Redis: view keys, status and editing
The Redis menu is a graphical interface (a Redis GUI) to view the keys, status and memory of each client’s Redis, and edit with an audit log. It shows up on clients with Redis access saved. It works with Azure Cache for Redis (TLS, port 6380) and ElastiCache (in-transit encryption, AUTH or an ACL user), outside cluster mode.
What it does
| Plan | What it shows and does |
|---|---|
| Free | Server status, latency, version, replication role, memory, connected clients and keys per database. |
| Pro and Team | Key browser with pattern search (SCAN), each key’s value by type, TTL and memory; INFO; SLOWLOG; a sample of the keys using the most memory. Admins write strings and hash fields, change or remove TTLs, rename and delete keys. |
What is accepted
- A redis:// or rediss:// (TLS) connection string, or host, port (1 to 65535), user, password, TLS and database.
- Database 0 to 1023.
- Writing a string to a string key or a new key. The key’s existing TTL is kept (read with PTTL and written back with PX, on any Redis version), or you set a new TTL in the same edit.
- Writing a field to a hash key or a new key.
- A TTL in seconds, a positive integer up to 10 years, or removing the TTL.
- Renaming to a name that does not exist yet (RENAMENX).
- Deleting one key, or several at once: up to 20 keys per minute per client.
What is not accepted
- Writing a string to a key of another type, or a hash field to a non-hash key: it is refused instead of overwriting.
- Renaming to a name that already exists.
- FLUSHALL, FLUSHDB, KEYS, a command console and the other refused commands in the table below.
- Redis in cluster mode.
- Browsing or editing on Free; editing or deleting as a member (on the web; on desktop, from 2.7.0).
Limits and timeouts
| Limit | Value |
|---|---|
| Keys per browser page | 100 by default, 1 to 500 |
| String value | up to 64 KB |
| Hash and set items | up to 200 |
| List and sorted set items | 100 per page |
| Stream entries | 50 |
| Each collection item | up to 4 KB |
| SLOWLOG | last 25 |
| Big-key sample | 1,000 keys, shows the 20 largest |
| Keys deleted | 20 per minute per client |
| Connect / per-command timeout | 5 s / 10 s |
Confirmations
- Deleting a key or a hash field asks for confirmation.
- Deleting more than one key asks you to type the number of keys.
Audit
- Web: every write, TTL change, rename and delete goes to the organization audit log, in the database: who, when, client, database, key name (and field) and the value size in bytes, never the value. For a multi-key delete, the count and the first 50 names.
- Desktop: the same actions go to the kubepier-audit.log file, in the app data folder, with the key names and the result.
Redis commands
Web and desktop use the same allowlist, checked before every command leaves. Any command outside it is refused. There is no free-form command console.
| Command | Used for | Status |
|---|---|---|
| PING, INFO, DBSIZE | Status, latency, memory, clients, keyspace and the INFO tab | Accepted (read) |
| SELECT | Pick the connection’s database | Accepted (read) |
| SCAN … MATCH … COUNT | Key browser and the big-key sample | Accepted (read) |
| TYPE, TTL, PTTL | Type and expiry of each key | Accepted (read) |
| MEMORY USAGE, MEMORY STATS | Per-key memory and the overview (only these two subcommands) | Accepted (read) |
| STRLEN, GET, GETRANGE | String value; big strings only up to 64 KB | Accepted (read) |
| HLEN, HSCAN | Hash fields, up to 200 | Accepted (read) |
| LLEN, LRANGE | List items | Accepted (read) |
| SCARD, SSCAN | Set members, up to 200 | Accepted (read) |
| ZCARD, ZRANGE … WITHSCORES | Sorted set members, always with scores | Accepted (read) |
| XLEN, XRANGE | Stream entries, up to 50 | Accepted (read) |
| SLOWLOG GET | SLOWLOG tab (command and key, never the values); GET subcommand only | Accepted (read) |
| SET | Write a string: plain SET, or with EX for a new TTL, or with PX to keep the key’s existing TTL (works on any Redis version) | Accepted (write, admin) |
