# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Account Management Idp API version: 1.0.0 extends: openapi/acronis-idp-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 10 - target: $.paths['/idp/token'].post update: x-apievangelist-phrasing: intent: Get an access token effect: write questions: - How do I get an access token for the Acronis API with my client credentials? - Can I exchange a refresh token for a new access token? - Which grant types does the token endpoint support? instructions: - text: Request an access token using grant type {grant_type} for client {client_id}. slots: grant_type: requestBody.grant_type client_id: requestBody.client_id - text: Refresh my access token with refresh token {refresh_token}. slots: refresh_token: requestBody.refresh_token - text: Log in as {username} with the password grant and get tokens. slots: username: requestBody.username method: generated generated: '2026-09-26' - target: $.paths['/idp/revoke_token'].post update: x-apievangelist-phrasing: intent: Revoke an access or refresh token effect: destructive questions: - How do I revoke a token so it can no longer be used? - Does revoking an access token also kill its refresh token? instructions: - text: Revoke token {token}. slots: token: requestBody.token - text: Invalidate refresh token {token} with hint {token_type_hint}. slots: token: requestBody.token token_type_hint: requestBody.token_type_hint method: generated generated: '2026-09-26' - target: $.paths['/idp/introspect_token'].post update: x-apievangelist-phrasing: intent: Check whether a token is active effect: read questions: - How can I tell if an access token is still valid? - What scopes and expiry does a given token carry? instructions: - text: Introspect token {token}. slots: token: requestBody.token - text: Check if access token {token} is still active. slots: token: requestBody.token method: generated generated: '2026-09-26' - target: $.paths['/idp/ott'].post update: x-apievangelist-phrasing: intent: Issue a one-time login token for a user effect: write questions: - How do I sign a user into the console from my own portal without their password? - Can I request a one-time token using a user's external ID? instructions: - text: Issue a one-time token for user {login} for purpose {purpose}. slots: login: requestBody.login purpose: requestBody.purpose - text: Create a one-time login token for user {user_id} with purpose {purpose}. slots: user_id: requestBody.user_id purpose: requestBody.purpose method: generated generated: '2026-09-26' - target: $.paths['/idp/ott/login'].post update: x-apievangelist-phrasing: intent: Log in with a one-time token effect: write questions: - How do I exchange a one-time token for a platform session cookie? - Can I authenticate to the platform with a one-time token over the API? instructions: - text: Log in with one-time token {ott}. slots: ott: requestBody.ott - text: Start a session using OTT {ott}. slots: ott: requestBody.ott method: generated generated: '2026-09-26' - target: $.paths['/idp/logout'].get update: x-apievangelist-phrasing: intent: Log out of the platform effect: write questions: - How do I end my current platform session? - Is there an endpoint that signs me out? instructions: - text: Log me out of the platform. - text: End my current IdP session. method: generated generated: '2026-09-26' - target: $.paths['/idp/device_authorization'].post update: x-apievangelist-phrasing: intent: Start a device authorization request effect: write questions: - How does a headless device get a user code so someone can sign it in? - Can I give the device a display name when requesting its codes? instructions: - text: Request device and user codes for client {client_id} with scope {scope}. slots: client_id: requestBody.client_id scope: requestBody.scope - text: Register device {display_name} for client {client_id} and issue its codes with scope {scope}. slots: display_name: requestBody.display_name client_id: requestBody.client_id scope: requestBody.scope method: generated generated: '2026-10-01' - target: $.paths['/idp/device_authorization/approval'].get update: x-apievangelist-phrasing: intent: Look up a pending device authorization effect: read questions: - What device is asking for authorization with this user code? - Can I check a device code before approving it? instructions: - text: Show the device authorization for user code {code}. slots: code: query.code - text: Look up pending device code {code} for tenant {tenant_uuid}. slots: code: query.code tenant_uuid: query.tenant_uuid method: generated generated: '2026-09-26' - target: $.paths['/idp/device_authorization/approval'].post update: x-apievangelist-phrasing: intent: Approve a device authorization code effect: write questions: - How do I approve a device that is waiting to sign in with a user code? - Who is allowed to approve a device code for another tenant? instructions: - text: Approve device code {code}. slots: code: requestBody.code - text: Approve user code {code} for tenant {tenant_uuid}. slots: code: requestBody.code tenant_uuid: requestBody.tenant_uuid method: generated generated: '2026-09-26' - target: $.paths['/idp/external-login'].get update: x-apievangelist-phrasing: intent: Get the one-time token external login page effect: read questions: - Which page handles external logins with a one-time token and redirects the user? - Can I send a user to a target URL after they log in with a one-time token? instructions: - text: Open the external login page with token {ott} and redirect to {targetURI}. slots: ott: query.ott targetURI: query.targetURI - text: Fetch the one-time token login page. method: generated generated: '2026-09-26'