# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for authentik Core API version: 1.0.0 extends: openapi/authentik-core-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 78 - target: $.paths['/core/application_entitlements/'].get update: x-apievangelist-phrasing: intent: List application entitlements effect: read questions: - Which entitlements are defined for my applications in authentik? - Can I filter entitlements to a single application? instructions: - text: List all application entitlements. - text: Show entitlements defined for application {app}. slots: app: query.app method: generated generated: '2026-09-26' - target: $.paths['/core/application_entitlements/'].post update: x-apievangelist-phrasing: intent: Create an application entitlement effect: write questions: - How do I define a new entitlement that users of an application can be granted? - Can I attach custom attributes to a new entitlement? instructions: - text: Create entitlement {name} for application {app}. slots: name: requestBody.name app: requestBody.app - text: Add a new entitlement {name} on app {app} with attributes {attributes}. slots: name: requestBody.name app: requestBody.app attributes: requestBody.attributes method: generated generated: '2026-09-26' - target: $.paths['/core/application_entitlements/{pbm_uuid}/'].get update: x-apievangelist-phrasing: intent: Get an application entitlement effect: read questions: - What attributes does a specific entitlement carry? - Which application does a given entitlement belong to? instructions: - text: Get entitlement {pbm_uuid}. slots: pbm_uuid: path.pbm_uuid - text: Show the name, app and attributes of entitlement {pbm_uuid}. slots: pbm_uuid: path.pbm_uuid method: generated generated: '2026-09-26' - target: $.paths['/core/application_entitlements/{pbm_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace an application entitlement effect: write questions: - Can I fully overwrite an existing entitlement's name and application? - What must I resend to replace an entitlement completely? instructions: - text: Replace entitlement {pbm_uuid} with name {name} on app {app}. slots: pbm_uuid: path.pbm_uuid name: requestBody.name app: requestBody.app - text: Overwrite entitlement {pbm_uuid} so it is {name} for application {app}. slots: pbm_uuid: path.pbm_uuid name: requestBody.name app: requestBody.app method: generated generated: '2026-09-26' - target: $.paths['/core/application_entitlements/{pbm_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete an application entitlement effect: destructive questions: - Can I remove an entitlement that is no longer needed? - What permanently deletes an application entitlement? instructions: - text: Delete entitlement {pbm_uuid}. slots: pbm_uuid: path.pbm_uuid - text: Remove application entitlement {pbm_uuid} permanently. slots: pbm_uuid: path.pbm_uuid method: generated generated: '2026-09-26' - target: $.paths['/core/application_entitlements/{pbm_uuid}/'].patch update: x-apievangelist-phrasing: intent: Edit fields on an entitlement effect: write questions: - Can I rename an entitlement without resending its application? - Is it possible to change only an entitlement's attributes? instructions: - text: Rename entitlement {pbm_uuid} to {name}. slots: pbm_uuid: path.pbm_uuid name: requestBody.name - text: Set only the attributes of entitlement {pbm_uuid} to {attributes}. slots: pbm_uuid: path.pbm_uuid attributes: requestBody.attributes method: generated generated: '2026-09-26' - target: $.paths['/core/application_entitlements/{pbm_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses an entitlement effect: read questions: - Which objects depend on a given entitlement before I delete it? - Is an entitlement still referenced by any policy binding? instructions: - text: List everything that uses entitlement {pbm_uuid}. slots: pbm_uuid: path.pbm_uuid - text: Show objects referencing entitlement {pbm_uuid}. slots: pbm_uuid: path.pbm_uuid method: generated generated: '2026-09-26' - target: $.paths['/core/application_entitlements/requestable/'].get update: x-apievangelist-phrasing: intent: List entitlements I can request effect: read questions: - Which entitlements am I allowed to request access to? - Can I see requestable entitlements for just one application? instructions: - text: List the entitlements the current user can request. - text: Show requestable entitlements for application {app}. slots: app: query.app method: generated generated: '2026-09-26' - target: $.paths['/core/applications/'].get update: x-apievangelist-phrasing: intent: List applications effect: read questions: - What applications are configured in my authentik instance? - Can I list only applications that have a launch URL, or those a particular user can access? instructions: - text: List applications in group {group}. slots: group: query.group - text: Show the applications user {for_user} has access to. slots: for_user: query.for_user - text: Search applications for {search}. slots: search: query.search method: generated generated: '2026-09-26' - target: $.paths['/core/applications/'].post update: x-apievangelist-phrasing: intent: Create