# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for authentik Endpoints API version: 1.0.0 extends: openapi/authentik-endpoints-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 70 - target: $.paths['/endpoints/agents/connectors/'].get update: x-apievangelist-phrasing: intent: List authentik Agent connectors effect: read questions: - Which authentik Agent connectors are set up for my devices? - Can I see only the Agent connectors that are currently enabled? instructions: - text: List all authentik Agent connectors. - text: Show Agent connectors named {name}. slots: name: query.name - text: List Agent connectors where enabled is {enabled}. slots: enabled: query.enabled method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/connectors/'].post update: x-apievangelist-phrasing: intent: Create an authentik Agent connector effect: write questions: - How do I set up a new connector for the authentik Agent on endpoints? - Can a new Agent connector set how long device auth sessions last? instructions: - text: Create an Agent connector named {name}. slots: name: requestBody.name - text: Add a new Agent connector {name} with a refresh interval of {refresh_interval}. slots: name: requestBody.name refresh_interval: requestBody.refresh_interval - text: Create Agent connector {name} using authorization flow {authorization_flow}. slots: name: requestBody.name authorization_flow: requestBody.authorization_flow method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/connectors/{connector_uuid}/'].get update: x-apievangelist-phrasing: intent: Get an authentik Agent connector effect: read questions: - What settings does a particular Agent connector have? - Is the NSS UID offset configured on this Agent connector? instructions: - text: Show Agent connector {connector_uuid}. slots: connector_uuid: path.connector_uuid - text: Fetch the snapshot expiry and session settings of Agent connector {connector_uuid}. slots: connector_uuid: path.connector_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/connectors/{connector_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace an Agent connector's settings effect: write questions: - Can I overwrite the full configuration of an Agent connector in one call? - What do I have to resend when fully replacing an Agent connector? instructions: - text: Replace every setting of Agent connector {connector_uuid}, naming it {name}. slots: connector_uuid: path.connector_uuid name: requestBody.name - text: Fully rewrite Agent connector {connector_uuid} as {name} with auth session duration {auth_session_duration}. slots: connector_uuid: path.connector_uuid name: requestBody.name auth_session_duration: requestBody.auth_session_duration method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/connectors/{connector_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete an authentik Agent connector effect: destructive questions: - How do I remove an Agent connector I no longer use? - Is deleting an Agent connector permanent? instructions: - text: Delete Agent connector {connector_uuid}. slots: connector_uuid: path.connector_uuid - text: Remove the authentik Agent connector {connector_uuid}. slots: connector_uuid: path.connector_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/connectors/{connector_uuid}/'].patch update: x-apievangelist-phrasing: intent: Change some settings on an Agent connector effect: write questions: - Can I just disable an Agent connector without touching its other settings? - Is it possible to change only the challenge idle timeout on an Agent connector? instructions: - text: On Agent connector {connector_uuid}, only set enabled to {enabled}. slots: connector_uuid: path.connector_uuid enabled: requestBody.enabled - text: Change just the challenge idle timeout of Agent connector {connector_uuid} to {challenge_idle_timeout}. slots: connector_uuid: path.connector_uuid challenge_idle_timeout: requestBody.challenge_idle_timeout method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/connectors/{connector_uuid}/mdm_config/'].post update: x-apievangelist-phrasing: intent: Generate MDM config to deploy the Agent effect: read questions: - How do I get a configuration profile to push the authentik Agent through my MDM? - Which platform and enrollment token does the MDM deployment config need? instructions: - text: Generate MDM configuration for connector {connector_uuid} on platform {platform} with enrollment token {enrollment_token}. slots: connector_uuid: path.connector_uuid platform: requestBody.platform enrollment_token: requestBody.enrollment_token - text: Build the MDM deployment profile for Agent connector {connector_uuid} targeting {platform}. slots: connector_uuid: path.connector_uuid platform: requestBody.platform method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/connectors/{connector_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses an Agent connector effect: read questions: - What objects depend on this Agent connector? - Would removing an Agent connector break anything else? instructions: - text: Show everything that references Agent connector {connector_uuid}. slots: connector_uuid: path.connector_uuid - text: List objects using Agent connector {connector_uuid}. slots: connector_uuid: path.connector_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/connectors/agent_config/'].get update: x-apievangelist-phrasing: intent: Get the running Agent's configuration effect: read questions: - Where does the installed authentik Agent fetch its own configuration from? - Can the Agent on a device read the config its connector assigns it? instructions: - text: Fetch the Agent configuration for this device. - text: Get the config the authentik Agent should run with. method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/connectors/auth_fed/'].post update: x-apievangelist-phrasing: intent: Authenticate a device via federated JWT effect: write questions: - How does an enrolled device sign in to authentik using a federated token? - Can a device exchange a JWT from a federation provider for an Agent session? instructions: - text: Run federated authentication for device {device}. slots: device: query.device - text: Authenticate device {device} through JWT federation. slots: device: query.device method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/connectors/auth_ia/'].post update: x-apievangelist-phrasing: intent: Start interactive Agent authentication effect: write questions: - How does the Agent start an interactive login for a user on a device? - Can I pass a login hint when the Agent begins interactive auth? instructions: - text: Begin interactive Agent authentication. - text: Start interactive authentication with login hint {login_hint}. slots: login_hint: query.login_hint method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/connectors/check_in/'].post update: x-apievangelist-phrasing: intent: Report a device check-in from the Agent effect: write questions: - How does the Agent report a device's OS, disks and installed software to authentik? - What inventory can a device send when it checks in? instructions: - text: Send a device check-in with operating system {os} and vendor {vendor}. slots: os: requestBody.os vendor: requestBody.vendor - text: Check in this device reporting hardware {hardware} and software {software}. slots: hardware: requestBody.hardware software: requestBody.software method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/connectors/enroll/'].post update: x-apievangelist-phrasing: intent: Enroll a device with the Agent effect: write questions: - How do I enroll a new laptop into authentik endpoint management? - Which details does a device need to provide to enroll? instructions: - text: Enroll device {device_name} with serial number {device_serial}. slots: device_name: requestBody.device_name device_serial: requestBody.device_serial - text: Register the machine with serial {device_serial} as {device_name}. slots: device_serial: requestBody.device_serial device_name: requestBody.device_name method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/enrollment_tokens/'].get update: x-apievangelist-phrasing: intent: List device enrollment tokens effect: read questions: - What enrollment tokens exist for enrolling devices? - Can I see only the enrollment tokens tied to one connector? instructions: - text: List all device enrollment tokens. - text: Show enrollment tokens for connector {connector}. slots: connector: query.connector method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/enrollment_tokens/'].post update: x-apievangelist-phrasing: intent: Create a device enrollment token effect: write questions: - How do I make a token that devices use to enroll with the Agent? - Can an enrollment token expire and drop devices into a device group? instructions: - text: Create enrollment token {name} for connector {connector}. slots: name: requestBody.name connector: requestBody.connector - text: Make an enrollment token {name} on connector {connector} that expires at {expires}. slots: name: requestBody.name connector: requestBody.connector expires: requestBody.expires - text: Create token {name} for connector {connector} placing devices in group {device_group}. slots: name: requestBody.name connector: requestBody.connector device_group: requestBody.device_group method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/enrollment_tokens/{token_uuid}/'].get update: x-apievangelist-phrasing: intent: Get a device enrollment token effect: read questions: - What connector and expiry does a given enrollment token have? - Which device group will an enrollment token assign? instructions: - text: Show enrollment token {token_uuid}. slots: token_uuid: path.token_uuid - text: Fetch the details of enrollment token {token_uuid}. slots: token_uuid: path.token_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/enrollment_tokens/{token_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace an enrollment token's settings effect: write questions: - Can I overwrite all fields of an enrollment token at once? - What must I resend when fully replacing an enrollment token? instructions: - text: Replace enrollment token {token_uuid} with name {name} on connector {connector}. slots: token_uuid: path.token_uuid name: requestBody.name connector: requestBody.connector - text: Fully rewrite enrollment token {token_uuid} as {name} for connector {connector}, expiring {expires}. slots: token_uuid: path.token_uuid name: requestBody.name connector: requestBody.connector expires: requestBody.expires method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/enrollment_tokens/{token_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a device enrollment token effect: destructive questions: - How do I revoke an enrollment token so no more devices can use it? - Is deleting an enrollment token irreversible? instructions: - text: Delete enrollment token {token_uuid}. slots: token_uuid: path.token_uuid - text: Remove device enrollment token {token_uuid}. slots: token_uuid: path.token_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/enrollment_tokens/{token_uuid}/'].patch update: x-apievangelist-phrasing: intent: Change part of an enrollment token effect: write questions: - Can I just extend an enrollment token's expiry without changing anything else? - Is it possible to only move an enrollment token to another device group? instructions: - text: Only set the expiry of enrollment token {token_uuid} to {expires}. slots: token_uuid: path.token_uuid expires: requestBody.expires - text: Change just the device group of enrollment token {token_uuid} to {device_group}. slots: token_uuid: path.token_uuid device_group: requestBody.device_group method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/enrollment_tokens/{token_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses an enrollment token effect: read questions: - Which objects reference a particular enrollment token? - What would be affected if I removed this enrollment token? instructions: - text: Show what depends on enrollment token {token_uuid}. slots: token_uuid: path.token_uuid - text: List objects referencing enrollment token {token_uuid}. slots: token_uuid: path.token_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/enrollment_tokens/{token_uuid}/view_key/'].get update: x-apievangelist-phrasing: intent: Reveal an enrollment token's key effect: read questions: - How do I see the actual secret key of an enrollment token? - Is viewing an enrollment token's key logged? instructions: - text: Reveal the key for enrollment token {token_uuid}. slots: token_uuid: path.token_uuid - text: Show me the secret value of enrollment token {token_uuid}. slots: token_uuid: path.token_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/psso/ise/'].get update: x-apievangelist-phrasing: intent: List Platform SSO Secure Enclave keys effect: read questions: - Which Apple Secure Enclave keys are registered for Platform SSO? - Can I filter Platform SSO enclave keys by user? instructions: - text: List all Platform SSO Secure Enclave key registrations. - text: Show Secure Enclave keys registered for user {user}. slots: user: query.user - text: Find the Secure Enclave registration with key ID {apple_enclave_key_id}. slots: apple_enclave_key_id: query.apple_enclave_key_id method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/psso/ise/'].post update: x-apievangelist-phrasing: intent: Register a Secure Enclave key for a user effect: write questions: - How do I register an Apple Secure Enclave key for a user's Platform SSO? - What does a new Platform SSO enclave key record need? instructions: - text: Register Secure Enclave key {apple_secure_enclave_key} with ID {apple_enclave_key_id} for user {user} on a {device_type}. slots: apple_secure_enclave_key: requestBody.apple_secure_enclave_key apple_enclave_key_id: requestBody.apple_enclave_key_id user: requestBody.user device_type: requestBody.device_type - text: Save a {device_type} Secure Enclave key {apple_secure_enclave_key} (ID {apple_enclave_key_id}) so {user} can use Platform SSO. slots: device_type: requestBody.device_type apple_secure_enclave_key: requestBody.apple_secure_enclave_key apple_enclave_key_id: requestBody.apple_enclave_key_id user: requestBody.user method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/psso/ise/{uuid}/'].get update: x-apievangelist-phrasing: intent: Get a Secure Enclave key registration effect: read questions: - Which user and device type does a Secure Enclave key record belong to? - Can I look up one Platform SSO enclave key registration? instructions: - text: Show Secure Enclave key registration {uuid}. slots: uuid: path.uuid - text: Fetch the Platform SSO enclave key record {uuid}. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/psso/ise/{uuid}/'].put update: x-apievangelist-phrasing: intent: Replace a Secure Enclave key registration effect: write questions: - Can I overwrite every field of a Platform SSO enclave key record? - What is required to fully replace a Secure Enclave key registration? instructions: - text: Replace enclave key record {uuid} with key {apple_secure_enclave_key}, ID {apple_enclave_key_id}, user {user}, device type {device_type}. slots: uuid: path.uuid apple_secure_enclave_key: requestBody.apple_secure_enclave_key apple_enclave_key_id: requestBody.apple_enclave_key_id user: requestBody.user device_type: requestBody.device_type - text: 'Overwrite all of enclave registration {uuid}: user {user}, key {apple_secure_enclave_key}, key ID {apple_enclave_key_id}, type {device_type}.' slots: uuid: path.uuid user: requestBody.user apple_secure_enclave_key: requestBody.apple_secure_enclave_key apple_enclave_key_id: requestBody.apple_enclave_key_id device_type: requestBody.device_type method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/psso/ise/{uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a Secure Enclave key registration effect: destructive questions: - How do I remove a user's Platform SSO Secure Enclave key? - Is removing an enclave key registration permanent? instructions: - text: Delete Secure Enclave key registration {uuid}. slots: uuid: path.uuid - text: Remove the Platform SSO enclave key {uuid}. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/psso/ise/{uuid}/'].patch update: x-apievangelist-phrasing: intent: Change part of a Secure Enclave key record effect: write questions: - Can I just reassign a Secure Enclave key record to another user? - Is it possible to only change the device type on an enclave key registration? instructions: - text: Only change the user of enclave key record {uuid} to {user}. slots: uuid: path.uuid user: requestBody.user - text: Set just the device type of Secure Enclave registration {uuid} to {device_type}. slots: uuid: path.uuid device_type: requestBody.device_type method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/psso/ise/{uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a Secure Enclave key record effect: read questions: - What objects reference a given Platform SSO enclave key? - Does anything depend on this Secure Enclave key registration? instructions: - text: Show what references Secure Enclave registration {uuid}. slots: uuid: path.uuid - text: List objects using enclave key record {uuid}. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/psso/register/device/'].post update: x-apievangelist-phrasing: intent: Register a device for Platform SSO effect: write questions: - How does a Mac register its signing and encryption keys for Platform SSO? - Which device keys are needed to register for Platform SSO? instructions: - text: Register this device for Platform SSO with signing key {device_signing_key} ({sign_key_id}) and encryption key {device_encryption_key} ({enc_key_id}). slots: device_signing_key: requestBody.device_signing_key sign_key_id: requestBody.sign_key_id device_encryption_key: requestBody.device_encryption_key enc_key_id: requestBody.enc_key_id - text: 'Enroll this Mac in Platform SSO: key IDs {sign_key_id} and {enc_key_id}, keys {device_signing_key} and {device_encryption_key}.' slots: sign_key_id: requestBody.sign_key_id enc_key_id: requestBody.enc_key_id device_signing_key: requestBody.device_signing_key device_encryption_key: requestBody.device_encryption_key method: generated generated: '2026-09-26' - target: $.paths['/endpoints/agents/psso/register/user/'].post update: x-apievangelist-phrasing: intent: Register a user for Platform SSO effect: write questions: - How does a user register their Secure Enclave key for Platform SSO sign-in? - What must a user send to complete Platform SSO user registration? instructions: - text: Register the Platform SSO user with auth {user_auth}, enclave key {user_secure_enclave_key} and key ID {enclave_key_id}. slots: user_auth: requestBody.user_auth user_secure_enclave_key: requestBody.user_secure_enclave_key enclave_key_id: requestBody.enclave_key_id - text: Complete Platform SSO user registration using enclave key ID {enclave_key_id}, key {user_secure_enclave_key} and credentials {user_auth}. slots: enclave_key_id: requestBody.enclave_key_id user_secure_enclave_key: requestBody.user_secure_enclave_key user_auth: requestBody.user_auth method: generated generated: '2026-09-26' - target: $.paths['/endpoints/connectors/'].get update: x-apievangelist-phrasing: intent: List all endpoint connectors of any type effect: read questions: - What endpoint connectors of every kind are configured? - Can I search across all device connectors regardless of type? instructions: - text: List every endpoint connector, whatever its type. - text: Search all endpoint connectors for {search}. slots: search: query.search method: generated generated: '2026-09-26' - target: $.paths['/endpoints/connectors/{connector_uuid}/'].get update: x-apievangelist-phrasing: intent: Get any endpoint connector by ID effect: read questions: - How can I look up an endpoint connector when I don't know its type? - What type is a given endpoint connector? instructions: - text: Show endpoint connector {connector_uuid} regardless of type. slots: connector_uuid: path.connector_uuid - text: Look up generic endpoint connector {connector_uuid}. slots: connector_uuid: path.connector_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/connectors/{connector_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete any endpoint connector effect: destructive questions: - Can I delete an endpoint connector without knowing whether it's Fleet, Chrome or Agent? - Is deleting a generic endpoint connector permanent? instructions: - text: Delete endpoint connector {connector_uuid} of whatever type. slots: connector_uuid: path.connector_uuid - text: Remove generic endpoint connector {connector_uuid}. slots: connector_uuid: path.connector_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/connectors/{connector_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses any endpoint connector effect: read questions: - What depends on an endpoint connector of any type? - Before removing a generic connector, what references it? instructions: - text: Show what uses generic endpoint connector {connector_uuid}. slots: connector_uuid: path.connector_uuid - text: List dependents of endpoint connector {connector_uuid} across all connector types. slots: connector_uuid: path.connector_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/connectors/types/'].get update: x-apievangelist-phrasing: intent: List creatable endpoint connector types effect: read questions: - What kinds of endpoint connectors can I create? - Which device connector types does this authentik version support? instructions: - text: List the endpoint connector types I can create. - text: Show all available connector types for device management. method: generated generated: '2026-09-26' - target: $.paths['/endpoints/device_access_groups/'].get update: x-apievangelist-phrasing: intent: List device access groups effect: read questions: - Which device access groups have been defined? - Can I find a device access group by name? instructions: - text: List all device access groups. - text: Show device access groups named {name}. slots: name: query.name method: generated generated: '2026-09-26' - target: $.paths['/endpoints/device_access_groups/'].post update: x-apievangelist-phrasing: intent: Create a device access group effect: write questions: - How do I create a group to control access for a set of devices? - Can a new device access group carry custom attributes? instructions: - text: Create a device access group named {name}. slots: name: requestBody.name - text: Add device access group {name} with attributes {attributes}. slots: name: requestBody.name attributes: requestBody.attributes method: generated generated: '2026-09-26' - target: $.paths['/endpoints/device_access_groups/{pbm_uuid}/'].get update: x-apievangelist-phrasing: intent: Get a device access group effect: read questions: - What attributes are set on a specific device access group? - Can I view one device access group's details? instructions: - text: Show device access group {pbm_uuid}. slots: pbm_uuid: path.pbm_uuid - text: Fetch the attributes of device access group {pbm_uuid}. slots: pbm_uuid: path.pbm_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/device_access_groups/{pbm_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace a device access group effect: write questions: - Can I overwrite a device access group's name and attributes together? - What does a full replacement of a device access group require? instructions: - text: Replace device access group {pbm_uuid} with name {name}. slots: pbm_uuid: path.pbm_uuid name: requestBody.name - text: Fully rewrite device access group {pbm_uuid} as {name} with attributes {attributes}. slots: pbm_uuid: path.pbm_uuid name: requestBody.name attributes: requestBody.attributes method: generated generated: '2026-09-26' - target: $.paths['/endpoints/device_access_groups/{pbm_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a device access group effect: destructive questions: - How do I remove a device access group? - Is deleting a device access group reversible? instructions: - text: Delete device access group {pbm_uuid}. slots: pbm_uuid: path.pbm_uuid - text: Remove the device access group {pbm_uuid}. slots: pbm_uuid: path.pbm_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/device_access_groups/{pbm_uuid}/'].patch update: x-apievangelist-phrasing: intent: Change part of a device access group effect: write questions: - Can I just rename a device access group? - Is it possible to only update the attributes of a device access group? instructions: - text: Only rename device access group {pbm_uuid} to {name}. slots: pbm_uuid: path.pbm_uuid name: requestBody.name - text: Change just the attributes of device access group {pbm_uuid} to {attributes}. slots: pbm_uuid: path.pbm_uuid attributes: requestBody.attributes method: generated generated: '2026-09-26' - target: $.paths['/endpoints/device_access_groups/{pbm_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a device access group effect: read questions: - Which devices or objects reference a device access group? - What would break if I deleted this device access group? instructions: - text: Show what references device access group {pbm_uuid}. slots: pbm_uuid: path.pbm_uuid - text: List objects using device access group {pbm_uuid}. slots: pbm_uuid: path.pbm_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/device_bindings/'].get update: x-apievangelist-phrasing: intent: List device policy bindings effect: read questions: - Which policies, users or groups are bound to device access targets? - Can I list only the enabled device bindings for one target? instructions: - text: List all device policy bindings. - text: Show device bindings for target {target}. slots: target: query.target - text: List device bindings that use policy {policy}. slots: policy: query.policy method: generated generated: '2026-09-26' - target: $.paths['/endpoints/device_bindings/'].post update: x-apievangelist-phrasing: intent: Bind a policy, user or group to a device target effect: write questions: - How do I bind a policy to a device access group? - Can a device binding be negated or given a timeout? instructions: - text: Bind policy {policy} to device target {target} at order {order}. slots: policy: requestBody.policy target: requestBody.target order: requestBody.order - text: Create a device binding for group {group} on target {target} with order {order}. slots: group: requestBody.group target: requestBody.target order: requestBody.order - text: 'Bind user {user} to device target {target} at order {order}, negated: {negate}.' slots: user: requestBody.user target: requestBody.target order: requestBody.order negate: requestBody.negate method: generated generated: '2026-09-26' - target: $.paths['/endpoints/device_bindings/{policy_binding_uuid}/'].get update: x-apievangelist-phrasing: intent: Get a device policy binding effect: read questions: - What policy and order does a particular device binding use? - Is a given device binding negated? instructions: - text: Show device binding {policy_binding_uuid}. slots: policy_binding_uuid: path.policy_binding_uuid - text: Fetch the settings of device policy binding {policy_binding_uuid}. slots: policy_binding_uuid: path.policy_binding_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/device_bindings/{policy_binding_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace a device policy binding effect: write questions: - Can I overwrite every field of a device binding at once? - What must be resent when fully replacing a device binding? instructions: - text: Replace device binding {policy_binding_uuid} with target {target} at order {order}. slots: policy_binding_uuid: path.policy_binding_uuid target: requestBody.target order: requestBody.order - text: Fully rewrite device binding {policy_binding_uuid} to bind policy {policy} to {target} at order {order}. slots: policy_binding_uuid: path.policy_binding_uuid policy: requestBody.policy target: requestBody.target order: requestBody.order method: generated generated: '2026-09-26' - target: $.paths['/endpoints/device_bindings/{policy_binding_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a device policy binding effect: destructive questions: - How do I unbind a policy from a device target? - Is deleting a device binding permanent? instructions: - text: Delete device binding {policy_binding_uuid}. slots: policy_binding_uuid: path.policy_binding_uuid - text: Remove the device policy binding {policy_binding_uuid}. slots: policy_binding_uuid: path.policy_binding_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/device_bindings/{policy_binding_uuid}/'].patch update: x-apievangelist-phrasing: intent: Change part of a device policy binding effect: write questions: - Can I just disable a device binding without deleting it? - Is it possible to only change a device binding's order? instructions: - text: Only set enabled on device binding {policy_binding_uuid} to {enabled}. slots: policy_binding_uuid: path.policy_binding_uuid enabled: requestBody.enabled - text: Change just the order of device binding {policy_binding_uuid} to {order}. slots: policy_binding_uuid: path.policy_binding_uuid order: requestBody.order method: generated generated: '2026-09-26' - target: $.paths['/endpoints/device_bindings/{policy_binding_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a device policy binding effect: read questions: - What objects reference a given device binding? - Does anything depend on this device policy binding? instructions: - text: Show what references device binding {policy_binding_uuid}. slots: policy_binding_uuid: path.policy_binding_uuid - text: List dependents of device policy binding {policy_binding_uuid}. slots: policy_binding_uuid: path.policy_binding_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/devices/'].get update: x-apievangelist-phrasing: intent: List managed devices effect: read questions: - Which devices are registered in authentik? - Can I find a device by its identifier or name? instructions: - text: List all managed devices. - text: Find devices named {name}. slots: name: query.name - text: Look up the device with identifier {identifier}. slots: identifier: query.identifier method: generated generated: '2026-09-26' - target: $.paths['/endpoints/devices/{device_uuid}/'].get update: x-apievangelist-phrasing: intent: Get a managed device effect: read questions: - What access group and expiry does a particular device have? - Can I see the attributes recorded for one device? instructions: - text: Show device {device_uuid}. slots: device_uuid: path.device_uuid - text: Fetch the details of managed device {device_uuid}. slots: device_uuid: path.device_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/devices/{device_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace a managed device's settings effect: write questions: - Can I overwrite all editable fields of a device in one request? - What must I resend when fully replacing a device record? instructions: - text: Replace device {device_uuid} with name {name}. slots: device_uuid: path.device_uuid name: requestBody.name - text: Fully rewrite device {device_uuid} as {name} in access group {access_group}. slots: device_uuid: path.device_uuid name: requestBody.name access_group: requestBody.access_group method: generated generated: '2026-09-26' - target: $.paths['/endpoints/devices/{device_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a managed device effect: destructive questions: - How do I remove a device from authentik? - Is deleting a device record permanent? instructions: - text: Delete device {device_uuid}. slots: device_uuid: path.device_uuid - text: Remove managed device {device_uuid} from authentik. slots: device_uuid: path.device_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/devices/{device_uuid}/'].patch update: x-apievangelist-phrasing: intent: Change part of a managed device effect: write questions: - Can I just move a device into a different access group? - Is it possible to only set an expiry on a device? instructions: - text: Only move device {device_uuid} into access group {access_group}. slots: device_uuid: path.device_uuid access_group: requestBody.access_group - text: Set just the expiry of device {device_uuid} to {expires}. slots: device_uuid: path.device_uuid expires: requestBody.expires - text: Rename only device {device_uuid} to {name}. slots: device_uuid: path.device_uuid name: requestBody.name method: generated generated: '2026-09-26' - target: $.paths['/endpoints/devices/{device_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a managed device effect: read questions: - What objects reference a particular device? - Before deleting a device, what depends on it? instructions: - text: Show what references device {device_uuid}. slots: device_uuid: path.device_uuid - text: List objects using managed device {device_uuid}. slots: device_uuid: path.device_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/devices/summary/'].get update: x-apievangelist-phrasing: intent: Get a summary of managed devices effect: read questions: - Is there an overview of my device fleet's counts? - What does the device summary report? instructions: - text: Show the managed device summary. - text: Give me an overview of all devices. method: generated generated: '2026-09-26' - target: $.paths['/endpoints/fleet/connectors/'].get update: x-apievangelist-phrasing: intent: List Fleet connectors effect: read questions: - Which Fleet device management connectors are configured? - Can I find a Fleet connector by name? instructions: - text: List all Fleet connectors. - text: Show Fleet connectors named {name}. slots: name: query.name method: generated generated: '2026-09-26' - target: $.paths['/endpoints/fleet/connectors/'].post update: x-apievangelist-phrasing: intent: Connect a Fleet server effect: write questions: - How do I connect my Fleet server to authentik for device data? - Can a Fleet connector map Fleet users and teams to access groups? instructions: - text: Create Fleet connector {name} for URL {url} with token {token}. slots: name: requestBody.name url: requestBody.url token: requestBody.token - text: 'Add Fleet connector {name} at {url} using token {token}, mapping teams to access groups: {map_teams_access_group}.' slots: name: requestBody.name url: requestBody.url token: requestBody.token map_teams_access_group: requestBody.map_teams_access_group method: generated generated: '2026-09-26' - target: $.paths['/endpoints/fleet/connectors/{connector_uuid}/'].get update: x-apievangelist-phrasing: intent: Get a Fleet connector effect: read questions: - What URL and mapping options does a Fleet connector use? - Is user mapping turned on for this Fleet connector? instructions: - text: Show Fleet connector {connector_uuid}. slots: connector_uuid: path.connector_uuid - text: Fetch the settings of Fleet connector {connector_uuid}. slots: connector_uuid: path.connector_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/fleet/connectors/{connector_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace a Fleet connector effect: write questions: - Can I overwrite a Fleet connector's URL, token and name together? - What must I resend to fully replace a Fleet connector? instructions: - text: Replace Fleet connector {connector_uuid} as {name} at {url} with token {token}. slots: connector_uuid: path.connector_uuid name: requestBody.name url: requestBody.url token: requestBody.token - text: 'Overwrite all settings of Fleet connector {connector_uuid}: name {name}, server {url}, token {token}, map users {map_users}.' slots: connector_uuid: path.connector_uuid name: requestBody.name url: requestBody.url token: requestBody.token map_users: requestBody.map_users method: generated generated: '2026-09-26' - target: $.paths['/endpoints/fleet/connectors/{connector_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a Fleet connector effect: destructive questions: - How do I disconnect a Fleet server from authentik? - Is deleting a Fleet connector permanent? instructions: - text: Delete Fleet connector {connector_uuid}. slots: connector_uuid: path.connector_uuid - text: Remove the Fleet connector {connector_uuid}. slots: connector_uuid: path.connector_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/fleet/connectors/{connector_uuid}/'].patch update: x-apievangelist-phrasing: