# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for authentik Providers API version: 1.0.0 extends: openapi/authentik-providers-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 131 - target: $.paths['/providers/all/'].get update: x-apievangelist-phrasing: intent: List all providers of every type effect: read questions: - Which providers of any type are configured in my authentik instance? - Can I see only backchannel providers, or exclude them from the full provider list? - Are there providers not yet attached to any application? instructions: - text: List every provider across all protocol types. - text: Search all providers for {search}. slots: search: query.search - text: Show all providers with backchannel set to {backchannel}. slots: backchannel: query.backchannel method: generated generated: '2026-09-26' - target: $.paths['/providers/all/{id}/'].get update: x-apievangelist-phrasing: intent: Get any provider by ID effect: read questions: - What type of provider is a given provider ID, whatever its protocol? - Can I look up a provider generically without knowing if it is OAuth2, SAML or LDAP? instructions: - text: Get provider {id} from the generic all-providers endpoint. slots: id: path.id - text: Show the basic details of provider {id} regardless of its type. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/all/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a provider of any type effect: destructive questions: - Can I delete a provider without knowing which protocol type it is? - What happens when I remove a provider through the generic provider endpoint? instructions: - text: Delete provider {id} via the all-providers endpoint. slots: id: path.id - text: Remove provider {id}, whatever its type. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/all/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what depends on a provider effect: read questions: - What objects reference a provider before I delete it, whatever its type? - Is any application still using this provider from the generic list? instructions: - text: List everything that uses provider {id} via the generic provider endpoint. slots: id: path.id - text: Show the dependents of provider {id} before I remove it. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/all/types/'].get update: x-apievangelist-phrasing: intent: List creatable provider types effect: read questions: - What kinds of providers can I create in authentik? - Which provider protocols are available to add, like OAuth2, SAML or proxy? instructions: - text: List all the provider types I can create. - text: Show me the available provider type options. method: generated generated: '2026-09-26' - target: $.paths['/providers/google_workspace/'].get update: x-apievangelist-phrasing: intent: List Google Workspace providers effect: read questions: - Which Google Workspace sync providers have I set up? - Can I filter Google Workspace providers by the delegated admin subject? instructions: - text: List my Google Workspace providers. - text: Find Google Workspace providers delegated to {delegated_subject}. slots: delegated_subject: query.delegated_subject - text: Show Google Workspace providers named {name}. slots: name: query.name method: generated generated: '2026-09-26' - target: $.paths['/providers/google_workspace/'].post update: x-apievangelist-phrasing: intent: Create a Google Workspace provider effect: write questions: - How do I sync authentik users and groups into Google Workspace? - What credentials and delegated subject does a new Google Workspace provider need? - Can I run a new Google Workspace provider in dry-run mode first? instructions: - text: Create Google Workspace provider {name} as {delegated_subject} with credentials {credentials}, group domain {default_group_email_domain}. slots: name: requestBody.name delegated_subject: requestBody.delegated_subject credentials: requestBody.credentials default_group_email_domain: requestBody.default_group_email_domain - text: Set up Google sync {name}, dry run {dry_run}, impersonating {delegated_subject}, key {credentials}, domain {default_group_email_domain}. slots: name: requestBody.name dry_run: requestBody.dry_run delegated_subject: requestBody.delegated_subject credentials: requestBody.credentials default_group_email_domain: requestBody.default_group_email_domain method: generated generated: '2026-09-26' - target: $.paths['/providers/google_workspace/{id}/'].get update: x-apievangelist-phrasing: intent: Get a Google Workspace provider effect: read questions: - What settings does a specific Google Workspace provider use for user deletion? - Which OAuth scopes is my Google Workspace provider configured with? instructions: - text: Get Google Workspace provider {id}. slots: id: path.id - text: Show the configuration of Google Workspace provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/google_workspace/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a Google Workspace provider's config effect: write questions: - Can I fully replace the configuration of an existing Google Workspace provider? - How do I swap the service account credentials on a Google Workspace provider? instructions: - text: Replace Google Workspace provider {id} with name {name}, subject {delegated_subject}, credentials {credentials}, domain {default_group_email_domain}. slots: id: path.id name: requestBody.name delegated_subject: requestBody.delegated_subject credentials: requestBody.credentials default_group_email_domain: requestBody.default_group_email_domain - text: 'Overwrite Google Workspace provider {id}: {name}, key {credentials}, subject {delegated_subject}, domain {default_group_email_domain}.' slots: id: path.id name: requestBody.name credentials: requestBody.credentials delegated_subject: requestBody.delegated_subject default_group_email_domain: requestBody.default_group_email_domain method: generated generated: '2026-09-26' - target: $.paths['/providers/google_workspace/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a Google Workspace provider effect: destructive questions: - Can I remove a Google Workspace sync provider I no longer need? - Does deleting a Google Workspace provider stop syncing to Google? instructions: - text: Delete Google Workspace provider {id}. slots: id: path.id - text: Remove the Google Workspace sync provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/google_workspace/{id}/'].patch update: x-apievangelist-phrasing: intent: Update some Google Workspace provider settings effect: write questions: - Can I turn off dry-run on a Google Workspace provider without resending everything? - How do I change only the group filter on my Google Workspace provider? instructions: - text: Set dry run to {dry_run} on Google Workspace provider {id}. slots: id: path.id dry_run: requestBody.dry_run - text: Change the user delete action on Google Workspace provider {id} to {user_delete_action}. slots: id: path.id user_delete_action: requestBody.user_delete_action method: generated generated: '2026-09-26' - target: $.paths['/providers/google_workspace/{id}/sync/object/'].post update: x-apievangelist-phrasing: intent: Re-sync one user or group to Google Workspace effect: write questions: - Can I push a single user to Google Workspace without running a full sync? - Is it possible to force one group to re-sync to Google even while in dry run? instructions: - text: Sync {sync_object_model} {sync_object_id} to Google Workspace provider {id}. slots: id: path.id sync_object_model: requestBody.sync_object_model sync_object_id: requestBody.sync_object_id - text: Re-sync object {sync_object_id} of type {sync_object_model} through Google Workspace provider {id}, overriding dry run {override_dry_run}. slots: id: path.id sync_object_id: requestBody.sync_object_id sync_object_model: requestBody.sync_object_model override_dry_run: requestBody.override_dry_run method: generated generated: '2026-09-26' - target: $.paths['/providers/google_workspace/{id}/sync/status/'].get update: x-apievangelist-phrasing: intent: Check a Google Workspace provider's sync status effect: read questions: - Is my Google Workspace sync currently running or did it finish? - When did the last Google Workspace provider sync complete? instructions: - text: Check the sync status of Google Workspace provider {id}. slots: id: path.id - text: Show whether Google Workspace provider {id} is syncing right now. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/google_workspace/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a Google Workspace provider effect: read questions: - What objects depend on my Google Workspace provider? - Is any application still bound to this Google Workspace sync provider? instructions: - text: List the objects that use Google Workspace provider {id}. slots: id: path.id - text: Show dependents of Google Workspace provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/google_workspace_groups/'].get update: x-apievangelist-phrasing: intent: List groups synced to Google Workspace effect: read questions: - Which authentik groups have been mapped to Google Workspace groups? - Can I find the Google group linked to a specific authentik group name? instructions: - text: List Google Workspace group mappings. - text: Show Google Workspace group links for authentik group {group_name}. slots: group_name: query.group__name - text: List groups synced by Google Workspace provider {provider_id}. slots: provider_id: query.provider__id method: generated generated: '2026-09-26' - target: $.paths['/providers/google_workspace_groups/'].post update: x-apievangelist-phrasing: intent: Link a group to a Google Workspace group effect: write questions: - How do I manually tie an authentik group to an existing Google group ID? - Can I record a Google Workspace group mapping by hand? instructions: - text: Link authentik group {group} to Google group {google_id} on provider {provider}. slots: group: requestBody.group google_id: requestBody.google_id provider: requestBody.provider - text: 'Create a Google Workspace group mapping: Google ID {google_id}, group {group}, provider {provider}.' slots: google_id: requestBody.google_id group: requestBody.group provider: requestBody.provider method: generated generated: '2026-09-26' - target: $.paths['/providers/google_workspace_groups/{id}/'].get update: x-apievangelist-phrasing: intent: Get a Google Workspace group mapping effect: read questions: - Which Google group ID does a particular group mapping point to? - What authentik group is behind this Google Workspace group link? instructions: - text: Get Google Workspace group mapping {id}. slots: id: path.id - text: Show the Google group link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/google_workspace_groups/{id}/'].delete update: x-apievangelist-phrasing: intent: Remove a Google Workspace group mapping effect: destructive questions: - Can I unlink an authentik group from its Google Workspace group? - What happens if I delete a Google group mapping record? instructions: - text: Delete Google Workspace group mapping {id}. slots: id: path.id - text: Unlink the Google group mapping {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/google_workspace_groups/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a Google Workspace group mapping effect: read questions: - Does anything reference this Google Workspace group mapping? - What depends on a synced Google group link before I remove it? instructions: - text: List objects using Google Workspace group mapping {id}. slots: id: path.id - text: Show dependents of the Google group link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/google_workspace_users/'].get update: x-apievangelist-phrasing: intent: List users synced to Google Workspace effect: read questions: - Which authentik users have been provisioned into Google Workspace? - Can I check whether a given username is linked to a Google account? instructions: - text: List Google Workspace user mappings. - text: Find the Google Workspace user link for username {username}. slots: username: query.user__username - text: List users synced by Google Workspace provider {provider_id}. slots: provider_id: query.provider__id method: generated generated: '2026-09-26' - target: $.paths['/providers/google_workspace_users/'].post update: x-apievangelist-phrasing: intent: Link a user to a Google Workspace account effect: write questions: - How do I manually map an authentik user to an existing Google user ID? - Can I add a Google Workspace user link without running sync? instructions: - text: Link user {user} to Google user {google_id} on provider {provider}. slots: user: requestBody.user google_id: requestBody.google_id provider: requestBody.provider - text: Create a Google Workspace user mapping for Google ID {google_id}, user {user}, provider {provider}. slots: google_id: requestBody.google_id user: requestBody.user provider: requestBody.provider method: generated generated: '2026-09-26' - target: $.paths['/providers/google_workspace_users/{id}/'].get update: x-apievangelist-phrasing: intent: Get a Google Workspace user mapping effect: read questions: - Which Google account is a specific user mapping tied to? - What does a single Google Workspace user link record contain? instructions: - text: Get Google Workspace user mapping {id}. slots: id: path.id - text: Show the Google user link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/google_workspace_users/{id}/'].delete update: x-apievangelist-phrasing: intent: Remove a Google Workspace user mapping effect: destructive questions: - Can I unlink a user from their Google Workspace account record? - Is it possible to delete a stale Google user mapping? instructions: - text: Delete Google Workspace user mapping {id}. slots: id: path.id - text: Unlink the Google user mapping {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/google_workspace_users/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a Google Workspace user mapping effect: read questions: - Does anything reference this Google Workspace user mapping? - What depends on a synced Google user link? instructions: - text: List objects using Google Workspace user mapping {id}. slots: id: path.id - text: Show dependents of the Google user link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/ldap/'].get update: x-apievangelist-phrasing: intent: List LDAP providers effect: read questions: - Which LDAP outpost providers do I have configured? - Can I find LDAP providers by their base DN or TLS server name? instructions: - text: List my LDAP providers. - text: Find LDAP providers with base DN {base_dn}. slots: base_dn: query.base_dn__iexact - text: Show LDAP providers using authorization flow {flow_slug}. slots: flow_slug: query.authorization_flow__slug__iexact method: generated generated: '2026-09-26' - target: $.paths['/providers/ldap/'].post update: x-apievangelist-phrasing: intent: Create an LDAP provider effect: write questions: - How do I expose authentik users over LDAP for a legacy app? - Can a new LDAP provider support MFA during bind? instructions: - text: Create an LDAP provider {name} with authorization flow {authorization_flow} and invalidation flow {invalidation_flow}. slots: name: requestBody.name authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow - text: Set up LDAP provider {name} with base DN {base_dn}, bind flow {authorization_flow}, invalidation flow {invalidation_flow}. slots: name: requestBody.name base_dn: requestBody.base_dn authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow method: generated generated: '2026-09-26' - target: $.paths['/providers/ldap/{id}/'].get update: x-apievangelist-phrasing: intent: Get an LDAP provider effect: read questions: - What base DN and bind mode does a specific LDAP provider use? - Which certificate is my LDAP provider serving for LDAPS? instructions: - text: Get LDAP provider {id}. slots: id: path.id - text: Show the settings of LDAP provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/ldap/{id}/'].put update: x-apievangelist-phrasing: intent: Replace an LDAP provider's config effect: write questions: - Can I overwrite every setting of an LDAP provider in one request? - How do I fully reconfigure an existing LDAP provider? instructions: - text: Replace LDAP provider {id} with name {name}, authorization flow {authorization_flow}, invalidation flow {invalidation_flow}. slots: id: path.id name: requestBody.name authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow - text: 'Overwrite LDAP provider {id}: name {name}, base DN {base_dn}, flows {authorization_flow} and {invalidation_flow}.' slots: id: path.id name: requestBody.name base_dn: requestBody.base_dn authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow method: generated generated: '2026-09-26' - target: $.paths['/providers/ldap/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete an LDAP provider effect: destructive questions: - Can I remove an LDAP provider I'm no longer using? - Will deleting an LDAP provider break binds from my legacy apps? instructions: - text: Delete LDAP provider {id}. slots: id: path.id - text: Remove the LDAP provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/ldap/{id}/'].patch update: x-apievangelist-phrasing: intent: Update some LDAP provider settings effect: write questions: - Can I change just the base DN of my LDAP provider? - How do I enable MFA support on an existing LDAP provider? instructions: - text: Set the base DN of LDAP provider {id} to {base_dn}. slots: id: path.id base_dn: requestBody.base_dn - text: Turn MFA support {mfa_support} on LDAP provider {id}. slots: id: path.id mfa_support: requestBody.mfa_support - text: Change the search mode of LDAP provider {id} to {search_mode}. slots: id: path.id search_mode: requestBody.search_mode method: generated generated: '2026-09-26' - target: $.paths['/providers/ldap/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses an LDAP provider effect: read questions: - Which applications or outposts depend on my LDAP provider? - Is an LDAP provider still referenced anywhere? instructions: - text: List objects that use LDAP provider {id}. slots: id: path.id - text: Show dependents of LDAP provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/microsoft_entra/'].get update: x-apievangelist-phrasing: intent: List Microsoft Entra providers effect: read questions: - Which Microsoft Entra ID sync providers are configured? - Can I list Entra providers that exclude service account users? instructions: - text: List my Microsoft Entra providers. - text: Find Microsoft Entra providers named {name}. slots: name: query.name - text: Show Entra providers filtering on group {filter_group}. slots: filter_group: query.filter_group method: generated generated: '2026-09-26' - target: $.paths['/providers/microsoft_entra/'].post update: x-apievangelist-phrasing: intent: Create a Microsoft Entra provider effect: write questions: - How do I provision authentik users and groups into Microsoft Entra ID? - What app registration details does a Microsoft Entra provider require? instructions: - text: Create a Microsoft Entra provider {name} for tenant {tenant_id} with client ID {client_id} and secret {client_secret}. slots: name: requestBody.name tenant_id: requestBody.tenant_id client_id: requestBody.client_id client_secret: requestBody.client_secret - text: Set up Entra sync {name} in dry-run {dry_run} using tenant {tenant_id}, client {client_id}, secret {client_secret}. slots: name: requestBody.name dry_run: requestBody.dry_run tenant_id: requestBody.tenant_id client_id: requestBody.client_id client_secret: requestBody.client_secret method: generated generated: '2026-09-26' - target: $.paths['/providers/microsoft_entra/{id}/'].get update: x-apievangelist-phrasing: intent: Get a Microsoft Entra provider effect: read questions: - Which Entra tenant is a specific provider syncing to? - What group delete action does my Microsoft Entra provider use? instructions: - text: Get Microsoft Entra provider {id}. slots: id: path.id - text: Show the configuration of Entra provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/microsoft_entra/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a Microsoft Entra provider's config effect: write questions: - Can I fully replace an Entra provider's tenant, client and secret at once? - How do I overwrite all settings of a Microsoft Entra sync provider? instructions: - text: Replace Entra provider {id} with name {name}, tenant {tenant_id}, client {client_id}, secret {client_secret}. slots: id: path.id name: requestBody.name tenant_id: requestBody.tenant_id client_id: requestBody.client_id client_secret: requestBody.client_secret - text: 'Overwrite Microsoft Entra provider {id} config: {name}, tenant {tenant_id}, app {client_id}, secret {client_secret}.' slots: id: path.id name: requestBody.name tenant_id: requestBody.tenant_id client_id: requestBody.client_id client_secret: requestBody.client_secret method: generated generated: '2026-09-26' - target: $.paths['/providers/microsoft_entra/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a Microsoft Entra provider effect: destructive questions: - Can I delete a Microsoft Entra sync provider? - What happens to Entra syncing when I remove its provider? instructions: - text: Delete Microsoft Entra provider {id}. slots: id: path.id - text: Remove the Entra sync provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/microsoft_entra/{id}/'].patch update: x-apievangelist-phrasing: intent: Update some Microsoft Entra provider settings effect: write questions: - Can I rotate only the client secret on my Entra provider? - How do I switch a Microsoft Entra provider out of dry-run mode? instructions: - text: Update the client secret of Entra provider {id} to {client_secret}. slots: id: path.id client_secret: requestBody.client_secret - text: Set dry run to {dry_run} on Microsoft Entra provider {id}. slots: id: path.id dry_run: requestBody.dry_run method: generated generated: '2026-09-26' - target: $.paths['/providers/microsoft_entra/{id}/sync/object/'].post update: x-apievangelist-phrasing: intent: Re-sync one user or group to Microsoft Entra effect: write questions: - Can I push just one user to Entra ID without a full sync? - Is there a way to re-sync a single group to Microsoft Entra on demand? instructions: - text: Sync {sync_object_model} {sync_object_id} to Microsoft Entra provider {id}. slots: id: path.id sync_object_model: requestBody.sync_object_model sync_object_id: requestBody.sync_object_id - text: Re-sync object {sync_object_id} ({sync_object_model}) through Entra provider {id} with dry-run override {override_dry_run}. slots: id: path.id sync_object_id: requestBody.sync_object_id sync_object_model: requestBody.sync_object_model override_dry_run: requestBody.override_dry_run method: generated generated: '2026-09-26' - target: $.paths['/providers/microsoft_entra/{id}/sync/status/'].get update: x-apievangelist-phrasing: intent: Check a Microsoft Entra provider's sync status effect: read questions: - Is my Microsoft Entra sync still running? - When did the Entra provider last finish syncing? instructions: - text: Check the sync status of Microsoft Entra provider {id}. slots: id: path.id - text: Show whether Entra provider {id} is currently syncing. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/microsoft_entra/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a Microsoft Entra provider effect: read questions: - What objects reference my Microsoft Entra provider? - Is an Entra sync provider still attached to any application? instructions: - text: List objects that use Microsoft Entra provider {id}. slots: id: path.id - text: Show dependents of Entra provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/microsoft_entra_groups/'].get update: x-apievangelist-phrasing: intent: List groups synced to Microsoft Entra effect: read questions: - Which authentik groups are linked to Entra ID groups? - Can I look up the Entra group mapped to a given group UUID? instructions: - text: List Microsoft Entra group mappings. - text: Show Entra group links for authentik group {group_name}. slots: group_name: query.group__name - text: List groups synced by Entra provider {provider_id}. slots: provider_id: query.provider__id method: generated generated: '2026-09-26' - target: $.paths['/providers/microsoft_entra_groups/'].post update: x-apievangelist-phrasing: intent: Link a group to a Microsoft Entra group effect: write questions: - How do I manually map an authentik group to an existing Entra group object ID? - Can I create an Entra group link by hand? instructions: - text: Link group {group} to Entra group {microsoft_id} on provider {provider}. slots: group: requestBody.group microsoft_id: requestBody.microsoft_id provider: requestBody.provider - text: 'Create a Microsoft Entra group mapping: Microsoft ID {microsoft_id}, group {group}, provider {provider}.' slots: microsoft_id: requestBody.microsoft_id group: requestBody.group provider: requestBody.provider method: generated generated: '2026-09-26' - target: $.paths['/providers/microsoft_entra_groups/{id}/'].get update: x-apievangelist-phrasing: intent: Get a Microsoft Entra group mapping effect: read questions: - Which Entra group object does this mapping record point to? - What authentik group sits behind a given Entra group link? instructions: - text: Get Microsoft Entra group mapping {id}. slots: id: path.id - text: Show the Entra group link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/microsoft_entra_groups/{id}/'].delete update: x-apievangelist-phrasing: intent: Remove a Microsoft Entra group mapping effect: destructive questions: - Can I unlink an authentik group from its Entra group? - Is it safe to delete a stale Microsoft Entra group mapping? instructions: - text: Delete Microsoft Entra group mapping {id}. slots: id: path.id - text: Unlink the Entra group mapping {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/microsoft_entra_groups/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a Microsoft Entra group mapping effect: read questions: - Does anything reference this Entra group mapping? - What depends on a Microsoft Entra group link? instructions: - text: List objects using Microsoft Entra group mapping {id}. slots: id: path.id - text: Show dependents of the Entra group link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/microsoft_entra_users/'].get update: x-apievangelist-phrasing: intent: List users synced to Microsoft Entra effect: read questions: - Which authentik users have been provisioned into Entra ID? - Can I check whether a username has an Entra user link? instructions: - text: List Microsoft Entra user mappings. - text: Find the Entra user link for username {username}. slots: username: query.user__username - text: List users synced by Entra provider {provider_id}. slots: provider_id: query.provider__id method: generated generated: '2026-09-26' - target: $.paths['/providers/microsoft_entra_users/'].post update: x-apievangelist-phrasing: intent: Link a user to a Microsoft Entra account effect: write questions: - How do I map an authentik user to an existing Entra user object ID? - Can I add a Microsoft Entra user link manually? instructions: - text: Link user {user} to Entra user {microsoft_id} on provider {provider}. slots: user: requestBody.user microsoft_id: requestBody.microsoft_id provider: requestBody.provider - text: Create a Microsoft Entra user mapping for Microsoft ID {microsoft_id}, user {user}, provider {provider}. slots: microsoft_id: requestBody.microsoft_id user: requestBody.user provider: requestBody.provider method: generated generated: '2026-09-26' - target: $.paths['/providers/microsoft_entra_users/{id}/'].get update: x-apievangelist-phrasing: intent: Get a Microsoft Entra user mapping effect: read questions: - Which Entra account is a specific user mapping tied to? - What does one Microsoft Entra user link record hold? instructions: - text: Get Microsoft Entra user mapping {id}. slots: id: path.id - text: Show the Entra