---
# @generated by sylphx-gen 0.1.0 from contracts@190f1b33b937c1aef79697684018db853389b521c75e19ff69ac6af609e96f45. Do not edit.
title: "Move an identity"
description: "`auth.identities.move` (POST /v1/{name}:move): Moves a federated or device identity from one end user to another, to fix a wrongly linked player."
type: reference
product: auth
summary: "Moves a federated or device identity from one end user to another, to fix a wrongly linked player."
updated: 2026-09-28
nav: false
---

Moves a federated or device identity from one end user to another, to fix a wrongly linked player. One transaction: the identity changes owner, the sessions of both end users are revoked, and nothing else about either moves (profile, memberships, data). Refused when it would leave the source with no sign-in, unless the source is suspended, and when the target already has an identity of the same provider. The reason is audited with the operator, both end users and the identity's fingerprint. An operator action: an end user's own session cannot call it.

- **Path** `POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user/identities/identity:move`
- **Scope** `auth:write`
- **Effect** `destructive` — a successful call removes data; the CLI asks before it runs.
- **Collection** [identities](/docs/api/identities)

## Request

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | The name of the identity to move. Required. |
| `target_end_user` | `string` | The end user that receives the identity. Required. |
| `reason` | `string` | Why the identity moves (1 to 512 characters); recorded in the audit trail. Required. |

## Response

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/end_users/{end_user}/identities/{identity}`. |
| `uid` | `string` | The identity's id; never reused. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `type` | `IdentityType` | What kind of sign-in this is. Output only. One of `password`, `email`, `oidc`, `device`, `passkey`. |
| `provider` | `string` | The provider of a federated identity (`google`, `apple`,...); empty otherwise. Output only. |
| `fingerprint` | `string` | A one-way digest of the provider and the provider's subject (or of the device credential's verifier). It identifies the identity in an audit trail and reveals neither. Output only. |
| `link_time` | `timestamp` | When the identity was linked. Output only. |
| `last_use_time` | `timestamp` | The last sign-in with this identity, when known. Output only. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `generation` | `int64` | Increases by one on every change to `spec`. Output only. |
| `etag` | `string` | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as `If-Match` or `etag` to make Update and Delete conditional; a mismatch fails with ABORTED / 409 `ETAG_MISMATCH`. Output only. |
| `create_time` | `timestamp` | When the Resource was created. Output only. |
| `update_time` | `timestamp` | When the Resource last changed. Output only. |
| `delete_time` | `timestamp` | Set while the Resource is being deleted. Output only. |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |
| `creator` | `string` | The principal that created the Resource. Output only. |

## Errors

- [`UNAUTHENTICATED`](/docs/api/errors/UNAUTHENTICATED) — No valid key or token was presented.
- [`PERMISSION_DENIED`](/docs/api/errors/PERMISSION_DENIED) — The key lacks the method's permission.
- [`RESOURCE_NOT_FOUND`](/docs/api/errors/RESOURCE_NOT_FOUND) — The named Resource does not exist or is not visible.
- [`INVALID_FIELD`](/docs/api/errors/INVALID_FIELD) — A field failed validation.
- [`INVALID_STATE`](/docs/api/errors/INVALID_STATE) — The Resource is in a state that forbids the call.
- [`RESOURCE_ALREADY_EXISTS`](/docs/api/errors/RESOURCE_ALREADY_EXISTS) — A Resource with this name exists.
- [`IDEMPOTENCY_KEY_REUSED`](/docs/api/errors/IDEMPOTENCY_KEY_REUSED) — An Idempotency-Key was reused with another body.
- [`IDEMPOTENCY_IN_PROGRESS`](/docs/api/errors/IDEMPOTENCY_IN_PROGRESS) — The first call with this Idempotency-Key is still running.

Every error arrives in the body [Errors](/docs/platform/errors) describes.

## Examples

**cURL**

```curl
curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user/identities/identity:move" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"reason":"…","target_end_user":"…"}'
```

**TypeScript**

```ts
const response = await sylphx.auth.identities.move({ name: 'orgs/acme/projects/shop/envs/production/end_users/end-user/identities/identity', reason: '…', targetEndUser: '…' })
```

**Rust**

```rust
let mut req = sylphx::auth::MoveIdentityRequest::default();
req.name = "orgs/acme/projects/shop/envs/production/end_users/end-user/identities/identity".to_string();
req.reason = "…".to_string();
req.target_end_user = "…".to_string();
let response = sx.auth().identities().r#move(req).await?;
```

**CLI**

```bash
sylphx auth identities move orgs/acme/projects/shop/envs/production/end_users/end-user/identities/identity --yes
```

**MCP**

```json
{ "method_id": "auth.identities.move", "args": {"name":"orgs/acme/projects/shop/envs/production/end_users/end-user/identities/identity","reason":"…","target_end_user":"…"} }
```
