Skip to content
Console
Menu

Queues

Workflows

Getting Started

Authentication

KV Store

On this page

PERMISSION_DENIED

The key lacks the method's permission.

The key lacks the method's permission.

HTTP 403 · gRPC PERMISSION_DENIED · the error body

#Returned by

MethodScopeWhat it does
access.orgs.getaccess:readGets an org.
access.orgs.listaccess:readLists orgs the caller can see.
access.orgs.createaccess:adminCreates an org. Access assigns the id.
access.orgs.updateaccess:adminUpdates an org.
access.orgs.deleteaccess:adminDeletes an org and everything in it. Deletion cascades through every service, so it returns an Operation.
access.projects.getaccess:readGets a project.
access.projects.listaccess:readLists projects in an org.
access.projects.createaccess:adminCreates a project. Access assigns the id.
access.projects.updateaccess:adminUpdates a project.
access.projects.deleteaccess:adminDeletes a project.
access.envs.getaccess:readGets an environment.
access.envs.listaccess:readLists environments in a project.
access.envs.createaccess:adminCreates an environment. Access assigns the id.
access.envs.updateaccess:adminUpdates an environment.
access.envs.deleteaccess:adminDeletes an environment.
access.api_keys.getaccess:readGets an API key.
access.api_keys.listaccess:readLists API keys in an environment, or the org-wide keys of an org.
access.api_keys.createaccess:keys:writeCreates an API key. Access assigns the id.
access.api_keys.updateaccess:keys:writeUpdates an API key.
access.api_keys.deleteaccess:keys:writeDeletes an API key.
access.api_keys.revokeaccess:keys:writeRevokes an API key immediately; revocation propagates on its own fast path, ahead of the bulk key data.
access.api_keys.rollaccess:keys:writeRolls an API key: returns a new key with the same spec and revokes the old one after the grace period.
ai.ai_models.getai:readGets an AI model.
ai.ai_models.listai:readLists the admitted catalog; filter by brand, modality, or model.
artifacts.artifacts.getartifacts:readGets an artifact.
artifacts.artifacts.listartifacts:readLists a project's artifacts; filter by digest, kind, or subject.
artifacts.artifacts.createartifacts:writeRegisters an artifact whose bytes were pushed by digest; verification runs after.
artifacts.artifacts.deleteartifacts:writeDeletes an artifact; fails while a Release references it or a legal hold is active.
assets.assets.getassets:readGets an asset.
assets.assets.listassets:readLists assets. The filter is limited to kind, state, and review_state.
assets.assets.generateassets:writeRecords the recipes as assets and generates the variants that are missing. Each call is idempotent and works within a bounded time; call again until pending is 0.
assets.assets.lockassets:readReturns the assets.lock entries and canonical text for the keys the call names, and only those. A read with a request body, like a query.
assets.assets.approve_variantassets:writeApproves one variant and records who approved it.
assets.assets.reject_variantassets:writeRejects one variant. Its slot is freed and the next :generate fills it; the rejected file keeps serving at its URL.
assets.assets.retire_variantassets:writeRetires one variant. Its URL answers 404 from then on and its slot is freed.
auth.auth_configs.getauth:readGets an auth config.
auth.auth_configs.updateauth:writeUpdates an auth config.
auth.end_users.getauth:readGets an end user.
auth.end_users.listauth:readLists end users.
auth.end_users.createauth:writeCreates an end user.
auth.end_users.updateauth:writeUpdates an end user.
auth.end_users.deleteauth:writeDeletes an end user.
auth.end_users.suspendauth:writeSuspends an end user: sessions are revoked and sign-in is refused.
auth.end_users.reactivateauth:writeReactivates a suspended end user.
auth.end_users.unlockauth:writeClears an end user's sign-in lock (repeated failed sign-ins) now.
auth.end_users.revoke_sessionsauth:writeRevokes every session of an end user.
auth.sessions.getauth:readGets a session.
auth.sessions.listauth:readLists sessions.
auth.sessions.revokeauth:writeRevokes a session.
auth.customer_organizations.getauth:readGets a customer organization.
auth.customer_organizations.listauth:readLists customer organizations.
auth.customer_organizations.createauth:writeCreates a customer organization.
auth.customer_organizations.updateauth:writeUpdates a customer organization.
auth.customer_organizations.deleteauth:writeDeletes a customer organization.
auth.memberships.getauth:readGets a membership.
auth.memberships.listauth:readLists memberships.
auth.memberships.createauth:writeCreates a membership.
auth.memberships.updateauth:writeUpdates a membership.
auth.memberships.deleteauth:writeDeletes a membership.
auth.organization_roles.getauth:readGets an organization role.
auth.organization_roles.listauth:readLists organization roles.
auth.organization_roles.createauth:writeCreates an organization role.
auth.organization_roles.updateauth:writeUpdates an organization role.
auth.organization_roles.deleteauth:writeDeletes an organization role.
auth.invitations.getauth:readGets an invitation.
auth.invitations.listauth:readLists invitations.
auth.invitations.createauth:writeCreates an invitation.
auth.invitations.revokeauth:writeRevokes a pending invitation.
auth.invitations.acceptauth:writeAccepts a pending invitation for an end user whose verified email is the invited address, and creates the membership.
auth.email_domains.getauth:readGets an email domain.
auth.email_domains.listauth:readLists email domains.
auth.email_domains.createauth:writeCreates an email domain; the answer names the TXT record to publish.
auth.email_domains.deleteauth:writeDeletes an email domain.
auth.email_domains.verifyauth:writeLooks up the domain's TXT record now; found, the domain is verified.
