Sign in Start free trial
← Help centre

Restore Safenix files at a specific date and time

Restore files from a Safenix recovery point selected by its exact UTC date and time, without changing the current filesystem.

Restore files at a precise time by selecting a recovery point with --at. The restore can run on any machine; the original server is not required.

What you need

You need exactly these four items:

  • the server identifier: SAFENIX_AGENT_ID
  • the encryption password: SAFENIX_ENCRYPTION_PASSWORD
  • the control-plane address: SAFENIX_CONTROL_PLANE_URL
  • a restore credential issued from the dashboard, beginning with sk_restore_: SAFENIX_API_TOKEN

The restore credential is issued from the dashboard under Credential for the relevant server. It is read-only, applies only to that server, and expires after 12 hours by default, with a maximum lifetime of 72 hours. It does not contain the encryption password.

The token used by the agent to upload backups cannot be used for restore. It can write backups but cannot read them, including on the original machine. Reading a backup always requires a restore credential issued from the dashboard.

1. Check the available recovery points

List the available recovery points before choosing the time to restore:

safenix-agent snapshots

The command lists each recovery point's date and time in UTC, identifier, size, file count, and protected paths.

2. Restore the selected date and time

Use an RFC3339 timestamp. This example restores the recovery point at 19:00 UTC on 12 August 2026:

safenix-agent restore --output-dir ./restore --at 2026-08-12T19:00:00Z

Replace the timestamp with the UTC date and time of the recovery point you need. If you omit --at, Safenix uses the most recent recovery point.

Restore only selected paths

To restore only part of the backup, provide the paths with --paths:

safenix-agent restore --output-dir ./restore --paths /etc,/var/www

Use --output-dir to specify where the restored files go. All restored files are written inside that directory. Nothing is written outside it, so the filesystem currently in use remains unchanged.

Without --output-dir, the command does not restore anything. It only lists what is available and states that explicitly.

After the restore

Safenix does not automatically put restored files back in their original locations. This is deliberate: the operator decides the final step. A notes file is written together with the restored files and contains commands ready to copy them where they are needed.

Still stuck?

If this page did not solve it, write to us and a person answers.

Contact