an application effect: write questions: - How do I register a new application in authentik? - Can I link a provider and a launch URL when creating an application? instructions: - text: Create application {name} with slug {slug}. slots: name: requestBody.name slug: requestBody.slug - text: Create application {name} ({slug}) using provider {provider} and launch URL {meta_launch_url}. slots: name: requestBody.name slug: requestBody.slug provider: requestBody.provider meta_launch_url: requestBody.meta_launch_url method: generated generated: '2026-09-26' - target: $.paths['/core/applications/{slug}/'].get update: x-apievangelist-phrasing: intent: Get an application effect: read questions: - Which provider is attached to a given application? - What launch URL and publisher does an application show? instructions: - text: Get application {slug}. slots: slug: path.slug - text: Show the provider and metadata for application {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/core/applications/{slug}/'].put update: x-apievangelist-phrasing: intent: Replace an application effect: write questions: - Can I overwrite an application's whole configuration in one call? - What happens to unset fields when I replace an application entirely? instructions: - text: Replace application {slug} with name {name} and new slug {new_slug}. slots: slug: path.slug name: requestBody.name new_slug: requestBody.slug - text: Overwrite application {slug} as {name}, bound to provider {provider}. slots: slug: path.slug name: requestBody.name provider: requestBody.provider method: generated generated: '2026-09-26' - target: $.paths['/core/applications/{slug}/'].delete update: x-apievangelist-phrasing: intent: Delete an application effect: destructive questions: - Can I remove an application from authentik for good? - What deletes an application I retired? instructions: - text: Delete application {slug}. slots: slug: path.slug - text: Remove application {slug} permanently. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/core/applications/{slug}/'].patch update: x-apievangelist-phrasing: intent: Edit fields on an application effect: write questions: - Can I hide an application from the user library without changing anything else? - Is it possible to change just an application's icon or description? instructions: - text: Set meta-hide to {meta_hide} on application {slug}. slots: meta_hide: requestBody.meta_hide slug: path.slug - text: Change only the launch URL of application {slug} to {meta_launch_url}. slots: slug: path.slug meta_launch_url: requestBody.meta_launch_url - text: Update the description of application {slug} to {meta_description}. slots: slug: path.slug meta_description: requestBody.meta_description method: generated generated: '2026-09-26' - target: $.paths['/core/applications/{slug}/check_access/'].get update: x-apievangelist-phrasing: intent: Check access to an application effect: read questions: - Does a specific user pass the policies to open an application? - Why is someone being denied access to an app? instructions: - text: Check whether user {for_user} can access application {slug}. slots: for_user: query.for_user slug: path.slug - text: Test my own access to application {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/core/applications/{slug}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses an application effect: read questions: - Which objects reference an application before I delete it? - Is an application still used by any brand or binding? instructions: - text: List everything that uses application {slug}. slots: slug: path.slug - text: Show objects that depend on application {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/core/applications/requestable/'].get update: x-apievangelist-phrasing: intent: List applications I can request effect: read questions: - Which applications can I ask to be given access to? - Can I search requestable applications by name? instructions: - text: List the applications the current user can request access to. - text: Find requestable applications named {name}. slots: name: query.name method: generated generated: '2026-09-26' - target: $.paths['/core/authenticated_sessions/'].get update: x-apievangelist-phrasing: intent: List signed-in sessions effect: read questions: - Who is currently logged in to authentik, and from where? - Can I find sessions by a user's username or last IP address? instructions: - text: List active sessions for user {username}. slots: username: query.user__username - text: Show sessions last seen from IP {ip}. slots: ip: query.session__last_ip method: generated generated: '2026-09-26' - target: $.paths['/core/authenticated_sessions/{uuid}/'].get update: x-apievangelist-phrasing: intent: Get a signed-in session effect: read questions: - What device and IP is a specific session coming from? - Can I inspect one authenticated session by its id? instructions: - text: Get session {uuid}. slots: uuid: path.uuid - text: Show the user agent and last IP of session {uuid}. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/core/authenticated_sessions/{uuid}/'].delete update: x-apievangelist-phrasing: intent: Revoke a session effect: destructive questions: - Can I log out one specific session remotely? - What ends a single suspicious login session? instructions: - text: Revoke session {uuid}. slots: uuid: path.uuid - text: Sign out the single session {uuid}. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/core/authenticated_sessions/{uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a session effect: read questions: - Which objects reference a given authenticated session? - Does anything depend on a session before I revoke it? instructions: - text: List objects that use session {uuid}. slots: uuid: path.uuid - text: Show what references authenticated session {uuid}. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/core/authenticated_sessions/bulk_delete/'].delete update: x-apievangelist-phrasing: intent: Revoke all sessions for several users effect: destructive questions: - Can I force-logout several users at once? - Is there a way to kill every session belonging to a list of users? instructions: - text: Revoke all sessions for users {user_pks}. slots: user_pks: query.user_pks - text: Log out every session of the users with ids {user_pks}. slots: user_pks: query.user_pks method: generated generated: '2026-09-26' - target: $.paths['/core/brands/'].get update: x-apievangelist-phrasing: intent: List brands effect: read questions: - Which brands are configured, and which domain does each serve? - Can I find the default brand or brands using a given authentication flow? instructions: - text: List all brands. - text: Find the brand for domain {domain}. slots: domain: query.domain method: generated generated: '2026-09-26' - target: $.paths['/core/brands/'].post update: x-apievangelist-phrasing: intent: Create a brand effect: write questions: - How do I add a new brand for another domain with its own logo and title? - Can I assign custom flows and a web certificate when creating a brand? instructions: - text: Create a brand for domain {domain}. slots: domain: requestBody.domain - text: Create a brand on {domain} titled {branding_title} with logo {branding_logo}. slots: domain: requestBody.domain branding_title: requestBody.branding_title branding_logo: requestBody.branding_logo method: generated generated: '2026-09-26' - target: $.paths['/core/brands/{brand_uuid}/'].get update: x-apievangelist-phrasing: intent: Get a brand effect: read questions: - Which flows and certificate does a particular brand use? - What logo and title is set on a brand? instructions: - text: Get brand {brand_uuid}. slots: brand_uuid: path.brand_uuid - text: Show the branding and flows of brand {brand_uuid}. slots: brand_uuid: path.brand_uuid method: generated generated: '2026-09-26' - target: $.paths['/core/brands/{brand_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace a brand effect: write questions: - Can I overwrite a brand's entire configuration at once? - What happens to flows I leave out when replacing a brand? instructions: - text: Replace brand {brand_uuid} with domain {domain}. slots: brand_uuid: path.brand_uuid domain: requestBody.domain - text: Overwrite brand {brand_uuid} on {domain} with title {branding_title}. slots: brand_uuid: path.brand_uuid domain: requestBody.domain branding_title: requestBody.branding_title method: generated generated: '2026-09-26' - target: $.paths['/core/brands/{brand_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a brand effect: destructive questions: - Can I remove a brand I no longer serve? - What deletes a brand permanently? instructions: - text: Delete brand {brand_uuid}. slots: brand_uuid: path.brand_uuid - text: Remove brand {brand_uuid} for good. slots: brand_uuid: path.brand_uuid method: generated generated: '2026-09-26' - target: $.paths['/core/brands/{brand_uuid}/'].patch update: x-apievangelist-phrasing: intent: Edit fields on a brand effect: write questions: - Can I change just a brand's favicon or custom CSS? - Is it possible to swap only the recovery flow on a brand? instructions: - text: Set the custom CSS of brand {brand_uuid} to {branding_custom_css}. slots: brand_uuid: path.brand_uuid branding_custom_css: requestBody.branding_custom_css - text: Change only the recovery flow on brand {brand_uuid} to {flow_recovery}. slots: brand_uuid: path.brand_uuid flow_recovery: requestBody.flow_recovery - text: Update the favicon of brand {brand_uuid} to {branding_favicon}. slots: brand_uuid: path.brand_uuid branding_favicon: requestBody.branding_favicon method: generated generated: '2026-09-26' - target: $.paths['/core/brands/{brand_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a brand effect: read questions: - Which objects reference a brand before I delete it? - Is a brand still in use anywhere? instructions: - text: List everything that uses brand {brand_uuid}. slots: brand_uuid: path.brand_uuid - text: Show objects depending on brand {brand_uuid}. slots: brand_uuid: path.brand_uuid method: generated generated: '2026-09-26' - target: $.paths['/core/brands/current/'].get update: x-apievangelist-phrasing: intent: Get the brand for the current request effect: read questions: - Which brand is being served for the domain