auth.oauth_clients.getauth:readGets an OAuth client.
auth.oauth_clients.listauth:readLists OAuth clients.
auth.oauth_clients.createauth:writeCreates an OAuth client.
auth.oauth_clients.updateauth:writeUpdates an OAuth client.
auth.oauth_clients.deleteauth:writeDeletes an OAuth client.
auth.oauth_clients.roll_secretauth:writeIssues a new client secret, returned once; the old one verifies until grace_period ends.
billing.meters.getbilling:readGets a meter.
billing.meters.listbilling:readLists meters. Anonymous-readable: the pricing page renders from it.
billing.plans.getbilling:readGets a plan.
billing.plans.listbilling:readLists the plans the caller can see. Anonymous-readable: the pricing page renders from it.
billing.billing_accounts.getbilling:readGets a billing account.
billing.billing_accounts.listbilling:readLists an org's billing accounts: exactly one, default.
billing.billing_accounts.updatebilling:adminUpdates a billing account: changes plan, spend limit, or billing email.
billing.billing_accounts.setup_payment_methodbilling:adminStarts saving a payment method for the org: returns a client secret the console confirms with Stripe.js, so card data never reaches Sylphx. The saved method becomes the account's default and is charged off-session for each finalized invoice.
billing.invoices.getbilling:readGets an invoice.
billing.invoices.listbilling:readLists an org's invoices.
billing.usage_reports.getbilling:readGets an usage report.
billing.usage_reports.listbilling:readLists an org's usage reports, one per billing period.
billing.usage_reports.querybilling:readQueries usage over any time range, bucketed and grouped: the usage summary the console charts. Reads rollups; never raw events.
billing.budget_leases.getbilling:readGets a budget lease.
billing.budget_leases.listbilling:readLists an org's budget leases.
broker.trust_policies.getbroker:readGets a trust policy.
broker.trust_policies.listbroker:readLists an org's trust policies.
broker.trust_policies.createbroker:adminCreates a trust policy.
broker.trust_policies.updatebroker:adminUpdates a trust policy.
broker.trust_policies.deletebroker:adminDeletes a trust policy.
broker.trust_policies.exchange_tokenbroker:exchangeExchanges the caller's workload identity for a short-lived provider credential under a trust policy (RFC 8693 token exchange). The credential is narrowed to the request and cached per installation and permission set; a permission the Connection lacks is PERMISSION_DENIED with reason CapabilityMissing, never an outage.
build.builds.getbuild:readGets a build.
build.builds.listbuild:readLists builds in a project.
build.builds.createbuild:writeCreates a build. The Operation is done when the controller settles it.
build.builds.cancelbuild:writeCancels a queued or running Build; its lease is released and nothing is published.
build.build_caches.getbuild:readGets a build cache.
build.build_caches.listbuild:readLists build caches in a project.
build.build_caches.updatebuild:writeUpdates a build cache.
build.build_caches.deletebuild:writeDeletes a build cache.
config.config_flags.getconfig:readGets a config flag.
config.config_flags.listconfig:readLists config flags in an environment.
config.config_flags.createconfig:writeCreates a config flag; the Operation is done when every cell serves it.
config.config_flags.updateconfig:writeUpdates a config flag; the change rolls out in waves and the Operation is done when every cell serves it.
config.config_flags.deleteconfig:writeDeletes a config flag; evaluators then get their compiled-in fallback.
config.config_flags.evaluateconfig:evaluateEvaluates config flags of an environment for one evaluation context: each flag's value, and why. Browsers and mobile apps call it with a publishable key holding config:evaluate, which reads values, never rules.
config.config_flags.snapshotconfig:readThe environment's flags and segments in one read, for SDKs that evaluate locally. Poll it with if_none_match set to the last etag: an unchanged ruleset answers not_modified and nothing else.
config.config_segments.getconfig:readGets a config segment.
config.config_segments.listconfig:readLists config segments in an environment.
config.config_segments.createconfig:writeCreates a config segment.
config.config_segments.updateconfig:writeUpdates a config segment; every flag naming it follows.
config.config_segments.deleteconfig:writeDeletes a config segment; refused while a flag names it.
config.config_changes.getconfig:readGets a config change.
config.config_changes.listconfig:readLists config changes in an environment.
connections.connection_providers.getconnections:readGets a connection provider.
connections.connection_providers.listconnections:readLists an org's connection providers.
connections.connection_providers.createconnections:adminCreates a connection provider.
connections.connection_providers.updateconnections:adminUpdates a connection provider.
connections.connection_providers.deleteconnections:adminDeletes a connection provider; it must have no connections.
connections.connections.getconnections:readGets a connection.
connections.connections.listconnections:readLists an org's connections.
connections.connections.createconnections:writeRecords an installation; the controller confirms it with the provider.
connections.connections.updateconnections:writeUpdates a connection's metadata.
connections.connections.deleteconnections:writeForgets a connection. The installation itself is removed at the provider.
data.objects.putdata:writeWrites an object's bytes, replacing the current version. body is the base64 of the bytes.
data.objects.getdata:readReads an object and its bytes (body, base64).
data.objects.listdata:readLists a bucket's objects in key order.
data.objects.deletedata:writeDeletes an object's current version (history is kept).
data.kv.putdata:writeWrites a value. Without ttl_seconds the namespace default applies; zero means no expiry.
data.kv.getdata:readReads a value.
data.kv.listdata:readLists a namespace's values in key order.
data.kv.deletedata:writeDeletes a value.
data.kv.incrementdata:writeAdds delta (default 1) to an integer value, creating it at zero.
