# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for dotCMS REST SAML Authentication API version: 1.0.0 extends: openapi/dotcms-saml-authentication-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 5 - target: $.paths['/api/v1/dotsaml/login/{idpConfigId}'].get update: x-apievangelist-phrasing: intent: Start a SAML single sign-on login effect: read questions: - How do I send a user to the identity provider's login screen for SAML SSO? - What kicks off the SAML authentication request for a site? instructions: - text: Start a SAML login for IDP configuration {idpConfigId}. slots: idpConfigId: path.idpConfigId - text: Redirect me to the identity provider sign-in for {idpConfigId}. slots: idpConfigId: path.idpConfigId method: generated generated: '2026-09-26' - target: $.paths['/api/v1/dotsaml/login/{idpConfigId}'].post update: x-apievangelist-phrasing: intent: Handle the SAML login callback effect: write questions: - Where does the identity provider post the SAML assertion after a user signs in? - Does the SAML callback create the user in dotCMS if they don't exist? instructions: - text: Process the SAML assertion callback for IDP configuration {idpConfigId}. slots: idpConfigId: path.idpConfigId - text: Complete the SSO login and sign the user in for {idpConfigId}. slots: idpConfigId: path.idpConfigId method: generated generated: '2026-09-26' - target: $.paths['/api/v1/dotsaml/logout/{idpConfigId}'].get update: x-apievangelist-phrasing: intent: Log out of SAML via GET effect: write questions: - How do I start a SAML logout from a browser link? - Which GET route ends the SAML session and redirects to the logout page? instructions: - text: Start a SAML logout via GET for IDP configuration {idpConfigId}. slots: idpConfigId: path.idpConfigId - text: Sign me out of SSO for {idpConfigId} using the GET logout link. slots: idpConfigId: path.idpConfigId method: generated generated: '2026-09-26' - target: $.paths['/api/v1/dotsaml/logout/{idpConfigId}'].post update: x-apievangelist-phrasing: intent: Handle a SAML logout callback via POST effect: write questions: - Where does the identity provider POST its logout callback? - Can the IDP send a SAML logout response back with a POST? instructions: - text: Process the SAML logout POST callback for IDP configuration {idpConfigId}. slots: idpConfigId: path.idpConfigId - text: Handle the identity provider's logout POST for {idpConfigId} and redirect to the logout endpoint. slots: idpConfigId: path.idpConfigId method: generated generated: '2026-09-26' - target: $.paths['/api/v1/dotsaml/metadata/{idpConfigId}'].get update: x-apievangelist-phrasing: intent: Get the SAML service provider metadata effect: read questions: - Where do I get the SP metadata XML to register dotCMS with my identity provider? - Is the SAML metadata endpoint limited to administrators? instructions: - text: Get the SAML service provider metadata for {idpConfigId}. slots: idpConfigId: path.idpConfigId - text: Download the SP metadata XML for IDP configuration {idpConfigId}. slots: idpConfigId: path.idpConfigId method: generated generated: '2026-09-26'