Skip to content
Console
Menu

Queues

Workflows

Getting Started

Authentication

KV Store

Auth quickstart

An end user created, read back and deleted, in a few calls.

This page creates one end user from your server, reads it back, checks that it has no sessions and deletes it. It uses the one API at https://api.sylphx.com.

#1. Find your environment

Every key can read where it belongs. Auth answers a key only inside its own environment, so the call below gives you the parent name for the rest.

Shell
sylphx access whoami

The env it returns looks like orgs/acme/projects/shop/envs/production.

#2. Create the end user

sylphx auth end-users create \
--parent orgs/acme/projects/shop/envs/production \
--email ada@example.com \
--password "$(openssl rand -base64 24)"

Auth assigns the id and stores only a hash of the password. The answer is the end user: its name (…/end_users/{id}), its email, its state and the factors it can sign in with. A password that appears in a known breach is refused. An email is unique among the live end users of an environment, so a second end user with the same email is refused.

#3. Read it back

Shell
sylphx auth end-users get orgs/acme/projects/shop/envs/production/end_users/<id>

Check the email is the one you sent, state is active, and factors includes password.

#4. Check its sessions

Shell
sylphx auth sessions list orgs/acme/projects/shop/envs/production/end_users/<id>

A user who has only just been created has none. When one signs in, each session is listed here and can be revoked with sylphx auth sessions revoke.

#5. Delete it

Shell
sylphx auth end-users delete orgs/acme/projects/shop/envs/production/end_users/<id> --yes

Deleting is revocation: every session ends and new sign-ins are refused.

#Next: sign users in from your pages

Your own sign-up form does not need your secret key. It calls the client API with the publishable key; see how a sign-in reaches your app.