| HSET, HDEL | Write and delete a hash field | Accepted (write, admin) |
| EXPIRE, PERSIST | Set or remove the TTL | Accepted (write, admin) |
| RENAMENX | Rename without overwriting another key | Accepted (write, admin) |
| UNLINK | Delete keys without blocking the server | Accepted (write, admin) |
| FLUSHALL, FLUSHDB | Would wipe the whole database at once | Refused |
| KEYS | Blocks the server on large databases; Kubepier uses SCAN | Refused |
| DEL, RENAME | Have safe versions on the list (UNLINK, RENAMENX) | Refused |
| CONFIG, DEBUG, SHUTDOWN, MIGRATE | Change the configuration, move data or bring the server down | Refused |
| EVAL, EVALSHA, FUNCTION, SCRIPT | Would run arbitrary code on the server | Refused |
| MONITOR | Would show every client’s traffic and values | Refused |
| ACL, CLIENT (including CLIENT KILL) | Touch the server’s users and connections | Refused |
| Other MEMORY and SLOWLOG subcommands (DOCTOR, RESET…) | Beyond what the screen needs | Refused |
| Any other command | There is no free console | Refused |
Write commands only pass in write mode: on the web, in the paid-plan admin routes; on desktop, on the Pro and Team plans (from 2.7.0, admins only). A refused command comes back as "command not allowed" (403 on the web) and never reaches Redis.
On connect, the Redis client also sends AUTH (password or ACL user).
Permissions you need on your side
With ACLs (Redis 6 or newer), create a user just for Kubepier with these commands. On Redis without ACLs, the password (AUTH) is enough.
# Read-only (status, key browser, INFO, SLOWLOG)
ACL SETUSER kubepier on >PASSWORD ~* -@all +ping +info +dbsize +select \
+scan +type +ttl +pttl +memory|usage +memory|stats +strlen +get +getrange \
+hlen +hscan +llen +lrange +scard +sscan +zcard +zrange +xlen +xrange +slowlog|get
# Editing (Pro/Team; admin): add
ACL SETUSER kubepier +set +hset +hdel +expire +persist +renamenx +unlink Without MEMORY USAGE (disabled on some managed services), per-key memory shows empty. On Azure Cache for Redis, the access key works as the password.
Azure Cache for Redis (port 6380, TLS) and connection route
In the Redis form, pick the Connection route. Direct: allow the egress IPs on the firewall (Azure Cache: Firewall; port 6380 with TLS). Through the cluster: for caches with a private endpoint, ElastiCache or Memorystore, through a relay in a cluster on the same network. On the Direct route, a host that resolves only to a private IP answers host_privado right away, without trying to connect. A connection closed by the server (conexao_encerrada) is usually a firewall without the egress IPs, the wrong TLS setting or port, or a connection limit: allow the IPs or switch to Through the cluster. A wrong password is not a closed connection: since 2026-10-05 on the web, and from 2.3.0 on desktop, it shows as an authentication error (WRONGPASS).
Common errors
- WRONGPASS (invalid username-password pair) or NOAUTH: an authentication error: the saved password (or ACL user) is wrong, or the password is missing. It is not the network: fix the credential in the client form. On Azure Cache, paste the whole connection string copied from Access keys of the right cache, not just the key, so a dev key does not get mixed with the prd host. On the web, the status shows the Redis message and actions answer "no permission on the service". On desktop up to 2.2.0, this case shows as Connection is closed.
- "no permission on the service" / NOPERM: a command from the ACL above is missing.
- "The key is of type …": the key exists with another type; Kubepier does not overwrite it.
- "A key with that name already exists": pick another name.
- "too many deletions" (429 on the web): 20 keys deleted per minute per client.
- "command not allowed": the command is outside the allowlist; others cannot be enabled.
- Connection or TLS error: check host, port and TLS (Azure Cache: 6380 with TLS) and, on the web, the egress IPs.