Create a manual snapshot
Install the CLI and sign in using the steps in Get your code. Production database operations require the project owner’s account. Dev snapshots can also be created by a project Admin. Managed Newly agent credentials work on dev only. Run these commands with your project id, the last part ofapp.newly.app/projects/<id>:
Snapshots expire after their retention period. Choose a frequency and retention that leave space for expiration cleanup and extra manual snapshots. For example, hourly snapshots kept for 24 hours would exceed the five-snapshot limit. Check
backup status and backup list to see the current state.
Run snapshots from your own scheduler
Your scheduler invokesnewly db backup create repeatedly. It doesn’t need database-provider credentials or a provider-managed scheduling feature. It does require Newly and the database provider to be available when the job runs.
Authenticate the job
On your own computer, create a separate CLI token and sign in as the project owner:NEWLY_API_TOKEN, and configure NEWLY_API_URL with the API URL printed by the command. Both values are required; the API URL is Newly’s API address, not your app’s backend address.
The token carries your account’s CLI permissions. Keep it out of app code, chat messages and job logs. Monitor authentication failures and replace the job’s token when necessary.
Example: GitHub Actions
In a GitHub repository you control, add:- A repository secret named
NEWLY_API_TOKENcontaining the owner’s CLI token. - Repository variables named
NEWLY_API_URLandNEWLY_PROJECT_IDcontaining the printed API URL and your project id.
.github/workflows/newly-database-snapshot.yml on that repository’s default branch:
Handle failed or uncertain runs
Treat a nonzero exit code as a failed job. Investigate expired credentials, the snapshot limit and service availability. The CLI prints a backup operation id before submitting the request. If the command times out or loses its response, the snapshot operation can still be running. Inspect that operation and the snapshot list before retrying:Backups that can run while Newly is unavailable
CLI snapshot automation depends on Newly. For direct database access during a Newly outage, export and securely save the owner’s connection URL before the outage:pg_dump, from infrastructure you control. A previously saved URL lets those tools connect without calling Newly, provided the database provider and network are available and the credentials remain valid.
Production URL export, including read-only access, and owner export in either environment require an owner’s CLI key and a fresh verification code sent to the account’s verified email. The CLI prompts for this code; a web session or confirmation flag alone cannot authorize export. Each code expires after five minutes and authorizes one specific request. Never share it with an agent or in chat.
An external pg_dump job produces a database export in your storage. It doesn’t create a snapshot listed by newly db backup list; you manage its storage, retention and restoration yourself. The connection URL grants database access, not a database-provider account or access to the provider’s snapshot API. Changing the owner’s database password also affects the deployed API and sign-in services.
Invalidate previously exported URLs
If a database URL leaks or someone who held it leaves, rotate the managed database passwords with this command:Restore a snapshot
Prepare a separate restore preview and inspect its result before deciding to replace the live database:cleanup_required: true, inspect the result, discard remaining unapplied previews, then remove the previous branch with: