Skip to content
Console
Menu

Queues

Workflows

Getting Started

Authentication

KV Store

sylphx access api_keys

Every sylphx access api_keys command: its argument, its flags and a run line.

The api_keys commands of Sylphx Access, as the CLI spells them: the same calls as the api_keys API page, typed for the shell. Install, sign in and the grammar are on the CLI index.

#get

Gets an API key.

NAME — the resource's name; a bare id is enough below the linked project.

CLI

Shell
sylphx access api-keys get orgs/acme/projects/shop/envs/production/api_keys/api-key

GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/api_keys/api-key · scope access:read · effect read · Request, response and examples

#list

Lists API keys in an environment, or the org-wide keys of an org.

PARENT — optional: the CLI fills it from the linked project or the key's scope when it is left out.

CLI

Shell
sylphx access api-keys list orgs/acme/projects/shop/envs/production

GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/api_keys · scope access:read · effect read · Request, response and examples

Flags

FlagTypeWhat it does
--page-sizeintAt most this many; default 50, clamped to 1000.
--page-tokenstringnext_page_token of the previous page.
--filterstringAIP-160 filter over labels, filterable spec fields, and Ready.
--order-bystringAIP-132 ordering over filterable fields.

#create

Creates an API key. Access assigns the id.

CLI

Shell
sylphx access api-keys create --parent orgs/acme/projects/shop/envs/production --spec.kind secret

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/api_keys · scope access:keys:write · effect write · Request, response and examples

Flags

FlagTypeWhat it does
--parentstringThe parent to create in; defaults to the linked project or the key's scope.
--meta.labelskey=valueCaller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value.
--meta.annotationskey=valueCaller-writable, unindexed annotations. Repeat the flag for each value.
--meta.display-namestringCaller-writable human-readable name.
--spec.kindenumSecret (server-side) or publishable (browser, publishable_ok methods only). Required. One of secret, publishable.
--spec.scopesstringScopes <service>:<action>, a subset of the creator's effective scopes. Required. Repeat the flag for each value.
--spec.labelstringA free-form label, for example the talent id a key was minted for.
--spec.expire-timetimestampWhen the key stops verifying; required in unclaimed projects.

#update

Updates an API key.

NAME — the resource's name; a bare id is enough below the linked project.

CLI

Shell
sylphx access api-keys update orgs/acme/projects/shop/envs/production/api_keys/api-key

PATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/api_keys/api-key · scope access:keys:write · effect write · Request, response and examples

Flags

FlagTypeWhat it does
--meta.labelskey=valueCaller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value.
--meta.annotationskey=valueCaller-writable, unindexed annotations. Repeat the flag for each value.
--meta.display-namestringCaller-writable human-readable name.
--spec.labelstringA free-form label, for example the talent id a key was minted for.
--dry-runboolValidate and print the result without writing (validate_only).

#delete

Deletes an API key.

NAME — the resource's name; a bare id is enough below the linked project.

CLI

Shell
sylphx access api-keys delete orgs/acme/projects/shop/envs/production/api_keys/api-key --yes

DELETE https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/api_keys/api-key · scope access:keys:write · effect destructive · Request, response and examples

Flags

FlagTypeWhat it does
--etagstringDelete only if the current etag matches.
--dry-runboolValidate and print the result without writing (validate_only).
--yesboolDo not ask before this destructive call.

#revoke

Revokes an API key immediately; revocation propagates on its own fast path, ahead of the bulk key data.

NAME — the resource's name; a bare id is enough below the linked project.

CLI

Shell
sylphx access api-keys revoke orgs/acme/projects/shop/envs/production/api_keys/api-key --yes

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/api_keys/api-key:revoke · scope access:keys:write · effect destructive · Request, response and examples

Flags

FlagTypeWhat it does
--etagstringRevoke only if the current etag matches.
--yesboolDo not ask before this destructive call.

#roll

Rolls an API key: returns a new key with the same spec and revokes the old one after the grace period.

NAME — the resource's name; a bare id is enough below the linked project.

CLI

Shell
sylphx access api-keys roll orgs/acme/projects/shop/envs/production/api_keys/api-key

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/api_keys/api-key:roll · scope access:keys:write · effect write · Request, response and examples

Flags

FlagTypeWhat it does
--grace-perioddurationHow long the old key keeps verifying; default 24h.
--etagstringRoll only if the current etag matches.