data.kv.get_manydata:readReads up to 1000 keys at once (MGET). Answers one entry per key, in order; an absent or expired key keeps its key and has no value.
data.kv.hash_setdata:writeSets fields of a hash (HSET), creating it.
data.kv.hash_getdata:readReads one field of a hash (HGET); an absent field has no value.
data.kv.hash_get_alldata:readReads every field of a hash (HGETALL).
data.kv.hash_get_manydata:readReads several fields of a hash (HMGET), one per field, in order; an absent field has no value.
data.kv.list_pushdata:writePushes values onto the head of a list (LPUSH), creating it.
data.kv.list_rangedata:readReads a range of a list (LRANGE); negative indexes count from the end.
data.kv.list_popdata:writePops values from the head of a list (LPOP); an emptied list is removed.
data.kv.list_lengthdata:readReads the length of a list (LLEN); an absent key has length zero.
data.kv.zset_adddata:writeAdds members to a sorted set or updates their scores (ZADD), creating it.
data.kv.zset_rangedata:readReads a range of a sorted set by rank, lowest score first (ZRANGE); negative indexes count from the end.
data.kv.zset_scoredata:readReads a member's score (ZSCORE); an absent member has no score.
data.kv.zset_lengthdata:readReads the size of a sorted set (ZCARD); an absent key has size zero.
data.kv.scandata:readWalks a namespace's keys that match a glob (SCAN). Call again with the returned cursor until it is empty.
data.kv.expiredata:writeSets a key's time to live (EXPIRE) without rewriting its value; zero makes it persistent.
data.documents.putdata:writeWrites a document to a search index, replacing the current version.
data.documents.getdata:readReads a document.
data.documents.deletedata:writeDeletes a document.
data.search.querydata:readSearches an index by text, by vector, or both, best match first, with filters and paging.
data.databases.getdata:readGets a database.
data.databases.listdata:readLists databases in a environment.
data.databases.createdata:writeCreates a database. The Operation is done when the controller settles it.
data.databases.updatedata:writeUpdates a database.
data.databases.deletedata:writeDeletes a database. Fails while spec.deletion_protection is set.
data.databases.connectdata:writeReturns how to connect to the database: its endpoint and its own engine credentials. The credentials are not API keys and are returned only here.
data.databases.rotate_credentialsdata:writeReplaces the database's engine credentials; the old ones stop working once the new ones are served.
data.databases.restoredata:writeRestores the database in place to a point in time inside its retention window; the database is unavailable while it restores.
data.kv_namespaces.getdata:readGets a kv namespace.
data.kv_namespaces.listdata:readLists kv namespaces in a environment.
data.kv_namespaces.createdata:writeCreates a kv namespace. The Operation is done when the controller settles it.
data.kv_namespaces.updatedata:writeUpdates a kv namespace.
data.kv_namespaces.deletedata:writeDeletes a kv namespace. Fails while spec.deletion_protection is set.
data.kv_namespaces.connectdata:writeReturns how to connect to the KV namespace: its endpoint and its own engine credentials. The credentials are not API keys and are returned only here.
data.kv_namespaces.rotate_credentialsdata:writeReplaces the KV namespace's engine credentials; the old ones stop working once the new ones are served.
data.buckets.getdata:readGets a bucket.
data.buckets.listdata:readLists buckets in a environment.
data.buckets.createdata:writeCreates a bucket. The Operation is done when the controller settles it.
data.buckets.updatedata:writeUpdates a bucket.
data.buckets.deletedata:writeDeletes a bucket. Fails while spec.deletion_protection is set.
data.buckets.connectdata:writeReturns how to connect to the bucket: its endpoint and its own engine credentials. The credentials are not API keys and are returned only here.
data.buckets.rotate_credentialsdata:writeReplaces the bucket's engine credentials; the old ones stop working once the new ones are served.
data.search_indexes.getdata:readGets a search index.
data.search_indexes.listdata:readLists search indexs in a environment.
data.search_indexes.createdata:writeCreates a search index. The Operation is done when the controller settles it.
data.search_indexes.updatedata:writeUpdates a search index.
data.search_indexes.deletedata:writeDeletes a search index. Fails while spec.deletion_protection is set.
data.search_indexes.connectdata:writeReturns how to connect to the search index: its endpoint and its own engine credentials. The credentials are not API keys and are returned only here.
data.search_indexes.rotate_credentialsdata:writeReplaces the search index's engine credentials; the old ones stop working once the new ones are served.
entitlement.entitlements.getentitlement:readGets an org's entitlement.
entitlement.entitlements.listentitlement:readLists an org's entitlements: exactly one, default.
events.topics.getevents:readGets a topic.
events.topics.listevents:readLists topics.
events.topics.createevents:writeCreates a topic.
events.topics.updateevents:writeUpdates a topic.
events.topics.deleteevents:writeDeletes a topic.
events.topics.publishevents:publishPublishes CloudEvents into a Topic, atomically. Replaying the same source + id with the same payload returns the stored event; a different payload fails with RESOURCE_ALREADY_EXISTS.
events.events.getevents:readGets an event.
events.events.listevents:readLists events.
events.connectors.getevents:readGets a connector.
events.connectors.listevents:readLists connectors.
events.subscriptions.getevents:readGets a subscription.
events.subscriptions.listevents:readLists subscriptions.
events.subscriptions.createevents:writeCreates a subscription.
events.subscriptions.updateevents:writeUpdates a subscription.
events.subscriptions.deleteevents:writeDeletes a subscription.
events.queues.getevents:readGets a queue.
events.queues.listevents:readLists queues.
events.queues.createevents:writeCreates a queue.
