# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Datadog Get API version: 1.0.0 extends: openapi/datadog-get-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 72 - target: $.paths['/api/v2/agentless_scanning/accounts/aws'].get update: x-apievangelist-phrasing: intent: List agentless scan options for AWS accounts effect: read questions: - Which AWS accounts have agentless scanning options configured? - Can I see what agentless scanning is set to scan in each of my AWS accounts? instructions: - text: Show the agentless scanning options configured for my AWS accounts. - text: List every AWS account's agentless scan settings. method: generated generated: '2026-10-01' - target: $.paths['/api/v2/api_keys/{api_key_id}'].get update: x-apievangelist-phrasing: intent: Look up a single API key effect: read questions: - How do I look up the details of one Datadog API key? - Can I see who created a specific API key and when it was last modified? instructions: - text: Get the API key {api_key_id}. slots: api_key_id: path.api_key_id - text: Fetch API key {api_key_id} including its {include} relationships. slots: api_key_id: path.api_key_id include: query.include method: generated generated: '2026-10-01' - target: $.paths['/api/v2/apicatalog/api/{id}/openapi'].get update: x-apievangelist-phrasing: intent: Download an API catalog entry as OpenAPI effect: read questions: - Can I export an API from the API catalog as an OpenAPI file? - Where do I get the OpenAPI definition for an API registered in the catalog? instructions: - text: Download the OpenAPI file for catalog API {id}. slots: id: path.id - text: Export API {id} from the API catalog in OpenAPI format. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/apm/config/metrics/{metric_id}'].get update: x-apievangelist-phrasing: intent: Get a span-based metric effect: read questions: - What filter and aggregation does one of my span-based metrics use? - Can I inspect how a metric generated from APM spans is defined? instructions: - text: Get the span-based metric {metric_id}. slots: metric_id: path.metric_id - text: Show me the definition of span metric {metric_id}. slots: metric_id: path.metric_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/authn_mappings/{authn_mapping_id}'].get update: x-apievangelist-phrasing: intent: Get an AuthN mapping effect: read questions: - Which role does a particular SAML attribute AuthN mapping assign? - Can I look up one AuthN mapping by its UUID? instructions: - text: Get AuthN mapping {authn_mapping_id}. slots: authn_mapping_id: path.authn_mapping_id - text: Show which attribute and role AuthN mapping {authn_mapping_id} links. slots: authn_mapping_id: path.authn_mapping_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/cases/projects/{project_id}'].get update: x-apievangelist-phrasing: intent: Get a Case Management project effect: read questions: - How do I see the details of a Case Management project? - What is the name and key of a given cases project? instructions: - text: Get the case project {project_id}. slots: project_id: path.project_id - text: Show me the details of Case Management project {project_id}. slots: project_id: path.project_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/downtime/{downtime_id}'].get update: x-apievangelist-phrasing: intent: Get a scheduled downtime effect: read questions: - When does a particular downtime start and end, and what does it silence? - Can I check the scope and schedule of one downtime? instructions: - text: Get downtime {downtime_id}. slots: downtime_id: path.downtime_id - text: Show downtime {downtime_id} with its {include} included. slots: downtime_id: path.downtime_id include: query.include method: generated generated: '2026-10-01' - target: $.paths['/api/v2/incidents'].get update: x-apievangelist-phrasing: intent: List incidents in the organization effect: read questions: - What incidents does my organization have open or recorded in Datadog? - Can I page through all incidents a few at a time? instructions: - text: List all incidents in my organization. - text: List incidents {page_size} per page starting at offset {page_offset}. slots: page_size: query.page[size] page_offset: query.page[offset] method: generated generated: '2026-10-01' - target: $.paths['/api/v2/incidents/config/types'].get update: x-apievangelist-phrasing: intent: List incident types effect: read questions: - Which incident types are configured for my organization? - Can I include deleted incident types when listing them? instructions: - text: List all incident types. - text: List incident types with include_deleted set to {include_deleted}. slots: include_deleted: query.include_deleted method: generated generated: '2026-10-01' - target: $.paths['/api/v2/incidents/config/types/{incident_type_id}'].get