---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "sylphx money store_connections"
description: "The sylphx money store_connections commands of Sylphx Money: every verb, with its argument, its flags and a run line."
type: reference
product: purchases
summary: "Every sylphx money store_connections command: its argument, its flags and a run line."
updated: 2026-09-28
nav: false
---

The `store_connections` commands of Sylphx Money, as the CLI spells them: the same
calls as [the `store_connections` API page](/docs/api/store_connections), typed for the
shell. [Install, sign in and the grammar](/docs/cli) are on the CLI index.

## get

Gets a store connection.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx money store-connections get orgs/acme/projects/shop/envs/production/store_connections/store-connection
```

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/store_connections/store-connection` · scope `billing:read` · effect `read` · [Request, response and examples](/docs/api/store_connections/get)

## list

Lists store connections.

**`PARENT`** — optional: the CLI fills it from the linked project or the
key's scope when it is left out.

**CLI**

```bash
sylphx money store-connections list orgs/acme/projects/shop/envs/production
```

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/store_connections` · scope `billing:read` · effect `read` · [Request, response and examples](/docs/api/store_connections/list)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--page-size` | `int` | At most this many; default 50, clamped to 1000. |
| `--page-token` | `string` | `next_page_token` of the previous page. |
| `--filter` | `string` | AIP-160 filter over filterable fields. |

## create

Creates a store connection; its credential is sealed and never returned.

**`ID`** — The id segment of the new Resource's name; the server assigns one when omitted.

**CLI**

```bash
sylphx money store-connections create --parent orgs/acme/projects/shop/envs/production
```

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/store_connections` · scope `billing:write` · effect `write` · [Request, response and examples](/docs/api/store_connections/create)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--parent` | `string` | The parent to create in; defaults to the linked project or the key's scope. |
| `--meta.labels` | `key=value` | Caller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value. |
| `--meta.annotations` | `key=value` | Caller-writable, unindexed annotations. Repeat the flag for each value. |
| `--meta.display-name` | `string` | Caller-writable human-readable name. |
| `--spec.app-store.bundle-ids` | `string` | The apps' bundle ids. Repeat the flag for each value. |
| `--spec.app-store.issuer-id` | `string` | The App Store Connect issuer id. |
| `--spec.app-store.key-id` | `string` | The In-App Purchase key id. |
| `--spec.app-store.private-key` | `string` | The In-App Purchase key (`.p8` PEM). Write-only: sealed on write, never returned; omit it on update to keep the stored key. The value is never returned. |
| `--spec.app-store.app-apple-id` | `int` | The app's Apple id, needed to verify production notifications. |
| `--spec.app-store.account-token-prefix` | `string` | An earlier `appAccountToken` scheme the app's shipped builds use: the token is UUIDv5 in the URL namespace of this prefix followed by the subject id (for example `https://accounts.example.com/v2/`). Tokens in Money's own scheme are always accepted as well. |
| `--spec.google-play.package-names` | `string` | The apps' package names. Repeat the flag for each value. |
| `--spec.google-play.service-account-json` | `string` | The service account's JSON key. Write-only: sealed on write, never returned; omit it on update to keep the stored key. The value is never returned. |
| `--spec.google-play.notification-audience` | `string` | The audience Play's Pub/Sub push token must carry for real-time developer notifications; unset refuses them. |
| `--spec.google-play.notification-service-account` | `string` | The service account Pub/Sub pushes as. |
| `--spec.allow-sandbox` | `bool` | Accept purchases the store marks as sandbox or license-test. Off in production: a sandbox purchase is then refused. |
| `--spec.require-account-token` | `bool` | Refuse a purchase that does not carry the subject's account token (App Store `appAccountToken`, Play `obfuscatedAccountId`). |
| `--dry-run` | `bool` | Validate and print the result without writing (validate_only). |

## update

Updates a store connection; a new credential replaces the stored one.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx money store-connections update orgs/acme/projects/shop/envs/production/store_connections/store-connection
```

`PATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/store_connections/store-connection` · scope `billing:write` · effect `write` · [Request, response and examples](/docs/api/store_connections/update)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--meta.labels` | `key=value` | Caller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value. |
| `--meta.annotations` | `key=value` | Caller-writable, unindexed annotations. Repeat the flag for each value. |
| `--meta.display-name` | `string` | Caller-writable human-readable name. |
| `--spec.app-store.bundle-ids` | `string` | The apps' bundle ids. Repeat the flag for each value. |
| `--spec.app-store.issuer-id` | `string` | The App Store Connect issuer id. |
| `--spec.app-store.key-id` | `string` | The In-App Purchase key id. |
| `--spec.app-store.private-key` | `string` | The In-App Purchase key (`.p8` PEM). Write-only: sealed on write, never returned; omit it on update to keep the stored key. The value is never returned. |
| `--spec.app-store.app-apple-id` | `int` | The app's Apple id, needed to verify production notifications. |
| `--spec.app-store.account-token-prefix` | `string` | An earlier `appAccountToken` scheme the app's shipped builds use: the token is UUIDv5 in the URL namespace of this prefix followed by the subject id (for example `https://accounts.example.com/v2/`). Tokens in Money's own scheme are always accepted as well. |
| `--spec.google-play.package-names` | `string` | The apps' package names. Repeat the flag for each value. |
| `--spec.google-play.service-account-json` | `string` | The service account's JSON key. Write-only: sealed on write, never returned; omit it on update to keep the stored key. The value is never returned. |
| `--spec.google-play.notification-audience` | `string` | The audience Play's Pub/Sub push token must carry for real-time developer notifications; unset refuses them. |
| `--spec.google-play.notification-service-account` | `string` | The service account Pub/Sub pushes as. |
| `--spec.allow-sandbox` | `bool` | Accept purchases the store marks as sandbox or license-test. Off in production: a sandbox purchase is then refused. |
| `--spec.require-account-token` | `bool` | Refuse a purchase that does not carry the subject's account token (App Store `appAccountToken`, Play `obfuscatedAccountId`). |
| `--allow-missing` | `bool` | Create the store connection when it does not exist (declarative upsert). |
| `--dry-run` | `bool` | Validate and print the result without writing (validate_only). |

## delete

Deletes a store connection and its sealed credential.

**`NAME`** — the resource's name; a bare id is enough below the linked
project.

**CLI**

```bash
sylphx money store-connections delete orgs/acme/projects/shop/envs/production/store_connections/store-connection --yes
```

`DELETE https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/store_connections/store-connection` · scope `billing:write` · effect `destructive` · [Request, response and examples](/docs/api/store_connections/delete)

**Flags**

| Flag | Type | What it does |
| --- | --- | --- |
| `--etag` | `string` | The ETag the caller read; the delete fails if it changed. |
| `--yes` | `bool` | Do not ask before this destructive call. |
