---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "UNAUTHENTICATED"
description: "UNAUTHENTICATED (UNAUTHENTICATED, HTTP 401): No valid key or token was presented."
type: reference
product: platform
summary: "No valid key or token was presented."
updated: 2026-09-28
nav: false
---

No valid key or token was presented.

**HTTP** 401 · **gRPC** `UNAUTHENTICATED` · [the error body](/docs/platform/errors)

## Returned by

| Method | Scope | What it does |
| --- | --- | --- |
| [`access.whoami`](/docs/api/access/whoami) | `access:whoami` | Returns the caller: the principal and the scope of the key or token that authenticated this request. Clients fill their org, project, and env defaults from it; every valid key may call it, whatever its scopes. |
| [`access.orgs.get`](/docs/api/orgs/get) | `access:read` | Gets an org. |
| [`access.orgs.list`](/docs/api/orgs/list) | `access:read` | Lists orgs the caller can see. |
| [`access.orgs.create`](/docs/api/orgs/create) | `access:admin` | Creates an org. Access assigns the id. |
| [`access.orgs.update`](/docs/api/orgs/update) | `access:admin` | Updates an org. |
| [`access.orgs.delete`](/docs/api/orgs/delete) | `access:admin` | Deletes an org and everything in it. Deletion cascades through every service, so it returns an Operation. |
| [`access.projects.get`](/docs/api/projects/get) | `access:read` | Gets a project. |
| [`access.projects.list`](/docs/api/projects/list) | `access:read` | Lists projects in an org. |
| [`access.projects.create`](/docs/api/projects/create) | `access:admin` | Creates a project. Access assigns the id. |
| [`access.projects.update`](/docs/api/projects/update) | `access:admin` | Updates a project. |
| [`access.projects.delete`](/docs/api/projects/delete) | `access:admin` | Deletes a project. |
| [`access.envs.get`](/docs/api/envs/get) | `access:read` | Gets an environment. |
| [`access.envs.list`](/docs/api/envs/list) | `access:read` | Lists environments in a project. |
| [`access.envs.create`](/docs/api/envs/create) | `access:admin` | Creates an environment. Access assigns the id. |
| [`access.envs.update`](/docs/api/envs/update) | `access:admin` | Updates an environment. |
| [`access.envs.delete`](/docs/api/envs/delete) | `access:admin` | Deletes an environment. |
| [`access.api_keys.get`](/docs/api/api_keys/get) | `access:read` | Gets an API key. |
| [`access.api_keys.list`](/docs/api/api_keys/list) | `access:read` | Lists API keys in an environment, or the org-wide keys of an org. |
| [`access.api_keys.create`](/docs/api/api_keys/create) | `access:keys:write` | Creates an API key. Access assigns the id. |
| [`access.api_keys.update`](/docs/api/api_keys/update) | `access:keys:write` | Updates an API key. |
| [`access.api_keys.delete`](/docs/api/api_keys/delete) | `access:keys:write` | Deletes an API key. |
| [`access.api_keys.revoke`](/docs/api/api_keys/revoke) | `access:keys:write` | Revokes an API key immediately; revocation propagates on its own fast path, ahead of the bulk key data. |
| [`access.api_keys.roll`](/docs/api/api_keys/roll) | `access:keys:write` | Rolls an API key: returns a new key with the same spec and revokes the old one after the grace period. |
| [`ai.ai_models.get`](/docs/api/ai_models/get) | `ai:read` | Gets an AI model. |
| [`ai.ai_models.list`](/docs/api/ai_models/list) | `ai:read` | Lists the admitted catalog; filter by `brand`, `modality`, or `model`. |
| [`artifacts.artifacts.get`](/docs/api/artifacts/get) | `artifacts:read` | Gets an artifact. |
| [`artifacts.artifacts.list`](/docs/api/artifacts/list) | `artifacts:read` | Lists a project's artifacts; filter by `digest`, `kind`, or `subject`. |
| [`artifacts.artifacts.create`](/docs/api/artifacts/create) | `artifacts:write` | Registers an artifact whose bytes were pushed by digest; verification runs after. |
| [`artifacts.artifacts.delete`](/docs/api/artifacts/delete) | `artifacts:write` | Deletes an artifact; fails while a Release references it or a legal hold is active. |
| [`assets.assets.get`](/docs/api/assets/get) | `assets:read` | Gets an asset. |
| [`assets.assets.list`](/docs/api/assets/list) | `assets:read` | Lists assets. The filter is limited to `kind`, `state`, and `review_state`. |
| [`assets.assets.generate`](/docs/api/assets/generate) | `assets:write` | Records the recipes as assets and generates the variants that are missing. Each call is idempotent and works within a bounded time; call again until `pending` is 0. |
| [`assets.assets.lock`](/docs/api/assets/lock) | `assets:read` | Returns the `assets.lock` entries and canonical text for the keys the call names, and only those. A read with a request body, like a query. |
| [`assets.assets.approve_variant`](/docs/api/assets/approve_variant) | `assets:write` | Approves one variant and records who approved it. |
| [`assets.assets.reject_variant`](/docs/api/assets/reject_variant) | `assets:write` | Rejects one variant. Its slot is freed and the next `:generate` fills it; the rejected file keeps serving at its URL. |
| [`assets.assets.retire_variant`](/docs/api/assets/retire_variant) | `assets:write` | Retires one variant. Its URL answers 404 from then on and its slot is freed. |
| [`auth.auth_configs.get`](/docs/api/auth_configs/get) | `auth:read` | Gets an auth config. |
| [`auth.auth_configs.update`](/docs/api/auth_configs/update) | `auth:write` | Updates an auth config. |
| [`auth.end_users.get`](/docs/api/end_users/get) | `auth:read` | Gets an end user. |
| [`auth.end_users.list`](/docs/api/end_users/list) | `auth:read` | Lists end users. |
| [`auth.end_users.create`](/docs/api/end_users/create) | `auth:write` | Creates an end user. |
| [`auth.end_users.update`](/docs/api/end_users/update) | `auth:write` | Updates an end user. |
| [`auth.end_users.delete`](/docs/api/end_users/delete) | `auth:write` | Deletes an end user. |
| [`auth.end_users.suspend`](/docs/api/end_users/suspend) | `auth:write` | Suspends an end user: sessions are revoked and sign-in is refused. |
| [`auth.end_users.reactivate`](/docs/api/end_users/reactivate) | `auth:write` | Reactivates a suspended end user. |
| [`auth.end_users.unlock`](/docs/api/end_users/unlock) | `auth:write` | Clears an end user's sign-in lock (repeated failed sign-ins) now. |
| [`auth.end_users.revoke_sessions`](/docs/api/end_users/revoke_sessions) | `auth:write` | Revokes every session of an end user. |
| [`auth.sessions.get`](/docs/api/sessions/get) | `auth:read` | Gets a session. |
| [`auth.sessions.list`](/docs/api/sessions/list) | `auth:read` | Lists sessions. |
| [`auth.sessions.revoke`](/docs/api/sessions/revoke) | `auth:write` | Revokes a session. |
| [`auth.customer_organizations.get`](/docs/api/customer_organizations/get) | `auth:read` | Gets a customer organization. |
| [`auth.customer_organizations.list`](/docs/api/customer_organizations/list) | `auth:read` | Lists customer organizations. |
| [`auth.customer_organizations.create`](/docs/api/customer_organizations/create) | `auth:write` | Creates a customer organization. |
| [`auth.customer_organizations.update`](/docs/api/customer_organizations/update) | `auth:write` | Updates a customer organization. |
| [`auth.customer_organizations.delete`](/docs/api/customer_organizations/delete) | `auth:write` | Deletes a customer organization. |
| [`auth.memberships.get`](/docs/api/memberships/get) | `auth:read` | Gets a membership. |
| [`auth.memberships.list`](/docs/api/memberships/list) | `auth:read` | Lists memberships. |
| [`auth.memberships.create`](/docs/api/memberships/create) | `auth:write` | Creates a membership. |
| [`auth.memberships.update`](/docs/api/memberships/update) | `auth:write` | Updates a membership. |
| [`auth.memberships.delete`](/docs/api/memberships/delete) | `auth:write` | Deletes a membership. |
| [`auth.organization_roles.get`](/docs/api/organization_roles/get) | `auth:read` | Gets an organization role. |
| [`auth.organization_roles.list`](/docs/api/organization_roles/list) | `auth:read` | Lists organization roles. |
| [`auth.organization_roles.create`](/docs/api/organization_roles/create) | `auth:write` | Creates an organization role. |
| [`auth.organization_roles.update`](/docs/api/organization_roles/update) | `auth:write` | Updates an organization role. |
| [`auth.organization_roles.delete`](/docs/api/organization_roles/delete) | `auth:write` | Deletes an organization role. |
| [`auth.invitations.get`](/docs/api/invitations/get) | `auth:read` | Gets an invitation. |
| [`auth.invitations.list`](/docs/api/invitations/list) | `auth:read` | Lists invitations. |
| [`auth.invitations.create`](/docs/api/invitations/create) | `auth:write` | Creates an invitation. |
| [`auth.invitations.revoke`](/docs/api/invitations/revoke) | `auth:write` | Revokes a pending invitation. |
| [`auth.invitations.accept`](/docs/api/invitations/accept) | `auth:write` | Accepts a pending invitation for an end user whose verified email is the invited address, and creates the membership. |
| [`auth.email_domains.get`](/docs/api/email_domains/get) | `auth:read` | Gets an email domain. |
