Menu
Platform
AI
App store purchases
Database
Flags
Jobs and cron
Localization
Monitoring
Notifications
Payments
Queues
Sandboxes
Webhooks
Getting Started
Authentication
KV Store
Deploy & Infrastructure
Reference
On this page
RESOURCE_NOT_FOUND
The named Resource does not exist or is not visible.
The named Resource does not exist or is not visible.
HTTP 404 · gRPC NOT_FOUND · the error body
#Returned by
| Method | Scope | What it does |
|---|---|---|
access.orgs.get | access:read | Gets an org. |
access.orgs.update | access:admin | Updates an org. |
access.orgs.delete | access:admin | Deletes an org and everything in it. Deletion cascades through every service, so it returns an Operation. |
access.projects.get | access:read | Gets a project. |
access.projects.update | access:admin | Updates a project. |
access.projects.delete | access:admin | Deletes a project. |
access.envs.get | access:read | Gets an environment. |
access.envs.update | access:admin | Updates an environment. |
access.envs.delete | access:admin | Deletes an environment. |
access.api_keys.get | access:read | Gets an API key. |
access.api_keys.update | access:keys:write | Updates an API key. |
access.api_keys.delete | access:keys:write | Deletes an API key. |
access.api_keys.revoke | access:keys:write | Revokes an API key immediately; revocation propagates on its own fast path, ahead of the bulk key data. |
access.api_keys.roll | access:keys:write | Rolls an API key: returns a new key with the same spec and revokes the old one after the grace period. |
ai.ai_models.get | ai:read | Gets an AI model. |
artifacts.artifacts.get | artifacts:read | Gets an artifact. |
artifacts.artifacts.delete | artifacts:write | Deletes an artifact; fails while a Release references it or a legal hold is active. |
assets.assets.get | assets:read | Gets an asset. |
assets.assets.generate | assets:write | Records the recipes as assets and generates the variants that are missing. Each call is idempotent and works within a bounded time; call again until pending is 0. |
assets.assets.approve_variant | assets:write | Approves one variant and records who approved it. |
assets.assets.reject_variant | assets:write | Rejects one variant. Its slot is freed and the next :generate fills it; the rejected file keeps serving at its URL. |
assets.assets.retire_variant | assets:write | Retires one variant. Its URL answers 404 from then on and its slot is freed. |
auth.auth_configs.get | auth:read | Gets an auth config. |
auth.auth_configs.update | auth:write | Updates an auth config. |
auth.end_users.get | auth:read | Gets an end user. |
auth.end_users.update | auth:write | Updates an end user. |
auth.end_users.delete | auth:write | Deletes an end user. |
auth.end_users.suspend | auth:write | Suspends an end user: sessions are revoked and sign-in is refused. |
auth.end_users.reactivate | auth:write | Reactivates a suspended end user. |
auth.end_users.unlock | auth:write | Clears an end user's sign-in lock (repeated failed sign-ins) now. |
auth.end_users.revoke_sessions | auth:write | Revokes every session of an end user. |
auth.sessions.get | auth:read | Gets a session. |
auth.sessions.revoke | auth:write | Revokes a session. |
auth.customer_organizations.get | auth:read | Gets a customer organization. |
auth.customer_organizations.update | auth:write | Updates a customer organization. |
auth.customer_organizations.delete | auth:write | Deletes a customer organization. |
auth.memberships.get | auth:read | Gets a membership. |
auth.memberships.update | auth:write | Updates a membership. |
auth.memberships.delete | auth:write | Deletes a membership. |
auth.organization_roles.get | auth:read | Gets an organization role. |
auth.organization_roles.update | auth:write | Updates an organization role. |
auth.organization_roles.delete | auth:write | Deletes an organization role. |
auth.invitations.get | auth:read | Gets an invitation. |
auth.invitations.revoke | auth:write | Revokes a pending invitation. |
auth.invitations.accept | auth:write | Accepts a pending invitation for an end user whose verified email is the invited address, and creates the membership. |
auth.email_domains.get | auth:read | Gets an email domain. |
auth.email_domains.delete | auth:write | Deletes an email domain. |
auth.email_domains.verify | auth:write | Looks up the domain's TXT record now; found, the domain is verified. |
auth.oauth_clients.get | auth:read | Gets an OAuth client. |
auth.oauth_clients.update | auth:write | Updates an OAuth client. |
