# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Elk Stack Security API version: 1.0.0 extends: openapi/elk-stack-security-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 100 - target: $.paths['/_encryption/_reset'].post update: x-apievangelist-phrasing: intent: Reset the project encryption key effect: destructive questions: - How do I recover when the project encryption key can no longer be read from disk? - What data is lost if I destroy and regenerate the project encryption key? instructions: - text: Reset the project encryption key, confirming data loss with {accept_data_loss}. slots: accept_data_loss: query.accept_data_loss - text: Destroy the current PEK and generate a new one; accept_data_loss is {accept_data_loss}. slots: accept_data_loss: query.accept_data_loss method: generated generated: '2026-09-26' - target: $.paths['/_security/profile/_activate'].post update: x-apievangelist-phrasing: intent: Activate a user profile for another user effect: write questions: - How does Kibana create or refresh a user profile on behalf of a user who just logged in? - Can a profile be activated with a username and password instead of an access token? instructions: - text: Activate the user profile for {username} using grant type {grant_type}. slots: username: requestBody.username grant_type: requestBody.grant_type - text: Activate a profile from access token {access_token} with grant type {grant_type}. slots: access_token: requestBody.access_token grant_type: requestBody.grant_type method: generated generated: '2026-09-26' - target: $.paths['/_security/_authenticate'].get update: x-apievangelist-phrasing: intent: See who I'm authenticated as effect: read questions: - Which user and roles is my current Elasticsearch credential authenticated as? - How can I verify that my credentials work and see the realm they come from? instructions: - text: Tell me who I'm currently authenticated as. - text: Show the authenticated user, roles and realm for my current credentials. method: generated generated: '2026-09-26' - target: $.paths['/_security/role'].get update: x-apievangelist-phrasing: intent: List all native realm roles effect: read questions: - Which roles are defined in the native realm? - Can I list every role, including the implicit ones? instructions: - text: List all roles in the native realm. - text: Get every role, with include_implicit set to {include_implicit}. slots: include_implicit: query.include_implicit method: generated generated: '2026-09-26' - target: $.paths['/_security/role'].post update: x-apievangelist-phrasing: intent: Create or update many roles at once effect: write questions: - How do I create several native realm roles in a single request? - Can I bulk-update the privileges of multiple roles together? instructions: - text: Bulk create or update the roles {roles}. slots: roles: requestBody.roles - text: 'Upsert these role definitions in one batch: {roles}.' slots: roles: requestBody.roles method: generated generated: '2026-09-26' - target: $.paths['/_security/role'].delete update: x-apievangelist-phrasing: intent: Delete many roles at once effect: destructive questions: - How do I delete several native realm roles in one call? - Can I bulk-remove roles by listing their names? instructions: - text: Bulk delete the roles {names}. slots: names: requestBody.names - text: 'Remove these roles from the native realm together: {names}.' slots: names: requestBody.names method: generated generated: '2026-09-26' - target: $.paths['/_security/api_key/_bulk_update'].post update: x-apievangelist-phrasing: intent: Update multiple API keys at once effect: write questions: - How do I apply the same metadata or expiration to many API keys in one request? - Can I change the role descriptors on several API keys together? instructions: - text: Set expiration {expiration} on API keys {ids}. slots: expiration: requestBody.expiration ids: requestBody.ids - text: Bulk update API keys {ids} with metadata {metadata}. slots: ids: requestBody.ids metadata: requestBody.metadata method: generated generated: '2026-09-26' - target: $.paths['/_security/user/{username}/_password'].put update: x-apievangelist-phrasing: intent: Change a user's password (PUT) effect: write questions: - How do I reset the password of a specific native realm user? - Can I set a user's password from a precomputed hash instead of plain text? instructions: - text: Change the password for user {username} to {password}. slots: username: path.username password: requestBody.password - text: Set password hash {password_hash} on user {username}. slots: username: path.username password_hash: requestBody.password_hash method: generated generated: '2026-09-26' - target: $.paths['/_security/user/{username}/_password'].post update: x-apievangelist-phrasing: intent: Change a named user's password via POST effect: write questions: - Is there a POST form of the endpoint for changing a named user's password? - Can a built-in user like kibana_system get a new password through a POST call? instructions: - text: With POST, give user {username} the new password {password}. slots: username: path.username password: requestBody.password - text: POST a new hashed credential {password_hash} for built-in user {username}. slots: username: path.username password_hash: requestBody.password_hash method: generated generated: '2026-09-26' - target: $.paths['/_security/user/_password'].put update: x-apievangelist-phrasing: intent: Change my own password (PUT) effect: write questions: - How do I change the password of the user I'm currently logged in as? - Can I update my own password without naming my username in the path? instructions: - text: Change my own password to {password}. slots: password: requestBody.password - text: Replace my current credential with hash {password_hash}. slots: password_hash: requestBody.password_hash method: generated generated: '2026-09-26' - target: $.paths['/_security/user/_password'].post update: x-apievangelist-phrasing: intent: Change my own password via POST effect: write questions: - Is there a POST version of changing the password for the logged-in user? - Can I refresh the index immediately after changing my own password with a POST request? instructions: - text: Using POST, update the password of the current user to {password}. slots: password: requestBody.password - text: POST my new password {password} and set refresh to {refresh}. slots: password: requestBody.password refresh: query.refresh method: generated generated: '2026-09-26' - target: $.paths['/_security/api_key/{ids}/_clear_cache'].post update: x-apievangelist-phrasing: intent: Clear cached API keys effect: write questions: - How do I evict specific API keys from the API key cache? - Can I flush every cached API key at once? instructions: - text: Clear the API key cache for keys {ids}. slots: ids: path.ids - text: Evict API key IDs {ids} from the cache. slots: ids: path.ids