# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for BigPanda SSO & JIT Provisioning API version: 1.0.0 extends: openapi/bigpanda-sso-jit-provisioning-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 10 - target: $.paths['/resources/v2.1/sso-config/{provider}/configure'].post update: x-apievangelist-phrasing: intent: Configure SSO for an identity provider effect: write questions: - How do I set up single sign-on to BigPanda with our identity provider? - What do I supply when configuring SSO for a specific provider? instructions: - text: Configure SSO for identity provider {provider} using these metadata values. slots: provider: path.provider - text: Set up single sign-on with {provider}, authenticating with auth details {auth_details}. slots: provider: path.provider auth_details: header.x-bp-auth-details method: generated generated: '2026-09-26' - target: $.paths['/resources/v2.1/jit-domains/{jit_domain_name}'].delete update: x-apievangelist-phrasing: intent: Delete a just-in-time domain rule effect: destructive questions: - Can I stop an email domain from auto-provisioning accounts on first SSO login? - How do I remove a JIT domain rule? instructions: - text: Delete the JIT domain rule for {jit_domain_name}. slots: jit_domain_name: path.jit_domain_name - text: Stop auto-provisioning users from the domain {jit_domain_name}. slots: jit_domain_name: path.jit_domain_name method: generated generated: '2026-09-26' - target: $.paths['/resources/v2.1/jit-roles/{jit_role_id}'].delete update: x-apievangelist-phrasing: intent: Delete a just-in-time role rule effect: destructive questions: - Can I remove a rule that hands out a role automatically on first SSO login? - What deletes a JIT role rule by its ID? instructions: - text: Delete JIT role rule {jit_role_id}. slots: jit_role_id: path.jit_role_id - text: Remove the just-in-time role assignment rule {jit_role_id}. slots: jit_role_id: path.jit_role_id method: generated generated: '2026-09-26' - target: $.paths['/resources/v2.1/saml-debug'].get update: x-apievangelist-phrasing: intent: Get SAML debug information effect: read questions: - Why are our SAML assertions failing during SSO setup? - Can I see SAML debug output while validating a new SSO connection? instructions: - text: Get the SAML debug information for our organization. - text: Pull SAML debug details using auth details {auth_details}. slots: auth_details: header.x-bp-auth-details method: generated generated: '2026-09-26' - target: $.paths['/resources/v2.1/sso-config'].get update: x-apievangelist-phrasing: intent: Get the organization's SSO configuration effect: read questions: - Is SSO turned on for our BigPanda organization, and with which provider? - What does our current single sign-on configuration look like? instructions: - text: Show our organization's SSO configuration. - text: Get the current SSO config using auth details {auth_details}. slots: auth_details: header.x-bp-auth-details method: generated generated: '2026-09-26' - target: $.paths['/resources/v2.1/sso-config'].put update: x-apievangelist-phrasing: intent: Enable, disable or switch SSO effect: write questions: - Can I disable SSO for the organization temporarily? - How do I switch our organization to a different SSO provider? instructions: - text: Turn off SSO for our organization. - text: Update the SSO status and provider using auth details {auth_details}. slots: auth_details: header.x-bp-auth-details method: generated generated: '2026-09-26' - target: $.paths['/resources/v2.1/jit-domains'].get update: x-apievangelist-phrasing: intent: List just-in-time domain rules effect: read questions: - Which email domains are allowed to auto-provision accounts on first SSO login? - Can I see all our JIT domain rules? instructions: - text: List our JIT domain rules. - text: Show which email domains get accounts created automatically at first login. method: generated generated: '2026-09-26' - target: $.paths['/resources/v2.1/jit-domains'].post update: x-apievangelist-phrasing: intent: Allow a domain to auto-provision accounts effect: write questions: - How do I let everyone on our email domain get an account automatically at first SSO login? - Can I add a new JIT domain rule for a subsidiary's domain? instructions: - text: Create a JIT domain rule for our email domain. - text: Allow users from the new domain to be provisioned on their first SSO login. method: generated generated: '2026-09-26' - target: $.paths['/resources/v2.1/jit-roles'].get update: x-apievangelist-phrasing: intent: List just-in-time role rules effect: read questions: - Which role does a new user get when their account is created on first SSO login? - Can I list all JIT role rules for our organization? instructions: - text: List our organization's JIT role rules. - text: Show the rules that decide a new SSO user's starting role. method: generated generated: '2026-09-26' - target: $.paths['/resources/v2.1/jit-roles'].post update: x-apievangelist-phrasing: intent: Create a just-in-time role rule effect: write questions: - How can I give new SSO users a role automatically when their account is created? - Can I add a JIT role rule so first-time users land in a specific role? instructions: - text: Create a JIT role rule that assigns a role on first SSO login. - text: Add a just-in-time rule giving newly provisioned users a default role. method: generated generated: '2026-09-26'