---
# @generated by sylphx-gen 0.1.0 from contracts@190f1b33b937c1aef79697684018db853389b521c75e19ff69ac6af609e96f45. Do not edit.
title: "sylphx auth identities"
description: "The sylphx auth identities commands of Sylphx Auth: every verb, with its argument, its flags and a run line."
type: reference
product: auth
summary: "Every sylphx auth identities command: its argument, its flags and a run line."
updated: 2026-09-28
nav: false
---

The `identities` commands of Sylphx Auth, as the CLI spells them: the same
calls as [the `identities` API page](/docs/api/identities), typed for the
shell. [Install, sign in and the grammar](/docs/cli) are on the CLI index.

## get

Gets an identity of an end user.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx auth identities get orgs/acme/projects/shop/envs/production/end_users/end-user/identities/identity
```

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user/identities/identity` · scope `auth:read` · effect `read` · [Request, response and examples](/docs/api/identities/get)

## list

Lists the identities an end user signs in with.

**`PARENT`** — optional: the CLI fills it from the linked project or the
key's scope when it is left out.

**CLI**

```bash
sylphx auth identities list orgs/acme/projects/shop/envs/production/end_users/end-user
```

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user/identities` · scope `auth:read` · effect `read` · [Request, response and examples](/docs/api/identities/list)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--page-size` | `int` | At most this many; default 50, clamped to 1000. |
| `--page-token` | `string` | `next_page_token` of the previous page. |
| `--filter` | `string` | AIP-160 filter over labels and filterable fields. |
| `--order-by` | `string` | AIP-132 ordering over filterable fields. |

## move

Moves a federated or device identity from one end user to another, to fix a wrongly linked player. One transaction: the identity changes owner, the sessions of both end users are revoked, and nothing else about either moves (profile, memberships, data). Refused when it would leave the source with no sign-in, unless the source is suspended, and when the target already has an identity of the same provider. The reason is audited with the operator, both end users and the identity's fingerprint. An operator action: an end user's own session cannot call it.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx auth identities move orgs/acme/projects/shop/envs/production/end_users/end-user/identities/identity --yes
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user/identities/identity:move` · scope `auth:write` · effect `destructive` · [Request, response and examples](/docs/api/identities/move)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--target-end-user` | `string` | The end user that receives the identity. Required. |
| `--reason` | `string` | Why the identity moves (1 to 512 characters); recorded in the audit trail. Required. |
| `--yes` | `bool` | Do not ask before this destructive call. |