auth.oauth_clients.delete | auth:write | Deletes an OAuth client. |
auth.oauth_clients.roll_secret | auth:write | Issues a new client secret, returned once; the old one verifies until grace_period ends. |
billing.meters.get | billing:read | Gets a meter. |
billing.plans.get | billing:read | Gets a plan. |
billing.billing_accounts.get | billing:read | Gets a billing account. |
billing.billing_accounts.update | billing:admin | Updates a billing account: changes plan, spend limit, or billing email. |
billing.billing_accounts.setup_payment_method | billing:admin | Starts saving a payment method for the org: returns a client secret the console confirms with Stripe.js, so card data never reaches Sylphx. The saved method becomes the account's default and is charged off-session for each finalized invoice. |
billing.invoices.get | billing:read | Gets an invoice. |
billing.usage_reports.get | billing:read | Gets an usage report. |
billing.budget_leases.get | billing:read | Gets a budget lease. |
broker.trust_policies.get | broker:read | Gets a trust policy. |
broker.trust_policies.update | broker:admin | Updates a trust policy. |
broker.trust_policies.delete | broker:admin | Deletes a trust policy. |
broker.trust_policies.exchange_token | broker:exchange | Exchanges the caller's workload identity for a short-lived provider credential under a trust policy (RFC 8693 token exchange). The credential is narrowed to the request and cached per installation and permission set; a permission the Connection lacks is PERMISSION_DENIED with reason CapabilityMissing, never an outage. |
build.builds.get | build:read | Gets a build. |
build.builds.cancel | build:write | Cancels a queued or running Build; its lease is released and nothing is published. |
build.build_caches.get | build:read | Gets a build cache. |
build.build_caches.update | build:write | Updates a build cache. |
build.build_caches.delete | build:write | Deletes a build cache. |
config.config_flags.get | config:read | Gets a config flag. |
config.config_flags.update | config:write | Updates a config flag; the change rolls out in waves and the Operation is done when every cell serves it. |
config.config_flags.delete | config:write | Deletes a config flag; evaluators then get their compiled-in fallback. |
config.config_segments.get | config:read | Gets a config segment. |
config.config_segments.update | config:write | Updates a config segment; every flag naming it follows. |
config.config_segments.delete | config:write | Deletes a config segment; refused while a flag names it. |
config.config_changes.get | config:read | Gets a config change. |
connections.connection_providers.get | connections:read | Gets a connection provider. |
connections.connection_providers.update | connections:admin | Updates a connection provider. |
connections.connection_providers.delete | connections:admin | Deletes a connection provider; it must have no connections. |
connections.connections.get | connections:read | Gets a connection. |
connections.connections.update | connections:write | Updates a connection's metadata. |
connections.connections.delete | connections:write | Forgets a connection. The installation itself is removed at the provider. |
data.objects.put | data:write | Writes an object's bytes, replacing the current version. body is the base64 of the bytes. |
data.objects.get | data:read | Reads an object and its bytes (body, base64). |
data.objects.list | data:read | Lists a bucket's objects in key order. |
data.objects.delete | data:write | Deletes an object's current version (history is kept). |
data.kv.put | data:write | Writes a value. Without ttl_seconds the namespace default applies; zero means no expiry. |
data.kv.get | data:read | Reads a value. |
data.kv.list | data:read | Lists a namespace's values in key order. |
data.kv.delete | data:write | Deletes a value. |
data.kv.increment | data:write | Adds delta (default 1) to an integer value, creating it at zero. |
data.kv.get_many | data:read | Reads up to 1000 keys at once (MGET). Answers one entry per key, in order; an absent or expired key keeps its key and has no value. |
data.kv.hash_set | data:write | Sets fields of a hash (HSET), creating it. |
data.kv.hash_get | data:read | Reads one field of a hash (HGET); an absent field has no value. |
data.kv.hash_get_all | data:read | Reads every field of a hash (HGETALL). |
data.kv.hash_get_many | data:read | Reads several fields of a hash (HMGET), one per field, in order; an absent field has no value. |
