---
title: Auth quickstart
description: Create an end user with an email and password, read it back, check its sessions and delete it, with the CLI, cURL or the SDK.
type: tutorial
product: auth
summary: An end user created, read back and deleted, in a few calls.
updated: 2026-10-01
order: 1
---

This page creates one end user from your server, reads it back, checks that it
has no sessions and deletes it. It uses the one API at
`https://api.sylphx.com`.

<Prerequisites
	items={[
		'An account, and a project with an environment - see the platform start page',
		'A Sylphx key with the auth:read and auth:write scopes, scoped to the environment, as SYLPHX_API_KEY',
	]}
/>

## 1. Find your environment

Every key can read where it belongs. Auth answers a key only inside its own
environment, so the call below gives you the parent name for the rest.

```bash
sylphx access whoami
```

The `env` it returns looks like `orgs/acme/projects/shop/envs/production`.

## 2. Create the end user

<CodeTabs>
	<CodeTab
		label="CLI"
		language="bash"
		code={`sylphx auth end-users create \\
  --parent orgs/acme/projects/shop/envs/production \\
  --email ada@example.com \\
  --password "$(openssl rand -base64 24)"`}
	/>
	<CodeTab
		label="cURL"
		language="bash"
		code={`curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users" \\
  -H "Authorization: Bearer $SYLPHX_API_KEY" \\
  -H "Content-Type: application/json" \\
  -d '{"email": "ada@example.com", "password": "a-long-random-password", "meta": {"display_name": "Ada"}}'`}
	/>
	<CodeTab
		label="TypeScript"
		language="ts"
		code={`import { Sylphx } from '@sylphx/sdk'

const sylphx = new Sylphx() // reads SYLPHX_API_KEY
const { env } = await sylphx.access.whoami({})

const user = await sylphx.auth.endUsers.create({
  parent: env!,
  endUser: { email: 'ada@example.com', password: crypto.randomUUID() + crypto.randomUUID() },
})
console.log(user.name)`}
	/>
</CodeTabs>

Auth assigns the id and stores only a hash of the password. The answer is the
end user: its `name` (`…/end_users/{id}`), its `email`, its `state` and the
`factors` it can sign in with. A password that appears in a known breach is
refused. An email is unique among the live end users of an environment, so a second
end user with the same email is refused.

## 3. Read it back

```bash
sylphx auth end-users get orgs/acme/projects/shop/envs/production/end_users/<id>
```

Check the `email` is the one you sent, `state` is `active`, and `factors`
includes `password`.

## 4. Check its sessions

```bash
sylphx auth sessions list orgs/acme/projects/shop/envs/production/end_users/<id>
```

A user who has only just been created has none. When one signs in, each
session is listed here and can be revoked with
`sylphx auth sessions revoke`.

## 5. Delete it

```bash
sylphx auth end-users delete orgs/acme/projects/shop/envs/production/end_users/<id> --yes
```

Deleting is revocation: every session ends and new sign-ins are refused.

## Next: sign users in from your pages

Your own sign-up form does not need your secret key. It calls the client API
with the publishable key; see [how a sign-in reaches your
app](/docs/auth#how-a-sign-in-reaches-your-app).

<RelatedDocs
	links={[
		{
			href: '/docs/auth',
			label: 'Auth overview',
			description: 'What is served, the two keys and the client API.',
		},
		{
			href: '/docs/api/end_users',
			label: 'The end_users collection',
			description: 'Every method, field and example.',
		},
	]}
/>