events.queues.updateevents:writeUpdates a queue.
events.queues.deleteevents:writeDeletes a queue.
events.queues.sendevents:publishEnqueues messages directly, without a Subscription.
events.queues.leaseevents:writeLeases up to max_messages ready messages for the visibility timeout.
events.queues.ackevents:writeAcknowledges leased messages; each is removed. A lease that is stale (expired or superseded) is reported, not applied.
events.queues.nackevents:writeReturns leased messages to the Queue after delay; each nack counts as a delivery.
events.queues.replayevents:writeMoves dead-lettered messages, optionally bounded by dead-letter time, back to ready.
events.webhook_endpoints.getevents:readGets a webhook endpoint.
events.webhook_endpoints.listevents:readLists webhook endpoints.
events.webhook_endpoints.createevents:writeCreates a webhook endpoint.
events.webhook_endpoints.updateevents:writeUpdates a webhook endpoint.
events.webhook_endpoints.deleteevents:writeDeletes a webhook endpoint.
events.webhook_endpoints.replayevents:writeRedelivers every dead-lettered delivery to the endpoint created in a time range, each as a new attempt.
events.webhook_endpoints.rotate_secretevents:writeReplaces the endpoint's signing secret and returns the new one, once (status.signing_secret). For 24 hours deliveries carry a signature with each secret, so a receiver can switch without dropping one.
events.webhook_endpoints.testevents:writeSends a test event (type sylphx.webhook.test) to the endpoint alone, through the same signing, retries, and delivery log as any other event.
events.webhook_deliveries.getevents:readGets a webhook delivery.
events.webhook_deliveries.listevents:readLists webhook deliveries.
events.webhook_deliveries.replayevents:writeRedelivers one delivery now, as a new attempt.
events.inbound_endpoints.getevents:readGets an inbound endpoint.
events.inbound_endpoints.listevents:readLists inbound endpoints.
events.inbound_endpoints.createevents:writeCreates an inbound endpoint.
events.inbound_endpoints.updateevents:writeUpdates an inbound endpoint.
events.inbound_endpoints.deleteevents:writeDeletes an inbound endpoint.
events.realtime_channels.getevents:readGets a realtime channel.
events.realtime_channels.listevents:readLists realtime channels.
events.realtime_channels.createevents:writeCreates a realtime channel.
events.realtime_channels.updateevents:writeUpdates a realtime channel.
events.realtime_channels.publishevents:publishPublishes one message to the channel: it is appended to the channel's history and pushed to every connected client. A retry with the same Idempotency-Key returns the first message.
events.realtime_channels.issue_tokenevents:publishMints a subscribe token (rtt_…) for this channel alone, at most an hour long, for a browser or device that holds no key. A token that names a client id enters the channel's presence while it is connected.
events.realtime_channels.deleteevents:writeDeletes a realtime channel.
events.realtime_messages.getevents:readGets one retained message of a channel.
events.realtime_messages.listevents:readLists a channel's retained messages, oldest first.
events.realtime_members.getevents:readGets one client present in a channel.
events.realtime_members.listevents:readLists the clients present in a channel now.
hosting.services.gethosting:readGets a service.
hosting.services.listhosting:readLists services in a environment.
hosting.services.createhosting:writeCreates a service. The Operation is done when the controller settles it.
hosting.services.updatehosting:writeUpdates a service.
hosting.services.deletehosting:writeDeletes a service.
hosting.service_rollouts.gethosting:readGets a rollout.
hosting.service_rollouts.listhosting:readLists rollouts in a service.
hosting.service_rollouts.createhosting:writeCreates a rollout.
hosting.service_rollouts.pausehosting:writeHolds a Rollout at its current wave.
hosting.service_rollouts.resumehosting:writeResumes a paused Rollout.
hosting.service_rollouts.aborthosting:writeStops a Rollout; the cells it reached return to the previous Release.
hosting.previews.gethosting:readGets a preview.
hosting.previews.listhosting:readLists previews in a environment.
hosting.previews.createhosting:writeCreates a preview. The Operation is done when the controller settles it.
hosting.previews.deletehosting:writeDeletes a preview.
hosting.source_links.gethosting:readGets a source link.
hosting.source_links.listhosting:readLists source links in a project.
hosting.source_links.createhosting:writeCreates a source link. The Operation is done when the controller settles it.
hosting.source_links.updatehosting:writeUpdates a source link.
hosting.source_links.deletehosting:writeDeletes a source link.
keys.keys.getkeys:readGets a key.
keys.keys.listkeys:readLists keys in an environment.
keys.keys.createkeys:writeCreates a key; the signer generates its first version.
keys.keys.updatekeys:writeUpdates a key's rotation period, deletion protection, or metadata.
keys.keys.deletekeys:writeDeletes a key and schedules every version's destruction.
keys.keys.rotatekeys:writeRotates a key: adds a version and makes it primary. Older versions keep verifying and decrypting until destroyed.
keys.keys.signkeys:signSigns data or a digest with a SIGN key. Every use is audited.
keys.keys.verifykeys:verifyVerifies a signature made by a SIGN key.
keys.keys.encryptkeys:encryptEncrypts data with an ENCRYPT key.
keys.keys.decryptkeys:decryptDecrypts a ciphertext made by Encrypt with this key.
keys.keys.mac_signkeys:signComputes a MAC of data with a MAC key.
keys.keys.mac_verifykeys:verifyVerifies a MAC made by a MAC key, in constant time.
keys.key_versions.getkeys:readGets a key version.
keys.key_versions.listkeys:readLists a key's versions.