user link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/microsoft_entra_users/{id}/'].delete update: x-apievangelist-phrasing: intent: Remove a Microsoft Entra user mapping effect: destructive questions: - Can I unlink a user from their Entra account record? - Is it possible to delete an outdated Microsoft Entra user mapping? instructions: - text: Delete Microsoft Entra user mapping {id}. slots: id: path.id - text: Unlink the Entra user mapping {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/microsoft_entra_users/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a Microsoft Entra user mapping effect: read questions: - Does anything reference this Entra user mapping? - What depends on a Microsoft Entra user link? instructions: - text: List objects using Microsoft Entra user mapping {id}. slots: id: path.id - text: Show dependents of the Entra user link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/oauth2/'].get update: x-apievangelist-phrasing: intent: List OAuth2/OpenID providers effect: read questions: - Which OAuth2 and OpenID Connect providers have I configured? - Can I find the OAuth2 provider that owns a particular client ID? - Are any OAuth2 providers set up as public clients? instructions: - text: List my OAuth2 providers. - text: Find the OAuth2 provider with client ID {client_id}. slots: client_id: query.client_id - text: Show OAuth2 providers of client type {client_type}. slots: client_type: query.client_type method: generated generated: '2026-09-26' - target: $.paths['/providers/oauth2/'].post update: x-apievangelist-phrasing: intent: Create an OAuth2/OpenID provider effect: write questions: - How do I add OpenID Connect login for a new app in authentik? - Can I set access and refresh token lifetimes when creating an OAuth2 provider? instructions: - text: Create an OAuth2 provider {name} with redirect URIs {redirect_uris}, authorization flow {authorization_flow} and invalidation flow {invalidation_flow}. slots: name: requestBody.name redirect_uris: requestBody.redirect_uris authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow - text: Set up a {client_type} OIDC provider {name} redirecting to {redirect_uris}, flows {authorization_flow} and {invalidation_flow}. slots: client_type: requestBody.client_type name: requestBody.name redirect_uris: requestBody.redirect_uris authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow method: generated generated: '2026-09-26' - target: $.paths['/providers/oauth2-dcr/'].get update: x-apievangelist-phrasing: intent: List OAuth2 dynamic client registration configs effect: read questions: - Which OAuth2 providers allow dynamic client registration? - Can I see the DCR settings attached to a given OAuth2 provider? instructions: - text: List OAuth2 dynamic client registration configurations. - text: Show the DCR config for OAuth2 provider {provider}. slots: provider: query.provider method: generated generated: '2026-09-26' - target: $.paths['/providers/oauth2-dcr/'].post update: x-apievangelist-phrasing: intent: Enable dynamic client registration effect: write questions: - How do I let clients register themselves dynamically against an OAuth2 provider? - Can dynamically registered clients get a default application group and restricted grant types? instructions: - text: Enable dynamic client registration on OAuth2 provider {provider}. slots: provider: requestBody.provider - text: Create a DCR config for provider {provider} allowing grant types {allowed_grant_types}. slots: provider: requestBody.provider allowed_grant_types: requestBody.allowed_grant_types method: generated generated: '2026-09-26' - target: $.paths['/providers/oauth2-dcr/{pbm_uuid}/'].get update: x-apievangelist-phrasing: intent: Get a dynamic client registration config effect: read questions: - What token validity do dynamically registered clients get under a DCR config? - Which grant types does a specific DCR configuration allow? instructions: - text: Get dynamic client registration config {pbm_uuid}. slots: pbm_uuid: path.pbm_uuid - text: Show DCR settings {pbm_uuid}. slots: pbm_uuid: path.pbm_uuid method: generated generated: '2026-09-26' - target: $.paths['/providers/oauth2-dcr/{pbm_uuid}/'].put update: x-apievangelist-phrasing: intent: Replace a dynamic client registration config effect: write questions: - Can I overwrite a whole DCR configuration in one call? - How do I fully reset the dynamic registration settings for a provider? instructions: - text: Replace DCR config {pbm_uuid} for OAuth2 provider {provider}. slots: pbm_uuid: path.pbm_uuid provider: requestBody.provider - text: 'Overwrite dynamic registration config {pbm_uuid}: provider {provider}, policy mode {policy_engine_mode}.' slots: pbm_uuid: path.pbm_uuid provider: requestBody.provider policy_engine_mode: requestBody.policy_engine_mode method: generated generated: '2026-09-26' - target: $.paths['/providers/oauth2-dcr/{pbm_uuid}/'].delete update: x-apievangelist-phrasing: intent: Disable dynamic client registration effect: destructive questions: - How can I stop clients from registering dynamically with an OAuth2 provider? - Can I delete a DCR configuration? instructions: - text: Delete dynamic client registration config {pbm_uuid}. slots: pbm_uuid: path.pbm_uuid - text: Turn off DCR by removing config {pbm_uuid}. slots: pbm_uuid: path.pbm_uuid method: generated generated: '2026-09-26' - target: $.paths['/providers/oauth2-dcr/{pbm_uuid}/'].patch update: x-apievangelist-phrasing: intent: Update some dynamic client registration settings effect: write questions: - Can I shorten the access token lifetime just for dynamically registered clients? - How do I change only the allowed grant types in a DCR config? instructions: - text: Set access token validity {access_token_validity} on DCR config {pbm_uuid}. slots: pbm_uuid: path.pbm_uuid access_token_validity: requestBody.access_token_validity - text: Restrict DCR config {pbm_uuid} to grant types {allowed_grant_types}. slots: pbm_uuid: path.pbm_uuid allowed_grant_types: requestBody.allowed_grant_types method: generated generated: '2026-09-26' - target: $.paths['/providers/oauth2/{id}/'].get update: x-apievangelist-phrasing: intent: Get an OAuth2/OpenID provider effect: read questions: - What redirect URIs and grant types does a specific OAuth2 provider allow? - Which signing key is my OIDC provider using for ID tokens? instructions: - text: Get OAuth2 provider {id}. slots: id: path.id - text: Show the configuration of OIDC provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/oauth2/{id}/'].put update: x-apievangelist-phrasing: intent: Replace an OAuth2 provider's config effect: write questions: - Can I overwrite every setting on an OAuth2 provider at once? - How do I fully reconfigure an existing OIDC provider? instructions: - text: Replace OAuth2 provider {id} with name {name}, redirect URIs {redirect_uris}, flows {authorization_flow} and {invalidation_flow}. slots: id: path.id name: requestBody.name redirect_uris: requestBody.redirect_uris authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow - text: 'Overwrite OIDC provider {id}: {name}, redirects {redirect_uris}, authorization {authorization_flow}, invalidation {invalidation_flow}.' slots: id: path.id name: requestBody.name redirect_uris: requestBody.redirect_uris authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow method: generated generated: '2026-09-26' - target: $.paths['/providers/oauth2/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete an OAuth2/OpenID provider effect: destructive questions: - Can I delete an OAuth2 provider for an app I've retired? - Will removing an OIDC provider break logins for its client? instructions: - text: Delete OAuth2 provider {id}. slots: id: path.id - text: Remove the OIDC provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/oauth2/{id}/'].patch update: x-apievangelist-phrasing: intent: Update some OAuth2 provider settings effect: write questions: - Can I add a redirect URI to an OAuth2 provider without resending everything? - How do I change only the access token validity on an OIDC provider? instructions: - text: Set the redirect URIs of OAuth2 provider {id} to {redirect_uris}. slots: id: path.id redirect_uris: requestBody.redirect_uris - text: Change access token validity on OAuth2 provider {id} to {access_token_validity}. slots: id: path.id access_token_validity: requestBody.access_token_validity - text: Rotate the client secret of OAuth2 provider {id} to {client_secret}. slots: id: path.id client_secret: requestBody.client_secret method: generated generated: '2026-09-26' - target: $.paths['/providers/oauth2/{id}/preview_user/'].get update: x-apievangelist-phrasing: intent: Preview a user's OAuth2 claims effect: read questions: - What claims will an OAuth2 provider send for a particular user? - Can I test my OIDC property mappings against a real user before rollout? instructions: - text: Preview the user data OAuth2 provider {id} would issue. slots: id: path.id - text: Show the OIDC claims provider {id} generates for user {for_user}. slots: id: path.id for_user: query.for_user method: generated generated: '2026-09-26' - target: $.paths['/providers/oauth2/{id}/setup_urls/'].get update: x-apievangelist-phrasing: intent: Get an OAuth2 provider's endpoint URLs effect: read questions: - What issuer, authorize and token URLs do I