data.kv.list_push | data:write | Pushes values onto the head of a list (LPUSH), creating it. |
data.kv.list_range | data:read | Reads a range of a list (LRANGE); negative indexes count from the end. |
data.kv.list_pop | data:write | Pops values from the head of a list (LPOP); an emptied list is removed. |
data.kv.list_length | data:read | Reads the length of a list (LLEN); an absent key has length zero. |
data.kv.zset_add | data:write | Adds members to a sorted set or updates their scores (ZADD), creating it. |
data.kv.zset_range | data:read | Reads a range of a sorted set by rank, lowest score first (ZRANGE); negative indexes count from the end. |
data.kv.zset_score | data:read | Reads a member's score (ZSCORE); an absent member has no score. |
data.kv.zset_length | data:read | Reads the size of a sorted set (ZCARD); an absent key has size zero. |
data.kv.scan | data:read | Walks a namespace's keys that match a glob (SCAN). Call again with the returned cursor until it is empty. |
data.kv.expire | data:write | Sets a key's time to live (EXPIRE) without rewriting its value; zero makes it persistent. |
data.documents.put | data:write | Writes a document to a search index, replacing the current version. |
data.documents.get | data:read | Reads a document. |
data.documents.delete | data:write | Deletes a document. |
data.search.query | data:read | Searches an index by text, by vector, or both, best match first, with filters and paging. |
data.databases.get | data:read | Gets a database. |
data.databases.update | data:write | Updates a database. |
data.databases.delete | data:write | Deletes a database. Fails while spec.deletion_protection is set. |
data.databases.connect | data:write | Returns how to connect to the database: its endpoint and its own engine credentials. The credentials are not API keys and are returned only here. |
data.databases.rotate_credentials | data:write | Replaces the database's engine credentials; the old ones stop working once the new ones are served. |
data.databases.restore | data:write | Restores the database in place to a point in time inside its retention window; the database is unavailable while it restores. |
data.kv_namespaces.get | data:read | Gets a kv namespace. |
data.kv_namespaces.update | data:write | Updates a kv namespace. |
data.kv_namespaces.delete | data:write | Deletes a kv namespace. Fails while spec.deletion_protection is set. |
data.kv_namespaces.connect | data:write | Returns how to connect to the KV namespace: its endpoint and its own engine credentials. The credentials are not API keys and are returned only here. |
data.kv_namespaces.rotate_credentials | data:write | Replaces the KV namespace's engine credentials; the old ones stop working once the new ones are served. |
data.buckets.get | data:read | Gets a bucket. |
data.buckets.update | data:write | Updates a bucket. |
data.buckets.delete | data:write | Deletes a bucket. Fails while spec.deletion_protection is set. |
data.buckets.connect | data:write | Returns how to connect to the bucket: its endpoint and its own engine credentials. The credentials are not API keys and are returned only here. |
data.buckets.rotate_credentials | data:write | Replaces the bucket's engine credentials; the old ones stop working once the new ones are served. |
data.search_indexes.get | data:read | Gets a search index. |
data.search_indexes.update | data:write | Updates a search index. |
data.search_indexes.delete | data:write | Deletes a search index. Fails while spec.deletion_protection is set. |
data.search_indexes.connect | data:write | Returns how to connect to the search index: its endpoint and its own engine credentials. The credentials are not API keys and are returned only here. |
data.search_indexes.rotate_credentials | data:write | Replaces the search index's engine credentials; the old ones stop working once the new ones are served. |
entitlement.entitlements.get | entitlement:read | Gets an org's entitlement. |
events.topics.get | events:read | Gets a topic. |
events.topics.update | events:write | Updates a topic. |
events.topics.delete | events:write | Deletes a topic. |
events.topics.publish | events:publish | Publishes CloudEvents into a Topic, atomically. Replaying the same source + id with the same payload returns the stored event; a different payload fails with RESOURCE_ALREADY_EXISTS. |
events.events.get | events:read | Gets an event. |
