Skip to content
Console
Menu

Generated Assets

Workflows

Getting Started

Authentication

KV Store

Move an identity

Moves a federated or device identity from one end user to another, to fix a wrongly linked player.

Moves a federated or device identity from one end user to another, to fix a wrongly linked player. One transaction: the identity changes owner, the sessions of both end users are revoked, and nothing else about either moves (profile, memberships, data). Refused when it would leave the source with no sign-in, unless the source is suspended, and when the target already has an identity of the same provider. The reason is audited with the operator, both end users and the identity's fingerprint. An operator action: an end user's own session cannot call it.

  • Path POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user/identities/identity:move
  • Scope auth:write
  • Effect destructive — a successful call removes data; the CLI asks before it runs.
  • Collection identities

#Request

FieldTypeWhat it is
namestringThe name of the identity to move. Required.
target_end_userstringThe end user that receives the identity. Required.
reasonstringWhy the identity moves (1 to 512 characters); recorded in the audit trail. Required.

#Response

FieldTypeWhat it is
namestringorgs/{org}/projects/{project}/envs/{env}/end_users/{end_user}/identities/{identity}.
uidstringThe identity's id; never reused. Output only.
metaResourceMetaResource metadata.
typeIdentityTypeWhat kind of sign-in this is. Output only. One of password, email, oidc, device, passkey.
providerstringThe provider of a federated identity (google, apple,...); empty otherwise. Output only.
fingerprintstringA one-way digest of the provider and the provider's subject (or of the device credential's verifier). It identifies the identity in an audit trail and reveals neither. Output only.
link_timetimestampWhen the identity was linked. Output only.
last_use_timetimestampThe last sign-in with this identity, when known. Output only.

#ResourceMeta

FieldTypeWhat it is
generationint64Increases by one on every change to spec. Output only.
etagstringStrong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as If-Match or etag to make Update and Delete conditional; a mismatch fails with ABORTED / 409 ETAG_MISMATCH. Output only.
create_timetimestampWhen the Resource was created. Output only.
update_timetimestampWhen the Resource last changed. Output only.
delete_timetimestampSet while the Resource is being deleted. Output only.
labelsmap<string, string>Caller-writable, indexed labels (AIP-122 label rules).
annotationsmap<string, string>Caller-writable, unindexed annotations.
display_namestringCaller-writable human-readable name.
creatorstringThe principal that created the Resource. Output only.

#Errors

Every error arrives in the body Errors describes.

#Examples

curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user/identities/identity:move" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"reason":"…","target_end_user":"…"}'