# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for authentik Policies API version: 1.0.0 extends: openapi/authentik-policies-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 76 - target: $.paths['/policies/all/'].get update: x-apievangelist-phrasing: intent: List policies of every type effect: read questions: - Which policies of any type exist in my authentik instance? - Can I find policies that are not bound to anything yet? - Which policies are not used by any prompt stage? instructions: - text: List all policies across every policy type. - text: Show policies of any type where unbound is {bindings__isnull}. slots: bindings__isnull: query.bindings__isnull - text: Search all policy types for {search}. slots: search: query.search method: generated generated: '2026-09-26' - target: $.paths['/policies/all/{policy_uuid}/'].get update: x-apievangelist-phrasing: intent: Get any policy by UUID effect: read questions: - What is a policy when I only know its UUID and not its type? - Can I look up a policy generically regardless of its kind? instructions: - text: Show policy {policy_uuid} whatever its type. slots: policy_uuid: path.policy_uuid - text: Look up the generic policy record {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/all/{policy_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a policy of any type effect: destructive questions: - Can I delete a policy by UUID without knowing which type it is? - Is there one endpoint that removes any kind of policy? instructions: - text: Delete policy {policy_uuid} regardless of its type. slots: policy_uuid: path.policy_uuid - text: Remove the generic policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/all/{policy_uuid}/test/'].post update: x-apievangelist-phrasing: intent: Test a policy against a user effect: read questions: - How do I check whether a policy would pass or fail for a particular user? - Can I dry-run a policy with extra context before binding it? instructions: - text: Test policy {policy_uuid} against user {user}. slots: policy_uuid: path.policy_uuid user: requestBody.user - text: Evaluate policy {policy_uuid} for user {user} with context {context}. slots: policy_uuid: path.policy_uuid user: requestBody.user context: requestBody.context method: generated generated: '2026-09-26' - target: $.paths['/policies/all/{policy_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a policy of any type effect: read questions: - Which flows, stages or apps reference a policy I only know by UUID? - What would break if I deleted this policy, whatever its type? instructions: - text: List objects that use policy {policy_uuid} of any type. slots: policy_uuid: path.policy_uuid - text: Show generic dependents of policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/all/cache_clear/'].post update: x-apievangelist-phrasing: intent: Clear the policy cache effect: destructive questions: - How do I flush cached policy results so changes take effect immediately? - Can I reset authentik's policy evaluation cache? instructions: - text: Clear the policy cache. - text: Flush all cached policy results. method: generated generated: '2026-09-26' - target: $.paths['/policies/all/cache_info/'].get update: x-apievangelist-phrasing: intent: Show policy cache statistics effect: read questions: - How many policy results are currently cached? - What does the policy cache hold right now? instructions: - text: Show info about cached policies. - text: Report how many policy results are in the cache. method: generated generated: '2026-09-26' - target: $.paths['/policies/all/types/'].get update: x-apievangelist-phrasing: intent: List creatable policy types effect: read questions: - What kinds of policies can I create in authentik? - Which policy types are available to add? instructions: - text: List all creatable policy types. - text: Show the policy types I can create. method: generated generated: '2026-09-26' - target: $.paths['/policies/bindings/'].get update: x-apievangelist-phrasing: intent: List policy bindings effect: read questions: - Which policies, users or groups are bound to a given flow or application? - Can I list only disabled policy bindings? - What bindings reference a particular policy? instructions: - text: List all policy bindings. - text: Show bindings attached to target {target}. slots: target: query.target - text: Find bindings for policy {policy} where enabled is {enabled}. slots: policy: query.policy enabled: query.enabled method: generated generated: '2026-09-26' - target: $.paths['/policies/bindings/'].post update: x-apievangelist-phrasing: intent: Bind a policy, user or group to a target effect: write questions: - How do I attach a policy to a flow or application? - Can I bind a group directly to a target instead of a policy? - Is it possible to negate a binding or set a timeout on it? instructions: - text: Bind policy {policy} to target {target} at order {order}. slots: policy: requestBody.policy target: requestBody.target order: requestBody.order - text: Bind group {group} to target {target} with order {order}. slots: group: requestBody.group target: requestBody.target order: requestBody.order - text: Create a negated binding of policy {policy} on {target} at order {order}, negate {negate}. slots: policy: requestBody.policy target: requestBody.target order: requestBody.order negate: requestBody.negate method: generated generated: '2026-09-26' - target: $.paths['/policies/bindings/{policy_binding_uuid}/'].get update: x-apievangelist-phrasing: intent: Get one policy binding effect: read questions: - What does a specific policy binding link together? - How do I see the order and timeout of one binding? instructions: - text: Show policy binding {policy_binding_uuid}. slots: policy_binding_uuid: path.policy_binding_uuid - text: Get the settings of binding {policy_binding_uuid}. slots: policy_binding_uuid: path.policy_binding_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/bindings/{policy_binding_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace a policy binding effect: write questions: - Can I fully redefine an existing binding with a new target and order? - Is there a full-replace call for a policy binding? instructions: - text: Replace binding {policy_binding_uuid} with target {target} and order {order}. slots: policy_binding_uuid: path.policy_binding_uuid target: requestBody.target order: requestBody.order - text: 'Overwrite binding {policy_binding_uuid}: policy {policy}, target {target}, order {order}.' slots: policy_binding_uuid: path.policy_binding_uuid policy: requestBody.policy target: requestBody.target order: requestBody.order method: generated generated: '2026-09-26' - target: $.paths['/policies/bindings/{policy_binding_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a policy binding effect: destructive questions: - How do I unbind a policy from a flow or application? - Can I delete a binding without deleting the policy itself? instructions: - text: Delete policy binding {policy_binding_uuid}. slots: policy_binding_uuid: path.policy_binding_uuid - text: Unbind by removing binding {policy_binding_uuid}. slots: policy_binding_uuid: path.policy_binding_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/bindings/{policy_binding_uuid}/'].patch update: x-apievangelist-phrasing: intent: Change individual fields of a binding effect: write questions: - Can I just disable a policy binding without redefining it? - Is it possible to change only a binding's order or timeout? instructions: - text: Set enabled to {enabled} on binding {policy_binding_uuid}. slots: policy_binding_uuid: path.policy_binding_uuid enabled: requestBody.enabled - text: Move binding {policy_binding_uuid} to order {order}. slots: policy_binding_uuid: path.policy_binding_uuid order: requestBody.order - text: Change the timeout of binding {policy_binding_uuid} to {timeout} seconds. slots: policy_binding_uuid: path.policy_binding_uuid timeout: requestBody.timeout method: generated generated: '2026-09-26' - target: $.paths['/policies/bindings/{policy_binding_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a policy binding effect: read questions: - Which objects reference a particular policy binding? - What depends on this binding before I remove it? instructions: - text: List objects that use binding {policy_binding_uuid}. slots: policy_binding_uuid: path.policy_binding_uuid - text: Show dependents of policy binding {policy_binding_uuid}. slots: policy_binding_uuid: path.policy_binding_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/dummy/'].get update: x-apievangelist-phrasing: intent: List dummy test policies effect: read questions: - Which dummy policies have I set up for testing flows? - Can I filter dummy policies by the result they return? instructions: - text: List all dummy policies. - text: Show dummy policies that return result {result}. slots: result: query.result method: generated generated: '2026-09-26' - target: $.paths['/policies/dummy/'].post update: x-apievangelist-phrasing: intent: Create a dummy test policy effect: write questions: - How do I create a placeholder policy that always passes or fails for testing? - Can a dummy policy wait a random time before returning? instructions: - text: Create a dummy policy {name} that returns {result}. slots: name: requestBody.name result: requestBody.result - text: Create dummy policy {name} waiting between {wait_min} and {wait_max} seconds. slots: name: requestBody.name wait_min: requestBody.wait_min wait_max: requestBody.wait_max method: generated generated: '2026-09-26' - target: $.paths['/policies/dummy/{policy_uuid}/'].get update: x-apievangelist-phrasing: intent: Get one dummy policy effect: read questions: - What result and wait times does a specific dummy policy use? - Can I view one dummy policy's settings by UUID? instructions: - text: Show dummy policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Get the result and wait range of dummy policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/dummy/{policy_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace a dummy policy effect: write questions: - Can I fully overwrite a dummy policy's configuration? - Is there a full-update call for dummy test policies? instructions: - text: Replace dummy policy {policy_uuid} with name {name} and result {result}. slots: policy_uuid: path.policy_uuid name: requestBody.name result: requestBody.result - text: Fully update dummy policy {policy_uuid}, naming it {name}. slots: policy_uuid: path.policy_uuid name: requestBody.name method: generated generated: '2026-09-26' - target: $.paths['/policies/dummy/{policy_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a dummy policy effect: destructive questions: - How do I remove a dummy test policy once testing is done? - Can I delete a dummy policy by UUID? instructions: - text: Delete dummy policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Remove the dummy test policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/dummy/{policy_uuid}/'].patch update: x-apievangelist-phrasing: intent: Change fields of a dummy policy effect: write questions: - Can I flip only the result of a dummy policy? - Is it possible to adjust just the wait range on a dummy policy? instructions: - text: Change dummy policy {policy_uuid} to return {result}. slots: policy_uuid: path.policy_uuid result: requestBody.result - text: Set dummy policy {policy_uuid} maximum wait to {wait_max} seconds. slots: policy_uuid: path.policy_uuid wait_max: requestBody.wait_max method: generated generated: '2026-09-26' - target: $.paths['/policies/dummy/{policy_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a dummy policy effect: read questions: - Which bindings or objects still reference a dummy policy? - What depends on this dummy test policy? instructions: - text: List objects that use dummy policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Show dependents of dummy test policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/event_matcher/'].get update: x-apievangelist-phrasing: intent: List event matcher policies effect: read questions: - Which event matcher policies are configured for notifications? - Can I find event matcher policies that match a given action or client IP? instructions: - text: List all event matcher policies. - text: Show event matcher policies for action {action}. slots: action: query.action - text: Find event matcher policies matching client IP {client_ip}. slots: client_ip: query.client_ip method: generated generated: '2026-09-26' - target: $.paths['/policies/event_matcher/'].post update: x-apievangelist-phrasing: intent: Create an event matcher policy effect: write questions: - How do I create a policy that matches specific events for alerts? - Can an event matcher policy match on app, model and client IP together? instructions: - text: Create event matcher policy {name} for action {action}. slots: name: requestBody.name action: requestBody.action - text: Create event matcher {name} matching app {app}, model {model} and client IP {client_ip}. slots: name: requestBody.name app: requestBody.app model: requestBody.model client_ip: requestBody.client_ip method: generated generated: '2026-09-26' - target: $.paths['/policies/event_matcher/{policy_uuid}/'].get update: x-apievangelist-phrasing: intent: Get one event matcher policy effect: read questions: - What events does a specific event matcher policy match? - Can I view one event matcher policy's criteria? instructions: - text: Show event matcher policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Get the match criteria of event matcher {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/event_matcher/{policy_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace an event matcher policy effect: write questions: - Can I fully redefine an event matcher policy's criteria? - Is there a full-replace call for event matcher policies? instructions: - text: Replace event matcher {policy_uuid} with name {name} and action {action}. slots: policy_uuid: path.policy_uuid name: requestBody.name action: requestBody.action - text: Fully update event matcher policy {policy_uuid}, named {name}, for app {app}. slots: policy_uuid: path.policy_uuid name: requestBody.name app: requestBody.app method: generated generated: '2026-09-26' - target: $.paths['/policies/event_matcher/{policy_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete an event matcher policy effect: destructive questions: - How do I remove an event matcher policy I no longer alert on? - Can I delete an event matcher policy by UUID? instructions: - text: Delete event matcher policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Remove the event matcher {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/event_matcher/{policy_uuid}/'].patch update: x-apievangelist-phrasing: intent: Change fields of an event matcher policy effect: write questions: - Can I change only the client IP an event matcher policy matches? - Is it possible to update just the query of an event matcher? instructions: - text: Change event matcher {policy_uuid} to match client IP {client_ip}. slots: policy_uuid: path.policy_uuid client_ip: requestBody.client_ip - text: Set the query on event matcher policy {policy_uuid} to {query}. slots: policy_uuid: path.policy_uuid query: requestBody.query method: generated generated: '2026-09-26' - target: $.paths['/policies/event_matcher/{policy_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses an event matcher policy effect: read questions: - Which notification rules or bindings reference an event matcher policy? - What depends on this event matcher? instructions: - text: List objects that use event matcher policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Show