CLI
Every command accepts --json and --yes. naro help prints the long form, including the subcommands collapsed in this table.
Commands
| Command | What it does |
|---|---|
naro login | Sign in through GitHub. Opens a browser. |
naro logout | Forget the stored session. |
naro whoami | Show who is signed in. |
naro token | Print an access token for CI. Use it as NARO_TOKEN. |
naro link | Link this directory to a project, writing .naro/project.json. |
naro unlink | Remove the link. |
naro projects [--team <slug>] | List projects, optionally scoped to a team. |
naro project inspect | Show the linked project. |
naro deploy [--prod] [--root <dir>] | Build locally and deploy. Preview unless --prod. --root points at the app in a monorepo. |
naro deployments | List the linked project's deployments. |
naro inspect <deployment-id> | Show one deployment with its build logs. |
naro cancel <deployment-id> | Stop a build that is still running. |
naro git connect | disconnect | Connect or disconnect a repository so every push deploys. |
naro logs [deployment-id] [--type build|runtime] | Runtime logs, or a deployment's build logs with --type build. |
naro analytics [--range <r>] [--path <p>] [--referrer <host>] [--country <cc>] [--device <d>] [--browser <b>] [--os <o>] | Web Analytics from real visits: the range's visitors and page views (--range, 7d by default), then the top pages, referrers, countries, devices, browsers and operating systems by page views. --path, --referrer, --country, --device, --browser and --os narrow it to one value each, all of them at once. --json prints the whole report, trend included. |
naro insights [--metric <m>] [--range <r>] [--env <e>] [--route <pattern>] [--path <p>] [--country <cc>] [--device <d>] [--browser <b>] [--os <o>] | enable | disable | Speed Insights from real visits: each Web Vital's p75 with its good, needs-improvement and poor shares, then the selected metric (--metric, --range) by page, device, the elements behind slow visits and deployment. Production by default; --env preview reads the preview worker. --route lists the paths under one route; enable and disable turn measuring on or off for both. --path, --country, --device, --browser and --os narrow it to one value each (Speed Insights has no referrer, so --referrer is refused), and a line under the metrics gives the page load's p75 and the mean of each step. |
naro protection [--project <id>] | enable | disable | bypass [remove] | Show or change preview protection: on, only members of the project can open the preview URL; off, anyone with the link can. enable and disable switch it; the edge picks the change up within about a minute. bypass creates the secret that CI or a monitor sends as the x-naro-protection-bypass header (shown once, replacing any earlier one) and bypass remove deletes it. |
naro env list | add | remove | pull | List, add, remove, or pull environment variables. |
naro domains list | add <host> | remove <host> | verify [host] | List, add, or remove custom domains; verify re-checks DNS and prints what is missing. A project can have up to 20 custom domains (an apex added with its www form counts as two), and the names of those that serve it can take up to 4,800 bytes together. |
naro db enable | info | query <sql> | push | dump | restore | pull | reset [--yes] | lint | table <action> | index <action> | Create the project's database, show its status and limits, run SQL against it, create and change tables and indexes without SQL, push pending migrations, dump it to a file, restore it to an earlier point, pull its schema into a first migration, reset it to what the migration files say, policies included, or lint it for what D1 trips on and for policies the Data API cannot apply. |
naro migration new <name> | list | up | repair <name> [--status <s>] [--yes] | Create a numbered migration file, compare local files with what is applied, apply the pending ones, or repair the ledger when it stopped matching the database. |
naro gen types [--lang typescript] [--output <file>] | Print TypeScript types for the database schema: a Row interface per table and the Database type createClient<Database>() from naro-js takes. TypeScript is the only --lang. |
naro backend [status] | enable | disable | keys [--reveal] | keys rotate --anon|--service | Show the project's backend — on or off, status, URL and anon key — turn it on (provision is the same command) or off, print the service key with --reveal, or replace a key. |
naro backend auth [email set|remove] [oauth set|remove <google|github>] [redirects list|add|remove <url>] [require-verification <on|off>] [signups <on|off>] [password --min-length <n>] | Show or change sign-in: whether anyone may sign up (signups off leaves only the accounts you create), the fewest characters a new password takes, the Resend account confirmation and reset emails go out from, the Google and GitHub apps, the origins a sign-in may send the browser back to, and whether sign-in waits for a confirmed email. Email and password sign-in needs none of it set up. Secrets are read from stdin (--api-key-stdin, --client-secret-stdin), never from the command line. |
naro backend users [create --username <name> --password-stdin] [delete <id|username|email>] | List, create or delete the project's users, as Supabase's auth.admin does: create takes a username, an email or both and a password (--password-stdin), and the account is confirmed and signs in at once, also while sign-ups are closed. delete takes an id, username or email and asks first. |
naro policy list [--table <t>] | create "<CREATE POLICY …>" [--allow-unindexed] | drop <name> --table <t> | set <table> [--select <rule>] [--owner <column>] [--select-when <filter>] [--from-file <policy.json>] | remove <table> | Row-level security for the Data API, as in Postgres and Supabase: list the policies as CREATE POLICY, create them from CREATE POLICY statements (a --file may hold several, and DROP POLICY), or drop one by name. set is shorthand that writes naro_select … naro_delete from a rule (none, public, authenticated or owner) or a condition in filter syntax with auth.uid(); remove drops every policy on a table. A table without a policy denies every anon and signed-in request. Write a table's policies in its migration to keep them with the table: these commands change the database directly. |
naro storage [status] | enable | bucket <action> [name] | ls [naro://<bucket>[/<prefix>]] | cp <from> <to> | rm <naro://bucket/path> | Naro Storage: turn it on, show its limits and what is stored, make, change, empty or remove buckets, and list, copy and remove files at naro://<bucket>/<path> with the project's service key. |
naro promote <deployment-id> | Publish an existing build to production without rebuilding. |
naro rollback [deployment-id] | Roll production back to the previous build. |
Global options
| Command | What it does |
|---|---|
--json | One machine-readable JSON object on stdout. |
--yes, -y | Never prompt. For CI and agents. |
--token <t> | Access token, or set NARO_TOKEN. |
--project <id> | Target a project, overriding .naro/project.json. |
--root <dir> | The app directory inside the repository, for monorepos. |
--name <name> | Project name for a first deploy. |
--team <slug> | Team scope for listing and linking. |
--prod | Target production. |
--debug | Verbose diagnostics. |
JSON output
--json prints exactly one JSON object on stdout and sends logs to stderr, so a caller can parse stdout without filtering it first.
Error codes
A failure returns success: false with a code and a message. The codes are stable — branch on the code, never on the message.
| Code | What it does |
|---|---|
NOT_LOGGED_IN | No session. Run naro login, or pass a token. |
PROJECT_NOT_LINKED | This directory has no link file. Run naro link, or deploy once. |
FRAMEWORK_UNSUPPORTED | naro could not match the project to a framework it builds. |
BUILD_FAILED | The framework's build failed. Read the build logs, fix the code, deploy again. |
DEPLOYMENT_NOT_FOUND | No deployment with that id on this project. |
DEPLOYMENT_NOT_PROMOTABLE | Only a READY deployment that still has its artifact can be promoted. |
UNAUTHORIZED | The session or token cannot act on this project. |
RATE_LIMITED | Too many requests. Wait, then retry. |