Menu
Platform
AI
App store purchases
Database
Flags
Jobs and cron
Localization
Monitoring
Notifications
Payments
Queues
Sandboxes
Webhooks
Getting Started
Authentication
KV Store
Deploy & Infrastructure
Reference
sylphx keys keys
Every sylphx keys keys command: its argument, its flags and a run line.
The keys commands of Sylphx Keys, as the CLI spells them: the same
calls as the keys API page, typed for the
shell. Install, sign in and the grammar are on the CLI index.
#get
Gets a key.
NAME — the resource's name; a bare id is enough below the linked
project.
CLI
sylphx keys keys get orgs/acme/projects/shop/envs/production/keys/keyGET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key · scope keys:read · effect read · Request, response and examples
#list
Lists keys in an environment.
PARENT — optional: the CLI fills it from the linked project or the
key's scope when it is left out.
CLI
sylphx keys keys list orgs/acme/projects/shop/envs/productionGET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys · scope keys:read · effect read · Request, response and examples
Flags
| Flag | Type | What it does |
|---|---|---|
--page-size | int | At most this many; default 50, clamped to 1000. |
--page-token | string | next_page_token of the previous page. |
--filter | string | AIP-160 filter over labels and filterable fields. |
--order-by | string | AIP-132 ordering over filterable fields. |
#create
Creates a key; the signer generates its first version.
ID — The id segment of the new Resource's name; the server assigns one when omitted.
CLI
sylphx keys keys create --parent orgs/acme/projects/shop/envs/production --spec.purpose sign --spec.algorithm ed25519POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys · scope keys:write · effect write · Request, response and examples
Flags
| Flag | Type | What it does |
|---|---|---|
--parent | string | The parent to create in; defaults to the linked project or the key's scope. |
--meta.labels | key=value | Caller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value. |
--meta.annotations | key=value | Caller-writable, unindexed annotations. Repeat the flag for each value. |
--meta.display-name | string | Caller-writable human-readable name. |
--spec.purpose | enum | What the key does. Required. One of sign, encrypt, mac. |
--spec.algorithm | enum | The algorithm; it must suit the purpose. Required. One of ed25519, ec_p256_sha256, rsa_pkcs1_2048_sha256, rsa_pss_3072_sha256, aes_256_gcm, hmac_sha256. |
--spec.rotation-period | duration | Rotate automatically this often; unset means rotate only on request. |
--spec.deletion-protection | bool | While true, Delete fails with DELETION_PROTECTED. Default true. |
--dry-run | bool | Validate and print the result without writing (validate_only). |
--no-wait | bool | Return the call at once instead of waiting for it to finish. |
#update
Updates a key's rotation period, deletion protection, or metadata.
NAME — the resource's name; a bare id is enough below the linked
project.
CLI
sylphx keys keys update orgs/acme/projects/shop/envs/production/keys/keyPATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key · scope keys:write · effect write · Request, response and examples
Flags
| Flag | Type | What it does |
|---|---|---|
--meta.labels | key=value | Caller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value. |
--meta.annotations | key=value | Caller-writable, unindexed annotations. Repeat the flag for each value. |
--meta.display-name | string | Caller-writable human-readable name. |
--spec.rotation-period | duration | Rotate automatically this often; unset means rotate only on request. |
--spec.deletion-protection | bool | While true, Delete fails with DELETION_PROTECTED. Default true. |
--dry-run | bool | Validate and print the result without writing (validate_only). |
--no-wait | bool | Return the call at once instead of waiting for it to finish. |
#delete
Deletes a key and schedules every version's destruction.
NAME — the resource's name; a bare id is enough below the linked
project.
