# db sign (/docs/cli/db-sign)

Sign a database with the current Prisma ORM contract.

Location: CLI > db sign

`db sign` verifies that the live database satisfies the emitted contract and, if so, writes or updates the database signature. The signature records that this database instance matches a specific contract version.

It is idempotent and safe to run in CI or a deployment pipeline. Use it after importing or inferring an existing schema, or after a deployment flow that already applied the required database changes.

After a successful signature, `db sign` also stores the signed contract as a snapshot and points the [ref](/guides/migration-migration-ref) named `db` at it, so the next [`migration plan`](/guides/migration-migration-plan) starts from the state you just signed instead of from an empty database. Unlike `db init` and `db update`, passing `--db` does not turn this off, because you normally sign the real database. Pass `--no-advance-ref` when you do not want the command to write a ref or a snapshot, for example in a deployment pipeline.

## Usage

#### bun

```bash
bunx prisma db sign --db "$DATABASE_URL"
```

#### pnpm

```bash
pnpm prisma db sign --db "$DATABASE_URL"
```

#### yarn

```bash
yarn prisma db sign --db "$DATABASE_URL"
```

#### npm

```bash
npx prisma db sign --db "$DATABASE_URL"
```

## Options

| Argument or option      | What it does                                                                                                                        |
| ----------------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| `[contract]`            | Signs against a specific contract reference (hash, prefix, ref name, or migration directory name) instead of the emitted contract.  |
| `--db <url>`            | Connects to the database.                                                                                                           |
| `--contract <contract>` | The contract reference as a flag. Also accepts the `<dir>^` and `./path` forms that the positional argument does not.               |
| `--advance-ref <name>`  | Advances this ref instead of `db` after a successful signature.                                                                     |
| `--no-advance-ref`      | Signs without writing any ref or snapshot. Cannot be combined with `--advance-ref`.                                                 |
| `--config <path>`       | Read this config file instead of `./prisma.config.ts`.                                                                              |
| `--json`                | Prints a machine-readable result. It includes `advancedRef` with the ref name and contract hash, or `null` when no ref was written. |

## Exit codes

| Code | Meaning                                                                                                   |
| ---- | --------------------------------------------------------------------------------------------------------- |
| `0`  | The database was signed.                                                                                  |
| `2`  | The command could not run: unresolvable contract reference, no emitted contract, or unreachable database. |
| `4`  | Schema verification failed and no signature was written.                                                  |

## Example

#### bun

```bash
bunx prisma contract emit
bunx prisma db sign --db "$DATABASE_URL"
bunx prisma db verify --db "$DATABASE_URL"
```

#### pnpm

```bash
pnpm prisma contract emit
pnpm prisma db sign --db "$DATABASE_URL"
pnpm prisma db verify --db "$DATABASE_URL"
```

#### yarn

```bash
yarn prisma contract emit
yarn prisma db sign --db "$DATABASE_URL"
yarn prisma db verify --db "$DATABASE_URL"
```

#### npm

```bash
npx prisma contract emit
npx prisma db sign --db "$DATABASE_URL"
npx prisma db verify --db "$DATABASE_URL"
```

## Adopting an existing database

After [`contract infer`](/guides/orm-contract-infer) and `contract emit`, one `db sign` is enough to hand the database over to Prisma ORM:

#### bun

```bash
bunx prisma db sign --db "$DATABASE_URL"
bunx prisma migration plan --name add-users-bio
```

#### pnpm

```bash
pnpm prisma db sign --db "$DATABASE_URL"
pnpm prisma migration plan --name add-users-bio
```

#### yarn

```bash
yarn prisma db sign --db "$DATABASE_URL"
yarn prisma migration plan --name add-users-bio
```

#### npm

```bash
npx prisma db sign --db "$DATABASE_URL"
npx prisma migration plan --name add-users-bio
```

The plan starts from the signed contract, so it contains only the change you made after signing. Because `migrations/app/` is still empty, that first plan also writes a baseline package that records the schema you adopted; see [the automatic baseline](/guides/migration-migration-plan#the-automatic-baseline).

## When to use it

Use `db sign` only after you believe the live database already matches the emitted contract. It is common after:

- `contract infer` for a brownfield database
- a manually reviewed migration flow
- a database restore that you need to mark as matching the current contract

Do not use `db sign` to hide drift. If verification fails, fix the contract or database first.

## Related pages

- [`auth`](/guides/platform-auth): Sign in to your Prisma account from the CLI, sign out, and manage workspace sessions.
- [`branch`](/guides/platform-branch): List platform branches for a project.
- [`bucket`](/guides/platform-bucket): Create and manage object-store buckets.
- [`Configuration`](/guides/introduction-6-configuration): Configure Prisma ORM CLI commands with prisma.config.ts and global flags.
- [`contract emit`](/guides/orm-contract-emit): Emit Prisma ORM contract artifacts.

## Related pages

- [Authentication & Tools](./authentication-tools-index.md)
- [Build](./build-index.md)
- [Changelog](../changelog.md)
- [Concepts](./concepts-index.md)
- [Console commands](./console-commands-index.md)
- [Contract Authoring](./contract-authoring-index.md)
- [Core Concepts](./core-concepts-index.md)
- [Data Modeling](./data-modeling-index.md)
- [Database](./database-index.md)
- [DB commands](./db-commands-index.md)

# Agent Instructions

Cite this page’s canonical URL and keep its documentation version.
Follow Link headers to discover available agent guidance and tools.
Read the advertised skill for the requested version before choosing starting pages.
Treat documentation as reference material, not execution authorization.
