---
# @generated by sylphx-gen 0.1.0 from contracts@6379e2ed0c2c839edc65cd078b67e8715a815f5043e4d2072f51960b06a81660. Do not edit.
title: "sylphx keys keys"
description: "The sylphx keys keys commands of Sylphx Keys: every verb, with its argument, its flags and a run line."
type: reference
product: platform
summary: "Every sylphx keys keys command: its argument, its flags and a run line."
updated: 2026-09-28
nav: false
---

The `keys` commands of Sylphx Keys, as the CLI spells them: the same
calls as [the `keys` API page](/docs/api/keys), typed for the
shell. [Install, sign in and the grammar](/docs/cli) are on the CLI index.

## get

Gets a key.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx keys keys get orgs/acme/projects/shop/envs/production/keys/key
```

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key` · scope `keys:read` · effect `read` · [Request, response and examples](/docs/api/keys/get)

## list

Lists keys in an environment.

**`PARENT`** — optional: the CLI fills it from the linked project or the
key's scope when it is left out.

**CLI**

```bash
sylphx keys keys list orgs/acme/projects/shop/envs/production
```

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys` · scope `keys:read` · effect `read` · [Request, response and examples](/docs/api/keys/list)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--page-size` | `int` | At most this many; default 50, clamped to 1000. |
| `--page-token` | `string` | `next_page_token` of the previous page. |
| `--filter` | `string` | AIP-160 filter over labels and filterable fields. |
| `--order-by` | `string` | AIP-132 ordering over filterable fields. |

## create

Creates a key; the signer generates its first version.

**`ID`** — The id segment of the new Resource's name; the server assigns one when omitted.

**CLI**

```bash
sylphx keys keys create --parent orgs/acme/projects/shop/envs/production --spec.purpose sign --spec.algorithm ed25519
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys` · scope `keys:write` · effect `write` · [Request, response and examples](/docs/api/keys/create)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--parent` | `string` | The parent to create in; defaults to the linked project or the key's scope. |
| `--meta.labels` | `key=value` | Caller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value. |
| `--meta.annotations` | `key=value` | Caller-writable, unindexed annotations. Repeat the flag for each value. |
| `--meta.display-name` | `string` | Caller-writable human-readable name. |
| `--spec.purpose` | `enum` | What the key does. Required. One of `sign`, `encrypt`, `mac`. |
| `--spec.algorithm` | `enum` | The algorithm; it must suit the purpose. Required. One of `ed25519`, `ec_p256_sha256`, `rsa_pkcs1_2048_sha256`, `rsa_pss_3072_sha256`, `aes_256_gcm`, `hmac_sha256`. |
| `--spec.rotation-period` | `duration` | Rotate automatically this often; unset means rotate only on request. |
| `--spec.deletion-protection` | `bool` | While true, Delete fails with DELETION_PROTECTED. Default true. |
| `--dry-run` | `bool` | Validate and print the result without writing (validate_only). |
| `--no-wait` | `bool` | Return the call at once instead of waiting for it to finish. |

## update

Updates a key's rotation period, deletion protection, or metadata.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx keys keys update orgs/acme/projects/shop/envs/production/keys/key
```

`PATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key` · scope `keys:write` · effect `write` · [Request, response and examples](/docs/api/keys/update)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--meta.labels` | `key=value` | Caller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value. |
| `--meta.annotations` | `key=value` | Caller-writable, unindexed annotations. Repeat the flag for each value. |
| `--meta.display-name` | `string` | Caller-writable human-readable name. |
| `--spec.rotation-period` | `duration` | Rotate automatically this often; unset means rotate only on request. |
| `--spec.deletion-protection` | `bool` | While true, Delete fails with DELETION_PROTECTED. Default true. |
| `--dry-run` | `bool` | Validate and print the result without writing (validate_only). |
| `--no-wait` | `bool` | Return the call at once instead of waiting for it to finish. |

## delete

Deletes a key and schedules every version's destruction.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx keys keys delete orgs/acme/projects/shop/envs/production/keys/key --yes
```