dependents of event matcher {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/expression/'].get update: x-apievangelist-phrasing: intent: List expression policies effect: read questions: - Which Python expression policies exist in authentik? - Can I search expression policies by the code they contain? instructions: - text: List all expression policies. - text: Find expression policies whose expression contains {expression}. slots: expression: query.expression method: generated generated: '2026-09-26' - target: $.paths['/policies/expression/'].post update: x-apievangelist-phrasing: intent: Create an expression policy effect: write questions: - How do I write a custom Python policy for access decisions? - Can I turn on execution logging for a new expression policy? instructions: - text: Create expression policy {name} with code {expression}. slots: name: requestBody.name expression: requestBody.expression - text: Add expression policy {name} running {expression} with execution logging {execution_logging}. slots: name: requestBody.name expression: requestBody.expression execution_logging: requestBody.execution_logging method: generated generated: '2026-09-26' - target: $.paths['/policies/expression/{policy_uuid}/'].get update: x-apievangelist-phrasing: intent: Get one expression policy effect: read questions: - What Python code does a specific expression policy run? - Can I view one expression policy by UUID? instructions: - text: Show expression policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Get the Python code of expression policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/expression/{policy_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace an expression policy effect: write questions: - Can I fully overwrite an expression policy's name and code? - Is there a full-replace call for expression policies? instructions: - text: Replace expression policy {policy_uuid} with name {name} and code {expression}. slots: policy_uuid: path.policy_uuid name: requestBody.name expression: requestBody.expression - text: Fully update expression policy {policy_uuid} to {name} running {expression}. slots: policy_uuid: path.policy_uuid name: requestBody.name expression: requestBody.expression method: generated generated: '2026-09-26' - target: $.paths['/policies/expression/{policy_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete an expression policy effect: destructive questions: - How do I remove a custom Python expression policy? - Can I delete an expression policy by UUID? instructions: - text: Delete expression policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Remove the Python expression policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/expression/{policy_uuid}/'].patch update: x-apievangelist-phrasing: intent: Edit an expression policy's code effect: write questions: - Can I change just the Python code of an expression policy? - Is it possible to toggle execution logging on an existing expression policy? instructions: - text: Change the code of expression policy {policy_uuid} to {expression}. slots: policy_uuid: path.policy_uuid expression: requestBody.expression - text: Set execution logging to {execution_logging} on expression policy {policy_uuid}. slots: policy_uuid: path.policy_uuid execution_logging: requestBody.execution_logging method: generated generated: '2026-09-26' - target: $.paths['/policies/expression/{policy_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses an expression policy effect: read questions: - Which flows or bindings reference a given expression policy? - What depends on this Python expression policy? instructions: - text: List objects that use expression policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Show dependents of Python expression policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/geoip/'].get update: x-apievangelist-phrasing: intent: List GeoIP policies effect: read questions: - Which GeoIP policies restrict logins by location? - Can I search GeoIP policies by name? instructions: - text: List all GeoIP policies. - text: Find GeoIP policies named {name}. slots: name: query.name method: generated generated: '2026-09-26' - target: $.paths['/policies/geoip/'].post update: x-apievangelist-phrasing: intent: Create a GeoIP policy effect: write questions: - How do I restrict sign-ins to certain countries? - Can a GeoIP policy block impossible travel between logins? - Is it possible to allow only specific ASNs? instructions: - text: Create GeoIP policy {name} allowing countries {countries}. slots: name: requestBody.name countries: requestBody.countries - text: Create GeoIP policy {name} for countries {countries} with impossible travel check {check_impossible_travel}. slots: name: requestBody.name countries: requestBody.countries check_impossible_travel: requestBody.check_impossible_travel - text: Create GeoIP policy {name} for countries {countries} and ASNs {asns}. slots: name: requestBody.name countries: requestBody.countries asns: requestBody.asns method: generated generated: '2026-09-26' - target: $.paths['/policies/geoip/{policy_uuid}/'].get update: x-apievangelist-phrasing: intent: Get one GeoIP policy effect: read questions: - Which countries