events.connectors.get | events:read | Gets a connector. |
events.subscriptions.get | events:read | Gets a subscription. |
events.subscriptions.update | events:write | Updates a subscription. |
events.subscriptions.delete | events:write | Deletes a subscription. |
events.queues.get | events:read | Gets a queue. |
events.queues.update | events:write | Updates a queue. |
events.queues.delete | events:write | Deletes a queue. |
events.queues.send | events:publish | Enqueues messages directly, without a Subscription. |
events.queues.lease | events:write | Leases up to max_messages ready messages for the visibility timeout. |
events.queues.ack | events:write | Acknowledges leased messages; each is removed. A lease that is stale (expired or superseded) is reported, not applied. |
events.queues.nack | events:write | Returns leased messages to the Queue after delay; each nack counts as a delivery. |
events.queues.replay | events:write | Moves dead-lettered messages, optionally bounded by dead-letter time, back to ready. |
events.webhook_endpoints.get | events:read | Gets a webhook endpoint. |
events.webhook_endpoints.update | events:write | Updates a webhook endpoint. |
events.webhook_endpoints.delete | events:write | Deletes a webhook endpoint. |
events.webhook_endpoints.replay | events:write | Redelivers every dead-lettered delivery to the endpoint created in a time range, each as a new attempt. |
events.webhook_endpoints.rotate_secret | events:write | Replaces the endpoint's signing secret and returns the new one, once (status.signing_secret). For 24 hours deliveries carry a signature with each secret, so a receiver can switch without dropping one. |
events.webhook_endpoints.test | events:write | Sends a test event (type sylphx.webhook.test) to the endpoint alone, through the same signing, retries, and delivery log as any other event. |
events.webhook_deliveries.get | events:read | Gets a webhook delivery. |
events.webhook_deliveries.replay | events:write | Redelivers one delivery now, as a new attempt. |
events.inbound_endpoints.get | events:read | Gets an inbound endpoint. |
events.inbound_endpoints.update | events:write | Updates an inbound endpoint. |
events.inbound_endpoints.delete | events:write | Deletes an inbound endpoint. |
events.realtime_channels.get | events:read | Gets a realtime channel. |
events.realtime_channels.update | events:write | Updates a realtime channel. |
events.realtime_channels.publish | events:publish | Publishes one message to the channel: it is appended to the channel's history and pushed to every connected client. A retry with the same Idempotency-Key returns the first message. |
events.realtime_channels.issue_token | events:publish | Mints a subscribe token (rtt_…) for this channel alone, at most an hour long, for a browser or device that holds no key. A token that names a client id enters the channel's presence while it is connected. |
events.realtime_channels.delete | events:write | Deletes a realtime channel. |
events.realtime_messages.get | events:read | Gets one retained message of a channel. |
events.realtime_messages.list | events:read | Lists a channel's retained messages, oldest first. |
events.realtime_members.get | events:read | Gets one client present in a channel. |
events.realtime_members.list | events:read | Lists the clients present in a channel now. |
hosting.services.get | hosting:read | Gets a service. |
hosting.services.update | hosting:write | Updates a service. |
hosting.services.delete | hosting:write | Deletes a service. |
hosting.service_rollouts.get | hosting:read | Gets a rollout. |
hosting.service_rollouts.pause | hosting:write | Holds a Rollout at its current wave. |
hosting.service_rollouts.resume | hosting:write | Resumes a paused Rollout. |
hosting.service_rollouts.abort | hosting:write | Stops a Rollout; the cells it reached return to the previous Release. |
hosting.previews.get | hosting:read | Gets a preview. |
hosting.previews.delete | hosting:write | Deletes a preview. |
hosting.source_links.get | hosting:read | Gets a source link. |
hosting.source_links.update | hosting:write | Updates a source link. |
hosting.source_links.delete | hosting:write | Deletes a source link. |
keys.keys.get | keys:read | Gets a key. |
keys.keys.update | keys:write | Updates a key's rotation period, deletion protection, or metadata. |
keys.keys.delete | keys:write | Deletes a key and schedules every version's destruction. |