CLI
sylphx keys keys delete orgs/acme/projects/shop/envs/production/keys/key --yesDELETE https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key · scope keys:write · effect destructive · Request, response and examples
Flags
| Flag | Type | What it does |
|---|---|---|
--etag | string | Delete only if the current etag matches. |
--dry-run | bool | Validate and print the result without writing (validate_only). |
--force | bool | Also delete every child Resource; without it a parent with children fails with FAILED_PRECONDITION. |
--no-wait | bool | Return the call at once instead of waiting for it to finish. |
--yes | bool | Do not ask before this destructive call. |
#rotate
Rotates a key: adds a version and makes it primary. Older versions keep verifying and decrypting until destroyed.
NAME — the resource's name; a bare id is enough below the linked
project.
CLI
sylphx keys keys rotate orgs/acme/projects/shop/envs/production/keys/keyPOST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:rotate · scope keys:write · effect write · Request, response and examples
Flags
| Flag | Type | What it does |
|---|---|---|
--etag | string | Rotate only if the current etag matches. |
--dry-run | bool | Validate and print the result without writing (validate_only). |
--no-wait | bool | Return the call at once instead of waiting for it to finish. |
#sign
Signs data or a digest with a SIGN key. Every use is audited.
NAME — the resource's name; a bare id is enough below the linked
project.
CLI
sylphx keys keys sign orgs/acme/projects/shop/envs/production/keys/keyPOST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:sign · scope keys:sign · effect read · Request, response and examples
Flags
| Flag | Type | What it does |
|---|---|---|
--key-version | string | The version to use; default the primary version. |
--data | string | The message to sign, at most 64 KiB. Set exactly one of data and digest. |
--digest | string | The digest of the message under the algorithm's hash. |
#verify
Verifies a signature made by a SIGN key.
NAME — the resource's name; a bare id is enough below the linked
project.
CLI
sylphx keys keys verify orgs/acme/projects/shop/envs/production/keys/keyPOST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:verify · scope keys:verify · effect read · Request, response and examples
Flags
| Flag | Type | What it does |
|---|---|---|
--key-version | string | The version to use; default the primary version; the signature names none. |
--data | string | The signed message. Set exactly one of data and digest. |
--digest | string | The digest of the signed message. |
--signature | string | The signature to check. Required. |
#encrypt
Encrypts data with an ENCRYPT key.
NAME — the resource's name; a bare id is enough below the linked
project.
CLI
sylphx keys keys encrypt orgs/acme/projects/shop/envs/production/keys/keyPOST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:encrypt · scope keys:encrypt · effect read · Request, response and examples
Flags
| Flag | Type | What it does |
|---|---|---|
--plaintext | string | The plaintext, at most 64 KiB. Required. The value is never returned. |
--additional-authenticated-data | string | Data bound to the ciphertext and required again to decrypt it. |
#decrypt
Decrypts a ciphertext made by Encrypt with this key.
NAME — the resource's name; a bare id is enough below the linked
project.
CLI
sylphx keys keys decrypt orgs/acme/projects/shop/envs/production/keys/keyPOST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:decrypt · scope keys:decrypt · effect read · Request, response and examples
Flags
| Flag | Type | What it does |
|---|---|---|
--ciphertext | string | The ciphertext from Encrypt. Required. |
--additional-authenticated-data | string | The additional authenticated data given to Encrypt. |
#mac-sign
Computes a MAC of data with a MAC key.
NAME — the resource's name; a bare id is enough below the linked
project.
CLI
sylphx keys keys mac-sign orgs/acme/projects/shop/envs/production/keys/keyPOST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:macSign · scope keys:sign · effect read · Request, response and examples
Flags
| Flag | Type | What it does |
|---|---|---|
--key-version | string | The version to use; default the primary version. |
--data | string | The message, at most 64 KiB. Required. |
#mac-verify
Verifies a MAC made by a MAC key, in constant time.
NAME — the resource's name; a bare id is enough below the linked
project.
CLI
sylphx keys keys mac-verify orgs/acme/projects/shop/envs/production/keys/keyPOST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:macVerify · scope keys:verify · effect read · Request, response and examples
Flags
| Flag | Type | What it does |
|---|---|---|
--key-version | string | The version to use; default the primary version. |
--data | string | The message. Required. |
--mac | string | The MAC to check. Required. |