Skip to content
Console
Menu

Generated Assets

Workflows

Getting Started

Authentication

KV Store

Identities

An Identity is one way an end user signs in: a password, a verified email, a federated provider account, a device credential (a guest…

An Identity is one way an end user signs in: a password, a verified email, a federated provider account, a device credential (a guest account's secret), or a passkey. An end user always keeps at least one. An identity moves from one end user to another only by :move, an operator action; the end user never does it. It shows a fingerprint (a one-way digest), never the secret.

Service Sylphx Auth · Resource type auth.sylphx.com/Identity · Name pattern orgs/{org}/projects/{project}/envs/{env}/end_users/{end_user}/identities/{identity} · Shape record

#Fields

FieldTypeWhat it is
namestringorgs/{org}/projects/{project}/envs/{env}/end_users/{end_user}/identities/{identity}.
uidstringThe identity's id; never reused. Output only.
metaResourceMetaResource metadata.
typeIdentityTypeWhat kind of sign-in this is. Output only. One of password, email, oidc, device, passkey.
providerstringThe provider of a federated identity (google, apple,...); empty otherwise. Output only.
fingerprintstringA one-way digest of the provider and the provider's subject (or of the device credential's verifier). It identifies the identity in an audit trail and reveals neither. Output only.
link_timetimestampWhen the identity was linked. Output only.
last_use_timetimestampThe last sign-in with this identity, when known. Output only.

#Methods

Every method of the collection, in the registry's order, with the scope it needs. The full request, response and examples are one link away.

MethodCallWhat it does
GETgetGets an identity of an end user.
GETlistLists the identities an end user signs in with.
POSTmoveMoves a federated or device identity from one end user to another, to fix a wrongly linked player. One transaction: the identity changes owner, the sessions of both end users are revoked, and nothing else about either moves (profile, memberships, data). Refused when it would leave the source with no sign-in, unless the source is suspended, and when the target already has an identity of the same provider. The reason is audited with the operator, both end users and the identity's fingerprint. An operator action: an end user's own session cannot call it.

#get

Gets an identity of an end user.

GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user/identities/identity · scope auth:read · effect read · Request, response and examples

#list

Lists the identities an end user signs in with.

GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user/identities · scope auth:read · effect read · paginated · Request, response and examples

#move

Moves a federated or device identity from one end user to another, to fix a wrongly linked player. One transaction: the identity changes owner, the sessions of both end users are revoked, and nothing else about either moves (profile, memberships, data). Refused when it would leave the source with no sign-in, unless the source is suspended, and when the target already has an identity of the same provider. The reason is audited with the operator, both end users and the identity's fingerprint. An operator action: an end user's own session cannot call it.

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user/identities/identity:move · scope auth:write · effect destructive · Request, response and examples