keys.keys.rotate | keys:write | Rotates a key: adds a version and makes it primary. Older versions keep verifying and decrypting until destroyed. |
keys.keys.sign | keys:sign | Signs data or a digest with a SIGN key. Every use is audited. |
keys.keys.verify | keys:verify | Verifies a signature made by a SIGN key. |
keys.keys.encrypt | keys:encrypt | Encrypts data with an ENCRYPT key. |
keys.keys.decrypt | keys:decrypt | Decrypts a ciphertext made by Encrypt with this key. |
keys.keys.mac_sign | keys:sign | Computes a MAC of data with a MAC key. |
keys.keys.mac_verify | keys:verify | Verifies a MAC made by a MAC key, in constant time. |
keys.key_versions.get | keys:read | Gets a key version. |
keys.key_versions.destroy | keys:write | Schedules a key version's destruction after a 24-hour grace; the primary version cannot be destroyed. |
localization.catalogs.get | localization:read | Gets a catalog. |
localization.catalogs.update | localization:write | Updates a catalog. |
localization.catalogs.delete | localization:write | Deletes a catalog. |
localization.catalogs.sync | localization:write | Reads the source files and the committed translations into the catalog, then translates what is new or stale. Each call is idempotent and works within a bounded time; call again until pending is 0. |
localization.catalogs.export | localization:read | Returns the catalog's files per locale in the requested format, with the QA report. A read with a request body, like a query. |
localization.entries.get | localization:read | Gets a catalog entry. |
localization.entries.pin_translation | localization:write | Sets the text of one locale as a human override that AI never overwrites. QA runs on the text first; a text with a QA error is rejected with INVALID_FIELD, and the problem lists the findings. |
localization.entries.unpin_translation | localization:write | Removes the human override of one locale; the next sync may translate it again. |
localization.glossaries.get | localization:read | Gets a glossary. |
localization.glossaries.update | localization:write | Updates a glossary. |
localization.glossaries.delete | localization:write | Deletes a glossary. |
money.price_catalogs.get | billing:read | Gets the environment's catalog. |
money.price_catalogs.sync | billing:write | Pushes the catalog to the merchant account's processor now: products and prices by lookup key; an amount change makes a new price. |
money.store_connections.get | billing:read | Gets a store connection. |
money.store_connections.update | billing:write | Updates a store connection; a new credential replaces the stored one. |
money.store_connections.delete | billing:write | Deletes a store connection and its sealed credential. |
money.store_purchases.get | billing:read | Gets a store purchase. |
money.customer_subscriptions.get | billing:read | Gets a customer subscription. |
money.customer_subscriptions.cancel | billing:write | Cancels a web subscription, now or at the period end, and optionally refunds its last payment (for example a statutory cancellation window). |
money.customer_subscriptions.resume | billing:write | Resumes a web subscription set to cancel at its period end. |
money.customer_subscriptions.update_quantity | billing:write | Changes the seat quantity of a web subscription, now, and syncs the processor's subscription item to it. A retry with the same Idempotency-Key (required) and the same request changes nothing twice. |
money.entitlement_grants.get | billing:read | Gets an entitlement grant. |
money.merchant_accounts.get | billing:read | Gets a merchant account. |
money.merchant_accounts.refresh | billing:write | Reads the connected account back from the processor. |
money.merchant_accounts.disconnect | billing:write | Disconnects the account: Sylphx loses access; checkout is refused. |
money.checkout_sessions.get | billing:read | Gets a checkout session. |
money.portal_sessions.get | billing:read | Gets a portal session. |
network.domains.get | network:read | Gets a domain. |
network.domains.update | network:write | Updates a domain. |
network.domains.delete | network:write | Deletes a domain. |
network.domains.verify | network:write | Checks the verification record now instead of at the next sweep. |
network.certificates.get | network:read | Gets a certificate. |
network.routes.get | network:read | Gets a route. |
network.routes.update | network:write | Updates a route. |
network.routes.delete | network:write | Deletes a route. |
network.egress_identities.get | network:read | Gets an egress identity. |
