# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for authentik Outposts API version: 1.0.0 extends: openapi/authentik-outposts-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 34 - target: $.paths['/outposts/instances/'].get update: x-apievangelist-phrasing: intent: List outposts effect: read questions: - Which outposts are deployed in my authentik instance? - Can I find outposts that have no providers attached? - Is there a way to filter outposts by the service connection they run on? instructions: - text: List all outposts. - text: Search outposts by name for {search}. slots: search: query.search - text: Show outposts running on service connection {service_connection__name__iexact}. slots: service_connection__name__iexact: query.service_connection__name__iexact method: generated generated: '2026-09-26' - target: $.paths['/outposts/instances/'].post update: x-apievangelist-phrasing: intent: Create an outpost effect: write questions: - How do I deploy a new proxy or LDAP outpost in authentik? - Can I attach several providers to a single new outpost? instructions: - text: Create a {type} outpost named {name} serving providers {providers} with config {config}. slots: type: requestBody.type name: requestBody.name providers: requestBody.providers config: requestBody.config - text: Set up outpost {name} of type {type} for providers {providers} on service connection {service_connection} using config {config}. slots: name: requestBody.name type: requestBody.type providers: requestBody.providers service_connection: requestBody.service_connection config: requestBody.config method: generated generated: '2026-09-26' - target: $.paths['/outposts/instances/{uuid}/'].get update: x-apievangelist-phrasing: intent: Get an outpost's details effect: read questions: - What providers and config does one specific outpost have? - Where can I look up a single outpost by its UUID? instructions: - text: Show outpost {uuid}. slots: uuid: path.uuid - text: Get the configuration of outpost {uuid}. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/outposts/instances/{uuid}/'].put update: x-apievangelist-phrasing: intent: Replace an outpost's settings effect: write questions: - Can I overwrite an outpost's whole definition, including name, type, providers and config, in one call? - What is required to fully replace an existing outpost's configuration? instructions: - text: Replace outpost {uuid} with name {name}, type {type}, providers {providers} and config {config}. slots: uuid: path.uuid name: requestBody.name type: requestBody.type providers: requestBody.providers config: requestBody.config - text: Fully redefine outpost {uuid} as {name} of type {type} serving {providers} with config {config}. slots: uuid: path.uuid name: requestBody.name type: requestBody.type providers: requestBody.providers config: requestBody.config method: generated generated: '2026-09-26' - target: $.paths['/outposts/instances/{uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete an outpost effect: destructive questions: - How do I remove an outpost I no longer run? - Can I decommission an outpost from authentik entirely? instructions: - text: Delete outpost {uuid}. slots: uuid: path.uuid - text: Remove outpost {uuid} permanently. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/outposts/instances/{uuid}/'].patch update: x-apievangelist-phrasing: intent: Change some outpost settings effect: write questions: - Can I just rename an outpost without resending its config? - Is it possible to add providers to an existing outpost by changing only that field? instructions: - text: Rename outpost {uuid} to {name}. slots: uuid: path.uuid name: requestBody.name - text: Change the providers on outpost {uuid} to {providers}. slots: uuid: path.uuid providers: requestBody.providers - text: Move outpost {uuid} onto service connection {service_connection}. slots: uuid: path.uuid service_connection: requestBody.service_connection method: generated generated: '2026-09-26' - target: $.paths['/outposts/instances/{uuid}/health/'].get update: x-apievangelist-phrasing: intent: Check an outpost's current health effect: read questions: - Is my outpost connected and healthy right now? - What version are my outpost instances running and when did they last check in? instructions: - text: Show the health of outpost {uuid}. slots: uuid: path.uuid - text: Check whether outpost {uuid} is up and reporting in. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/outposts/instances/{uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses an outpost effect: read questions: - Which objects depend on a given outpost? - Will anything break if I delete this outpost? instructions: - text: List objects that use outpost {uuid}. slots: uuid: path.uuid - text: Show what references outpost {uuid} before I remove it. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/outposts/instances/default_settings/'].get update: x-apievangelist-phrasing: intent: Get the global default outpost config effect: read questions: - What default configuration does authentik apply to new outposts? - Where can I see the baseline outpost config settings? instructions: - text: Show the global default outpost configuration. - text: Get the default settings new outposts start with. method: generated generated: '2026-09-26' - target: $.paths['/outposts/ldap/'].get update: x-apievangelist-phrasing: intent: List LDAP providers served by outposts effect: read questions: - Which LDAP providers is my LDAP outpost serving? - Can I search the LDAP providers visible to outposts by name? instructions: - text: List LDAP providers for outposts. - text: Find the outpost LDAP provider named {name}. slots: name: query.name method: generated generated: '2026-09-26' - target: $.paths['/outposts/ldap/{id}/check_access/'].get update: x-apievangelist-phrasing: intent: Check LDAP access to an application effect: read questions: - Is the current user allowed to bind to an application through the LDAP outpost? - Can I verify LDAP access to an app by its slug? instructions: - text: Check LDAP provider {id} access to application {app_slug}. slots: id: path.id app_slug: query.app_slug - text: Verify whether LDAP provider {id} grants access. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/outposts/proxy/'].get update: x-apievangelist-phrasing: intent: List proxy providers served by outposts effect: read questions: - Which proxy providers does my proxy outpost pick up? - Can I search the proxy providers available to outposts by name? instructions: - text: List proxy providers for outposts. - text: Find the outpost proxy provider named {name}. slots: name: query.name method: generated generated: '2026-09-26' - target: $.paths['/outposts/radius/'].get update: x-apievangelist-phrasing: intent: List RADIUS providers served by outposts effect: read questions: - Which RADIUS providers does the RADIUS outpost serve? - Can I look up RADIUS providers for outposts by name? instructions: - text: List RADIUS providers for outposts. - text: Find the outpost RADIUS provider named {name}. slots: name: query.name method: generated generated: '2026-09-26' - target: $.paths['/outposts/radius/{id}/check_access/'].get update: x-apievangelist-phrasing: intent: Check RADIUS access to an application effect: read questions: - Does the user have access to an application over RADIUS? - Can I test RADIUS access to an app by its slug? instructions: - text: Check RADIUS provider {id} access to application {app_slug}. slots: id: path.id app_slug: query.app_slug - text: Verify whether RADIUS provider {id} grants access. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/outposts/service_connections/all/'].get update: x-apievangelist-phrasing: intent: List all outpost service connections effect: read questions: - Which Docker and Kubernetes service connections exist across authentik? - Can I search every outpost integration regardless of type by name? instructions: - text: List all service connections of every type. - text: Search all service connections for {search}. slots: search: query.search method: generated generated: '2026-09-26' - target: $.paths['/outposts/service_connections/all/{uuid}/'].get update: x-apievangelist-phrasing: intent: Get any service connection by ID effect: read questions: - What are the details of a service connection when I don't know if it's Docker or Kubernetes? - Where can I look up a generic outpost integration by UUID? instructions: - text: Show service connection {uuid}. slots: uuid: path.uuid - text: Get the generic details of outpost integration {uuid}. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/outposts/service_connections/all/{uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete any service connection effect: destructive questions: - Can I remove a service connection without knowing whether it's Docker or Kubernetes? - What endpoint deletes an outpost integration of any type? instructions: - text: Delete service connection {uuid}. slots: uuid: path.uuid - text: Remove outpost integration {uuid} whatever its type. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/outposts/service_connections/all/{uuid}/state/'].get update: x-apievangelist-phrasing: intent: Check a service connection's state effect: read questions: - Is my service connection healthy and reachable? - What version of Docker or Kubernetes is a service connection talking to? instructions: - text: Show the state of service connection {uuid}. slots: uuid: path.uuid - text: Check whether service connection {uuid} is reachable. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/outposts/service_connections/all/{uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a service connection effect: read questions: - Which outposts rely on a given service connection? - Is any object still referencing this outpost integration? instructions: - text: List objects that use service connection {uuid}. slots: uuid: path.uuid - text: Show what depends on outpost integration {uuid}. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/outposts/service_connections/all/types/'].get update: x-apievangelist-phrasing: intent: List creatable service connection types effect: read questions: - What kinds of outpost integrations can I create? - Which service connection types does authentik support? instructions: - text: List the service connection types I can create. - text: Show available outpost integration types. method: generated generated: '2026-09-26' - target: $.paths['/outposts/service_connections/docker/'].get update: x-apievangelist-phrasing: intent: List Docker service connections effect: read questions: - Which Docker integrations are configured for outposts? - Can I find Docker connections that have TLS verification turned on? - Is there a way to list only the local Docker socket connections? instructions: - text: List Docker service connections. - text: Find Docker service connections pointing at {url}. slots: url: query.url - text: Show Docker connections where local is {local}. slots: local: query.local method: generated generated: '2026-09-26' - target: $.paths['/outposts/service_connections/docker/'].post update: x-apievangelist-phrasing: intent: Add a Docker service connection effect: write questions: - How do I connect authentik to a Docker host so it can deploy outposts? - Can I use the local Docker socket instead of a remote URL? instructions: - text: Create Docker service connection {name} at {url}. slots: name: requestBody.name url: requestBody.url - text: Add Docker connection {name} for {url} using TLS verification certificate {tls_verification}. slots: name: requestBody.name url: requestBody.url tls_verification: requestBody.tls_verification method: generated generated: '2026-09-26' - target: $.paths['/outposts/service_connections/docker/{uuid}/'].get update: x-apievangelist-phrasing: intent: Get a Docker service connection effect: read questions: - What URL and TLS settings does a specific Docker integration use? - Where can I view one Docker service connection? instructions: - text: Show Docker service connection {uuid}. slots: uuid: path.uuid - text: Get the Docker integration settings for {uuid}. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/outposts/service_connections/docker/{uuid}/'].put update: x-apievangelist-phrasing: intent: Replace a Docker service connection effect: write questions: - Can I overwrite a Docker connection's name and URL together? - What must I send to fully replace a Docker integration? instructions: - text: Replace Docker connection {uuid} with name {name} and URL {url}. slots: uuid: path.uuid name: requestBody.name url: requestBody.url - text: Fully redefine Docker integration {uuid} as {name} at {url} with TLS auth cert {tls_authentication}. slots: uuid: path.uuid name: requestBody.name url: requestBody.url tls_authentication: requestBody.tls_authentication method: generated generated: '2026-09-26' - target: $.paths['/outposts/service_connections/docker/{uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a Docker service connection effect: destructive questions: - How can I remove a Docker integration I stopped using? - Can I delete one Docker service connection by its ID? instructions: - text: Delete Docker service connection {uuid}. slots: uuid: path.uuid - text: Remove Docker integration {uuid}. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/outposts/service_connections/docker/{uuid}/'].patch update: x-apievangelist-phrasing: intent: Change some Docker connection settings effect: write questions: - Can I switch just the URL on an existing Docker connection? - Is it possible to change only the TLS certificates on a Docker integration? instructions: - text: Point Docker connection {uuid} at {url}. slots: uuid: path.uuid url: requestBody.url - text: Set TLS verification certificate {tls_verification} on Docker connection {uuid}. slots: uuid: path.uuid tls_verification: requestBody.tls_verification method: generated generated: '2026-09-26' - target: $.paths['/outposts/service_connections/docker/{uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a Docker connection effect: read questions: - Which outposts are deployed through a given Docker integration? - Does anything still depend on this Docker service connection? instructions: - text: List objects that use Docker connection {uuid}. slots: uuid: path.uuid - text: Show what references Docker integration {uuid}. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/outposts/service_connections/kubernetes/'].get update: x-apievangelist-phrasing: intent: List Kubernetes service connections effect: read questions: - Which Kubernetes clusters is authentik connected to for outposts? - Can I list only the in-cluster local Kubernetes connections? instructions: - text: List Kubernetes service connections. - text: Find the Kubernetes connection named {name}. slots: name: query.name method: generated generated: '2026-09-26' - target: $.paths['/outposts/service_connections/kubernetes/'].post update: x-apievangelist-phrasing: intent: Add a Kubernetes service connection effect: write questions: - How do I let authentik deploy outposts into a Kubernetes cluster? - Can I connect a cluster by pasting a kubeconfig? instructions: - text: Create Kubernetes service connection {name}. slots: name: requestBody.name - text: Add Kubernetes connection {name} using kubeconfig {kubeconfig}. slots: name: requestBody.name kubeconfig: requestBody.kubeconfig method: generated generated: '2026-09-26' - target: $.paths['/outposts/service_connections/kubernetes/{uuid}/'].get update: x-apievangelist-phrasing: intent: Get a Kubernetes service connection effect: read questions: - What settings does a specific Kubernetes integration have? - Where can I view one Kubernetes service connection? instructions: - text: Show Kubernetes service connection {uuid}. slots: uuid: path.uuid - text: Get the Kubernetes integration details for {uuid}. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/outposts/service_connections/kubernetes/{uuid}/'].put update: x-apievangelist-phrasing: intent: Replace a Kubernetes service connection effect: write questions: - Can I overwrite a Kubernetes connection's name and kubeconfig at once? - What does fully replacing a Kubernetes integration require? instructions: - text: Replace Kubernetes connection {uuid} with name {name}. slots: uuid: path.uuid name: requestBody.name - text: Fully redefine Kubernetes integration {uuid} as {name} with kubeconfig {kubeconfig}. slots: uuid: path.uuid name: requestBody.name kubeconfig: requestBody.kubeconfig method: generated generated: '2026-09-26' - target: $.paths['/outposts/service_connections/kubernetes/{uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a Kubernetes service connection effect: destructive questions: - How can I disconnect authentik from a Kubernetes cluster? - Can I delete one Kubernetes service connection by its ID? instructions: - text: Delete Kubernetes service connection {uuid}. slots: uuid: path.uuid - text: Remove Kubernetes integration {uuid}. slots: uuid: path.uuid method: generated generated: '2026-09-26' - target: $.paths['/outposts/service_connections/kubernetes/{uuid}/'].patch update: x-apievangelist-phrasing: intent: Change some Kubernetes connection settings effect: write questions: - Can I rotate just the kubeconfig on an existing Kubernetes connection? - Is it possible to turn off SSL verification for a Kubernetes integration only? instructions: - text: Swap the kubeconfig on Kubernetes connection {uuid} for {kubeconfig}. slots: uuid: path.uuid kubeconfig: requestBody.kubeconfig - text: Set SSL verification on Kubernetes connection {uuid} to {verify_ssl}. slots: uuid: path.uuid verify_ssl: requestBody.verify_ssl method: generated generated: '2026-09-26' - target: $.paths['/outposts/service_connections/kubernetes/{uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a Kubernetes connection effect: read questions: - Which outposts are deployed through a given Kubernetes integration? - Does anything still depend on this Kubernetes service connection? instructions: - text: List objects that use Kubernetes connection {uuid}. slots: uuid: path.uuid - text: Show what references Kubernetes integration {uuid}. slots: uuid: path.uuid method: generated generated: '2026-09-26'