# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Canonical Certificates API version: 1.0.0 extends: openapi/canonical-certificates-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 8 - target: $.paths['/1.0/certificates'].get update: x-apievangelist-phrasing: intent: List trusted client certificates effect: read questions: - Which client certificates are trusted by this server? - Can I get the list of trusted certificate URLs? instructions: - text: List the trusted client certificates. - text: Show the fingerprints of every trusted client. method: generated generated: '2026-09-26' - target: $.paths['/1.0/certificates'].post update: x-apievangelist-phrasing: intent: Trust a new client certificate effect: write questions: - How do I add a new trusted client by its certificate? - Can a client be trusted using the trust password? instructions: - text: Add client certificate {certificate} to the trust store. slots: certificate: requestBody.certificate - text: Trust the certificate {certificate} using trust password {password}. slots: certificate: requestBody.certificate password: requestBody.trust-password method: generated generated: '2026-09-26' - target: $.paths['/1.0/certificates/{fingerprint}'].get update: x-apievangelist-phrasing: intent: Get a trusted certificate effect: read questions: - What details are stored for a trusted certificate? - Can I look up a client certificate by its fingerprint? instructions: - text: Show the trusted certificate {fingerprint}. slots: fingerprint: path.fingerprint - text: Get the details for certificate fingerprint {fingerprint}. slots: fingerprint: path.fingerprint method: generated generated: '2026-09-26' - target: $.paths['/1.0/certificates/{fingerprint}'].put update: x-apievangelist-phrasing: intent: Replace a trusted certificate's configuration effect: write questions: - How do I overwrite all settings of a trusted certificate? - Can I fully redefine which projects a certificate is restricted to? instructions: - text: Replace the certificate's configuration with name {name}, restricted {restricted} and projects {projects}. slots: name: requestBody.name restricted: requestBody.restricted projects: requestBody.projects - text: Overwrite the whole trusted certificate entry {fingerprint} with type {type}. slots: fingerprint: path.fingerprint type: requestBody.type method: generated generated: '2026-10-01' - target: $.paths['/1.0/certificates/{fingerprint}'].delete update: x-apievangelist-phrasing: intent: Remove a trusted certificate effect: destructive questions: - How do I revoke a client's trust on this server? - What happens when I delete a certificate from the trust store? instructions: - text: Delete trusted certificate {fingerprint}. slots: fingerprint: path.fingerprint - text: Revoke trust for the client with fingerprint {fingerprint}. slots: fingerprint: path.fingerprint method: generated generated: '2026-09-26' - target: $.paths['/1.0/certificates/{fingerprint}'].patch update: x-apievangelist-phrasing: intent: Update some fields of a trusted certificate effect: write questions: - Can I just rename a trusted certificate without changing anything else? - Is there a partial update to restrict a certificate to certain projects? instructions: - text: Rename trusted certificate {fingerprint} to {name}. slots: fingerprint: path.fingerprint name: requestBody.name - text: Patch the certificate to be restricted to projects {projects}. slots: projects: requestBody.projects method: generated generated: '2026-10-01' - target: $.paths['/1.0/certificates?recursion=1'].get update: x-apievangelist-phrasing: intent: List trusted certificates with details effect: read questions: - Can I list trusted certificates with all their fields expanded? - Which call returns full certificate objects instead of URLs? instructions: - text: List all trusted certificates with full details. - text: Show each trusted certificate's name, type and restrictions in one response. method: generated generated: '2026-09-26' - target: $.paths['/1.0/certificates?public'].post update: x-apievangelist-phrasing: intent: Add a certificate as an untrusted client effect: write questions: - How does a client that isn't trusted yet add itself using a token? - Can a new client register its own TLS certificate with a trust token? instructions: - text: Add my client certificate using trust token {trust_token}. slots: trust_token: requestBody.trust_token - text: Register certificate {certificate} as {name} with token {token}. slots: certificate: requestBody.certificate name: requestBody.name token: requestBody.token method: generated generated: '2026-09-26'