Menu
Platform
AI
App store purchases
Database
Flags
Jobs and cron
Localization
Monitoring
Notifications
Payments
Queues
Sandboxes
Webhooks
Getting Started
Authentication
KV Store
Deploy & Infrastructure
Reference
Auth quickstart
An end user created, read back and deleted, in a few calls.
This page creates one end user from your server, reads it back, checks that it
has no sessions and deletes it. It uses the one API at
https://api.sylphx.com.
#1. Find your environment
Every key can read where it belongs. Auth answers a key only inside its own environment, so the call below gives you the parent name for the rest.
sylphx access whoamiThe env it returns looks like orgs/acme/projects/shop/envs/production.
#2. Create the end user
sylphx auth end-users create \
--parent orgs/acme/projects/shop/envs/production \
--email ada@example.com \
--password "$(openssl rand -base64 24)"Auth assigns the id and stores only a hash of the password. The answer is the
end user: its name (…/end_users/{id}), its email, its state and the
factors it can sign in with. A password that appears in a known breach is
refused. An email is unique among the live end users of an environment, so a second
end user with the same email is refused.
#3. Read it back
sylphx auth end-users get orgs/acme/projects/shop/envs/production/end_users/<id>Check the email is the one you sent, state is active, and factors
includes password.
#4. Check its sessions
sylphx auth sessions list orgs/acme/projects/shop/envs/production/end_users/<id>A user who has only just been created has none. When one signs in, each
session is listed here and can be revoked with
sylphx auth sessions revoke.
#5. Delete it
sylphx auth end-users delete orgs/acme/projects/shop/envs/production/end_users/<id> --yesDeleting is revocation: every session ends and new sign-ins are refused.
#Next: sign users in from your pages
Your own sign-up form does not need your secret key. It calls the client API with the publishable key; see how a sign-in reaches your app.