---
# @generated by sylphx-gen 0.1.0 from contracts@fb95f0c42a0ec5d8e3cb694c0054b529c0b24b184112c65ef60c9044b4ce61f9. Do not edit.
title: "sylphx secrets profiles"
description: "The sylphx secrets profiles commands of Sylphx Secrets: every verb, with its argument, its flags and a run line."
type: reference
product: platform
summary: "Every sylphx secrets profiles command: its argument, its flags and a run line."
updated: 2026-09-28
nav: false
---

The `profiles` commands of Sylphx Secrets, as the CLI spells them: the same
calls as [the `profiles` API page](/docs/api/profiles), typed for the
shell. [Install, sign in and the grammar](/docs/cli) are on the CLI index.

## get

Gets a profile: its kind, grants, sites and latest version; never a value.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx secrets profiles get orgs/acme/projects/shop/envs/production/profiles/profile
```

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile` · scope `secrets:read` · effect `read` · [Request, response and examples](/docs/api/profiles/get)

## list

Lists the profiles of an environment.

**`PARENT`** — optional: the CLI fills it from the linked project or the
key's scope when it is left out.

**CLI**

```bash
sylphx secrets profiles list orgs/acme/projects/shop/envs/production
```

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles` · scope `secrets:read` · effect `read` · [Request, response and examples](/docs/api/profiles/list)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--page-size` | `int` | At most this many; default 50, clamped to 1000. |
| `--page-token` | `string` | `next_page_token` of the previous page. |
| `--filter` | `string` | AIP-160 filter over labels and filterable fields. |
| `--order-by` | `string` | AIP-132 ordering over filterable fields. |

## create

Creates an empty profile; its first version is written by a write-back mount (`:open` with WRITE_BACK, then `:commit`).

**`ID`** — The id segment of the new Resource's name; the server assigns one when omitted.

**CLI**

```bash
sylphx secrets profiles create --parent orgs/acme/projects/shop/envs/production --spec.kind browser
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles` · scope `secrets:write` · effect `write` · [Request, response and examples](/docs/api/profiles/create)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--parent` | `string` | The parent to create in; defaults to the linked project or the key's scope. |
| `--meta.labels` | `key=value` | Caller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value. |
| `--meta.annotations` | `key=value` | Caller-writable, unindexed annotations. Repeat the flag for each value. |
| `--meta.display-name` | `string` | Caller-writable human-readable name. |
| `--spec.kind` | `enum` | What the profile holds. Required. One of `browser`, `computer`. |
| `--spec.grants` | `json` | Who may mount it and how. A principal with no grant cannot mount it, whatever its scopes. Repeat the flag for each value. |
| `--spec.paths` | `string` | For a `computer` profile: the paths under the sandbox's home directory its archive holds, for example `.config/app`. Repeat the flag for each value. |
| `--dry-run` | `bool` | Validate and print the result without writing (validate_only). |

## update

Updates a profile's grants or declared paths. Granting a mount is this call: nothing else adds a grant.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx secrets profiles update orgs/acme/projects/shop/envs/production/profiles/profile
```

`PATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile` · scope `secrets:write` · effect `write` · [Request, response and examples](/docs/api/profiles/update)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--meta.labels` | `key=value` | Caller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value. |
| `--meta.annotations` | `key=value` | Caller-writable, unindexed annotations. Repeat the flag for each value. |
| `--meta.display-name` | `string` | Caller-writable human-readable name. |
| `--spec.grants` | `json` | Who may mount it and how. A principal with no grant cannot mount it, whatever its scopes. Repeat the flag for each value. |
| `--spec.paths` | `string` | For a `computer` profile: the paths under the sandbox's home directory its archive holds, for example `.config/app`. Repeat the flag for each value. |
| `--dry-run` | `bool` | Validate and print the result without writing (validate_only). |

## delete

Deletes a profile; with `force`, a profile that has versions too, which destroys every version.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx secrets profiles delete orgs/acme/projects/shop/envs/production/profiles/profile --yes
```

`DELETE https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile` · scope `secrets:write` · effect `destructive` · [Request, response and examples](/docs/api/profiles/delete)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--etag` | `string` | Delete only if the current etag matches. |
| `--dry-run` | `bool` | Validate and print the result without writing (validate_only). |
| `--force` | `bool` | Also destroy every version; without it a profile with versions fails with INVALID_STATE. |
| `--yes` | `bool` | Do not ask before this destructive call. |

## open

Mounts a profile for one session: returns the state of one version and, for WRITE_BACK, an attachment that `:commit` writes through until it expires. Every call is audited with the caller's context; the caller's principal needs a grant of at least the requested mode.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx secrets profiles open orgs/acme/projects/shop/envs/production/profiles/profile
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile:open` · scope `secrets:mount` · effect `read` · [Request, response and examples](/docs/api/profiles/open)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--mode` | `enum` | READ_ONLY (the default) or WRITE_BACK. One of `read_only`, `write_back`. |
| `--version` | `string` | A version to mount; unset mounts the latest. |
| `--ttl` | `duration` | How long a WRITE_BACK attachment may commit; default 1 hour, at most 12 hours. A lost session cannot write back after it. |
| `--context` | `key=value` | Who mounts it, for the audit trail: for example `run`, `step`, `member`. At most 16 entries; keys and values are names, never values. Repeat the flag for each value. |

## commit

Writes a mounted profile back as a new version, by compare-and-set on the version the attachment was opened at (or last committed). When another write landed first, nothing is lost: the result is still a new version, merged site by site with the newer write winning, and marked as a conflict.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx secrets profiles commit orgs/acme/projects/shop/envs/production/profiles/profile
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile:commit` · scope `secrets:mount` · effect `write` · [Request, response and examples](/docs/api/profiles/commit)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--attachment` | `string` | The `attachment` OpenProfile returned with WRITE_BACK. Required. |
| `--state` | `string` | The whole state to write, in the profile kind's form, at most 2 MiB. Required. The value is never returned. |
