# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Authentication Service Auth Service API version: 1.0.0 extends: openapi/palo-alto-networks-auth-service-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 3 - target: $.paths['/auth/v1/oauth2/access_token'].post update: x-apievangelist-phrasing: intent: Get a SASE access token effect: write questions: - How do I get an access token for the SASE APIs with my client ID and secret? - Which tenant service group should my token be scoped to? instructions: - text: Create an access token scoped to {scope}. slots: scope: requestBody.scope - text: Request a client credentials token with grant type {grant_type} for TSG scope {scope}. slots: grant_type: requestBody.grant_type scope: requestBody.scope method: generated generated: '2026-10-01' - target: $.paths['/auth/v1/oauth2/userinfo'].get update: x-apievangelist-phrasing: intent: Get claims for my current token effect: read questions: - Who does the token I'm calling with belong to? - What OAuth 2.0 claims come with my current bearer token? instructions: - text: Show the OAuth claims for the token I'm authenticated with. - text: Tell me which user my current access token was issued to. method: generated generated: '2026-10-01' - target: $.paths['/auth/v1/oauth2/userinfo'].post update: x-apievangelist-phrasing: intent: Get claims for a supplied access token effect: read questions: - Can I inspect the claims of a token other than the one I'm calling with? - How do I find out who a given access token was issued to? instructions: - text: Get the OAuth claims for access token {access_token}. slots: access_token: requestBody.access_token - text: Look up which user token {access_token} belongs to. slots: access_token: requestBody.access_token method: generated generated: '2026-10-01'