update: x-apievangelist-phrasing: intent: Get an incident type effect: read questions: - What are the settings of one specific incident type? - Can I look up an incident type's name and description by ID? instructions: - text: Get incident type {incident_type_id}. slots: incident_type_id: path.incident_type_id - text: Show the configuration of incident type {incident_type_id}. slots: incident_type_id: path.incident_type_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/incidents/{incident_id}'].get update: x-apievangelist-phrasing: intent: Get an incident's details effect: read questions: - What is the current status, severity and commander of a given incident? - How do I pull up everything about one incident by its ID? instructions: - text: Get incident {incident_id}. slots: incident_id: path.incident_id - text: Show incident {incident_id} including {include}. slots: incident_id: path.incident_id include: query.include method: generated generated: '2026-10-01' - target: $.paths['/api/v2/incidents/{incident_id}/relationships/integrations'].get update: x-apievangelist-phrasing: intent: List an incident's integration metadata effect: read questions: - Which chat channels or tickets are linked to an incident through integrations? - Can I see all the integration metadata attached to an incident? instructions: - text: List the integrations linked to incident {incident_id}. slots: incident_id: path.incident_id - text: Show all integration metadata for incident {incident_id}. slots: incident_id: path.incident_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/incidents/{incident_id}/relationships/integrations/{integration_metadata_id}'].get update: x-apievangelist-phrasing: intent: Get one incident integration record effect: read questions: - How do I read a single integration metadata entry on an incident? - What does one specific integration link on an incident contain? instructions: - text: Get integration metadata {integration_metadata_id} on incident {incident_id}. slots: integration_metadata_id: path.integration_metadata_id incident_id: path.incident_id - text: Show the details of integration {integration_metadata_id} attached to incident {incident_id}. slots: integration_metadata_id: path.integration_metadata_id incident_id: path.incident_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/incidents/{incident_id}/relationships/todos'].get update: x-apievangelist-phrasing: intent: List an incident's todos effect: read questions: - What follow-up todos are still outstanding on an incident? - Can I list every todo item assigned during an incident? instructions: - text: List the todos for incident {incident_id}. slots: incident_id: path.incident_id - text: Show every task on incident {incident_id}'s todo list. slots: incident_id: path.incident_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/incidents/{incident_id}/relationships/todos/{todo_id}'].get update: x-apievangelist-phrasing: intent: Get one incident todo effect: read questions: - Who is assigned to a particular incident todo and is it done? - How do I read a single todo from an incident? instructions: - text: Get todo {todo_id} on incident {incident_id}. slots: todo_id: path.todo_id incident_id: path.incident_id - text: Show the assignees and due date of todo {todo_id} for incident {incident_id}. slots: todo_id: path.todo_id incident_id: path.incident_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/integration/aws/accounts/{aws_account_config_id}'].get update: x-apievangelist-phrasing: intent: Get an AWS account integration config effect: read questions: - How is a given AWS account integration configured in Datadog? - Can I see the metrics, logs and regions settings for one AWS integration config? instructions: - text: Get the AWS integration config {aws_account_config_id}. slots: aws_account_config_id: path.aws_account_config_id - text: Show the settings of AWS account integration {aws_account_config_id}. slots: aws_account_config_id: path.aws_account_config_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/integration/aws/logs/services'].get update: x-apievangelist-phrasing: intent: List AWS services that can send logs effect: read questions: - Which AWS services can forward their logs to Datadog? - Is there a list of log-ready AWS services I can enable? instructions: - text: List the AWS services that can send logs. - text: Show me every log-ready AWS service. method: generated generated: '2026-10-01' - target: $.paths['/api/v2/integration/ms-teams/configuration/tenant-based-handles/{handle_id}'].get update: x-apievangelist-phrasing: intent: Get a Microsoft Teams tenant-based handle effect: read questions: - Which Microsoft Teams tenant, team and channel does a tenant-based handle point to? - Can I look up a