# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Harness Oidc Access Token API version: 1.0.0 extends: openapi/harness-oidc-access-token-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 4 - target: $.paths['/ng/api/oidc/access-token/aws/webidentity-session-access'].post update: x-apievangelist-phrasing: intent: Exchange an OIDC token for AWS IAM role credentials effect: write questions: - Can I get temporary AWS credentials for an IAM role using an OIDC token? - What does it take to assume an AWS role with web identity from a pipeline? instructions: - text: Get AWS credentials for IAM role {role_arn} using OIDC token {token}. slots: role_arn: requestBody.iamRoleArn token: requestBody.oidcIdToken - text: Assume AWS role {role_arn} through web identity federation. slots: role_arn: requestBody.iamRoleArn method: generated generated: '2026-09-26' - target: $.paths['/ng/api/oidc/access-token/gcp/service-account-access'].post update: x-apievangelist-phrasing: intent: Get a GCP service account token via OIDC effect: write questions: - Can I impersonate a GCP service account using an OIDC ID token? - How is a Google Cloud service account access token generated without keys? instructions: - text: Generate a GCP service account access token from OIDC token {token} with request {request}. slots: token: requestBody.oidcIdToken request: requestBody.gcpOidcTokenRequestDTO - text: Get a keyless GCP service account token for request {request} using ID token {token}. slots: request: requestBody.gcpOidcTokenRequestDTO token: requestBody.oidcIdToken method: generated generated: '2026-09-26' - target: $.paths['/ng/api/oidc/access-token/azure'].post update: x-apievangelist-phrasing: intent: Exchange an OIDC token for Azure credentials effect: write questions: - Can I get Azure credentials from an OIDC token without a client secret? - What tenant and client IDs are needed for Azure workload identity federation? instructions: - text: Exchange an OIDC token for Azure credentials in tenant {tenant_id} for app {client_id} with request {request}. slots: tenant_id: requestBody.tenantId client_id: requestBody.clientId request: requestBody.azureOidcTokenRequestDTO - text: Get an Azure access token for resource {resource}, tenant {tenant_id}, client {client_id}, request {request}. slots: resource: requestBody.resource tenant_id: requestBody.tenantId client_id: requestBody.clientId request: requestBody.azureOidcTokenRequestDTO method: generated generated: '2026-09-26' - target: $.paths['/ng/api/oidc/access-token/gcp/workload-access'].post update: x-apievangelist-phrasing: intent: Get a GCP workload identity access token effect: write questions: - Can I get a GCP workload identity federation token from an OIDC ID token? - Which call returns a federated workload access token for Google Cloud? instructions: - text: Generate a GCP workload identity token from OIDC token {token} with request {request}. slots: token: requestBody.oidcIdToken request: requestBody.gcpOidcTokenRequestDTO - text: Exchange ID token {token} for a federated workload access token using {request}. slots: token: requestBody.oidcIdToken request: requestBody.gcpOidcTokenRequestDTO method: generated generated: '2026-09-26'