paste into my app for this OIDC provider? - Where is the JWKS and userinfo endpoint for my OAuth2 provider? instructions: - text: Get the setup URLs for OAuth2 provider {id}. slots: id: path.id - text: Show the issuer, token and authorize endpoints of OIDC provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/oauth2/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses an OAuth2 provider effect: read questions: - Which applications are bound to my OAuth2 provider? - Does anything still reference this OIDC provider? instructions: - text: List objects that use OAuth2 provider {id}. slots: id: path.id - text: Show dependents of OIDC provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/proxy/'].get update: x-apievangelist-phrasing: intent: List proxy providers effect: read questions: - Which proxy providers protect my internal apps? - Can I find the proxy provider serving a specific external host? instructions: - text: List my proxy providers. - text: Find the proxy provider for external host {external_host}. slots: external_host: query.external_host__iexact - text: Show proxy providers running in mode {mode}. slots: mode: query.mode__iexact method: generated generated: '2026-09-26' - target: $.paths['/providers/proxy/'].post update: x-apievangelist-phrasing: intent: Create a proxy provider effect: write questions: - How do I put authentik authentication in front of an app with no login of its own? - Can a proxy provider pass HTTP basic auth to the upstream app? instructions: - text: Create a proxy provider {name} for external host {external_host} with flows {authorization_flow} and {invalidation_flow}. slots: name: requestBody.name external_host: requestBody.external_host authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow - text: Set up proxy {name} forwarding {external_host} to internal host {internal_host}, flows {authorization_flow} and {invalidation_flow}. slots: name: requestBody.name external_host: requestBody.external_host internal_host: requestBody.internal_host authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow method: generated generated: '2026-09-26' - target: $.paths['/providers/proxy/{id}/'].get update: x-apievangelist-phrasing: intent: Get a proxy provider effect: read questions: - Which internal host does a specific proxy provider forward to? - What paths does my proxy provider skip authentication for? instructions: - text: Get proxy provider {id}. slots: id: path.id - text: Show the settings of proxy provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/proxy/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a proxy provider's config effect: write questions: - Can I overwrite a proxy provider's hosts and flows all at once? - How do I fully reconfigure an existing proxy provider? instructions: - text: Replace proxy provider {id} with name {name}, external host {external_host}, flows {authorization_flow} and {invalidation_flow}. slots: id: path.id name: requestBody.name external_host: requestBody.external_host authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow - text: 'Overwrite proxy {id}: {name}, public URL {external_host}, authorization {authorization_flow}, invalidation {invalidation_flow}.' slots: id: path.id name: requestBody.name external_host: requestBody.external_host authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow method: generated generated: '2026-09-26' - target: $.paths['/providers/proxy/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a proxy provider effect: destructive questions: - Can I remove a proxy provider for an app I've taken offline? - Does deleting a proxy provider stop the outpost from protecting that host? instructions: - text: Delete proxy provider {id}. slots: id: path.id - text: Remove the proxy provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/proxy/{id}/'].patch update: x-apievangelist-phrasing: intent: Update some proxy provider settings effect: write questions: - Can I change only the skip-path regex on a proxy provider? - How do I switch a proxy provider to forward-auth mode? instructions: - text: Set the unauthenticated path regex on proxy provider {id} to {skip_path_regex}. slots: id: path.id skip_path_regex: requestBody.skip_path_regex - text: Change proxy provider {id} to mode {mode}. slots: id: path.id mode: requestBody.mode - text: Point proxy provider {id} at internal host {internal_host}. slots: id: path.id internal_host: requestBody.internal_host method: generated generated: '2026-09-26' - target: $.paths['/providers/proxy/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a proxy provider effect: read questions: - Which applications or outposts use my proxy provider? - Is a proxy provider still referenced before I delete it? instructions: - text: List objects that use proxy provider {id}. slots: id: path.id - text: Show dependents of proxy provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/rac/'].get update: x-apievangelist-phrasing: intent: List remote access (RAC) providers effect: read questions: - Which remote access providers for RDP, SSH or VNC have I set up? - Are any RAC providers not yet attached to an application? instructions: - text: List my RAC remote access providers. - text: Find RAC providers named {name}. slots: name: query.name__iexact method: generated generated: '2026-09-26' - target: $.paths['/providers/rac/'].post update: x-apievangelist-phrasing: intent: Create a remote access (RAC) provider effect: write questions: - How do I give users browser-based RDP or SSH access through authentik? - Can a new RAC provider delete the connection token when the user disconnects? instructions: - text: Create a RAC provider {name} with authorization flow {authorization_flow}. slots: name: requestBody.name authorization_flow: requestBody.authorization_flow - text: Set up remote access provider {name} using flow {authorization_flow} with connection expiry {connection_expiry}. slots: name: requestBody.name authorization_flow: requestBody.authorization_flow connection_expiry: requestBody.connection_expiry method: generated generated: '2026-09-26' - target: $.paths['/providers/rac/{id}/'].get update: x-apievangelist-phrasing: intent: Get a remote access (RAC) provider effect: read questions: - How long do connections last on a specific RAC provider? - What connection settings does my remote access provider pass along? instructions: - text: Get RAC provider {id}. slots: id: path.id - text: Show the settings of remote access provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/rac/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a RAC provider's config effect: write questions: - Can I overwrite every setting of a remote access provider at once? - How do I fully reconfigure a RAC provider? instructions: - text: Replace RAC provider {id} with name {name} and authorization flow {authorization_flow}. slots: id: path.id name: requestBody.name authorization_flow: requestBody.authorization_flow - text: 'Overwrite remote access provider {id}: name {name}, flow {authorization_flow}, settings {settings}.' slots: id: path.id name: requestBody.name authorization_flow: requestBody.authorization_flow settings: requestBody.settings method: generated generated: '2026-09-26' - target: $.paths['/providers/rac/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a remote access (RAC) provider effect: destructive questions: - Can I remove a RAC provider for machines I've decommissioned? - What happens to remote desktop access when its RAC provider is deleted? instructions: - text: Delete RAC provider {id}. slots: id: path.id - text: Remove the remote access provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/rac/{id}/'].patch update: x-apievangelist-phrasing: intent: Update some RAC provider settings effect: write questions: - Can I change just the connection expiry on a remote access provider? - How do I make a RAC provider drop its token on disconnect? instructions: - text: Set connection expiry on RAC provider {id} to {connection_expiry}. slots: id: path.id connection_expiry: requestBody.connection_expiry - text: Set delete-token-on-disconnect to {delete_token_on_disconnect} for RAC provider {id}. slots: id: path.id delete_token_on_disconnect: requestBody.delete_token_on_disconnect method: generated generated: '2026-09-26' - target: $.paths['/providers/rac/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a RAC provider effect: read questions: - Which applications or endpoints depend on my remote access provider? - Is a RAC provider still in use anywhere? instructions: - text: List objects that use RAC provider {id}. slots: id: path.id - text: Show dependents of remote access provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/radius/'].get update: x-apievangelist-phrasing: intent: List RADIUS providers effect: read questions: - Which RADIUS providers authenticate my network devices? - Can I find RADIUS providers by the client networks they accept? instructions: - text: List my RADIUS providers. - text: Find RADIUS providers allowing client networks {client_networks}. slots: client_networks: query.client_networks__iexact - text: Show RADIUS providers named {name}. slots: name: query.name__iexact method: generated generated: '2026-09-26' - target: $.paths['/providers/radius/'].post update: x-apievangelist-phrasing: intent: Create a RADIUS provider effect: write