---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "Update an auth config"
description: "`auth.auth_configs.update` (PATCH /v1/{auth_config.name}): Updates an auth config."
type: reference
product: auth
summary: "Updates an auth config."
updated: 2026-09-28
nav: false
---

> **This method is not served on the public API.** `api.sylphx.com` does not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.

Updates an auth config.

- **Path** `PATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/auth_configs/auth-config`
- **Scope** `auth:write`
- **Effect** `write` — a successful call changes state.
- **Collection** [auth_configs](/docs/api/auth_configs)
- **Query** `update_mask`, `allow_missing`, `validate_only`

## Request

| Field | Type | What it is |
| --- | --- | --- |
| `auth_config` | `AuthConfig` | The auth config to update; `name` identifies it. Required. |
| `update_mask` | `field_mask` | The fields to write; unset writes every populated field. |
| `allow_missing` | `bool` | Create the auth config when it does not exist (declarative upsert). |
| `validate_only` | `bool` | Validate and return the result without writing anything. |

### AuthConfig

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/auth_configs/{auth_config}`. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `spec` | `AuthConfigSpec` | Desired state. Required. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |

### AuthConfigSpec

| Field | Type | What it is |
| --- | --- | --- |
| `auth_methods` | `AuthMethod[]` | Sign-in methods offered to end users. One of `password`, `magic_link`, `email_otp`, `passkey`, `totp`, `oidc`, `saml`. |
| `mfa_required` | `bool` | Require a second factor for every end user. |
| `passkey_policy` | `PasskeyPolicy` | Passkey policy; unset enforces nothing. |
| `lockout_enabled` | `bool` | Progressive lockout by user and IP. |
| `session_policy` | `SessionPolicy` | Session limits. |
| `captcha_secret` | `string` | The CAPTCHA verifier secret, held in Sylphx Secrets; unset disables CAPTCHA. |
| `portal` | `PortalConfig` | Account Portal origin and branding. |
| `mail_sending_domain` | `string` | The Notify Sending Domain Auth mail is sent from; unset uses the Sylphx default. |
| `user_sync_database` | `string` | A Sylphx Data database end users are synced into; unset disables sync. |

### PasskeyPolicy

| Field | Type | What it is |
| --- | --- | --- |
| `required` | `bool` | Require a passkey for every end user. |
| `device_bound` | `bool` | Refuse synced (multi-device) passkeys. |
| `aaguid_allowlist` | `string[]` | Allowed authenticator AAGUIDs; empty allows any. |

### SessionPolicy

| Field | Type | What it is |
| --- | --- | --- |
| `max_concurrent_sessions` | `int32` | Concurrent sessions per end user; excess sessions are revoked, oldest first. 0 is unlimited. |
| `idle_timeout` | `duration` | Revoke after this long without use; default 30d. |
| `absolute_timeout` | `duration` | Revoke this long after sign-in regardless of use; default 90d. |
| `fingerprint_binding` | `bool` | Bind sessions to network and agent; a mismatch demands step-up. |

### PortalConfig

| Field | Type | What it is |
| --- | --- | --- |
| `custom_domain` | `string` | A verified Network Domain serving the portal; unset uses the default origin. |
| `product_title` | `string` | The product name shown to end users. |
| `logo_uri` | `string` | An HTTPS logo URI. |
| `primary_color` | `string` | The primary color, `#rrggbb`. |
| `sylphx_branding` | `bool` | Show Sylphx branding. |

## Response

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/auth_configs/{auth_config}`. |
| `uid` | `string` | `acf_<cell><ulid>`; never reused. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `spec` | `AuthConfigSpec` | Desired state. Required. |
| `status` | `AuthConfigStatus` | Observed state. Output only. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `generation` | `int64` | Increases by one on every change to `spec`. Output only. |
| `etag` | `string` | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as `If-Match` or `etag` to make Update and Delete conditional; a mismatch fails with ABORTED / 409 `ETAG_MISMATCH`. Output only. |
| `create_time` | `timestamp` | When the Resource was created. Output only. |
| `update_time` | `timestamp` | When the Resource last changed. Output only. |
| `delete_time` | `timestamp` | Set while the Resource is being deleted. Output only. |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |
| `creator` | `string` | The principal that created the Resource. Output only. |

### AuthConfigSpec

| Field | Type | What it is |
| --- | --- | --- |
| `auth_methods` | `AuthMethod[]` | Sign-in methods offered to end users. One of `password`, `magic_link`, `email_otp`, `passkey`, `totp`, `oidc`, `saml`. |
| `mfa_required` | `bool` | Require a second factor for every end user. |
| `passkey_policy` | `PasskeyPolicy` | Passkey policy; unset enforces nothing. |
| `lockout_enabled` | `bool` | Progressive lockout by user and IP. |
| `session_policy` | `SessionPolicy` | Session limits. |
| `captcha_secret` | `string` | The CAPTCHA verifier secret, held in Sylphx Secrets; unset disables CAPTCHA. |
| `portal` | `PortalConfig` | Account Portal origin and branding. |
| `mail_sending_domain` | `string` | The Notify Sending Domain Auth mail is sent from; unset uses the Sylphx default. |
| `user_sync_database` | `string` | A Sylphx Data database end users are synced into; unset disables sync. |

