Skip to content
Console
Menu

Queues

Workflows

Getting Started

Authentication

KV Store

Keys

A Key is a non-exportable key on the regional signer: a handle for signing, encryption, or MAC.

This method is not served on the public API. api.sylphx.com does not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.

A Key is a non-exportable key on the regional signer: a handle for signing, encryption, or MAC. Rotation adds a version and keeps the old one usable for verification and decryption until it is destroyed.

Service Sylphx Keys · Resource type keys.sylphx.com/Key · Name pattern orgs/{org}/projects/{project}/envs/{env}/keys/{key} · Shape spec_status

Not available yet. Sylphx Keys is declared in the registry but no backend serves it: every call answers 501 with the problem code UNIMPLEMENTED.

#Fields

FieldTypeWhat it is
namestringorgs/{org}/projects/{project}/envs/{env}/keys/{key}.
uidstringkms_<cell><ulid>. Output only.
metaResourceMetaResource metadata.
specKeySpecDesired state. Required.
statusKeyStatusObserved state. Output only.

#Methods

Every method of the collection, in the registry's order, with the scope it needs. The full request, response and examples are one link away.

MethodCallWhat it does
GETgetGets a key.
GETlistLists keys in an environment.
POSTcreateCreates a key; the signer generates its first version.
PATCHupdateUpdates a key's rotation period, deletion protection, or metadata.
DELETEdeleteDeletes a key and schedules every version's destruction.
POSTrotateRotates a key: adds a version and makes it primary. Older versions keep verifying and decrypting until destroyed.
POSTsignSigns data or a digest with a SIGN key. Every use is audited.
POSTverifyVerifies a signature made by a SIGN key.
POSTencryptEncrypts data with an ENCRYPT key.
POSTdecryptDecrypts a ciphertext made by Encrypt with this key.
POSTmac_signComputes a MAC of data with a MAC key.
POSTmac_verifyVerifies a MAC made by a MAC key, in constant time.

#get

Gets a key.

GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key · scope keys:read · effect read · not available yet · Request, response and examples

#list

Lists keys in an environment.

GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys · scope keys:read · effect read · not available yet · paginated · Request, response and examples

#create

Creates a key; the signer generates its first version.

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys · scope keys:write · effect write · not available yet · long-running · Request, response and examples

#update

Updates a key's rotation period, deletion protection, or metadata.

PATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key · scope keys:write · effect write · not available yet · long-running · Request, response and examples

#delete

Deletes a key and schedules every version's destruction.

DELETE https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key · scope keys:write · effect destructive · not available yet · long-running · Request, response and examples

#rotate

Rotates a key: adds a version and makes it primary. Older versions keep verifying and decrypting until destroyed.

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:rotate · scope keys:write · effect write · not available yet · validate_only · long-running · Request, response and examples

#sign

Signs data or a digest with a SIGN key. Every use is audited.

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:sign · scope keys:sign · effect read · not available yet · Request, response and examples

#verify

Verifies a signature made by a SIGN key.

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:verify · scope keys:verify · effect read · not available yet · Request, response and examples

#encrypt

Encrypts data with an ENCRYPT key.

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:encrypt · scope keys:encrypt · effect read · not available yet · Request, response and examples

#decrypt

Decrypts a ciphertext made by Encrypt with this key.

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:decrypt · scope keys:decrypt · effect read · not available yet · Request, response and examples

#mac_sign

Computes a MAC of data with a MAC key.

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:macSign · scope keys:sign · effect read · not available yet · Request, response and examples

#mac_verify

Verifies a MAC made by a MAC key, in constant time.

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:macVerify · scope keys:verify · effect read · not available yet · Request, response and examples