Menu
Platform
AI
App store purchases
Credits
Database
Flags
Generated Assets
Monitoring
Notifications
Organizations
Payments
- Payments
- Payments quickstart
- Checkout policies
- Checkout sessions
- Customer subscriptions
- Entitlement grants
- Exchange rates
- Licence keys
- Licence tokens
- Merchant accounts
- Portal sessions
- Price catalogs
- Revenue
- Revenue facts
- Revenue sources
- Tax threshold statuses
- Usage events
- Usage invoices
- Usage meter prices
- Usage meters
- Usage reservations
- Usage settings
- Usage tiers
Sandboxes
Webhooks
Getting Started
Authentication
KV Store
Deploy & Infrastructure
Reference
Update a profile
Updates a profile's grants or declared paths.
Updates a profile's grants or declared paths. Granting a mount is this call: nothing else adds a grant.
- Path
PATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile - Scope
secrets:write - Effect
write— a successful call changes state. - Collection profiles
- Query
update_mask,validate_only
#Request
| Field | Type | What it is |
|---|---|---|
profile | Profile | The profile to update; name identifies it. Required. |
update_mask | field_mask | The fields to write (spec.grants, spec.paths); unset writes both. |
validate_only | bool | Validate and return the result without writing anything. |
#Profile
| Field | Type | What it is |
|---|---|---|
name | string | orgs/{org}/projects/{project}/envs/{env}/profiles/{profile}. |
meta | ResourceMeta | Resource metadata. |
spec | ProfileSpec | Desired state. Required. |
#ResourceMeta
| Field | Type | What it is |
|---|---|---|
labels | map<string, string> | Caller-writable, indexed labels (AIP-122 label rules). |
annotations | map<string, string> | Caller-writable, unindexed annotations. |
display_name | string | Caller-writable human-readable name. |
#ProfileSpec
| Field | Type | What it is |
|---|---|---|
kind | ProfileKind | What the profile holds. Required. One of browser, computer. |
grants | ProfileGrant[] | Who may mount it and how. A principal with no grant cannot mount it, whatever its scopes. |
paths | string[] | For a computer profile: the paths under the sandbox's home directory its archive holds, for example .config/app. |
#ProfileGrant
| Field | Type | What it is |
|---|---|---|
principal | string | The Access principal, as its keys carry it (for example a service account's id). Required. |
mode | ProfileMountMode | The most it may mount: READ_ONLY, or WRITE_BACK (which includes READ_ONLY). Required. One of read_only, write_back. |
#Response
| Field | Type | What it is |
|---|---|---|
name | string | orgs/{org}/projects/{project}/envs/{env}/profiles/{profile}. |
uid | string | pfl_<cell><ulid>. Output only. |
meta | ResourceMeta | Resource metadata. |
spec | ProfileSpec | Desired state. Required. |
status | ProfileStatus | Observed state. Output only. |
#ResourceMeta
| Field | Type | What it is |
|---|---|---|
generation | int64 | Increases by one on every change to spec. Output only. |
etag | string | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as If-Match or etag to make Update and Delete conditional; a mismatch fails with ABORTED / 409 ETAG_MISMATCH. Output only. |
create_time | timestamp | When the Resource was created. Output only. |
update_time | timestamp | When the Resource last changed. Output only. |
delete_time | timestamp | Set while the Resource is being deleted. Output only. |
labels | map<string, string> | Caller-writable, indexed labels (AIP-122 label rules). |
annotations | map<string, string> | Caller-writable, unindexed annotations. |
display_name | string | Caller-writable human-readable name. |
creator | string | The principal that created the Resource. Output only. |
#ProfileSpec
| Field | Type | What it is |
|---|---|---|
kind | ProfileKind | What the profile holds. Required. One of browser, computer. |
grants | ProfileGrant[] | Who may mount it and how. A principal with no grant cannot mount it, whatever its scopes. |
paths | string[] | For a computer profile: the paths under the sandbox's home directory its archive holds, for example .config/app. |
#ProfileStatus
| Field | Type | What it is |
|---|---|---|
observed_generation | int64 | The generation this status was computed from. Output only. |
conditions | Condition[] | Ready. Output only. |
latest_version | string | The newest version; empty until the first write-back. Output only. |
sites | ProfileSite[] | The sites of the latest version and when each last changed. Output only. |
#ProfileGrant
| Field | Type | What it is |
|---|---|---|
principal | string | The Access principal, as its keys carry it (for example a service account's id). Required. |
mode | ProfileMountMode | The most it may mount: READ_ONLY, or WRITE_BACK (which includes READ_ONLY). Required. One of read_only, write_back. |
#Condition
| Field | Type | What it is |
|---|---|---|
type | string | The condition type, for example Ready. |
status | ConditionStatus | Whether the condition holds. One of true, false, unknown. |
observed_generation | int64 | The generation this observation was made against. |
reason | string | A machine-readable UpperCamelCase reason. |
message | string | A customer-safe human-readable message. |
severity | Severity | How severe a FALSE condition is. One of info, warning, error. |
transition_time | timestamp | When status last changed. |
#ProfileSite
| Field | Type | What it is |
|---|---|---|
site | string | The registrable domain (eTLD+1), for example example.com; for a computer profile, one declared path. Output only. |
update_time | timestamp | When this site's record last changed. Output only. |
#Errors
UNAUTHENTICATED— No valid key or token was presented.PERMISSION_DENIED— The key lacks the method's permission.RESOURCE_NOT_FOUND— The named Resource does not exist or is not visible.UNKNOWN_FIELD— The request has a field the schema does not know.INVALID_FIELD— A field failed validation.ETAG_MISMATCH— The etag sent does not match the Resource's current etag.IDEMPOTENCY_KEY_REUSED— An Idempotency-Key was reused with another body.IDEMPOTENCY_IN_PROGRESS— The first call with this Idempotency-Key is still running.
Every error arrives in the body Errors describes.
#Examples
curl -X PATCH "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile" \
-H "Authorization: Bearer $SYLPHX_API_KEY" \
-H "Content-Type: application/json" \
-d '{"name":"orgs/acme/projects/shop/envs/production/profiles/profile","spec":{"kind":"browser"}}'