method: generated generated: '2026-09-26' - target: $.paths['/_security/privilege/{application}/_clear_cache'].post update: x-apievangelist-phrasing: intent: Clear cached application privileges effect: write questions: - How do I evict an application's privileges from the privilege cache? - Why do my application privilege changes not show up until the cache is cleared? instructions: - text: Clear the privilege cache for application {application}. slots: application: path.application - text: Evict cached privileges of app {application}. slots: application: path.application method: generated generated: '2026-09-26' - target: $.paths['/_security/realm/{realms}/_clear_cache'].post update: x-apievangelist-phrasing: intent: Clear the user cache for realms effect: write questions: - How do I force a realm to re-authenticate users by clearing its user cache? - Can I evict only specific users from a realm's cache? instructions: - text: Clear the user cache for realm {realms}. slots: realms: path.realms - text: Evict users {usernames} from the cache of realm {realms}. slots: realms: path.realms usernames: query.usernames method: generated generated: '2026-09-26' - target: $.paths['/_security/role/{name}/_clear_cache'].post update: x-apievangelist-phrasing: intent: Clear cached roles effect: write questions: - How do I evict a role from the native role cache after editing it? - Can I clear the role cache for just one role? instructions: - text: Clear the role cache for role {name}. slots: name: path.name - text: Evict cached role {name} from the native role cache. slots: name: path.name method: generated generated: '2026-09-26' - target: $.paths['/_security/service/{namespace}/{service}/credential/token/{name}/_clear_cache'].post update: x-apievangelist-phrasing: intent: Clear service account token caches effect: write questions: - How do I evict a service account token from the token caches? - Can I clear cached credentials for one specific service account token? instructions: - text: Clear the cache for service token {name} of service {namespace}/{service}. slots: namespace: path.namespace service: path.service name: path.name - text: Evict cached token {name} for {namespace}/{service}. slots: namespace: path.namespace service: path.service name: path.name method: generated generated: '2026-09-26' - target: $.paths['/_security/api_key/clone'].put update: x-apievangelist-phrasing: intent: Clone an API key (PUT) effect: write questions: - How do I copy an existing API key so it gets a new ID but the same role descriptors? - Can a cloned API key have its own name and expiration? instructions: - text: Clone API key {api_key} under the name {name}. slots: api_key: requestBody.api_key name: requestBody.name - text: Duplicate key {api_key} with expiration {expiration}. slots: api_key: requestBody.api_key expiration: requestBody.expiration method: generated generated: '2026-09-26' - target: $.paths['/_security/api_key/clone'].post update: x-apievangelist-phrasing: intent: Clone an API key via POST effect: write questions: - Is there a POST endpoint to make a copy of an API key with a fresh ID? - Does a copied key inherit the source key's permissions? instructions: - text: Via POST, create a copy of API key {api_key} called {name}. slots: api_key: requestBody.api_key name: requestBody.name - text: POST a clone of {api_key} carrying metadata {metadata}. slots: api_key: requestBody.api_key metadata: requestBody.metadata method: generated generated: '2026-09-26' - target: $.paths['/_security/api_key'].get update: x-apievangelist-phrasing: intent: Get API key information effect: read questions: - What API keys exist for a given user or realm? - Can I list only the API keys that are still active? - Which API keys do I own? instructions: - text: Get information for API key {id}. slots: id: query.id - text: Show the API keys owned by user {username}. slots: username: query.username - text: 'Look up API keys named {name}, active only: {active_only}.' slots: name: query.name active_only: query.active_only method: generated generated: '2026-09-26' - target: $.paths['/_security/api_key'].put update: x-apievangelist-phrasing: intent: Create an API key (PUT) effect: write questions: - How do I create an API key so a script can call Elasticsearch without basic auth? - Can I restrict a new API key to specific role descriptors? instructions: - text: Create an API key named {name} that expires in {expiration}. slots: name: requestBody.name expiration: requestBody.expiration - text: Create API key {name} limited to role descriptors {role_descriptors}. slots: name: requestBody.name role_descriptors: requestBody.role_descriptors method: generated generated: '2026-09-26' - target: $.paths['/_security/api_key'].post update: x-apievangelist-phrasing: intent: Create an API key via POST effect: write questions: - Is there a POST request for generating a new Elasticsearch API key? - Does a newly generated API key never expire unless I set an expiration? instructions: - text: Using POST, generate an API key called {name}. slots: name: requestBody.name - text: POST a new key {name} with metadata {metadata}. slots: name: requestBody.name metadata: requestBody.metadata method: generated generated: '2026-09-26' - target: $.paths['/_security/api_key'].delete update: x-apievangelist-phrasing: intent: Invalidate API keys effect: destructive questions: - How do I revoke API keys so they stop authenticating? - Can I invalidate all API keys belonging to one user? - Are invalidated API keys still visible afterwards? instructions: - text: Invalidate API keys {ids}. slots: ids: requestBody.ids - text: Revoke every API key owned by user {username}. slots: username: requestBody.username - text: Invalidate the API key named {name}. slots: name: requestBody.name method: generated generated: '2026-09-26' - target: $.paths['/_security/cross_cluster/api_key'].post update: x-apievangelist-phrasing: intent: Create a cross-cluster API key effect: write questions: - How do I create an API key for API key based remote cluster access? - Can a cross-cluster key grant both search and replication access? instructions: - text: Create cross-cluster API key {name} with access {access}. slots: name: requestBody.name access: requestBody.access - text: Create a remote cluster key {name} granting {access} that expires in {expiration}. slots: name: requestBody.name access: requestBody.access expiration: requestBody.expiration method: generated generated: '2026-09-26' - target: $.paths['/_security/service/{namespace}/{service}/credential/token/{name}'].put update: x-apievangelist-phrasing: intent: Create a named service account token (PUT) effect: write questions: - How do I create a named token for a service account like elastic/fleet-server? - Can a service account token be used instead of basic authentication? instructions: - text: Create service token {name} for service account {namespace}/{service}. slots: namespace: path.namespace service: path.service name: path.name - text: Issue token {name} to {namespace}/{service} with refresh {refresh}. slots: namespace: path.namespace service: path.service name: path.name refresh: query.refresh method: generated generated: '2026-09-26' - target: $.paths['/_security/service/{namespace}/{service}/credential/token/{name}'].post update: x-apievangelist-phrasing: intent: Create a named service account token via POST effect: write questions: - Is there a POST call for issuing a named service account token? - Can I POST to mint a credential with my chosen token name for a service? instructions: - text: Using POST, mint token {name} for service {namespace}/{service}. slots: namespace: path.namespace service: path.service name: path.name - text: POST a new credential called {name} under {namespace}/{service}. slots: namespace: path.namespace service: path.service name: path.name method: generated generated: '2026-09-26' - target: $.paths['/_security/service/{namespace}/{service}/credential/token/{name}'].delete update: x-apievangelist-phrasing: intent: Delete a service account token effect: destructive questions: - How do I revoke a service account token that was leaked? - Can I delete one named token for a service account? instructions: - text: Delete service token {name} from {namespace}/{service}. slots: namespace: path.namespace service: path.service name: path.name - text: Revoke the {name} token of service account {namespace}/{service}. slots: namespace: path.namespace service: path.service name: path.name method: generated generated: '2026-09-26' - target: $.paths['/_security/service/{namespace}/{service}/credential/token'].post update: x-apievangelist-phrasing: intent: Create an auto-named service account token effect: write questions: - Can Elasticsearch generate a service account token with an automatically assigned name? - How do I get a token for a service account without choosing a token name? instructions: - text: Create an auto-named token for service account {namespace}/{service}. slots: namespace: path.namespace service: path.service - text: Generate a token with a system-assigned name for {namespace}/{service}. slots: namespace: path.namespace service: path.service method: generated generated: '2026-09-26' - target: $.paths['/_security/delegate_pki'].post update: x-apievangelist-phrasing: intent: Exchange a PKI certificate chain for a token effect: write questions: - How do I exchange a client X.509 certificate chain for an Elasticsearch access token? - Can a proxy that terminates TLS delegate PKI authentication to Elasticsearch? instructions: - text: Delegate PKI authentication for certificate chain {x509_certificate_chain}. slots: x509_certificate_chain: requestBody.x509_certificate_chain - text: Get an access token from X.509 chain {x509_certificate_chain}. slots: x509_certificate_chain: requestBody.x509_certificate_chain method: generated generated: '2026-09-26' - target: $.paths['/_security/privilege/{application}/{name}'].get update: x-apievangelist-phrasing: intent: Get one application privilege effect: read questions: - What actions does a specific named privilege of my application grant? - Can I look up a single application privilege by application and name? instructions: - text: Get privilege {name} of application {application}. slots: application: path.application name: path.name - text: Show the actions granted by {application} privilege {name}. slots: application: path.application name: path.name method: generated generated: '2026-09-26' - target: $.paths['/_security/privilege/{application}/{name}'].delete update: x-apievangelist-phrasing: intent: Delete application privileges effect: destructive questions: - How do I remove an application privilege I no longer use? - Can I delete a single privilege from an application? instructions: - text: Delete privilege {name} from application {application}. slots: application: path.application name: path.name - text: Remove application privilege {application}/{name}. slots: application: path.application name: path.name method: generated generated: '2026-09-26' - target: $.paths['/_security/role/{name}'].get update: x-apievangelist-phrasing: intent: Get a specific role effect: read questions: - What cluster and index privileges does a particular role grant? - Can I look up one role by name in the native realm? instructions: - text: Show the role {name}. slots: name: path.name - text: Get the privileges defined in role {name}. slots: name: path.name method: generated generated: '2026-09-26' - target: $.paths['/_security/role/{name}'].put update: x-apievangelist-phrasing: intent: Create or update a role (PUT) effect: write questions: - How do I create a role that grants read access to certain indices? - Can a role include remote cluster index privileges? instructions: - text: Create role {name} with index privileges {indices}. slots: name: path.name indices: requestBody.indices - text: Update role {name} to grant cluster privileges {cluster}. slots: name: path.name cluster: requestBody.cluster method: generated generated: '2026-09-26' - target: $.paths['/_security/role/{name}'].post update: x-apievangelist-phrasing: intent: Create or update a role via POST effect: write questions: - Is there a POST request for defining a single native realm role? - Can I give a role a description and run_as permissions? instructions: - text: Via POST, define role {name} with description {description}. slots: name: path.name description: requestBody.description - text: POST role {name} allowing run_as for {run_as}. slots: name: path.name run_as: requestBody.run_as method: generated generated: '2026-09-26' - target: $.paths['/_security/role/{name}'].delete update: x-apievangelist-phrasing: intent: Delete a role effect: destructive questions: - How do I remove a single role from the native realm? - What happens to users assigned a role after I delete it? instructions: - text: Delete role {name}. slots: name: path.name - text: Remove the native realm role {name}. slots: name: path.name method: generated generated: '2026-09-26' - target: $.paths['/_security/role_mapping/{name}'].get update: x-apievangelist-phrasing: intent: Get a role mapping effect: read questions: - Which roles does a specific role mapping assign, and to which users? - Can I look up one role mapping by name? instructions: - text: Show role mapping {name}. slots: name: path.name - text: Get the rules and roles of mapping {name}. slots: name: path.name method: generated generated: '2026-09-26' - target: $.paths['/_security/role_mapping/{name}'].put update: x-apievangelist-phrasing: intent: Create or update a role mapping (PUT) effect: write questions: - How do I map LDAP or SAML users to Elasticsearch roles? - Can a role mapping assign roles through templates instead of fixed names? instructions: - text: Create role mapping {name} assigning