# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for authentik Oauth2 API version: 1.0.0 extends: openapi/authentik-oauth2-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 12 - target: $.paths['/oauth2/access_tokens/'].get update: x-apievangelist-phrasing: intent: List issued OAuth2 access tokens effect: read questions: - Which OAuth2 access tokens has authentik issued to a given user? - Can I see the access tokens handed out by one specific OAuth2 provider? instructions: - text: List all OAuth2 access tokens. - text: Show OAuth2 access tokens issued to user {user}. slots: user: query.user - text: List access tokens issued by OAuth2 provider {provider}. slots: provider: query.provider method: generated generated: '2026-09-26' - target: $.paths['/oauth2/access_tokens/{id}/'].get update: x-apievangelist-phrasing: intent: Get one OAuth2 access token effect: read questions: - Which user and provider does a particular access token belong to? - Where can I inspect a single issued OAuth2 access token by its ID? instructions: - text: Show the details of access token {id}. slots: id: path.id - text: Look up OAuth2 access token {id} and tell me who it belongs to. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/oauth2/access_tokens/{id}/'].delete update: x-apievangelist-phrasing: intent: Revoke an OAuth2 access token effect: destructive questions: - How do I kill an access token that was leaked? - Can I delete a single OAuth2 access token without touching the user's refresh token? instructions: - text: Delete access token {id}. slots: id: path.id - text: Revoke OAuth2 access token {id} right away. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/oauth2/access_tokens/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what references an access token effect: read questions: - Is anything in authentik still referencing this access token? - Which objects would be affected if I removed a given OAuth2 access token? instructions: - text: List objects that use access token {id}. slots: id: path.id - text: Check what depends on OAuth2 access token {id} before I delete it. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/oauth2/authorization_codes/'].get update: x-apievangelist-phrasing: intent: List OAuth2 authorization codes effect: read questions: - Which authorization codes are outstanding for a user? - Can I filter pending OAuth2 authorization codes by provider? instructions: - text: List all OAuth2 authorization codes. - text: Show authorization codes issued to user {user}. slots: user: query.user - text: List authorization codes for OAuth2 provider {provider}. slots: provider: query.provider method: generated generated: '2026-09-26' - target: $.paths['/oauth2/authorization_codes/{id}/'].get update: x-apievangelist-phrasing: intent: Get one OAuth2 authorization code effect: read questions: - Which user and client is a specific authorization code tied to? - Where can I view one OAuth2 authorization code by its ID? instructions: - text: Show authorization code {id}. slots: id: path.id - text: Get the details of OAuth2 authorization code {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/oauth2/authorization_codes/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete an OAuth2 authorization code effect: destructive questions: - Can I invalidate an authorization code before a client exchanges it? - What is the way to delete an unused OAuth2 authorization code? instructions: - text: Delete authorization code {id}. slots: id: path.id - text: Invalidate OAuth2 authorization code {id} so it can't be redeemed. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/oauth2/authorization_codes/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what references an authorization code effect: read questions: - Which objects still point at a given authorization code? - Is an OAuth2 authorization code referenced by anything else in authentik? instructions: - text: List objects that use authorization code {id}. slots: id: path.id - text: Show what depends on OAuth2 authorization code {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/oauth2/refresh_tokens/'].get update: x-apievangelist-phrasing: intent: List OAuth2 refresh tokens effect: read questions: - Which long-lived refresh tokens does a user currently hold? - Can I list the refresh tokens issued by one OAuth2 provider? instructions: - text: List all OAuth2 refresh tokens. - text: Show refresh tokens belonging to user {user}. slots: user: query.user - text: List refresh tokens issued by OAuth2 provider {provider}. slots: provider: query.provider method: generated generated: '2026-09-26' - target: $.paths['/oauth2/refresh_tokens/{id}/'].get update: x-apievangelist-phrasing: intent: Get one OAuth2 refresh token effect: read questions: - Which provider issued a particular refresh token, and to whom? - Where do I view a single OAuth2 refresh token by its ID? instructions: - text: Show refresh token {id}. slots: id: path.id - text: Get the details of OAuth2 refresh token {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/oauth2/refresh_tokens/{id}/'].delete update: x-apievangelist-phrasing: intent: Revoke an OAuth2 refresh token effect: destructive questions: - How do I stop a client from minting new access tokens with a refresh token? - Can I delete one user's OAuth2 refresh token to force them to sign in again? instructions: - text: Delete refresh token {id}. slots: id: path.id - text: Revoke OAuth2 refresh token {id} now. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/oauth2/refresh_tokens/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what references a refresh token effect: read questions: - Which objects are linked to a specific refresh token? - Does anything else in authentik depend on this OAuth2 refresh token? instructions: - text: List objects that use refresh token {id}. slots: id: path.id - text: Check what depends on OAuth2 refresh token {id} before revoking it. slots: id: path.id method: generated generated: '2026-09-26'