---
# @generated by sylphx-gen 0.1.0 from contracts@fb95f0c42a0ec5d8e3cb694c0054b529c0b24b184112c65ef60c9044b4ce61f9. Do not edit.
title: "Open a profile"
description: "`secrets.profiles.open` (POST /v1/{name}:open): Mounts a profile for one session: returns the state of one version and, for WRITE_BACK, an attachment that `:commit` writes through until it expires."
type: reference
product: platform
summary: "Mounts a profile for one session: returns the state of one version and, for WRITE_BACK, an attachment that `:commit` writes through until it…"
updated: 2026-09-28
nav: false
---

Mounts a profile for one session: returns the state of one version and, for WRITE_BACK, an attachment that `:commit` writes through until it expires. Every call is audited with the caller's context; the caller's principal needs a grant of at least the requested mode.

- **Path** `POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile:open`
- **Scope** `secrets:mount`
- **Effect** `read` — nothing is written.
- **Collection** [profiles](/docs/api/profiles)

## Request

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | The profile to mount. Required. |
| `mode` | `ProfileMountMode` | READ_ONLY (the default) or WRITE_BACK. One of `read_only`, `write_back`. |
| `version` | `string` | A version to mount; unset mounts the latest. |
| `ttl` | `duration` | How long a WRITE_BACK attachment may commit; default 1 hour, at most 12 hours. A lost session cannot write back after it. |
| `context` | `map<string, string>` | Who mounts it, for the audit trail: for example `run`, `step`, `member`. At most 16 entries; keys and values are names, never values. |

## Response

| Field | Type | What it is |
| --- | --- | --- |
| `attachment` | `string` | The attachment this mount is recorded as; `:commit` takes it. |
| `version` | `string` | The version mounted; empty when the profile has none yet. |
| `mode` | `ProfileMountMode` | The mode granted. One of `read_only`, `write_back`. |
| `state` | `bytes` | The profile's state: for a `browser` profile the Playwright `storageState` JSON document, for a `computer` profile the archive of its declared paths. Empty when the profile has no version yet. Never returned again. |
| `expire_time` | `timestamp` | When a WRITE_BACK attachment stops accepting commits. |
| `sites` | `ProfileSite[]` | The sites in the state and when each last changed. |

### ProfileSite

| Field | Type | What it is |
| --- | --- | --- |
| `site` | `string` | The registrable domain (eTLD+1), for example `example.com`; for a `computer` profile, one declared path. Output only. |
| `update_time` | `timestamp` | When this site's record last changed. Output only. |

## Errors

- [`UNAUTHENTICATED`](/docs/api/errors/UNAUTHENTICATED) — No valid key or token was presented.
- [`PERMISSION_DENIED`](/docs/api/errors/PERMISSION_DENIED) — The key lacks the method's permission.
- [`RESOURCE_NOT_FOUND`](/docs/api/errors/RESOURCE_NOT_FOUND) — The named Resource does not exist or is not visible.
- [`INVALID_FIELD`](/docs/api/errors/INVALID_FIELD) — A field failed validation.

Every error arrives in the body [Errors](/docs/platform/errors) describes.

## Examples

**cURL**

```curl
curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile:open" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{}'
```

**TypeScript**

```ts
const response = await sylphx.secrets.profiles.open({ name: 'orgs/acme/projects/shop/envs/production/profiles/profile' })
```

**Rust**

```rust
let mut req = sylphx::secrets::OpenProfileRequest::default();
req.name = "orgs/acme/projects/shop/envs/production/profiles/profile".to_string();
let response = sx.secrets().profiles().open(req).await?;
```

**CLI**

```bash
sylphx secrets profiles open orgs/acme/projects/shop/envs/production/profiles/profile
```

**MCP**

```json
{ "method_id": "secrets.profiles.open", "args": {"name":"orgs/acme/projects/shop/envs/production/profiles/profile"} }
```
