# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for authentik Sources API version: 1.0.0 extends: openapi/authentik-sources-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 173 - target: $.paths['/sources/all/'].get update: x-apievangelist-phrasing: intent: List all federation and sync sources effect: read questions: - Which login and directory sources are set up in authentik across every type? - Can I filter the combined source list down to only managed, built-in sources? instructions: - text: List every source regardless of type. - text: Search all sources for {search}. slots: search: query.search - text: Show only sources whose managed flag is {managed}. slots: managed: query.managed method: generated generated: '2026-09-26' - target: $.paths['/sources/all/{slug}/'].get update: x-apievangelist-phrasing: intent: Get any source by its slug effect: read questions: - What type of source is behind a given slug, whatever protocol it uses? - Can I look up a source's generic details without knowing if it's LDAP, SAML or OAuth? instructions: - text: Show the source with slug {slug}. slots: slug: path.slug - text: Look up generic source {slug} and tell me its component type. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/all/{slug}/'].delete update: x-apievangelist-phrasing: intent: Delete a source of any type effect: destructive questions: - Can built-in sources be deleted, or only ones I created? - What's the generic way to remove a source without going through its type-specific endpoint? instructions: - text: Delete source {slug} through the all-sources endpoint. slots: slug: path.slug - text: Remove the non-built-in source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/all/{slug}/used_by/'].get update: x-apievangelist-phrasing: intent: See what depends on a source effect: read questions: - Which objects still reference a source before I delete it? - What would break if I removed a particular source, regardless of its type? instructions: - text: List everything that uses source {slug}. slots: slug: path.slug - text: Check dependents of source {slug} via the generic sources endpoint. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/all/types/'].get update: x-apievangelist-phrasing: intent: List source types that can be created effect: read questions: - What kinds of sources can I create in authentik? - Which source protocols are available to add as a new source? instructions: - text: List all creatable source types. - text: Show me the source type catalog I can pick from when adding a source. method: generated generated: '2026-09-26' - target: $.paths['/sources/all/user_settings/'].get update: x-apievangelist-phrasing: intent: List sources the current user can configure effect: read questions: - Which sources can I, as a signed-in user, connect or configure on my own account? - What sources show up in a user's personal settings page? instructions: - text: List the sources I can configure from my user settings. - text: Show which sources the current user is allowed to link to their account. method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/all/'].get update: x-apievangelist-phrasing: intent: List group-source connections of every type effect: read questions: - Which authentik groups are linked to groups in external sources, across all source types? - Can I find every group connection coming from one source slug? instructions: - text: List all group-source connections. - text: Show group connections of every source type for source {source_slug}. slots: source_slug: query.source__slug - text: Find group connections of any type for group {group}. slots: group: query.group method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/all/{id}/'].get update: x-apievangelist-phrasing: intent: Get a group-source connection of any type effect: read questions: - What external identifier is a particular group connection mapped to, whatever its source type? - Is there a way to read one group connection without knowing which source type it belongs to? instructions: - text: Show group-source connection {id} from the all-types endpoint. slots: id: path.id - text: Get the identifier stored on generic group connection {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/all/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a group-source connection of any type effect: write questions: - Can I fully overwrite a group connection's source and identifier through the generic endpoint? - What's required to replace an existing group link regardless of its source type? instructions: - text: Replace generic group connection {id} with source {source} and identifier {identifier}. slots: id: path.id source: requestBody.source identifier: requestBody.identifier - text: Overwrite all fields of group connection {id} via the all-types endpoint, identifier {identifier}. slots: id: path.id identifier: requestBody.identifier method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/all/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a group-source connection of any type effect: destructive questions: - How can I unlink a group from an external source without knowing the source type? - Does removing a group connection through the generic endpoint delete the group itself? instructions: - text: Delete group-source connection {id} via the all-types endpoint. slots: id: path.id - text: Unlink generic group connection {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/all/{id}/'].patch update: x-apievangelist-phrasing: intent: Edit part of a group-source connection of any type effect: write questions: - Can I change only the external identifier on a group link without resending everything? - Is it possible to patch a group connection through the endpoint that covers all source types? instructions: - text: Change just the identifier on generic group connection {id} to {identifier}. slots: id: path.id identifier: requestBody.identifier - text: Patch group connection {id} (any type) to point at source {source}. slots: id: path.id source: requestBody.source method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/all/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a group-source connection of any type effect: read questions: - Which objects reference a given group connection, whatever its source type? - Before unlinking a group via the generic endpoint, what depends on that link? instructions: - text: List dependents of generic group connection {id}. slots: id: path.id - text: Show what uses group-source connection {id} across source types. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/kerberos/'].get update: x-apievangelist-phrasing: intent: List Kerberos group connections effect: read questions: - Which groups are linked to a Kerberos realm source? - Can I list Kerberos group links for just one group? instructions: - text: List Kerberos group connections. - text: Show Kerberos group links for group {group}. slots: group: query.group - text: Find Kerberos group connections on source {source_slug}. slots: source_slug: query.source__slug method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/kerberos/'].post update: x-apievangelist-phrasing: intent: Link a group to a Kerberos source effect: write questions: - How do I map an authentik group to a group from a Kerberos source? - What identifier does a new Kerberos group connection need? instructions: - text: Link Kerberos source {source} to a group with identifier {identifier}. slots: source: requestBody.source identifier: requestBody.identifier - text: Create a Kerberos group connection for identifier {identifier}. slots: identifier: requestBody.identifier method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/kerberos/{id}/'].get update: x-apievangelist-phrasing: intent: Get a Kerberos group connection effect: read questions: - What does a single Kerberos group link point to? - Can I see which Kerberos source a specific group connection came from? instructions: - text: Show Kerberos group connection {id}. slots: id: path.id - text: Get the Kerberos identifier on group link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/kerberos/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a Kerberos group connection effect: write questions: - Can I overwrite a Kerberos group link with a new source and identifier? - What fields must I send to fully replace a Kerberos group connection? instructions: - text: Replace Kerberos group connection {id} with source {source} and identifier {identifier}. slots: id: path.id source: requestBody.source identifier: requestBody.identifier - text: Overwrite Kerberos group link {id} entirely. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/kerberos/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a Kerberos group connection effect: destructive questions: - Can I unlink a group from its Kerberos source? - What happens when a Kerberos group connection is removed? instructions: - text: Delete Kerberos group connection {id}. slots: id: path.id - text: Unlink the Kerberos group mapping {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/kerberos/{id}/'].patch update: x-apievangelist-phrasing: intent: Edit part of a Kerberos group connection effect: write questions: - Is there a way to change only the identifier of a Kerberos group link? - Can I point an existing Kerberos group connection at another Kerberos source? instructions: - text: Set identifier {identifier} on Kerberos group connection {id}. slots: id: path.id identifier: requestBody.identifier - text: Move Kerberos group link {id} to source {source}. slots: id: path.id source: requestBody.source method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/kerberos/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a Kerberos group connection effect: read questions: - What references a Kerberos group connection? - Is anything depending on this Kerberos group link before I delete it? instructions: - text: List objects that use Kerberos group connection {id}. slots: id: path.id - text: Check dependents of Kerberos group link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/ldap/'].get update: x-apievangelist-phrasing: intent: List LDAP group connections effect: read questions: - Which authentik groups were synced from an LDAP directory? - Can I search the LDAP group connections by name? instructions: - text: List LDAP group connections. - text: Search LDAP group links for {search}. slots: search: query.search - text: Show LDAP group connections from source {source_slug}. slots: source_slug: query.source__slug method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/ldap/'].post update: x-apievangelist-phrasing: intent: Link a group to a LDAP source effect: write questions: - How do I tie an authentik group to an LDAP group by its DN or unique ID? - What's needed to create a new LDAP group connection by hand? instructions: - text: Link LDAP source {source} to a group using identifier {identifier}. slots: source: requestBody.source identifier: requestBody.identifier - text: Create an LDAP group connection with identifier {identifier}. slots: identifier: requestBody.identifier method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/ldap/{id}/'].get update: x-apievangelist-phrasing: intent: Get a LDAP group connection effect: read