Teams tenant-based handle by its ID? instructions: - text: Get Microsoft Teams tenant-based handle {handle_id}. slots: handle_id: path.handle_id - text: Show the tenant, team and channel behind tenant-based handle {handle_id}. slots: handle_id: path.handle_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/integration/ms-teams/configuration/workflows-webhook-handles/{handle_id}'].get update: x-apievangelist-phrasing: intent: Get a Microsoft Teams Workflows webhook handle effect: read questions: - What is the name of a Microsoft Teams Workflows webhook handle? - Can I read one Workflows webhook handle from the Teams integration? instructions: - text: Get Workflows webhook handle {handle_id}. slots: handle_id: path.handle_id - text: Show the name of Teams Workflows webhook handle {handle_id}. slots: handle_id: path.handle_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/integration/opsgenie/services/{integration_service_id}'].get update: x-apievangelist-phrasing: intent: Get an Opsgenie integration service effect: read questions: - How is a single Opsgenie service set up in the integration? - Which region does a given Opsgenie integration service use? instructions: - text: Get Opsgenie integration service {integration_service_id}. slots: integration_service_id: path.integration_service_id - text: Show the Opsgenie service object {integration_service_id}. slots: integration_service_id: path.integration_service_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/integrations/fastly/accounts/{account_id}/services/{service_id}'].get update: x-apievangelist-phrasing: intent: Get a Fastly service for an account effect: read questions: - What tags are set on a Fastly service in my Fastly integration? - Can I look up one Fastly service under a specific Fastly account? instructions: - text: Get Fastly service {service_id} in account {account_id}. slots: service_id: path.service_id account_id: path.account_id - text: Show the config of Fastly service {service_id} for Fastly account {account_id}. slots: service_id: path.service_id account_id: path.account_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/ip_allowlist'].get update: x-apievangelist-phrasing: intent: Get the IP allowlist and whether it is on effect: read questions: - Is the IP allowlist currently enabled for my organization? - Which IP ranges are on my organization's allowlist? instructions: - text: Show my IP allowlist and its enabled state. - text: List the entries currently in the IP allowlist. method: generated generated: '2026-10-01' - target: $.paths['/api/v2/logs/config/metrics/{metric_id}'].get update: x-apievangelist-phrasing: intent: Get a log-based metric effect: read questions: - What query and group-bys does a log-based metric use? - Can I inspect how one metric generated from logs is computed? instructions: - text: Get the log-based metric {metric_id}. slots: metric_id: path.metric_id - text: Show the definition of logs metric {metric_id}. slots: metric_id: path.metric_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/logs/config/restriction_queries/role/{role_id}'].get update: x-apievangelist-phrasing: intent: Get the log restriction query for a role effect: read questions: - Which logs restriction query applies to a particular role? - What log data can users in a given role see? instructions: - text: Get the logs restriction query attached to role {role_id}. slots: role_id: path.role_id - text: Show which restriction query limits log access for role {role_id}. slots: role_id: path.role_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/logs/config/restriction_queries/{restriction_query_id}'].get update: x-apievangelist-phrasing: intent: Get a logs restriction query effect: read questions: - What filter does a specific logs restriction query apply? - Can I read a restriction query by its own ID? instructions: - text: Get restriction query {restriction_query_id}. slots: restriction_query_id: path.restriction_query_id - text: Show the query string of logs restriction query {restriction_query_id}. slots: restriction_query_id: path.restriction_query_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/logs/events'].get update: x-apievangelist-phrasing: intent: Search logs with a query effect: read questions: - How do I search my logs for errors from a specific service? - Can I restrict a log search to certain indexes or a storage tier? - Is there a way to page through log search results with a cursor? instructions: - text: Search logs matching {query} from {from} to {to}. slots: query: query.filter[query] from: query.filter[from] to: query.filter[to] - text: Find logs matching {query} in index {indexes}, up to {limit} results. slots: query: query.filter[query] indexes: query.filter[indexes] limit: query.page[limit] method: generated generated: '2026-10-01' - target: $.paths['/api/v2/metrics'].get update: x-apievangelist-phrasing: intent: List metrics with their tag configuration status effect: read questions: - Which of my metrics already have Metrics without Limits tag configurations? - Can I find metrics that haven't been queried recently? - What distribution metrics do I have with percentiles enabled? instructions: - text: List metrics with tag configurations set to {configured}. slots: configured: query.filter[configured] - text: List {metric_type} metrics tagged {tags}. slots: metric_type: query.filter[metric_type] tags: query.filter[tags] method: generated generated: '2026-10-01' - target: $.paths['/api/v2/monitor/notification_rule/{rule_id}'].get update: x-apievangelist-phrasing: intent: Get a monitor notification rule effect: read questions: - Which recipients does a monitor notification rule route alerts to? - Can I look up a monitor notification rule by ID? instructions: - text: Get monitor notification rule {rule_id}. slots: rule_id: path.rule_id - text: Show monitor notification rule {rule_id} with {include} included. slots: rule_id: path.rule_id include: query.include method: generated generated: '2026-10-01' - target: $.paths['/api/v2/on-call/escalation-policies/{policy_id}'].get update: x-apievangelist-phrasing: intent: Get an On-Call escalation policy effect: read questions: - What are the escalation steps in one of my On-Call escalation policies? - How long does an escalation policy wait before paging the next tier? instructions: - text: Get escalation policy {policy_id}. slots: policy_id: path.policy_id - text: Show escalation policy {policy_id} with its {include}. slots: policy_id: path.policy_id include: query.include method: generated generated: '2026-10-01' - target: $.paths['/api/v2/on-call/schedules/{schedule_id}'].get update: x-apievangelist-phrasing: intent: Get an On-Call schedule effect: read questions: - What layers and rotations make up a given On-Call schedule? - Can I read the configuration of one On-Call schedule? instructions: - text: Get On-Call schedule {schedule_id}. slots: schedule_id: path.schedule_id - text: Show the rotation layers of schedule {schedule_id}. slots: schedule_id: path.schedule_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/on-call/schedules/{schedule_id}/on-call'].get update: x-apievangelist-phrasing: intent: Find who is on call for a schedule effect: read questions: - Who is on call right now for a particular schedule? - Can I check who will be on call for a schedule at a specific time? instructions: - text: Tell me who is on call for schedule {schedule_id}. slots: schedule_id: path.schedule_id - text: Find who is on call for schedule {schedule_id} at {at_ts}. slots: schedule_id: path.schedule_id at_ts: query.filter[at_ts] method: generated generated: '2026-10-01' - target: $.paths['/api/v2/on-call/teams/{team_id}/on-call'].get update: x-apievangelist-phrasing: intent: Find a team's on-call users effect: read questions: - Which people on a team are currently on call? - How do I find out who to reach on a team's on-call rotation? instructions: - text: List who is on call for team {team_id}. slots: team_id: path.team_id - text: Show team {team_id}'s on-call responders including {include}. slots: team_id: path.team_id include: query.include method: generated generated: '2026-10-01' - target: $.paths['/api/v2/on-call/teams/{team_id}/routing-rules'].get update: x-apievangelist-phrasing: intent: Get a team's On-Call routing rules effect: read questions: - How are pages routed to a team's escalation policies? - What routing rules decide which policy a team's pages use? instructions: - text: Get the On-Call routing rules for team {team_id}. slots: team_id: path.team_id - text: Show team {team_id}'s page routing rules with {include}. slots: team_id: path.team_id include: query.include method: generated generated: '2026-10-01' - target: $.paths['/api/v2/org_configs/{org_config_name}'].get update: x-apievangelist-phrasing: intent: Get an org config value effect: read questions: - What is the current value of a specific organization config setting? - Can I read the description of an Org Config by name? instructions: - text: Get the org config {org_config_name}. slots: org_config_name: path.org_config_name - text: Show the value of org setting {org_config_name}. slots: org_config_name: path.org_config_name method: generated generated: '2026-10-01' - target: $.paths['/api/v2/powerpacks/{powerpack_id}'].get update: x-apievangelist-phrasing: intent: Get a powerpack effect: read questions: - Which widgets does a dashboard powerpack contain? - Can I fetch a reusable powerpack's definition by ID? instructions: - text: Get powerpack {powerpack_id}. slots: powerpack_id: path.powerpack_id - text: Show the widget group in powerpack {powerpack_id}. slots: powerpack_id: path.powerpack_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/remote_config/products/cws/policy/{policy_id}'].get update: x-apievangelist-phrasing: intent: Get a Workload Protection policy effect: read questions: - What does a Workload Protection policy contain and which hosts does it target? - Can I read a Workload Protection policy on a commercial (non-US1-FED) site? instructions: - text: Get Workload Protection policy {policy_id}. slots: policy_id: path.policy_id - text: Show the details of CWS policy {policy_id}. slots: policy_id: path.policy_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/remote_config/products/obs_pipelines/pipelines/{pipeline_id}'].get update: x-apievangelist-phrasing: intent: Get an Observability Pipelines pipeline effect: read questions: - What sources, processors and destinations does an observability pipeline use? - Can I fetch one Observability Pipelines configuration by its ID? instructions: - text: Get observability pipeline {pipeline_id}. slots: pipeline_id: path.pipeline_id - text: Show the configuration of pipeline {pipeline_id}. slots: pipeline_id: path.pipeline_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/restriction_policy/{resource_id}'].get update: x-apievangelist-phrasing: intent: Get a resource's restriction policy effect: read questions: - Who is allowed to edit or view a specific dashboard or resource? - Can I read the access bindings on a resource's restriction policy? instructions: - text: Get the restriction policy for resource {resource_id}. slots: resource_id: path.resource_id - text: Show who has access to {resource_id}. slots: resource_id: path.resource_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/roles/{role_id}'].get update: x-apievangelist-phrasing: intent: Get a role effect: read questions: - What is a given role called and how many users have it? - How do I look up one role in my organization by role ID? instructions: - text: Get role {role_id}. slots: role_id: path.role_id - text: Show the name and user count of role {role_id}. slots: role_id: path.role_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/rum/config/metrics/{metric_id}'].get update: x-apievangelist-phrasing: intent: Get a RUM-based metric effect: read questions: - How is a metric generated from RUM events defined? - Which event type and filter does a RUM-based metric use? instructions: - text: Get the RUM-based metric {metric_id}. slots: metric_id: path.metric_id - text: Show the definition of RUM metric {metric_id}. slots: metric_id: path.metric_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/scim/Groups/{group_id}'].get update: x-apievangelist-phrasing: intent: Get a SCIM group effect: read questions: - Which members belong to a group provisioned over SCIM? - Can I fetch one SCIM group by its group ID? instructions: - text: Get SCIM group {group_id}. slots: group_id: path.group_id - text: Show the members of SCIM group {group_id}. slots: group_id: path.group_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/scim/Users/{user_uuid}'].get update: x-apievangelist-phrasing: intent: Get a SCIM user effect: read questions: - How do I read a user's SCIM record, including active status and emails? - Can I look up a provisioned user through SCIM by UUID? instructions: - text: Get SCIM user {user_uuid}. slots: user_uuid: path.user_uuid - text: Show the SCIM profile of user {user_uuid}. slots: user_uuid: path.user_uuid method: generated generated: '2026-10-01' - target: $.paths['/api/v2/security/sboms/{asset_type}'].get update: x-apievangelist-phrasing: intent: Get the SBOM for an asset effect: read questions: - Can I pull the software bill of materials for a container image or repo? - Which components are in the SBOM for a given asset? instructions: - text: Get the SBOM for {asset_type} asset {asset_name}. slots: asset_type: path.asset_type asset_name: query.filter[asset_name] - text: Get the SBOM for image {asset_name} of type {asset_type} at digest {repo_digest}. slots: asset_name: query.filter[asset_name] asset_type: path.asset_type repo_digest: query.filter[repo_digest] method: generated generated: '2026-10-01' - target: $.paths['/api/v2/security/signals/notification_rules'].get update: x-apievangelist-phrasing: intent: List security signal notification rules effect: read questions: - Which notification rules send alerts for security signals? - Can I see every signal-based notification rule I have set up? instructions: - text: List all security signal notification rules. - text: Show every notification rule for security signals. method: generated generated: '2026-10-01' - target: $.paths['/api/v2/security/signals/notification_rules/{id}'].get update: x-apievangelist-phrasing: intent: Get a security signal notification rule effect: read questions: - What conditions and targets does one signal notification rule have? - Can I read a single security-signal notification rule by ID? instructions: - text: Get signal notification rule {id}. slots: id: path.id - text: Show the targets of security signal notification rule {id}. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/security/vulnerabilities/notification_rules'].get update: x-apievangelist-phrasing: intent: List vulnerability notification rules effect: read questions: - Which notification rules alert me about security vulnerabilities? - Can I see all the vulnerability notification rules configured? instructions: - text: List all vulnerability notification rules. - text: Show every notification rule for vulnerabilities. method: generated generated: '2026-10-01' - target: $.paths['/api/v2/security/vulnerabilities/notification_rules/{id}'].get update: x-apievangelist-phrasing: intent: Get a vulnerability notification rule effect: read questions: - What severities and recipients does one vulnerability notification rule cover? - Can I fetch a single vulnerability notification rule by ID? instructions: - text: Get vulnerability notification rule {id}. slots: id: path.id - text: Show the targets of vulnerability notification rule {id}. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/security_monitoring/configuration/suppressions/{suppression_id}'].get update: x-apievangelist-phrasing: intent: Get a security suppression rule effect: read questions: - What does a specific security suppression rule silence? - Can I look up one suppression rule and its expiration? instructions: - text: Get suppression rule {suppression_id}. slots: suppression_id: path.suppression_id - text: Show the query and expiry of suppression {suppression_id}. slots: suppression_id: path.suppression_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/security_monitoring/rules/{rule_id}'].get update: x-apievangelist-phrasing: intent: Get a detection rule's details effect: read questions: - What queries and cases does a security detection rule use? - Can I read the current definition of one detection rule? instructions: - text: Get detection rule {rule_id}. slots: rule_id: path.rule_id - text: Show the current queries and cases of security rule {rule_id}. slots: rule_id: path.rule_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/security_monitoring/rules/{rule_id}/version_history'].get update: x-apievangelist-phrasing: intent: Get a detection rule's version history effect: read questions: - Who changed a detection rule and what did earlier versions look like? - Can I page through past versions of a security rule? instructions: - text: Show the version history of rule {rule_id}. slots: rule_id: path.rule_id - text: List versions of rule {rule_id}, page {page_number} with {page_size} per page. slots: rule_id: path.rule_id page_number: query.page[number] page_size: query.page[size] method: generated generated: '2026-10-01' - target: $.paths['/api/v2/security_monitoring/signals'].get update: x-apievangelist-phrasing: intent: Quickly list security signals with query params effect: read questions: - Which security signals fired in the last hour? - Can I filter security signals by query string in the URL and sort them? instructions: - text: List security signals matching {query} between {from} and {to} using the GET list. slots: query: query.filter[query] from: query.filter[from] to: query.filter[to] - text: Get the latest {limit} security signals sorted by {sort}. slots: limit: query.page[limit] sort: query.sort method: generated generated: '2026-10-01' - target: $.paths['/api/v2/security_monitoring/signals/search'].post update: x-apievangelist-phrasing: intent: Search security signals with a request body effect: read questions: - Can I search security signals by posting a JSON filter instead of using URL params? - What's the way to run a complex security signal search with a body filter? instructions: - text: Search security signals with the body filter {filter}. slots: filter: requestBody.filter - text: Run a POST signal search with filter {filter}, page {page} and sort {sort}. slots: filter: requestBody.filter page: requestBody.page sort: requestBody.sort method: generated generated: '2026-10-01' - target: $.paths['/api/v2/security_monitoring/signals/{signal_id}'].get update: x-apievangelist-phrasing: intent: Get a security signal's details effect: read questions: - What triggered a particular security signal and what are its attributes? - How do I open one security signal by its ID? instructions: - text: Get security signal {signal_id}. slots: signal_id: path.signal_id - text: Show the full details of signal {signal_id}. slots: signal_id: path.signal_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/services/{service_id}'].get update: x-apievangelist-phrasing: intent: Get an incident service effect: read questions: - What are the details of a service used for incident management? - Can I include the related users when reading an incident service? instructions: - text: Get incident service {service_id}. slots: service_id: path.service_id - text: Show incident service {service_id} including {include}. slots: service_id: path.service_id include: query.include method: generated generated: '2026-10-01' - target: $.paths['/api/v2/siem-historical-detections/jobs/{job_id}'].get update: x-apievangelist-phrasing: intent: Get a historical detection job effect: read questions: - What is the status of a historical detections job I ran? - Can I look up a SIEM historical detection job by ID? instructions: - text: Get historical detection job {job_id}. slots: job_id: path.job_id - text: Show the details and status of SIEM job {job_id}. slots: job_id: path.job_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/slo/report/{report_id}/download'].get update: x-apievangelist-phrasing: intent: Download a completed SLO report effect: read questions: - How do I download an SLO report once the job finishes? - Do SLO reports stay available forever after they're generated? instructions: - text: Download SLO report {report_id}. slots: report_id: path.report_id - text: Fetch the finished SLO report file for {report_id}. slots: report_id: path.report_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/slo/report/{report_id}/status'].get update: x-apievangelist-phrasing: intent: Check an SLO report job's status effect: read questions: - Is my SLO report job finished yet? - Can I poll the progress of an SLO report generation? instructions: - text: Check the status of SLO report job {report_id}. slots: report_id: path.report_id - text: Tell me whether SLO report {report_id} has completed. slots: report_id: path.report_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/spans/events'].get update: x-apievangelist-phrasing: intent: List spans matching a search query effect: read questions: - How do I see my latest APM spans that match a query? - What is the rate limit for listing spans through the API? instructions: - text: List spans matching {query} from {from} to {to}. slots: query: query.filter[query] from: query.filter[from] to: query.filter[to] - text: Get the latest {limit} spans for {query} sorted by {sort}. slots: limit: query.page[limit] query: query.filter[query] sort: query.sort method: generated generated: '2026-10-01' - target: $.paths['/api/v2/team/{team_id}'].get update: x-apievangelist-phrasing: intent: Get a team effect: read questions: - What is a team's handle, name and description? - Can I look up a single team by its ID? instructions: - text: Get team {team_id}. slots: team_id: path.team_id - text: Show the profile of team {team_id}. slots: team_id: path.team_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/team/{team_id}/links'].get update: x-apievangelist-phrasing: intent: List a team's links effect: read questions: - Which runbooks and docs links are attached to a team? - Can I list all the links on a team's page? instructions: - text: List the links for team {team_id}. slots: team_id: path.team_id - text: Show every link saved on team {team_id}. slots: team_id: path.team_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/team/{team_id}/links/{link_id}'].get update: x-apievangelist-phrasing: intent: Get one team link effect: read questions: - What URL and label does one specific team link have? - How do I read a single link from a team? instructions: - text: Get link {link_id} for team {team_id}. slots: link_id: path.link_id team_id: path.team_id - text: Show the URL of team {team_id}'s link {link_id}. slots: team_id: path.team_id link_id: path.link_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/team/{team_id}/memberships'].get update: x-apievangelist-phrasing: intent: List a team's members effect: read questions: - Who are the members of a team and what roles do they have? - Can I search a team's members by keyword? instructions: - text: List the members of team {team_id}. slots: team_id: path.team_id - text: Find members of team {team_id} matching {keyword}. slots: team_id: path.team_id keyword: query.filter[keyword] method: generated generated: '2026-10-01' - target: $.paths['/api/v2/team/{team_id}/permission-settings'].get update: x-apievangelist-phrasing: intent: Get a team's permission settings effect: read questions: - Who is allowed to edit a team or manage its membership? - Can I see all the permission settings for a team? instructions: - text: Get the permission settings of team {team_id}. slots: team_id: path.team_id - text: Show who can manage team {team_id}. slots: team_id: path.team_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/teams/{team_id}'].get update: x-apievangelist-phrasing: intent: Get an incident team effect: read questions: - What are the details of a team defined for incident management? - Can I see the users related to an incident team? instructions: - text: Get incident team {team_id}. slots: team_id: path.team_id - text: Show incident team {team_id} including {include}. slots: team_id: path.team_id include: query.include method: generated generated: '2026-10-01' - target: $.paths['/api/v2/usage/lambda_traced_invocations'].get update: x-apievangelist-phrasing: intent: Get hourly Lambda traced invocation usage effect: read questions: - How many Lambda traced invocations did we use per hour? - Is the Lambda traced invocations usage endpoint deprecated? instructions: - text: Get hourly Lambda traced invocation usage starting {start_hr}. slots: start_hr: query.start_hr - text: Show Lambda traced invocations usage from {start_hr} to {end_hr}. slots: start_hr: query.start_hr end_hr: query.end_hr method: generated generated: '2026-10-01' - target: $.paths['/api/v2/usage/observability_pipelines'].get update: x-apievangelist-phrasing: intent: Get hourly Observability Pipelines usage effect: read questions: - How much Observability Pipelines usage did we have each hour? - Does the observability pipelines usage endpoint still get updates? instructions: - text: Get hourly Observability Pipelines usage starting {start_hr}. slots: start_hr: query.start_hr - text: Show observability pipelines usage from {start_hr} to {end_hr}. slots: start_hr: query.start_hr end_hr: query.end_hr method: generated generated: '2026-10-01' - target: $.paths['/api/v2/user_invitations/{user_invitation_uuid}'].get update: x-apievangelist-phrasing: intent: Get a user invitation effect: read questions: - Has a user invitation I sent been accepted or expired? - Can I look up a user invitation by its UUID? instructions: - text: Get user invitation {user_invitation_uuid}. slots: user_invitation_uuid: path.user_invitation_uuid - text: Show the status of invitation {user_invitation_uuid}. slots: user_invitation_uuid: path.user_invitation_uuid method: generated generated: '2026-10-01' - target: $.paths['/api/v2/users/{user_id}'].get update: x-apievangelist-phrasing: intent: Get a user's details effect: read questions: - What is a user's email, status and role in my organization? - How do I look up one user's profile by user ID? instructions: - text: Get user {user_id}. slots: user_id: path.user_id - text: Show the account details of user {user_id}. slots: user_id: path.user_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/users/{user_id}/orgs'].get update: x-apievangelist-phrasing: intent: List the organizations a user belongs to effect: read questions: - Which organizations has a given user joined? - Can I see every org a user is a member of? instructions: - text: List the organizations user {user_id} has joined. slots: user_id: path.user_id - text: Show which orgs user {user_id} belongs to. slots: user_id: path.user_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/users/{user_id}/permissions'].get update: x-apievangelist-phrasing: intent: List a user's permissions effect: read questions: - What permissions does a user get from their roles? - Can I check whether a user has a specific permission? instructions: - text: List the permissions granted to user {user_id}. slots: user_id: path.user_id - text: Show user {user_id}'s effective permission set. slots: user_id: path.user_id method: generated generated: '2026-10-01' - target: $.paths['/api/v2/users/{user_uuid}/memberships'].get update: x-apievangelist-phrasing: intent: List a user's team memberships effect: read questions: - Which teams is a particular user a member of? - Can I list a user's team memberships and roles? instructions: - text: List the team memberships of user {user_uuid}. slots: user_uuid: path.user_uuid - text: Show which teams user {user_uuid} belongs to. slots: user_uuid: path.user_uuid method: generated generated: '2026-10-01' - target: $.paths['/api/v2/workflows/{workflow_id}/instances/{instance_id}'].get update: x-apievangelist-phrasing: intent: Get a workflow execution effect: read questions: - Did a specific workflow run succeed, and what did it output? - What permission does my application key need to read workflow executions? instructions: - text: Get execution {instance_id} of workflow {workflow_id}. slots: instance_id: path.instance_id workflow_id: path.workflow_id - text: Show the status of workflow {workflow_id} run {instance_id}. slots: workflow_id: path.workflow_id instance_id: path.instance_id method: generated generated: '2026-10-01'