keys.key_versions.destroykeys:writeSchedules a key version's destruction after a 24-hour grace; the primary version cannot be destroyed.
localization.catalogs.getlocalization:readGets a catalog.
localization.catalogs.listlocalization:readLists catalogs.
localization.catalogs.createlocalization:writeCreates a catalog.
localization.catalogs.updatelocalization:writeUpdates a catalog.
localization.catalogs.deletelocalization:writeDeletes a catalog.
localization.catalogs.synclocalization:writeReads the source files and the committed translations into the catalog, then translates what is new or stale. Each call is idempotent and works within a bounded time; call again until pending is 0.
localization.catalogs.exportlocalization:readReturns the catalog's files per locale in the requested format, with the QA report. A read with a request body, like a query.
localization.entries.getlocalization:readGets a catalog entry.
localization.entries.listlocalization:readLists catalog entries. The filter is limited to state, locale, and qa_state.
localization.entries.pin_translationlocalization:writeSets the text of one locale as a human override that AI never overwrites. QA runs on the text first; a text with a QA error is rejected with INVALID_FIELD, and the problem lists the findings.
localization.entries.unpin_translationlocalization:writeRemoves the human override of one locale; the next sync may translate it again.
localization.glossaries.getlocalization:readGets a glossary.
localization.glossaries.listlocalization:readLists glossarys.
localization.glossaries.createlocalization:writeCreates a glossary.
localization.glossaries.updatelocalization:writeUpdates a glossary.
localization.glossaries.deletelocalization:writeDeletes a glossary.
money.price_catalogs.getbilling:readGets the environment's catalog.
money.price_catalogs.updatebilling:writeUpdates the environment's catalog: its features and products, whole.
money.price_catalogs.syncbilling:writePushes the catalog to the merchant account's processor now: products and prices by lookup key; an amount change makes a new price.
money.store_connections.getbilling:readGets a store connection.
money.store_connections.listbilling:readLists store connections.
money.store_connections.createbilling:writeCreates a store connection; its credential is sealed and never returned.
money.store_connections.updatebilling:writeUpdates a store connection; a new credential replaces the stored one.
money.store_connections.deletebilling:writeDeletes a store connection and its sealed credential.
money.store_purchases.verifybilling:writeVerifies a store purchase with the store, binds it to the subject, and returns its record and a signed grant. Re-verifying returns the same record and grant. Called from the app's server with a secret key that holds billing:write; a publishable key cannot call it.
money.store_purchases.getbilling:readGets a store purchase.
money.store_purchases.listbilling:readLists store purchases, newest first.
money.customer_subscriptions.getbilling:readGets a customer subscription.
money.customer_subscriptions.listbilling:readLists customer subscriptions, newest first.
money.customer_subscriptions.cancelbilling:writeCancels a web subscription, now or at the period end, and optionally refunds its last payment (for example a statutory cancellation window).
money.customer_subscriptions.resumebilling:writeResumes a web subscription set to cancel at its period end.
money.customer_subscriptions.update_quantitybilling:writeChanges the seat quantity of a web subscription, now, and syncs the processor's subscription item to it. A retry with the same Idempotency-Key (required) and the same request changes nothing twice.
money.entitlement_grants.getbilling:readGets an entitlement grant.
money.entitlement_grants.listbilling:readLists entitlement grants.
money.entitlement_grants.checkbilling:readAnswers whether a subject holds a feature now, and how much of it.
money.merchant_accounts.getbilling:readGets a merchant account.
money.merchant_accounts.listbilling:readLists merchant accounts.
money.merchant_accounts.connectbilling:writeStarts connecting a Stripe account: returns the processor's authorisation URL for an org owner to open, which the processor's redirect completes. With a restricted key in the request the account connects at once instead, and the connected merchant account comes back in the response.
money.merchant_accounts.refreshbilling:writeReads the connected account back from the processor.
money.merchant_accounts.disconnectbilling:writeDisconnects the account: Sylphx loses access; checkout is refused.
money.checkout_sessions.createbilling:writeCreates a hosted checkout for a subject.
money.checkout_sessions.getbilling:readGets a checkout session.
money.portal_sessions.createbilling:writeCreates a customer portal session for a subject.
money.portal_sessions.getbilling:readGets a portal session.
network.domains.getnetwork:readGets a domain.
network.domains.listnetwork:readLists domains in a project.
network.domains.createnetwork:writeCreates a domain. The Operation is done when the controller settles it.
network.domains.updatenetwork:writeUpdates a domain.
network.domains.deletenetwork:writeDeletes a domain.
network.domains.verifynetwork:writeChecks the verification record now instead of at the next sweep.
network.certificates.getnetwork:readGets a certificate.
network.certificates.listnetwork:readLists certificates in a project.
network.routes.getnetwork:readGets a route.
network.routes.listnetwork:readLists routes in a environment.
network.routes.createnetwork:writeCreates a route. The Operation is done when the controller settles it.
network.routes.updatenetwork:writeUpdates a route.
network.routes.deletenetwork:writeDeletes a route.
network.egress_identities.getnetwork:readGets an egress identity.
network.egress_identities.listnetwork:readLists egress identitys in a project.
network.egress_identities.createnetwork:writeCreates an egress identity. The Operation is done when the controller settles it.
network.egress_identities.updatenetwork:writeUpdates an egress identity.
network.egress_identities.deletenetwork:writeDeletes an egress identity.
network.private_links.getnetwork:readGets a private link.
network.private_links.listnetwork:readLists private links in a environment.
network.private_links.createnetwork:writeCreates a private link. The Operation is done when the controller settles it.
network.private_links.updatenetwork:writeUpdates a private link.
