---
# @generated by sylphx-gen 0.1.0 from contracts@fb95f0c42a0ec5d8e3cb694c0054b529c0b24b184112c65ef60c9044b4ce61f9. Do not edit.
title: "Commit a profile"
description: "`secrets.profiles.commit` (POST /v1/{name}:commit): Writes a mounted profile back as a new version, by compare-and-set on the version the attachment was opened at (or last committed)."
type: reference
product: platform
summary: "Writes a mounted profile back as a new version, by compare-and-set on the version the attachment was opened at (or last committed)."
updated: 2026-09-28
nav: false
---

Writes a mounted profile back as a new version, by compare-and-set on the version the attachment was opened at (or last committed). When another write landed first, nothing is lost: the result is still a new version, merged site by site with the newer write winning, and marked as a conflict.

- **Path** `POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile:commit`
- **Scope** `secrets:mount`
- **Effect** `write` — a successful call changes state.
- **Collection** [profiles](/docs/api/profiles)

## Request

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | The profile to write back. Required. |
| `attachment` | `string` | The `attachment` OpenProfile returned with WRITE_BACK. Required. |
| `state` | `bytes` | The whole state to write, in the profile kind's form, at most 2 MiB. Required. Never returned again. |

## Response

| Field | Type | What it is |
| --- | --- | --- |
| `profile_version` | `ProfileVersion` | The version written. |
| `conflict` | `bool` | True when another write landed after this attachment's base: the version holds both, merged site by site with this write winning the sites it changed. |

### ProfileVersion

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `…/profiles/{profile}/profile_versions/{profile_version}`; the id is the version number, from 1. |
| `uid` | `string` | `pflv_<cell><ulid>`. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `sites` | `ProfileSite[]` | The sites it holds and when each last changed. Output only. |
| `base_version` | `string` | The version the write was based on; empty for a first write. Output only. |
| `conflict_version` | `string` | Set when another version landed after the base: that version, whose sites this one kept where this write did not change them. Output only. |
| `size_bytes` | `int64` | The size of the state, in bytes. Output only. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `generation` | `int64` | Increases by one on every change to `spec`. Output only. |
| `etag` | `string` | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as `If-Match` or `etag` to make Update and Delete conditional; a mismatch fails with ABORTED / 409 `ETAG_MISMATCH`. Output only. |
| `create_time` | `timestamp` | When the Resource was created. Output only. |
| `update_time` | `timestamp` | When the Resource last changed. Output only. |
| `delete_time` | `timestamp` | Set while the Resource is being deleted. Output only. |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |
| `creator` | `string` | The principal that created the Resource. Output only. |

### ProfileSite

| Field | Type | What it is |
| --- | --- | --- |
| `site` | `string` | The registrable domain (eTLD+1), for example `example.com`; for a `computer` profile, one declared path. Output only. |
| `update_time` | `timestamp` | When this site's record last changed. Output only. |

## Errors

- [`UNAUTHENTICATED`](/docs/api/errors/UNAUTHENTICATED) — No valid key or token was presented.
- [`PERMISSION_DENIED`](/docs/api/errors/PERMISSION_DENIED) — The key lacks the method's permission.
- [`RESOURCE_NOT_FOUND`](/docs/api/errors/RESOURCE_NOT_FOUND) — The named Resource does not exist or is not visible.
- [`INVALID_FIELD`](/docs/api/errors/INVALID_FIELD) — A field failed validation.
- [`INVALID_STATE`](/docs/api/errors/INVALID_STATE) — The Resource is in a state that forbids the call.
- [`IDEMPOTENCY_KEY_REUSED`](/docs/api/errors/IDEMPOTENCY_KEY_REUSED) — An Idempotency-Key was reused with another body.
- [`IDEMPOTENCY_IN_PROGRESS`](/docs/api/errors/IDEMPOTENCY_IN_PROGRESS) — The first call with this Idempotency-Key is still running.

Every error arrives in the body [Errors](/docs/platform/errors) describes.

## Examples

**cURL**

```curl
curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile:commit" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"attachment":"…","state":"…"}'
```

**TypeScript**

```ts
const response = await sylphx.secrets.profiles.commit({ attachment: '…', name: 'orgs/acme/projects/shop/envs/production/profiles/profile', state: '…' })
```

**Rust**

```rust
let mut req = sylphx::secrets::CommitProfileRequest::default();
req.attachment = "…".to_string();
req.name = "orgs/acme/projects/shop/envs/production/profiles/profile".to_string();
req.state = "…".to_string();
let response = sx.secrets().profiles().commit(req).await?;
```

**CLI**

```bash
sylphx secrets profiles commit orgs/acme/projects/shop/envs/production/profiles/profile
```

**MCP**

```json
{ "method_id": "secrets.profiles.commit", "args": {"attachment":"…","name":"orgs/acme/projects/shop/envs/production/profiles/profile","state":"…"} }
```
