Skip to content
Console
Menu

Queues

Workflows

Getting Started

Authentication

KV Store

Revoke an API key

Revokes an API key immediately; revocation propagates on its own fast path, ahead of the bulk key data.

This method is not served on the public API. api.sylphx.com does not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.

Revokes an API key immediately; revocation propagates on its own fast path, ahead of the bulk key data.

  • Path POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/api_keys/api-key:revoke
  • Scope access:keys:write
  • Effect destructive — a successful call removes data; the CLI asks before it runs.
  • Collection api_keys

#Request

FieldTypeWhat it is
namestringThe name of the API key to revoke. Required.
etagstringRevoke only if the current etag matches.
validate_onlyboolValidate without revoking.

#Response

FieldTypeWhat it is
namestringorgs/{org}/projects/{project}/envs/{env}/api_keys/{api_key}, or orgs/{org}/api_keys/{api_key} for an org-wide key.
uidstringkey_<cell><ulid>; equals the name segment. Output only.
metaResourceMetaResource metadata.
specApiKeySpecDesired state. Required.
statusApiKeyStatusObserved state. Output only.

#ResourceMeta

FieldTypeWhat it is
generationint64Increases by one on every change to spec. Output only.
etagstringStrong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as If-Match or etag to make Update and Delete conditional; a mismatch fails with ABORTED / 409 ETAG_MISMATCH. Output only.
create_timetimestampWhen the Resource was created. Output only.
update_timetimestampWhen the Resource last changed. Output only.
delete_timetimestampSet while the Resource is being deleted. Output only.
labelsmap<string, string>Caller-writable, indexed labels (AIP-122 label rules).
annotationsmap<string, string>Caller-writable, unindexed annotations.
display_namestringCaller-writable human-readable name.
creatorstringThe principal that created the Resource. Output only.

#ApiKeySpec

FieldTypeWhat it is
kindApiKeyKindSecret (server-side) or publishable (browser, publishable_ok methods only). Required. One of secret, publishable.
scopesstring[]Scopes <service>:<action>, a subset of the creator's effective scopes. Required.
labelstringA free-form label, for example the talent id a key was minted for.
expire_timetimestampWhen the key stops verifying; required in unclaimed projects.

#ApiKeyStatus

FieldTypeWhat it is
observed_generationint64The generation this status was computed from. Output only.
conditionsCondition[]Ready, Reconciling, Stalled. Output only.
secretstringThe full key. Set only in the responses of Create and Roll. Output only. Never returned again.
last4stringThe last four characters, for display. Output only.
principalstringThe key's own principal. Output only.
revoke_timetimestampSet when the key was revoked. Output only.
revoke_reasonRevokeReasonWhy the key was revoked. Output only. One of user, rotation, leaked, claimed, claim_expired, org_deleted, admin, role_changed, logout.
last_use_timetimestampWhen the key last verified, at snapshot granularity. Output only.
last_use_ipstringThe client address of the key's last use. Output only.
role_boundboolA device key (sylphx login): bound to the approving human's role in the org, and revoked when that role changes or the human leaves. Output only.

#Condition

FieldTypeWhat it is
typestringThe condition type, for example Ready.
statusConditionStatusWhether the condition holds. One of true, false, unknown.
observed_generationint64The generation this observation was made against.
reasonstringA machine-readable UpperCamelCase reason.
messagestringA customer-safe human-readable message.
severitySeverityHow severe a FALSE condition is. One of info, warning, error.
transition_timetimestampWhen status last changed.

#Errors

Every error arrives in the body Errors describes.

#Examples

curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/api_keys/api-key:revoke" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{}'