Skip to content
Console
Menu

Queues

Workflows

Getting Started

Authentication

KV Store

Get an auth config

Gets an auth config.

This method is not served on the public API. api.sylphx.com does not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.

Gets an auth config.

  • Path GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/auth_configs/auth-config
  • Scope auth:read
  • Effect read — nothing is written.
  • Collection auth_configs

#Request

FieldTypeWhat it is
namestringThe name of the auth config to get. Required.

#Response

FieldTypeWhat it is
namestringorgs/{org}/projects/{project}/envs/{env}/auth_configs/{auth_config}.
uidstringacf_<cell><ulid>; never reused. Output only.
metaResourceMetaResource metadata.
specAuthConfigSpecDesired state. Required.
statusAuthConfigStatusObserved state. Output only.

#ResourceMeta

FieldTypeWhat it is
generationint64Increases by one on every change to spec. Output only.
etagstringStrong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as If-Match or etag to make Update and Delete conditional; a mismatch fails with ABORTED / 409 ETAG_MISMATCH. Output only.
create_timetimestampWhen the Resource was created. Output only.
update_timetimestampWhen the Resource last changed. Output only.
delete_timetimestampSet while the Resource is being deleted. Output only.
labelsmap<string, string>Caller-writable, indexed labels (AIP-122 label rules).
annotationsmap<string, string>Caller-writable, unindexed annotations.
display_namestringCaller-writable human-readable name.
creatorstringThe principal that created the Resource. Output only.

#AuthConfigSpec

FieldTypeWhat it is
auth_methodsAuthMethod[]Sign-in methods offered to end users. One of password, magic_link, email_otp, passkey, totp, oidc, saml.
mfa_requiredboolRequire a second factor for every end user.
passkey_policyPasskeyPolicyPasskey policy; unset enforces nothing.
lockout_enabledboolProgressive lockout by user and IP.
session_policySessionPolicySession limits.
captcha_secretstringThe CAPTCHA verifier secret, held in Sylphx Secrets; unset disables CAPTCHA.
portalPortalConfigAccount Portal origin and branding.
mail_sending_domainstringThe Notify Sending Domain Auth mail is sent from; unset uses the Sylphx default.
user_sync_databasestringA Sylphx Data database end users are synced into; unset disables sync.

#AuthConfigStatus

FieldTypeWhat it is
observed_generationint64The generation this status was computed from. Output only.
conditionsCondition[]Ready, Reconciling, Stalled. Output only.
portal_originstringThe Account Portal origin in use. Output only.
issuer_uristringThe OAuth issuer URI; tokens verify from its JWKS. Output only.

#PasskeyPolicy

FieldTypeWhat it is
requiredboolRequire a passkey for every end user.
device_boundboolRefuse synced (multi-device) passkeys.
aaguid_allowliststring[]Allowed authenticator AAGUIDs; empty allows any.

#SessionPolicy

FieldTypeWhat it is
max_concurrent_sessionsint32Concurrent sessions per end user; excess sessions are revoked, oldest first. 0 is unlimited.
idle_timeoutdurationRevoke after this long without use; default 30d.
absolute_timeoutdurationRevoke this long after sign-in regardless of use; default 90d.
fingerprint_bindingboolBind sessions to network and agent; a mismatch demands step-up.

#PortalConfig

FieldTypeWhat it is
custom_domainstringA verified Network Domain serving the portal; unset uses the default origin.
product_titlestringThe product name shown to end users.
logo_uristringAn HTTPS logo URI.
primary_colorstringThe primary color, #rrggbb.
sylphx_brandingboolShow Sylphx branding.

#Condition

FieldTypeWhat it is
typestringThe condition type, for example Ready.
statusConditionStatusWhether the condition holds. One of true, false, unknown.
observed_generationint64The generation this observation was made against.
reasonstringA machine-readable UpperCamelCase reason.
messagestringA customer-safe human-readable message.
severitySeverityHow severe a FALSE condition is. One of info, warning, error.
transition_timetimestampWhen status last changed.

#Errors

Every error arrives in the body Errors describes.

#Examples

curl "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/auth_configs/auth-config" \
  -H "Authorization: Bearer $SYLPHX_API_KEY"