Skip to content
Console
Menu

Getting Started

Authentication

KV Store

Profiles

A Profile is sign-in state a sandbox session mounts: a browser's cookies and storage per site, or a computer's application sign-ins.

A Profile is sign-in state a sandbox session mounts: a browser's cookies and storage per site, or a computer's application sign-ins. It is secret-like: every version is envelope-encrypted under a data key of its own profile, no read method returns a value, and mounting is a separate, audited permission (secrets:mount) granted per principal on the profile.

Service Sylphx Secrets · Resource type secrets.sylphx.com/Profile · Name pattern orgs/{org}/projects/{project}/envs/{env}/profiles/{profile} · Shape spec_status

#Fields

FieldTypeWhat it is
namestringorgs/{org}/projects/{project}/envs/{env}/profiles/{profile}.
uidstringpfl_<cell><ulid>. Output only.
metaResourceMetaResource metadata.
specProfileSpecDesired state. Required.
statusProfileStatusObserved state. Output only.

#Methods

Every method of the collection, in the registry's order, with the scope it needs. The full request, response and examples are one link away.

MethodCallWhat it does
GETgetGets a profile: its kind, grants, sites and latest version; never a value.
GETlistLists the profiles of an environment.
POSTcreateCreates an empty profile; its first version is written by a write-back mount (:open with WRITE_BACK, then :commit).
PATCHupdateUpdates a profile's grants or declared paths. Granting a mount is this call: nothing else adds a grant.
DELETEdeleteDeletes a profile; with force, a profile that has versions too, which destroys every version.
POSTopenMounts a profile for one session: returns the state of one version and, for WRITE_BACK, an attachment that :commit writes through until it expires. Every call is audited with the caller's context; the caller's principal needs a grant of at least the requested mode.
POSTcommitWrites a mounted profile back as a new version, by compare-and-set on the version the attachment was opened at (or last committed). When another write landed first, nothing is lost: the result is still a new version, merged site by site with the newer write winning, and marked as a conflict.

#get

Gets a profile: its kind, grants, sites and latest version; never a value.

GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile · scope secrets:read · effect read · Request, response and examples

#list

Lists the profiles of an environment.

GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles · scope secrets:read · effect read · paginated · Request, response and examples

#create

Creates an empty profile; its first version is written by a write-back mount (:open with WRITE_BACK, then :commit).

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles · scope secrets:write · effect write · Request, response and examples

#update

Updates a profile's grants or declared paths. Granting a mount is this call: nothing else adds a grant.

PATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile · scope secrets:write · effect write · Request, response and examples

#delete

Deletes a profile; with force, a profile that has versions too, which destroys every version.

DELETE https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile · scope secrets:write · effect destructive · Request, response and examples

#open

Mounts a profile for one session: returns the state of one version and, for WRITE_BACK, an attachment that :commit writes through until it expires. Every call is audited with the caller's context; the caller's principal needs a grant of at least the requested mode.

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile:open · scope secrets:mount · effect read · Request, response and examples

#commit

Writes a mounted profile back as a new version, by compare-and-set on the version the attachment was opened at (or last committed). When another write landed first, nothing is lost: the result is still a new version, merged site by site with the newer write winning, and marked as a conflict.

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile:commit · scope secrets:mount · effect write · Request, response and examples