Menu
Platform
AI
App store purchases
Database
Flags
Jobs and cron
Localization
Monitoring
Notifications
Payments
Queues
Sandboxes
Webhooks
Getting Started
Authentication
KV Store
Deploy & Infrastructure
Reference
Create a key
Creates a key; the signer generates its first version.
This method is not served on the public API.
api.sylphx.comdoes not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.
Creates a key; the signer generates its first version.
Not available yet. Sylphx Keys is declared in the registry but no backend serves it: every call answers 501 with the problem code UNIMPLEMENTED.
- Path
POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys - Scope
keys:write - Effect
write— a successful call changes state. - Collection keys
- Query
key_id,validate_only - Operation answers with an
Operation; the result isKey
#Request
| Field | Type | What it is |
|---|---|---|
parent | string | The environment to create in. Required. |
key | Key | The key to create; only spec and caller-writable metadata are read. Required. |
key_id | string | The id of the new key, ^[a-z]([a-z0-9_-]{0,61}[a-z0-9])?$; the server assigns one when empty. |
validate_only | bool | Validate and return the result without writing anything. |
#Key
| Field | Type | What it is |
|---|---|---|
name | string | orgs/{org}/projects/{project}/envs/{env}/keys/{key}. |
meta | ResourceMeta | Resource metadata. |
spec | KeySpec | Desired state. Required. |
#ResourceMeta
| Field | Type | What it is |
|---|---|---|
labels | map<string, string> | Caller-writable, indexed labels (AIP-122 label rules). |
annotations | map<string, string> | Caller-writable, unindexed annotations. |
display_name | string | Caller-writable human-readable name. |
#KeySpec
| Field | Type | What it is |
|---|---|---|
purpose | KeyPurpose | What the key does. Required. One of sign, encrypt, mac. |
algorithm | KeyAlgorithm | The algorithm; it must suit the purpose. Required. One of ed25519, ec_p256_sha256, rsa_pkcs1_2048_sha256, rsa_pss_3072_sha256, aes_256_gcm, hmac_sha256. |
rotation_period | duration | Rotate automatically this often; unset means rotate only on request. |
deletion_protection | bool | While true, Delete fails with DELETION_PROTECTED. Default true. |
#Response
| Field | Type | What it is |
|---|---|---|
name | string | {parent-of-target}/operations/{operation}. |
target | string | The name of the Resource being changed. |
target_generation | int64 | The generation this Operation waits for. |
verb | OperationVerb | What the Operation does. One of create, update, delete, custom. |
custom_verb | string | The custom method verb when verb is CUSTOM, for example revoke. |
done | bool | Whether the Operation has finished. |
create_time | timestamp | When the Operation started. |
end_time | timestamp | When the Operation finished. |
response | any | The settled Resource (or Empty for a delete). One of the result group. |
error | ProblemDetails | The failure, as the one error body. One of the result group. |
progress | OperationProgress | Progress while not done. |
#ProblemDetails
| Field | Type | What it is |
|---|---|---|
type | string | https://sylphx.com/docs/errors/<code in kebab-case>. |
title | string | A short customer-safe summary of the problem class. |
status | int32 | The HTTP status, fixed by grpc_status. |
detail | string | A customer-safe explanation of this occurrence. Never contains SQL, stack traces, internal hostnames, or another tenant's data. |
instance | string | The request id (Sylphx-Request-Id). |
code | string | The stable UPPER_SNAKE code, one of ErrorCode without its prefix. |
grpc_status | string | One of the 16 canonical gRPC status names, for example ABORTED. |
retryable | bool | Whether the same request may be retried. |
effect | ErrorEffect | What the failed call committed. One of none, applied, unknown. |
retry_after_ms | int64 | How long to wait before retrying, when the server knows. |
details | any[] | Typed details such as PreconditionFailure or EntitlementDenial. |
#OperationProgress
| Field | Type | What it is |
|---|---|---|
percent | int32 | Percent complete, when the controller can tell. |
message | string | A customer-safe progress message. |
conditions | Condition[] | The target's conditions when this progress was read. |
#Condition
| Field | Type | What it is |
|---|---|---|
type | string | The condition type, for example Ready. |
status | ConditionStatus | Whether the condition holds. One of true, false, unknown. |
observed_generation | int64 | The generation this observation was made against. |
reason | string | A machine-readable UpperCamelCase reason. |
message | string | A customer-safe human-readable message. |
severity | Severity | How severe a FALSE condition is. One of info, warning, error. |
transition_time | timestamp | When status last changed. |
#Errors
UNAUTHENTICATED— No valid key or token was presented.PERMISSION_DENIED— The key lacks the method's permission.UNKNOWN_FIELD— The request has a field the schema does not know.INVALID_FIELD— A field failed validation.RESOURCE_ALREADY_EXISTS— A Resource with this name exists.IDEMPOTENCY_KEY_REUSED— An Idempotency-Key was reused with another body.IDEMPOTENCY_IN_PROGRESS— The first call with this Idempotency-Key is still running.PLAN_LIMIT_REACHED— The plan's limit is reached.
Every error arrives in the body Errors describes.
#Examples
curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys" \
-H "Authorization: Bearer $SYLPHX_API_KEY" \
-H "Content-Type: application/json" \
-d '{"spec":{"algorithm":"ed25519","purpose":"sign"}}'