# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for BlueConic REST API v2 OAuth 2.0 API version: 1.0.0 extends: openapi/blueconic-oauth-2-0-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 3 - target: $.paths['/oauth/authorize'].get update: x-apievangelist-phrasing: intent: Start the OAuth authorization code flow effect: read questions: - How do I send a user to grant my app access to their BlueConic account? - Is PKCE required when starting the authorization code flow? - What redirect URI rules apply when requesting authorization? instructions: - text: Start the authorization flow for client {client_id} redirecting to {redirect_uri} with code challenge {code_challenge}. slots: client_id: query.client_id redirect_uri: query.redirect_uri code_challenge: query.code_challenge - text: Build the authorize URL with response type {response_type}, client {client_id}, redirect {redirect_uri}, challenge {code_challenge}. slots: response_type: query.response_type client_id: query.client_id redirect_uri: query.redirect_uri code_challenge: query.code_challenge method: generated generated: '2026-10-01' - target: $.paths['/oauth/revoke'].post update: x-apievangelist-phrasing: intent: Revoke an access or refresh token effect: destructive questions: - How do I invalidate a refresh token when a user disconnects? - Can I revoke an access token before it expires? instructions: - text: Revoke token {token} for client {client_id} using secret {client_secret}. slots: token: requestBody.token client_id: requestBody.client_id client_secret: requestBody.client_secret - text: Revoke the {token_type_hint} {token} for client {client_id} with secret {client_secret}. slots: token_type_hint: requestBody.token_type_hint token: requestBody.token client_id: requestBody.client_id client_secret: requestBody.client_secret method: generated generated: '2026-10-01' - target: $.paths['/oauth/token'].post update: x-apievangelist-phrasing: intent: Exchange a grant for an access token effect: write questions: - What's the call to exchange an authorization code for an access token? - Can I use a refresh token to get a new access token, and is rotation on? - Which grant types does the token endpoint accept? instructions: - text: Exchange code {code} with verifier {code_verifier} for a token as client {client_id} with secret {client_secret} via {grant_type}. slots: code: requestBody.code code_verifier: requestBody.code_verifier client_id: requestBody.client_id client_secret: requestBody.client_secret grant_type: requestBody.grant_type - text: Refresh the access token using {refresh_token} for client {client_id}, secret {client_secret}, grant {grant_type}. slots: refresh_token: requestBody.refresh_token client_id: requestBody.client_id client_secret: requestBody.client_secret grant_type: requestBody.grant_type method: generated generated: '2026-10-01'