# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Harness Oidc ID Token API version: 1.0.0 extends: openapi/harness-oidc-id-token-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 5 - target: $.paths['/ng/api/oidc/id-token/azure'].post update: x-apievangelist-phrasing: intent: Generate an OIDC ID token for Azure effect: write questions: - Can Harness issue an OIDC token so I can authenticate to Azure without a stored client secret? - What Azure details go into a Harness-issued OIDC ID token? instructions: - text: Generate an Azure OIDC ID token for account {account} and tenant {tenant}. slots: account: requestBody.accountId tenant: requestBody.tenantId - text: Issue an Azure ID token for client {client} with audience {audience}. slots: client: requestBody.clientId audience: requestBody.audience method: generated generated: '2026-09-26' - target: $.paths['/ng/api/oidc/id-token/gcp'].post update: x-apievangelist-phrasing: intent: Generate an OIDC ID token for GCP (v1) effect: write questions: - How do I get a Harness OIDC token for GCP workload identity federation? - Which workload pool and provider IDs does the original GCP token endpoint need? instructions: - text: Generate a GCP OIDC token for project {gcpProject} using workload pool {pool} and provider {provider}. slots: gcpProject: requestBody.gcpProjectId pool: requestBody.workloadPoolId provider: requestBody.providerId - text: Use the original GCP endpoint to issue an ID token for account {account}. slots: account: requestBody.accountId method: generated generated: '2026-09-26' - target: $.paths['/ng/api/oidc/id-token/gcp-v2'].post update: x-apievangelist-phrasing: intent: Generate an OIDC ID token for GCP (v2) effect: write questions: - Is there a v2 endpoint for generating GCP OIDC ID tokens? - Can the newer GCP token endpoint impersonate a service account email? instructions: - text: Generate a GCP v2 OIDC token for project {gcpProject}, pool {pool}, provider {provider}. slots: gcpProject: requestBody.gcpProjectId pool: requestBody.workloadPoolId provider: requestBody.providerId - text: Issue a v2 GCP ID token for service account {email}. slots: email: requestBody.serviceAccountEmail method: generated generated: '2026-09-26' - target: $.paths['/ng/api/oidc/id-token/custom'].post update: x-apievangelist-phrasing: intent: Generate a custom OIDC ID token effect: write questions: - Can I mint an OIDC ID token with my own audience and subject for any relying party? - What custom attributes can I put into a Harness OIDC token? instructions: - text: Generate a custom OIDC ID token with audience {aud}. slots: aud: requestBody.aud - text: Mint a custom ID token for subject {sub} and audience {aud}. slots: sub: requestBody.sub aud: requestBody.aud method: generated generated: '2026-09-26' - target: $.paths['/ng/api/oidc/id-token/aws'].post update: x-apievangelist-phrasing: intent: Generate an OIDC ID token for AWS effect: write questions: - How do I get a Harness OIDC token to assume an AWS role without long-lived keys? - Can I add session tag keys to the AWS OIDC token? instructions: - text: Generate an AWS OIDC ID token for region {region}. slots: region: requestBody.region - text: Issue an AWS ID token with session tag keys {tags}. slots: tags: requestBody.oidcSessionTagKeys method: generated generated: '2026-09-26'