network.private_links.deletenetwork:writeDeletes a private link.
notify.mail_domains.getnotify:readGets an email domain.
notify.mail_domains.listnotify:readLists email domains.
notify.mail_domains.createnotify:writeCreates an email domain.
notify.mail_domains.updatenotify:writeUpdates an email domain.
notify.mail_domains.deletenotify:writeDeletes an email domain.
notify.mail_domains.verifynotify:writeChecks the domain's DNS records now instead of on the next sweep.
notify.mail_routes.getnotify:readGets a route.
notify.mail_routes.listnotify:readLists an email domain's routes.
notify.mail_routes.createnotify:writeCreates a route.
notify.mail_routes.updatenotify:writeUpdates a route.
notify.mail_routes.deletenotify:writeDeletes a route.
notify.senders.getnotify:readGets a sender.
notify.senders.listnotify:readLists senders.
notify.senders.createnotify:writeCreates a sender.
notify.senders.updatenotify:writeUpdates a sender.
notify.senders.deletenotify:writeDeletes a sender.
notify.senders.verifynotify:writeRe-checks the sender's registration or credentials now.
notify.recipients.getnotify:readGets a recipient.
notify.recipients.listnotify:readLists recipients.
notify.recipients.createnotify:writeCreates a recipient.
notify.recipients.updatenotify:writeUpdates a recipient.
notify.recipients.deletenotify:writeDeletes a recipient.
notify.preferences.getnotify:readGets a preference.
notify.preferences.listnotify:readLists preferences.
notify.preferences.updatenotify:writeUpdates a preference.
notify.preferences.deletenotify:writeDeletes a preference.
notify.suppressions.getnotify:readGets a suppression.
notify.suppressions.listnotify:readLists suppressions.
notify.suppressions.createnotify:writeCreates a suppression.
notify.suppressions.deletenotify:writeDeletes a suppression.
notify.templates.getnotify:readGets a template.
notify.templates.listnotify:readLists templates.
notify.templates.createnotify:writeCreates a template.
notify.templates.updatenotify:writeUpdates a template.
notify.templates.deletenotify:writeDeletes a template.
notify.messages.getnotify:readGets a message.
notify.messages.listnotify:readLists messages.
notify.messages.createnotify:sendSends a Message.
notify.messages.cancelnotify:sendCancels a Message whose deliveries have not been handed off.
notify.mailboxes.getnotify:readGets a mailbox.
notify.mailboxes.listnotify:readLists mailboxes.
notify.mailboxes.createnotify:writeCreates a mailbox.
notify.mailboxes.updatenotify:writeUpdates a mailbox.
notify.mailboxes.deletenotify:writeDeletes a mailbox and its inbound email.
notify.mailboxes.erase_addressnotify:writeRemoves an address's personal data from every inbound email of the mailbox that it sent or that names it, keeping the dedupe keys so a poll never brings the mail back.
notify.inbound_emails.getnotify:readGets an inbound email.
notify.inbound_emails.listnotify:readLists a mailbox's inbound email in feed order, oldest first.
notify.inbox_items.getnotify:readGets an inbox item.
notify.inbox_items.listnotify:readLists inbox items.
notify.inbox_items.mark_readnotify:writeMarks an inbox item read.
notify.inbox_items.mark_unreadnotify:writeMarks an inbox item unread.
notify.inbox_items.archivenotify:writeArchives an inbox item.
notify.broadcasts.getnotify:readGets a broadcast.
notify.broadcasts.listnotify:readLists broadcasts.
notify.broadcasts.createnotify:writeCreates a broadcast.
notify.broadcasts.updatenotify:writeUpdates a broadcast.
notify.broadcasts.deletenotify:writeDeletes a broadcast.
notify.broadcasts.sendnotify:sendSends a Broadcast now.
notify.broadcasts.cancelnotify:sendCancels a Broadcast; messages already admitted still deliver.
observability.log_entries.getobservability:readGets a log entry.
observability.log_entries.writeobservability:ingestIngests a batch of log entries atomically. The same Idempotency-Key and digest replays the same batch; a different digest under the key conflicts.
observability.log_entries.queryobservability:readQueries the environment's log entries over a bounded interval; follow a trace with trace_id = "...".
observability.traces.getobservability:readGets a trace.
observability.traces.write_spansobservability:ingestIngests a batch of spans atomically; a span's parent and time invariants are validated. Replay rules are those of WriteLogEntries.
observability.traces.queryobservability:readQueries the environment's traces over a bounded interval, returning summaries without spans.
observability.error_groups.getobservability:readGets an error group.
observability.error_groups.listobservability:readLists error groups; filter by state, service_name, and last_seen_time.
observability.error_groups.captureobservability:ingestCaptures one error occurrence. It is grouped by fingerprint when the caller sets one, else by exception type and the symbolicated in-app stack; release is never part of the group. A new occurrence reopens a resolved group. Secrets and personal data are scrubbed by the environment's Scrubbing Policy before storage. A fingerprint-equal replay bills no second new-error unit. Under quota pressure the response says what to sample. Browsers call it with a publishable key that holds observability:ingest (CORS allowed, rate-limited per environment).
observability.error_groups.acknowledgeobservability:writeAcknowledges an error group.
observability.error_groups.resolveobservability:writeResolves an error group; a new occurrence reopens it.
observability.error_groups.reopenobservability:writeReopens a resolved or acknowledged error group.
observability.error_events.getobservability:readGets an error event.
observability.error_events.listobservability:readLists error events.
observability.source_maps.createobservability:writeUploads a source map for one release and minified file. Uploading the same release and file again replaces it.
