Connect · Redis Cloud
Connect to Redis Cloud from your Mac
Copy the public endpoint (host and port) from the database’s Configuration tab and the default user’s password from its Security settings, then connect as the user default. TLS is off until you turn it on (paid plans only); after that, use rediss:// and Redis Cloud’s CA file.
Updated 9 October 2026
The Redis Cloud steps on this page come from Redis’s documentation as of October 2026; we didn’t
connect to a Redis Cloud database ourselves. The redis-cli output is from our own TLS-only Redis
8.10.2 test server.
What you need
- The database’s public endpoint: a host name and a port. Both Essentials and Pro databases have one. Pro databases also have a private endpoint, reachable only over VPC peering, Google Cloud Private Service Connect, or AWS Transit Gateway or PrivateLink; Pro can also block the public endpoint.
- The default user’s password, or the name and password of a user you created with role-based access control.
- If the database has a CIDR allow list, your Mac’s public IP address on it. The allow list is available on paid Essentials and on Pro, not on free Essentials.
- If TLS is on: Redis Cloud’s CA file,
redis_ca.pem.
Find your connection details
- In the Redis Cloud console, choose Databases and select your database.
- On the Configuration tab, find the public endpoint: in the Access section for Essentials,
or the General section for Pro. It reads
<host>:<port>. - Find the password. For Essentials, go to Security, select Configure for Default user, and use the eye icon. For Pro, it’s in the Security section of the Configuration tab.
- Or select Connect to open the connection wizard, which has a ready-made
redis-clicommand and code for several client libraries.
| Setting | Value |
|---|---|
| Host | the endpoint, such as redis-12345.c12345.us-east-1-mz.ec2.cloud.rlrcp.com |
| Port | the number after the colon; not 6379 (static endpoints carry it in the name: redis-<port>) |
| User | default |
| Password | the Default user password |
| Database | 0, the only one |
| TLS | off unless you turn it on |
Redis Cloud has two kinds of endpoint names. Static ones start with redis-<port>.c<number>;
dynamic ones are three words and a number ending in db.redis.io, such as
horse-battery-staple-12345.db.redis.io. Redis recommends the dynamic name for applications,
because it can later point to a different database.
Users and roles. The default user exists on every database. For named users, open Data
Access Control: define permissions as Redis ACL rules, group them into roles, and assign users to
roles. Three ACL rules are predefined: Full-Access (+@all ~*), Read-Write
(+@all -@dangerous ~*) and Read-Only (+@read ~*). You manage users in the console, not with
ACL SETUSER, which Redis Cloud doesn’t support. Once you have users, Redis recommends turning off
the default user. Its password must be shorter than 50 characters.
Database 0 only. Redis Cloud doesn’t support multiple numbered databases: SELECT is accepted
for compatibility but does nothing. Keep every connection on database 0.
Clustering. Large or busy databases are split into shards behind the same single endpoint, so
clients don’t notice, except that commands touching several keys need all of them in one hash
slot. On Pro you can turn on the OSS Cluster API (in the Performance section), and then
clients must speak the cluster protocol and follow MOVED redirects themselves.
RESP version. Each database is set to RESP2 or RESP3 (the Protocol setting); you can change it when you edit the database.
Connection string
redis://default:<password>@<endpoint>:<port>
Once TLS is on, use rediss:// instead. For a user you created, put its name in place of
default. See Redis connection strings and
special characters in passwords.
TLS
TLS isn’t on by default, and it’s only available on paid Essentials plans and on Pro. Redis recommends it for any database you reach over its public endpoint, which is what your Mac does.
To turn it on: open the database’s Configuration screen, select Edit, turn on the Transport layer security (TLS) toggle in the Security section, then Save database. After that every client must use TLS. Existing connections carry on until they reconnect.
The CA file. Select Download server certificate (on the database’s Configuration screen,
or under Redis Cloud certificate authority in Account Settings) to get redis_ca.pem. It
holds Redis Cloud’s own self-signed root certificates for Essentials and for Pro (which Redis calls
deprecated but still in use) and the publicly trusted GlobalSign root. Give your client the whole
file; Redis warns that some clients read only the first certificate in it.
Client certificates. You can also require them (mutual TLS) by selecting Mutual TLS (require client authentication) and adding or generating a certificate. If you generate one in the console, download it straight away: the private key isn’t offered again.
Connect with Inlet
- Choose New Connection, pick Redis, and enter the endpoint, the port, user
defaultand the password. Or pasteredis://default:<password>@<endpoint>:<port>(rediss://with TLS) and Inlet fills in the form. - If the database uses TLS, set TLS to Verify full and choose
redis_ca.pemas the CA certificate: Inlet checks the server’s certificate against every root in the file. If you turned on mutual TLS, add the client certificate and key. - Save the password in the Keychain, or have Inlet ask every time.
- Leave the database at 0.
- Tag the environment. On a connection tagged production, Inlet refuses write and admin commands before they’re sent. To have the server refuse them too, sign in as a user whose role uses the Read-Only rule.
Connect from the command line
Copy the command under Redis CLI in the connection wizard. Or, without TLS:
REDISCLI_AUTH='<password>' redis-cli -h <endpoint> -p <port>
With TLS, add the CA file, as in Redis’s documentation:
redis-cli -h <endpoint> -p <port> --tls --cacert redis_ca.pem
With mutual TLS, add --cert redis_user.crt --key redis_user_private.key. Putting the password in
REDISCLI_AUTH keeps it off the command line; -a <password> also works but prints a warning.
brew install redis gives you redis-cli with TLS support.
Troubleshooting
-
A timeout, or connection refused: check the port (it isn’t 6379), that your current IP is on the CIDR allow list if there is one, and, on Pro, that the public endpoint isn’t blocked.
-
WRONGPASS invalid username-password pair: a wrong password, the default user turned off, or a user whose role doesn’t include this database. Inlet says
Wrong user name or password. -
NOAUTH Authentication required: no password was sent. Inlet says
The server needs a password.and asks for it. -
The connection closes as soon as it opens: TLS is on for the database and off in your client. Against our TLS-only test server,
redis-cliwithout--tlsprinted:Error: Connection reset by peerInlet says
The server closed the connection while Inlet was signing in. If it accepts only TLS, turn on TLS for this connection. -
certificate verify failed: the client doesn’t trust the certificate. Use the wholeredis_ca.pem. Against our test server, without its CA file:Could not connect to Redis at localhost:6390: SSL_connect failed: certificate verify failedInlet says
The server’s certificate couldn’t be verified:followed by OpenSSL’s reason, such asunable to get local issuer certificate. -
NOPERM: your user’s role doesn’t allow that command or key.
-
MOVED: the OSS Cluster API is on, so the server expects cluster-aware clients. Inlet connects to one node and says which node holds the key.
-
CROSSSLOT: on a clustered database, a command named keys in different hash slots.
Related
Sources
- redis.io/docs/latest/operate/rc/databases/connect/
- redis.io/docs/latest/operate/rc/databases/view-edit-database/
- redis.io/docs/latest/operate/rc/security/access-control/data-access-control/default-user/
- redis.io/docs/latest/operate/rc/security/access-control/data-access-control/role-based-access-control/
- redis.io/docs/latest/operate/rc/security/access-control/data-access-control/configure-acls/
- redis.io/docs/latest/operate/rc/security/database-security/tls-ssl/
- redis.io/docs/latest/operate/rc/security/cidr-whitelist/
- redis.io/docs/latest/operate/rc/compatibility/
- redis.io/docs/latest/operate/rs/references/compatibility/commands/connection/
- redis.io/docs/latest/operate/rc/databases/configuration/clustering/