📣
TiDB Cloud Premium is now in public preview. Unlimited growth, instant elasticity, advanced security for enterprise workloads. Try it out →

TiDB Cloud CLI Regions, Security, and Limitations



This reference describes current regions, authentication, platform, and preview boundaries for TiDB Cloud CLI. For file system regions and limitations, see TiDB Cloud Filesystem Regions and Limitations.

Supported regions

When using TiDB Cloud CLI, you need to configure a default region for CLI operations.

The following table lists the supported regions for TiDB Cloud CLI and shows which TiDB Cloud CLI services are available in each region.

ProviderLocationCanonical region codeTiDB Cloud StarterTiDB Cloud Filesystem
AWSN. Virginiaaws-us-east-1SupportedSupported
AWSOregonaws-us-west-2SupportedSupported
AWSSingaporeaws-ap-southeast-1SupportedSupported
AWSFrankfurtaws-eu-central-1SupportedNot supported
AWSTokyoaws-ap-northeast-1SupportedNot supported
Alibaba CloudSingaporealicloud-ap-southeast-1SupportedSupported

If your configured region supports TiDB Cloud Starter but not TiDB Cloud Filesystem, you can manage Starter instances in that region. File system commands fail with an unsupported endpoint error.

Supported file system regions are built into each ti release. To use a file system in a region added after your installed version was released, upgrade ti. You cannot enable an unsupported region by specifying a service URL.

Credential requirements

OperationRequired credential
ti configure, all ti db control-plane operationsTiDB Cloud API public/private key
ti fs create-file-systemTiDB Cloud API key
ti fs delete-file-systemTiDB Cloud API key and file system ID
Describe or update file system extraction and embedding configurationTiDB Cloud API key and explicit file system ID
Generate, list, enable, disable, or delete file system tokensTiDB Cloud API key and explicit file system ID
Refresh a file system tokenThe current FS bearer token only
Remote file, layer, pack, mount, Git, journal, and owner vault operationsFS owner token or registered resource credential
Delegated vault read, list, run, or mountScope-appropriate delegated vault token
Drain and unmount after a successful background mountNon-secret mount locator in the same HOME

TiDB Cloud API calls use Digest authentication. SQL HTTPS execution uses generated SQL username/password Basic authentication over TLS. These credentials are not interchangeable.

Security best practices

  • Create TiDB Cloud API keys with only the access required for the workflow. Do not reuse a personal administrator key in unattended automation.
  • Inject automation credentials from a CI secret store or runtime secret manager. Do not place credentials in source control, container images, shell scripts, or command-line arguments that can appear in process listings and shell history.
  • Do not copy the complete ~/.ti/ directory into an agent sandbox. For an existing file system, pass only TI_FS_TOKEN and TI_REGION_CODE; use TI_FS_FILE_SYSTEM_ID only as an optional assertion.
  • Use --read-only for SQL inspection by untrusted or exploratory agents. Use --admin only for DDL or privilege management, and use --read-write only when data changes are intended.
  • Use --dry-run before destructive control-plane operations. Keep ~/.ti/credentials, resource credentials, and DB SQL credentials owner-readable only.
  • Review local operation logs before sharing diagnostics. The logs exclude SQL text, paths, payloads, and credential values, but command names, flag names, profile and region metadata, status codes, and operational timing can still be sensitive.

For file system tokens, mounts, Vault, and AI provider security, see Authorization, Manage File System Tokens, and Configure AI Providers for a File System.

Product limitations

  • The TiDB Cloud CLI is in preview, and command contracts can change.
  • Database management targets TiDB Cloud Starter instances, not other TiDB Cloud database plans.
  • SQL execution accepts one statement per invocation.
  • Read-write is the default SQL role; use explicit role flags in security-sensitive automation.
  • Telemetry management commands are intentionally not implemented. Control telemetry through ~/.ti/.preferences or TI_TELEMETRY; serverless-function deployment, Homebrew, and Scoop distribution are not implemented.

Was this page helpful?