roles {roles} to users matching {rules}. slots: name: path.name roles: requestBody.roles rules: requestBody.rules - text: Update mapping {name} and set enabled to {enabled}. slots: name: path.name enabled: requestBody.enabled method: generated generated: '2026-09-26' - target: $.paths['/_security/role_mapping/{name}'].post update: x-apievangelist-phrasing: intent: Create or update a role mapping via POST effect: write questions: - Is there a POST endpoint for defining which roles a group of users receives? - Can I POST a mapping that uses role templates? instructions: - text: Via POST, create role mapping {name} with role templates {role_templates}. slots: name: path.name role_templates: requestBody.role_templates - text: POST mapping {name} granting {roles}. slots: name: path.name roles: requestBody.roles method: generated generated: '2026-09-26' - target: $.paths['/_security/role_mapping/{name}'].delete update: x-apievangelist-phrasing: intent: Delete a role mapping effect: destructive questions: - How do I remove a role mapping so users stop receiving its roles? - Can I delete one role mapping by name? instructions: - text: Delete role mapping {name}. slots: name: path.name - text: Remove the mapping {name} that assigns roles to users. slots: name: path.name method: generated generated: '2026-09-26' - target: $.paths['/_security/user/{username}'].get update: x-apievangelist-phrasing: intent: Get a specific user effect: read questions: - What roles and details does a particular native realm user have? - Can I see a user's profile UID along with their account? instructions: - text: Show user {username}. slots: username: path.username - text: 'Get user {username} including profile uid: {with_profile_uid}.' slots: username: path.username with_profile_uid: query.with_profile_uid method: generated generated: '2026-09-26' - target: $.paths['/_security/user/{username}'].put update: x-apievangelist-phrasing: intent: Create or update a user (PUT) effect: write questions: - How do I add a new user to the native realm with a password and roles? - Can I update a user's roles without changing their password? instructions: - text: Create user {username} with password {password} and roles {roles}. slots: username: path.username password: requestBody.password roles: requestBody.roles - text: Update user {username}'s email to {email}. slots: username: path.username email: requestBody.email method: generated generated: '2026-09-26' - target: $.paths['/_security/user/{username}'].post update: x-apievangelist-phrasing: intent: Create or update a user via POST effect: write questions: - Is there a POST request for adding a native realm user? - Can I set a user's full name and metadata when creating them? instructions: - text: Via POST, add user {username} with full name {full_name}. slots: username: path.username full_name: requestBody.full_name - text: POST user {username} assigned the roles {roles}. slots: username: path.username roles: requestBody.roles method: generated generated: '2026-09-26' - target: $.paths['/_security/user/{username}'].delete update: x-apievangelist-phrasing: intent: Delete a user effect: destructive questions: - How do I delete a user from the native realm? - Can a deleted native user be restored afterwards? instructions: - text: Delete user {username}. slots: username: path.username - text: Remove native realm user {username} permanently. slots: username: path.username method: generated generated: '2026-09-26' - target: $.paths['/_security/user/{username}/_disable'].put update: x-apievangelist-phrasing: intent: Disable a user (PUT) effect: write questions: - How do I block a native user from logging in without deleting them? - Can I disable a built-in user account? instructions: - text: Disable user {username}. slots: username: path.username - text: Prevent {username} from authenticating by disabling the account. slots: username: path.username method: generated generated: '2026-09-26' - target: $.paths['/_security/user/{username}/_disable'].post update: x-apievangelist-phrasing: intent: Disable a user via POST effect: write questions: - Is there a POST call for turning off a native realm account? - Can I POST to deactivate an account and refresh right away? instructions: - text: Using POST, deactivate account {username}. slots: username: path.username - text: POST a disable for {username} with refresh {refresh}. slots: username: path.username refresh: query.refresh method: generated generated: '2026-09-26' - target: $.paths['/_security/profile/{uid}/_disable'].put update: x-apievangelist-phrasing: intent: Disable a user profile (PUT) effect: write questions: - How do I hide a user profile from user profile searches? - Can I disable a profile by its UID? instructions: - text: Disable user profile {uid}. slots: uid: path.uid - text: Hide profile {uid} from profile suggestions. slots: uid: path.uid method: generated generated: '2026-09-26' - target: $.paths['/_security/profile/{uid}/_disable'].post update: x-apievangelist-phrasing: intent: Disable a user profile via POST effect: write questions: - Is there a POST request to make a profile invisible in searches? - Can I POST to deactivate a Kibana user profile? instructions: - text: Using POST, deactivate profile {uid}. slots: uid: path.uid - text: POST a disable for Kibana profile {uid} with refresh {refresh}. slots: uid: path.uid refresh: query.refresh method: generated generated: '2026-09-26' - target: $.paths['/_security/user/{username}/_enable'].put update: x-apievangelist-phrasing: intent: Enable a user (PUT) effect: write questions: - How do I re-enable a native user account that was disabled? - Can I let a disabled built-in user log in again? instructions: - text: Enable user {username}. slots: username: path.username - text: Restore login access for disabled account {username}. slots: username: path.username method: generated generated: '2026-09-26' - target: $.paths['/_security/user/{username}/_enable'].post update: x-apievangelist-phrasing: intent: Enable a user via POST effect: write questions: - Is there a POST call for reactivating a disabled native account? - Can I POST to turn a user back on and refresh immediately? instructions: - text: Using POST, reactivate user {username}. slots: username: path.username - text: POST an enable for {username} with refresh {refresh}. slots: username: path.username refresh: query.refresh method: generated generated: '2026-09-26' - target: $.paths['/_security/profile/{uid}/_enable'].put update: x-apievangelist-phrasing: intent: Enable a user profile (PUT) effect: write questions: - How do I make a disabled user profile visible in profile searches again? - Can I re-enable a profile by its UID? instructions: - text: Enable user profile {uid}. slots: uid: path.uid - text: Make profile {uid} show up in profile suggestions again. slots: uid: path.uid method: generated generated: '2026-09-26' - target: $.paths['/_security/profile/{uid}/_enable'].post update: x-apievangelist-phrasing: intent: Enable a user profile via POST effect: write questions: - Is there a POST request to reactivate a hidden profile? - Can I POST to turn a Kibana user profile back on? instructions: - text: Using POST, reactivate profile {uid}. slots: uid: path.uid - text: POST an enable for Kibana profile {uid} with refresh {refresh}. slots: uid: path.uid refresh: query.refresh method: generated generated: '2026-09-26' - target: $.paths['/_security/enroll/kibana'].get update: x-apievangelist-phrasing: intent: Enroll a Kibana instance effect: read questions: - How does a new Kibana instance get the credentials it needs to talk to a secured cluster? - What does the Kibana enrollment call return? instructions: - text: Enroll a Kibana instance with this cluster. - text: Get the enrollment credentials and CA for a new Kibana. method: generated generated: '2026-09-26' - target: $.paths['/_security/enroll/node'].get update: x-apievangelist-phrasing: intent: Enroll a new node into the cluster effect: read questions: - How do I add a new node to a cluster that has security enabled? - What certificates does a node receive when it enrolls? instructions: - text: Enroll a new node into this secured cluster. - text: Get the transport certificates a new node needs to join. method: generated generated: '2026-09-26' - target: $.paths['/_security/privilege/_builtin'].get update: x-apievangelist-phrasing: intent: List built-in privileges effect: read questions: - Which cluster and index privileges are available in this Elasticsearch version? - Where can I see every built-in privilege name? instructions: - text: List all built-in cluster and index privileges. - text: Show the built-in privilege names available in this version. method: generated generated: '2026-09-26' - target: $.paths['/_security/privilege'].get update: x-apievangelist-phrasing: intent: List all application privileges effect: read questions: - Which application privileges are defined across all applications? - Can I see every application privilege at once? instructions: - text: List all application privileges. - text: Show every application privilege defined on the cluster. method: generated generated: '2026-09-26' - target: $.paths['/_security/privilege'].put update: x-apievangelist-phrasing: intent: Create or update application privileges (PUT) effect: write questions: - How do I define custom privileges for my own application? - Can I add several application privileges in a single request? instructions: - text: Create or update application privileges with refresh {refresh}. slots: refresh: query.refresh - text: Add the application privileges I describe and refresh with {refresh}. slots: refresh: query.refresh method: generated generated: '2026-09-26' - target: $.paths['/_security/privilege'].post update: x-apievangelist-phrasing: intent: Create or update application privileges via POST effect: write questions: - Is there a POST form of the endpoint for defining app privileges? - Can I POST custom privilege definitions for several applications together? instructions: - text: Using POST, upsert app privileges, refresh set to {refresh}. slots: refresh: query.refresh - text: POST my privilege definitions for my applications. method: generated generated: '2026-09-26' - target: $.paths['/_security/privilege/{application}'].get update: x-apievangelist-phrasing: intent: List privileges for one application effect: read questions: - Which privileges are defined for a specific application? - Can I list all privileges for just my app? instructions: - text: List the privileges of application {application}. slots: application: path.application - text: Show every privilege defined for app {application}. slots: application: path.application method: generated generated: '2026-09-26' - target: $.paths['/_security/role_mapping'].get update: x-apievangelist-phrasing: intent: List all role mappings effect: read questions: - Which role mappings are configured on this cluster? - Can I see every mapping of users to roles at once? instructions: - text: List all role mappings. - text: Show every role mapping with its rules. method: generated generated: '2026-09-26' - target: $.paths['/_security/service/{namespace}/{service}'].get update: x-apievangelist-phrasing: intent: Get one service account effect: read questions: - What role descriptor does a specific service account have? - Can I look up a service account by namespace and service name? instructions: - text: Get service account {namespace}/{service}. slots: namespace: path.namespace service: path.service - text: Show the role descriptor of service {namespace}/{service}. slots: namespace: path.namespace service: path.service method: generated generated: '2026-09-26' - target: $.paths['/_security/service/{namespace}'].get update: x-apievangelist-phrasing: intent: List service accounts in a namespace effect: read questions: - Which service accounts exist in a given namespace? - Can I list all service accounts under the elastic namespace? instructions: - text: List service accounts in namespace {namespace}. slots: namespace: path.namespace - text: Show every service account under {namespace}. slots: namespace: path.namespace method: generated generated: '2026-09-26' - target: $.paths['/_security/service'].get update: x-apievangelist-phrasing: intent: List all service accounts effect: read questions: - Which service accounts are available in Elasticsearch? - Can I see every service account across all namespaces? instructions: - text: List all service accounts. - text: Show every service account across namespaces. method: generated generated: '2026-09-26' - target: $.paths['/_security/service/{namespace}/{service}/credential'].get update: x-apievangelist-phrasing: intent: List a service account's credentials effect: read questions: - Which tokens exist for a specific service account? - Can I see both index-backed and file-backed tokens for a service? instructions: - text: List credentials for service account {namespace}/{service}. slots: namespace: path.namespace service: path.service - text: Show all tokens issued to {namespace}/{service}. slots: namespace: path.namespace service: path.service method: generated generated: '2026-09-26' - target: $.paths['/_security/settings'].get update: x-apievangelist-phrasing: intent: Get security index settings effect: read questions: - What user-configurable settings are applied to the .security index? - Can I check the replica settings of the security system indices? instructions: - text: Show the security index settings. - text: Get settings for the .security indices, waiting {master_timeout} for the master. slots: master_timeout: query.master_timeout method: generated generated: '2026-09-26' - target: $.paths['/_security/settings'].put update: x-apievangelist-phrasing: intent: Update security index settings effect: write questions: - How do I change the number of replicas for the .security index? - Can I update settings for the security profile and tokens indices too? instructions: - text: Update the .security index settings to {security}. slots: security: requestBody.security - text: Apply settings {security-tokens} to the security tokens index. slots: security-tokens: requestBody.security-tokens method: generated generated: '2026-09-26' - target: $.paths['/_security/stats'].get update: x-apievangelist-phrasing: intent: Get security usage stats effect: read questions: - What security usage statistics do the nodes in my cluster report? - Where can I gather security stats from every node? instructions: - text: Show security usage statistics for all nodes. - text: Gather security stats across the cluster. method: generated generated: '2026-09-26' - target: $.paths['/_security/oauth2/token'].post update: x-apievangelist-phrasing: intent: Get an OAuth2 bearer token effect: write questions: - How do I get a bearer access token from Elasticsearch using a username and password? - Can I refresh an expired access token with a refresh token? - Which grant types can I use to obtain a token? instructions: - text: Get a bearer token for user {username} with password {password} using grant type {grant_type}. slots: username: requestBody.username password: requestBody.password grant_type: requestBody.grant_type - text: Exchange refresh token {refresh_token} for a new access token. slots: refresh_token: requestBody.refresh_token method: generated generated: '2026-09-26' - target: $.paths['/_security/oauth2/token'].delete update: x-apievangelist-phrasing: intent: Invalidate access or refresh tokens effect: destructive questions: - How do I revoke an access token before it expires? - Can I invalidate all tokens issued to a user or realm? instructions: - text: Invalidate access token {token}. slots: token: requestBody.token - text: Revoke every token belonging to user {username}. slots: username: requestBody.username - text: Invalidate refresh token {refresh_token}. slots: refresh_token: requestBody.refresh_token method: generated generated: '2026-09-26' - target: $.paths['/_security/user'].get update: x-apievangelist-phrasing: intent: List all users effect: read questions: - Which users exist in the native realm, including built-in ones? - Can I list every user along with their profile IDs? instructions: - text: List all users. - text: 'Show every user, with profile uid included: {with_profile_uid}.' slots: with_profile_uid: query.with_profile_uid method: generated generated: '2026-09-26' - target: $.paths['/_security/user/_privileges'].get update: x-apievangelist-phrasing: intent: Get my own privileges effect: read questions: - What privileges does my logged-in user actually have? - Can I see all cluster, index and application privileges granted to me? instructions: - text: Show the privileges of the logged-in user. - text: List everything my current account is allowed to do. method: generated generated: '2026-09-26' - target: $.paths['/_security/profile/{uid}'].get update: x-apievangelist-phrasing: intent: Get a user profile effect: read questions: - What does a user profile contain for a given profile ID? - Can I fetch only certain application data stored in a profile? instructions: - text: Get user profile {uid}. slots: uid: path.uid - text: Show profile {uid} including data {data}. slots: uid: path.uid data: query.data method: generated generated: '2026-09-26' - target: $.paths['/_security/api_key/grant'].post update: x-apievangelist-phrasing: intent: Grant an API key on behalf of a user effect: write questions: - How do I create an API key for another user using their credentials? - Can I grant an API key from a user's access token instead of a password? instructions: - text: Grant API key {api_key} for user {username} using grant type {grant_type}. slots: api_key: requestBody.api_key username: requestBody.username grant_type: requestBody.grant_type - text: Create key {api_key} on behalf of the holder of access token {access_token} with grant type {grant_type}. slots: api_key: requestBody.api_key access_token: requestBody.access_token grant_type: requestBody.grant_type method: generated generated: '2026-09-26' - target: $.paths['/_security/user/_has_privileges'].get update: x-apievangelist-phrasing: intent: Check my privileges (GET) effect: read questions: - Do I have a specific set of cluster or index privileges? - How can I test whether my account may write to certain indices? instructions: - text: Check whether I have the index privileges {index}. slots: index: requestBody.index - text: Test if my account holds cluster privileges {cluster}. slots: cluster: requestBody.cluster method: generated generated: '2026-09-26' - target: $.paths['/_security/user/_has_privileges'].post update: x-apievangelist-phrasing: intent: Check my privileges via POST effect: read questions: - Is there a POST version of checking which privileges I hold? - Can I verify my application privileges with a POST request? instructions: - text: Using POST, verify my application privileges {application}. slots: application: requestBody.application - text: POST a check of my own cluster rights {cluster}. slots: cluster: requestBody.cluster method: generated generated: '2026-09-26' - target: $.paths['/_security/user/{user}/_has_privileges'].get update: x-apievangelist-phrasing: intent: Check a user's privileges (GET) effect: read questions: - Does a named user have particular index privileges? - How can I check another user's cluster privileges by username? instructions: - text: Check whether user {user} has index privileges {index}. slots: user: path.user index: requestBody.index - text: Test if {user} holds cluster privileges {cluster}. slots: user: path.user cluster: requestBody.cluster method: generated generated: '2026-09-26' - target: $.paths['/_security/user/{user}/_has_privileges'].post update: x-apievangelist-phrasing: intent: Check a user's privileges via POST effect: read questions: - Is there a POST call for testing a named user's privileges? - Can I POST to see if a specific user has certain application privileges? instructions: - text: Using POST, verify user {user} has application privileges {application}. slots: user: path.user application: requestBody.application - text: POST a privilege check for {user} on indices {index}. slots: user: path.user index: requestBody.index method: generated generated: '2026-09-26' - target: $.paths['/_security/profile/_has_privileges'].get update: x-apievangelist-phrasing: intent: Check privileges for user profiles (GET) effect: read questions: - Do the users behind a set of profile IDs have the privileges I need? - How can Kibana check privileges for many user profiles at once? instructions: - text: Check whether profiles {uids} have privileges {privileges}. slots: uids: requestBody.uids privileges: requestBody.privileges - text: Test privileges {privileges} for the users of profile IDs {uids}. slots: uids: requestBody.uids privileges: requestBody.privileges method: generated generated: '2026-09-26' - target: $.paths['/_security/profile/_has_privileges'].post update: x-apievangelist-phrasing: intent: Check privileges for user profiles via POST effect: read questions: - Is there a POST request for checking privileges by profile UID? - Can I POST a list of profile UIDs to see which lack a privilege? instructions: - text: Using POST, see which of profiles {uids} hold {privileges}. slots: uids: requestBody.uids privileges: requestBody.privileges - text: POST a profile privilege check of {privileges} across {uids}. slots: uids: requestBody.uids privileges: requestBody.privileges method: generated generated: '2026-09-26' - target: $.paths['/_security/oidc/authenticate'].post update: x-apievangelist-phrasing: intent: Complete OpenID Connect authentication effect: write questions: - How do I exchange an OpenID Connect authentication response for Elasticsearch tokens? - What state and nonce values must I send back after the OIDC redirect? instructions: - text: Authenticate the OIDC response at {redirect_uri} with state {state} and nonce {nonce}. slots: redirect_uri: requestBody.redirect_uri state: requestBody.state nonce: requestBody.nonce - text: Exchange OIDC redirect {redirect_uri} for tokens in realm {realm}, state {state}, nonce {nonce}. slots: redirect_uri: requestBody.redirect_uri realm: requestBody.realm state: requestBody.state nonce: requestBody.nonce method: generated generated: '2026-09-26' - target: $.paths['/_security/oidc/logout'].post update: x-apievangelist-phrasing: intent: Log out of OpenID Connect effect: destructive questions: - How do I log a user out of an OpenID Connect session in Elasticsearch? - Does OIDC logout invalidate the refresh token as well? instructions: - text: Log out of OIDC and invalidate access token {token}. slots: token: requestBody.token - text: End the OpenID Connect session for {token} and refresh token {refresh_token}. slots: token: requestBody.token refresh_token: requestBody.refresh_token method: generated generated: '2026-09-26' - target: $.paths['/_security/oidc/prepare'].post update: x-apievangelist-phrasing: intent: Prepare an OpenID Connect login request effect: read questions: - How do I build the OpenID Connect authentication URL to redirect a user to? - Can I pass a login hint when starting an OIDC login? instructions: - text: Prepare an OIDC authentication request for realm {realm}. slots: realm: requestBody.realm - text: Build the OIDC login URL for issuer {iss} with login hint {login_hint}. slots: iss: requestBody.iss login_hint: requestBody.login_hint method: generated generated: '2026-09-26' - target: $.paths['/_security/_query/api_key'].get update: x-apievangelist-phrasing: intent: Search API keys with a query (GET) effect: read questions: - How can I find API keys matching a query, such as those expiring soon? - Can I paginate and sort through API keys? instructions: - text: Find API keys matching {query}. slots: query: requestBody.query - text: Search API keys sorted by {sort}, returning {size} results. slots: sort: requestBody.sort size: requestBody.size method: generated generated: '2026-09-26' - target: $.paths['/_security/_query/api_key'].post update: x-apievangelist-phrasing: intent: Search API keys with a query via POST effect: read questions: - Is there a POST endpoint for querying API keys with aggregations? - Can I aggregate API keys by owner or status? instructions: - text: Using POST, query API keys with aggregations {aggregations}. slots: aggregations: requestBody.aggregations - text: POST an API key search for {query} starting at offset {from}. slots: query: requestBody.query from: requestBody.from method: generated generated: '2026-09-26' - target: $.paths['/_security/_query/role'].get update: x-apievangelist-phrasing: intent: Search roles with a query (GET) effect: read questions: - How can I find native roles whose description or name matches a query? - Can I page through roles in sorted order? instructions: - text: Find roles matching {query}. slots: query: requestBody.query - text: Page through roles sorted by {sort}, {size} at a time. slots: sort: requestBody.sort size: requestBody.size method: generated generated: '2026-09-26' - target: $.paths['/_security/_query/role'].post update: x-apievangelist-phrasing: intent: Search roles with a query via POST effect: read questions: - Is there a POST call for querying Elasticsearch native roles? - Can I continue a role search after a given sort value? instructions: - text: Using POST, query native roles for {query}. slots: query: requestBody.query - text: POST a role search continuing after {search_after}. slots: search_after: requestBody.search_after method: generated generated: '2026-09-26' - target: $.paths['/_security/_query/user'].get update: x-apievangelist-phrasing: intent: Search users with a query (GET) effect: read questions: - How can I find native users matching a query such as enabled status or role? - Can I page through users in sorted order? instructions: - text: Find users matching {query}. slots: query: requestBody.query - text: Page through users sorted by {sort}, {size} per page. slots: sort: requestBody.sort size: requestBody.size method: generated generated: '2026-09-26' - target: $.paths['/_security/_query/user'].post update: x-apievangelist-phrasing: intent: Search users with a query via POST effect: read questions: - Is there a POST endpoint for querying native realm users? - Can I include profile UIDs when searching users? instructions: - text: Using POST, query native users for {query}. slots: query: requestBody.query - text: POST a user search including profile uid {with_profile_uid}. slots: with_profile_uid: query.with_profile_uid method: generated generated: '2026-09-26' - target: $.paths['/_security/saml/authenticate'].post update: x-apievangelist-phrasing: intent: Submit a SAML response to log in effect: write questions: - How does a custom web app exchange a SAML response for Elasticsearch tokens? - Which request IDs must accompany a SAML response? instructions: - text: Authenticate SAML response {content} for request IDs {ids}. slots: content: requestBody.content ids: requestBody.ids - text: Consume SAML response {content} in realm {realm} matching {ids}. slots: content: requestBody.content realm: requestBody.realm ids: requestBody.ids method: generated generated: '2026-09-26' - target: $.paths['/_security/saml/complete_logout'].post update: x-apievangelist-phrasing: intent: Verify a SAML logout response effect: write questions: - How do I finish a SAML logout by verifying the IdP's logout response? - Can the logout response be passed as a query string? instructions: - text: Complete SAML logout in realm {realm} for request IDs {ids}. slots: realm: requestBody.realm