# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Auth0 Management Keys API version: 1.0.0 extends: openapi/auth0-keys-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 14 - target: $.paths['/keys/custom-signing'].get update: x-apievangelist-phrasing: intent: Get the custom signing keys JWKS effect: read questions: - What custom signing keys have I uploaded to my tenant? - Can I see the full JWKS of my bring-your-own signing keys? instructions: - text: Show me my custom signing keys JWKS. - text: Fetch the public keys I uploaded for custom token signing. method: generated generated: '2026-10-01' - target: $.paths['/keys/custom-signing'].put update: x-apievangelist-phrasing: intent: Create or replace the custom signing keys JWKS effect: write questions: - How do I upload my own public keys for custom token signing? - Does setting custom signing keys replace the whole existing set? instructions: - text: Replace my custom signing keys with {keys}. slots: keys: requestBody.keys - text: 'Upload this JWKS key set as my custom signing keys: {keys}.' slots: keys: requestBody.keys method: generated generated: '2026-10-01' - target: $.paths['/keys/custom-signing'].delete update: x-apievangelist-phrasing: intent: Delete all custom signing keys effect: destructive questions: - How do I remove every custom signing key I uploaded? - Can I clear out my bring-your-own signing key set entirely? instructions: - text: Delete my custom signing keys. - text: Remove the whole custom signing JWKS from the tenant. method: generated generated: '2026-10-01' - target: $.paths['/keys/encryption'].get update: x-apievangelist-phrasing: intent: List the tenant's encryption keys effect: read questions: - Which encryption keys does my tenant currently hold? - Can I get a total count of encryption keys when listing them? instructions: - text: List all encryption keys in my tenant. - text: Show page {page} of encryption keys with totals included. slots: page: query.page method: generated generated: '2026-10-01' - target: $.paths['/keys/encryption'].post update: x-apievangelist-phrasing: intent: Create a pre-activated encryption key effect: write questions: - How do I start bringing my own encryption key to my tenant? - What key type do I need to specify when creating a new encryption key? instructions: - text: Create a new encryption key of type {type}. slots: type: requestBody.type - text: Set up a pre-activated {type} encryption key without key material. slots: type: requestBody.type method: generated generated: '2026-10-01' - target: $.paths['/keys/encryption/rekey'].post update: x-apievangelist-phrasing: intent: Rekey the encryption key hierarchy effect: write questions: - How do I rotate the whole encryption key hierarchy? - Is there a single call to rekey my tenant's encryption keys? instructions: - text: Rekey my tenant's encryption key hierarchy. - text: Run a rekey operation on all encryption keys. method: generated generated: '2026-10-01' - target: $.paths['/keys/encryption/{kid}'].get update: x-apievangelist-phrasing: intent: Get one encryption key by key ID effect: read questions: - What is the state and type of a specific encryption key? - Can I look up an encryption key by its kid? instructions: - text: Show me encryption key {kid}. slots: kid: path.kid - text: Check the state of encryption key {kid}. slots: kid: path.kid method: generated generated: '2026-10-01' - target: $.paths['/keys/encryption/{kid}'].post update: x-apievangelist-phrasing: intent: Import wrapped key material and activate a key effect: write questions: - How do I import my own wrapped encryption key material? - What activates a pre-created encryption key? instructions: - text: Import wrapped key {wrapped_key} into encryption key {kid}. slots: wrapped_key: requestBody.wrapped_key kid: path.kid - text: Activate encryption key {kid} with my wrapped key material {wrapped_key}. slots: kid: path.kid wrapped_key: requestBody.wrapped_key method: generated generated: '2026-10-01' - target: $.paths['/keys/encryption/{kid}'].delete update: x-apievangelist-phrasing: intent: Delete a customer-provided encryption key effect: destructive questions: - How do I go back to native encryption after bringing my own key? - What happens when I delete a custom encryption key? instructions: - text: Delete encryption key {kid}. slots: kid: path.kid - text: Remove my custom key {kid} and revert to the native encryption key. slots: kid: path.kid method: generated generated: '2026-10-01' - target: $.paths['/keys/encryption/{kid}/wrapping-key'].post update: x-apievangelist-phrasing: intent: Create a public wrapping key for key import effect: write questions: - Where do I get a public key to wrap my encryption key material before import? - Is a wrapping key needed before importing my own encryption key? instructions: - text: Create a public wrapping key for encryption key {kid}. slots: kid: path.kid - text: Generate the wrapping key I need to wrap material for {kid}. slots: kid: path.kid method: generated generated: '2026-10-01' - target: $.paths['/keys/signing'].get update: x-apievangelist-phrasing: intent: List application signing keys effect: read questions: - Which application signing keys are current, next and previous in my tenant? - Can I see all the keys used to sign tokens for my applications? instructions: - text: List all application signing keys. - text: Show me the current and next token signing keys. method: generated generated: '2026-10-01' - target: $.paths['/keys/signing/rotate'].post update: x-apievangelist-phrasing: intent: Rotate the application signing key effect: write questions: - How do I rotate the key that signs my tenant's tokens? - Can I promote the next signing key to current in one step? instructions: - text: Rotate my application signing key. - text: Roll the tenant's token signing key now. method: generated generated: '2026-10-01' - target: $.paths['/keys/signing/{kid}'].get update: x-apievangelist-phrasing: intent: Get one application signing key by key ID effect: read questions: - What is the certificate and status of a specific signing key? - Can I fetch a signing key by its kid to check if it's revoked? instructions: - text: Show me signing key {kid}. slots: kid: path.kid - text: Check whether signing key {kid} has been revoked. slots: kid: path.kid method: generated generated: '2026-10-01' - target: $.paths['/keys/signing/{kid}/revoke'].put update: x-apievangelist-phrasing: intent: Revoke an application signing key effect: destructive questions: - How do I revoke a signing key I think was compromised? - Can a previous signing key be revoked by its key ID? instructions: - text: Revoke signing key {kid}. slots: kid: path.kid - text: Invalidate the compromised application signing key {kid}. slots: kid: path.kid method: generated generated: '2026-10-01'