observability.source_maps.getobservability:readGets a source map (without its content).
observability.source_maps.listobservability:readLists source maps, newest first; filter by release.
observability.scrubbing_policies.getobservability:readGets the environment's scrubbing policy (scrubbing_policies/default).
observability.scrubbing_policies.updateobservability:writeUpdates the environment's scrubbing policy.
release.releases.getrelease:readGets a release.
release.releases.listrelease:readLists releases in an environment, newest first by default.
release.releases.createrelease:writeCreates a release: admits it and rolls it out in waves. The Operation is done when the release is live or halted.
release.rollouts.getrelease:readGets a rollout.
release.rollouts.listrelease:readLists rollouts in an environment.
runners.scale_sets.getrunners:readGets a scale set.
runners.scale_sets.listrunners:readLists scale sets in a org.
runners.scale_sets.createrunners:writeCreates a scale set. The Operation is done when the controller settles it.
runners.scale_sets.updaterunners:writeUpdates a scale set.
runners.scale_sets.deleterunners:writeDeletes a scale set.
runners.runners.getrunners:readGets a runner.
runners.runners.listrunners:readLists runners in a scale set.
sandboxes.sandbox_shapes.getsandboxes:readGets a shape.
sandboxes.sandbox_shapes.listsandboxes:readLists shapes.
sandboxes.pools.getsandboxes:readGets a pool.
sandboxes.pools.listsandboxes:readLists pools in a environment.
sandboxes.pools.createsandboxes:writeCreates a pool. The Operation is done when the controller settles it.
sandboxes.pools.updatesandboxes:writeUpdates a pool.
sandboxes.pools.deletesandboxes:writeDeletes a pool.
sandboxes.leases.getsandboxes:readGets a lease.
sandboxes.leases.listsandboxes:readLists leases in a environment. Filter on meta.labels (for example labels.agent = "a_123"), status.state, and spec.kind.
sandboxes.leases.createsandboxes:writeCreates a lease: granted now and returned READY (or GRANTED when wait_ready is false), or refused with a typed error. There is no queue.
sandboxes.leases.renewsandboxes:writeExtends expire_time, never past the shape's longest lease. Does not change the generation.
sandboxes.leases.releasesandboxes:writeEnds a lease with END_REASON_RELEASED; the machine is destroyed and never leased again, and attached volumes are detached.
sandboxes.leases.pausesandboxes:writePauses a lease: its disk is kept and its machine destroyed; the generation increases. Process memory is not kept.
sandboxes.leases.resumesandboxes:writeResumes a paused lease on a machine granted now, or refuses it; the generation increases.
sandboxes.leases.set_networksandboxes:writeReplaces a running lease's outbound policy. The generation does not change; the new policy applies before the call returns.
sandboxes.leases.mint_tokensandboxes:execMints a lease token for the data plane, bound to the current generation. Hand it to a process that must not hold the Access key.
sandboxes.leases.execsandboxes:execRuns one command in the lease to completion and returns its output, capped at 1 MiB per stream. Long-running or interactive processes use the guest protocol at status.endpoints.guest_uri.
sandboxes.leases.read_filesandboxes:execReads one file from the lease, at most 16 MiB; larger files use the guest's /files.
sandboxes.leases.write_filesandboxes:execWrites one file in the lease, at most 16 MiB, creating parent directories.
sandboxes.leases.list_filessandboxes:execLists one directory in the lease.
sandboxes.leases.remove_filesandboxes:execRemoves one file or directory tree in the lease.
sandboxes.leases.open_portsandboxes:execExposes a guest port.
sandboxes.leases.close_portsandboxes:execStops exposing a guest port.
sandboxes.leases.actsandboxes:execPerforms computer actions on a DESKTOP, BROWSER, or ANDROID lease, in order, and returns each action's result and, when screenshot is set, the screenshot taken after the last action. The actions are the Anthropic computer tool's and OpenAI computer use's, one-to-one. Refused CONTROL_HELD_BY_HUMAN while a human holds control.
sandboxes.leases.open_streamsandboxes:execOpens a read-only live view of a lease's display: a short-lived viewer token bound to the lease and its generation, an embeddable URL, and the WebRTC signaling endpoint with ICE servers. Input needs control (AcquireLeaseControl).
sandboxes.leases.acquire_controlsandboxes:execTakes exclusive input control of a lease's display. A HUMAN acquire preempts an AGENT holder and returns a controller stream; an AGENT acquire is refused CONTROL_HELD_BY_HUMAN while a human holds control. Control lapses at ttl, which the platform caps at 30 minutes.
sandboxes.leases.release_controlsandboxes:execReleases control held under epoch; its controller tokens stop working.
sandboxes.leases.get_controlsandboxes:readGets who holds control of a lease's display.
sandboxes.leases.install_appsandboxes:execInstalls an Android app (APK) on an ANDROID lease.
sandboxes.lease_events.getsandboxes:readGets one lease event.
sandboxes.lease_events.listsandboxes:readLists a lease's events in order. With wait, blocks up to that long for an event after page_token (long poll).
sandboxes.volumes.getsandboxes:readGets a volume.
sandboxes.volumes.listsandboxes:readLists volumes in a environment.
sandboxes.volumes.createsandboxes:writeCreates a volume.
sandboxes.volumes.updatesandboxes:writeUpdates a volume: grows spec.size_gib and edits metadata.
sandboxes.volumes.deletesandboxes:writeDeletes a volume and destroys its data. Refused RESOURCE_IN_USE while it is attached.
sandboxes.snapshots.getsandboxes:readGets a snapshot.
sandboxes.snapshots.listsandboxes:readLists snapshots in a environment.
