Skip to content
Console
Menu

Queues

Workflows

Getting Started

Authentication

KV Store

Exchange token on a trust policy

Exchanges the caller's workload identity for a short-lived provider credential under a trust policy (RFC 8693 token exchange).

This method is not served on the public API. api.sylphx.com does not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.

Exchanges the caller's workload identity for a short-lived provider credential under a trust policy (RFC 8693 token exchange). The credential is narrowed to the request and cached per installation and permission set; a permission the Connection lacks is PERMISSION_DENIED with reason CapabilityMissing, never an outage.

Not available yet. Sylphx Broker is declared in the registry but no backend serves it: every call answers 501 with the problem code UNIMPLEMENTED.

  • Path POST https://api.sylphx.com/v1/orgs/acme/trust_policies/trust-policy:exchangeToken
  • Scope broker:exchange
  • Effect write — a successful call changes state.
  • Collection trust_policies

#Request

FieldTypeWhat it is
namestringThe trust policy to exchange under. Required.
subject_tokenstringThe caller's identity: a SPIFFE JWT-SVID or an Access-issued workload OIDC token, with audience broker.sylphx.com. Required. Never returned again.
permissionsmap<string, string>The permissions this call needs, at most the policy's; empty means the policy's.
repositoriesstring[]The repositories this call needs, at most the policy's; empty means the policy's.
ttldurationHow long the credential should live, at most the policy's max_ttl.

#Response

FieldTypeWhat it is
tokenstringThe provider credential. Never logged, persisted, or cached by the caller beyond expire_time. Never returned again.
credential_kindCredentialKindWhat token is. One of access_token, runner_registration.
expire_timetimestampWhen the credential stops working.
permissionsmap<string, string>The permissions the credential carries.
repositoriesstring[]The repositories the credential covers; empty means every repository the Connection covers.

#Errors

Every error arrives in the body Errors describes.

#Examples

curl -X POST "https://api.sylphx.com/v1/orgs/acme/trust_policies/trust-policy:exchangeToken" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"subject_token":"…"}'