network.egress_identities.update | network:write | Updates an egress identity. |
network.egress_identities.delete | network:write | Deletes an egress identity. |
network.private_links.get | network:read | Gets a private link. |
network.private_links.update | network:write | Updates a private link. |
network.private_links.delete | network:write | Deletes a private link. |
notify.mail_domains.get | notify:read | Gets an email domain. |
notify.mail_domains.update | notify:write | Updates an email domain. |
notify.mail_domains.delete | notify:write | Deletes an email domain. |
notify.mail_domains.verify | notify:write | Checks the domain's DNS records now instead of on the next sweep. |
notify.mail_routes.get | notify:read | Gets a route. |
notify.mail_routes.list | notify:read | Lists an email domain's routes. |
notify.mail_routes.create | notify:write | Creates a route. |
notify.mail_routes.update | notify:write | Updates a route. |
notify.mail_routes.delete | notify:write | Deletes a route. |
notify.senders.get | notify:read | Gets a sender. |
notify.senders.update | notify:write | Updates a sender. |
notify.senders.delete | notify:write | Deletes a sender. |
notify.senders.verify | notify:write | Re-checks the sender's registration or credentials now. |
notify.recipients.get | notify:read | Gets a recipient. |
notify.recipients.update | notify:write | Updates a recipient. |
notify.recipients.delete | notify:write | Deletes a recipient. |
notify.preferences.get | notify:read | Gets a preference. |
notify.preferences.update | notify:write | Updates a preference. |
notify.preferences.delete | notify:write | Deletes a preference. |
notify.suppressions.get | notify:read | Gets a suppression. |
notify.suppressions.delete | notify:write | Deletes a suppression. |
notify.templates.get | notify:read | Gets a template. |
notify.templates.update | notify:write | Updates a template. |
notify.templates.delete | notify:write | Deletes a template. |
notify.messages.get | notify:read | Gets a message. |
notify.messages.cancel | notify:send | Cancels a Message whose deliveries have not been handed off. |
notify.mailboxes.get | notify:read | Gets a mailbox. |
notify.mailboxes.update | notify:write | Updates a mailbox. |
notify.mailboxes.delete | notify:write | Deletes a mailbox and its inbound email. |
notify.mailboxes.erase_address | notify:write | Removes an address's personal data from every inbound email of the mailbox that it sent or that names it, keeping the dedupe keys so a poll never brings the mail back. |
notify.inbound_emails.get | notify:read | Gets an inbound email. |
notify.inbound_emails.list | notify:read | Lists a mailbox's inbound email in feed order, oldest first. |
notify.inbox_items.get | notify:read | Gets an inbox item. |
notify.inbox_items.mark_read | notify:write | Marks an inbox item read. |
notify.inbox_items.mark_unread | notify:write | Marks an inbox item unread. |
notify.inbox_items.archive | notify:write | Archives an inbox item. |
notify.broadcasts.get | notify:read | Gets a broadcast. |
notify.broadcasts.update | notify:write | Updates a broadcast. |
notify.broadcasts.delete | notify:write | Deletes a broadcast. |
notify.broadcasts.send | notify:send | Sends a Broadcast now. |
notify.broadcasts.cancel | notify:send | Cancels a Broadcast; messages already admitted still deliver. |
observability.log_entries.get | observability:read | Gets a log entry. |
observability.traces.get | observability:read | Gets a trace. |
observability.error_groups.get | observability:read | Gets an error group. |
observability.error_groups.acknowledge | observability:write | Acknowledges an error group. |
observability.error_groups.resolve | observability:write | Resolves an error group; a new occurrence reopens it. |
observability.error_groups.reopen | observability:write | Reopens a resolved or acknowledged error group. |
observability.error_events.get | observability:read | Gets an error event. |
observability.source_maps.get | observability:read | Gets a source map (without its content). |
observability.scrubbing_policies.get | observability:read | Gets the environment's scrubbing policy (scrubbing_policies/default). |
observability.scrubbing_policies.update | observability:write | Updates the environment's scrubbing policy. |
release.releases.get | release:read | Gets a release. |
release.rollouts.get | release:read | Gets a rollout. |
runners.scale_sets.get | runners:read | Gets a scale set. |