| [`auth.email_domains.list`](/docs/api/email_domains/list) | `auth:read` | Lists email domains. |
| [`auth.email_domains.create`](/docs/api/email_domains/create) | `auth:write` | Creates an email domain; the answer names the TXT record to publish. |
| [`auth.email_domains.delete`](/docs/api/email_domains/delete) | `auth:write` | Deletes an email domain. |
| [`auth.email_domains.verify`](/docs/api/email_domains/verify) | `auth:write` | Looks up the domain's TXT record now; found, the domain is verified. |
| [`auth.oauth_clients.get`](/docs/api/oauth_clients/get) | `auth:read` | Gets an OAuth client. |
| [`auth.oauth_clients.list`](/docs/api/oauth_clients/list) | `auth:read` | Lists OAuth clients. |
| [`auth.oauth_clients.create`](/docs/api/oauth_clients/create) | `auth:write` | Creates an OAuth client. |
| [`auth.oauth_clients.update`](/docs/api/oauth_clients/update) | `auth:write` | Updates an OAuth client. |
| [`auth.oauth_clients.delete`](/docs/api/oauth_clients/delete) | `auth:write` | Deletes an OAuth client. |
| [`auth.oauth_clients.roll_secret`](/docs/api/oauth_clients/roll_secret) | `auth:write` | Issues a new client secret, returned once; the old one verifies until `grace_period` ends. |
| [`billing.meters.get`](/docs/api/meters/get) | `billing:read` | Gets a meter. |
| [`billing.meters.list`](/docs/api/meters/list) | `billing:read` | Lists meters. Anonymous-readable: the pricing page renders from it. |
| [`billing.plans.get`](/docs/api/plans/get) | `billing:read` | Gets a plan. |
| [`billing.plans.list`](/docs/api/plans/list) | `billing:read` | Lists the plans the caller can see. Anonymous-readable: the pricing page renders from it. |
| [`billing.billing_accounts.get`](/docs/api/billing_accounts/get) | `billing:read` | Gets a billing account. |
| [`billing.billing_accounts.list`](/docs/api/billing_accounts/list) | `billing:read` | Lists an org's billing accounts: exactly one, `default`. |
| [`billing.billing_accounts.update`](/docs/api/billing_accounts/update) | `billing:admin` | Updates a billing account: changes plan, spend limit, or billing email. |
| [`billing.billing_accounts.setup_payment_method`](/docs/api/billing_accounts/setup_payment_method) | `billing:admin` | Starts saving a payment method for the org: returns a client secret the console confirms with Stripe.js, so card data never reaches Sylphx. The saved method becomes the account's default and is charged off-session for each finalized invoice. |
| [`billing.invoices.get`](/docs/api/invoices/get) | `billing:read` | Gets an invoice. |
| [`billing.invoices.list`](/docs/api/invoices/list) | `billing:read` | Lists an org's invoices. |
| [`billing.usage_reports.get`](/docs/api/usage_reports/get) | `billing:read` | Gets an usage report. |
| [`billing.usage_reports.list`](/docs/api/usage_reports/list) | `billing:read` | Lists an org's usage reports, one per billing period. |
| [`billing.usage_reports.query`](/docs/api/usage_reports/query) | `billing:read` | Queries usage over any time range, bucketed and grouped: the usage summary the console charts. Reads rollups; never raw events. |
| [`billing.budget_leases.get`](/docs/api/budget_leases/get) | `billing:read` | Gets a budget lease. |
| [`billing.budget_leases.list`](/docs/api/budget_leases/list) | `billing:read` | Lists an org's budget leases. |
| [`broker.trust_policies.get`](/docs/api/trust_policies/get) | `broker:read` | Gets a trust policy. |
| [`broker.trust_policies.list`](/docs/api/trust_policies/list) | `broker:read` | Lists an org's trust policies. |
| [`broker.trust_policies.create`](/docs/api/trust_policies/create) | `broker:admin` | Creates a trust policy. |
| [`broker.trust_policies.update`](/docs/api/trust_policies/update) | `broker:admin` | Updates a trust policy. |
| [`broker.trust_policies.delete`](/docs/api/trust_policies/delete) | `broker:admin` | Deletes a trust policy. |
| [`broker.trust_policies.exchange_token`](/docs/api/trust_policies/exchange_token) | `broker:exchange` | Exchanges the caller's workload identity for a short-lived provider credential under a trust policy (RFC 8693 token exchange). The credential is narrowed to the request and cached per installation and permission set; a permission the Connection lacks is PERMISSION_DENIED with reason `CapabilityMissing`, never an outage. |
| [`build.builds.get`](/docs/api/builds/get) | `build:read` | Gets a build. |
| [`build.builds.list`](/docs/api/builds/list) | `build:read` | Lists builds in a project. |
| [`build.builds.create`](/docs/api/builds/create) | `build:write` | Creates a build. The Operation is done when the controller settles it. |
| [`build.builds.cancel`](/docs/api/builds/cancel) | `build:write` | Cancels a queued or running Build; its lease is released and nothing is published. |
| [`build.build_caches.get`](/docs/api/build_caches/get) | `build:read` | Gets a build cache. |
| [`build.build_caches.list`](/docs/api/build_caches/list) | `build:read` | Lists build caches in a project. |
| [`build.build_caches.update`](/docs/api/build_caches/update) | `build:write` | Updates a build cache. |
| [`build.build_caches.delete`](/docs/api/build_caches/delete) | `build:write` | Deletes a build cache. |
| [`config.config_flags.get`](/docs/api/config_flags/get) | `config:read` | Gets a config flag. |
| [`config.config_flags.list`](/docs/api/config_flags/list) | `config:read` | Lists config flags in an environment. |
| [`config.config_flags.create`](/docs/api/config_flags/create) | `config:write` | Creates a config flag; the Operation is done when every cell serves it. |
| [`config.config_flags.update`](/docs/api/config_flags/update) | `config:write` | Updates a config flag; the change rolls out in waves and the Operation is done when every cell serves it. |
| [`config.config_flags.delete`](/docs/api/config_flags/delete) | `config:write` | Deletes a config flag; evaluators then get their compiled-in fallback. |
| [`config.config_flags.evaluate`](/docs/api/config_flags/evaluate) | `config:evaluate` | Evaluates config flags of an environment for one evaluation context: each flag's value, and why. Browsers and mobile apps call it with a publishable key holding `config:evaluate`, which reads values, never rules. |
| [`config.config_flags.snapshot`](/docs/api/config_flags/snapshot) | `config:read` | The environment's flags and segments in one read, for SDKs that evaluate locally. Poll it with `if_none_match` set to the last `etag`: an unchanged ruleset answers `not_modified` and nothing else. |
| [`config.config_segments.get`](/docs/api/config_segments/get) | `config:read` | Gets a config segment. |
| [`config.config_segments.list`](/docs/api/config_segments/list) | `config:read` | Lists config segments in an environment. |
| [`config.config_segments.create`](/docs/api/config_segments/create) | `config:write` | Creates a config segment. |
| [`config.config_segments.update`](/docs/api/config_segments/update) | `config:write` | Updates a config segment; every flag naming it follows. |
| [`config.config_segments.delete`](/docs/api/config_segments/delete) | `config:write` | Deletes a config segment; refused while a flag names it. |
| [`config.config_changes.get`](/docs/api/config_changes/get) | `config:read` | Gets a config change. |
| [`config.config_changes.list`](/docs/api/config_changes/list) | `config:read` | Lists config changes in an environment. |
| [`connections.connection_providers.get`](/docs/api/connection_providers/get) | `connections:read` | Gets a connection provider. |
| [`connections.connection_providers.list`](/docs/api/connection_providers/list) | `connections:read` | Lists an org's connection providers. |
| [`connections.connection_providers.create`](/docs/api/connection_providers/create) | `connections:admin` | Creates a connection provider. |
| [`connections.connection_providers.update`](/docs/api/connection_providers/update) | `connections:admin` | Updates a connection provider. |
| [`connections.connection_providers.delete`](/docs/api/connection_providers/delete) | `connections:admin` | Deletes a connection provider; it must have no connections. |
| [`connections.connections.get`](/docs/api/connections/get) | `connections:read` | Gets a connection. |
| [`connections.connections.list`](/docs/api/connections/list) | `connections:read` | Lists an org's connections. |
| [`connections.connections.create`](/docs/api/connections/create) | `connections:write` | Records an installation; the controller confirms it with the provider. |
| [`connections.connections.update`](/docs/api/connections/update) | `connections:write` | Updates a connection's metadata. |
| [`connections.connections.delete`](/docs/api/connections/delete) | `connections:write` | Forgets a connection. The installation itself is removed at the provider. |
| [`data.objects.put`](/docs/api/objects/put) | `data:write` | Writes an object's bytes, replacing the current version. `body` is the base64 of the bytes. |