### AuthConfigStatus

| Field | Type | What it is |
| --- | --- | --- |
| `observed_generation` | `int64` | The generation this status was computed from. Output only. |
| `conditions` | `Condition[]` | Ready, Reconciling, Stalled. Output only. |
| `portal_origin` | `string` | The Account Portal origin in use. Output only. |
| `issuer_uri` | `string` | The OAuth issuer URI; tokens verify from its JWKS. Output only. |

### PasskeyPolicy

| Field | Type | What it is |
| --- | --- | --- |
| `required` | `bool` | Require a passkey for every end user. |
| `device_bound` | `bool` | Refuse synced (multi-device) passkeys. |
| `aaguid_allowlist` | `string[]` | Allowed authenticator AAGUIDs; empty allows any. |

### SessionPolicy

| Field | Type | What it is |
| --- | --- | --- |
| `max_concurrent_sessions` | `int32` | Concurrent sessions per end user; excess sessions are revoked, oldest first. 0 is unlimited. |
| `idle_timeout` | `duration` | Revoke after this long without use; default 30d. |
| `absolute_timeout` | `duration` | Revoke this long after sign-in regardless of use; default 90d. |
| `fingerprint_binding` | `bool` | Bind sessions to network and agent; a mismatch demands step-up. |

### PortalConfig

| Field | Type | What it is |
| --- | --- | --- |
| `custom_domain` | `string` | A verified Network Domain serving the portal; unset uses the default origin. |
| `product_title` | `string` | The product name shown to end users. |
| `logo_uri` | `string` | An HTTPS logo URI. |
| `primary_color` | `string` | The primary color, `#rrggbb`. |
| `sylphx_branding` | `bool` | Show Sylphx branding. |

### Condition

| Field | Type | What it is |
| --- | --- | --- |
| `type` | `string` | The condition type, for example `Ready`. |
| `status` | `ConditionStatus` | Whether the condition holds. One of `true`, `false`, `unknown`. |
| `observed_generation` | `int64` | The generation this observation was made against. |
| `reason` | `string` | A machine-readable UpperCamelCase reason. |
| `message` | `string` | A customer-safe human-readable message. |
| `severity` | `Severity` | How severe a FALSE condition is. One of `info`, `warning`, `error`. |
| `transition_time` | `timestamp` | When `status` last changed. |

## Errors

- [`UNAUTHENTICATED`](/docs/api/errors/UNAUTHENTICATED) — No valid key or token was presented.
- [`PERMISSION_DENIED`](/docs/api/errors/PERMISSION_DENIED) — The key lacks the method's permission.
- [`RESOURCE_NOT_FOUND`](/docs/api/errors/RESOURCE_NOT_FOUND) — The named Resource does not exist or is not visible.
- [`UNKNOWN_FIELD`](/docs/api/errors/UNKNOWN_FIELD) — The request has a field the schema does not know.
- [`INVALID_FIELD`](/docs/api/errors/INVALID_FIELD) — A field failed validation.
- [`ETAG_MISMATCH`](/docs/api/errors/ETAG_MISMATCH) — The etag sent does not match the Resource's current etag.
- [`IDEMPOTENCY_KEY_REUSED`](/docs/api/errors/IDEMPOTENCY_KEY_REUSED) — An Idempotency-Key was reused with another body.
- [`IDEMPOTENCY_IN_PROGRESS`](/docs/api/errors/IDEMPOTENCY_IN_PROGRESS) — The first call with this Idempotency-Key is still running.

Every error arrives in the body [Errors](/docs/platform/errors) describes.

## Examples

**cURL**

```curl
curl -X PATCH "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/auth_configs/auth-config" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name":"orgs/acme/projects/shop/envs/production/auth_configs/auth-config","spec":{}}'
```

**TypeScript**

```ts
const response = await sylphx.auth.authConfigs.update({ authConfig: { name: 'orgs/acme/projects/shop/envs/production/auth_configs/auth-config', spec: {} } })
```

**Rust**

```rust
let mut req = sylphx::auth::UpdateAuthConfigRequest::default();
req.auth_config = Some(sylphx::auth::AuthConfig {
    name: "orgs/acme/projects/shop/envs/production/auth_configs/auth-config".to_string(),
    spec: Some(Default::default()),
    ..Default::default()
});
let response = sx.auth().auth_configs().update(req).await?;
```

**CLI**

```bash
sylphx auth auth-configs update orgs/acme/projects/shop/envs/production/auth_configs/auth-config
```

**MCP**

```json
{ "method_id": "auth.auth_configs.update", "args": {"auth_config":{"name":"orgs/acme/projects/shop/envs/production/auth_configs/auth-config","spec":{}}} }
```
