosting (preview). This is Canopy’s hosted
third-party MCP server marketplace, not a client for Canopy’s own MCP
servers - see MCP.
Canopy Connect (CI) & timeline
canopy ci report [--connection <id>] [--status <status>] [--env <environment_id>] [--commit <sha>]canopy ci connections list --team <id>canopy ci connect --team <id> --provider <id> --repo <host/owner/name>canopy ci runs list --pipeline <id>canopy ci runs show <run_id>canopy ci discover <connection_id>canopy ci validate [--file <path>]
canopy timeline --env <environment_id> [--cursor <cursor>]Gated behind host.ci (ga, enabled). See Canopy Connect
for the full connection → discovery → run lifecycle.
Costs & budgets
canopy costs summary --team <id>canopy costs breakdown --team <id>canopy costs anomalies --team <id> [--threshold <n>]canopy costs export [--format json|csv] --team <id> [--since <date>] [--until <date>]
canopy budgets list --team <id>canopy budgets set --team <id> [--id <id>] [--project <id>] [--environment <id>] [--limit <n>] [--currency <code>] [--disable]canopy budgets delete <budget_id> --team <id>Gated behind host.budgets.
Alerts (preview)
canopy alerts list [--space <id-or-slug>]canopy alerts create <name> --metric <metric> --threshold <n> --channel <in_app|webhook> [--webhook-url <url>] [--space <id-or-slug>]canopy alerts delete <rule_id> [--space <id-or-slug>]canopy alerts events [--space <id-or-slug>]--metric is one of open_incidents_count, budget_percent_used,
deploy_lag_minutes, or failed_ci_runs_on_default_branch.
--webhook-url is required when --channel webhook. Rules are evaluated
on the API’s own schedule - creating one does not fire it, and a rule
resolves on its own when the metric drops back below its threshold.
Incidents, notifications, recommendations
canopy incidents list <environment_id>canopy incidents show|mitigate|resolve|dismiss <environment_id> <incident_id>
canopy notifications list [--limit <n>] [--offset <n>]canopy notifications read <notification_id>canopy notifications read-all
canopy recommendations listcanopy recommendations inbox <environment_id|team_id>canopy recommendations apply|dismiss|revert <environment_id> <recommendation_id>recommendations (host.operational_recommendations) is fully
enabled. incidents and notifications exist in the CLI and API but
are currently disabled in production (host.incidents,
host.notifications - see Platform Features) -
expect a “feature disabled” error against api.canopy.pm today.
Maintenance
canopy maintenance list <team_id> <repository_id>canopy maintenance show <team_id> <repository_id> <task_id>canopy maintenance enable|disable <team_id> <repository_id> [category]canopy maintenance budget <team_id> <repository_id> <category> <cents>canopy maintenance run <team_id> <repository_id> <category> <proposal_json> <estimated_cost_cents> [--agent-identity-id <id>]Currently disabled in production (host.automation.maintenance,
experimental) - implemented, not yet launched.
Compliance & residency
canopy compliance status <team_id>canopy compliance assemble <team_id> <period_start> <period_end>canopy compliance export <team_id> <package_id>canopy compliance legal-review <team_id> <package_id>
canopy residency show|attest <environment|artifact> <id>Gated behind host.compliance (preview, internal - not in navigation).
residency specifically (host.compliance.residency_chain) is
currently disabled in production.
Docker images
canopy images login [--team <id>] [--name <n>] [--read-only] [--expires-in-days <n>] [--print]canopy images pin <namespace>/<name>[:tag] --team <id>canopy images lock <canopy.pipeline.ts> --team <id> [--update] [--check]canopy images list --team <id> [--limit <n>]See Package Registry.
Registry (npm packages)
canopy registry login --scope <@scope>canopy registry publish [--tag <tag>] [--dry-run]canopy registry list --team <id>canopy registry info <@scope/name>canopy registry stats <@scope/name>canopy registry daily-pulls <@scope/name> <version> [--since-days <n>]
canopy registry dist-tag ls <@scope/name>canopy registry dist-tag add <@scope/name@version> <tag>canopy registry dist-tag rm <@scope/name> <tag>
canopy registry namespace create <@scope> --team <id>canopy registry namespace verify <id> --team <id> --domain <domain>canopy registry namespace status <id> --team <id>canopy registry namespace public <id> --team <id> [--private]Gated behind host.registry.
login writes a managed block into ./.npmrc and is safe to re-run
(it rewrites its own block rather than appending). After that, publish a
new version with the real npm client - npm version patch && npm publish,
or npm publish --tag next for a prerelease that shouldn’t move
latest. Versions are immutable: republishing one is a 409, and there is
no unpublish.
namespace public makes a whole scope installable with no Canopy
credential at all - how you’d ship an SDK to your own customers. See
Package Registry for the full workflow.
Engineering Graph & Spaces (preview)
canopy graph node <ref>canopy graph edges <ref> [--depth <0-3>]canopy graph commit <sha>
canopy space listcanopy space create <name>canopy space use <id-or-slug>canopy space currentcanopy space search <query> [--space <id-or-slug>] [--kinds k1,k2]canopy space monitor [--space <id-or-slug>]canopy space ask <question> [--space <id-or-slug>]Both gated behind preview-lifecycle features (host.graph,
host.spaces) - enabled by default, but not a locked contract yet. See
Spaces.
Platform Features (staff-only)
canopy features listcanopy features set <key> enabled|disabled --reason "..."See Platform Features.
Admin (staff/operational)
canopy admin update-host-script <filename> [--file <path>]canopy admin network-selftestcanopy admin network-attach <environment_id> <network_name>canopy admin docker-options-report <environment_id> [--phase build|deploy|run]canopy admin mcp-network-selftestcanopy admin hosts listcanopy admin hosts add <hostname> [--ssh-port <n>] [--bootstrap-ssh-user <user>] [--bootstrap-ssh-port <n>] [--bootstrap-key-path <path>]canopy admin hosts set-status <id> active|draining|disabledcanopy admin hosts update-connection <id> [--hostname <h>] [--ssh-port <n>]canopy admin hosts health-check <id>canopy admin analytics overview|events [--event <name>]|users|revenue [--days <n>]canopy admin stripe planscanopy admin stripe set-plan <id> [--stripe-price-id <id>] [--stripe-product-id <id>]canopy admin builder [--limit <n>]canopy admin backups status|browse [--path <p>]|quota|size <path>canopy admin reconciliationcanopy admin missing-appscanopy admin repair-missing-app <environment_id>canopy admin builds-kill [--all]canopy admin host-scripts statuscanopy admin observability statusNot feature-gated (foundational/staff-operational surface):
projects, environments, deploys, domains, variables, teams,
billing, keys, admin, storage, database, agents.