---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "End users"
description: "The `end_users` collection of Sylphx Auth: An End User is a user of a customer's app, never a Sylphx member or principal."
type: reference
product: auth
summary: "An End User is a user of a customer's app, never a Sylphx member or principal."
updated: 2026-09-28
order: 900
---

An End User is a user of a customer's app, never a Sylphx member or principal. `(scope, email)` is unique among live end users. Delete is revocation: it revokes every session and refuses new ones.

**Service** Sylphx Auth · **Resource type** `auth.sylphx.com/EndUser` · **Name pattern** `orgs/{org}/projects/{project}/envs/{env}/end_users/{end_user}` · **Shape** `record`

## Fields

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/end_users/{end_user}`. |
| `uid` | `string` | `usr_<cell><ulid>`; never reused. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `email` | `string` | The primary email address. |
| `email_verify_time` | `timestamp` | When `email` was verified. Output only. |
| `password` | `string` | An initial password; write-only, checked against breached passwords. Never returned again. |
| `state` | `EndUserState` | The lifecycle state. Output only. One of `active`, `suspended`. |
| `factors` | `AuthMethod[]` | Enrolled factors. Output only. One of `password`, `magic_link`, `email_otp`, `passkey`, `totp`, `oidc`, `saml`. |
| `public_metadata` | `struct` | App data readable by the end user's own tokens. |
| `private_metadata` | `struct` | App data readable only with an Access key. |
| `last_login_time` | `timestamp` | The last successful sign-in. Output only. |
| `unsafe_metadata` | `struct` | App data the end user may write with their own session (preferences a sign-up form collects); never trust it for authorization. |
| `lock_expire_time` | `timestamp` | Until when sign-in is locked after repeated failures; unset when not locked. Unlock clears it; a suspension is `state`, not a lock. Output only. |

## Methods

Every method of the collection, in the registry's order, with the scope it
needs. The full request, response and examples are one link away.

| Method | Call | What it does |
| --- | --- | --- |
| `GET` | [`get`](/docs/api/end_users#get) | Gets an end user. |
| `GET` | [`list`](/docs/api/end_users#list) | Lists end users. |
| `POST` | [`create`](/docs/api/end_users#create) | Creates an end user. |
| `PATCH` | [`update`](/docs/api/end_users#update) | Updates an end user. |
| `DELETE` | [`delete`](/docs/api/end_users#delete) | Deletes an end user. |
| `POST` | [`suspend`](/docs/api/end_users#suspend) | Suspends an end user: sessions are revoked and sign-in is refused. |
| `POST` | [`reactivate`](/docs/api/end_users#reactivate) | Reactivates a suspended end user. |
| `POST` | [`unlock`](/docs/api/end_users#unlock) | Clears an end user's sign-in lock (repeated failed sign-ins) now. |
| `POST` | [`revoke_sessions`](/docs/api/end_users#revoke-sessions) | Revokes every session of an end user. |

## get

Gets an end user.

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user` · scope `auth:read` · effect `read` · [Request, response and examples](/docs/api/end_users/get)

## list

Lists end users.

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users` · scope `auth:read` · effect `read` · paginated · [Request, response and examples](/docs/api/end_users/list)

## create

Creates an end user.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users` · scope `auth:write` · effect `write` · [Request, response and examples](/docs/api/end_users/create)

## update

Updates an end user.

`PATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user` · scope `auth:write` · effect `write` · [Request, response and examples](/docs/api/end_users/update)

## delete

Deletes an end user.

`DELETE https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user` · scope `auth:write` · effect `destructive` · [Request, response and examples](/docs/api/end_users/delete)

## suspend

Suspends an end user: sessions are revoked and sign-in is refused.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user:suspend` · scope `auth:write` · effect `destructive` · [Request, response and examples](/docs/api/end_users/suspend)

## reactivate

Reactivates a suspended end user.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user:reactivate` · scope `auth:write` · effect `write` · [Request, response and examples](/docs/api/end_users/reactivate)

## unlock

Clears an end user's sign-in lock (repeated failed sign-ins) now.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user:unlock` · scope `auth:write` · effect `write` · [Request, response and examples](/docs/api/end_users/unlock)

## revoke_sessions

Revokes every session of an end user.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user:revokeSessions` · scope `auth:write` · effect `destructive` · [Request, response and examples](/docs/api/end_users/revoke_sessions)
