---
# @generated by sylphx-gen 0.1.0 from contracts@04e1ecbfe774a1a19c4948892114a2dfa4a5502a024d780c13f5d41103b96d5d. Do not edit.
title: "sylphx auth auth_configs"
description: "The sylphx auth auth_configs commands of Sylphx Auth: every verb, with its argument, its flags and a run line."
type: reference
product: auth
summary: "Every sylphx auth auth_configs command: its argument, its flags and a run line."
updated: 2026-09-28
nav: false
---

The `auth_configs` commands of Sylphx Auth, as the CLI spells them: the same
calls as [the `auth_configs` API page](/docs/api/auth_configs), typed for the
shell. [Install, sign in and the grammar](/docs/cli) are on the CLI index.

## get

Gets an auth config.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx auth auth-configs get orgs/acme/projects/shop/envs/production/auth_configs/auth-config
```

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/auth_configs/auth-config` · scope `auth:read` · effect `read` · [Request, response and examples](/docs/api/auth_configs/get)

## update

Updates an auth config.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx auth auth-configs update orgs/acme/projects/shop/envs/production/auth_configs/auth-config
```

`PATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/auth_configs/auth-config` · scope `auth:write` · effect `write` · [Request, response and examples](/docs/api/auth_configs/update)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--meta.labels` | `key=value` | Caller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value. |
| `--meta.annotations` | `key=value` | Caller-writable, unindexed annotations. Repeat the flag for each value. |
| `--meta.display-name` | `string` | Caller-writable human-readable name. |
| `--spec.auth-methods` | `enum` | Sign-in methods offered to end users. Repeat the flag for each value. One of `password`, `magic_link`, `email_otp`, `passkey`, `totp`, `oidc`, `saml`. |
| `--spec.mfa-required` | `bool` | Require a second factor for every end user. |
| `--spec.passkey-policy.required` | `bool` | Require a passkey for every end user. |
| `--spec.passkey-policy.device-bound` | `bool` | Refuse synced (multi-device) passkeys. |
| `--spec.passkey-policy.aaguid-allowlist` | `string` | Allowed authenticator AAGUIDs; empty allows any. Repeat the flag for each value. |
| `--spec.lockout-enabled` | `bool` | Progressive lockout by user and IP. |
| `--spec.session-policy.max-concurrent-sessions` | `int` | Concurrent sessions per end user; excess sessions are revoked, oldest first. 0 is unlimited. |
| `--spec.session-policy.idle-timeout` | `duration` | Revoke after this long without use; default 30d. |
| `--spec.session-policy.absolute-timeout` | `duration` | Revoke this long after sign-in regardless of use; default 90d. |
| `--spec.session-policy.fingerprint-binding` | `bool` | Bind sessions to network and agent; a mismatch demands step-up. |
| `--spec.captcha-secret` | `string` | The CAPTCHA verifier secret, held in Sylphx Secrets; unset disables CAPTCHA. |
| `--spec.portal.custom-domain` | `string` | A verified Network Domain serving the portal; unset uses the default origin. |
| `--spec.portal.product-title` | `string` | The product name shown to end users. |
| `--spec.portal.logo-uri` | `string` | An HTTPS logo URI. |
| `--spec.portal.primary-color` | `string` | The primary color, `#rrggbb`. |
| `--spec.portal.sylphx-branding` | `bool` | Show Sylphx branding. |
| `--spec.mail-sending-domain` | `string` | The Notify Sending Domain Auth mail is sent from; unset uses the Sylphx default. |
| `--spec.user-sync-database` | `string` | A Sylphx Data database end users are synced into; unset disables sync. |
| `--spec.social-providers` | `json` | Social sign-in: one entry per provider Sylphx serves (`google`, `github`, `apple`), whether it is on, and whether end users can use it now. An update changes only the providers it lists; the others keep their state. Without any change Google is on through Sylphx's shared client, when Sylphx has one. The provider's credentials (the shared client, or your own client id and secret) are set with the instance's `sign-in-providers:put`: a client secret never passes through this resource. Repeat the flag for each value. |
| `--allow-missing` | `bool` | Create the auth config when it does not exist (declarative upsert). |
| `--dry-run` | `bool` | Validate and print the result without writing (validate_only). |
