# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks Applications API version: 1.0.0 extends: openapi/palo-alto-networks-applications-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 48 - target: $.paths['/seb-api/v1/applications'].get update: x-apievangelist-phrasing: intent: List all secure browser applications effect: read questions: - Can I see every application defined in the Secure Enterprise Browser console across all types? - Is it possible to search secure browser applications by name or URL and page through them? instructions: - text: List all secure browser applications whose URL contains {url}. slots: url: query.url - text: Show secure browser applications of every type named like {name}, sorted by {sort}. slots: name: query.name sort: query.sort method: generated generated: '2026-09-26' - target: $.paths['/seb-api/v1/applications/{id}'].get update: x-apievangelist-phrasing: intent: Get a secure browser application by ID effect: read questions: - What is configured on a single secure browser application when I only know its ID? - Can I view the draft rather than the active version of a secure browser application? instructions: - text: Fetch secure browser application {id} without specifying its type. slots: id: path.id - text: Get the {configurationVersion} configuration of secure browser application {id}. slots: configurationVersion: query.configurationVersion id: path.id method: generated generated: '2026-09-26' - target: $.paths['/seb-api/v1/applications/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a secure browser application by ID effect: destructive questions: - Can I permanently remove one secure browser application using just its ID? - Is deleting a secure browser application by ID reversible? instructions: - text: Permanently delete secure browser application {id} by its ID alone. slots: id: path.id - text: Remove the secure browser app with ID {id}, no type needed. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/seb-api/v1/applications/type/{type}'].get update: x-apievangelist-phrasing: intent: List secure browser applications of one type effect: read questions: - Which secure browser applications exist of a particular type, like private or non-web apps? - Can I filter the applications of a single type by name? instructions: - text: List all secure browser applications of type {type}. slots: type: path.type - text: Find {type} applications in the secure browser named {name}. slots: type: path.type name: query.name method: generated generated: '2026-09-26' - target: $.paths['/seb-api/v1/applications/type/{type}'].post update: x-apievangelist-phrasing: intent: Create a secure browser application effect: write questions: - How do I add a single new custom application to the Secure Enterprise Browser console? - Is there a limit on how many URLs custom, private and non-web apps can hold combined? instructions: - text: Create one new secure browser application of type {type}. slots: type: path.type - text: Add a single {type} app to the secure browser management console. slots: type: path.type method: generated generated: '2026-09-26' - target: $.paths['/seb-api/v1/applications/type/{type}/{id}'].get update: x-apievangelist-phrasing: intent: Get a secure browser application within a type effect: read questions: - Can I fetch a secure browser application by ID scoped to its type? - What does the active configuration of a specific private app look like? instructions: - text: Get the {type} secure browser application {id}. slots: type: path.type id: path.id - text: Show the {configurationVersion} version of {type} app {id}. slots: configurationVersion: query.configurationVersion type: path.type id: path.id method: generated generated: '2026-09-26' - target: $.paths['/seb-api/v1/applications/type/{type}/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a secure browser application of a type effect: destructive questions: - Can I remove a secure browser app when I know both its type and ID? - What happens when I delete a non-web application from the secure browser? instructions: - text: Delete the {type} secure browser application {id}. slots: type: path.type id: path.id - text: Remove {type} app {id} from the secure browser console. slots: type: path.type id: path.id method: generated generated: '2026-09-26' - target: $.paths['/seb-api/v1/applications/type/{type}/{id}'].patch update: x-apievangelist-phrasing: intent: Partially update a secure browser application effect: write questions: - Can I change a few attributes of a secure browser application and leave the rest untouched? - Does editing a secure browser app's URLs count toward the 15,000-URL tenant limit? instructions: - text: Patch the {type} secure browser application {id} with only the changed attributes. slots: type: path.type id: path.id - text: Update secure browser app {id} of type {type}. slots: id: path.id type: path.type method: generated generated: '2026-09-26' - target: $.paths['/seb-api/v1/applications/categories'].get update: x-apievangelist-phrasing: intent: List secure browser application categories effect: read questions: - What application categories are available in the Secure Enterprise Browser? - Which categories can I assign to a secure browser app? instructions: - text: List the secure browser application categories. - text: Show me every category available for browser applications. method: generated generated: '2026-09-26' - target: $.paths['/seb-api/v1/applications/bulk-create/{type}'].post update: x-apievangelist-phrasing: intent: Bulk create secure browser applications effect: write