---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "sylphx auth end_users"
description: "The sylphx auth end_users commands of Sylphx Auth: every verb, with its argument, its flags and a run line."
type: reference
product: auth
summary: "Every sylphx auth end_users command: its argument, its flags and a run line."
updated: 2026-09-28
nav: false
---

The `end_users` commands of Sylphx Auth, as the CLI spells them: the same
calls as [the `end_users` API page](/docs/api/end_users), typed for the
shell. [Install, sign in and the grammar](/docs/cli) are on the CLI index.

## get

Gets an end user.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx auth end-users get orgs/acme/projects/shop/envs/production/end_users/end-user
```

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user` · scope `auth:read` · effect `read` · [Request, response and examples](/docs/api/end_users/get)

## list

Lists end users.

**`PARENT`** — optional: the CLI fills it from the linked project or the
key's scope when it is left out.

**CLI**

```bash
sylphx auth end-users list orgs/acme/projects/shop/envs/production
```

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users` · scope `auth:read` · effect `read` · [Request, response and examples](/docs/api/end_users/list)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--page-size` | `int` | At most this many; default 50, clamped to 1000. |
| `--page-token` | `string` | `next_page_token` of the previous page. |
| `--filter` | `string` | AIP-160 filter over labels and filterable fields. |
| `--order-by` | `string` | AIP-132 ordering over filterable fields. |

## create

Creates an end user.

**`ID`** — The id segment of the new Resource's name; the server assigns one when omitted.

**CLI**

```bash
sylphx auth end-users create --parent orgs/acme/projects/shop/envs/production
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users` · scope `auth:write` · effect `write` · [Request, response and examples](/docs/api/end_users/create)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--parent` | `string` | The parent to create in; defaults to the linked project or the key's scope. |
| `--meta.labels` | `key=value` | Caller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value. |
| `--meta.annotations` | `key=value` | Caller-writable, unindexed annotations. Repeat the flag for each value. |
| `--meta.display-name` | `string` | Caller-writable human-readable name. |
| `--email` | `string` | The primary email address. |
| `--password` | `string` | An initial password; write-only, checked against breached passwords. The value is never returned. |
| `--public-metadata` | `json` | App data readable by the end user's own tokens. |
| `--private-metadata` | `json` | App data readable only with an Access key. |
| `--unsafe-metadata` | `json` | App data the end user may write with their own session (preferences a sign-up form collects); never trust it for authorization. |
| `--dry-run` | `bool` | Validate and print the result without writing (validate_only). |

## update

Updates an end user.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx auth end-users update orgs/acme/projects/shop/envs/production/end_users/end-user
```

`PATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user` · scope `auth:write` · effect `write` · [Request, response and examples](/docs/api/end_users/update)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--meta.labels` | `key=value` | Caller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value. |
| `--meta.annotations` | `key=value` | Caller-writable, unindexed annotations. Repeat the flag for each value. |
| `--meta.display-name` | `string` | Caller-writable human-readable name. |
| `--email` | `string` | The primary email address. |
| `--password` | `string` | An initial password; write-only, checked against breached passwords. The value is never returned. |
| `--public-metadata` | `json` | App data readable by the end user's own tokens. |
| `--private-metadata` | `json` | App data readable only with an Access key. |
| `--unsafe-metadata` | `json` | App data the end user may write with their own session (preferences a sign-up form collects); never trust it for authorization. |
| `--dry-run` | `bool` | Validate and print the result without writing (validate_only). |

## delete

Deletes an end user.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx auth end-users delete orgs/acme/projects/shop/envs/production/end_users/end-user --yes
```

`DELETE https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user` · scope `auth:write` · effect `destructive` · [Request, response and examples](/docs/api/end_users/delete)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--etag` | `string` | Delete only if the current etag matches. |
| `--allow-missing` | `bool` | Succeed when the end user does not exist. |
| `--dry-run` | `bool` | Validate and print the result without writing (validate_only). |
| `--force` | `bool` | Also delete the end user's memberships; sessions are always revoked. |
| `--yes` | `bool` | Do not ask before this destructive call. |

## suspend

Suspends an end user: sessions are revoked and sign-in is refused.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx auth end-users suspend orgs/acme/projects/shop/envs/production/end_users/end-user --yes
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user:suspend` · scope `auth:write` · effect `destructive` · [Request, response and examples](/docs/api/end_users/suspend)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--reason` | `string` | Why; shown to administrators only. |
| `--etag` | `string` | Act only if the current etag matches. |
| `--yes` | `bool` | Do not ask before this destructive call. |

## reactivate

Reactivates a suspended end user.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx auth end-users reactivate orgs/acme/projects/shop/envs/production/end_users/end-user
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user:reactivate` · scope `auth:write` · effect `write` · [Request, response and examples](/docs/api/end_users/reactivate)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--etag` | `string` | Act only if the current etag matches. |

## unlock

Clears an end user's sign-in lock (repeated failed sign-ins) now.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx auth end-users unlock orgs/acme/projects/shop/envs/production/end_users/end-user
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user:unlock` · scope `auth:write` · effect `write` · [Request, response and examples](/docs/api/end_users/unlock)

## revoke-sessions

Revokes every session of an end user.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx auth end-users revoke-sessions orgs/acme/projects/shop/envs/production/end_users/end-user --yes
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user:revokeSessions` · scope `auth:write` · effect `destructive` · [Request, response and examples](/docs/api/end_users/revoke_sessions)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--yes` | `bool` | Do not ask before this destructive call. |