| [`data.objects.get`](/docs/api/objects/get) | `data:read` | Reads an object and its bytes (`body`, base64). |
| [`data.objects.list`](/docs/api/objects/list) | `data:read` | Lists a bucket's objects in key order. |
| [`data.objects.delete`](/docs/api/objects/delete) | `data:write` | Deletes an object's current version (history is kept). |
| [`data.kv.put`](/docs/api/kv/put) | `data:write` | Writes a value. Without `ttl_seconds` the namespace default applies; zero means no expiry. |
| [`data.kv.get`](/docs/api/kv/get) | `data:read` | Reads a value. |
| [`data.kv.list`](/docs/api/kv/list) | `data:read` | Lists a namespace's values in key order. |
| [`data.kv.delete`](/docs/api/kv/delete) | `data:write` | Deletes a value. |
| [`data.kv.increment`](/docs/api/kv/increment) | `data:write` | Adds `delta` (default 1) to an integer value, creating it at zero. |
| [`data.kv.get_many`](/docs/api/kv/get_many) | `data:read` | Reads up to 1000 keys at once (MGET). Answers one entry per key, in order; an absent or expired key keeps its key and has no `value`. |
| [`data.kv.hash_set`](/docs/api/kv/hash_set) | `data:write` | Sets fields of a hash (HSET), creating it. |
| [`data.kv.hash_get`](/docs/api/kv/hash_get) | `data:read` | Reads one field of a hash (HGET); an absent field has no `value`. |
| [`data.kv.hash_get_all`](/docs/api/kv/hash_get_all) | `data:read` | Reads every field of a hash (HGETALL). |
| [`data.kv.hash_get_many`](/docs/api/kv/hash_get_many) | `data:read` | Reads several fields of a hash (HMGET), one per field, in order; an absent field has no `value`. |
| [`data.kv.list_push`](/docs/api/kv/list_push) | `data:write` | Pushes values onto the head of a list (LPUSH), creating it. |
| [`data.kv.list_range`](/docs/api/kv/list_range) | `data:read` | Reads a range of a list (LRANGE); negative indexes count from the end. |
| [`data.kv.list_pop`](/docs/api/kv/list_pop) | `data:write` | Pops values from the head of a list (LPOP); an emptied list is removed. |
| [`data.kv.list_length`](/docs/api/kv/list_length) | `data:read` | Reads the length of a list (LLEN); an absent key has length zero. |
| [`data.kv.zset_add`](/docs/api/kv/zset_add) | `data:write` | Adds members to a sorted set or updates their scores (ZADD), creating it. |
| [`data.kv.zset_range`](/docs/api/kv/zset_range) | `data:read` | Reads a range of a sorted set by rank, lowest score first (ZRANGE); negative indexes count from the end. |
| [`data.kv.zset_score`](/docs/api/kv/zset_score) | `data:read` | Reads a member's score (ZSCORE); an absent member has no `score`. |
| [`data.kv.zset_length`](/docs/api/kv/zset_length) | `data:read` | Reads the size of a sorted set (ZCARD); an absent key has size zero. |
| [`data.kv.scan`](/docs/api/kv/scan) | `data:read` | Walks a namespace's keys that match a glob (SCAN). Call again with the returned `cursor` until it is empty. |
| [`data.kv.expire`](/docs/api/kv/expire) | `data:write` | Sets a key's time to live (EXPIRE) without rewriting its value; zero makes it persistent. |
| [`data.documents.put`](/docs/api/documents/put) | `data:write` | Writes a document to a search index, replacing the current version. |
| [`data.documents.get`](/docs/api/documents/get) | `data:read` | Reads a document. |
| [`data.documents.delete`](/docs/api/documents/delete) | `data:write` | Deletes a document. |
| [`data.search.query`](/docs/api/search/query) | `data:read` | Searches an index by text, by vector, or both, best match first, with filters and paging. |
| [`data.databases.get`](/docs/api/databases/get) | `data:read` | Gets a database. |
| [`data.databases.list`](/docs/api/databases/list) | `data:read` | Lists databases in a environment. |
| [`data.databases.create`](/docs/api/databases/create) | `data:write` | Creates a database. The Operation is done when the controller settles it. |
| [`data.databases.update`](/docs/api/databases/update) | `data:write` | Updates a database. |
| [`data.databases.delete`](/docs/api/databases/delete) | `data:write` | Deletes a database. Fails while `spec.deletion_protection` is set. |
| [`data.databases.connect`](/docs/api/databases/connect) | `data:write` | Returns how to connect to the database: its endpoint and its own engine credentials. The credentials are not API keys and are returned only here. |
| [`data.databases.rotate_credentials`](/docs/api/databases/rotate_credentials) | `data:write` | Replaces the database's engine credentials; the old ones stop working once the new ones are served. |
| [`data.databases.restore`](/docs/api/databases/restore) | `data:write` | Restores the database in place to a point in time inside its retention window; the database is unavailable while it restores. |
| [`data.kv_namespaces.get`](/docs/api/kv_namespaces/get) | `data:read` | Gets a kv namespace. |
| [`data.kv_namespaces.list`](/docs/api/kv_namespaces/list) | `data:read` | Lists kv namespaces in a environment. |
| [`data.kv_namespaces.create`](/docs/api/kv_namespaces/create) | `data:write` | Creates a kv namespace. The Operation is done when the controller settles it. |
| [`data.kv_namespaces.update`](/docs/api/kv_namespaces/update) | `data:write` | Updates a kv namespace. |
| [`data.kv_namespaces.delete`](/docs/api/kv_namespaces/delete) | `data:write` | Deletes a kv namespace. Fails while `spec.deletion_protection` is set. |
| [`data.kv_namespaces.connect`](/docs/api/kv_namespaces/connect) | `data:write` | Returns how to connect to the KV namespace: its endpoint and its own engine credentials. The credentials are not API keys and are returned only here. |
| [`data.kv_namespaces.rotate_credentials`](/docs/api/kv_namespaces/rotate_credentials) | `data:write` | Replaces the KV namespace's engine credentials; the old ones stop working once the new ones are served. |
| [`data.buckets.get`](/docs/api/buckets/get) | `data:read` | Gets a bucket. |
| [`data.buckets.list`](/docs/api/buckets/list) | `data:read` | Lists buckets in a environment. |
| [`data.buckets.create`](/docs/api/buckets/create) | `data:write` | Creates a bucket. The Operation is done when the controller settles it. |
| [`data.buckets.update`](/docs/api/buckets/update) | `data:write` | Updates a bucket. |
| [`data.buckets.delete`](/docs/api/buckets/delete) | `data:write` | Deletes a bucket. Fails while `spec.deletion_protection` is set. |
| [`data.buckets.connect`](/docs/api/buckets/connect) | `data:write` | Returns how to connect to the bucket: its endpoint and its own engine credentials. The credentials are not API keys and are returned only here. |
| [`data.buckets.rotate_credentials`](/docs/api/buckets/rotate_credentials) | `data:write` | Replaces the bucket's engine credentials; the old ones stop working once the new ones are served. |
| [`data.search_indexes.get`](/docs/api/search_indexes/get) | `data:read` | Gets a search index. |
| [`data.search_indexes.list`](/docs/api/search_indexes/list) | `data:read` | Lists search indexs in a environment. |
| [`data.search_indexes.create`](/docs/api/search_indexes/create) | `data:write` | Creates a search index. The Operation is done when the controller settles it. |
| [`data.search_indexes.update`](/docs/api/search_indexes/update) | `data:write` | Updates a search index. |
| [`data.search_indexes.delete`](/docs/api/search_indexes/delete) | `data:write` | Deletes a search index. Fails while `spec.deletion_protection` is set. |
| [`data.search_indexes.connect`](/docs/api/search_indexes/connect) | `data:write` | Returns how to connect to the search index: its endpoint and its own engine credentials. The credentials are not API keys and are returned only here. |
| [`data.search_indexes.rotate_credentials`](/docs/api/search_indexes/rotate_credentials) | `data:write` | Replaces the search index's engine credentials; the old ones stop working once the new ones are served. |
| [`entitlement.entitlements.get`](/docs/api/entitlements/get) | `entitlement:read` | Gets an org's entitlement. |
| [`entitlement.entitlements.list`](/docs/api/entitlements/list) | `entitlement:read` | Lists an org's entitlements: exactly one, `default`. |
| [`events.topics.get`](/docs/api/topics/get) | `events:read` | Gets a topic. |
| [`events.topics.list`](/docs/api/topics/list) | `events:read` | Lists topics. |
| [`events.topics.create`](/docs/api/topics/create) | `events:write` | Creates a topic. |
| [`events.topics.update`](/docs/api/topics/update) | `events:write` | Updates a topic. |
| [`events.topics.delete`](/docs/api/topics/delete) | `events:write` | Deletes a topic. |
| [`events.topics.publish`](/docs/api/topics/publish) | `events:publish` | Publishes CloudEvents into a Topic, atomically. Replaying the same `source` + `id` with the same payload returns the stored event; a different payload fails with RESOURCE_ALREADY_EXISTS. |
| [`events.events.get`](/docs/api/events/get) | `events:read` | Gets an event. |
| [`events.events.list`](/docs/api/events/list) | `events:read` | Lists events. |
| [`events.connectors.get`](/docs/api/connectors/get) | `events:read` | Gets a connector. |