runners.scale_sets.update | runners:write | Updates a scale set. |
runners.scale_sets.delete | runners:write | Deletes a scale set. |
runners.runners.get | runners:read | Gets a runner. |
sandboxes.sandbox_shapes.get | sandboxes:read | Gets a shape. |
sandboxes.pools.get | sandboxes:read | Gets a pool. |
sandboxes.pools.update | sandboxes:write | Updates a pool. |
sandboxes.pools.delete | sandboxes:write | Deletes a pool. |
sandboxes.leases.get | sandboxes:read | Gets a lease. |
sandboxes.leases.create | sandboxes:write | Creates a lease: granted now and returned READY (or GRANTED when wait_ready is false), or refused with a typed error. There is no queue. |
sandboxes.leases.renew | sandboxes:write | Extends expire_time, never past the shape's longest lease. Does not change the generation. |
sandboxes.leases.release | sandboxes:write | Ends a lease with END_REASON_RELEASED; the machine is destroyed and never leased again, and attached volumes are detached. |
sandboxes.leases.pause | sandboxes:write | Pauses a lease: its disk is kept and its machine destroyed; the generation increases. Process memory is not kept. |
sandboxes.leases.resume | sandboxes:write | Resumes a paused lease on a machine granted now, or refuses it; the generation increases. |
sandboxes.leases.set_network | sandboxes:write | Replaces a running lease's outbound policy. The generation does not change; the new policy applies before the call returns. |
sandboxes.leases.mint_token | sandboxes:exec | Mints a lease token for the data plane, bound to the current generation. Hand it to a process that must not hold the Access key. |
sandboxes.leases.exec | sandboxes:exec | Runs one command in the lease to completion and returns its output, capped at 1 MiB per stream. Long-running or interactive processes use the guest protocol at status.endpoints.guest_uri. |
sandboxes.leases.read_file | sandboxes:exec | Reads one file from the lease, at most 16 MiB; larger files use the guest's /files. |
sandboxes.leases.write_file | sandboxes:exec | Writes one file in the lease, at most 16 MiB, creating parent directories. |
sandboxes.leases.list_files | sandboxes:exec | Lists one directory in the lease. |
sandboxes.leases.remove_file | sandboxes:exec | Removes one file or directory tree in the lease. |
sandboxes.leases.open_port | sandboxes:exec | Exposes a guest port. |
sandboxes.leases.close_port | sandboxes:exec | Stops exposing a guest port. |
sandboxes.leases.act | sandboxes:exec | Performs computer actions on a DESKTOP, BROWSER, or ANDROID lease, in order, and returns each action's result and, when screenshot is set, the screenshot taken after the last action. The actions are the Anthropic computer tool's and OpenAI computer use's, one-to-one. Refused CONTROL_HELD_BY_HUMAN while a human holds control. |
sandboxes.leases.open_stream | sandboxes:exec | Opens a read-only live view of a lease's display: a short-lived viewer token bound to the lease and its generation, an embeddable URL, and the WebRTC signaling endpoint with ICE servers. Input needs control (AcquireLeaseControl). |
sandboxes.leases.acquire_control | sandboxes:exec | Takes exclusive input control of a lease's display. A HUMAN acquire preempts an AGENT holder and returns a controller stream; an AGENT acquire is refused CONTROL_HELD_BY_HUMAN while a human holds control. Control lapses at ttl, which the platform caps at 30 minutes. |
sandboxes.leases.release_control | sandboxes:exec | Releases control held under epoch; its controller tokens stop working. |
sandboxes.leases.get_control | sandboxes:read | Gets who holds control of a lease's display. |
sandboxes.leases.install_app | sandboxes:exec | Installs an Android app (APK) on an ANDROID lease. |
sandboxes.lease_events.get | sandboxes:read | Gets one lease event. |
sandboxes.lease_events.list | sandboxes:read | Lists a lease's events in order. With wait, blocks up to that long for an event after page_token (long poll). |
sandboxes.volumes.get | sandboxes:read | Gets a volume. |
sandboxes.volumes.update | sandboxes:write | Updates a volume: grows spec.size_gib and edits metadata. |
sandboxes.volumes.delete | sandboxes:write | Deletes a volume and destroys its data. Refused RESOURCE_IN_USE while it is attached. |
sandboxes.snapshots.get | sandboxes:read | Gets a snapshot. |
sandboxes.snapshots.create | sandboxes:write | Captures a running lease's disk as a snapshot. |
sandboxes.snapshots.delete | sandboxes:write | Deletes a snapshot. |
secrets.secrets.get | secrets:read | Gets a secret. |
