> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tofunmiadewuyi.com/custos/llms.txt
> Use this file to discover all available pages before exploring further.

# custoscp CLI

> Control-plane subcommands and flags.

```
usage: custoscp <serve|migrate|create-admin|gen-keys|version> [flags]
```

All configuration comes from environment variables — see
[Configuration](/custos/custos/control-plane/configuration). The database subcommands additionally accept
`--database-url` so you can pass a connection string without exporting it.

## `serve`

Runs the HTTP API until it receives SIGINT or SIGTERM, then shuts down gracefully.

```bash theme={null}
custoscp serve
```

No flags; everything is read from the environment. Fails fast if a required variable is missing.

## `migrate`

Runs the goose migrations embedded in the binary. Defaults to `up` when no subcommand is given.

```bash theme={null}
custoscp migrate up
custoscp migrate status
custoscp migrate down
```

| Flag | Default | Notes |
| - | - | - |
| `--database-url` | `$CUSTOS_DATABASE_URL` | required, by flag or environment |

Because migrations are embedded, the binary and its schema always ship together. Run `migrate up`
before the first `create-admin`, and after any upgrade whose release notes mention migrations.

## `create-admin`

Creates the first admin user. A bootstrap task, not an API call — there is no admin yet to authorize
it.

```bash theme={null}
custoscp create-admin --email you@example.com
```

| Flag | Default | Notes |
| - | - | - |
| `--email` | — | admin email |
| `--password` | generated | printed to stdout when generated |
| `--database-url` | `$CUSTOS_DATABASE_URL` | required, by flag or environment |

Requires the schema to exist already.

## `gen-keys`

Prints a fresh key bundle in env format. Also a bootstrap task.

```bash theme={null}
custoscp gen-keys > /root/custos-keys && chmod 600 /root/custos-keys
```

Output:

```text theme={null}
CUSTOS_MASTER_KEY=...
CUSTOS_SIGNING_PRIVATE_KEY=...
CUSTOS_SERVER_TRANSPORT_PRIVATE_KEY=...
CUSTOS_SERVER_TRANSPORT_PUBLIC_KEY=...    # set on clients, not read by the control plane
```

<Warning>
  Redirect this to a root-only file rather than letting it land in terminal scrollback or shell
  history. Losing `CUSTOS_MASTER_KEY` means losing every stored secret.
</Warning>

## `version`

```bash theme={null}
custoscp version
```

Also accepts `--version` and `-v`.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.