| [`events.connectors.list`](/docs/api/connectors/list) | `events:read` | Lists connectors. |
| [`events.subscriptions.get`](/docs/api/subscriptions/get) | `events:read` | Gets a subscription. |
| [`events.subscriptions.list`](/docs/api/subscriptions/list) | `events:read` | Lists subscriptions. |
| [`events.subscriptions.create`](/docs/api/subscriptions/create) | `events:write` | Creates a subscription. |
| [`events.subscriptions.update`](/docs/api/subscriptions/update) | `events:write` | Updates a subscription. |
| [`events.subscriptions.delete`](/docs/api/subscriptions/delete) | `events:write` | Deletes a subscription. |
| [`events.queues.get`](/docs/api/queues/get) | `events:read` | Gets a queue. |
| [`events.queues.list`](/docs/api/queues/list) | `events:read` | Lists queues. |
| [`events.queues.create`](/docs/api/queues/create) | `events:write` | Creates a queue. |
| [`events.queues.update`](/docs/api/queues/update) | `events:write` | Updates a queue. |
| [`events.queues.delete`](/docs/api/queues/delete) | `events:write` | Deletes a queue. |
| [`events.queues.send`](/docs/api/queues/send) | `events:publish` | Enqueues messages directly, without a Subscription. |
| [`events.queues.lease`](/docs/api/queues/lease) | `events:write` | Leases up to `max_messages` ready messages for the visibility timeout. |
| [`events.queues.ack`](/docs/api/queues/ack) | `events:write` | Acknowledges leased messages; each is removed. A lease that is stale (expired or superseded) is reported, not applied. |
| [`events.queues.nack`](/docs/api/queues/nack) | `events:write` | Returns leased messages to the Queue after `delay`; each nack counts as a delivery. |
| [`events.queues.replay`](/docs/api/queues/replay) | `events:write` | Moves dead-lettered messages, optionally bounded by dead-letter time, back to ready. |
| [`events.webhook_endpoints.get`](/docs/api/webhook_endpoints/get) | `events:read` | Gets a webhook endpoint. |
| [`events.webhook_endpoints.list`](/docs/api/webhook_endpoints/list) | `events:read` | Lists webhook endpoints. |
| [`events.webhook_endpoints.create`](/docs/api/webhook_endpoints/create) | `events:write` | Creates a webhook endpoint. |
| [`events.webhook_endpoints.update`](/docs/api/webhook_endpoints/update) | `events:write` | Updates a webhook endpoint. |
| [`events.webhook_endpoints.delete`](/docs/api/webhook_endpoints/delete) | `events:write` | Deletes a webhook endpoint. |
| [`events.webhook_endpoints.replay`](/docs/api/webhook_endpoints/replay) | `events:write` | Redelivers every dead-lettered delivery to the endpoint created in a time range, each as a new attempt. |
| [`events.webhook_endpoints.rotate_secret`](/docs/api/webhook_endpoints/rotate_secret) | `events:write` | Replaces the endpoint's signing secret and returns the new one, once (`status.signing_secret`). For 24 hours deliveries carry a signature with each secret, so a receiver can switch without dropping one. |
| [`events.webhook_endpoints.test`](/docs/api/webhook_endpoints/test) | `events:write` | Sends a test event (`type` `sylphx.webhook.test`) to the endpoint alone, through the same signing, retries, and delivery log as any other event. |
| [`events.webhook_deliveries.get`](/docs/api/webhook_deliveries/get) | `events:read` | Gets a webhook delivery. |
| [`events.webhook_deliveries.list`](/docs/api/webhook_deliveries/list) | `events:read` | Lists webhook deliveries. |
| [`events.webhook_deliveries.replay`](/docs/api/webhook_deliveries/replay) | `events:write` | Redelivers one delivery now, as a new attempt. |
| [`events.inbound_endpoints.get`](/docs/api/inbound_endpoints/get) | `events:read` | Gets an inbound endpoint. |
| [`events.inbound_endpoints.list`](/docs/api/inbound_endpoints/list) | `events:read` | Lists inbound endpoints. |
| [`events.inbound_endpoints.create`](/docs/api/inbound_endpoints/create) | `events:write` | Creates an inbound endpoint. |
| [`events.inbound_endpoints.update`](/docs/api/inbound_endpoints/update) | `events:write` | Updates an inbound endpoint. |
| [`events.inbound_endpoints.delete`](/docs/api/inbound_endpoints/delete) | `events:write` | Deletes an inbound endpoint. |
| [`events.realtime_channels.get`](/docs/api/realtime_channels/get) | `events:read` | Gets a realtime channel. |
| [`events.realtime_channels.list`](/docs/api/realtime_channels/list) | `events:read` | Lists realtime channels. |
| [`events.realtime_channels.create`](/docs/api/realtime_channels/create) | `events:write` | Creates a realtime channel. |
| [`events.realtime_channels.update`](/docs/api/realtime_channels/update) | `events:write` | Updates a realtime channel. |
| [`events.realtime_channels.publish`](/docs/api/realtime_channels/publish) | `events:publish` | Publishes one message to the channel: it is appended to the channel's history and pushed to every connected client. A retry with the same Idempotency-Key returns the first message. |
| [`events.realtime_channels.issue_token`](/docs/api/realtime_channels/issue_token) | `events:publish` | Mints a subscribe token (`rtt_…`) for this channel alone, at most an hour long, for a browser or device that holds no key. A token that names a client id enters the channel's presence while it is connected. |
| [`events.realtime_channels.delete`](/docs/api/realtime_channels/delete) | `events:write` | Deletes a realtime channel. |
| [`events.realtime_messages.get`](/docs/api/realtime_messages/get) | `events:read` | Gets one retained message of a channel. |
| [`events.realtime_messages.list`](/docs/api/realtime_messages/list) | `events:read` | Lists a channel's retained messages, oldest first. |
| [`events.realtime_members.get`](/docs/api/realtime_members/get) | `events:read` | Gets one client present in a channel. |
| [`events.realtime_members.list`](/docs/api/realtime_members/list) | `events:read` | Lists the clients present in a channel now. |
| [`hosting.services.get`](/docs/api/services/get) | `hosting:read` | Gets a service. |
| [`hosting.services.list`](/docs/api/services/list) | `hosting:read` | Lists services in a environment. |
| [`hosting.services.create`](/docs/api/services/create) | `hosting:write` | Creates a service. The Operation is done when the controller settles it. |
| [`hosting.services.update`](/docs/api/services/update) | `hosting:write` | Updates a service. |
| [`hosting.services.delete`](/docs/api/services/delete) | `hosting:write` | Deletes a service. |
| [`hosting.service_rollouts.get`](/docs/api/service_rollouts/get) | `hosting:read` | Gets a rollout. |
| [`hosting.service_rollouts.list`](/docs/api/service_rollouts/list) | `hosting:read` | Lists rollouts in a service. |
| [`hosting.service_rollouts.create`](/docs/api/service_rollouts/create) | `hosting:write` | Creates a rollout. |
| [`hosting.service_rollouts.pause`](/docs/api/service_rollouts/pause) | `hosting:write` | Holds a Rollout at its current wave. |
| [`hosting.service_rollouts.resume`](/docs/api/service_rollouts/resume) | `hosting:write` | Resumes a paused Rollout. |
| [`hosting.service_rollouts.abort`](/docs/api/service_rollouts/abort) | `hosting:write` | Stops a Rollout; the cells it reached return to the previous Release. |
| [`hosting.previews.get`](/docs/api/previews/get) | `hosting:read` | Gets a preview. |
| [`hosting.previews.list`](/docs/api/previews/list) | `hosting:read` | Lists previews in a environment. |
| [`hosting.previews.create`](/docs/api/previews/create) | `hosting:write` | Creates a preview. The Operation is done when the controller settles it. |
| [`hosting.previews.delete`](/docs/api/previews/delete) | `hosting:write` | Deletes a preview. |
| [`hosting.source_links.get`](/docs/api/source_links/get) | `hosting:read` | Gets a source link. |
| [`hosting.source_links.list`](/docs/api/source_links/list) | `hosting:read` | Lists source links in a project. |
| [`hosting.source_links.create`](/docs/api/source_links/create) | `hosting:write` | Creates a source link. The Operation is done when the controller settles it. |
| [`hosting.source_links.update`](/docs/api/source_links/update) | `hosting:write` | Updates a source link. |
| [`hosting.source_links.delete`](/docs/api/source_links/delete) | `hosting:write` | Deletes a source link. |
| [`keys.keys.get`](/docs/api/keys/get) | `keys:read` | Gets a key. |
| [`keys.keys.list`](/docs/api/keys/list) | `keys:read` | Lists keys in an environment. |
| [`keys.keys.create`](/docs/api/keys/create) | `keys:write` | Creates a key; the signer generates its first version. |
| [`keys.keys.update`](/docs/api/keys/update) | `keys:write` | Updates a key's rotation period, deletion protection, or metadata. |
| [`keys.keys.delete`](/docs/api/keys/delete) | `keys:write` | Deletes a key and schedules every version's destruction. |
| [`keys.keys.rotate`](/docs/api/keys/rotate) | `keys:write` | Rotates a key: adds a version and makes it primary. Older versions keep verifying and decrypting until destroyed. |
| [`keys.keys.sign`](/docs/api/keys/sign) | `keys:sign` | Signs data or a digest with a SIGN key. Every use is audited. |