questions: - How do I let a VPN or Wi-Fi controller authenticate users against authentik over RADIUS? - Can a new RADIUS provider require MFA? instructions: - text: Create a RADIUS provider {name} with flows {authorization_flow} and {invalidation_flow}. slots: name: requestBody.name authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow - text: Set up RADIUS provider {name} with shared secret {shared_secret} for networks {client_networks}, flows {authorization_flow} and {invalidation_flow}. slots: name: requestBody.name shared_secret: requestBody.shared_secret client_networks: requestBody.client_networks authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow method: generated generated: '2026-09-26' - target: $.paths['/providers/radius/{id}/'].get update: x-apievangelist-phrasing: intent: Get a RADIUS provider effect: read questions: - Which client networks may talk to a specific RADIUS provider? - Is MFA support enabled on my RADIUS provider? instructions: - text: Get RADIUS provider {id}. slots: id: path.id - text: Show the settings of RADIUS provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/radius/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a RADIUS provider's config effect: write questions: - Can I overwrite all settings of a RADIUS provider in one go? - How do I fully reconfigure an existing RADIUS provider? instructions: - text: Replace RADIUS provider {id} with name {name}, flows {authorization_flow} and {invalidation_flow}. slots: id: path.id name: requestBody.name authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow - text: 'Overwrite RADIUS provider {id}: {name}, secret {shared_secret}, authorization {authorization_flow}, invalidation {invalidation_flow}.' slots: id: path.id name: requestBody.name shared_secret: requestBody.shared_secret authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow method: generated generated: '2026-09-26' - target: $.paths['/providers/radius/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a RADIUS provider effect: destructive questions: - Can I remove a RADIUS provider I no longer use? - Will deleting a RADIUS provider cut off my network devices' logins? instructions: - text: Delete RADIUS provider {id}. slots: id: path.id - text: Remove the RADIUS provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/radius/{id}/'].patch update: x-apievangelist-phrasing: intent: Update some RADIUS provider settings effect: write questions: - Can I rotate only the shared secret on a RADIUS provider? - How do I change the allowed client networks for RADIUS? instructions: - text: Set the shared secret of RADIUS provider {id} to {shared_secret}. slots: id: path.id shared_secret: requestBody.shared_secret - text: Allow client networks {client_networks} on RADIUS provider {id}. slots: id: path.id client_networks: requestBody.client_networks method: generated generated: '2026-09-26' - target: $.paths['/providers/radius/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a RADIUS provider effect: read questions: - Which applications or outposts depend on my RADIUS provider? - Is a RADIUS provider still referenced anywhere? instructions: - text: List objects that use RADIUS provider {id}. slots: id: path.id - text: Show dependents of RADIUS provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/saml/'].get update: x-apievangelist-phrasing: intent: List SAML providers effect: read questions: - Which SAML service provider integrations are configured? - Can I find the SAML provider that posts to a particular ACS URL? - Are there SAML providers that don't sign their assertions? instructions: - text: List my SAML providers. - text: Find the SAML provider with ACS URL {acs_url}. slots: acs_url: query.acs_url - text: Show SAML providers with audience {audience}. slots: audience: query.audience method: generated generated: '2026-09-26' - target: $.paths['/providers/saml/'].post update: x-apievangelist-phrasing: intent: Create a SAML provider effect: write questions: - How do I set up SAML single sign-on for a service provider by hand? - Can I choose signing and encryption keys when creating a SAML provider? instructions: - text: Create a SAML provider {name} with ACS URL {acs_url}, flows {authorization_flow} and {invalidation_flow}. slots: name: requestBody.name acs_url: requestBody.acs_url authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow - text: Set up SAML provider {name} for audience {audience}, ACS {acs_url}, signed with {signing_kp}, flows {authorization_flow} and {invalidation_flow}. slots: name: requestBody.name audience: requestBody.audience acs_url: requestBody.acs_url signing_kp: requestBody.signing_kp authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow method: generated generated: '2026-09-26' - target: $.paths['/providers/saml/{id}/'].get update: x-apievangelist-phrasing: intent: Get a SAML provider effect: read questions: - What ACS URL and audience is a specific SAML provider configured with? - Which signature algorithm does my SAML provider use? instructions: - text: Get SAML provider {id}. slots: id: path.id - text: Show the configuration of SAML provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/saml/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a SAML provider's config effect: write questions: - Can I overwrite a SAML provider's entire configuration at once? - How do I fully reconfigure an existing SAML integration? instructions: - text: Replace SAML provider {id} with name {name}, ACS URL {acs_url}, flows {authorization_flow} and {invalidation_flow}. slots: id: path.id name: requestBody.name acs_url: requestBody.acs_url authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow - text: 'Overwrite SAML provider {id}: {name}, ACS {acs_url}, authorization {authorization_flow}, invalidation {invalidation_flow}.' slots: id: path.id name: requestBody.name acs_url: requestBody.acs_url authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow method: generated generated: '2026-09-26' - target: $.paths['/providers/saml/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a SAML provider effect: destructive questions: - Can I delete a SAML integration for a retired service? - Will removing a SAML provider stop SSO into that service provider? instructions: - text: Delete SAML provider {id}. slots: id: path.id - text: Remove the SAML provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/saml/{id}/'].patch update: x-apievangelist-phrasing: intent: Update some SAML provider settings effect: write questions: - Can I change only the ACS URL on my SAML provider? - How do I turn on assertion signing for an existing SAML provider? instructions: - text: Set the ACS URL of SAML provider {id} to {acs_url}. slots: id: path.id acs_url: requestBody.acs_url - text: Set sign assertion to {sign_assertion} on SAML provider {id}. slots: id: path.id sign_assertion: requestBody.sign_assertion - text: Change the single logout URL of SAML provider {id} to {sls_url}. slots: id: path.id sls_url: requestBody.sls_url method: generated generated: '2026-09-26' - target: $.paths['/providers/saml/{id}/metadata/'].get update: x-apievangelist-phrasing: intent: Download SAML IdP metadata effect: read questions: - Where do I get the SAML metadata XML to give my service provider? - Can I download SAML metadata forced to a specific binding? instructions: - text: Get the SAML metadata XML for provider {id}. slots: id: path.id - text: Download SAML metadata for provider {id} with binding {force_binding}. slots: id: path.id force_binding: query.force_binding method: generated generated: '2026-09-26' - target: $.paths['/providers/saml/{id}/preview_user/'].get update: x-apievangelist-phrasing: intent: Preview a user's SAML attributes effect: read questions: - What SAML attributes will be sent for a given user? - Can I test SAML property mappings against a user before going live? instructions: - text: Preview the user data SAML provider {id} would assert. slots: id: path.id - text: Show SAML attributes provider {id} generates for user {for_user}. slots: id: path.id for_user: query.for_user method: generated generated: '2026-09-26' - target: $.paths['/providers/saml/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a SAML provider effect: read questions: - Which applications are bound to my SAML provider? - Does anything still reference this SAML integration? instructions: - text: List objects that use SAML provider {id}. slots: id: path.id - text: Show dependents of SAML provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/saml/import_metadata/'].post update: x-apievangelist-phrasing: intent: Create a SAML provider from SP metadata effect: write questions: - Can I create a SAML provider by uploading the service provider's metadata file? - How do I import SP metadata XML instead of typing the ACS URL by hand? instructions: - text: Import SAML metadata file {file} as provider {name} with flows {authorization_flow} and {invalidation_flow}. slots: file: requestBody.file name: requestBody.name authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow - text: Build SAML provider {name} from uploaded SP metadata {file}, authorization {authorization_flow}, invalidation {invalidation_flow}. slots: name: requestBody.name file: requestBody.file authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow method: generated generated: '2026-09-26' - target: $.paths['/providers/scim/'].get update: x-apievangelist-phrasing: intent: List SCIM providers effect: read questions: - Which SCIM outbound provisioning providers are configured? - Can I find the SCIM provider pointing at a specific endpoint URL? instructions: - text: List my SCIM providers. - text: Find the SCIM provider with URL {url}. slots: url: query.url - text: Show SCIM providers named {name}. slots: name: query.name method: generated generated: '2026-09-26' - target: $.paths['/providers/scim/'].post update: x-apievangelist-phrasing: intent: Create a SCIM provider effect: write questions: - How do I provision users into a SaaS app over SCIM from authentik? - Can a SCIM provider authenticate with OAuth instead of a static token? instructions: - text: Create a SCIM provider {name} pointing at {url}. slots: name: requestBody.name url: requestBody.url - text: Set up SCIM provisioning {name} to {url} with bearer token {token}. slots: name: requestBody.name url: requestBody.url token: requestBody.token method: generated generated: '2026-09-26' - target: $.paths['/providers/scim/{id}/'].get update: x-apievangelist-phrasing: intent: Get a SCIM provider effect: read questions: - Which endpoint URL and auth mode does a specific SCIM provider use? - Does my SCIM provider verify the target's certificates? instructions: - text: Get SCIM provider {id}. slots: id: path.id - text: Show the configuration of SCIM provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/scim/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a SCIM provider's config effect: write questions: - Can I overwrite a SCIM provider's URL and credentials together? - How do I fully reconfigure an existing SCIM provider? instructions: - text: Replace SCIM provider {id} with name {name} and URL {url}. slots: id: path.id name: requestBody.name url: requestBody.url - text: 'Overwrite SCIM provider {id}: {name}, endpoint {url}, token {token}.' slots: id: path.id name: requestBody.name url: requestBody.url token: requestBody.token method: generated generated: '2026-09-26' - target: $.paths['/providers/scim/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a SCIM provider effect: destructive questions: - Can I remove a SCIM provider for an app I stopped provisioning? - Does deleting a SCIM provider stop outbound provisioning? instructions: - text: Delete SCIM provider {id}. slots: id: path.id - text: Remove the SCIM provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/scim/{id}/'].patch update: x-apievangelist-phrasing: intent: Update some SCIM provider settings effect: write questions: - Can I rotate only the bearer token on my SCIM provider? - How do I turn on compatibility mode for a picky SCIM target? instructions: - text: Set the token of SCIM provider {id} to {token}. slots: id: path.id token: requestBody.token - text: Switch SCIM provider {id} to compatibility mode {compatibility_mode}. slots: id: path.id compatibility_mode: requestBody.compatibility_mode - text: Set dry run {dry_run} on SCIM provider {id}. slots: id: path.id dry_run: requestBody.dry_run method: generated generated: '2026-09-26' - target: $.paths['/providers/scim/{id}/sync/object/'].post update: x-apievangelist-phrasing: intent: Re-sync one user or group over SCIM effect: write questions: - Can I push a single user to a SCIM target without a full sync? - Is there a way to re-provision just one group over SCIM? instructions: - text: Sync {sync_object_model} {sync_object_id} via SCIM provider {id}. slots: id: path.id sync_object_model: requestBody.sync_object_model sync_object_id: requestBody.sync_object_id - text: Re-provision object {sync_object_id} ({sync_object_model}) over SCIM provider {id}, dry-run override {override_dry_run}. slots: id: path.id sync_object_id: requestBody.sync_object_id sync_object_model: requestBody.sync_object_model override_dry_run: requestBody.override_dry_run method: generated generated: '2026-09-26' - target: $.paths['/providers/scim/{id}/sync/status/'].get update: x-apievangelist-phrasing: intent: Check a SCIM provider's sync status effect: read questions: - Is my SCIM provisioning sync running right now? - When did the last SCIM sync finish? instructions: - text: Check the sync status of SCIM provider {id}. slots: id: path.id - text: Show whether SCIM provider {id} is currently syncing. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/scim/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a SCIM provider effect: read questions: - Which applications reference my SCIM provider? - Is a SCIM provider still attached anywhere? instructions: - text: List objects that use SCIM provider {id}. slots: id: path.id - text: Show dependents of SCIM provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/scim_groups/'].get update: x-apievangelist-phrasing: intent: List groups provisioned over SCIM effect: read questions: - Which authentik groups have been pushed to SCIM targets? - Can I find the SCIM group record for a given group name? instructions: - text: List SCIM group mappings. - text: Show SCIM group links for authentik group {group_name}. slots: group_name: query.group__name - text: List groups provisioned by SCIM provider {provider_id}. slots: provider_id: query.provider__id method: generated generated: '2026-09-26' - target: $.paths['/providers/scim_groups/'].post update: x-apievangelist-phrasing: intent: Link a group to a SCIM group ID effect: write questions: - How do I record that an authentik group already exists in the SCIM target? - Can I manually create a SCIM group mapping? instructions: - text: Link group {group} to SCIM group {scim_id} on provider {provider}. slots: group: requestBody.group scim_id: requestBody.scim_id provider: requestBody.provider - text: 'Create a SCIM group mapping: SCIM ID {scim_id}, group {group}, provider {provider}.' slots: scim_id: requestBody.scim_id group: requestBody.group provider: requestBody.provider method: generated generated: '2026-09-26' - target: $.paths['/providers/scim_groups/{id}/'].get update: x-apievangelist-phrasing: intent: Get a SCIM group mapping effect: read questions: - Which remote SCIM group ID does this mapping point to? - What authentik group is behind a SCIM group record? instructions: - text: Get SCIM group mapping {id}. slots: id: path.id - text: Show the SCIM group link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/scim_groups/{id}/'].delete update: x-apievangelist-phrasing: intent: Remove a SCIM group mapping effect: destructive questions: - Can I unlink a group from its SCIM target record? - Is it safe to delete a stale SCIM group mapping? instructions: - text: Delete SCIM group mapping {id}. slots: id: path.id - text: Unlink the SCIM group mapping {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/scim_groups/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a SCIM group mapping effect: read questions: - Does anything reference this SCIM group mapping? - What depends on a SCIM group link? instructions: - text: List objects using SCIM group mapping {id}. slots: id: path.id - text: Show dependents of the SCIM group link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/scim_users/'].get update: x-apievangelist-phrasing: intent: List users provisioned over SCIM effect: read questions: - Which authentik users have been provisioned to SCIM targets? - Can I check whether a username has a SCIM user record? instructions: - text: List SCIM user mappings. - text: Find the SCIM user link for username {username}. slots: username: query.user__username - text: List users provisioned by SCIM provider {provider_id}. slots: provider_id: query.provider__id method: generated generated: '2026-09-26' - target: $.paths['/providers/scim_users/'].post update: x-apievangelist-phrasing: intent: Link a user to a SCIM user ID effect: write questions: - How do I record that a user already exists in the SCIM target? - Can I manually add a SCIM user mapping? instructions: - text: Link user {user} to SCIM user {scim_id} on provider {provider}. slots: user: requestBody.user scim_id: requestBody.scim_id provider: requestBody.provider - text: Create a SCIM user mapping for SCIM ID {scim_id}, user {user}, provider {provider}. slots: scim_id: requestBody.scim_id user: requestBody.user provider: requestBody.provider method: generated generated: '2026-09-26' - target: $.paths['/providers/scim_users/{id}/'].get update: x-apievangelist-phrasing: intent: Get a SCIM user mapping effect: read questions: - Which remote SCIM user ID is a given mapping tied to? - What does a single SCIM user link record contain? instructions: - text: Get SCIM user mapping {id}. slots: id: path.id - text: Show the SCIM user link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/scim_users/{id}/'].delete update: x-apievangelist-phrasing: intent: Remove a SCIM user mapping effect: destructive questions: - Can I unlink a user from their SCIM target record? - Is it possible to delete an outdated SCIM user mapping? instructions: - text: Delete SCIM user mapping {id}. slots: id: path.id - text: Unlink the SCIM user mapping {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/scim_users/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a SCIM user mapping effect: read questions: - Does anything reference this SCIM user mapping? - What depends on a SCIM user link? instructions: - text: List