Menu
Platform
AI
App store purchases
Database
Flags
Generated Assets
Jobs and cron
Localization
Monitoring
Notifications
Payments
Sandboxes
Webhooks
Getting Started
Authentication
KV Store
Deploy & Infrastructure
Reference
sylphx auth auth_configs
Every sylphx auth auth_configs command: its argument, its flags and a run line.
The auth_configs commands of Sylphx Auth, as the CLI spells them: the same
calls as the auth_configs API page, typed for the
shell. Install, sign in and the grammar are on the CLI index.
#get
Gets an auth config.
NAME — the resource's name; a bare id is enough below the linked
project.
CLI
sylphx auth auth-configs get orgs/acme/projects/shop/envs/production/auth_configs/auth-configGET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/auth_configs/auth-config · scope auth:read · effect read · Request, response and examples
#update
Updates an auth config.
NAME — the resource's name; a bare id is enough below the linked
project.
CLI
sylphx auth auth-configs update orgs/acme/projects/shop/envs/production/auth_configs/auth-configPATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/auth_configs/auth-config · scope auth:write · effect write · Request, response and examples
Flags
| Flag | Type | What it does |
|---|---|---|
--meta.labels | key=value | Caller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value. |
--meta.annotations | key=value | Caller-writable, unindexed annotations. Repeat the flag for each value. |
--meta.display-name | string | Caller-writable human-readable name. |
--spec.auth-methods | enum | Sign-in methods offered to end users. Repeat the flag for each value. One of password, magic_link, email_otp, passkey, totp, oidc, saml. |
--spec.mfa-required | bool | Require a second factor for every end user. |
--spec.passkey-policy.required | bool | Require a passkey for every end user. |
--spec.passkey-policy.device-bound | bool | Refuse synced (multi-device) passkeys. |
--spec.passkey-policy.aaguid-allowlist | string | Allowed authenticator AAGUIDs; empty allows any. Repeat the flag for each value. |
--spec.lockout-enabled | bool | Progressive lockout by user and IP. |
--spec.session-policy.max-concurrent-sessions | int | Concurrent sessions per end user; excess sessions are revoked, oldest first. 0 is unlimited. |
--spec.session-policy.idle-timeout | duration | Revoke after this long without use; default 30d. |
--spec.session-policy.absolute-timeout | duration | Revoke this long after sign-in regardless of use; default 90d. |
--spec.session-policy.fingerprint-binding | bool | Bind sessions to network and agent; a mismatch demands step-up. |
--spec.captcha-secret | string | The CAPTCHA verifier secret, held in Sylphx Secrets; unset disables CAPTCHA. |
--spec.portal.custom-domain | string | A verified Network Domain serving the portal; unset uses the default origin. |
--spec.portal.product-title | string | The product name shown to end users. |
--spec.portal.logo-uri | string | An HTTPS logo URI. |
--spec.portal.primary-color | string | The primary color, #rrggbb. |
--spec.portal.sylphx-branding | bool | Show Sylphx branding. |
--spec.mail-sending-domain | string | The Notify Sending Domain Auth mail is sent from; unset uses the Sylphx default. |
--spec.user-sync-database | string | A Sylphx Data database end users are synced into; unset disables sync. |
--spec.social-providers | json | Social sign-in: one entry per provider Sylphx serves (google, github, apple), whether it is on, and whether end users can use it now. An update changes only the providers it lists; the others keep their state. Without any change Google is on through Sylphx's shared client, when Sylphx has one. The provider's credentials (the shared client, or your own client id and secret) are set with the instance's sign-in-providers:put: a client secret never passes through this resource. Repeat the flag for each value. |
--allow-missing | bool | Create the auth config when it does not exist (declarative upsert). |
--dry-run | bool | Validate and print the result without writing (validate_only). |