| [`keys.keys.verify`](/docs/api/keys/verify) | `keys:verify` | Verifies a signature made by a SIGN key. |
| [`keys.keys.encrypt`](/docs/api/keys/encrypt) | `keys:encrypt` | Encrypts data with an ENCRYPT key. |
| [`keys.keys.decrypt`](/docs/api/keys/decrypt) | `keys:decrypt` | Decrypts a ciphertext made by Encrypt with this key. |
| [`keys.keys.mac_sign`](/docs/api/keys/mac_sign) | `keys:sign` | Computes a MAC of data with a MAC key. |
| [`keys.keys.mac_verify`](/docs/api/keys/mac_verify) | `keys:verify` | Verifies a MAC made by a MAC key, in constant time. |
| [`keys.key_versions.get`](/docs/api/key_versions/get) | `keys:read` | Gets a key version. |
| [`keys.key_versions.list`](/docs/api/key_versions/list) | `keys:read` | Lists a key's versions. |
| [`keys.key_versions.destroy`](/docs/api/key_versions/destroy) | `keys:write` | Schedules a key version's destruction after a 24-hour grace; the primary version cannot be destroyed. |
| [`localization.catalogs.get`](/docs/api/catalogs/get) | `localization:read` | Gets a catalog. |
| [`localization.catalogs.list`](/docs/api/catalogs/list) | `localization:read` | Lists catalogs. |
| [`localization.catalogs.create`](/docs/api/catalogs/create) | `localization:write` | Creates a catalog. |
| [`localization.catalogs.update`](/docs/api/catalogs/update) | `localization:write` | Updates a catalog. |
| [`localization.catalogs.delete`](/docs/api/catalogs/delete) | `localization:write` | Deletes a catalog. |
| [`localization.catalogs.sync`](/docs/api/catalogs/sync) | `localization:write` | Reads the source files and the committed translations into the catalog, then translates what is new or stale. Each call is idempotent and works within a bounded time; call again until `pending` is 0. |
| [`localization.catalogs.export`](/docs/api/catalogs/export) | `localization:read` | Returns the catalog's files per locale in the requested format, with the QA report. A read with a request body, like a query. |
| [`localization.entries.get`](/docs/api/entries/get) | `localization:read` | Gets a catalog entry. |
| [`localization.entries.list`](/docs/api/entries/list) | `localization:read` | Lists catalog entries. The filter is limited to `state`, `locale`, and `qa_state`. |
| [`localization.entries.pin_translation`](/docs/api/entries/pin_translation) | `localization:write` | Sets the text of one locale as a human override that AI never overwrites. QA runs on the text first; a text with a QA error is rejected with `INVALID_FIELD`, and the problem lists the findings. |
| [`localization.entries.unpin_translation`](/docs/api/entries/unpin_translation) | `localization:write` | Removes the human override of one locale; the next sync may translate it again. |
| [`localization.glossaries.get`](/docs/api/glossaries/get) | `localization:read` | Gets a glossary. |
| [`localization.glossaries.list`](/docs/api/glossaries/list) | `localization:read` | Lists glossarys. |
| [`localization.glossaries.create`](/docs/api/glossaries/create) | `localization:write` | Creates a glossary. |
| [`localization.glossaries.update`](/docs/api/glossaries/update) | `localization:write` | Updates a glossary. |
| [`localization.glossaries.delete`](/docs/api/glossaries/delete) | `localization:write` | Deletes a glossary. |
| [`money.price_catalogs.get`](/docs/api/price_catalogs/get) | `billing:read` | Gets the environment's catalog. |
| [`money.price_catalogs.update`](/docs/api/price_catalogs/update) | `billing:write` | Updates the environment's catalog: its features and products, whole. |
| [`money.price_catalogs.sync`](/docs/api/price_catalogs/sync) | `billing:write` | Pushes the catalog to the merchant account's processor now: products and prices by lookup key; an amount change makes a new price. |
| [`money.store_connections.get`](/docs/api/store_connections/get) | `billing:read` | Gets a store connection. |
| [`money.store_connections.list`](/docs/api/store_connections/list) | `billing:read` | Lists store connections. |
| [`money.store_connections.create`](/docs/api/store_connections/create) | `billing:write` | Creates a store connection; its credential is sealed and never returned. |
| [`money.store_connections.update`](/docs/api/store_connections/update) | `billing:write` | Updates a store connection; a new credential replaces the stored one. |
| [`money.store_connections.delete`](/docs/api/store_connections/delete) | `billing:write` | Deletes a store connection and its sealed credential. |
| [`money.store_purchases.verify`](/docs/api/store_purchases/verify) | `billing:write` | Verifies a store purchase with the store, binds it to the subject, and returns its record and a signed grant. Re-verifying returns the same record and grant. Called from the app's server with a secret key that holds `billing:write`; a publishable key cannot call it. |
| [`money.store_purchases.get`](/docs/api/store_purchases/get) | `billing:read` | Gets a store purchase. |
| [`money.store_purchases.list`](/docs/api/store_purchases/list) | `billing:read` | Lists store purchases, newest first. |
| [`money.customer_subscriptions.get`](/docs/api/customer_subscriptions/get) | `billing:read` | Gets a customer subscription. |
| [`money.customer_subscriptions.list`](/docs/api/customer_subscriptions/list) | `billing:read` | Lists customer subscriptions, newest first. |
| [`money.customer_subscriptions.cancel`](/docs/api/customer_subscriptions/cancel) | `billing:write` | Cancels a web subscription, now or at the period end, and optionally refunds its last payment (for example a statutory cancellation window). |
| [`money.customer_subscriptions.resume`](/docs/api/customer_subscriptions/resume) | `billing:write` | Resumes a web subscription set to cancel at its period end. |
| [`money.customer_subscriptions.update_quantity`](/docs/api/customer_subscriptions/update_quantity) | `billing:write` | Changes the seat quantity of a web subscription, now, and syncs the processor's subscription item to it. A retry with the same `Idempotency-Key` (required) and the same request changes nothing twice. |
| [`money.entitlement_grants.get`](/docs/api/entitlement_grants/get) | `billing:read` | Gets an entitlement grant. |
| [`money.entitlement_grants.list`](/docs/api/entitlement_grants/list) | `billing:read` | Lists entitlement grants. |
| [`money.entitlement_grants.check`](/docs/api/entitlement_grants/check) | `billing:read` | Answers whether a subject holds a feature now, and how much of it. |
| [`money.merchant_accounts.get`](/docs/api/merchant_accounts/get) | `billing:read` | Gets a merchant account. |
| [`money.merchant_accounts.list`](/docs/api/merchant_accounts/list) | `billing:read` | Lists merchant accounts. |
| [`money.merchant_accounts.connect`](/docs/api/merchant_accounts/connect) | `billing:write` | Starts connecting a Stripe account: returns the processor's authorisation URL for an org owner to open, which the processor's redirect completes. With a restricted key in the request the account connects at once instead, and the connected merchant account comes back in the response. |
| [`money.merchant_accounts.refresh`](/docs/api/merchant_accounts/refresh) | `billing:write` | Reads the connected account back from the processor. |
| [`money.merchant_accounts.disconnect`](/docs/api/merchant_accounts/disconnect) | `billing:write` | Disconnects the account: Sylphx loses access; checkout is refused. |
| [`money.checkout_sessions.create`](/docs/api/checkout_sessions/create) | `billing:write` | Creates a hosted checkout for a subject. |
| [`money.checkout_sessions.get`](/docs/api/checkout_sessions/get) | `billing:read` | Gets a checkout session. |
| [`money.portal_sessions.create`](/docs/api/portal_sessions/create) | `billing:write` | Creates a customer portal session for a subject. |
| [`money.portal_sessions.get`](/docs/api/portal_sessions/get) | `billing:read` | Gets a portal session. |
| [`network.domains.get`](/docs/api/domains/get) | `network:read` | Gets a domain. |
| [`network.domains.list`](/docs/api/domains/list) | `network:read` | Lists domains in a project. |
| [`network.domains.create`](/docs/api/domains/create) | `network:write` | Creates a domain. The Operation is done when the controller settles it. |
| [`network.domains.update`](/docs/api/domains/update) | `network:write` | Updates a domain. |
| [`network.domains.delete`](/docs/api/domains/delete) | `network:write` | Deletes a domain. |
| [`network.domains.verify`](/docs/api/domains/verify) | `network:write` | Checks the verification record now instead of at the next sweep. |
| [`network.certificates.get`](/docs/api/certificates/get) | `network:read` | Gets a certificate. |
| [`network.certificates.list`](/docs/api/certificates/list) | `network:read` | Lists certificates in a project. |
| [`network.routes.get`](/docs/api/routes/get) | `network:read` | Gets a route. |
| [`network.routes.list`](/docs/api/routes/list) | `network:read` | Lists routes in a environment. |
| [`network.routes.create`](/docs/api/routes/create) | `network:write` | Creates a route. The Operation is done when the controller settles it. |