I'm on right now? - What title and logo apply to the current request? instructions: - text: Get the current brand. - text: Show the brand that applies to this request's domain. method: generated generated: '2026-09-26' - target: $.paths['/core/groups/'].get update: x-apievangelist-phrasing: intent: List groups effect: read questions: - What groups exist in authentik, and who belongs to them? - Can I find the groups a particular username is a member of? instructions: - text: List groups that include member {username}. slots: username: query.members_by_username - text: Search groups for {search}, including their users. slots: search: query.search - text: Show superuser groups only, is-superuser = {is_superuser}. slots: is_superuser: query.is_superuser method: generated generated: '2026-09-26' - target: $.paths['/core/groups/'].post update: x-apievangelist-phrasing: intent: Create a group effect: write questions: - How do I create a new group and put users in it? - Can a new group inherit from parent groups or get roles assigned? instructions: - text: Create group {name}. slots: name: requestBody.name - text: Create group {name} with members {users} under parents {parents}. slots: name: requestBody.name users: requestBody.users parents: requestBody.parents method: generated generated: '2026-09-26' - target: $.paths['/core/groups/{group_uuid}/'].get update: x-apievangelist-phrasing: intent: Get a group effect: read questions: - Who are the members of a specific group? - Can I see a group's parents, children and inherited roles? instructions: - text: Get group {group_uuid}. slots: group_uuid: path.group_uuid - text: Show group {group_uuid} with its users and inherited roles. slots: group_uuid: path.group_uuid method: generated generated: '2026-09-26' - target: $.paths['/core/groups/{group_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace a group effect: write questions: - Can I overwrite a group's whole definition, member list included? - What must I send to fully replace a group? instructions: - text: Replace group {group_uuid} with name {name}. slots: group_uuid: path.group_uuid name: requestBody.name - text: Overwrite group {group_uuid} as {name} with exactly members {users}. slots: group_uuid: path.group_uuid name: requestBody.name users: requestBody.users method: generated generated: '2026-09-26' - target: $.paths['/core/groups/{group_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a group effect: destructive questions: - Can I remove a group entirely? - What deletes a group I no longer need? instructions: - text: Delete group {group_uuid}. slots: group_uuid: path.group_uuid - text: Remove group {group_uuid} permanently. slots: group_uuid: path.group_uuid method: generated generated: '2026-09-26' - target: $.paths['/core/groups/{group_uuid}/'].patch update: x-apievangelist-phrasing: intent: Edit fields on a group effect: write questions: - Can I rename a group without touching its members? - Is it possible to grant a group superuser status on its own? instructions: - text: Rename group {group_uuid} to {name}. slots: group_uuid: path.group_uuid name: requestBody.name - text: Set is-superuser to {is_superuser} on group {group_uuid}. slots: is_superuser: requestBody.is_superuser group_uuid: path.group_uuid - text: Change only the roles of group {group_uuid} to {roles}. slots: group_uuid: path.group_uuid roles: requestBody.roles method: generated generated: '2026-09-26' - target: $.paths['/core/groups/{group_uuid}/add_user/'].post update: x-apievangelist-phrasing: intent: Add a user to a group effect: write questions: - How do I add one person to an existing group? - Can I add a single member without rewriting the group's user list? instructions: - text: Add user {pk} to group {group_uuid}. slots: pk: requestBody.pk group_uuid: path.group_uuid - text: Put user id {pk} into group {group_uuid}. slots: pk: requestBody.pk group_uuid: path.group_uuid method: generated generated: '2026-09-26' - target: $.paths['/core/groups/{group_uuid}/remove_user/'].post update: x-apievangelist-phrasing: intent: Remove a user from a group effect: write questions: - Can I take one member out of a group? - What removes a single user from a group without deleting the user? instructions: - text: Remove user {pk} from group {group_uuid}. slots: pk: requestBody.pk group_uuid: path.group_uuid - text: Drop user id {pk} out of group {group_uuid}. slots: pk: requestBody.pk group_uuid: path.group_uuid method: generated generated: '2026-09-26' - target: $.paths['/core/groups/{group_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a group effect: read questions: - Which policies or bindings reference a group? - Is a group still used anywhere before I delete it? instructions: - text: List everything that uses group {group_uuid}. slots: group_uuid: path.group_uuid - text: Show objects that depend on group {group_uuid}. slots: group_uuid: path.group_uuid method: generated generated: '2026-09-26' - target: $.paths['/core/object_attributes/'].get update: x-apievangelist-phrasing: intent: List custom object attributes effect: read questions: - Which custom attribute definitions exist for