> ## Documentation Index
> Fetch the complete documentation index at: https://docs.forge.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Redis

> Protect Redis connections and commands.

Direct clients connect to the Resource gateway over TLS on TCP `6379`. Use the
Resource access name as the ACL username and a short-lived Forge token as the
password.

```sh theme={"system"}
redis-cli --tls \
  --cacert forge-resource-ca.pem \
  --host resources.example.com \
  --port 6379 \
  --user production-cache \
  --pass "$(forge resources token production-cache)"
```

With automatic routing, keep the destination hostname and ordinary client
command.

## Policy fields and actions

Forge supports RESP2 and RESP3 ordinary commands and buffered pipelines. It can
match the selected logical database, destination ACL user, and uppercase
top-level command. Connections and commands can be allowed, flagged, approved,
or blocked.

Keys, arguments, values, and replies are not retained or available as policy
fields. Redis response transformation is not supported.

## Destination authentication

The gateway uses the Redis ACL username and password assigned to the caller.
The caller's Forge credential is never forwarded to Redis. Destination TLS and
hostname verification are always required.

## Current limits

Transactions, Pub/Sub, `MONITOR`, Cluster or Sentinel routing, inline or
streamed RESP, key/value inspection, and response transformation are not
supported. Unsupported modes fail explicitly.

See [Credentials and identity](/resources/credentials-and-identity) and
[Resource Policies](/secure/resource-policies).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.