| [`network.routes.update`](/docs/api/routes/update) | `network:write` | Updates a route. |
| [`network.routes.delete`](/docs/api/routes/delete) | `network:write` | Deletes a route. |
| [`network.egress_identities.get`](/docs/api/egress_identities/get) | `network:read` | Gets an egress identity. |
| [`network.egress_identities.list`](/docs/api/egress_identities/list) | `network:read` | Lists egress identitys in a project. |
| [`network.egress_identities.create`](/docs/api/egress_identities/create) | `network:write` | Creates an egress identity. The Operation is done when the controller settles it. |
| [`network.egress_identities.update`](/docs/api/egress_identities/update) | `network:write` | Updates an egress identity. |
| [`network.egress_identities.delete`](/docs/api/egress_identities/delete) | `network:write` | Deletes an egress identity. |
| [`network.private_links.get`](/docs/api/private_links/get) | `network:read` | Gets a private link. |
| [`network.private_links.list`](/docs/api/private_links/list) | `network:read` | Lists private links in a environment. |
| [`network.private_links.create`](/docs/api/private_links/create) | `network:write` | Creates a private link. The Operation is done when the controller settles it. |
| [`network.private_links.update`](/docs/api/private_links/update) | `network:write` | Updates a private link. |
| [`network.private_links.delete`](/docs/api/private_links/delete) | `network:write` | Deletes a private link. |
| [`notify.mail_domains.get`](/docs/api/mail_domains/get) | `notify:read` | Gets an email domain. |
| [`notify.mail_domains.list`](/docs/api/mail_domains/list) | `notify:read` | Lists email domains. |
| [`notify.mail_domains.create`](/docs/api/mail_domains/create) | `notify:write` | Creates an email domain. |
| [`notify.mail_domains.update`](/docs/api/mail_domains/update) | `notify:write` | Updates an email domain. |
| [`notify.mail_domains.delete`](/docs/api/mail_domains/delete) | `notify:write` | Deletes an email domain. |
| [`notify.mail_domains.verify`](/docs/api/mail_domains/verify) | `notify:write` | Checks the domain's DNS records now instead of on the next sweep. |
| [`notify.mail_routes.get`](/docs/api/mail_routes/get) | `notify:read` | Gets a route. |
| [`notify.mail_routes.list`](/docs/api/mail_routes/list) | `notify:read` | Lists an email domain's routes. |
| [`notify.mail_routes.create`](/docs/api/mail_routes/create) | `notify:write` | Creates a route. |
| [`notify.mail_routes.update`](/docs/api/mail_routes/update) | `notify:write` | Updates a route. |
| [`notify.mail_routes.delete`](/docs/api/mail_routes/delete) | `notify:write` | Deletes a route. |
| [`notify.senders.get`](/docs/api/senders/get) | `notify:read` | Gets a sender. |
| [`notify.senders.list`](/docs/api/senders/list) | `notify:read` | Lists senders. |
| [`notify.senders.create`](/docs/api/senders/create) | `notify:write` | Creates a sender. |
| [`notify.senders.update`](/docs/api/senders/update) | `notify:write` | Updates a sender. |
| [`notify.senders.delete`](/docs/api/senders/delete) | `notify:write` | Deletes a sender. |
| [`notify.senders.verify`](/docs/api/senders/verify) | `notify:write` | Re-checks the sender's registration or credentials now. |
| [`notify.recipients.get`](/docs/api/recipients/get) | `notify:read` | Gets a recipient. |
| [`notify.recipients.list`](/docs/api/recipients/list) | `notify:read` | Lists recipients. |
| [`notify.recipients.create`](/docs/api/recipients/create) | `notify:write` | Creates a recipient. |
| [`notify.recipients.update`](/docs/api/recipients/update) | `notify:write` | Updates a recipient. |
| [`notify.recipients.delete`](/docs/api/recipients/delete) | `notify:write` | Deletes a recipient. |
| [`notify.preferences.get`](/docs/api/preferences/get) | `notify:read` | Gets a preference. |
| [`notify.preferences.list`](/docs/api/preferences/list) | `notify:read` | Lists preferences. |
| [`notify.preferences.update`](/docs/api/preferences/update) | `notify:write` | Updates a preference. |
| [`notify.preferences.delete`](/docs/api/preferences/delete) | `notify:write` | Deletes a preference. |
| [`notify.suppressions.get`](/docs/api/suppressions/get) | `notify:read` | Gets a suppression. |
| [`notify.suppressions.list`](/docs/api/suppressions/list) | `notify:read` | Lists suppressions. |
| [`notify.suppressions.create`](/docs/api/suppressions/create) | `notify:write` | Creates a suppression. |
| [`notify.suppressions.delete`](/docs/api/suppressions/delete) | `notify:write` | Deletes a suppression. |
| [`notify.templates.get`](/docs/api/templates/get) | `notify:read` | Gets a template. |
| [`notify.templates.list`](/docs/api/templates/list) | `notify:read` | Lists templates. |
| [`notify.templates.create`](/docs/api/templates/create) | `notify:write` | Creates a template. |
| [`notify.templates.update`](/docs/api/templates/update) | `notify:write` | Updates a template. |
| [`notify.templates.delete`](/docs/api/templates/delete) | `notify:write` | Deletes a template. |
| [`notify.messages.get`](/docs/api/messages/get) | `notify:read` | Gets a message. |
| [`notify.messages.list`](/docs/api/messages/list) | `notify:read` | Lists messages. |
| [`notify.messages.create`](/docs/api/messages/create) | `notify:send` | Sends a Message. |
| [`notify.messages.cancel`](/docs/api/messages/cancel) | `notify:send` | Cancels a Message whose deliveries have not been handed off. |
| [`notify.mailboxes.get`](/docs/api/mailboxes/get) | `notify:read` | Gets a mailbox. |
| [`notify.mailboxes.list`](/docs/api/mailboxes/list) | `notify:read` | Lists mailboxes. |
| [`notify.mailboxes.create`](/docs/api/mailboxes/create) | `notify:write` | Creates a mailbox. |
| [`notify.mailboxes.update`](/docs/api/mailboxes/update) | `notify:write` | Updates a mailbox. |
| [`notify.mailboxes.delete`](/docs/api/mailboxes/delete) | `notify:write` | Deletes a mailbox and its inbound email. |
| [`notify.mailboxes.erase_address`](/docs/api/mailboxes/erase_address) | `notify:write` | Removes an address's personal data from every inbound email of the mailbox that it sent or that names it, keeping the dedupe keys so a poll never brings the mail back. |
| [`notify.inbound_emails.get`](/docs/api/inbound_emails/get) | `notify:read` | Gets an inbound email. |
| [`notify.inbound_emails.list`](/docs/api/inbound_emails/list) | `notify:read` | Lists a mailbox's inbound email in feed order, oldest first. |
| [`notify.inbox_items.get`](/docs/api/inbox_items/get) | `notify:read` | Gets an inbox item. |
| [`notify.inbox_items.list`](/docs/api/inbox_items/list) | `notify:read` | Lists inbox items. |
| [`notify.inbox_items.mark_read`](/docs/api/inbox_items/mark_read) | `notify:write` | Marks an inbox item read. |
| [`notify.inbox_items.mark_unread`](/docs/api/inbox_items/mark_unread) | `notify:write` | Marks an inbox item unread. |
| [`notify.inbox_items.archive`](/docs/api/inbox_items/archive) | `notify:write` | Archives an inbox item. |
| [`notify.broadcasts.get`](/docs/api/broadcasts/get) | `notify:read` | Gets a broadcast. |
| [`notify.broadcasts.list`](/docs/api/broadcasts/list) | `notify:read` | Lists broadcasts. |
| [`notify.broadcasts.create`](/docs/api/broadcasts/create) | `notify:write` | Creates a broadcast. |
| [`notify.broadcasts.update`](/docs/api/broadcasts/update) | `notify:write` | Updates a broadcast. |
| [`notify.broadcasts.delete`](/docs/api/broadcasts/delete) | `notify:write` | Deletes a broadcast. |
| [`notify.broadcasts.send`](/docs/api/broadcasts/send) | `notify:send` | Sends a Broadcast now. |
| [`notify.broadcasts.cancel`](/docs/api/broadcasts/cancel) | `notify:send` | Cancels a Broadcast; messages already admitted still deliver. |
| [`observability.log_entries.get`](/docs/api/log_entries/get) | `observability:read` | Gets a log entry. |
| [`observability.log_entries.write`](/docs/api/log_entries/write) | `observability:ingest` | Ingests a batch of log entries atomically. The same `Idempotency-Key` and digest replays the same batch; a different digest under the key conflicts. |
| [`observability.log_entries.query`](/docs/api/log_entries/query) | `observability:read` | Queries the environment's log entries over a bounded interval; follow a trace with `trace_id = "..."`. |
| [`observability.traces.get`](/docs/api/traces/get) | `observability:read` | Gets a trace. |
| [`observability.traces.write_spans`](/docs/api/traces/write_spans) | `observability:ingest` | Ingests a batch of spans atomically; a span's parent and time invariants are validated. Replay rules are those of WriteLogEntries. |
| [`observability.traces.query`](/docs/api/traces/query) | `observability:read` | Queries the environment's traces over a bounded interval, returning summaries without spans. |
| [`observability.error_groups.get`](/docs/api/error_groups/get) | `observability:read` | Gets an error group. |
| [`observability.error_groups.list`](/docs/api/error_groups/list) | `observability:read` | Lists error groups; filter by `state`, `service_name`, and `last_seen_time`. |