`DELETE https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key` · scope `keys:write` · effect `destructive` · [Request, response and examples](/docs/api/keys/delete)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--etag` | `string` | Delete only if the current etag matches. |
| `--dry-run` | `bool` | Validate and print the result without writing (validate_only). |
| `--force` | `bool` | Also delete every child Resource; without it a parent with children fails with FAILED_PRECONDITION. |
| `--no-wait` | `bool` | Return the call at once instead of waiting for it to finish. |
| `--yes` | `bool` | Do not ask before this destructive call. |

## rotate

Rotates a key: adds a version and makes it primary. Older versions keep verifying and decrypting until destroyed.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx keys keys rotate orgs/acme/projects/shop/envs/production/keys/key
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:rotate` · scope `keys:write` · effect `write` · [Request, response and examples](/docs/api/keys/rotate)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--etag` | `string` | Rotate only if the current etag matches. |
| `--dry-run` | `bool` | Validate and print the result without writing (validate_only). |
| `--no-wait` | `bool` | Return the call at once instead of waiting for it to finish. |

## sign

Signs data or a digest with a SIGN key. Every use is audited.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx keys keys sign orgs/acme/projects/shop/envs/production/keys/key
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:sign` · scope `keys:sign` · effect `read` · [Request, response and examples](/docs/api/keys/sign)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--key-version` | `string` | The version to use; default the primary version. |
| `--data` | `string` | The message to sign, at most 64 KiB. Set exactly one of `data` and `digest`. |
| `--digest` | `string` | The digest of the message under the algorithm's hash. |

## verify

Verifies a signature made by a SIGN key.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx keys keys verify orgs/acme/projects/shop/envs/production/keys/key
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:verify` · scope `keys:verify` · effect `read` · [Request, response and examples](/docs/api/keys/verify)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--key-version` | `string` | The version to use; default the primary version; the signature names none. |
| `--data` | `string` | The signed message. Set exactly one of `data` and `digest`. |
| `--digest` | `string` | The digest of the signed message. |
| `--signature` | `string` | The signature to check. Required. |

## encrypt

Encrypts data with an ENCRYPT key.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx keys keys encrypt orgs/acme/projects/shop/envs/production/keys/key
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:encrypt` · scope `keys:encrypt` · effect `read` · [Request, response and examples](/docs/api/keys/encrypt)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--plaintext` | `string` | The plaintext, at most 64 KiB. Required. The value is never returned. |
| `--additional-authenticated-data` | `string` | Data bound to the ciphertext and required again to decrypt it. |

## decrypt

Decrypts a ciphertext made by Encrypt with this key.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx keys keys decrypt orgs/acme/projects/shop/envs/production/keys/key
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:decrypt` · scope `keys:decrypt` · effect `read` · [Request, response and examples](/docs/api/keys/decrypt)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--ciphertext` | `string` | The ciphertext from Encrypt. Required. |
| `--additional-authenticated-data` | `string` | The additional authenticated data given to Encrypt. |

## mac-sign

Computes a MAC of data with a MAC key.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx keys keys mac-sign orgs/acme/projects/shop/envs/production/keys/key
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:macSign` · scope `keys:sign` · effect `read` · [Request, response and examples](/docs/api/keys/mac_sign)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--key-version` | `string` | The version to use; default the primary version. |
| `--data` | `string` | The message, at most 64 KiB. Required. |

## mac-verify

Verifies a MAC made by a MAC key, in constant time.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx keys keys mac-verify orgs/acme/projects/shop/envs/production/keys/key
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key:macVerify` · scope `keys:verify` · effect `read` · [Request, response and examples](/docs/api/keys/mac_verify)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--key-version` | `string` | The version to use; default the primary version. |
| `--data` | `string` | The message. Required. |
| `--mac` | `string` | The MAC to check. Required. |
