---
# @generated by sylphx-gen 0.1.0 from contracts@e41a0a82ce4e85b77240402222da97d27f00a4498e6532efca0b4e93288879eb. Do not edit.
title: "sylphx secrets secret_versions"
description: "The sylphx secrets secret_versions commands of Sylphx Secrets: every verb, with its argument, its flags and a run line."
type: reference
product: platform
summary: "Every sylphx secrets secret_versions command: its argument, its flags and a run line."
updated: 2026-09-28
nav: false
---

The `secret_versions` commands of Sylphx Secrets, as the CLI spells them: the same
calls as [the `secret_versions` API page](/docs/api/secret_versions), typed for the
shell. [Install, sign in and the grammar](/docs/cli) are on the CLI index.

## get

Gets a secret version.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx secrets secret-versions get orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions/secret-version
```

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions/secret-version` · scope `secrets:read` · effect `read` · [Request, response and examples](/docs/api/secret_versions/get)

## list

Lists a secret's versions.

**`PARENT`** — optional: the CLI fills it from the linked project or the
key's scope when it is left out.

**CLI**

```bash
sylphx secrets secret-versions list orgs/acme/projects/shop/envs/production/secrets/secret
```

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions` · scope `secrets:read` · effect `read` · [Request, response and examples](/docs/api/secret_versions/list)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--page-size` | `int` | At most this many; default 50, clamped to 1000. |
| `--page-token` | `string` | `next_page_token` of the previous page. |
| `--filter` | `string` | AIP-160 filter over labels and filterable fields. |
| `--order-by` | `string` | AIP-132 ordering over filterable fields. |

## create

Adds a value to a secret as its newest version. The value is never returned.

**CLI**

```bash
sylphx secrets secret-versions create --parent orgs/acme/projects/shop/envs/production/secrets/secret --payload …
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions` · scope `secrets:write` · effect `write` · [Request, response and examples](/docs/api/secret_versions/create)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--parent` | `string` | The parent to create in; defaults to the linked project or the key's scope. |
| `--meta.labels` | `key=value` | Caller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value. |
| `--meta.annotations` | `key=value` | Caller-writable, unindexed annotations. Repeat the flag for each value. |
| `--meta.display-name` | `string` | Caller-writable human-readable name. |
| `--payload` | `string` | The value, at most 64 KiB. Write-only. Required. The value is never returned. |
| `--dry-run` | `bool` | Validate and print the result without writing (validate_only). |

## disable

Disables a secret version: bindings stop delivering it.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx secrets secret-versions disable orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions/secret-version
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions/secret-version:disable` · scope `secrets:write` · effect `write` · [Request, response and examples](/docs/api/secret_versions/disable)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--etag` | `string` | Disable only if the current etag matches. |
| `--dry-run` | `bool` | Validate and print the result without writing (validate_only). |

## enable

Enables a disabled secret version.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx secrets secret-versions enable orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions/secret-version
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions/secret-version:enable` · scope `secrets:write` · effect `write` · [Request, response and examples](/docs/api/secret_versions/enable)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--etag` | `string` | Enable only if the current etag matches. |
| `--dry-run` | `bool` | Validate and print the result without writing (validate_only). |

## destroy

Destroys a secret version's value irrecoverably.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx secrets secret-versions destroy orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions/secret-version --yes
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions/secret-version:destroy` · scope `secrets:write` · effect `destructive` · [Request, response and examples](/docs/api/secret_versions/destroy)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--etag` | `string` | Destroy only if the current etag matches. |
| `--dry-run` | `bool` | Validate and print the result without writing (validate_only). |
| `--yes` | `bool` | Do not ask before this destructive call. |

## access

Reads a secret version's value back. Break-glass: a separate permission, audited on every call, and never exposed to MCP.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx secrets secret-versions access orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions/secret-version
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret/secret_versions/secret-version:access` · scope `secrets:access` · effect `read` · [Request, response and examples](/docs/api/secret_versions/access)