| [`observability.error_groups.capture`](/docs/api/error_groups/capture) | `observability:ingest` | Captures one error occurrence. It is grouped by `fingerprint` when the caller sets one, else by exception type and the symbolicated in-app stack; release is never part of the group. A new occurrence reopens a resolved group. Secrets and personal data are scrubbed by the environment's Scrubbing Policy before storage. A fingerprint-equal replay bills no second new-error unit. Under quota pressure the response says what to sample. Browsers call it with a publishable key that holds `observability:ingest` (CORS allowed, rate-limited per environment). |
| [`observability.error_groups.acknowledge`](/docs/api/error_groups/acknowledge) | `observability:write` | Acknowledges an error group. |
| [`observability.error_groups.resolve`](/docs/api/error_groups/resolve) | `observability:write` | Resolves an error group; a new occurrence reopens it. |
| [`observability.error_groups.reopen`](/docs/api/error_groups/reopen) | `observability:write` | Reopens a resolved or acknowledged error group. |
| [`observability.error_events.get`](/docs/api/error_events/get) | `observability:read` | Gets an error event. |
| [`observability.error_events.list`](/docs/api/error_events/list) | `observability:read` | Lists error events. |
| [`observability.source_maps.create`](/docs/api/source_maps/create) | `observability:write` | Uploads a source map for one release and minified file. Uploading the same release and file again replaces it. |
| [`observability.source_maps.get`](/docs/api/source_maps/get) | `observability:read` | Gets a source map (without its content). |
| [`observability.source_maps.list`](/docs/api/source_maps/list) | `observability:read` | Lists source maps, newest first; filter by `release`. |
| [`observability.scrubbing_policies.get`](/docs/api/scrubbing_policies/get) | `observability:read` | Gets the environment's scrubbing policy (`scrubbing_policies/default`). |
| [`observability.scrubbing_policies.update`](/docs/api/scrubbing_policies/update) | `observability:write` | Updates the environment's scrubbing policy. |
| [`release.releases.get`](/docs/api/releases/get) | `release:read` | Gets a release. |
| [`release.releases.list`](/docs/api/releases/list) | `release:read` | Lists releases in an environment, newest first by default. |
| [`release.releases.create`](/docs/api/releases/create) | `release:write` | Creates a release: admits it and rolls it out in waves. The Operation is done when the release is live or halted. |
| [`release.rollouts.get`](/docs/api/rollouts/get) | `release:read` | Gets a rollout. |
| [`release.rollouts.list`](/docs/api/rollouts/list) | `release:read` | Lists rollouts in an environment. |
| [`runners.scale_sets.get`](/docs/api/scale_sets/get) | `runners:read` | Gets a scale set. |
| [`runners.scale_sets.list`](/docs/api/scale_sets/list) | `runners:read` | Lists scale sets in a org. |
| [`runners.scale_sets.create`](/docs/api/scale_sets/create) | `runners:write` | Creates a scale set. The Operation is done when the controller settles it. |
| [`runners.scale_sets.update`](/docs/api/scale_sets/update) | `runners:write` | Updates a scale set. |
| [`runners.scale_sets.delete`](/docs/api/scale_sets/delete) | `runners:write` | Deletes a scale set. |
| [`runners.runners.get`](/docs/api/runners/get) | `runners:read` | Gets a runner. |
| [`runners.runners.list`](/docs/api/runners/list) | `runners:read` | Lists runners in a scale set. |
| [`sandboxes.sandbox_shapes.get`](/docs/api/sandbox_shapes/get) | `sandboxes:read` | Gets a shape. |
| [`sandboxes.sandbox_shapes.list`](/docs/api/sandbox_shapes/list) | `sandboxes:read` | Lists shapes. |
| [`sandboxes.pools.get`](/docs/api/pools/get) | `sandboxes:read` | Gets a pool. |
| [`sandboxes.pools.list`](/docs/api/pools/list) | `sandboxes:read` | Lists pools in a environment. |
| [`sandboxes.pools.create`](/docs/api/pools/create) | `sandboxes:write` | Creates a pool. The Operation is done when the controller settles it. |
| [`sandboxes.pools.update`](/docs/api/pools/update) | `sandboxes:write` | Updates a pool. |
| [`sandboxes.pools.delete`](/docs/api/pools/delete) | `sandboxes:write` | Deletes a pool. |
| [`sandboxes.leases.get`](/docs/api/leases/get) | `sandboxes:read` | Gets a lease. |
| [`sandboxes.leases.list`](/docs/api/leases/list) | `sandboxes:read` | Lists leases in a environment. Filter on `meta.labels` (for example `labels.agent = "a_123"`), `status.state`, and `spec.kind`. |
| [`sandboxes.leases.create`](/docs/api/leases/create) | `sandboxes:write` | Creates a lease: granted now and returned READY (or GRANTED when `wait_ready` is false), or refused with a typed error. There is no queue. |
| [`sandboxes.leases.renew`](/docs/api/leases/renew) | `sandboxes:write` | Extends `expire_time`, never past the shape's longest lease. Does not change the generation. |
| [`sandboxes.leases.release`](/docs/api/leases/release) | `sandboxes:write` | Ends a lease with END_REASON_RELEASED; the machine is destroyed and never leased again, and attached volumes are detached. |
| [`sandboxes.leases.pause`](/docs/api/leases/pause) | `sandboxes:write` | Pauses a lease: its disk is kept and its machine destroyed; the generation increases. Process memory is not kept. |
| [`sandboxes.leases.resume`](/docs/api/leases/resume) | `sandboxes:write` | Resumes a paused lease on a machine granted now, or refuses it; the generation increases. |
| [`sandboxes.leases.set_network`](/docs/api/leases/set_network) | `sandboxes:write` | Replaces a running lease's outbound policy. The generation does not change; the new policy applies before the call returns. |
| [`sandboxes.leases.mint_token`](/docs/api/leases/mint_token) | `sandboxes:exec` | Mints a lease token for the data plane, bound to the current generation. Hand it to a process that must not hold the Access key. |
| [`sandboxes.leases.exec`](/docs/api/leases/exec) | `sandboxes:exec` | Runs one command in the lease to completion and returns its output, capped at 1 MiB per stream. Long-running or interactive processes use the guest protocol at `status.endpoints.guest_uri`. |
| [`sandboxes.leases.read_file`](/docs/api/leases/read_file) | `sandboxes:exec` | Reads one file from the lease, at most 16 MiB; larger files use the guest's `/files`. |
| [`sandboxes.leases.write_file`](/docs/api/leases/write_file) | `sandboxes:exec` | Writes one file in the lease, at most 16 MiB, creating parent directories. |
| [`sandboxes.leases.list_files`](/docs/api/leases/list_files) | `sandboxes:exec` | Lists one directory in the lease. |
| [`sandboxes.leases.remove_file`](/docs/api/leases/remove_file) | `sandboxes:exec` | Removes one file or directory tree in the lease. |
| [`sandboxes.leases.open_port`](/docs/api/leases/open_port) | `sandboxes:exec` | Exposes a guest port. |
| [`sandboxes.leases.close_port`](/docs/api/leases/close_port) | `sandboxes:exec` | Stops exposing a guest port. |
| [`sandboxes.leases.act`](/docs/api/leases/act) | `sandboxes:exec` | Performs computer actions on a DESKTOP, BROWSER, or ANDROID lease, in order, and returns each action's result and, when `screenshot` is set, the screenshot taken after the last action. The actions are the Anthropic computer tool's and OpenAI computer use's, one-to-one. Refused CONTROL_HELD_BY_HUMAN while a human holds control. |
| [`sandboxes.leases.open_stream`](/docs/api/leases/open_stream) | `sandboxes:exec` | Opens a read-only live view of a lease's display: a short-lived viewer token bound to the lease and its generation, an embeddable URL, and the WebRTC signaling endpoint with ICE servers. Input needs control (AcquireLeaseControl). |
| [`sandboxes.leases.acquire_control`](/docs/api/leases/acquire_control) | `sandboxes:exec` | Takes exclusive input control of a lease's display. A HUMAN acquire preempts an AGENT holder and returns a controller stream; an AGENT acquire is refused CONTROL_HELD_BY_HUMAN while a human holds control. Control lapses at `ttl`, which the platform caps at 30 minutes. |
| [`sandboxes.leases.release_control`](/docs/api/leases/release_control) | `sandboxes:exec` | Releases control held under `epoch`; its controller tokens stop working. |
| [`sandboxes.leases.get_control`](/docs/api/leases/get_control) | `sandboxes:read` | Gets who holds control of a lease's display. |
| [`sandboxes.leases.install_app`](/docs/api/leases/install_app) | `sandboxes:exec` | Installs an Android app (APK) on an ANDROID lease. |
| [`sandboxes.lease_events.get`](/docs/api/lease_events/get) | `sandboxes:read` | Gets one lease event. |
| [`sandboxes.lease_events.list`](/docs/api/lease_events/list) | `sandboxes:read` | Lists a lease's events in order. With `wait`, blocks up to that long for an event after `page_token` (long poll). |
| [`sandboxes.volumes.get`](/docs/api/volumes/get) | `sandboxes:read` | Gets a volume. |
| [`sandboxes.volumes.list`](/docs/api/volumes/list) | `sandboxes:read` | Lists volumes in a environment. |