intent: Change part of a Fleet connector effect: write questions: - Can I just rotate the API token on a Fleet connector? - Is it possible to only toggle user mapping on a Fleet connector? instructions: - text: Only update the token of Fleet connector {connector_uuid} to {token}. slots: connector_uuid: path.connector_uuid token: requestBody.token - text: Set just map users on Fleet connector {connector_uuid} to {map_users}. slots: connector_uuid: path.connector_uuid map_users: requestBody.map_users method: generated generated: '2026-09-26' - target: $.paths['/endpoints/fleet/connectors/{connector_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a Fleet connector effect: read questions: - What depends on a particular Fleet connector? - Which objects reference this Fleet connector? instructions: - text: Show what references Fleet connector {connector_uuid}. slots: connector_uuid: path.connector_uuid - text: List objects using Fleet connector {connector_uuid}. slots: connector_uuid: path.connector_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/google_chrome/connectors/'].get update: x-apievangelist-phrasing: intent: List Google Chrome connectors effect: read questions: - Which Google Chrome device connectors are set up? - Can I find a Chrome connector by name? instructions: - text: List all Google Chrome connectors. - text: Show Google Chrome connectors named {name}. slots: name: query.name method: generated generated: '2026-09-26' - target: $.paths['/endpoints/google_chrome/connectors/'].post update: x-apievangelist-phrasing: intent: Create a Google Chrome connector effect: write questions: - How do I connect Google Chrome device data to authentik? - What credentials does a new Chrome connector need? instructions: - text: Create Google Chrome connector {name} with credentials {credentials}. slots: name: requestBody.name credentials: requestBody.credentials - text: 'Add a Chrome connector {name} using credentials {credentials}, enabled: {enabled}.' slots: name: requestBody.name credentials: requestBody.credentials enabled: requestBody.enabled method: generated generated: '2026-09-26' - target: $.paths['/endpoints/google_chrome/connectors/{connector_uuid}/'].get update: x-apievangelist-phrasing: intent: Get a Google Chrome connector effect: read questions: - What is configured on a specific Google Chrome connector? - Is this Chrome connector enabled? instructions: - text: Show Google Chrome connector {connector_uuid}. slots: connector_uuid: path.connector_uuid - text: Fetch the settings of Chrome connector {connector_uuid}. slots: connector_uuid: path.connector_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/google_chrome/connectors/{connector_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace a Google Chrome connector effect: write questions: - Can I overwrite a Chrome connector's name and credentials together? - What must I resend to fully replace a Google Chrome connector? instructions: - text: Replace Google Chrome connector {connector_uuid} as {name} with credentials {credentials}. slots: connector_uuid: path.connector_uuid name: requestBody.name credentials: requestBody.credentials - text: 'Overwrite the whole Chrome connector {connector_uuid}: name {name}, credentials {credentials}, enabled {enabled}.' slots: connector_uuid: path.connector_uuid name: requestBody.name credentials: requestBody.credentials enabled: requestBody.enabled method: generated generated: '2026-09-26' - target: $.paths['/endpoints/google_chrome/connectors/{connector_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a Google Chrome connector effect: destructive questions: - How do I remove a Google Chrome connector? - Is deleting a Chrome connector reversible? instructions: - text: Delete Google Chrome connector {connector_uuid}. slots: connector_uuid: path.connector_uuid - text: Remove the Chrome connector {connector_uuid}. slots: connector_uuid: path.connector_uuid method: generated generated: '2026-09-26' - target: $.paths['/endpoints/google_chrome/connectors/{connector_uuid}/'].patch update: x-apievangelist-phrasing: intent: Change part of a Google Chrome connector effect: write questions: - Can I just swap the credentials on a Chrome connector? - Is it possible to only disable a Google Chrome connector? instructions: - text: Only update credentials of Chrome connector {connector_uuid} to {credentials}. slots: connector_uuid: path.connector_uuid credentials: requestBody.credentials - text: Set just enabled on Google Chrome connector {connector_uuid} to {enabled}. slots: connector_uuid: path.connector_uuid enabled: requestBody.enabled method: generated generated: '2026-09-26' - target: $.paths['/endpoints/google_chrome/connectors/{connector_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a Google Chrome connector effect: read questions: - What depends on a given Google Chrome connector? - Which objects reference this Chrome connector? instructions: - text: Show what references Google Chrome connector {connector_uuid}. slots: connector_uuid: path.connector_uuid - text: List objects using Chrome connector {connector_uuid}. slots: connector_uuid: path.connector_uuid method: generated generated: '2026-09-26'