InletDownload

Connect · Redis Cloud

Connect to Redis Cloud from your Mac

Copy the public endpoint (host and port) from the database’s Configuration tab and the default user’s password from its Security settings, then connect as the user default. TLS is off until you turn it on (paid plans only); after that, use rediss:// and Redis Cloud’s CA file.

Updated 9 October 2026

The Redis Cloud steps on this page come from Redis’s documentation as of October 2026; we didn’t connect to a Redis Cloud database ourselves. The redis-cli output is from our own TLS-only Redis 8.10.2 test server.

What you need

  • The database’s public endpoint: a host name and a port. Both Essentials and Pro databases have one. Pro databases also have a private endpoint, reachable only over VPC peering, Google Cloud Private Service Connect, or AWS Transit Gateway or PrivateLink; Pro can also block the public endpoint.
  • The default user’s password, or the name and password of a user you created with role-based access control.
  • If the database has a CIDR allow list, your Mac’s public IP address on it. The allow list is available on paid Essentials and on Pro, not on free Essentials.
  • If TLS is on: Redis Cloud’s CA file, redis_ca.pem.

Find your connection details

  1. In the Redis Cloud console, choose Databases and select your database.
  2. On the Configuration tab, find the public endpoint: in the Access section for Essentials, or the General section for Pro. It reads <host>:<port>.
  3. Find the password. For Essentials, go to Security, select Configure for Default user, and use the eye icon. For Pro, it’s in the Security section of the Configuration tab.
  4. Or select Connect to open the connection wizard, which has a ready-made redis-cli command and code for several client libraries.
SettingValue
Hostthe endpoint, such as redis-12345.c12345.us-east-1-mz.ec2.cloud.rlrcp.com
Portthe number after the colon; not 6379 (static endpoints carry it in the name: redis-<port>)
Userdefault
Passwordthe Default user password
Database0, the only one
TLSoff unless you turn it on

Redis Cloud has two kinds of endpoint names. Static ones start with redis-<port>.c<number>; dynamic ones are three words and a number ending in db.redis.io, such as horse-battery-staple-12345.db.redis.io. Redis recommends the dynamic name for applications, because it can later point to a different database.

Users and roles. The default user exists on every database. For named users, open Data Access Control: define permissions as Redis ACL rules, group them into roles, and assign users to roles. Three ACL rules are predefined: Full-Access (+@all ~*), Read-Write (+@all -@dangerous ~*) and Read-Only (+@read ~*). You manage users in the console, not with ACL SETUSER, which Redis Cloud doesn’t support. Once you have users, Redis recommends turning off the default user. Its password must be shorter than 50 characters.

Database 0 only. Redis Cloud doesn’t support multiple numbered databases: SELECT is accepted for compatibility but does nothing. Keep every connection on database 0.

Clustering. Large or busy databases are split into shards behind the same single endpoint, so clients don’t notice, except that commands touching several keys need all of them in one hash slot. On Pro you can turn on the OSS Cluster API (in the Performance section), and then clients must speak the cluster protocol and follow MOVED redirects themselves.

RESP version. Each database is set to RESP2 or RESP3 (the Protocol setting); you can change it when you edit the database.

Connection string

redis://default:<password>@<endpoint>:<port>

Once TLS is on, use rediss:// instead. For a user you created, put its name in place of default. See Redis connection strings and special characters in passwords.

TLS

TLS isn’t on by default, and it’s only available on paid Essentials plans and on Pro. Redis recommends it for any database you reach over its public endpoint, which is what your Mac does.

To turn it on: open the database’s Configuration screen, select Edit, turn on the Transport layer security (TLS) toggle in the Security section, then Save database. After that every client must use TLS. Existing connections carry on until they reconnect.

The CA file. Select Download server certificate (on the database’s Configuration screen, or under Redis Cloud certificate authority in Account Settings) to get redis_ca.pem. It holds Redis Cloud’s own self-signed root certificates for Essentials and for Pro (which Redis calls deprecated but still in use) and the publicly trusted GlobalSign root. Give your client the whole file; Redis warns that some clients read only the first certificate in it.

Client certificates. You can also require them (mutual TLS) by selecting Mutual TLS (require client authentication) and adding or generating a certificate. If you generate one in the console, download it straight away: the private key isn’t offered again.

Connect with Inlet

  1. Choose New Connection, pick Redis, and enter the endpoint, the port, user default and the password. Or paste redis://default:<password>@<endpoint>:<port> (rediss:// with TLS) and Inlet fills in the form.
  2. If the database uses TLS, set TLS to Verify full and choose redis_ca.pem as the CA certificate: Inlet checks the server’s certificate against every root in the file. If you turned on mutual TLS, add the client certificate and key.
  3. Save the password in the Keychain, or have Inlet ask every time.
  4. Leave the database at 0.
  5. Tag the environment. On a connection tagged production, Inlet refuses write and admin commands before they’re sent. To have the server refuse them too, sign in as a user whose role uses the Read-Only rule.

Connect from the command line

Copy the command under Redis CLI in the connection wizard. Or, without TLS:

REDISCLI_AUTH='<password>' redis-cli -h <endpoint> -p <port>

With TLS, add the CA file, as in Redis’s documentation:

redis-cli -h <endpoint> -p <port> --tls --cacert redis_ca.pem

With mutual TLS, add --cert redis_user.crt --key redis_user_private.key. Putting the password in REDISCLI_AUTH keeps it off the command line; -a <password> also works but prints a warning. brew install redis gives you redis-cli with TLS support.

Troubleshooting

  • A timeout, or connection refused: check the port (it isn’t 6379), that your current IP is on the CIDR allow list if there is one, and, on Pro, that the public endpoint isn’t blocked.

  • WRONGPASS invalid username-password pair: a wrong password, the default user turned off, or a user whose role doesn’t include this database. Inlet says Wrong user name or password.

  • NOAUTH Authentication required: no password was sent. Inlet says The server needs a password. and asks for it.

  • The connection closes as soon as it opens: TLS is on for the database and off in your client. Against our TLS-only test server, redis-cli without --tls printed:

    Error: Connection reset by peer
    

    Inlet says The server closed the connection while Inlet was signing in. If it accepts only TLS, turn on TLS for this connection.

  • certificate verify failed: the client doesn’t trust the certificate. Use the whole redis_ca.pem. Against our test server, without its CA file:

    Could not connect to Redis at localhost:6390: SSL_connect failed: certificate verify failed
    

    Inlet says The server’s certificate couldn’t be verified: followed by OpenSSL’s reason, such as unable to get local issuer certificate.

  • NOPERM: your user’s role doesn’t allow that command or key.

  • MOVED: the OSS Cluster API is on, so the server expects cluster-aware clients. Inlet connects to one node and says which node holds the key.

  • CROSSSLOT: on a clustered database, a command named keys in different hash slots.

Related

Sources