Skip to content
Console
Menu

Queues

Workflows

Getting Started

Authentication

KV Store

End users

An End User is a user of a customer's app, never a Sylphx member or principal.

An End User is a user of a customer's app, never a Sylphx member or principal. (scope, email) is unique among live end users. Delete is revocation: it revokes every session and refuses new ones.

Service Sylphx Auth · Resource type auth.sylphx.com/EndUser · Name pattern orgs/{org}/projects/{project}/envs/{env}/end_users/{end_user} · Shape record

#Fields

FieldTypeWhat it is
namestringorgs/{org}/projects/{project}/envs/{env}/end_users/{end_user}.
uidstringusr_<cell><ulid>; never reused. Output only.
metaResourceMetaResource metadata.
emailstringThe primary email address.
email_verify_timetimestampWhen email was verified. Output only.
passwordstringAn initial password; write-only, checked against breached passwords. Never returned again.
stateEndUserStateThe lifecycle state. Output only. One of active, suspended.
factorsAuthMethod[]Enrolled factors. Output only. One of password, magic_link, email_otp, passkey, totp, oidc, saml.
public_metadatastructApp data readable by the end user's own tokens.
private_metadatastructApp data readable only with an Access key.
last_login_timetimestampThe last successful sign-in. Output only.
unsafe_metadatastructApp data the end user may write with their own session (preferences a sign-up form collects); never trust it for authorization.
lock_expire_timetimestampUntil when sign-in is locked after repeated failures; unset when not locked. Unlock clears it; a suspension is state, not a lock. Output only.

#Methods

Every method of the collection, in the registry's order, with the scope it needs. The full request, response and examples are one link away.

MethodCallWhat it does
GETgetGets an end user.
GETlistLists end users.
POSTcreateCreates an end user.
PATCHupdateUpdates an end user.
DELETEdeleteDeletes an end user.
POSTsuspendSuspends an end user: sessions are revoked and sign-in is refused.
POSTreactivateReactivates a suspended end user.
POSTunlockClears an end user's sign-in lock (repeated failed sign-ins) now.
POSTrevoke_sessionsRevokes every session of an end user.

#get

Gets an end user.

GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user · scope auth:read · effect read · Request, response and examples

#list

Lists end users.

GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users · scope auth:read · effect read · paginated · Request, response and examples

#create

Creates an end user.

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users · scope auth:write · effect write · Request, response and examples

#update

Updates an end user.

PATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user · scope auth:write · effect write · Request, response and examples

#delete

Deletes an end user.

DELETE https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user · scope auth:write · effect destructive · Request, response and examples

#suspend

Suspends an end user: sessions are revoked and sign-in is refused.

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user:suspend · scope auth:write · effect destructive · Request, response and examples

#reactivate

Reactivates a suspended end user.

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user:reactivate · scope auth:write · effect write · Request, response and examples

#unlock

Clears an end user's sign-in lock (repeated failed sign-ins) now.

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user:unlock · scope auth:write · effect write · Request, response and examples

#revoke_sessions

Revokes every session of an end user.

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user:revokeSessions · scope auth:write · effect destructive · Request, response and examples