questions: - Which LDAP object is a given group connection tied to? - Can I read the LDAP identifier stored on one group link? instructions: - text: Show LDAP group connection {id}. slots: id: path.id - text: Get the LDAP source behind group link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/ldap/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a LDAP group connection effect: write questions: - Can I fully replace an LDAP group connection's source and identifier? - What does a full overwrite of an LDAP group link require? instructions: - text: Replace LDAP group connection {id} with source {source} and identifier {identifier}. slots: id: path.id source: requestBody.source identifier: requestBody.identifier - text: Overwrite LDAP group link {id} with identifier {identifier}. slots: id: path.id identifier: requestBody.identifier method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/ldap/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a LDAP group connection effect: destructive questions: - Can I disconnect a group from its LDAP directory entry? - Will deleting an LDAP group connection stop that group syncing? instructions: - text: Delete LDAP group connection {id}. slots: id: path.id - text: Unlink the group behind LDAP connection {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/ldap/{id}/'].patch update: x-apievangelist-phrasing: intent: Edit part of a LDAP group connection effect: write questions: - Can I update only the identifier on an LDAP group link? - Is there a partial update for LDAP group connections? instructions: - text: Change the identifier of LDAP group connection {id} to {identifier}. slots: id: path.id identifier: requestBody.identifier - text: Reassign LDAP group link {id} to source {source}. slots: id: path.id source: requestBody.source method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/ldap/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a LDAP group connection effect: read questions: - What objects depend on an LDAP group connection? - Is an LDAP group link referenced anywhere else? instructions: - text: List dependents of LDAP group connection {id}. slots: id: path.id - text: Show what uses LDAP group link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/oauth/'].get update: x-apievangelist-phrasing: intent: List OAuth group connections effect: read questions: - Which groups came in from an OAuth or OpenID Connect source? - Can I filter OAuth group connections to a single group? instructions: - text: List OAuth group connections. - text: Show OAuth group links for group {group}. slots: group: query.group - text: Find OAuth group connections from source {source_slug}. slots: source_slug: query.source__slug method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/oauth/'].post update: x-apievangelist-phrasing: intent: Link a group to a OAuth source effect: write questions: - How do I link an authentik group to a group claim from an OAuth source? - What does a new OAuth group connection need as its identifier? instructions: - text: Link OAuth source {source} to a group with identifier {identifier}. slots: source: requestBody.source identifier: requestBody.identifier - text: Create an OAuth group connection for claim value {identifier}. slots: identifier: requestBody.identifier method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/oauth/{id}/'].get update: x-apievangelist-phrasing: intent: Get a OAuth group connection effect: read questions: - What group identifier is stored on a single OAuth group link? - Which OAuth source does one group connection belong to? instructions: - text: Show OAuth group connection {id}. slots: id: path.id - text: Get the OAuth source and identifier for group link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/oauth/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a OAuth group connection effect: write questions: - Can I overwrite an OAuth group connection completely? - What must I send to replace an OAuth group link? instructions: - text: Replace OAuth group connection {id} with source {source} and identifier {identifier}. slots: id: path.id source: requestBody.source identifier: requestBody.identifier - text: Fully overwrite OAuth group link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/oauth/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a OAuth group connection effect: destructive questions: - Can I remove the link between a group and an OAuth source? - What happens to the group when an OAuth group connection is deleted? instructions: - text: Delete OAuth group connection {id}. slots: id: path.id - text: Unlink OAuth group mapping {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/oauth/{id}/'].patch update: x-apievangelist-phrasing: intent: Edit part of a OAuth group connection effect: write questions: - Is it possible to change only the identifier of an OAuth group link? - Can I switch an OAuth group connection to a different OAuth source? instructions: - text: Update the identifier on OAuth group connection {id} to {identifier}. slots: id: path.id identifier: requestBody.identifier - text: Point OAuth group link {id} at source {source}. slots: id: path.id source: requestBody.source method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/oauth/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a OAuth group connection effect: read questions: - What references an OAuth group connection? - Does anything rely on this OAuth group link? instructions: - text: List objects using OAuth group connection {id}. slots: id: path.id - text: Check what depends on OAuth group link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/plex/'].get update: x-apievangelist-phrasing: intent: List Plex group connections effect: read questions: - Which groups are linked to a Plex source? - Can I search Plex group connections? instructions: - text: List Plex group connections. - text: Search Plex group links for {search}. slots: search: query.search - text: Show Plex group connections for group {group}. slots: group: query.group method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/plex/'].post update: x-apievangelist-phrasing: intent: Link a group to a Plex source effect: write questions: - How do I attach an authentik group to a Plex source? - What identifier does a Plex group connection take? instructions: - text: Link Plex source {source} to a group with identifier {identifier}. slots: source: requestBody.source identifier: requestBody.identifier - text: Create a Plex group connection using identifier {identifier}. slots: identifier: requestBody.identifier method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/plex/{id}/'].get update: x-apievangelist-phrasing: intent: Get a Plex group connection effect: read questions: - What's stored on a single Plex group link? - Which Plex source is one group connection tied to? instructions: - text: Show Plex group connection {id}. slots: id: path.id - text: Get the identifier of Plex group link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/plex/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a Plex group connection effect: write questions: - Can I fully replace a Plex group connection? - Which fields are required to overwrite a Plex group link? instructions: - text: Replace Plex group connection {id} with source {source} and identifier {identifier}. slots: id: path.id source: requestBody.source identifier: requestBody.identifier - text: Overwrite Plex group link {id} completely. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/plex/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a Plex group connection effect: destructive questions: - Can I unlink a group from a Plex source? - Is deleting a Plex group connection reversible? instructions: - text: Delete Plex group connection {id}. slots: id: path.id - text: Remove the Plex group mapping {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/plex/{id}/'].patch update: x-apievangelist-phrasing: intent: Edit part of a Plex group connection effect: write questions: - Can I edit just the identifier on a Plex group link? - Is there a way to move a Plex group connection to another Plex source? instructions: - text: Set identifier {identifier} on Plex group connection {id}. slots: id: path.id identifier: requestBody.identifier - text: Reassign Plex group link {id} to source {source}. slots: id: path.id source: requestBody.source method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/plex/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a Plex group connection effect: read questions: - What depends on a Plex group connection? - Is a Plex group link referenced by other objects? instructions: - text: List dependents of Plex group connection {id}. slots: id: path.id - text: Show what uses Plex group link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/saml/'].get update: x-apievangelist-phrasing: intent: List SAML group connections effect: read questions: - Which groups were mapped in from a SAML identity provider? - Can I list SAML group connections for one SAML source? instructions: - text: List SAML group connections. - text: Show SAML group links from source {source_slug}. slots: source_slug: query.source__slug - text: Find SAML group connections for group {group}. slots: group: query.group method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/saml/'].post update: x-apievangelist-phrasing: intent: Link a group to a SAML source effect: write questions: - How do I map an authentik group to a group attribute from a SAML source? - What identifier does a new SAML group connection expect? instructions: - text: Link SAML source {source} to a group with identifier {identifier}. slots: source: requestBody.source identifier: requestBody.identifier - text: Create a SAML group connection for attribute value {identifier}. slots: identifier: requestBody.identifier method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/saml/{id}/'].get update: x-apievangelist-phrasing: intent: Get a SAML group connection effect: read questions: - What SAML group value is a specific group connection mapped to? - Which SAML source owns one group link? instructions: - text: Show SAML group connection {id}. slots: id: path.id - text: Get the SAML identifier on group link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/saml/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a SAML group connection effect: write questions: - Can I replace a SAML group connection's source and identifier together? - What's needed for a full overwrite of a SAML group link? instructions: - text: Replace SAML group connection {id} with source {source} and identifier {identifier}. slots: id: path.id source: requestBody.source identifier: requestBody.identifier - text: Overwrite SAML group link {id} in full. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/saml/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a SAML group connection effect: destructive questions: - Can I disconnect a group from its SAML identity provider mapping? - What happens when a SAML group connection is deleted? instructions: - text: Delete SAML group connection {id}. slots: id: path.id - text: Unlink SAML group mapping {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/saml/{id}/'].patch update: x-apievangelist-phrasing: intent: Edit part of a SAML group connection effect: write questions: - Can I change only the identifier on a SAML group link? - Is there a partial update for SAML group connections? instructions: - text: Change the identifier on SAML group connection {id} to {identifier}. slots: id: path.id identifier: requestBody.identifier - text: Point SAML group link {id} to source {source}. slots: id: path.id source: requestBody.source method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/saml/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a SAML group connection effect: read questions: - What references a SAML group connection? - Is anything relying on a SAML group link I want to remove? instructions: - text: List objects using SAML group connection {id}. slots: id: path.id - text: Check dependents of SAML group link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/telegram/'].get update: x-apievangelist-phrasing: intent: List Telegram group connections effect: read questions: - Which groups are linked to a Telegram source? - Can I search Telegram group connections? instructions: - text: List Telegram group connections. - text: Search Telegram group links for {search}. slots: search: query.search - text: Show Telegram group connections from source {source_slug}. slots: source_slug: query.source__slug method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/telegram/'].post update: x-apievangelist-phrasing: intent: Link a group to a Telegram source effect: write questions: - How do I link an authentik group to a Telegram source? - What identifier does a Telegram group connection need? instructions: - text: Link Telegram source {source} to a group with identifier {identifier}. slots: source: requestBody.source identifier: requestBody.identifier - text: Create a Telegram group connection with identifier {identifier}. slots: identifier: requestBody.identifier method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/telegram/{id}/'].get update: x-apievangelist-phrasing: intent: Get a Telegram group connection effect: read questions: - What does one Telegram group link contain? - Which Telegram source is a specific group connection tied to? instructions: - text: Show Telegram group connection {id}. slots: id: path.id - text: Get the identifier on Telegram group link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/telegram/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a Telegram group connection effect: write questions: - Can I overwrite a Telegram group connection entirely? - What must I send to replace a Telegram group link? instructions: - text: Replace Telegram group connection {id} with source {source} and identifier {identifier}. slots: id: path.id source: requestBody.source identifier: requestBody.identifier - text: Fully overwrite Telegram group link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/telegram/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a Telegram group connection effect: destructive questions: - Can I unlink a group from a Telegram source? - Does deleting a Telegram group connection affect the group's members? instructions: - text: Delete Telegram group connection {id}. slots: id: path.id - text: Remove Telegram group mapping {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/telegram/{id}/'].patch update: x-apievangelist-phrasing: intent: Edit part of a Telegram group connection effect: write questions: - Can I update only the identifier on a Telegram group link? - Is it possible to switch a Telegram group connection to another Telegram source? instructions: - text: Set identifier {identifier} on Telegram group connection {id}. slots: id: path.id identifier: requestBody.identifier - text: Move Telegram group link {id} to source {source}. slots: id: path.id source: requestBody.source method: generated generated: '2026-09-26' - target: $.paths['/sources/group_connections/telegram/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a Telegram group connection effect: read questions: - What depends on a Telegram group connection? - Is a Telegram group link referenced anywhere? instructions: - text: List dependents of Telegram group connection {id}. slots: id: path.id - text: Show what uses Telegram group link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/kerberos/'].get update: x-apievangelist-phrasing: intent: List Kerberos sources effect: read questions: - Which Kerberos realms are connected to authentik as login sources? - Can I find Kerberos sources that sync users from a particular realm? - Which Kerberos sources have user password sync turned on? instructions: - text: List all Kerberos sources. - text: Show Kerberos sources for realm {realm}. slots: realm: query.realm - text: Find Kerberos sources where user sync is {sync_users}. slots: sync_users: query.sync_users method: generated generated: '2026-09-26' - target: $.paths['/sources/kerberos/'].post update: x-apievangelist-phrasing: intent: Add a Kerberos source effect: write questions: - How do I connect a Kerberos realm to authentik for SPNEGO and password logins? - What's required to set up a new Kerberos source? instructions: - text: Create a Kerberos source {name} with slug {slug} for realm {realm}. slots: name: requestBody.name slug: requestBody.slug realm: requestBody.realm - text: Add Kerberos source {name} (slug {slug}, realm {realm}) that syncs users using principal {sync_principal}. slots: name: requestBody.name slug: requestBody.slug realm: requestBody.realm sync_principal: requestBody.sync_principal method: generated generated: '2026-09-26' - target: $.paths['/sources/kerberos/{slug}/'].get update: x-apievangelist-phrasing: intent: Get a Kerberos source effect: read questions: - What realm and sync settings does a specific Kerberos source use? - Is SPNEGO configured on one of my Kerberos sources? instructions: - text: Show Kerberos source {slug}. slots: slug: path.slug - text: Get the realm and kadmin settings of Kerberos source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/kerberos/{slug}/'].put update: x-apievangelist-phrasing: intent: Replace a Kerberos source's configuration effect: write questions: - Can I overwrite a Kerberos source's full configuration in one call? - Which fields are mandatory when replacing a Kerberos source? instructions: - text: Replace Kerberos source {slug} with name {name}, new slug {new_slug} and realm {realm}. slots: slug: path.slug name: requestBody.name new_slug: requestBody.slug realm: requestBody.realm - text: Fully reconfigure Kerberos source {slug} for realm {realm}. slots: slug: path.slug realm: requestBody.realm method: generated generated: '2026-09-26' - target: $.paths['/sources/kerberos/{slug}/'].delete update: x-apievangelist-phrasing: intent: Delete a Kerberos source effect: destructive questions: - How do I remove a Kerberos realm source from authentik? - What happens to users synced from a Kerberos source when I delete it? instructions: - text: Delete Kerberos source {slug}. slots: slug: path.slug - text: Remove the Kerberos realm source {slug} from authentik. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/kerberos/{slug}/'].patch update: x-apievangelist-phrasing: intent: Change settings on a Kerberos source effect: write questions: - Can I just toggle user syncing on a Kerberos source without resending everything? - Is it possible to change only the SPNEGO server name of a Kerberos source? instructions: - text: Disable Kerberos source {slug} by setting enabled to {enabled}. slots: slug: path.slug enabled: requestBody.enabled - text: Set the SPNEGO server name on Kerberos source {slug} to {spnego_server_name}. slots: slug: path.slug spnego_server_name: requestBody.spnego_server_name - text: Turn user sync to {sync_users} on Kerberos source {slug}. slots: slug: path.slug sync_users: requestBody.sync_users method: generated generated: '2026-09-26' - target: $.paths['/sources/kerberos/{slug}/sync/status/'].get update: x-apievangelist-phrasing: intent: Check a Kerberos source's sync status effect: read questions: - Did the last Kerberos user sync finish, and when did it run? - Is a Kerberos source currently syncing? instructions: - text: Show sync status for Kerberos source {slug}. slots: slug: path.slug - text: Check whether Kerberos source {slug} is syncing right now. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/kerberos/{slug}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a Kerberos source effect: read questions: - Which flows or objects reference a Kerberos source? - What depends on a Kerberos source before I delete it? instructions: - text: List objects that use Kerberos source {slug}. slots: slug: path.slug - text: Check dependents of Kerberos source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/ldap/'].get update: x-apievangelist-phrasing: intent: List LDAP sources effect: read questions: - Which LDAP or Active Directory servers are connected to authentik? - Can I find LDAP sources pointed at a specific server URI? - Which LDAP sources are syncing groups as well as users? instructions: - text: List all LDAP sources. - text: Show LDAP sources connected to {server_uri}. slots: server_uri: query.server_uri - text: Find LDAP sources with base DN {base_dn}. slots: base_dn: query.base_dn method: generated generated: '2026-09-26' - target: $.paths['/sources/ldap/'].post update: x-apievangelist-phrasing: intent: Add an LDAP source effect: write questions: - How do I connect an Active Directory or LDAP server to authentik? - What settings are required to create an LDAP source? instructions: - text: Create LDAP source {name} with slug {slug} at {server_uri} using base DN {base_dn}. slots: name: requestBody.name slug: requestBody.slug server_uri: requestBody.server_uri base_dn: requestBody.base_dn - text: Add LDAP source {name} (slug {slug}) at {server_uri}, base DN {base_dn}, binding as {bind_cn}. slots: name: requestBody.name slug: requestBody.slug server_uri: requestBody.server_uri base_dn: requestBody.base_dn bind_cn: requestBody.bind_cn method: generated generated: '2026-09-26' - target: $.paths['/sources/ldap/{slug}/'].get update: x-apievangelist-phrasing: intent: Get an LDAP source effect: read questions: - What server, base DN and filters does a particular LDAP source use? - Is StartTLS turned on for one of my LDAP sources? instructions: - text: Show LDAP source {slug}. slots: slug: path.slug - text: Get the connection and filter settings of LDAP source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/ldap/{slug}/'].put update: x-apievangelist-phrasing: intent: Replace an LDAP source's configuration effect: write questions: - Can I overwrite an LDAP source's whole configuration at once? - Which fields must be supplied when fully replacing an LDAP source? instructions: - text: Replace LDAP source {slug} with name {name}, slug {new_slug}, server {server_uri} and base DN {base_dn}. slots: slug: path.slug name: requestBody.name new_slug: requestBody.slug server_uri: requestBody.server_uri base_dn: requestBody.base_dn - text: Fully reconfigure LDAP source {slug} to use server {server_uri}. slots: slug: path.slug server_uri: requestBody.server_uri method: generated generated: '2026-09-26' - target: $.paths['/sources/ldap/{slug}/'].delete update: x-apievangelist-phrasing: intent: Delete an LDAP source effect: destructive questions: - How do I disconnect an LDAP directory from authentik? - Does deleting an LDAP source remove the users it synced? instructions: - text: Delete LDAP source {slug}. slots: slug: path.slug - text: Remove the LDAP directory source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/ldap/{slug}/'].patch update: x-apievangelist-phrasing: intent: Change settings on an LDAP source effect: write questions: - Can I rotate just the bind password on an LDAP source? - Is it possible to change only the user object filter of an LDAP source? instructions: - text: Set the bind password on LDAP source {slug} to {bind_password}. slots: slug: path.slug bind_password: requestBody.bind_password - text: Change the user object filter of LDAP source {slug} to {user_object_filter}. slots: slug: path.slug user_object_filter: requestBody.user_object_filter - text: Turn group sync to {sync_groups} on LDAP source {slug}. slots: slug: path.slug sync_groups: requestBody.sync_groups method: generated generated: '2026-09-26' - target: $.paths['/sources/ldap/{slug}/debug/'].get update: x-apievangelist-phrasing: intent: Get raw LDAP data for debugging effect: read questions: - How can I see the raw LDAP data authentik pulls from my directory? - Can I debug why LDAP users aren't mapping correctly by inspecting the raw entries? instructions: - text: Fetch raw debug data from LDAP source {slug}. slots: slug: path.slug - text: Dump the raw LDAP entries for source {slug} so I can troubleshoot. