---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "Keys"
description: "The `keys` collection of Sylphx Keys: A Key is a non-exportable key on the regional signer: a handle for signing, encryption, or MAC."
type: reference
product: platform
summary: "A Key is a non-exportable key on the regional signer: a handle for signing, encryption, or MAC."
updated: 2026-09-28
order: 900
---

> **This method is not served on the public API.** `api.sylphx.com` does not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.

A Key is a non-exportable key on the regional signer: a handle for signing, encryption, or MAC. Rotation adds a version and keeps the old one usable for verification and decryption until it is destroyed.

**Service** Sylphx Keys · **Resource type** `keys.sylphx.com/Key` · **Name pattern** `orgs/{org}/projects/{project}/envs/{env}/keys/{key}` · **Shape** `spec_status`

**Not available yet.** Sylphx Keys is declared in the registry but no backend serves it: every call answers `501` with the problem code `UNIMPLEMENTED`.

## Fields

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/keys/{key}`. |
| `uid` | `string` | `kms_<cell><ulid>`. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `spec` | `KeySpec` | Desired state. Required. |
| `status` | `KeyStatus` | Observed state. Output only. |

## Methods

Every method of the collection, in the registry's order, with the scope it
needs. The full request, response and examples are one link away.

| Method | Call | What it does |
| --- | --- | --- |
| `GET` | [`get`](/docs/api/keys#get) | Gets a key. |
| `GET` | [`list`](/docs/api/keys#list) | Lists keys in an environment. |
| `POST` | [`create`](/docs/api/keys#create) | Creates a key; the signer generates its first version. |
| `PATCH` | [`update`](/docs/api/keys#update) | Updates a key's rotation period, deletion protection, or metadata. |
| `DELETE` | [`delete`](/docs/api/keys#delete) | Deletes a key and schedules every version's destruction. |
| `POST` | [`rotate`](/docs/api/keys#rotate) | Rotates a key: adds a version and makes it primary. Older versions keep verifying and decrypting until destroyed. |
| `POST` | [`sign`](/docs/api/keys#sign) | Signs data or a digest with a SIGN key. Every use is audited. |
| `POST` | [`verify`](/docs/api/keys#verify) | Verifies a signature made by a SIGN key. |
| `POST` | [`encrypt`](/docs/api/keys#encrypt) | Encrypts data with an ENCRYPT key. |
| `POST` | [`decrypt`](/docs/api/keys#decrypt) | Decrypts a ciphertext made by Encrypt with this key. |
| `POST` | [`mac_sign`](/docs/api/keys#mac-sign) | Computes a MAC of data with a MAC key. |
| `POST` | [`mac_verify`](/docs/api/keys#mac-verify) | Verifies a MAC made by a MAC key, in constant time. |

## get

Gets a key.

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key` · scope `keys:read` · effect `read` · not available yet · [Request, response and examples](/docs/api/keys/get)

## list

Lists keys in an environment.

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys` · scope `keys:read` · effect `read` · not available yet · paginated · [Request, response and examples](/docs/api/keys/list)

## create

Creates a key; the signer generates its first version.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys` · scope `keys:write` · effect `write` · not available yet · long-running · [Request, response and examples](/docs/api/keys/create)

## update

Updates a key's rotation period, deletion protection, or metadata.

`PATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key` · scope `keys:write` · effect `write` · not available yet · long-running · [Request, response and examples](/docs/api/keys/update)

## delete

Deletes a key and schedules every version's destruction.

`DELETE https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key` · scope `keys:write` · effect `destructive` · not available yet · long-running · [Request, response and examples](/docs/api/keys/delete)

## rotate

Rotates a key: adds a version and makes it primary. Older versions keep verifying and decrypting until destroyed.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:rotate` · scope `keys:write` · effect `write` · not available yet · validate_only · long-running · [Request, response and examples](/docs/api/keys/rotate)

## sign

Signs data or a digest with a SIGN key. Every use is audited.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:sign` · scope `keys:sign` · effect `read` · not available yet · [Request, response and examples](/docs/api/keys/sign)

## verify

Verifies a signature made by a SIGN key.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:verify` · scope `keys:verify` · effect `read` · not available yet · [Request, response and examples](/docs/api/keys/verify)

## encrypt

Encrypts data with an ENCRYPT key.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:encrypt` · scope `keys:encrypt` · effect `read` · not available yet · [Request, response and examples](/docs/api/keys/encrypt)

## decrypt

Decrypts a ciphertext made by Encrypt with this key.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:decrypt` · scope `keys:decrypt` · effect `read` · not available yet · [Request, response and examples](/docs/api/keys/decrypt)

## mac_sign

Computes a MAC of data with a MAC key.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:macSign` · scope `keys:sign` · effect `read` · not available yet · [Request, response and examples](/docs/api/keys/mac_sign)

## mac_verify

Verifies a MAC made by a MAC key, in constant time.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:macVerify` · scope `keys:verify` · effect `read` · not available yet · [Request, response and examples](/docs/api/keys/mac_verify)