questions: - Can I add many secure browser applications of one type in a single request? - Is there a faster way to load dozens of private apps into the secure browser at once? instructions: - text: Bulk create several {type} applications in the secure browser. slots: type: path.type - text: Import a batch of {type} apps into the secure browser console in one call. slots: type: path.type method: generated generated: '2026-09-26' - target: $.paths['/seb-api/v1/applications/bulk-delete'].post update: x-apievangelist-phrasing: intent: Bulk delete secure browser applications effect: destructive questions: - Can I delete many secure browser applications at once in a single atomic operation? - If one ID in a bulk delete fails, are the other apps still removed? instructions: - text: Bulk delete the secure browser applications {appIds}. slots: appIds: requestBody.appIds - text: 'Permanently remove all of these browser app IDs at once: {appIds}.' slots: appIds: requestBody.appIds method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/applications'].get update: x-apievangelist-phrasing: intent: List Prisma Access application objects in a folder effect: read questions: - Which custom application objects are defined in a Prisma Access config folder? - Can I page through Prisma Access application objects with limit and offset? instructions: - text: List Prisma Access application objects in folder {folder}. slots: folder: query.folder - text: Find the Prisma Access application named {name} in folder {folder}. slots: name: query.name folder: query.folder method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/applications'].post update: x-apievangelist-phrasing: intent: Create a Prisma Access application object effect: write questions: - How do I define a custom App-ID application in a Prisma Access folder with its risk and category? - Can I mark a new Prisma Access application as evasive or used by malware? instructions: - text: Create Prisma Access application {name} in folder {folder} with category {category}, subcategory {subcategory}, technology {technology} and risk {risk}. slots: name: requestBody.name folder: query.folder category: requestBody.category subcategory: requestBody.subcategory technology: requestBody.technology risk: requestBody.risk - text: Add a custom app {name} to Prisma Access folder {folder} with a TCP timeout of {tcp_timeout} seconds. slots: name: requestBody.name folder: query.folder tcp_timeout: requestBody.tcp_timeout method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/applications/{id}'].get update: x-apievangelist-phrasing: intent: Get a Prisma Access application object effect: read questions: - What risk level and characteristics does a given Prisma Access application object have? - Can I look up one Prisma Access App-ID object by its identifier? instructions: - text: Get Prisma Access application object {id}. slots: id: path.id - text: Show the category and risk of Prisma Access app {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/applications/{id}'].put update: x-apievangelist-phrasing: intent: Edit a Prisma Access application object effect: write questions: - Can I change the risk rating of an existing Prisma Access application object? - Is it possible to adjust session timeouts on a custom Prisma Access app? instructions: - text: Edit Prisma Access application {id} and set its risk to {risk}. slots: id: path.id risk: requestBody.risk - text: Change the UDP timeout of Prisma Access app {id} to {udp_timeout} seconds. slots: id: path.id udp_timeout: requestBody.udp_timeout method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/applications/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a Prisma Access application object effect: destructive questions: - Can I remove a custom application object from Prisma Access configuration? - What gets deleted when I drop a Prisma Access App-ID object? instructions: - text: Delete Prisma Access application object {id}. slots: id: path.id - text: Remove the custom Prisma Access app {id} from the config. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/adem/v1/applications'].get update: x-apievangelist-phrasing: intent: List applications monitored by Autonomous DEM effect: read questions: - Which applications is Autonomous DEM probing with synthetic tests? - What synthetic tests are configured for a monitored application? instructions: - text: List the applications configured for monitoring in Autonomous DEM. - text: Show the ADEM synthetic tests for monitored application {app_id}. slots: app_id: query.app_id method: generated generated: '2026-09-26' - target: $.paths['/appid/api/v1/download/app'].post update: x-apievangelist-phrasing: intent: Download the application inventory as CSV effect: read questions: - Can I export the complete Prisma Cloud application inventory to a CSV file? - Is it possible to download only apps with a certain business criticality from the inventory? instructions: - text: Download the application inventory CSV filtered to business owner {businessOwner}. slots: businessOwner: requestBody.businessOwner - text: Export the inventory of {environment} applications as a CSV. slots: environment: requestBody.environment method: generated generated: '2026-09-26' - target: $.paths['/appid/api/v1/app/criteria'].get update: x-apievangelist-phrasing: intent: Download all application discovery criteria effect: read questions: - What discovery criteria group my assets into applications? - Can I include deleted discovery criteria when listing them? instructions: - text: Download all application discovery