sandboxes.snapshots.createsandboxes:writeCaptures a running lease's disk as a snapshot.
sandboxes.snapshots.deletesandboxes:writeDeletes a snapshot.
secrets.secrets.getsecrets:readGets a secret.
secrets.secrets.listsecrets:readLists secrets in an environment.
secrets.secrets.createsecrets:writeCreates a secret, without a value; add one with CreateSecretVersion.
secrets.secrets.updatesecrets:writeUpdates a secret.
secrets.secrets.deletesecrets:writeDeletes a secret and destroys every version.
secrets.secret_versions.getsecrets:readGets a secret version.
secrets.secret_versions.listsecrets:readLists a secret's versions.
secrets.secret_versions.createsecrets:writeAdds a value to a secret as its newest version. The value is never returned.
secrets.secret_versions.disablesecrets:writeDisables a secret version: bindings stop delivering it.
secrets.secret_versions.enablesecrets:writeEnables a disabled secret version.
secrets.secret_versions.destroysecrets:writeDestroys a secret version's value irrecoverably.
secrets.secret_versions.accesssecrets:accessReads a secret version's value back. Break-glass: a separate permission, audited on every call, and never exposed to MCP.
secrets.secret_bindings.getsecrets:readGets a secret binding.
secrets.secret_bindings.listsecrets:readLists secret bindings in an environment.
secrets.secret_bindings.createsecrets:writeCreates a secret binding.
secrets.secret_bindings.updatesecrets:writeUpdates a secret binding.
secrets.secret_bindings.deletesecrets:writeDeletes a secret binding.
workflows.workflows.getworkflows:readGets a workflow.
workflows.workflows.listworkflows:readLists workflows.
workflows.workflows.createworkflows:writeCreates a workflow.
workflows.workflows.updateworkflows:writeUpdates a workflow.
workflows.workflows.deleteworkflows:writeDeletes a workflow.
workflows.schedules.getworkflows:readGets a schedule.
workflows.schedules.listworkflows:readLists schedules.
workflows.schedules.createworkflows:writeCreates a schedule.
workflows.schedules.updateworkflows:writeUpdates a schedule.
workflows.schedules.deleteworkflows:writeDeletes a schedule.
workflows.schedules.pauseworkflows:writePauses a Schedule: no fire starts a Run until it is resumed.
workflows.schedules.resumeworkflows:writeResumes a paused Schedule; missed fires follow catchup_window.
workflows.runs.getworkflows:readGets a run.
workflows.runs.listworkflows:readLists runs.
workflows.runs.createworkflows:runStarts a Run of a Workflow.
workflows.runs.start_batchworkflows:runStarts a batch: a parent Run that fans out one child Run per item, each with a stable index and count.
workflows.runs.signalworkflows:runSends a named signal to a running Run; a wait op for that name resumes with its payload. A signal to a closed Run fails with INVALID_STATE.
workflows.runs.cancelworkflows:runRequests cancellation. Timers and waits stop; a running invocation is not interrupted: the handler receives one final invocation with cancel: true, and the Run ends cancelled when it answers.
workflows.runs.waitworkflows:readWaits up to timeout (at most 60s) for the Run to close, then returns it, closed or not.
workflows.runs.read_historyworkflows:readReads a page of the Run's immutable history, projected to Sylphx events.
workflows.jobs.getworkflows:readGets a job.
workflows.jobs.listworkflows:readLists jobs.
workflows.jobs.createworkflows:writeCreates a job.
workflows.jobs.updateworkflows:writeUpdates a job. Runs already started keep the generation they pinned.
workflows.jobs.deleteworkflows:writeDeletes a job.
workflows.job_runs.createworkflows:runStarts a run of a Job now. The same Idempotency-Key returns the same run for 24h; a Schedule fire uses {job}:{intended time}. With concurrency forbid, a start while a run is active fails with INVALID_STATE.
workflows.job_runs.getworkflows:readGets a job run.
workflows.job_runs.listworkflows:readLists a job's runs, newest first.
workflows.job_runs.cancelworkflows:runCancels a job run: SIGTERM, then SIGKILL after 30s. A closed run fails with INVALID_STATE.
workflows.job_runs.read_logsworkflows:readReads a page of a job run's log lines, oldest first. With wait, an empty page on a running run waits up to that long for new lines, so a client follows the log by passing each next_page_token back.
workflows.distributed_jobs.getworkflows:readGets a distributed job.
workflows.distributed_jobs.listworkflows:readLists distributed jobs.
workflows.distributed_jobs.createworkflows:writeCreates a distributed job.
workflows.distributed_jobs.updateworkflows:writeUpdates a distributed job. Runs already started keep the generation they pinned.
workflows.distributed_jobs.deleteworkflows:writeDeletes a distributed job.
workflows.distributed_runs.createworkflows:runStarts a run of a distributed job. The same Idempotency-Key returns the same run for 24h.
workflows.distributed_runs.getworkflows:readGets a distributed run: its state, shard and worker counts, and usage.
workflows.distributed_runs.listworkflows:readLists a distributed job's runs, newest first.
workflows.distributed_runs.cancelworkflows:runCancels a distributed run: workers get SIGTERM and 30s, then leases are released; finished shards are kept. A closed run fails with INVALID_STATE.
workflows.distributed_runs.add_shardsworkflows:runAppends shards to a run started with an open manifest; close ends the manifest, and the run ends once those shards are done.
workflows.distributed_runs.read_shardsworkflows:readReads a page of the run's shards, in queue order.
workflows.distributed_runs.read_workersworkflows:readReads a page of the run's workers.