and ASNs does a specific GeoIP policy cover? - Can I view one GeoIP policy's travel distance settings? instructions: - text: Show GeoIP policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Get the countries and distance settings of GeoIP policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/geoip/{policy_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace a GeoIP policy effect: write questions: - Can I fully redefine a GeoIP policy's name and countries? - Is there a full-replace call for GeoIP policies? instructions: - text: Replace GeoIP policy {policy_uuid} with name {name} and countries {countries}. slots: policy_uuid: path.policy_uuid name: requestBody.name countries: requestBody.countries - text: 'Fully update GeoIP policy {policy_uuid}: {name}, countries {countries}, ASNs {asns}.' slots: policy_uuid: path.policy_uuid name: requestBody.name countries: requestBody.countries asns: requestBody.asns method: generated generated: '2026-09-26' - target: $.paths['/policies/geoip/{policy_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a GeoIP policy effect: destructive questions: - How do I remove a location-based GeoIP restriction? - Can I delete a GeoIP policy by UUID? instructions: - text: Delete GeoIP policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Remove the location restriction GeoIP policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/geoip/{policy_uuid}/'].patch update: x-apievangelist-phrasing: intent: Change fields of a GeoIP policy effect: write questions: - Can I add countries to a GeoIP policy without redefining the rest? - Is it possible to change only the maximum travel distance on a GeoIP policy? instructions: - text: Set the allowed countries of GeoIP policy {policy_uuid} to {countries}. slots: policy_uuid: path.policy_uuid countries: requestBody.countries - text: Change GeoIP policy {policy_uuid} max history distance to {history_max_distance_km} km. slots: policy_uuid: path.policy_uuid history_max_distance_km: requestBody.history_max_distance_km method: generated generated: '2026-09-26' - target: $.paths['/policies/geoip/{policy_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a GeoIP policy effect: read questions: - Which flows or bindings reference a GeoIP policy? - What depends on this location policy? instructions: - text: List objects that use GeoIP policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Show dependents of location policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/geoip_iso3166/'].get update: x-apievangelist-phrasing: intent: List ISO 3166 country codes effect: read questions: - Which country codes can I use in a GeoIP policy? - What is the list of ISO-3166-1 countries authentik recognizes? instructions: - text: List all ISO-3166-1 countries. - text: Show the country codes available for GeoIP rules. method: generated generated: '2026-09-26' - target: $.paths['/policies/password/'].get update: x-apievangelist-phrasing: intent: List password strength policies effect: read questions: - Which password complexity policies are configured? - Can I find password policies that check against Have I Been Pwned? - Which password policies require a minimum length above a given value? instructions: - text: List all password strength policies. - text: Show password policies with HIBP check {check_have_i_been_pwned}. slots: check_have_i_been_pwned: query.check_have_i_been_pwned - text: Find password policies with minimum length {length_min}. slots: length_min: query.length_min method: generated generated: '2026-09-26' - target: $.paths['/policies/password/'].post update: x-apievangelist-phrasing: intent: Create a password strength policy effect: write questions: - How do I enforce a minimum password length and required symbols? - Can a password policy reject passwords found in breach databases? - Is a zxcvbn strength score threshold supported? instructions: - text: Create password policy {name} with minimum length {length_min}. slots: name: requestBody.name length_min: requestBody.length_min - text: Create password policy {name} requiring {amount_digits} digits and {amount_symbols} symbols. slots: name: requestBody.name amount_digits: requestBody.amount_digits amount_symbols: requestBody.amount_symbols - text: Create password policy {name} with zxcvbn check {check_zxcvbn} and threshold {zxcvbn_score_threshold}. slots: name: requestBody.name check_zxcvbn: requestBody.check_zxcvbn zxcvbn_score_threshold: requestBody.zxcvbn_score_threshold method: generated generated: '2026-09-26' - target: $.paths['/policies/password/{policy_uuid}/'].get update: x-apievangelist-phrasing: intent: Get one password strength policy effect: read questions: - What complexity rules does a specific password policy enforce? - Can I view one password policy's error message and checks? instructions: - text: Show password policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Get the complexity rules of password policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/password/{policy_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace a password strength policy effect: write questions: - Can I fully redefine all the rules of a password complexity policy? - Is there a full-replace call for password