---
# @generated by sylphx-gen 0.1.0 from contracts@190f1b33b937c1aef79697684018db853389b521c75e19ff69ac6af609e96f45. Do not edit.
title: "Identities"
description: "The `identities` collection of Sylphx Auth: An Identity is one way an end user signs in: a password, a verified email, a federated provider account, a device credential (a guest account's secret), or a passkey."
type: reference
product: auth
summary: "An Identity is one way an end user signs in: a password, a verified email, a federated provider account, a device credential (a guest…"
updated: 2026-09-28
order: 900
---

An Identity is one way an end user signs in: a password, a verified email, a federated provider account, a device credential (a guest account's secret), or a passkey. An end user always keeps at least one. An identity moves from one end user to another only by `:move`, an operator action; the end user never does it. It shows a fingerprint (a one-way digest), never the secret.

**Service** Sylphx Auth · **Resource type** `auth.sylphx.com/Identity` · **Name pattern** `orgs/{org}/projects/{project}/envs/{env}/end_users/{end_user}/identities/{identity}` · **Shape** `record`

## Fields

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/end_users/{end_user}/identities/{identity}`. |
| `uid` | `string` | The identity's id; never reused. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `type` | `IdentityType` | What kind of sign-in this is. Output only. One of `password`, `email`, `oidc`, `device`, `passkey`. |
| `provider` | `string` | The provider of a federated identity (`google`, `apple`,...); empty otherwise. Output only. |
| `fingerprint` | `string` | A one-way digest of the provider and the provider's subject (or of the device credential's verifier). It identifies the identity in an audit trail and reveals neither. Output only. |
| `link_time` | `timestamp` | When the identity was linked. Output only. |
| `last_use_time` | `timestamp` | The last sign-in with this identity, when known. Output only. |

## Methods

Every method of the collection, in the registry's order, with the scope it
needs. The full request, response and examples are one link away.

| Method | Call | What it does |
| --- | --- | --- |
| `GET` | [`get`](/docs/api/identities#get) | Gets an identity of an end user. |
| `GET` | [`list`](/docs/api/identities#list) | Lists the identities an end user signs in with. |
| `POST` | [`move`](/docs/api/identities#move) | Moves a federated or device identity from one end user to another, to fix a wrongly linked player. One transaction: the identity changes owner, the sessions of both end users are revoked, and nothing else about either moves (profile, memberships, data). Refused when it would leave the source with no sign-in, unless the source is suspended, and when the target already has an identity of the same provider. The reason is audited with the operator, both end users and the identity's fingerprint. An operator action: an end user's own session cannot call it. |

## get

Gets an identity of an end user.

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user/identities/identity` · scope `auth:read` · effect `read` · [Request, response and examples](/docs/api/identities/get)

## list

Lists the identities an end user signs in with.

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user/identities` · scope `auth:read` · effect `read` · paginated · [Request, response and examples](/docs/api/identities/list)

## move

Moves a federated or device identity from one end user to another, to fix a wrongly linked player. One transaction: the identity changes owner, the sessions of both end users are revoked, and nothing else about either moves (profile, memberships, data). Refused when it would leave the source with no sign-in, unless the source is suspended, and when the target already has an identity of the same provider. The reason is audited with the operator, both end users and the identity's fingerprint. An operator action: an end user's own session cannot call it.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user/identities/identity:move` · scope `auth:write` · effect `destructive` · [Request, response and examples](/docs/api/identities/move)
