Skip to content
Console
Menu

Getting Started

Authentication

KV Store

sylphx secrets secret_versions

Every sylphx secrets secret_versions command: its argument, its flags and a run line.

The secret_versions commands of Sylphx Secrets, as the CLI spells them: the same calls as the secret_versions API page, typed for the shell. Install, sign in and the grammar are on the CLI index.

#get

Gets a secret version.

NAME — the resource's name; a bare id is enough below the linked project.

CLI

Shell
sylphx secrets secret-versions get orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions/secret-version

GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions/secret-version · scope secrets:read · effect read · Request, response and examples

#list

Lists a secret's versions.

PARENT — optional: the CLI fills it from the linked project or the key's scope when it is left out.

CLI

Shell
sylphx secrets secret-versions list orgs/acme/projects/shop/envs/production/secrets/secret

GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions · scope secrets:read · effect read · Request, response and examples

Flags

FlagTypeWhat it does
--page-sizeintAt most this many; default 50, clamped to 1000.
--page-tokenstringnext_page_token of the previous page.
--filterstringAIP-160 filter over labels and filterable fields.
--order-bystringAIP-132 ordering over filterable fields.

#create

Adds a value to a secret as its newest version. The value is never returned.

CLI

Shell
sylphx secrets secret-versions create --parent orgs/acme/projects/shop/envs/production/secrets/secret --payload …

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions · scope secrets:write · effect write · Request, response and examples

Flags

FlagTypeWhat it does
--parentstringThe parent to create in; defaults to the linked project or the key's scope.
--meta.labelskey=valueCaller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value.
--meta.annotationskey=valueCaller-writable, unindexed annotations. Repeat the flag for each value.
--meta.display-namestringCaller-writable human-readable name.
--payloadstringThe value, at most 64 KiB. Write-only. Required. The value is never returned.
--dry-runboolValidate and print the result without writing (validate_only).

#disable

Disables a secret version: bindings stop delivering it.

NAME — the resource's name; a bare id is enough below the linked project.

CLI

Shell
sylphx secrets secret-versions disable orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions/secret-version

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions/secret-version:disable · scope secrets:write · effect write · Request, response and examples

Flags

FlagTypeWhat it does
--etagstringDisable only if the current etag matches.
--dry-runboolValidate and print the result without writing (validate_only).

#enable

Enables a disabled secret version.

NAME — the resource's name; a bare id is enough below the linked project.

CLI

Shell
sylphx secrets secret-versions enable orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions/secret-version

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions/secret-version:enable · scope secrets:write · effect write · Request, response and examples

Flags

FlagTypeWhat it does
--etagstringEnable only if the current etag matches.
--dry-runboolValidate and print the result without writing (validate_only).

#destroy

Destroys a secret version's value irrecoverably.

NAME — the resource's name; a bare id is enough below the linked project.

CLI

Shell
sylphx secrets secret-versions destroy orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions/secret-version --yes

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions/secret-version:destroy · scope secrets:write · effect destructive · Request, response and examples

Flags

FlagTypeWhat it does
--etagstringDestroy only if the current etag matches.
--dry-runboolValidate and print the result without writing (validate_only).
--yesboolDo not ask before this destructive call.

#access

Reads a secret version's value back. Break-glass: a separate permission, audited on every call, and never exposed to MCP.

NAME — the resource's name; a bare id is enough below the linked project.

CLI

Shell
sylphx secrets secret-versions access orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions/secret-version

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions/secret-version:access · scope secrets:access · effect read · Request, response and examples