Skip to main content
All configuration comes from environment variables — see Configuration. The database subcommands additionally accept --database-url so you can pass a connection string without exporting it.

serve

Runs the HTTP API until it receives SIGINT or SIGTERM, then shuts down gracefully.
No flags; everything is read from the environment. Fails fast if a required variable is missing.

migrate

Runs the goose migrations embedded in the binary. Defaults to up when no subcommand is given.
Because migrations are embedded, the binary and its schema always ship together. Run migrate up before the first create-admin, and after any upgrade whose release notes mention migrations.

create-admin

Creates the first admin user. A bootstrap task, not an API call — there is no admin yet to authorize it.
Requires the schema to exist already.

gen-keys

Prints a fresh key bundle in env format. Also a bootstrap task.
Output:
Redirect this to a root-only file rather than letting it land in terminal scrollback or shell history. Losing CUSTOS_MASTER_KEY means losing every stored secret.

version

Also accepts --version and -v.