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/ldap/{slug}/sync/status/'].get update: x-apievangelist-phrasing: intent: Check an LDAP source's sync status effect: read questions: - When did the last LDAP sync run, and did it succeed? - Is my LDAP directory sync still in progress? instructions: - text: Show sync status for LDAP source {slug}. slots: slug: path.slug - text: Check whether LDAP source {slug} is currently syncing. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/ldap/{slug}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses an LDAP source effect: read questions: - Which objects reference an LDAP source? - What would be affected if I removed an LDAP source? instructions: - text: List objects that use LDAP source {slug}. slots: slug: path.slug - text: Check dependents of LDAP source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/oauth/'].get update: x-apievangelist-phrasing: intent: List OAuth sources effect: read questions: - Which social login and OpenID Connect sources are configured in authentik? - Can I list only the OAuth sources built on one particular provider type? - Which OAuth sources have JWKS configured? instructions: - text: List all OAuth sources. - text: Show OAuth sources of provider type {provider_type}. slots: provider_type: query.provider_type - text: Find OAuth sources using consumer key {consumer_key}. slots: consumer_key: query.consumer_key method: generated generated: '2026-09-26' - target: $.paths['/sources/oauth/'].post update: x-apievangelist-phrasing: intent: Add an OAuth or OIDC login source effect: write questions: - How do I add a new social or OpenID Connect login button to authentik? - What client credentials does a new OAuth source require? instructions: - text: Create OAuth source {name} with slug {slug}, type {provider_type}, key {consumer_key} and secret {consumer_secret}. slots: name: requestBody.name slug: requestBody.slug provider_type: requestBody.provider_type consumer_key: requestBody.consumer_key consumer_secret: requestBody.consumer_secret - text: Add an OIDC source {name} (slug {slug}, type {provider_type}, key {consumer_key}, secret {consumer_secret}) from well-known URL {oidc_well_known_url}. slots: name: requestBody.name slug: requestBody.slug provider_type: requestBody.provider_type consumer_key: requestBody.consumer_key consumer_secret: requestBody.consumer_secret oidc_well_known_url: requestBody.oidc_well_known_url method: generated generated: '2026-09-26' - target: $.paths['/sources/oauth/{slug}/'].get update: x-apievangelist-phrasing: intent: Get an OAuth source effect: read questions: - What authorization and token URLs does a specific OAuth source use? - Is PKCE enabled on one of my OAuth login sources? instructions: - text: Show OAuth source {slug}. slots: slug: path.slug - text: Get the endpoints and scopes of OAuth source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/oauth/{slug}/'].put update: x-apievangelist-phrasing: intent: Replace an OAuth source's configuration effect: write questions: - Can I overwrite an OAuth source's full configuration including its credentials? - What must I include when fully replacing an OAuth source? instructions: - text: Replace OAuth source {slug} with name {name}, slug {new_slug}, type {provider_type}, key {consumer_key} and secret {consumer_secret}. slots: slug: path.slug name: requestBody.name new_slug: requestBody.slug provider_type: requestBody.provider_type consumer_key: requestBody.consumer_key consumer_secret: requestBody.consumer_secret - text: Fully reconfigure OAuth source {slug} as provider type {provider_type}. slots: slug: path.slug provider_type: requestBody.provider_type method: generated generated: '2026-09-26' - target: $.paths['/sources/oauth/{slug}/'].delete update: x-apievangelist-phrasing: intent: Delete an OAuth source effect: destructive questions: - How do I remove a social login option from authentik? - What happens to users' linked accounts when an OAuth source is deleted? instructions: - text: Delete OAuth source {slug}. slots: slug: path.slug - text: Remove the social login source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/oauth/{slug}/'].patch update: x-apievangelist-phrasing: intent: Change settings on an OAuth source effect: write questions: - Can I rotate just the client secret on an OAuth source? - Is it possible to add extra scopes to an existing OAuth source without resending everything? instructions: - text: Set the client secret of OAuth source {slug} to {consumer_secret}. slots: slug: path.slug consumer_secret: requestBody.consumer_secret - text: Add scopes {additional_scopes} to OAuth source {slug}. slots: slug: path.slug additional_scopes: requestBody.additional_scopes - text: Turn PKCE to {pkce} on OAuth source {slug}. slots: slug: path.slug pkce: requestBody.pkce method: generated generated: '2026-09-26' - target: $.paths['/sources/oauth/{slug}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses an OAuth source effect: read questions: - Which objects reference an OAuth login source? - Is an OAuth source still used somewhere before I delete it? instructions: - text: List objects that use OAuth source {slug}. slots: slug: path.slug - text: Check dependents of OAuth source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/oauth/source_types/'].get update: x-apievangelist-phrasing: intent: List supported OAuth provider types effect: read questions: - Which built-in provider types can an OAuth source be based on? - What default URLs does authentik use for a given OAuth provider type? instructions: - text: List all OAuth source provider types. - text: Show the OAuth provider type named {name}. slots: name: query.name method: generated generated: '2026-09-26' - target: $.paths['/sources/plex/'].get update: x-apievangelist-phrasing: intent: List Plex sources effect: read questions: - Which Plex login sources are configured? - Can I find Plex sources that allow friends of the server owner to sign in? instructions: - text: List all Plex sources. - text: Show Plex sources where allow friends is {allow_friends}. slots: allow_friends: query.allow_friends - text: Find Plex sources with client ID {client_id}. slots: client_id: query.client_id method: generated generated: '2026-09-26' - target: $.paths['/sources/plex/'].post update: x-apievangelist-phrasing: intent: Add a Plex login source effect: write questions: - How do I let people sign in to authentik with their Plex account? - What token does a new Plex source require? instructions: - text: Create Plex source {name} with slug {slug} using Plex token {plex_token}. slots: name: requestBody.name slug: requestBody.slug plex_token: requestBody.plex_token - text: Add Plex source {name} (slug {slug}, token {plex_token}) limited to servers {allowed_servers}. slots: name: requestBody.name slug: requestBody.slug plex_token: requestBody.plex_token allowed_servers: requestBody.allowed_servers method: generated generated: '2026-09-26' - target: $.paths['/sources/plex/{slug}/'].get update: x-apievangelist-phrasing: intent: Get a Plex source effect: read questions: - Which Plex servers are allowed on a specific Plex source? - Does one of my Plex sources let friends log in? instructions: - text: Show Plex source {slug}. slots: slug: path.slug - text: Get the allowed servers on Plex source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/plex/{slug}/'].put update: x-apievangelist-phrasing: intent: Replace a Plex source's configuration effect: write questions: - Can I overwrite a Plex source's full configuration? - What fields are required when replacing a Plex source? instructions: - text: Replace Plex source {slug} with name {name}, slug {new_slug} and token {plex_token}. slots: slug: path.slug name: requestBody.name new_slug: requestBody.slug plex_token: requestBody.plex_token - text: Fully reconfigure Plex source {slug} with Plex token {plex_token}. slots: slug: path.slug plex_token: requestBody.plex_token method: generated generated: '2026-09-26' - target: $.paths['/sources/plex/{slug}/'].delete update: x-apievangelist-phrasing: intent: Delete a Plex source effect: destructive questions: - How do I remove Plex login from authentik? - Is deleting a Plex source permanent? instructions: - text: Delete Plex source {slug}. slots: slug: path.slug - text: Remove the Plex login source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/plex/{slug}/'].patch update: x-apievangelist-phrasing: intent: Change settings on a Plex source effect: write questions: - Can I change only the allowed servers on a Plex source? - Is there a way to stop friends from logging in via Plex without redoing the source? instructions: - text: Set allowed servers on Plex source {slug} to {allowed_servers}. slots: slug: path.slug allowed_servers: requestBody.allowed_servers - text: Set allow friends to {allow_friends} on Plex source {slug}. slots: slug: path.slug allow_friends: requestBody.allow_friends method: generated generated: '2026-09-26' - target: $.paths['/sources/plex/{slug}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a Plex source effect: read questions: - Which objects reference a Plex source? - Does anything depend on my Plex source? instructions: - text: List objects that use Plex source {slug}. slots: slug: path.slug - text: Check dependents of Plex source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/plex/redeem_token/'].post update: x-apievangelist-phrasing: intent: Redeem a Plex token to start sign-in effect: write questions: - How does authentik check a Plex token against the servers a source allows? - What happens after a Plex token is redeemed for a user who isn't logged in yet? instructions: - text: Redeem Plex token {plex_token} against source {slug} and start the login flow. slots: plex_token: requestBody.plex_token slug: query.slug - text: Validate Plex token {plex_token} for server access and redirect to enrollment. slots: plex_token: requestBody.plex_token method: generated generated: '2026-09-26' - target: $.paths['/sources/plex/redeem_token_authenticated/'].post update: x-apievangelist-phrasing: intent: Link a Plex account to a signed-in user effect: write questions: - Can an already logged-in user connect their Plex account by redeeming a token? - What creates a Plex user connection for someone who is already authenticated? instructions: - text: Redeem Plex token {plex_token} for my signed-in account on source {slug}. slots: plex_token: requestBody.plex_token slug: query.slug - text: Connect my current user to Plex using token {plex_token}. slots: plex_token: requestBody.plex_token method: generated generated: '2026-09-26' - target: $.paths['/sources/saml/'].get update: x-apievangelist-phrasing: intent: List SAML sources effect: read questions: - Which SAML identity providers are configured as login sources? - Can I find SAML sources that allow IdP-initiated logins? - Which SAML sources require signed assertions? instructions: - text: List all SAML sources. - text: Show SAML sources with SSO URL {sso_url}. slots: sso_url: query.sso_url - text: Find SAML sources using binding type {binding_type}. slots: binding_type: query.binding_type method: generated generated: '2026-09-26' - target: $.paths['/sources/saml/'].post update: x-apievangelist-phrasing: intent: Add a SAML login source effect: write questions: - How do I federate authentik with an external SAML identity provider? - Which settings are mandatory for a new SAML source? instructions: - text: Create SAML source {name} with slug {slug}, SSO URL {sso_url} and pre-auth flow {pre_authentication_flow}. slots: name: requestBody.name slug: requestBody.slug sso_url: requestBody.sso_url pre_authentication_flow: requestBody.pre_authentication_flow - text: Add SAML source {name} (slug {slug}, SSO {sso_url}, pre-auth flow {pre_authentication_flow}) with logout URL {slo_url}. slots: name: requestBody.name slug: requestBody.slug sso_url: requestBody.sso_url pre_authentication_flow: requestBody.pre_authentication_flow slo_url: requestBody.slo_url method: generated generated: '2026-09-26' - target: $.paths['/sources/saml/{slug}/'].get update: x-apievangelist-phrasing: intent: Get a SAML source effect: read questions: - What SSO URL and signing settings does a particular SAML source use? - Is force re-authentication on for one of my SAML sources? instructions: - text: Show SAML source {slug}. slots: slug: path.slug - text: Get the signing and binding settings of SAML source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/saml/{slug}/'].put update: x-apievangelist-phrasing: intent: Replace a SAML source's configuration effect: write questions: - Can I overwrite a SAML source's whole configuration in one call? - What is required when fully replacing a SAML source? instructions: - text: Replace SAML source {slug} with name {name}, slug {new_slug}, SSO URL {sso_url} and pre-auth flow {pre_authentication_flow}. slots: slug: path.slug name: requestBody.name new_slug: requestBody.slug sso_url: requestBody.sso_url pre_authentication_flow: requestBody.pre_authentication_flow - text: Fully reconfigure SAML source {slug} to use SSO URL {sso_url}. slots: slug: path.slug sso_url: requestBody.sso_url method: generated generated: '2026-09-26' - target: $.paths['/sources/saml/{slug}/'].delete update: x-apievangelist-phrasing: intent: Delete a SAML source effect: destructive questions: - How do I remove a SAML identity provider from authentik? - What happens to users linked through a SAML source if I delete it? instructions: - text: Delete SAML source {slug}. slots: slug: path.slug - text: Remove SAML identity provider source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/saml/{slug}/'].patch update: x-apievangelist-phrasing: intent: Change settings on a SAML source effect: write questions: - Can I swap only the verification certificate on a SAML source? - Is it possible to switch a SAML source's binding type without resending everything? instructions: - text: Set the verification keypair on SAML source {slug} to {verification_kp}. slots: slug: path.slug verification_kp: requestBody.verification_kp - text: Change the binding type of SAML source {slug} to {binding_type}. slots: slug: path.slug binding_type: requestBody.binding_type - text: Set how long temporary users last on SAML source {slug} to {temporary_user_delete_after}. slots: slug: path.slug temporary_user_delete_after: requestBody.temporary_user_delete_after method: generated generated: '2026-09-26' - target: $.paths['/sources/saml/{slug}/metadata/'].get update: x-apievangelist-phrasing: intent: Download a SAML source's metadata XML effect: read questions: - Where do I get the SP metadata XML to give my SAML identity provider? - Can I export a SAML source's metadata as XML? instructions: - text: Get the SAML metadata XML for source {slug}. slots: slug: path.slug - text: Export SP metadata for SAML source {slug} so I can upload it to the IdP. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/saml/{slug}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a SAML source effect: read questions: - Which objects reference a SAML source? - Is a SAML source still in use anywhere? instructions: - text: List objects that use SAML source {slug}. slots: slug: path.slug - text: Check dependents of SAML source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/scim/'].get update: x-apievangelist-phrasing: intent: List SCIM sources effect: read questions: - Which SCIM sources are provisioning users into authentik? - Can I search SCIM sources by name? instructions: - text: List all SCIM sources. - text: Find SCIM sources named {name}. slots: name: query.name - text: Search SCIM sources for {search}. slots: search: query.search method: generated generated: '2026-09-26' - target: $.paths['/sources/scim/'].post update: x-apievangelist-phrasing: intent: Add a SCIM provisioning source effect: write questions: - How do I let an external system push users and groups into authentik over SCIM? - What does a new SCIM source need? instructions: - text: Create SCIM source {name} with slug {slug}. slots: name: requestBody.name slug: requestBody.slug - text: Add SCIM source {name} (slug {slug}) placing users under path template {user_path_template}. slots: name: requestBody.name slug: requestBody.slug user_path_template: requestBody.user_path_template method: generated generated: '2026-09-26' - target: $.paths['/sources/scim/{slug}/'].get update: x-apievangelist-phrasing: intent: Get a SCIM source effect: read questions: - What property mappings and user path does a SCIM source use? - Is a particular SCIM source enabled? instructions: - text: Show SCIM source {slug}. slots: slug: path.slug - text: Get the configuration of SCIM source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/scim/{slug}/'].put update: x-apievangelist-phrasing: intent: Replace a SCIM source's configuration effect: write questions: - Can I overwrite a SCIM source's configuration fully? - Which fields are required when replacing a SCIM source? instructions: - text: Replace SCIM source {slug} with name {name} and slug {new_slug}. slots: slug: path.slug name: requestBody.name new_slug: requestBody.slug - text: Fully reconfigure SCIM source {slug} with user path template {user_path_template}. slots: slug: path.slug user_path_template: requestBody.user_path_template method: generated generated: '2026-09-26' - target: $.paths['/sources/scim/{slug}/'].delete update: x-apievangelist-phrasing: intent: Delete a SCIM source effect: destructive questions: - How do I stop an external system provisioning via SCIM into authentik? - Is removing a SCIM source reversible? instructions: - text: Delete SCIM source {slug}. slots: slug: path.slug - text: Remove SCIM provisioning source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/scim/{slug}/'].patch update: x-apievangelist-phrasing: intent: Change settings on a SCIM source effect: write questions: - Can I disable a SCIM source without deleting it? - Is it possible to change only the user path template on a SCIM source? instructions: - text: Set enabled to {enabled} on SCIM source {slug}. slots: slug: path.slug enabled: requestBody.enabled - text: Change the user path template of SCIM source {slug} to {user_path_template}. slots: slug: path.slug user_path_template: requestBody.user_path_template method: generated generated: '2026-09-26' - target: $.paths['/sources/scim/{slug}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a SCIM source effect: read questions: - Which objects reference a SCIM source? - Does anything depend on a SCIM source I plan to remove? instructions: - text: List objects that use SCIM source {slug}. slots: slug: path.slug - text: Check dependents of SCIM source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/scim_groups/'].get update: x-apievangelist-phrasing: intent: List groups provisioned via SCIM effect: read questions: - Which groups were pushed into authentik by a SCIM source? - Can I find a SCIM-provisioned group by its authentik group name? instructions: - text: List SCIM source groups. - text: Show SCIM-provisioned groups from source {source_slug}. slots: source_slug: query.source__slug - text: Find the SCIM group record for group name {group_name}. slots: group_name: query.group__name method: generated generated: '2026-09-26' - target: $.paths['/sources/scim_groups/'].post update: x-apievangelist-phrasing: intent: Record a SCIM-provisioned group effect: write questions: - How do I manually tie an authentik group to its external SCIM ID? - What's needed to create a SCIM source group record? instructions: - text: Create a SCIM group record linking group {group} to external ID {external_id} on source {source}. slots: group: requestBody.group external_id: requestBody.external_id source: requestBody.source - text: Register SCIM external group {external_id} for group {group} from source {source} with attributes {attributes}. slots: group: requestBody.group external_id: requestBody.external_id source: requestBody.source attributes: requestBody.attributes method: generated generated: '2026-09-26' - target: $.paths['/sources/scim_groups/{id}/'].get update: x-apievangelist-phrasing: intent: Get a SCIM-provisioned group record effect: read questions: - What external ID and attributes are stored for a SCIM-provisioned group? - Which SCIM source created a given group record? instructions: - text: Show SCIM source group {id}. slots: id: path.id - text: Get the SCIM attributes stored on group record {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/scim_groups/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a SCIM group record effect: write questions: - Can I overwrite a SCIM group record's external ID, group and source together? - What's required to fully replace a SCIM source group? instructions: - text: Replace SCIM group record {id} with external ID {external_id}, group {group} and source {source}. slots: id: path.id external_id: requestBody.external_id group: requestBody.group source: requestBody.source - text: Overwrite SCIM source group {id} in full. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/scim_groups/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a SCIM group record effect: destructive questions: - Can I remove the SCIM link for a provisioned group? - What happens when a SCIM source group record is deleted? instructions: - text: Delete SCIM source group {id}. slots: id: path.id - text: Remove the SCIM group record {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/scim_groups/{id}/'].patch update: x-apievangelist-phrasing: intent: Edit part of a SCIM group record effect: write questions: - Can I change only the external ID on a SCIM-provisioned group? - Is it possible to update the stored SCIM attributes of a group without resending the rest? instructions: - text: Set external ID {external_id} on SCIM group record {id}. slots: id: path.id external_id: requestBody.external_id - text: Update the SCIM attributes of group record {id} to {attributes}. slots: id: path.id attributes: requestBody.attributes method: generated generated: '2026-09-26' - target: $.paths['/sources/scim_groups/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a SCIM group record effect: read questions: - What references a SCIM-provisioned group record? - Is a SCIM source group depended on by anything? instructions: - text: List objects that use SCIM group record {id}. slots: id: path.id - text: Check dependents of SCIM source group {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/scim_users/'].get update: x-apievangelist-phrasing: intent: List users provisioned via SCIM effect: read questions: - Which users were pushed into authentik by a SCIM source? - Can I find the SCIM record for a user by username? instructions: - text: List SCIM source users. - text: Show SCIM-provisioned users from source {source_slug}. slots: source_slug: query.source__slug - text: Find the SCIM user record for username {username}. slots: username: query.user__username method: generated generated: '2026-09-26' - target: $.paths['/sources/scim_users/'].post update: x-apievangelist-phrasing: intent: Record a SCIM-provisioned user effect: write questions: - How do I manually map an authentik user to their external SCIM ID? - What does creating a SCIM source user record require? instructions: - text: Create a SCIM user record linking user {user} to external ID {external_id} on source {source}. slots: user: requestBody.user external_id: requestBody.external_id source: requestBody.source - text: Register SCIM external user {external_id} for user {user} from source {source} with attributes {attributes}. slots: user: requestBody.user external_id: requestBody.external_id source: requestBody.source attributes: requestBody.attributes method: generated generated: '2026-09-26' - target: $.paths['/sources/scim_users/{id}/'].get update: x-apievangelist-phrasing: intent: Get a SCIM-provisioned user record effect: read questions: - What external ID and SCIM attributes are stored for a provisioned user? - Which SCIM source created a particular user record? instructions: - text: Show SCIM source user {id}. slots: id: path.id - text: Get the SCIM attributes on user record {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/scim_users/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a SCIM user record effect: write questions: - Can I overwrite a SCIM user record's external ID, user and source at once? - What's required to fully replace a SCIM source user? instructions: - text: Replace SCIM user record {id} with external ID {external_id}, user {user} and source {source}. slots: id: path.id external_id: requestBody.external_id user: requestBody.user source: requestBody.source - text: Overwrite SCIM source user {id} completely. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/scim_users/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a SCIM user record effect: destructive questions: - Can I remove the SCIM link for a provisioned user? - Does deleting a SCIM source user record affect the authentik user? instructions: - text: Delete SCIM source user {id}. slots: id: path.id - text: Remove the SCIM user record {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/scim_users/{id}/'].patch update: x-apievangelist-phrasing: intent: Edit part of a SCIM user record effect: write questions: - Can I change only the external ID of a SCIM-provisioned user? - Is it possible to patch the stored SCIM attributes of a user? instructions: - text: Set external ID {external_id} on SCIM user record {id}. slots: id: path.id external_id: requestBody.external_id - text: Update the SCIM attributes of user record {id} to {attributes}. slots: id: path.id attributes: requestBody.attributes method: generated generated: '2026-09-26' - target: $.paths['/sources/scim_users/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a SCIM user record effect: read questions: - What references a SCIM-provisioned user record? - Is a SCIM source user depended on by other objects? instructions: - text: List objects that use SCIM user record {id}. slots: id: path.id - text: Check dependents of SCIM source user {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/telegram/'].get update: x-apievangelist-phrasing: intent: List Telegram sources effect: read questions: - Which Telegram bot login sources are set up in authentik? - Can I find a Telegram source by its bot username? instructions: - text: List all Telegram sources. - text: Show Telegram sources for bot {bot_username}. slots: bot_username: query.bot_username - text: 'Find Telegram sources where message access is requested: {request_message_access}.' slots: request_message_access: query.request_message_access method: generated generated: '2026-09-26' - target: $.paths['/sources/telegram/'].post update: x-apievangelist-phrasing: intent: Add a Telegram login source effect: write questions: - How do I let users sign in to authentik with Telegram? - What bot details does a new Telegram source need? instructions: - text: Create Telegram source {name} with slug {slug} for bot {bot_username} using token {bot_token} and pre-auth flow {pre_authentication_flow}. slots: name: requestBody.name slug: requestBody.slug bot_username: requestBody.bot_username bot_token: requestBody.bot_token pre_authentication_flow: requestBody.pre_authentication_flow - text: Add Telegram login {name} (slug {slug}) with bot {bot_username}, token {bot_token}, pre-auth flow {pre_authentication_flow}. slots: name: requestBody.name slug: requestBody.slug bot_username: requestBody.bot_username bot_token: requestBody.bot_token pre_authentication_flow: requestBody.pre_authentication_flow method: generated generated: '2026-09-26' - target: $.paths['/sources/telegram/{slug}/'].get update: x-apievangelist-phrasing: intent: Get a Telegram source effect: read questions: - Which bot does a particular Telegram source use? - Does one of my Telegram sources request permission to message users? instructions: - text: Show Telegram source {slug}. slots: slug: path.slug - text: Get the bot settings of Telegram source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/telegram/{slug}/'].put update: x-apievangelist-phrasing: intent: Replace a Telegram source's configuration effect: write questions: - Can I overwrite a Telegram source's full configuration? - Which fields must I send to fully replace a Telegram source? instructions: - text: Replace Telegram source {slug} with name {name}, slug {new_slug}, bot {bot_username}, token {bot_token}, pre-auth flow {pre_authentication_flow}. slots: slug: path.slug name: requestBody.name new_slug: requestBody.slug bot_username: requestBody.bot_username bot_token: requestBody.bot_token pre_authentication_flow: requestBody.pre_authentication_flow - text: Fully reconfigure Telegram source {slug} to use bot {bot_username}. slots: slug: path.slug bot_username: requestBody.bot_username method: generated generated: '2026-09-26' - target: $.paths['/sources/telegram/{slug}/'].delete update: x-apievangelist-phrasing: intent: Delete a Telegram source effect: destructive questions: - How do I remove Telegram login from authentik? - Is deleting a Telegram source permanent? instructions: - text: Delete Telegram source {slug}. slots: slug: path.slug - text: Remove the Telegram login source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/telegram/{slug}/'].patch update: x-apievangelist-phrasing: intent: Change settings on a Telegram source effect: write questions: - Can I rotate just the bot token on a Telegram source? - Is it possible to turn off message access on a Telegram source without redoing it? instructions: - text: Set the bot token of Telegram source {slug} to {bot_token}. slots: slug: path.slug bot_token: requestBody.bot_token - text: Set request message access to {request_message_access} on Telegram source {slug}. slots: slug: path.slug request_message_access: requestBody.request_message_access method: generated generated: '2026-09-26' - target: $.paths['/sources/telegram/{slug}/connect_user/'].post update: x-apievangelist-phrasing: intent: Connect a Telegram account to a user effect: write questions: - How do I link someone's Telegram account to their authentik user using the login widget data? - What Telegram auth fields are needed to connect a user to a Telegram source? instructions: - text: Connect Telegram user {telegram_id} to source {slug} with auth date {auth_date} and hash {hash}. slots: slug: path.slug telegram_id: requestBody.id auth_date: requestBody.auth_date hash: requestBody.hash - text: Link Telegram account {telegram_id} (username {username}) via source {slug}, auth date {auth_date}, hash {hash}. slots: slug: path.slug telegram_id: requestBody.id username: requestBody.username auth_date: requestBody.auth_date hash: requestBody.hash method: generated generated: '2026-09-26' - target: $.paths['/sources/telegram/{slug}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a Telegram source effect: read questions: - Which objects reference a Telegram source? - Does anything depend on my Telegram login source? instructions: - text: List objects that use Telegram source {slug}. slots: slug: path.slug - text: Check dependents of Telegram source {slug}. slots: slug: path.slug method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/all/'].get update: x-apievangelist-phrasing: intent: List user-source connections of every type effect: read questions: - Which external accounts are linked to authentik users, across all source types? - Can I see every source a specific user has connected? instructions: - text: List all user-source connections. - text: Show user connections of every source type for user {user}. slots: user: query.user - text: Find user connections of any type on source {source_slug}. slots: source_slug: query.source__slug method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/all/{id}/'].get update: x-apievangelist-phrasing: intent: Get a user-source connection of any type effect: read questions: - What external identifier is linked to a user in one connection, whatever the source type? - Can I read a user's source link without knowing if it's OAuth, SAML or LDAP? instructions: - text: Show user-source connection {id} from the all-types endpoint. slots: id: path.id - text: Get the identifier on generic user connection {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/all/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a user-source connection of any type effect: write questions: - Can I overwrite a user's source link through the endpoint covering all source types? - What must be sent to replace a generic user connection? instructions: - text: Replace generic user connection {id} with source {source} and identifier {identifier}. slots: id: path.id source: requestBody.source identifier: requestBody.identifier - text: Overwrite user connection {id} via the all-types endpoint with identifier {identifier}. slots: id: path.id identifier: requestBody.identifier method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/all/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a user-source connection of any type effect: destructive questions: - How can I unlink a user's external account without knowing the source type? - Does removing a generic user connection delete the user? instructions: - text: Delete user-source connection {id} via the all-types endpoint. slots: id: path.id - text: Unlink generic user connection {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/all/{id}/'].patch update: x-apievangelist-phrasing: intent: Edit part of a user-source connection of any type effect: write questions: - Can I patch just the identifier on a user link through the generic endpoint? - Is there a partial update that works for user connections of any source type? instructions: - text: Change just the identifier on generic user connection {id} to {identifier}. slots: id: path.id identifier: requestBody.identifier - text: Patch user connection {id} (any type) to point at source {source}. slots: id: path.id source: requestBody.source method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/all/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a user-source connection of any type effect: read questions: - Which objects reference a user connection, whatever its source type? - Is a user's external account link referenced by anything, regardless of source type? instructions: - text: List dependents of generic user connection {id}. slots: id: path.id - text: Show what uses user-source connection {id} across source types. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/kerberos/'].get update: x-apievangelist-phrasing: intent: List Kerberos user connections effect: read questions: - Which users have a Kerberos principal linked to their account? - Can I list Kerberos user links for just one user? instructions: - text: List Kerberos user connections. - text: Show Kerberos user links for user {user}. slots: user: query.user - text: Find Kerberos user connections on source {source_slug}. slots: source_slug: query.source__slug method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/kerberos/'].post update: x-apievangelist-phrasing: intent: Link a user to a Kerberos principal effect: write questions: - How do I link a user to their Kerberos principal? - What identifier does a new Kerberos user connection take? instructions: - text: Link a user to Kerberos source {source} with principal {identifier}. slots: source: requestBody.source identifier: requestBody.identifier - text: Create a Kerberos user connection for principal {identifier}. slots: identifier: requestBody.identifier method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/kerberos/{id}/'].get update: x-apievangelist-phrasing: intent: Get a Kerberos user connection effect: read questions: - Which Kerberos principal is stored on a single user link? - What Kerberos source does one user connection belong to? instructions: - text: Show Kerberos user connection {id}. slots: id: path.id - text: Get the principal on Kerberos user link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/kerberos/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a Kerberos user connection effect: write questions: - Can I fully replace a Kerberos user connection? - What's required to overwrite a Kerberos user link? instructions: - text: Replace Kerberos user connection {id} with source {source} and principal {identifier}. slots: id: path.id source: requestBody.source identifier: requestBody.identifier - text: Overwrite Kerberos user link {id} entirely. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/kerberos/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a Kerberos user connection effect: destructive questions: - Can I unlink a user from their Kerberos principal? - What happens when a Kerberos user connection is removed? instructions: - text: Delete Kerberos user connection {id}. slots: id: path.id - text: Unlink the Kerberos principal on user link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/kerberos/{id}/'].patch update: x-apievangelist-phrasing: intent: Edit part of a Kerberos user connection effect: write questions: - Is there a way to change only the principal on a Kerberos user link? - Can I point a Kerberos user connection at another Kerberos source? instructions: - text: Set principal {identifier} on Kerberos user connection {id}. slots: id: path.id identifier: requestBody.identifier - text: Move Kerberos user link {id} to source {source}. slots: id: path.id source: requestBody.source method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/kerberos/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a Kerberos user connection effect: read questions: - What references a Kerberos user connection? - Is anything depending on a Kerberos user link? instructions: - text: List objects that use Kerberos user connection {id}. slots: id: path.id - text: Check dependents of Kerberos user link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/ldap/'].get update: x-apievangelist-phrasing: intent: List LDAP user connections effect: read questions: - Which authentik users are tied to entries in an LDAP directory? - Can I search LDAP user connections? instructions: - text: List LDAP user connections. - text: Search LDAP user links for {search}. slots: search: query.search - text: Show LDAP user connections for user {user}. slots: user: query.user method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/ldap/'].post update: x-apievangelist-phrasing: intent: Link a user to an LDAP entry effect: write questions: - How do I tie an authentik user to an LDAP directory entry by hand? - What identifier does an LDAP user connection need? instructions: - text: Link a user to LDAP source {source} with identifier {identifier}. slots: source: requestBody.source identifier: requestBody.identifier - text: Create an LDAP user connection for directory ID {identifier}. slots: identifier: requestBody.identifier method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/ldap/{id}/'].get update: x-apievangelist-phrasing: intent: Get a LDAP user connection effect: read questions: - Which LDAP entry is a given user connection mapped to? - Can I read the LDAP identifier on one user link? instructions: - text: Show LDAP user connection {id}. slots: id: path.id - text: Get the LDAP source behind user link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/ldap/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a LDAP user connection effect: write questions: - Can I overwrite an LDAP user connection completely? - What does a full replace of an LDAP user link require? instructions: - text: Replace LDAP user connection {id} with source {source} and identifier {identifier}. slots: id: path.id source: requestBody.source identifier: requestBody.identifier - text: Overwrite LDAP user link {id} with identifier {identifier}. slots: id: path.id identifier: requestBody.identifier method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/ldap/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a LDAP user connection effect: destructive questions: - Can I disconnect a user from their LDAP directory entry? - Will deleting an LDAP user connection stop that user syncing? instructions: - text: Delete LDAP user connection {id}. slots: id: path.id - text: Unlink the user behind LDAP connection {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/ldap/{id}/'].patch update: x-apievangelist-phrasing: intent: Edit part of a LDAP user connection effect: write questions: - Can I update only the identifier on an LDAP user link? - Is there a partial update for LDAP user connections? instructions: - text: Change the identifier of LDAP user connection {id} to {identifier}. slots: id: path.id identifier: requestBody.identifier - text: Reassign LDAP user link {id} to source {source}. slots: id: path.id source: requestBody.source method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/ldap/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a LDAP user connection effect: read questions: - What objects depend on an LDAP user connection? - Is an LDAP user link referenced elsewhere? instructions: - text: List dependents of LDAP user connection {id}. slots: id: path.id - text: Show what uses LDAP user link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/oauth/'].get update: x-apievangelist-phrasing: intent: List OAuth user connections effect: read questions: - Which users have signed in with a social or OIDC account? - Can I see OAuth-linked accounts for a single user? instructions: - text: List OAuth user connections. - text: Show OAuth user links for user {user}. slots: user: query.user - text: Find OAuth user connections from source {source_slug}. slots: source_slug: query.source__slug method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/oauth/'].post update: x-apievangelist-phrasing: intent: Link a user to an OAuth account effect: write questions: - How do I link an authentik user to their account at an OAuth provider? - Can I store an access token and expiry when creating an OAuth user connection? instructions: - text: Link a user to OAuth source {source} with remote ID {identifier}. slots: source: requestBody.source identifier: requestBody.identifier - text: Create an OAuth user connection for remote ID {identifier} with access token {access_token} expiring {expires}. slots: identifier: requestBody.identifier access_token: requestBody.access_token expires: requestBody.expires method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/oauth/{id}/'].get update: x-apievangelist-phrasing: intent: Get a OAuth user connection effect: read questions: - What remote account ID and token expiry are stored on an OAuth user link? - Which OAuth source does one user connection belong to? instructions: - text: Show OAuth user connection {id}. slots: id: path.id - text: Get the token expiry on OAuth user link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/oauth/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a OAuth user connection effect: write questions: - Can I overwrite an OAuth user connection including its access token? - What must I send to fully replace an OAuth user link? instructions: - text: Replace OAuth user connection {id} with source {source} and remote ID {identifier}. slots: id: path.id source: requestBody.source identifier: requestBody.identifier - text: Overwrite OAuth user link {id} with access token {access_token}. slots: id: path.id access_token: requestBody.access_token method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/oauth/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a OAuth user