| [`sandboxes.volumes.create`](/docs/api/volumes/create) | `sandboxes:write` | Creates a volume. |
| [`sandboxes.volumes.update`](/docs/api/volumes/update) | `sandboxes:write` | Updates a volume: grows `spec.size_gib` and edits metadata. |
| [`sandboxes.volumes.delete`](/docs/api/volumes/delete) | `sandboxes:write` | Deletes a volume and destroys its data. Refused RESOURCE_IN_USE while it is attached. |
| [`sandboxes.snapshots.get`](/docs/api/snapshots/get) | `sandboxes:read` | Gets a snapshot. |
| [`sandboxes.snapshots.list`](/docs/api/snapshots/list) | `sandboxes:read` | Lists snapshots in a environment. |
| [`sandboxes.snapshots.create`](/docs/api/snapshots/create) | `sandboxes:write` | Captures a running lease's disk as a snapshot. |
| [`sandboxes.snapshots.delete`](/docs/api/snapshots/delete) | `sandboxes:write` | Deletes a snapshot. |
| [`secrets.secrets.get`](/docs/api/secrets/get) | `secrets:read` | Gets a secret. |
| [`secrets.secrets.list`](/docs/api/secrets/list) | `secrets:read` | Lists secrets in an environment. |
| [`secrets.secrets.create`](/docs/api/secrets/create) | `secrets:write` | Creates a secret, without a value; add one with CreateSecretVersion. |
| [`secrets.secrets.update`](/docs/api/secrets/update) | `secrets:write` | Updates a secret. |
| [`secrets.secrets.delete`](/docs/api/secrets/delete) | `secrets:write` | Deletes a secret and destroys every version. |
| [`secrets.secret_versions.get`](/docs/api/secret_versions/get) | `secrets:read` | Gets a secret version. |
| [`secrets.secret_versions.list`](/docs/api/secret_versions/list) | `secrets:read` | Lists a secret's versions. |
| [`secrets.secret_versions.create`](/docs/api/secret_versions/create) | `secrets:write` | Adds a value to a secret as its newest version. The value is never returned. |
| [`secrets.secret_versions.disable`](/docs/api/secret_versions/disable) | `secrets:write` | Disables a secret version: bindings stop delivering it. |
| [`secrets.secret_versions.enable`](/docs/api/secret_versions/enable) | `secrets:write` | Enables a disabled secret version. |
| [`secrets.secret_versions.destroy`](/docs/api/secret_versions/destroy) | `secrets:write` | Destroys a secret version's value irrecoverably. |
| [`secrets.secret_versions.access`](/docs/api/secret_versions/access) | `secrets:access` | Reads a secret version's value back. Break-glass: a separate permission, audited on every call, and never exposed to MCP. |
| [`secrets.secret_bindings.get`](/docs/api/secret_bindings/get) | `secrets:read` | Gets a secret binding. |
| [`secrets.secret_bindings.list`](/docs/api/secret_bindings/list) | `secrets:read` | Lists secret bindings in an environment. |
| [`secrets.secret_bindings.create`](/docs/api/secret_bindings/create) | `secrets:write` | Creates a secret binding. |
| [`secrets.secret_bindings.update`](/docs/api/secret_bindings/update) | `secrets:write` | Updates a secret binding. |
| [`secrets.secret_bindings.delete`](/docs/api/secret_bindings/delete) | `secrets:write` | Deletes a secret binding. |
| [`workflows.workflows.get`](/docs/api/workflows/get) | `workflows:read` | Gets a workflow. |
| [`workflows.workflows.list`](/docs/api/workflows/list) | `workflows:read` | Lists workflows. |
| [`workflows.workflows.create`](/docs/api/workflows/create) | `workflows:write` | Creates a workflow. |
| [`workflows.workflows.update`](/docs/api/workflows/update) | `workflows:write` | Updates a workflow. |
| [`workflows.workflows.delete`](/docs/api/workflows/delete) | `workflows:write` | Deletes a workflow. |
| [`workflows.schedules.get`](/docs/api/schedules/get) | `workflows:read` | Gets a schedule. |
| [`workflows.schedules.list`](/docs/api/schedules/list) | `workflows:read` | Lists schedules. |
| [`workflows.schedules.create`](/docs/api/schedules/create) | `workflows:write` | Creates a schedule. |
| [`workflows.schedules.update`](/docs/api/schedules/update) | `workflows:write` | Updates a schedule. |
| [`workflows.schedules.delete`](/docs/api/schedules/delete) | `workflows:write` | Deletes a schedule. |
| [`workflows.schedules.pause`](/docs/api/schedules/pause) | `workflows:write` | Pauses a Schedule: no fire starts a Run until it is resumed. |
| [`workflows.schedules.resume`](/docs/api/schedules/resume) | `workflows:write` | Resumes a paused Schedule; missed fires follow `catchup_window`. |
| [`workflows.runs.get`](/docs/api/runs/get) | `workflows:read` | Gets a run. |
| [`workflows.runs.list`](/docs/api/runs/list) | `workflows:read` | Lists runs. |
| [`workflows.runs.create`](/docs/api/runs/create) | `workflows:run` | Starts a Run of a Workflow. |
| [`workflows.runs.start_batch`](/docs/api/runs/start_batch) | `workflows:run` | Starts a batch: a parent Run that fans out one child Run per item, each with a stable index and count. |
| [`workflows.runs.signal`](/docs/api/runs/signal) | `workflows:run` | Sends a named signal to a running Run; a `wait` op for that name resumes with its payload. A signal to a closed Run fails with INVALID_STATE. |
| [`workflows.runs.cancel`](/docs/api/runs/cancel) | `workflows:run` | Requests cancellation. Timers and waits stop; a running invocation is not interrupted: the handler receives one final invocation with `cancel: true`, and the Run ends `cancelled` when it answers. |
| [`workflows.runs.wait`](/docs/api/runs/wait) | `workflows:read` | Waits up to `timeout` (at most 60s) for the Run to close, then returns it, closed or not. |
| [`workflows.runs.read_history`](/docs/api/runs/read_history) | `workflows:read` | Reads a page of the Run's immutable history, projected to Sylphx events. |
| [`workflows.jobs.get`](/docs/api/jobs/get) | `workflows:read` | Gets a job. |
| [`workflows.jobs.list`](/docs/api/jobs/list) | `workflows:read` | Lists jobs. |
| [`workflows.jobs.create`](/docs/api/jobs/create) | `workflows:write` | Creates a job. |
| [`workflows.jobs.update`](/docs/api/jobs/update) | `workflows:write` | Updates a job. Runs already started keep the generation they pinned. |
| [`workflows.jobs.delete`](/docs/api/jobs/delete) | `workflows:write` | Deletes a job. |
| [`workflows.job_runs.create`](/docs/api/job_runs/create) | `workflows:run` | Starts a run of a Job now. The same `Idempotency-Key` returns the same run for 24h; a Schedule fire uses `{job}:{intended time}`. With concurrency `forbid`, a start while a run is active fails with INVALID_STATE. |
| [`workflows.job_runs.get`](/docs/api/job_runs/get) | `workflows:read` | Gets a job run. |
| [`workflows.job_runs.list`](/docs/api/job_runs/list) | `workflows:read` | Lists a job's runs, newest first. |
| [`workflows.job_runs.cancel`](/docs/api/job_runs/cancel) | `workflows:run` | Cancels a job run: SIGTERM, then SIGKILL after 30s. A closed run fails with INVALID_STATE. |
| [`workflows.job_runs.read_logs`](/docs/api/job_runs/read_logs) | `workflows:read` | Reads a page of a job run's log lines, oldest first. With `wait`, an empty page on a running run waits up to that long for new lines, so a client follows the log by passing each `next_page_token` back. |
| [`workflows.distributed_jobs.get`](/docs/api/distributed_jobs/get) | `workflows:read` | Gets a distributed job. |
| [`workflows.distributed_jobs.list`](/docs/api/distributed_jobs/list) | `workflows:read` | Lists distributed jobs. |
| [`workflows.distributed_jobs.create`](/docs/api/distributed_jobs/create) | `workflows:write` | Creates a distributed job. |
| [`workflows.distributed_jobs.update`](/docs/api/distributed_jobs/update) | `workflows:write` | Updates a distributed job. Runs already started keep the generation they pinned. |
| [`workflows.distributed_jobs.delete`](/docs/api/distributed_jobs/delete) | `workflows:write` | Deletes a distributed job. |
| [`workflows.distributed_runs.create`](/docs/api/distributed_runs/create) | `workflows:run` | Starts a run of a distributed job. The same `Idempotency-Key` returns the same run for 24h. |
| [`workflows.distributed_runs.get`](/docs/api/distributed_runs/get) | `workflows:read` | Gets a distributed run: its state, shard and worker counts, and usage. |
| [`workflows.distributed_runs.list`](/docs/api/distributed_runs/list) | `workflows:read` | Lists a distributed job's runs, newest first. |
| [`workflows.distributed_runs.cancel`](/docs/api/distributed_runs/cancel) | `workflows:run` | Cancels a distributed run: workers get SIGTERM and 30s, then leases are released; finished shards are kept. A closed run fails with INVALID_STATE. |
| [`workflows.distributed_runs.add_shards`](/docs/api/distributed_runs/add_shards) | `workflows:run` | Appends shards to a run started with an open manifest; `close` ends the manifest, and the run ends once those shards are done. |
| [`workflows.distributed_runs.read_shards`](/docs/api/distributed_runs/read_shards) | `workflows:read` | Reads a page of the run's shards, in queue order. |
| [`workflows.distributed_runs.read_workers`](/docs/api/distributed_runs/read_workers) | `workflows:read` | Reads a page of the run's workers. |