users or other models? - Can I list only enabled attribute definitions for a given model? instructions: - text: List custom attribute definitions for model {model}. slots: model: query.object_type__model - text: Show object attributes with enabled = {enabled}. slots: enabled: query.enabled method: generated generated: '2026-09-26' - target: $.paths['/core/object_attributes/'].post update: x-apievangelist-phrasing: intent: Define a custom object attribute effect: write questions: - How do I add a custom field definition to a model such as users? - Can a custom attribute be required, unique or validated with a regex? instructions: - text: Create attribute {key} labelled {label} of type {type} on {object_type}. slots: key: requestBody.key label: requestBody.label type: requestBody.type object_type: requestBody.object_type - text: Define required attribute {key} ({label}, {type}) on {object_type} with regex {regex}. slots: key: requestBody.key label: requestBody.label type: requestBody.type object_type: requestBody.object_type regex: requestBody.regex method: generated generated: '2026-09-26' - target: $.paths['/core/object_attributes/{attribute_id}/'].get update: x-apievangelist-phrasing: intent: Get a custom attribute definition effect: read questions: - What type and validation rules does a custom attribute have? - Is a particular attribute definition required or unique? instructions: - text: Get attribute definition {attribute_id}. slots: attribute_id: path.attribute_id - text: Show the key, type and regex of attribute {attribute_id}. slots: attribute_id: path.attribute_id method: generated generated: '2026-09-26' - target: $.paths['/core/object_attributes/{attribute_id}/'].put update: x-apievangelist-phrasing: intent: Replace a custom attribute definition effect: write questions: - Can I fully redefine an existing custom attribute? - What fields must be resent to replace an attribute definition? instructions: - text: Replace attribute {attribute_id} with key {key}, label {label}, type {type} on {object_type}. slots: attribute_id: path.attribute_id key: requestBody.key label: requestBody.label type: requestBody.type object_type: requestBody.object_type - text: Overwrite attribute definition {attribute_id} as {key} of type {type} for {object_type}, labelled {label}. slots: attribute_id: path.attribute_id key: requestBody.key type: requestBody.type object_type: requestBody.object_type label: requestBody.label method: generated generated: '2026-09-26' - target: $.paths['/core/object_attributes/{attribute_id}/'].delete update: x-apievangelist-phrasing: intent: Delete a custom attribute definition effect: destructive questions: - Can I remove a custom attribute definition I no longer want? - What deletes an object attribute definition? instructions: - text: Delete attribute definition {attribute_id}. slots: attribute_id: path.attribute_id - text: Remove custom attribute {attribute_id}. slots: attribute_id: path.attribute_id method: generated generated: '2026-09-26' - target: $.paths['/core/object_attributes/{attribute_id}/'].patch update: x-apievangelist-phrasing: intent: Edit a custom attribute definition effect: write questions: - Can I disable a custom attribute without deleting it? - Is it possible to change only an attribute's label? instructions: - text: Set enabled to {enabled} on attribute {attribute_id}. slots: enabled: requestBody.enabled attribute_id: path.attribute_id - text: Change the label of attribute {attribute_id} to {label}. slots: attribute_id: path.attribute_id label: requestBody.label - text: 'Make attribute {attribute_id} required: {is_required}.' slots: attribute_id: path.attribute_id is_required: requestBody.is_required method: generated generated: '2026-09-26' - target: $.paths['/core/tokens/'].get update: x-apievangelist-phrasing: intent: List tokens effect: read questions: - What API and app-password tokens exist in authentik? - Can I list only the tokens belonging to one username or with a given intent? instructions: - text: List tokens owned by {username}. slots: username: query.user__username - text: Show tokens with intent {intent}. slots: intent: query.intent method: generated generated: '2026-09-26' - target: $.paths['/core/tokens/'].post update: x-apievangelist-phrasing: intent: Create a token effect: write questions: - How do I create an API token for a user? - Can I make a token that expires on a specific date? instructions: - text: Create token {identifier} with intent {intent}. slots: identifier: requestBody.identifier intent: requestBody.intent - text: Create token {identifier} for user {user} expiring at {expires}. slots: identifier: requestBody.identifier user: requestBody.user expires: requestBody.expires method: generated generated: '2026-09-26' - target: $.paths['/core/tokens/{identifier}/'].get update: x-apievangelist-phrasing: intent: Get a token's details effect: read questions: - When does a specific token expire and who owns it? - Can I see a token's metadata without revealing its secret? instructions: - text: Get token {identifier}. slots: identifier: path.identifier - text: Show the owner, intent and expiry of token {identifier}. slots: identifier: path.identifier method: generated generated: '2026-09-26' - target: $.paths['/core/tokens/{identifier}/'].put update: x-apievangelist-phrasing: intent: Replace a token effect: write questions: - Can I overwrite a token's full definition including its identifier? - What must I resend to replace a token completely? instructions: - text: Replace token {identifier} with new identifier {new_identifier}. slots: identifier: path.identifier new_identifier: requestBody.identifier - text: Overwrite token {identifier} using identifier {new_identifier} and description {description}. slots: identifier: path.identifier new_identifier: requestBody.identifier description: requestBody.description method: generated generated: '2026-09-26' - target: $.paths['/core/tokens/{identifier}/'].delete update: x-apievangelist-phrasing: intent: Delete a token effect: destructive questions: - Can I revoke an API token by deleting it? - What permanently removes a leaked token? instructions: - text: Delete token {identifier}. slots: identifier: path.identifier - text: Revoke and remove token {identifier}. slots: identifier: path.identifier method: generated generated: '2026-09-26' - target: $.paths['/core/tokens/{identifier}/'].patch update: x-apievangelist-phrasing: intent: Edit fields on a token effect: write questions: - Can I extend a token's expiry date without recreating it? - Is it possible to change only a token's description? instructions: - text: Set the expiry of token {identifier} to {expires}. slots: identifier: path.identifier expires: requestBody.expires - text: Change the description of token {identifier} to {description}. slots: identifier: path.identifier description: requestBody.description method: generated generated: '2026-09-26' - target: $.paths['/core/tokens/{identifier}/set_key/'].post update: x-apievangelist-phrasing: intent: Set a token's secret key effect: write questions: - Can I set the secret value of a token to a key I choose? - What permission do I need to overwrite a token's key, and is it logged? instructions: - text: Set the key of token {identifier} to {key}. slots: identifier: path.identifier key: requestBody.key - text: Replace the secret of token {identifier} with {key}. slots: identifier: path.identifier key: requestBody.key method: generated generated: '2026-09-26' - target: $.paths['/core/tokens/{identifier}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a token effect: read questions: - Which objects reference a token before I delete it? - Is a token still tied to an outpost or other object? instructions: - text: List everything that uses token {identifier}. slots: identifier: path.identifier - text: Show objects depending on token {identifier}. slots: identifier: path.identifier method: generated generated: '2026-09-26' - target: $.paths['/core/tokens/{identifier}/view_key/'].get update: x-apievangelist-phrasing: intent: Reveal a token's secret key effect: read questions: - How can I see the actual secret value of a token? - Is viewing a token's key recorded in the audit log? instructions: - text: Show the secret key of token {identifier}. slots: identifier: path.identifier - text: Reveal the key for token {identifier}. slots: identifier: path.identifier method: generated generated: '2026-09-26' - target: $.paths['/core/transactional/applications/'].put update: x-apievangelist-phrasing: intent: Create an application and provider together effect: write questions: - Can I create an application and its provider in one atomic step? - Is there a way to validate and apply an app, provider and policy bindings as a blueprint? instructions: - text: Create application {app} with a {provider_model} provider configured as {provider}. slots: app: requestBody.app provider_model: requestBody.provider_model provider: requestBody.provider - text: Apply app {app}, {provider_model} provider {provider} and bindings {policy_bindings} in one transaction. slots: app: requestBody.app provider_model: requestBody.provider_model provider: requestBody.provider policy_bindings: requestBody.policy_bindings method: generated generated: '2026-09-26' - target: $.paths['/core/user_consent/'].get update: x-apievangelist-phrasing: intent: List user consents effect: read questions: - Which applications have users granted consent to? - Can I list consents for one user or one application? instructions: - text: List consents given by user {user}. slots: user: query.user - text: Show all consents granted to application {application}. slots: application: query.application method: generated generated: '2026-09-26' - target: $.paths['/core/user_consent/{id}/'].get update: x-apievangelist-phrasing: intent: Get a user consent effect: read questions: - What permissions did a user consent to for an app? - When does a specific consent record expire? instructions: - text: Get consent {id}. slots: id: path.id - text: Show the details of consent record {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/core/user_consent/{id}/'].delete update: x-apievangelist-phrasing: intent: Revoke a user consent effect: destructive questions: - Can I withdraw consent a user gave to an application? - What forces an app to ask a user for consent again? instructions: - text: Revoke consent {id}. slots: id: path.id - text: Delete consent record {id} so the user is prompted again. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/core/user_consent/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a consent effect: read questions: - Does anything reference a given consent record? - Which objects depend on a user consent? instructions: - text: List objects that use consent {id}. slots: id: path.id - text: Show what references consent record {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/core/users/'].get update: x-apievangelist-phrasing: intent: List users effect: read questions: - Which users are in my authentik directory? - Can I find users who haven't logged in since a certain date, or who are inactive? - Is it possible to list users by group name or role? instructions: - text: Find the user with email {email}. slots: email: query.email - text: List users who last logged in before {date}. slots: date: query.last_login__lt - text: Show members of group {group} who are active = {is_active}. slots: group: query.groups_by_name is_active: query.is_active method: generated generated: '2026-09-26' - target: $.paths['/core/users/'].post update: x-apievangelist-phrasing: intent: Create a user effect: write questions: - How do I add a new user account? - Can I put a new user straight into groups and a directory path? instructions: - text: Create user {username} named {name}. slots: username: requestBody.username name: requestBody.name - text: Create user {username} ({name}) with email {email} in groups {groups}. slots: username: requestBody.username name: requestBody.name email: requestBody.email groups: requestBody.groups method: generated generated: '2026-09-26' - target: $.paths['/core/users/{id}/'].get update: x-apievangelist-phrasing: intent: Get a user effect: read questions: - What groups and attributes does a specific user have? - When did a particular user last sign in? instructions: - text: Get user {id}. slots: id: path.id - text: Show the profile, groups and last login of user {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/core/users/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a user effect: write questions: - Can I overwrite a user's whole record in one call? - What must I send to fully replace a user account? instructions: - text: Replace user {id} with username {username} and name {name}. slots: id: path.id username: requestBody.username name: requestBody.name - text: Overwrite user {id} as {username} ({name}) with email {email}. slots: id: path.id username: requestBody.username name: requestBody.name email: requestBody.email method: generated generated: '2026-09-26' - target: $.paths['/core/users/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a user effect: destructive questions: - Can I permanently delete a user account? - What removes a former employee's account entirely? instructions: - text: Delete user {id}. slots: id: path.id - text: Remove user account {id} permanently. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/core/users/{id}/'].patch update: x-apievangelist-phrasing: intent: Edit fields on a user effect: write questions: - Can I deactivate a user without deleting them? - Is it possible to change just a user's email address? instructions: - text: Set is-active to {is_active} on user {id}. slots: is_active: requestBody.is_active id: path.id - text: Change the email of user {id} to {email}. slots: id: path.id email: requestBody.email - text: Update only the attributes of user {id} to {attributes}. slots: id: path.id attributes: requestBody.attributes method: generated generated: '2026-09-26' - target: $.paths['/core/users/{id}/impersonate/'].post update: x-apievangelist-phrasing: intent: Impersonate a user effect: write questions: - Can an admin sign in as another user to troubleshoot their account? - Do I have to give a reason when I impersonate someone? instructions: - text: Impersonate user {id} with reason {reason}. slots: id: path.id reason: requestBody.reason - text: Start impersonating user {id} because {reason}. slots: id: path.id reason: requestBody.reason method: generated generated: '2026-09-26' - target: $.paths['/core/users/{id}/recovery/'].post update: x-apievangelist-phrasing: intent: Create an account recovery link effect: write questions: - Can I generate a temporary recovery link to hand to a locked-out user? - How long does an account recovery link stay valid? instructions: - text: Create a recovery link for user {id}. slots: id: path.id - text: Generate a recovery link for user {id} valid for {token_duration}. slots: id: path.id token_duration: requestBody.token_duration method: generated generated: '2026-09-26' - target: $.paths['/core/users/{id}/recovery_email/'].post update: x-apievangelist-phrasing: intent: Email an account recovery link effect: write questions: - Can authentik email a user a link to recover their account? - Which email stage is used to send a recovery message? instructions: - text: Email a recovery link to user {id} using email stage {email_stage}. slots: id: path.id email_stage: requestBody.email_stage - text: Send user {id} a recovery email through stage {email_stage}, valid for {token_duration}. slots: id: path.id email_stage: requestBody.email_stage token_duration: requestBody.token_duration method: generated generated: '2026-09-26' - target: $.paths['/core/users/{id}/set_password/'].post update: x-apievangelist-phrasing: intent: Set a user's password effect: write questions: - Can an admin set a new plain-text password for a user? - What resets a user's password to a value I choose? instructions: - text: Set the password of user {id} to {password}. slots: id: path.id password: requestBody.password - text: Reset user {id}'s password to {password}. slots: id: path.id password: requestBody.password method: generated generated: '2026-09-26' - target: $.paths['/core/users/{id}/set_password_hash/'].post update: x-apievangelist-phrasing: intent: Set a password from a Django hash effect: write questions: - Can I migrate a user's password by importing an existing Django password hash? - Does setting a pre-hashed password sync the change to LDAP or Kerberos? instructions: - text: Set user {id}'s password from the Django hash {password}. slots: id: path.id password: requestBody.password - text: Import pre-hashed password {password} for user {id}. slots: password: requestBody.password id: path.id method: generated generated: '2026-09-26' - target: $.paths['/core/users/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a user effect: read questions: - Which objects reference a user before I delete the account? - Is a user still bound to any policies or tokens? instructions: - text: List everything that uses user {id}. slots: id: path.id - text: Show objects that depend on user account {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/core/users/account_lockdown/'].post update: x-apievangelist-phrasing: intent: Lock down a user account effect: destructive questions: - Can I lock down a compromised account and get a flow link to finish it? - What happens if I trigger an account lockdown without naming a user? instructions: - text: Start an account lockdown for user {user}. slots: user: requestBody.user - text: Lock down my own account. method: generated generated: '2026-09-26' - target: $.paths['/core/users/export/'].post update: x-apievangelist-phrasing: intent: Export users to a file effect: write questions: - Can I export my user directory to a downloadable file? - Is the user export generated asynchronously, and how do I know when it's done? instructions: - text: Export all users. - text: Export users in group {group} with active = {is_active}. slots: group: query.groups_by_name is_active: query.is_active method: generated generated: '2026-09-26' - target: $.paths['/core/users/impersonate_end/'].get update: x-apievangelist-phrasing: intent: Stop impersonating a user effect: write questions: - How do I get back to my own admin account after impersonating someone? - What ends an active impersonation session? instructions: - text: End the current impersonation. - text: Stop impersonating and return to my own account. method: generated generated: '2026-09-26' - target: $.paths['/core/users/me/'].get update: x-apievangelist-phrasing: intent: Get the signed-in user effect: read questions: - Who am I signed in as right now? - Can I fetch the current user's details and whether they are being impersonated? instructions: - text: Show information about the current user. - text: Get my own account details. method: generated generated: '2026-09-26' - target: $.paths['/core/users/paths/'].get update: x-apievangelist-phrasing: intent: List user directory paths effect: read questions: - What directory paths are users organized into? - Can I search the list of user paths? instructions: - text: List all user paths. - text: Search user paths for {search}. slots: search: query.search method: generated generated: '2026-09-26' - target: $.paths['/core/users/service_account/'].post update: x-apievangelist-phrasing: intent: Create a service account effect: write questions: - How do I create a non-human service account for automation? - Can a new service account get its own group and an expiring token? instructions: - text: Create service account {name}. slots: name: requestBody.name - text: Create service account {name} with a group, create_group = {create_group}. slots: name: requestBody.name create_group: requestBody.create_group - text: Create service account {name} whose token expires at {expires}. slots: name: requestBody.name expires: requestBody.expires method: generated generated: '2026-09-26' - target: $.paths['/core/users/switch/'].post update: x-apievangelist-phrasing: intent: Switch the browser to another user effect: write questions: - Can I switch my browser session over to a different user account? - Where does user switching send me afterwards? instructions: - text: Switch the browser session to user {user_pk}. slots: user_pk: requestBody.user_pk - text: Start user switching to {user_pk} and then go to {next}. slots: user_pk: requestBody.user_pk next: query.next method: generated generated: '2026-09-26'