generated: '2026-09-04' method: generated source: openapi/_original/authentik-openapi.yml (every operationId below was verified present in the published contract), conventions/authentik-conventions.yml, errors/authentik-problem-types.yml, and the authentik documentation pages cited in each skill provider: Authentik providerId: authentik api_base: https://{authentik_host}/api/v3 auth: 'HTTP Bearer token (Authorization header, Bearer scheme) issued to a user, service account or agent account' note: 'authentik is self-hosted. Every skill runs against the operator''s own deployment — there is no shared vendor host, and no skill should be run against a host the caller does not control.' provider_published_skills: false provider_published_skills_note: No AGENTS.md, skills/ directory or provider-published agent skill was found on goauthentik.io, docs.goauthentik.io or in the goauthentik GitHub organization. These five are generated by API Evangelist from the published contract. skills: - name: authentik-provision-user-access file: authentik-provision-user-access.md description: Provision a user and grant application access through group membership, then verify it. operations: 8 destructive: false - name: authentik-offboard-user-safely file: authentik-offboard-user-safely.md description: Schedule a user's deactivation or deletion with session and token revocation, and cancel it before it runs. operations: 7 destructive: true reversible: true reversal_window: Any time before the scheduled date and time; authentik sweeps every five minutes. - name: authentik-create-oauth2-application file: authentik-create-oauth2-application.md description: Create an OAuth2/OIDC provider and application, wire scope mappings and bind an access policy. operations: 9 destructive: false - name: authentik-agent-account-token file: authentik-agent-account-token.md description: Issue a scoped expiring API token for an automation or AI agent, delegate time-boxed access, and revoke it. operations: 12 destructive: true reversible: true reversal_window: A delegated grant can be revoked for as long as it is active; the token itself can be destroyed at any time but cannot be restored. - name: authentik-webhook-notifications file: authentik-webhook-notifications.md description: Route authentik events to an external webhook receiver and test delivery. operations: 8 destructive: false safety_rules: - No Idempotency-Key header exists on this API. A retried POST creates a second object unless the resource carries a unique name/slug constraint. - Call GET /{id}/used_by/ before any DELETE — it is the only consequence preview the API publishes. - Ordinary DELETE is immediate and permanent. Only scheduled offboardings and active access grants have a published reversal operation. - 'No 429 and no rate-limit headers exist. Pace client-side and back off on 500.' - 'A missing permission returns 403, not 401. An object hidden by object-level permissions can present as 404.'