strength policies? instructions: - text: Replace password policy {policy_uuid} with name {name} and minimum length {length_min}. slots: policy_uuid: path.policy_uuid name: requestBody.name length_min: requestBody.length_min - text: Fully update password policy {policy_uuid} named {name}, requiring {amount_uppercase} uppercase letters. slots: policy_uuid: path.policy_uuid name: requestBody.name amount_uppercase: requestBody.amount_uppercase method: generated generated: '2026-09-26' - target: $.paths['/policies/password/{policy_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a password strength policy effect: destructive questions: - How do I remove a password complexity policy? - Can I delete a password strength policy by UUID? instructions: - text: Delete password policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Remove the password complexity policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/password/{policy_uuid}/'].patch update: x-apievangelist-phrasing: intent: Tweak rules of a password strength policy effect: write questions: - Can I raise only the minimum length on an existing password policy? - Is it possible to change just the error message users see on a weak password? instructions: - text: Raise the minimum length of password policy {policy_uuid} to {length_min}. slots: policy_uuid: path.policy_uuid length_min: requestBody.length_min - text: Set the error message of password policy {policy_uuid} to {error_message}. slots: policy_uuid: path.policy_uuid error_message: requestBody.error_message - text: Allow at most {hibp_allowed_count} breach hits on password policy {policy_uuid}. slots: policy_uuid: path.policy_uuid hibp_allowed_count: requestBody.hibp_allowed_count method: generated generated: '2026-09-26' - target: $.paths['/policies/password/{policy_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a password strength policy effect: read questions: - Which prompt stages or bindings reference a password complexity policy? - What depends on this password strength policy? instructions: - text: List objects that use password policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Show dependents of password complexity policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/password_expiry/'].get update: x-apievangelist-phrasing: intent: List password expiry policies effect: read questions: - Which password expiry policies force users to rotate passwords? - Can I filter expiry policies by the number of days? instructions: - text: List all password expiry policies. - text: Show password expiry policies with a {days}-day limit. slots: days: query.days method: generated generated: '2026-09-26' - target: $.paths['/policies/password_expiry/'].post update: x-apievangelist-phrasing: intent: Create a password expiry policy effect: write questions: - How do I make passwords expire after a set number of days? - Can an expiry policy only deny access instead of forcing a reset? instructions: - text: Create password expiry policy {name} expiring after {days} days. slots: name: requestBody.name days: requestBody.days - text: Create expiry policy {name} for {days} days with deny only {deny_only}. slots: name: requestBody.name days: requestBody.days deny_only: requestBody.deny_only method: generated generated: '2026-09-26' - target: $.paths['/policies/password_expiry/{policy_uuid}/'].get update: x-apievangelist-phrasing: intent: Get one password expiry policy effect: read questions: - After how many days does a specific expiry policy expire passwords? - Can I view one password expiry policy by UUID? instructions: - text: Show password expiry policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Get the day limit of expiry policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/password_expiry/{policy_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace a password expiry policy effect: write questions: - Can I fully redefine a password expiry policy's name and days? - Is there a full-replace call for expiry policies? instructions: - text: Replace expiry policy {policy_uuid} with name {name} and {days} days. slots: policy_uuid: path.policy_uuid name: requestBody.name days: requestBody.days - text: 'Fully update password expiry policy {policy_uuid}: {name}, {days} days, deny only {deny_only}.' slots: policy_uuid: path.policy_uuid name: requestBody.name days: requestBody.days deny_only: requestBody.deny_only method: generated generated: '2026-09-26' - target: $.paths['/policies/password_expiry/{policy_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a password expiry policy effect: destructive questions: - How do I stop forcing password rotation by removing an expiry policy? - Can I delete a password expiry policy by UUID? instructions: - text: Delete password expiry policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Remove the password rotation policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/password_expiry/{policy_uuid}/'].patch update: x-apievangelist-phrasing: intent: Change a password expiry period effect: write questions: - Can I change only the number of days before passwords expire? - Is it possible to switch an existing expiry policy to deny only? instructions: - text: Change expiry policy {policy_uuid} to {days} days. slots: policy_uuid: path.policy_uuid days: requestBody.days - text: Set deny only to {deny_only} on password expiry policy {policy_uuid}. slots: policy_uuid: path.policy_uuid deny_only: requestBody.deny_only method: generated generated: '2026-09-26' - target: $.paths['/policies/password_expiry/{policy_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a password expiry policy effect: read questions: - Which flows or bindings reference a password expiry policy? - What depends on this rotation policy? instructions: - text: List the bindings still referencing expiry rule {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Show dependents of rotation policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/reputation/'].get update: x-apievangelist-phrasing: intent: List reputation policies effect: read questions: - Which reputation policies block suspicious IPs or usernames? - Can I filter reputation policies by their score threshold? instructions: - text: List all reputation policies. - text: Show reputation policies with threshold {threshold}. slots: threshold: query.threshold method: generated generated: '2026-09-26' - target: $.paths['/policies/reputation/'].post update: x-apievangelist-phrasing: intent: Create a reputation policy effect: write questions: - How do I block logins from IPs with a bad reputation score? - Can a reputation policy check usernames as well as IPs? instructions: - text: Create reputation policy {name} with threshold {threshold}. slots: name: requestBody.name threshold: requestBody.threshold - text: Create reputation policy {name} checking IP {check_ip} and username {check_username}. slots: name: requestBody.name check_ip: requestBody.check_ip check_username: requestBody.check_username method: generated generated: '2026-09-26' - target: $.paths['/policies/reputation/{policy_uuid}/'].get update: x-apievangelist-phrasing: intent: Get one reputation policy effect: read questions: - What threshold does a specific reputation policy use? - Can I view one reputation policy's IP and username checks? instructions: - text: Show reputation policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Get the threshold and checks of reputation policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/reputation/{policy_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace a reputation policy effect: write questions: - Can I fully redefine a reputation policy? - Is there a full-replace call for reputation policies? instructions: - text: Replace reputation policy {policy_uuid} with name {name} and threshold {threshold}. slots: policy_uuid: path.policy_uuid name: requestBody.name threshold: requestBody.threshold - text: Fully update reputation policy {policy_uuid}, naming it {name}. slots: policy_uuid: path.policy_uuid name: requestBody.name method: generated generated: '2026-09-26' - target: $.paths['/policies/reputation/{policy_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a reputation policy effect: destructive questions: - How do I remove a reputation-based blocking policy? - Can I delete a reputation policy by UUID? instructions: - text: Delete reputation policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Remove the reputation blocking policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/reputation/{policy_uuid}/'].patch update: x-apievangelist-phrasing: intent: Change a reputation policy's threshold effect: write questions: - Can I adjust only the score threshold of a reputation policy? - Is it possible to stop a reputation policy checking usernames? instructions: - text: Change reputation policy {policy_uuid} threshold to {threshold}. slots: policy_uuid: path.policy_uuid threshold: requestBody.threshold - text: Set username checking to {check_username} on reputation policy {policy_uuid}. slots: policy_uuid: path.policy_uuid check_username: requestBody.check_username method: generated generated: '2026-09-26' - target: $.paths['/policies/reputation/{policy_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a reputation policy effect: read questions: - Which flows or bindings reference a reputation policy? - What depends on this reputation blocking policy? instructions: - text: List objects that use reputation policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Show dependents of reputation blocking policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/reputation/scores/'].get update: x-apievangelist-phrasing: intent: List reputation scores effect: read questions: - Which IPs or usernames have accumulated bad reputation scores? - Can I look up the reputation score for a specific IP address? instructions: - text: List all recorded reputation scores. - text: Show the reputation score for IP {ip}. slots: ip: query.ip - text: Find reputation scores for identifier {identifier}. slots: identifier: query.identifier method: generated generated: '2026-09-26' - target: $.paths['/policies/reputation/scores/{reputation_uuid}/'].get update: x-apievangelist-phrasing: intent: Get one reputation score record effect: read questions: - What is the detail of one reputation score entry? - Can I view a single IP or username score record by UUID? instructions: - text: Show reputation score record {reputation_uuid}. slots: reputation_uuid: path.reputation_uuid - text: Get the score entry {reputation_uuid}. slots: reputation_uuid: path.reputation_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/reputation/scores/{reputation_uuid}/'].delete update: x-apievangelist-phrasing: intent: Reset a reputation score effect: destructive questions: - How do I clear a bad reputation score so a user or IP can log in again? - Can I delete a single reputation score entry? instructions: - text: Delete reputation score {reputation_uuid}. slots: reputation_uuid: path.reputation_uuid - text: Reset the reputation of score entry {reputation_uuid}. slots: reputation_uuid: path.reputation_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/reputation/scores/{reputation_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a reputation score effect: read questions: - Which objects reference a given reputation score record? - What depends on this score entry? instructions: - text: List objects that use reputation score {reputation_uuid}. slots: reputation_uuid: path.reputation_uuid - text: Show dependents of score entry {reputation_uuid}. slots: reputation_uuid: path.reputation_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/unique_password/'].get update: x-apievangelist-phrasing: intent: List password uniqueness policies effect: read questions: - Which policies stop users from reusing old passwords? - Can I filter password uniqueness policies by how many past passwords they remember? instructions: - text: List all password uniqueness policies. - text: Show uniqueness policies remembering {num_historical_passwords} past passwords. slots: num_historical_passwords: query.num_historical_passwords method: generated generated: '2026-09-26' - target: $.paths['/policies/unique_password/'].post update: x-apievangelist-phrasing: intent: Create a password uniqueness policy effect: write questions: - How do I prevent users from reusing their recent passwords? - Can I set how many previous passwords are checked for reuse? instructions: - text: Create password uniqueness policy {name}. slots: name: requestBody.name - text: Create uniqueness policy {name} blocking reuse of the last {num_historical_passwords} passwords. slots: name: requestBody.name num_historical_passwords: requestBody.num_historical_passwords method: generated generated: '2026-09-26' - target: $.paths['/policies/unique_password/{policy_uuid}/'].get update: x-apievangelist-phrasing: intent: Get one password uniqueness policy effect: read questions: - How many past passwords does a specific uniqueness policy remember? - Can I view one password reuse policy by UUID? instructions: - text: Show password uniqueness policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Get the history depth of reuse policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/unique_password/{policy_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace a password uniqueness policy effect: write questions: - Can I fully redefine a password reuse policy? - Is there a full-replace call for password uniqueness policies? instructions: - text: Replace uniqueness policy {policy_uuid} with name {name}. slots: policy_uuid: path.policy_uuid name: requestBody.name - text: 'Fully update reuse policy {policy_uuid}: {name}, remembering {num_historical_passwords} passwords.' slots: policy_uuid: path.policy_uuid name: requestBody.name num_historical_passwords: requestBody.num_historical_passwords method: generated generated: '2026-09-26' - target: $.paths['/policies/unique_password/{policy_uuid}/'].delete update: x-apievangelist-phrasing: intent: Delete a password uniqueness policy effect: destructive questions: - How do I allow password reuse again by removing a uniqueness policy? - Can I delete a password reuse policy by UUID? instructions: - text: Delete password uniqueness policy {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Remove the password reuse policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26' - target: $.paths['/policies/unique_password/{policy_uuid}/'].patch update: x-apievangelist-phrasing: intent: Change password history depth effect: write questions: - Can I change only how many previous passwords a reuse policy checks? - Is it possible to point a uniqueness policy at a different password field? instructions: - text: Set reuse policy {policy_uuid} to remember {num_historical_passwords} passwords. slots: policy_uuid: path.policy_uuid num_historical_passwords: requestBody.num_historical_passwords - text: Change the password field of uniqueness policy {policy_uuid} to {password_field}. slots: policy_uuid: path.policy_uuid password_field: requestBody.password_field method: generated generated: '2026-09-26' - target: $.paths['/policies/unique_password/{policy_uuid}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a password uniqueness policy effect: read questions: - Which prompt stages or bindings reference a password reuse policy? - What depends on this uniqueness policy? instructions: - text: Find every binding tied to the no-reuse rule {policy_uuid}. slots: policy_uuid: path.policy_uuid - text: Show dependents of reuse policy {policy_uuid}. slots: policy_uuid: path.policy_uuid method: generated generated: '2026-09-26'