# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Elastic Cloud Enterprise Authentication API version: 1.0.0 extends: openapi/elk-stack-authentication-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 18 - target: $.paths['/users/auth'].get update: x-apievangelist-phrasing: intent: Get my authentication info effect: read questions: - Am I currently holding elevated permissions in Elastic Cloud Enterprise? - Can I see whether my user has a TOTP device set up? instructions: - text: Show my current authentication information. - text: Tell me whether my session has elevated permissions. method: generated generated: '2026-09-26' - target: $.paths['/users/auth/_login'].post update: x-apievangelist-phrasing: intent: Log in with a username and password effect: write questions: - How do I sign in to ECE with a username and password? - What does a login request need to return a session token? instructions: - text: Log in as {username} with password {password}. slots: username: requestBody.username password: requestBody.password - text: Authenticate user {username} using {password} and login state {login_state}. slots: username: requestBody.username password: requestBody.password login_state: requestBody.login_state method: generated generated: '2026-09-26' - target: $.paths['/users/auth/_logout'].post update: x-apievangelist-phrasing: intent: Log out of the current session effect: destructive questions: - How do I end my current ECE session? - Does logging out destroy the session token? instructions: - text: Log me out. - text: Destroy my current session. method: generated generated: '2026-09-26' - target: $.paths['/users/auth/_refresh'].post update: x-apievangelist-phrasing: intent: Refresh my authentication token effect: write questions: - Can I get a new auth token before the current one expires? - What call issues a fresh authentication token? instructions: - text: Refresh my authentication token. - text: Issue me a new session token. method: generated generated: '2026-09-26' - target: $.paths['/users/auth/keys'].get update: x-apievangelist-phrasing: intent: List API keys I can see effect: read questions: - Which API keys exist that I am allowed to view? - Can I page through the API key list? instructions: - text: List my API keys. - text: Show the next page of API keys from {next_page}. slots: next_page: query.next_page method: generated generated: '2026-09-26' - target: $.paths['/users/auth/keys'].post update: x-apievangelist-phrasing: intent: Create an API key effect: write questions: - How do I create a new API key for automation? - Can a new API key have an expiration and role assignments? instructions: - text: Create an API key described as {description}. slots: description: requestBody.description - text: Create an API key {description} that expires in {expiration}. slots: description: requestBody.description expiration: requestBody.expiration method: generated generated: '2026-09-26' - target: $.paths['/users/auth/keys'].delete update: x-apievangelist-phrasing: intent: Delete several of my API keys effect: destructive questions: - Can I revoke a batch of API keys in one call? - What deletes or invalidates a list of my API keys? instructions: - text: Delete the API keys {keys}. slots: keys: requestBody.keys - text: 'Invalidate these API keys at once: {keys}.' slots: keys: requestBody.keys method: generated generated: '2026-09-26' - target: $.paths['/users/auth/keys/_all'].get update: x-apievangelist-phrasing: intent: List API keys of all users (deprecated) effect: read questions: - Can an admin see the API keys belonging to every user? - Is the all-users API key listing still supported? instructions: - text: List API keys for all users with the deprecated endpoint. - text: Show every user's API key metadata. method: generated generated: '2026-09-26' - target: $.paths['/users/auth/keys/_all'].delete update: x-apievangelist-phrasing: intent: Delete API keys across multiple users effect: destructive questions: - Can I revoke API keys belonging to several different users in one request? - How does an admin invalidate other users' keys in bulk? instructions: - text: 'Delete these API keys across users: {user_api_keys}.' slots: user_api_keys: requestBody.user_api_keys - text: Invalidate the multi-user key set {user_api_keys}. slots: user_api_keys: requestBody.user_api_keys method: generated generated: '2026-09-26' - target: $.paths['/users/auth/keys/{api_key_id}'].get update: x-apievangelist-phrasing: intent: Get one of my API keys effect: read questions: - What is the metadata for a particular API key? - Can I check when a specific key was created? instructions: - text: Get API key {api_key_id}. slots: api_key_id: path.api_key_id - text: Show the metadata for my key {api_key_id}. slots: api_key_id: path.api_key_id method: generated generated: '2026-09-26' - target: $.paths['/users/auth/keys/{api_key_id}'].delete update: x-apievangelist-phrasing: intent: Delete one of my API keys effect: destructive questions: - How do I revoke a single API key that leaked? - Can I invalidate just one of my keys? instructions: - text: Delete API key {api_key_id}. slots: api_key_id: path.api_key_id - text: Revoke my key {api_key_id} now. slots: api_key_id: path.api_key_id method: generated generated: '2026-09-26' - target: $.paths['/users/auth/methods'].get update: x-apievangelist-phrasing: intent: List available authentication methods effect: read questions: - Which sign-in methods are enabled, like password or SAML? - What authentication options does this installation offer? instructions: - text: List the available authentication methods. - text: Show which login options are enabled. method: generated generated: '2026-09-26' - target: $.paths['/users/auth/saml/_callback'].post update: x-apievangelist-phrasing: intent: Complete SAML sign-in from the identity provider effect: write questions: - What handles the SAML response coming back from my identity provider? - Is RelayState needed when completing SAML login? instructions: - text: Complete SAML login with response {SAMLResponse}. slots: SAMLResponse: requestBody.SAMLResponse - text: Post SAML response {SAMLResponse} with relay state {RelayState}. slots: SAMLResponse: requestBody.SAMLResponse RelayState: requestBody.RelayState method: generated generated: '2026-09-26' - target: $.paths['/users/auth/saml/_init'].get update: x-apievangelist-phrasing: intent: Start SAML single sign-on effect: read questions: - How do I kick off SAML single sign-on to my identity provider? - Can I choose which SAML realm to redirect to? instructions: - text: Start SAML sign-on. - text: Begin SAML SSO against realm {realm} with state {state}. slots: realm: query.realm state: query.state method: generated generated: '2026-09-26' - target: $.paths['/users/{user_id}/auth/keys'].get update: x-apievangelist-phrasing: intent: List a user's API keys effect: read questions: - Which API keys has a particular user created? - Can an admin audit the keys one user owns? instructions: - text: List the API keys created by user {user_id}. slots: user_id: path.user_id - text: Audit every key belonging to {user_id}. slots: user_id: path.user_id method: generated generated: '2026-09-26' - target: $.paths['/users/{user_id}/auth/keys'].delete update: x-apievangelist-phrasing: intent: Delete all API keys of a user effect: destructive questions: - How do I revoke every API key for a user who left? - Can I wipe all of one user's keys in a single call? instructions: - text: Delete all API keys for user {user_id}. slots: user_id: path.user_id - text: Invalidate every key owned by {user_id}. slots: user_id: path.user_id method: generated generated: '2026-09-26' - target: $.paths['/users/{user_id}/auth/keys/{api_key_id}'].get update: x-apievangelist-phrasing: intent: Get one API key of a user effect: read questions: - Can I view a single API key that belongs to another user? - What metadata does one user's specific key have? instructions: - text: Get API key {api_key_id} of user {user_id}. slots: api_key_id: path.api_key_id user_id: path.user_id - text: Show metadata for user {user_id}'s key {api_key_id}. slots: user_id: path.user_id api_key_id: path.api_key_id method: generated generated: '2026-09-26' - target: $.paths['/users/{user_id}/auth/keys/{api_key_id}'].delete update: x-apievangelist-phrasing: intent: Delete one API key of a user effect: destructive questions: - How does an admin revoke one specific key belonging to another user? - Can I invalidate a single key without touching the user's others? instructions: - text: Delete API key {api_key_id} of user {user_id}. slots: api_key_id: path.api_key_id user_id: path.user_id - text: Revoke user {user_id}'s key {api_key_id}. slots: user_id: path.user_id api_key_id: path.api_key_id method: generated generated: '2026-09-26'