Skip to content
Console
Menu

Generated Assets

Workflows

Getting Started

Authentication

KV Store

On this page

sylphx auth auth_configs

Every sylphx auth auth_configs command: its argument, its flags and a run line.

The auth_configs commands of Sylphx Auth, as the CLI spells them: the same calls as the auth_configs API page, typed for the shell. Install, sign in and the grammar are on the CLI index.

#get

Gets an auth config.

NAME — the resource's name; a bare id is enough below the linked project.

CLI

Shell
sylphx auth auth-configs get orgs/acme/projects/shop/envs/production/auth_configs/auth-config

GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/auth_configs/auth-config · scope auth:read · effect read · Request, response and examples

#update

Updates an auth config.

NAME — the resource's name; a bare id is enough below the linked project.

CLI

Shell
sylphx auth auth-configs update orgs/acme/projects/shop/envs/production/auth_configs/auth-config

PATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/auth_configs/auth-config · scope auth:write · effect write · Request, response and examples

Flags

FlagTypeWhat it does
--meta.labelskey=valueCaller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value.
--meta.annotationskey=valueCaller-writable, unindexed annotations. Repeat the flag for each value.
--meta.display-namestringCaller-writable human-readable name.
--spec.auth-methodsenumSign-in methods offered to end users. Repeat the flag for each value. One of password, magic_link, email_otp, passkey, totp, oidc, saml.
--spec.mfa-requiredboolRequire a second factor for every end user.
--spec.passkey-policy.requiredboolRequire a passkey for every end user.
--spec.passkey-policy.device-boundboolRefuse synced (multi-device) passkeys.
--spec.passkey-policy.aaguid-allowliststringAllowed authenticator AAGUIDs; empty allows any. Repeat the flag for each value.
--spec.lockout-enabledboolProgressive lockout by user and IP.
--spec.session-policy.max-concurrent-sessionsintConcurrent sessions per end user; excess sessions are revoked, oldest first. 0 is unlimited.
--spec.session-policy.idle-timeoutdurationRevoke after this long without use; default 30d.
--spec.session-policy.absolute-timeoutdurationRevoke this long after sign-in regardless of use; default 90d.
--spec.session-policy.fingerprint-bindingboolBind sessions to network and agent; a mismatch demands step-up.
--spec.captcha-secretstringThe CAPTCHA verifier secret, held in Sylphx Secrets; unset disables CAPTCHA.
--spec.portal.custom-domainstringA verified Network Domain serving the portal; unset uses the default origin.
--spec.portal.product-titlestringThe product name shown to end users.
--spec.portal.logo-uristringAn HTTPS logo URI.
--spec.portal.primary-colorstringThe primary color, #rrggbb.
--spec.portal.sylphx-brandingboolShow Sylphx branding.
--spec.mail-sending-domainstringThe Notify Sending Domain Auth mail is sent from; unset uses the Sylphx default.
--spec.user-sync-databasestringA Sylphx Data database end users are synced into; unset disables sync.
--spec.social-providersjsonSocial sign-in: one entry per provider Sylphx serves (google, github, apple), whether it is on, and whether end users can use it now. An update changes only the providers it lists; the others keep their state. Without any change Google is on through Sylphx's shared client, when Sylphx has one. The provider's credentials (the shared client, or your own client id and secret) are set with the instance's sign-in-providers:put: a client secret never passes through this resource. Repeat the flag for each value.
--allow-missingboolCreate the auth config when it does not exist (declarative upsert).
--dry-runboolValidate and print the result without writing (validate_only).