# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Amazon CloudFront Origin Access Control API version: 1.0.0 extends: openapi/cloudfront-originaccesscontrol-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 4 - target: $.paths['/2020-05-31/origin-access-control'].get update: x-apievangelist-phrasing: intent: List origin access controls effect: read questions: - Which origin access controls have I set up for my S3 origins? - Can I see every OAC in my account? - How do I find the origin access controls I've created? instructions: - text: List all of my origin access controls. - text: Show every OAC configured in my account. method: generated generated: '2026-10-01' - target: $.paths['/2020-05-31/origin-access-control'].post update: x-apievangelist-phrasing: intent: Create an origin access control effect: write questions: - How do I lock down my S3 bucket so only CloudFront can read it? - Can I create a new origin access control to sign requests to my origin? - What's needed to add an OAC for a private origin? instructions: - text: Create a new origin access control. - text: Add an OAC so CloudFront signs requests to my private S3 origin. method: generated generated: '2026-10-01' - target: $.paths['/2020-05-31/origin-access-control/{Id}'].get update: x-apievangelist-phrasing: intent: Get an origin access control effect: read questions: - What signing behavior does a specific origin access control use? - Can I look up one OAC by its ID? - Where do I view the settings of a single origin access control? instructions: - text: Get origin access control {id}. slots: id: path.Id - text: Show the signing settings of OAC {id}. slots: id: path.Id method: generated generated: '2026-10-01' - target: $.paths['/2020-05-31/origin-access-control/{Id}'].delete update: x-apievangelist-phrasing: intent: Delete an origin access control effect: destructive questions: - How do I remove an origin access control I'm no longer using? - Does deleting an OAC require its current ETag? - Can I get rid of an old origin access control? instructions: - text: Delete origin access control {id}. slots: id: path.Id - text: Delete OAC {id} using ETag {etag}. slots: id: path.Id etag: header.If-Match method: generated generated: '2026-10-01'