connection effect: destructive questions: - Can I disconnect a user's social login account? - What happens when an OAuth user connection is deleted? instructions: - text: Delete OAuth user connection {id}. slots: id: path.id - text: Unlink the social account on OAuth user link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/oauth/{id}/'].patch update: x-apievangelist-phrasing: intent: Edit part of a OAuth user connection effect: write questions: - Can I refresh only the stored access token on an OAuth user link? - Is it possible to change just the expiry of an OAuth user connection? instructions: - text: Set access token {access_token} on OAuth user connection {id}. slots: id: path.id access_token: requestBody.access_token - text: Change the expiry of OAuth user link {id} to {expires}. slots: id: path.id expires: requestBody.expires method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/oauth/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a OAuth user connection effect: read questions: - What references an OAuth user connection? - Does anything rely on an OAuth user link? instructions: - text: List objects using OAuth user connection {id}. slots: id: path.id - text: Check what depends on OAuth user link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/plex/'].get update: x-apievangelist-phrasing: intent: List Plex user connections effect: read questions: - Which users have a Plex account connected? - Can I list Plex user links for one Plex source? instructions: - text: List Plex user connections. - text: Show Plex user links from source {source_slug}. slots: source_slug: query.source__slug - text: Find Plex user connections for user {user}. slots: user: query.user method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/plex/'].post update: x-apievangelist-phrasing: intent: Link a user to a Plex account effect: write questions: - How do I link a user to their Plex account with a Plex token? - What does a new Plex user connection require? instructions: - text: Link a user to Plex source {source} with identifier {identifier} and token {plex_token}. slots: source: requestBody.source identifier: requestBody.identifier plex_token: requestBody.plex_token - text: Create a Plex user connection for Plex ID {identifier} using token {plex_token}. slots: identifier: requestBody.identifier plex_token: requestBody.plex_token method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/plex/{id}/'].get update: x-apievangelist-phrasing: intent: Get a Plex user connection effect: read questions: - What's stored on a single Plex user link? - Which Plex source is one user connection tied to? instructions: - text: Show Plex user connection {id}. slots: id: path.id - text: Get the identifier of Plex user link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/plex/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a Plex user connection effect: write questions: - Can I fully replace a Plex user connection including its token? - What's required to overwrite a Plex user link? instructions: - text: Replace Plex user connection {id} with source {source}, identifier {identifier} and token {plex_token}. slots: id: path.id source: requestBody.source identifier: requestBody.identifier plex_token: requestBody.plex_token - text: Overwrite Plex user link {id} completely. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/plex/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a Plex user connection effect: destructive questions: - Can I unlink a user's Plex account? - Is deleting a Plex user connection reversible? instructions: - text: Delete Plex user connection {id}. slots: id: path.id - text: Remove the Plex account link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/plex/{id}/'].patch update: x-apievangelist-phrasing: intent: Edit part of a Plex user connection effect: write questions: - Can I update only the Plex token on a user connection? - Is there a partial update for Plex user links? instructions: - text: Set Plex token {plex_token} on Plex user connection {id}. slots: id: path.id plex_token: requestBody.plex_token - text: Change the identifier of Plex user link {id} to {identifier}. slots: id: path.id identifier: requestBody.identifier method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/plex/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a Plex user connection effect: read questions: - What depends on a Plex user connection? - Is a Plex user link referenced by other objects? instructions: - text: List dependents of Plex user connection {id}. slots: id: path.id - text: Show what uses Plex user link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/saml/'].get update: x-apievangelist-phrasing: intent: List SAML user connections effect: read questions: - Which users are linked to a SAML identity provider? - Can I list SAML user connections for a single user? instructions: - text: List SAML user connections. - text: Show SAML user links for user {user}. slots: user: query.user - text: Find SAML user connections from source {source_slug}. slots: source_slug: query.source__slug method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/saml/'].post update: x-apievangelist-phrasing: intent: Link a user to a SAML identity effect: write questions: - How do I link a user to their SAML NameID from an identity provider? - What identifier does a new SAML user connection expect? instructions: - text: Link a user to SAML source {source} with NameID {identifier}. slots: source: requestBody.source identifier: requestBody.identifier - text: Create a SAML user connection for NameID {identifier}. slots: identifier: requestBody.identifier method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/saml/{id}/'].get update: x-apievangelist-phrasing: intent: Get a SAML user connection effect: read questions: - What SAML NameID is stored on a specific user link? - Which SAML source owns one user connection? instructions: - text: Show SAML user connection {id}. slots: id: path.id - text: Get the NameID on SAML user link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/saml/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a SAML user connection effect: write questions: - Can I replace a SAML user connection's source and identifier together? - What's needed to fully overwrite a SAML user link? instructions: - text: Replace SAML user connection {id} with source {source} and NameID {identifier}. slots: id: path.id source: requestBody.source identifier: requestBody.identifier - text: Overwrite SAML user link {id} in full. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/saml/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a SAML user connection effect: destructive questions: - Can I disconnect a user from their SAML identity? - What happens when a SAML user connection is deleted? instructions: - text: Delete SAML user connection {id}. slots: id: path.id - text: Unlink SAML user mapping {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/saml/{id}/'].patch update: x-apievangelist-phrasing: intent: Edit part of a SAML user connection effect: write questions: - Can I change only the NameID on a SAML user link? - Is there a partial update for SAML user connections? instructions: - text: Change the NameID on SAML user connection {id} to {identifier}. slots: id: path.id identifier: requestBody.identifier - text: Point SAML user link {id} to source {source}. slots: id: path.id source: requestBody.source method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/saml/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a SAML user connection effect: read questions: - What references a SAML user connection? - Is anything relying on a SAML user link I want to remove? instructions: - text: List objects using SAML user connection {id}. slots: id: path.id - text: Check dependents of SAML user link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/telegram/'].get update: x-apievangelist-phrasing: intent: List Telegram user connections effect: read questions: - Which users have a Telegram account connected? - Can I search Telegram user connections? instructions: - text: List Telegram user connections. - text: Search Telegram user links for {search}. slots: search: query.search - text: Show Telegram user connections for user {user}. slots: user: query.user method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/telegram/'].post update: x-apievangelist-phrasing: intent: Link a user to a Telegram account effect: write questions: - How do I record a Telegram user connection by hand, without the login widget? - What identifier does a Telegram user connection need? instructions: - text: Link a user to Telegram source {source} with Telegram ID {identifier}. slots: source: requestBody.source identifier: requestBody.identifier - text: Create a Telegram user connection record for Telegram ID {identifier}. slots: identifier: requestBody.identifier method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/telegram/{id}/'].get update: x-apievangelist-phrasing: intent: Get a Telegram user connection effect: read questions: - What does one Telegram user link contain? - Which Telegram source is a user connection tied to? instructions: - text: Show Telegram user connection {id}. slots: id: path.id - text: Get the Telegram ID on user link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/telegram/{id}/'].put update: x-apievangelist-phrasing: intent: Replace a Telegram user connection effect: write questions: - Can I overwrite a Telegram user connection entirely? - What must I send to replace a Telegram user link? instructions: - text: Replace Telegram user connection {id} with source {source} and Telegram ID {identifier}. slots: id: path.id source: requestBody.source identifier: requestBody.identifier - text: Fully overwrite Telegram user link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/telegram/{id}/'].delete update: x-apievangelist-phrasing: intent: Delete a Telegram user connection effect: destructive questions: - Can I unlink a user's Telegram account? - Does deleting a Telegram user connection remove the authentik user? instructions: - text: Delete Telegram user connection {id}. slots: id: path.id - text: Remove the Telegram account link {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/telegram/{id}/'].patch update: x-apievangelist-phrasing: intent: Edit part of a Telegram user connection effect: write questions: - Can I update only the Telegram ID on a user link? - Is it possible to move a Telegram user connection to another Telegram source? instructions: - text: Set Telegram ID {identifier} on Telegram user connection {id}. slots: id: path.id identifier: requestBody.identifier - text: Move Telegram user link {id} to source {source}. slots: id: path.id source: requestBody.source method: generated generated: '2026-09-26' - target: $.paths['/sources/user_connections/telegram/{id}/used_by/'].get update: x-apievangelist-phrasing: intent: See what uses a Telegram user connection effect: read questions: - What depends on a Telegram user connection? - Is a Telegram user link referenced anywhere? instructions: - text: List dependents of Telegram user connection {id}. slots: id: path.id - text: Show what uses Telegram user link {id}. slots: id: path.id method: generated generated: '2026-09-26'