ids: requestBody.ids - text: Verify the IdP logout query string {query_string} for realm {realm} and IDs {ids}. slots: query_string: requestBody.query_string realm: requestBody.realm ids: requestBody.ids method: generated generated: '2026-09-26' - target: $.paths['/_security/saml/invalidate'].post update: x-apievangelist-phrasing: intent: Process an IdP-initiated SAML logout effect: destructive questions: - How do I handle a SAML LogoutRequest sent by the identity provider? - What does Elasticsearch return after consuming an IdP logout request? instructions: - text: Invalidate SAML sessions from logout request query {query_string}. slots: query_string: requestBody.query_string - text: Consume IdP LogoutRequest {query_string} for realm {realm}. slots: query_string: requestBody.query_string realm: requestBody.realm method: generated generated: '2026-09-26' - target: $.paths['/_security/saml/logout'].post update: x-apievangelist-phrasing: intent: Log out of a SAML session effect: destructive questions: - How do I log a user out of SAML and invalidate their Elasticsearch tokens? - Will a SAML logout give me a redirect URL for the IdP? instructions: - text: Log out of SAML and invalidate token {token}. slots: token: requestBody.token - text: End the SAML session for {token} with refresh token {refresh_token}. slots: token: requestBody.token refresh_token: requestBody.refresh_token method: generated generated: '2026-09-26' - target: $.paths['/_security/saml/prepare'].post update: x-apievangelist-phrasing: intent: Prepare a SAML authentication request effect: read questions: - How do I generate the SAML AuthnRequest URL to redirect a user to the IdP? - Can I attach a relay state to a SAML login? instructions: - text: Prepare a SAML authentication request for realm {realm}. slots: realm: requestBody.realm - text: Build the SAML AuthnRequest URL for ACS {acs} with relay state {relay_state}. slots: acs: requestBody.acs relay_state: requestBody.relay_state method: generated generated: '2026-09-26' - target: $.paths['/_security/saml/metadata/{realm_name}'].get update: x-apievangelist-phrasing: intent: Generate SAML service provider metadata effect: read questions: - How do I get the SAML metadata XML to give my identity provider? - Can I generate SP metadata for one SAML realm? instructions: - text: Generate SAML service provider metadata for realm {realm_name}. slots: realm_name: path.realm_name - text: Get the SP metadata XML of SAML realm {realm_name}. slots: realm_name: path.realm_name method: generated generated: '2026-09-26' - target: $.paths['/_security/profile/_suggest'].get update: x-apievangelist-phrasing: intent: Suggest user profiles (GET) effect: read questions: - How can I find user profiles whose names match what someone is typing? - Can profile suggestions favour certain users with a hint? instructions: - text: Suggest user profiles matching {name}. slots: name: requestBody.name - text: Return {size} profile suggestions for the name {name}. slots: name: requestBody.name size: requestBody.size method: generated generated: '2026-09-26' - target: $.paths['/_security/profile/_suggest'].post update: x-apievangelist-phrasing: intent: Suggest user profiles via POST effect: read questions: - Is there a POST request for profile autocomplete suggestions? - Can I POST a hint to boost particular profile UIDs in suggestions? instructions: - text: Using POST, suggest profiles for {name} boosted by hint {hint}. slots: name: requestBody.name hint: requestBody.hint - text: POST a profile autocomplete query for {name}. slots: name: requestBody.name method: generated generated: '2026-09-26' - target: $.paths['/_security/api_key/{id}'].put update: x-apievangelist-phrasing: intent: Update an API key effect: write questions: - How do I change the permissions or expiration of one existing API key? - Can I update the metadata on an API key I created? instructions: - text: Update API key {id} with role descriptors {role_descriptors}. slots: id: path.id role_descriptors: requestBody.role_descriptors - text: Set expiration {expiration} on API key {id}. slots: id: path.id expiration: requestBody.expiration method: generated generated: '2026-09-26' - target: $.paths['/_security/cross_cluster/api_key/{id}'].put update: x-apievangelist-phrasing: intent: Update a cross-cluster API key effect: write questions: - How do I change the remote access granted by a cross-cluster API key? - Can I extend the expiration of a cross-cluster key? instructions: - text: Update cross-cluster API key {id} with access {access}. slots: id: path.id access: requestBody.access - text: Change cross-cluster key {id} to access {access} and expire in {expiration}. slots: id: path.id access: requestBody.access expiration: requestBody.expiration method: generated generated: '2026-09-26' - target: $.paths['/_security/profile/{uid}/_data'].put update: x-apievangelist-phrasing: intent: Update user profile data (PUT) effect: write questions: - How do I store application data or labels on a user profile? - Can I guard a profile update with sequence number concurrency control? instructions: - text: Update profile {uid} with data {data}. slots: uid: path.uid data: requestBody.data - text: Set labels {labels} on user profile {uid}. slots: uid: path.uid labels: requestBody.labels method: generated generated: '2026-09-26' - target: $.paths['/_security/profile/{uid}/_data'].post update: x-apievangelist-phrasing: intent: Update user profile data via POST effect: write questions: - Is there a POST request for writing labels onto a Kibana profile? - Can I POST profile data only if the sequence number still matches? instructions: - text: Using POST, write data {data} to profile {uid} if seq_no is {if_seq_no}. slots: uid: path.uid data: requestBody.data if_seq_no: query.if_seq_no - text: POST new labels {labels} for Kibana profile {uid}. slots: uid: path.uid labels: requestBody.labels method: generated generated: '2026-09-26' - target: $.paths['/_ssl/certificates'].get update: x-apievangelist-phrasing: intent: Get SSL certificate information effect: read questions: - Which X.509 certificates is my cluster using to encrypt communications? - When do the SSL certificates on my Elasticsearch nodes expire? instructions: - text: Show the SSL certificates used by the cluster. - text: List TLS certificates on this node with their expiry dates. method: generated generated: '2026-09-26' - target: $.paths['/api/security/role/_query'].post update: x-apievangelist-phrasing: intent: Query Kibana roles effect: read questions: - How do I search Kibana roles with filters, paging and sorting? - Can I find Kibana roles matching a text query? instructions: - text: Query Kibana roles for {query}. slots: query: requestBody.query - text: List Kibana roles matching filters {filters}, {size} per page. slots: filters: requestBody.filters size: requestBody.size method: generated generated: '2026-09-26'