---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "sylphx access api_keys"
description: "The sylphx access api_keys commands of Sylphx Access: every verb, with its argument, its flags and a run line."
type: reference
product: platform
summary: "Every sylphx access api_keys command: its argument, its flags and a run line."
updated: 2026-09-28
nav: false
---

The `api_keys` commands of Sylphx Access, as the CLI spells them: the same
calls as [the `api_keys` API page](/docs/api/api_keys), typed for the
shell. [Install, sign in and the grammar](/docs/cli) are on the CLI index.

## get

Gets an API key.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx access api-keys get orgs/acme/projects/shop/envs/production/api_keys/api-key
```

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/api_keys/api-key` · scope `access:read` · effect `read` · [Request, response and examples](/docs/api/api_keys/get)

## list

Lists API keys in an environment, or the org-wide keys of an org.

**`PARENT`** — optional: the CLI fills it from the linked project or the
key's scope when it is left out.

**CLI**

```bash
sylphx access api-keys list orgs/acme/projects/shop/envs/production
```

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/api_keys` · scope `access:read` · effect `read` · [Request, response and examples](/docs/api/api_keys/list)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--page-size` | `int` | At most this many; default 50, clamped to 1000. |
| `--page-token` | `string` | `next_page_token` of the previous page. |
| `--filter` | `string` | AIP-160 filter over labels, filterable spec fields, and Ready. |
| `--order-by` | `string` | AIP-132 ordering over filterable fields. |

## create

Creates an API key. Access assigns the id.

**CLI**

```bash
sylphx access api-keys create --parent orgs/acme/projects/shop/envs/production --spec.kind secret
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/api_keys` · scope `access:keys:write` · effect `write` · [Request, response and examples](/docs/api/api_keys/create)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--parent` | `string` | The parent to create in; defaults to the linked project or the key's scope. |
| `--meta.labels` | `key=value` | Caller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value. |
| `--meta.annotations` | `key=value` | Caller-writable, unindexed annotations. Repeat the flag for each value. |
| `--meta.display-name` | `string` | Caller-writable human-readable name. |
| `--spec.kind` | `enum` | Secret (server-side) or publishable (browser, `publishable_ok` methods only). Required. One of `secret`, `publishable`. |
| `--spec.scopes` | `string` | Scopes `<service>:<action>`, a subset of the creator's effective scopes. Required. Repeat the flag for each value. |
| `--spec.label` | `string` | A free-form label, for example the talent id a key was minted for. |
| `--spec.expire-time` | `timestamp` | When the key stops verifying; required in unclaimed projects. |

## update

Updates an API key.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx access api-keys update orgs/acme/projects/shop/envs/production/api_keys/api-key
```

`PATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/api_keys/api-key` · scope `access:keys:write` · effect `write` · [Request, response and examples](/docs/api/api_keys/update)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--meta.labels` | `key=value` | Caller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value. |
| `--meta.annotations` | `key=value` | Caller-writable, unindexed annotations. Repeat the flag for each value. |
| `--meta.display-name` | `string` | Caller-writable human-readable name. |
| `--spec.label` | `string` | A free-form label, for example the talent id a key was minted for. |
| `--dry-run` | `bool` | Validate and print the result without writing (validate_only). |

## delete

Deletes an API key.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx access api-keys delete orgs/acme/projects/shop/envs/production/api_keys/api-key --yes
```

`DELETE https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/api_keys/api-key` · scope `access:keys:write` · effect `destructive` · [Request, response and examples](/docs/api/api_keys/delete)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--etag` | `string` | Delete only if the current etag matches. |
| `--dry-run` | `bool` | Validate and print the result without writing (validate_only). |
| `--yes` | `bool` | Do not ask before this destructive call. |

## revoke

Revokes an API key immediately; revocation propagates on its own fast path, ahead of the bulk key data.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx access api-keys revoke orgs/acme/projects/shop/envs/production/api_keys/api-key --yes
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/api_keys/api-key:revoke` · scope `access:keys:write` · effect `destructive` · [Request, response and examples](/docs/api/api_keys/revoke)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--etag` | `string` | Revoke only if the current etag matches. |
| `--yes` | `bool` | Do not ask before this destructive call. |

## roll

Rolls an API key: returns a new key with the same spec and revokes the old one after the grace period.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx access api-keys roll orgs/acme/projects/shop/envs/production/api_keys/api-key
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/api_keys/api-key:roll` · scope `access:keys:write` · effect `write` · [Request, response and examples](/docs/api/api_keys/roll)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--grace-period` | `duration` | How long the old key keeps verifying; default 24h. |
| `--etag` | `string` | Roll only if the current etag matches. |