secrets.secrets.update | secrets:write | Updates a secret. |
secrets.secrets.delete | secrets:write | Deletes a secret and destroys every version. |
secrets.secret_versions.get | secrets:read | Gets a secret version. |
secrets.secret_versions.disable | secrets:write | Disables a secret version: bindings stop delivering it. |
secrets.secret_versions.enable | secrets:write | Enables a disabled secret version. |
secrets.secret_versions.destroy | secrets:write | Destroys a secret version's value irrecoverably. |
secrets.secret_versions.access | secrets:access | Reads a secret version's value back. Break-glass: a separate permission, audited on every call, and never exposed to MCP. |
secrets.secret_bindings.get | secrets:read | Gets a secret binding. |
secrets.secret_bindings.update | secrets:write | Updates a secret binding. |
secrets.secret_bindings.delete | secrets:write | Deletes a secret binding. |
workflows.workflows.get | workflows:read | Gets a workflow. |
workflows.workflows.update | workflows:write | Updates a workflow. |
workflows.workflows.delete | workflows:write | Deletes a workflow. |
workflows.schedules.get | workflows:read | Gets a schedule. |
workflows.schedules.update | workflows:write | Updates a schedule. |
workflows.schedules.delete | workflows:write | Deletes a schedule. |
workflows.schedules.pause | workflows:write | Pauses a Schedule: no fire starts a Run until it is resumed. |
workflows.schedules.resume | workflows:write | Resumes a paused Schedule; missed fires follow catchup_window. |
workflows.runs.get | workflows:read | Gets a run. |
workflows.runs.start_batch | workflows:run | Starts a batch: a parent Run that fans out one child Run per item, each with a stable index and count. |
workflows.runs.signal | workflows:run | Sends a named signal to a running Run; a wait op for that name resumes with its payload. A signal to a closed Run fails with INVALID_STATE. |
workflows.runs.cancel | workflows:run | Requests cancellation. Timers and waits stop; a running invocation is not interrupted: the handler receives one final invocation with cancel: true, and the Run ends cancelled when it answers. |
workflows.runs.wait | workflows:read | Waits up to timeout (at most 60s) for the Run to close, then returns it, closed or not. |
workflows.runs.read_history | workflows:read | Reads a page of the Run's immutable history, projected to Sylphx events. |
workflows.jobs.get | workflows:read | Gets a job. |
workflows.jobs.update | workflows:write | Updates a job. Runs already started keep the generation they pinned. |
workflows.jobs.delete | workflows:write | Deletes a job. |
workflows.job_runs.create | workflows:run | Starts a run of a Job now. The same Idempotency-Key returns the same run for 24h; a Schedule fire uses {job}:{intended time}. With concurrency forbid, a start while a run is active fails with INVALID_STATE. |
workflows.job_runs.get | workflows:read | Gets a job run. |
workflows.job_runs.cancel | workflows:run | Cancels a job run: SIGTERM, then SIGKILL after 30s. A closed run fails with INVALID_STATE. |
workflows.job_runs.read_logs | workflows:read | Reads a page of a job run's log lines, oldest first. With wait, an empty page on a running run waits up to that long for new lines, so a client follows the log by passing each next_page_token back. |
workflows.distributed_jobs.get | workflows:read | Gets a distributed job. |
workflows.distributed_jobs.update | workflows:write | Updates a distributed job. Runs already started keep the generation they pinned. |
workflows.distributed_jobs.delete | workflows:write | Deletes a distributed job. |
workflows.distributed_runs.create | workflows:run | Starts a run of a distributed job. The same Idempotency-Key returns the same run for 24h. |
workflows.distributed_runs.get | workflows:read | Gets a distributed run: its state, shard and worker counts, and usage. |
workflows.distributed_runs.cancel | workflows:run | Cancels a distributed run: workers get SIGTERM and 30s, then leases are released; finished shards are kept. A closed run fails with INVALID_STATE. |
workflows.distributed_runs.add_shards | workflows:run | Appends shards to a run started with an open manifest; close ends the manifest, and the run ends once those shards are done. |
workflows.distributed_runs.read_shards | workflows:read | Reads a page of the run's shards, in queue order. |
workflows.distributed_runs.read_workers | workflows:read | Reads a page of the run's workers. |