criteria, predefined and custom. - text: List discovery criteria with deleted ones included set to {fetch_deleted}. slots: fetch_deleted: query.fetch_deleted method: generated generated: '2026-09-26' - target: $.paths['/appid/api/v1/app/criteria'].post update: x-apievangelist-phrasing: intent: Create custom application discovery criteria effect: write questions: - How do I define a custom filter that groups scanned assets into a new application? - Can creating discovery criteria also create the application definition? instructions: - text: Create discovery criteria {name} for application {app} with metadata {metadata}. slots: name: requestBody.name app: requestBody.app metadata: requestBody.metadata - text: Add custom discovery criteria {name} for {app} and set create_definition to {create_definition}. slots: name: requestBody.name app: requestBody.app create_definition: query.create_definition method: generated generated: '2026-09-26' - target: $.paths['/appid/api/v1/app/criteria/{id}'].get update: x-apievangelist-phrasing: intent: Get an application's discovery criteria effect: read questions: - Which discovery criteria were used to find a particular application? - Can I see the asset filter behind one app in the application inventory? instructions: - text: Get the discovery criteria for application {id}. slots: id: path.id - text: Show how application {id} was discovered. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/appid/api/v1/app/criteria/{id}'].delete update: x-apievangelist-phrasing: intent: Delete application discovery criteria effect: destructive questions: - Can I remove a custom discovery criteria that I no longer need? - What permission do I need to delete discovery criteria? instructions: - text: Delete discovery criteria {id}. slots: id: path.id - text: Remove the application discovery rule with criteria ID {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/appid/api/v1/app/criteria/{id}'].patch update: x-apievangelist-phrasing: intent: Update application discovery criteria effect: write questions: - Can I rename or change the filter of an existing discovery criteria? - Is it possible to point existing discovery criteria at a different application? instructions: - text: Update discovery criteria {id} to name {name}, application {app} and metadata {metadata}. slots: id: path.id name: requestBody.name app: requestBody.app metadata: requestBody.metadata - text: Change the metadata filter on discovery criteria {id} to {metadata}. slots: id: path.id metadata: requestBody.metadata method: generated generated: '2026-09-26' - target: $.paths['/appid/api/v1/download/app/{id}'].get update: x-apievangelist-phrasing: intent: Download an application's details as CSV effect: read questions: - Can I export the alerts, vulnerabilities or assets of one application to CSV? - Which file types can I choose when downloading an application's details? instructions: - text: Download the {file_type} details CSV for application {id}. slots: file_type: query.file_type id: path.id - text: Export application {id} details as a {file_type} file. slots: id: path.id file_type: query.file_type method: generated generated: '2026-09-26' - target: $.paths['/appid/api/v1/download/app/config/{id}'].get update: x-apievangelist-phrasing: intent: Download an Application Bill of Materials effect: read questions: - How do I get the Application Bill of Materials for an app? - Can I download an ABOM listing an application's assets and vulnerabilities as CSV? instructions: - text: Download the ABOM for application {id}. slots: id: path.id - text: Get the application bill of materials CSV for app {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/appid/api/v2/app'].post update: x-apievangelist-phrasing: intent: List discovered applications in the inventory effect: read questions: - Which applications has Prisma Cloud discovered in my Application Inventory? - Can I filter discovered applications by owner or business criticality? - How many applications does the inventory list return at most? instructions: - text: List discovered applications owned by {owner}. slots: owner: requestBody.owner - text: Show inventory applications in environment {environment} with criticality {businessCriticality}. slots: environment: requestBody.environment businessCriticality: requestBody.businessCriticality method: generated generated: '2026-09-26' - target: $.paths['/appid/api/v2/app/{id}'].get update: x-apievangelist-phrasing: intent: Get a discovered application's details effect: read questions: - What details does the inventory hold for one discovered application? - Can I look up an Application Inventory entry by its ID? instructions: - text: Get inventory details for discovered application {id}. slots: id: path.id - text: Show the owner and environment of inventory app {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/appid/api/v2/app/{id}/assets'].post update: x-apievangelist-phrasing: intent: List assets that belong to an application effect: read questions: - Which cloud assets are associated with a discovered application? - Can I filter and page through the assets of one application? instructions: - text: List the assets associated with application {id}. slots: id: path.id - text: Get the next page of assets for application {id} using token {nextPageToken}. slots: id: path.id nextPageToken: requestBody.nextPageToken method: generated generated: '2026-09-26' - target: $.paths['/appid/api/v2/app/{id}/vulnerabilities'].post update: x-apievangelist-phrasing: intent: List vulnerabilities in an application effect: read questions: - What vulnerabilities affect a discovered application? - Can I filter an application's vulnerabilities before paging through them? instructions: - text: List the vulnerabilities found in application {id}. slots: id: path.id - text: Show vulnerabilities for application {id} matching {filters}. slots: id: path.id filters: requestBody.filters method: generated generated: '2026-09-26' - target: $.paths['/appid/api/v2/app/{id}/alerts'].post update: x-apievangelist-phrasing: intent: List alerts for an application effect: read questions: - Which security alerts are open against a discovered application? - Can I see the alert details for one app in the inventory? instructions: - text: List the alerts for application {id}. slots: id: path.id - text: Show alerts on application {id} matching {filters}. slots: id: path.id filters: requestBody.filters method: generated generated: '2026-09-26' - target: $.paths['/appid/api/v2/app/summary'].get update: x-apievangelist-phrasing: intent: Get application inventory statistics effect: read questions: - How many applications have been discovered in my environment overall? - What are the total vulnerability counts across all discovered applications? instructions: - text: Get the application summary statistics for my environment. - text: Show how many apps and vulnerabilities the inventory has in total. method: generated generated: '2026-09-26' - target: $.paths['/appid/api/v2/app/{id}/grouped-counts'].post update: x-apievangelist-phrasing: intent: Get an application's risk counts effect: read questions: - What is the grouped risk count for a single application? - Can I get risk counts for one app narrowed by filters? instructions: - text: Get the risk counts for application {id}. slots: id: path.id - text: Show grouped risk counts for application {id} using filters {filters}. slots: id: path.id filters: requestBody.filters method: generated generated: '2026-09-26' - target: $.paths['/appid/api/v2/tags'].get update: x-apievangelist-phrasing: intent: List tags used for application discovery effect: read questions: - Which tags are used to scan and discover applications? - What asset tags drive application discovery in Prisma Cloud? instructions: - text: List the tags used to discover applications. - text: Show me every discovery tag for the application inventory. method: generated generated: '2026-09-26' - target: $.paths['/appid/search/api/v1/app'].post update: x-apievangelist-phrasing: intent: Search applications with an RQL query effect: read questions: - Can I find discovered applications by writing an RQL query against the application inventory? - Which applications match a saved RQL search over a given time range? - Is there a way to run an application search query in Prisma Cloud and get each match's details? instructions: - text: Run the RQL application search {query}. slots: query: query.query - text: Search applications with RQL {query} over time range {timeRange}. slots: query: query.query timeRange: query.timeRange method: generated generated: '2026-10-01' - target: $.paths['/appid/search/api/v1/app/risk'].post update: x-apievangelist-phrasing: intent: Get an application's vulnerabilities and alerts by query effect: read questions: - What vulnerabilities and alerts are tied to the assets behind one application, found through the search API? - Can I pull an application's combined risk findings, vulnerabilities plus alerts, in a single search call? instructions: - text: Search the vulnerabilities and alerts on the assets of application {applicationId}. slots: applicationId: requestBody.applicationId - text: Return combined vulnerability and alert findings for application {applicationId} matching {query}. slots: applicationId: requestBody.applicationId query: requestBody.query method: generated generated: '2026-10-01' - target: $.paths['/appid/search/api/v1/app/service'].post update: x-apievangelist-phrasing: intent: Count assets, vulnerabilities and alerts per service effect: read questions: - How many assets, vulnerabilities and alerts does each service inside an application have? - Can I break an application's risk down service by service? instructions: - text: Show per-service counts of assets, vulnerabilities and alerts for application {applicationId}. slots: applicationId: requestBody.applicationId - text: Break down risk by service for application {applicationId} using search {query}. slots: applicationId: requestBody.applicationId query: requestBody.query method: generated generated: '2026-10-01' - target: $.paths['/appid/app/service/{id}'].get update: x-apievangelist-phrasing: intent: Get an application's assets and services effect: read questions: - Which assets and services make up a given application, along with the alerts on those assets? - Can I see the service map of one application from its ID? instructions: - text: List the assets and services that belong to application {id}. slots: id: path.id - text: Show the services of application {id} with the alerts raised on their assets. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/api/applications'].get update: x-apievangelist-phrasing: intent: List SaaS apps connected to SaaS Security effect: read questions: - Which SaaS applications are connected to my SaaS Security tenant? - How many active incidents and scanned assets does each connected SaaS app have? instructions: - text: List the SaaS applications connected to SaaS Security. - text: Show connection status for each connected SaaS app. method: generated generated: '2026-09-26' - target: $.paths['/v2/applications'].get update: x-apievangelist-phrasing: intent: List ZTNA-protected applications effect: read questions: - Which private applications are protected by ZTNA? - What connector group provides access to each ZTNA application? instructions: - text: List all ZTNA-protected applications. - text: Show the private resources exposed through ZTNA and their connector groups. method: generated generated: '2026-09-26' - target: $.paths['/v2/applications'].post update: x-apievangelist-phrasing: intent: Create a ZTNA application effect: write questions: - How do I publish a private application through ZTNA with a connector group? - Can I enable ZTNA access to a new app immediately on creation? instructions: - text: Create ZTNA application {name} for {fqdn} using connector group {group_id}. slots: name: requestBody.name fqdn: requestBody.fqdn group_id: requestBody.group_id - text: Protect {fqdn} with ZTNA as {name} via group {group_id}, exposing ports {ports}. slots: fqdn: requestBody.fqdn name: requestBody.name group_id: requestBody.group_id ports: requestBody.ports method: generated generated: '2026-09-26' - target: $.paths['/v2/applications/{app_id}'].get update: x-apievangelist-phrasing: intent: Get a ZTNA application effect: read questions: - Which FQDN and ports does a specific ZTNA application expose? - Is ZTNA access enabled for a particular application? instructions: - text: Get ZTNA application {app_id}. slots: app_id: path.app_id - text: Show the ports and protocols of ZTNA app {app_id}. slots: app_id: path.app_id method: generated generated: '2026-09-26' - target: $.paths['/v2/applications/{app_id}'].put update: x-apievangelist-phrasing: intent: Update a ZTNA application effect: write questions: - Can I move a ZTNA application to a different connector group? - Is it possible to change the FQDN a ZTNA application points to? instructions: - text: Update ZTNA application {app_id} to use connector group {group_id}. slots: app_id: path.app_id group_id: requestBody.group_id - text: Point ZTNA app {app_id} named {name} at {fqdn}. slots: app_id: path.app_id name: requestBody.name fqdn: requestBody.fqdn method: generated generated: '2026-09-26' - target: $.paths['/v2/applications/{app_id}'].delete update: x-apievangelist-phrasing: intent: Delete a ZTNA application effect: destructive questions: - Can I stop protecting a private app with ZTNA by deleting its definition? - What happens to user access when a ZTNA application is removed? instructions: - text: Delete ZTNA application {app_id}. slots: app_id: path.app_id - text: Remove the ZTNA definition for app {app_id}. slots: app_id: path.app_id method: generated generated: '2026-09-26' - target: $.paths['/applications'].get update: x-apievangelist-phrasing: intent: List Strata Cloud Manager application objects effect: read questions: - Which application objects are defined in a Strata Cloud Manager folder, snippet or device? - Can I list config application objects scoped to a snippet? instructions: - text: List Strata Cloud Manager applications in snippet {snippet}. slots: snippet: query.snippet - text: Show SCM application objects defined on device {device}. slots: device: query.device method: generated generated: '2026-09-26' - target: $.paths['/applications'].post update: x-apievangelist-phrasing: intent: Create a Strata Cloud Manager application effect: write questions: - How can I add a custom application object to Strata Cloud Manager configuration? - Which fields are required for a new SCM application, like category and risk? instructions: - text: Create Strata Cloud Manager application {name} with category {category} and risk {risk}. slots: name: requestBody.name category: requestBody.category risk: requestBody.risk - text: Add SCM app {name} in category {category}, risk {risk}, with parent app {parent_app}. slots: name: requestBody.name category: requestBody.category risk: requestBody.risk parent_app: requestBody.parent_app method: generated generated: '2026-09-26' - target: $.paths['/applications/{id}'].get update: x-apievangelist-phrasing: intent: Get a Strata Cloud Manager application effect: read questions: - What does an existing Strata Cloud Manager application object contain? - Can I fetch an SCM application object by its UUID? instructions: - text: Get Strata Cloud Manager application {id}. slots: id: path.id - text: Show the SCM application object with UUID {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/applications/{id}'].put update: x-apievangelist-phrasing: intent: Update a Strata Cloud Manager application effect: write questions: - Can I recategorize an existing Strata Cloud Manager application object? - Is it possible to flag an SCM application as prone to misuse after creating it? instructions: - text: Update Strata Cloud Manager application {id} with name {name}, category {category} and risk {risk}. slots: id: path.id name: requestBody.name category: requestBody.category risk: requestBody.risk - text: Change the description of SCM application {id} named {name} to {description}. slots: id: path.id name: requestBody.name description: requestBody.description method: generated generated: '2026-09-26' - target: $.paths['/applications/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a Strata Cloud Manager application effect: destructive questions: - Can I delete a custom application object from Strata Cloud Manager? - What happens to an SCM application once I delete it by UUID? instructions: - text: Delete Strata Cloud Manager application {id}. slots: id: path.id - text: Remove SCM application object {id}. slots: id: path.id method: generated generated: '2026-09-26'