# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for authentik Crypto API version: 1.0.0 extends: openapi/authentik-crypto-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 10 - target: $.paths['/crypto/certificatekeypairs/'].get update: x-apievangelist-phrasing: intent: List certificate-key pairs effect: read questions: - Which certificates and key pairs are stored in my authentik instance? - Can I list only the certificate-key pairs that include a private key? - Is there a way to filter certificates by key type or whether authentik manages them? instructions: - text: List all certificate-key pairs. - text: 'Show only certificate-key pairs that have a private key: {has_key}.' slots: has_key: query.has_key - text: Find certificate-key pairs of key type {key_type} named {name}. slots: key_type: query.key_type name: query.name method: generated generated: '2026-09-26' - target: $.paths['/crypto/certificatekeypairs/'].post update: x-apievangelist-phrasing: intent: Import a certificate-key pair effect: write questions: - How do I upload an existing PEM certificate so authentik can use it? - Can I import a certificate without its private key? instructions: - text: Import certificate {certificate_data} as a new keypair called {name}. slots: certificate_data: requestBody.certificate_data name: requestBody.name - text: Upload PEM certificate {certificate_data} with private key {key_data} under the name {name}. slots: certificate_data: requestBody.certificate_data key_data: requestBody.key_data name: requestBody.name method: generated generated: '2026-09-26' - target: $.paths['/crypto/certificatekeypairs/{kp_uuid}/'].get update: x-apievangelist-phrasing: intent: Get a certificate-key pair effect: read questions: - What are the details of one certificate-key pair, like its fingerprint and expiry? - Can I look up a single stored certificate by its UUID? instructions: - text: Show the details of certificate-key pair {kp_uuid}. slots: kp_uuid: path.kp_uuid - text: Get the metadata for keypair {kp_uuid}. slots: kp_uuid: path.kp_uuid method: generated generated: '2026-09-26' - target: $.paths['/crypto/certificatekeypairs/{kp_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace a certificate-key pair effect: write questions: - How do I swap in a renewed certificate on an existing keypair? - Can I fully replace the name and PEM data of a stored certificate in one call? instructions: - text: Replace keypair {kp_uuid} with name {name} and certificate {certificate_data}. slots: kp_uuid: path.kp_uuid name: requestBody.name certificate_data: requestBody.certificate_data - text: Overwrite keypair {kp_uuid} entirely with certificate {certificate_data}, key {key_data} and name {name}. slots: kp_uuid: path.kp_uuid certificate_data: requestBody.certificate_data key_data: requestBody.key_data name: requestBody.name method: generated generated: '2026-09-26' - target: $.paths['/crypto/certificatekeypairs/{kp_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a certificate-key pair effect: destructive questions: - How do I remove a certificate I no longer need from authentik? - What happens when I delete a keypair that something still uses? instructions: - text: Delete certificate-key pair {kp_uuid}. slots: kp_uuid: path.kp_uuid - text: Remove the stored certificate {kp_uuid} permanently. slots: kp_uuid: path.kp_uuid method: generated generated: '2026-09-26' - target: $.paths['/crypto/certificatekeypairs/{kp_uuid}/'].patch update: x-apievangelist-phrasing: intent: Edit fields on a certificate-key pair effect: write questions: - Can I just rename a certificate-key pair without re-uploading it? - How do I add a private key to a certificate that was imported without one? instructions: - text: Rename keypair {kp_uuid} to {name}. slots: kp_uuid: path.kp_uuid name: requestBody.name - text: Attach private key {key_data} to the existing keypair {kp_uuid}. slots: key_data: requestBody.key_data kp_uuid: path.kp_uuid method: generated generated: '2026-09-26' - target: $.paths['/crypto/certificatekeypairs/{kp_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a certificate-key pair effect: read questions: - Which providers or sources depend on this certificate before I rotate it? - Is a certificate still referenced by anything in authentik? instructions: - text: List every object that uses certificate {kp_uuid}. slots: kp_uuid: path.kp_uuid - text: Check what depends on keypair {kp_uuid} before I delete it. slots: kp_uuid: path.kp_uuid method: generated generated: '2026-09-26' - target: $.paths['/crypto/certificatekeypairs/{kp_uuid}/view_certificate/'].get update: x-apievangelist-phrasing: intent: View or download a certificate effect: read questions: - How do I get the PEM text of a certificate stored in authentik? - Can I download a certificate as a file, and is that access logged? instructions: - text: Show the certificate PEM for keypair {kp_uuid}. slots: kp_uuid: path.kp_uuid - text: 'Download the public certificate of {kp_uuid} as a file: {download}.' slots: kp_uuid: path.kp_uuid download: query.download method: generated generated: '2026-09-26' - target: $.paths['/crypto/certificatekeypairs/{kp_uuid}/view_private_key/'].get update: x-apievangelist-phrasing: intent: View or download a private key effect: read questions: - How can I export the private key that belongs to a stored keypair? - Does authentik record an audit event when someone views a private key? instructions: - text: Reveal the private key for keypair {kp_uuid}. slots: kp_uuid: path.kp_uuid - text: 'Download the private key of {kp_uuid} as a file: {download}.' slots: kp_uuid: path.kp_uuid download: query.download method: generated generated: '2026-09-26' - target: $.paths['/crypto/certificatekeypairs/generate/'].post update: x-apievangelist-phrasing: intent: Generate a self-signed certificate effect: write questions: - Can authentik create a self-signed certificate for me? - How long can a generated certificate be valid, and can I add subject alternative names? - Which key algorithm can I choose when generating a new keypair? instructions: - text: Generate a self-signed certificate for {common_name} valid for {validity_days} days. slots: common_name: requestBody.common_name validity_days: requestBody.validity_days - text: Create a new self-signed keypair for {common_name} with SANs {subject_alt_name}, {validity_days} days, algorithm {alg}. slots: common_name: requestBody.common_name subject_alt_name: requestBody.subject_alt_name validity_days: requestBody.validity_days alg: requestBody.alg method: generated generated: '2026-09-26'