---
# @generated by sylphx-gen 0.1.0 from contracts@fb95f0c42a0ec5d8e3cb694c0054b529c0b24b184112c65ef60c9044b4ce61f9. Do not edit.
title: "Profiles"
description: "The `profiles` collection of Sylphx Secrets: A Profile is sign-in state a sandbox session mounts: a browser's cookies and storage per site, or a computer's application sign-ins."
type: reference
product: platform
summary: "A Profile is sign-in state a sandbox session mounts: a browser's cookies and storage per site, or a computer's application sign-ins."
updated: 2026-09-28
order: 900
---

A Profile is sign-in state a sandbox session mounts: a browser's cookies and storage per site, or a computer's application sign-ins. It is secret-like: every version is envelope-encrypted under a data key of its own profile, no read method returns a value, and mounting is a separate, audited permission (`secrets:mount`) granted per principal on the profile.

**Service** Sylphx Secrets · **Resource type** `secrets.sylphx.com/Profile` · **Name pattern** `orgs/{org}/projects/{project}/envs/{env}/profiles/{profile}` · **Shape** `spec_status`

## Fields

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/profiles/{profile}`. |
| `uid` | `string` | `pfl_<cell><ulid>`. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `spec` | `ProfileSpec` | Desired state. Required. |
| `status` | `ProfileStatus` | Observed state. Output only. |

## Methods

Every method of the collection, in the registry's order, with the scope it
needs. The full request, response and examples are one link away.

| Method | Call | What it does |
| --- | --- | --- |
| `GET` | [`get`](/docs/api/profiles#get) | Gets a profile: its kind, grants, sites and latest version; never a value. |
| `GET` | [`list`](/docs/api/profiles#list) | Lists the profiles of an environment. |
| `POST` | [`create`](/docs/api/profiles#create) | Creates an empty profile; its first version is written by a write-back mount (`:open` with WRITE_BACK, then `:commit`). |
| `PATCH` | [`update`](/docs/api/profiles#update) | Updates a profile's grants or declared paths. Granting a mount is this call: nothing else adds a grant. |
| `DELETE` | [`delete`](/docs/api/profiles#delete) | Deletes a profile; with `force`, a profile that has versions too, which destroys every version. |
| `POST` | [`open`](/docs/api/profiles#open) | Mounts a profile for one session: returns the state of one version and, for WRITE_BACK, an attachment that `:commit` writes through until it expires. Every call is audited with the caller's context; the caller's principal needs a grant of at least the requested mode. |
| `POST` | [`commit`](/docs/api/profiles#commit) | Writes a mounted profile back as a new version, by compare-and-set on the version the attachment was opened at (or last committed). When another write landed first, nothing is lost: the result is still a new version, merged site by site with the newer write winning, and marked as a conflict. |

## get

Gets a profile: its kind, grants, sites and latest version; never a value.

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile` · scope `secrets:read` · effect `read` · [Request, response and examples](/docs/api/profiles/get)

## list

Lists the profiles of an environment.

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles` · scope `secrets:read` · effect `read` · paginated · [Request, response and examples](/docs/api/profiles/list)

## create

Creates an empty profile; its first version is written by a write-back mount (`:open` with WRITE_BACK, then `:commit`).

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles` · scope `secrets:write` · effect `write` · [Request, response and examples](/docs/api/profiles/create)

## update

Updates a profile's grants or declared paths. Granting a mount is this call: nothing else adds a grant.

`PATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile` · scope `secrets:write` · effect `write` · [Request, response and examples](/docs/api/profiles/update)

## delete

Deletes a profile; with `force`, a profile that has versions too, which destroys every version.

`DELETE https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile` · scope `secrets:write` · effect `destructive` · [Request, response and examples](/docs/api/profiles/delete)

## open

Mounts a profile for one session: returns the state of one version and, for WRITE_BACK, an attachment that `:commit` writes through until it expires. Every call is audited with the caller's context; the caller's principal needs a grant of at least the requested mode.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile:open` · scope `secrets:mount` · effect `read` · [Request, response and examples](/docs/api/profiles/open)

## commit

Writes a mounted profile back as a new version, by compare-and-set on the version the attachment was opened at (or last committed). When another write landed first, nothing is lost: the result is still a new version, merged site by site with the newer write winning, and marked as a conflict.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile:commit` · scope `secrets:mount` · effect `write` · [Request, response and examples](/docs/api/profiles/commit)