objects using SCIM user mapping {id}. slots: id: path.id - text: Show dependents of the SCIM user link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/ssf/'].get update: x-apievangelist-phrasing: intent: List Shared Signals (SSF) providers effect: read questions: - Which Shared Signals Framework providers are configured? - Are any SSF providers not attached to an application? instructions: - text: List my SSF providers. - text: Find SSF providers named {name}. slots: name: query.name__iexact method: generated generated: '2026-09-26' - target: $.paths['/providers/ssf/'].post update: x-apievangelist-phrasing: intent: Create a Shared Signals (SSF) provider effect: write questions: - How do I broadcast security events to receivers with the Shared Signals Framework? - What signing key does a new SSF provider need? instructions: - text: Create an SSF provider {name} signing with key {signing_key}. slots: name: requestBody.name signing_key: requestBody.signing_key - text: Set up Shared Signals provider {name} with key {signing_key} and event retention {event_retention}. slots: name: requestBody.name signing_key: requestBody.signing_key event_retention: requestBody.event_retention method: generated generated: '2026-09-26' - target: $.paths['/providers/ssf/{id}/'].get update: x-apievangelist-phrasing: intent: Get a Shared Signals (SSF) provider effect: read questions: - How long does a specific SSF provider retain security events? - Which OIDC providers can authenticate to my SSF provider? instructions: - text: Get SSF provider {id}. slots: id: path.id - text: Show the settings of Shared Signals provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/ssf/{id}/'].put update: x-apievangelist-phrasing: intent: Replace an SSF provider's config effect: write questions: - Can I overwrite every setting of an SSF provider at once? - How do I fully reconfigure a Shared Signals provider? instructions: - text: Replace SSF provider {id} with name {name} and signing key {signing_key}. slots: id: path.id name: requestBody.name signing_key: requestBody.signing_key - text: 'Overwrite Shared Signals provider {id}: {name}, key {signing_key}, retention {event_retention}.' slots: id: path.id name: requestBody.name signing_key: requestBody.signing_key event_retention: requestBody.event_retention method: generated generated: '2026-09-26' - target: $.paths['/providers/ssf/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a Shared Signals (SSF) provider effect: destructive questions: - Can I remove an SSF provider I no longer need? - Will deleting a Shared Signals provider stop event delivery to receivers? instructions: - text: Delete SSF provider {id}. slots: id: path.id - text: Remove the Shared Signals provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/ssf/{id}/'].patch update: x-apievangelist-phrasing: intent: Update some SSF provider settings effect: write questions: - Can I change only the event retention on my SSF provider? - How do I stop an SSF provider verifying push receivers' certificates? instructions: - text: Set event retention on SSF provider {id} to {event_retention}. slots: id: path.id event_retention: requestBody.event_retention - text: Set push certificate verification {push_verify_certificates} on SSF provider {id}. slots: id: path.id push_verify_certificates: requestBody.push_verify_certificates method: generated generated: '2026-09-26' - target: $.paths['/providers/ssf/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses an SSF provider effect: read questions: - Which applications reference my Shared Signals provider? - Is an SSF provider still in use anywhere? instructions: - text: List objects that use SSF provider {id}. slots: id: path.id - text: Show dependents of Shared Signals provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/wsfed/'].get update: x-apievangelist-phrasing: intent: List WS-Federation providers effect: read questions: - Which WS-Federation providers are configured? - Can I filter WS-Fed providers by SAML token version or ACS URL? instructions: - text: List my WS-Federation providers. - text: Show WS-Fed providers using SAML version {saml_version}. slots: saml_version: query.saml_version - text: Find WS-Federation providers named {name}. slots: name: query.name method: generated generated: '2026-09-26' - target: $.paths['/providers/wsfed/'].post update: x-apievangelist-phrasing: intent: Create a WS-Federation provider effect: write questions: - How do I set up WS-Federation sign-in for an app that needs it, like SharePoint? - What reply URL and realm does a new WS-Fed provider need? instructions: - text: Create a WS-Federation provider {name} with reply URL {reply_url}, realm {wtrealm}, flows {authorization_flow} and {invalidation_flow}. slots: name: requestBody.name reply_url: requestBody.reply_url wtrealm: requestBody.wtrealm authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow - text: Set up WS-Fed {name} for realm {wtrealm} replying to {reply_url}, token version {saml_version}, flows {authorization_flow}/{invalidation_flow}. slots: name: requestBody.name wtrealm: requestBody.wtrealm reply_url: requestBody.reply_url saml_version: requestBody.saml_version authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow method: generated generated: '2026-09-26' - target: $.paths['/providers/wsfed/{id}/'].get update: x-apievangelist-phrasing: intent: Get a WS-Federation provider effect: read questions: - What realm and reply URL does a specific WS-Fed provider use? - Which signing key does my WS-Federation provider use? instructions: - text: Get WS-Federation provider {id}. slots: id: path.id - text: Show the configuration of WS-Fed provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/wsfed/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a WS-Federation provider's config effect: write questions: - Can I overwrite a WS-Federation provider's whole configuration? - How do I fully reconfigure an existing WS-Fed integration? instructions: - text: Replace WS-Federation provider {id} with name {name}, reply URL {reply_url}, realm {wtrealm}, flows {authorization_flow} and {invalidation_flow}. slots: id: path.id name: requestBody.name reply_url: requestBody.reply_url wtrealm: requestBody.wtrealm authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow - text: 'Overwrite WS-Fed provider {id}: {name}, realm {wtrealm}, reply {reply_url}, flows {authorization_flow}/{invalidation_flow}.' slots: id: path.id name: requestBody.name wtrealm: requestBody.wtrealm reply_url: requestBody.reply_url authorization_flow: requestBody.authorization_flow invalidation_flow: requestBody.invalidation_flow method: generated generated: '2026-09-26' - target: $.paths['/providers/wsfed/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a WS-Federation provider effect: destructive questions: - Can I delete a WS-Federation integration I've retired? - Will removing a WS-Fed provider break sign-in for its relying party? instructions: - text: Delete WS-Federation provider {id}. slots: id: path.id - text: Remove the WS-Fed provider {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/providers/wsfed/{id}/'].patch update: x-apievangelist-phrasing: intent: Update some WS-Federation provider settings effect: write questions: - Can I change only the reply URL of a WS-Fed provider? - How do I switch the SAML token version a WS-Federation provider issues? instructions: - text: Set the reply URL of WS-Federation provider {id} to {reply_url}. slots: id: path.id reply_url: requestBody.reply_url - text: Change the SAML version of WS-Fed provider {id} to {saml_version}. slots: id: path.id saml_version: requestBody.saml_version - text: Update the realm of WS-Fed provider {id} to {wtrealm}. slots: id: path.id wtrealm: requestBody.wtrealm method: generated generated: '2026-09-26' - target: $.paths['/providers/wsfed/{id}/metadata/'].get update: x-apievangelist-phrasing: intent: Download WS-Federation metadata effect: read questions: - Where do I get the federation metadata XML for my WS-Fed relying party? - Can I download WS-Federation metadata as a file? instructions: - text: Get the WS-Federation metadata XML for provider {id}. slots: id: path.id - text: 'Download WS-Fed metadata for provider {id} as a file: {download}.' slots: id: path.id download: query.download method: generated generated: '2026-09-26' - target: $.paths['/providers/wsfed/{id}/preview_user/'].get update: x-apievangelist-phrasing: intent: Preview a user's WS-Federation claims effect: read questions: - What claims will a WS-Federation provider send for a given user? - Can I test WS-Fed property mappings against a real user? instructions: - text: Preview the user data WS-Federation provider {id} would send. slots: id: path.id - text: Show WS-Fed claims provider {id} generates for user {for_user}. slots: id: path.id for_user: query.for_user method: generated generated: '2026-09-26' - target: $.paths['/providers/wsfed/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a WS-Federation provider effect: read questions: - Which applications are bound to my WS-Federation provider? - Does anything still reference this WS-Fed integration? instructions: - text: List objects that use WS-Federation provider {id}. slots: id: path.id - text: Show dependents of WS-Fed provider {id}. slots: id: path.id method: generated generated: '2026-09-26'