# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Identity Services Authentication Profiles API version: 1.0.0 extends: openapi/palo-alto-networks-authentication-profiles-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 10 - target: $.paths['/authentication-profiles'].get update: x-apievangelist-phrasing: intent: List authentication profiles effect: read questions: - Which authentication profiles are configured in a folder? - Can I look up an authentication profile by name? instructions: - text: List authentication profiles in folder {folder}. slots: folder: query.folder - text: Find the authentication profile named {name}. slots: name: query.name method: generated generated: '2026-09-26' - target: $.paths['/authentication-profiles'].post update: x-apievangelist-phrasing: intent: Create an authentication profile effect: write questions: - How do I create an authentication profile with multi-factor authentication? - Can I set account lockout rules when creating an authentication profile? instructions: - text: Create authentication profile {name} using method {method}. slots: name: requestBody.name method: requestBody.method - text: Create authentication profile {name} with MFA settings {multi_factor_auth}. slots: name: requestBody.name multi_factor_auth: requestBody.multi_factor_auth method: generated generated: '2026-09-26' - target: $.paths['/authentication-profiles/{id}'].get update: x-apievangelist-phrasing: intent: Get an authentication profile effect: read questions: - What method and lockout settings does one authentication profile use? - Can I fetch a single authentication profile by id? instructions: - text: Show authentication profile {id}. slots: id: path.id - text: Get the settings of authentication profile {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/authentication-profiles/{id}'].put update: x-apievangelist-phrasing: intent: Update an authentication profile effect: write questions: - How do I change the allow list on an existing authentication profile? - Can I turn on single sign-on for an authentication profile I already have? instructions: - text: Update authentication profile {id} named {name} with allow list {allow_list}. slots: id: path.id name: requestBody.name allow_list: requestBody.allow_list - text: Change the lockout policy of existing profile {id} ({name}) to {lockout}. slots: id: path.id name: requestBody.name lockout: requestBody.lockout method: generated generated: '2026-09-26' - target: $.paths['/authentication-profiles/{id}'].delete update: x-apievangelist-phrasing: intent: Delete an authentication profile effect: destructive questions: - How do I remove an authentication profile? - Can I delete an authentication profile that is no longer referenced? instructions: - text: Delete authentication profile {id}. slots: id: path.id - text: Remove the unused authentication profile {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/authentication-profiles'].get update: x-apievangelist-phrasing: intent: List authentication profiles effect: read questions: - Which authentication profiles exist in a Prisma Access folder? - Can I find an authentication profile by name? instructions: - text: List the SSE config authentication profiles in folder {folder}. slots: folder: query.folder - text: Find the authentication profile named {name} in folder {folder}. slots: name: query.name folder: query.folder method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/authentication-profiles'].post update: x-apievangelist-phrasing: intent: Create an authentication profile effect: write questions: - How do I create an authentication profile with MFA and lockout settings? - Can a new authentication profile use single sign-on? instructions: - text: Create authentication profile {name} in folder {folder}. slots: name: requestBody.name folder: query.folder - text: Create authentication profile {name} in {folder} using method {method} and user domain {user_domain}. slots: name: requestBody.name folder: query.folder method: requestBody.method user_domain: requestBody.user_domain method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/authentication-profiles/{id}'].get update: x-apievangelist-phrasing: intent: Get an authentication profile effect: read questions: - What method and allow list does a specific authentication profile use? - Can I pull one authentication profile by its ID? instructions: - text: Fetch SSE config authentication profile {id}. slots: id: path.id - text: Show the SSE v1 settings of authentication profile {id}. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/authentication-profiles/{id}'].put update: x-apievangelist-phrasing: intent: Edit an authentication profile effect: write questions: - Can I change the lockout policy on an existing authentication profile? - Is it possible to add multi-factor authentication to a profile I already have? instructions: - text: Rename authentication profile {id} to {name}. slots: id: path.id name: requestBody.name - text: Set the allow list on authentication profile {id} to {allow_list}. slots: id: path.id allow_list: requestBody.allow_list method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/authentication-profiles/{id}'].delete update: x-apievangelist-phrasing: intent: Delete an authentication profile effect: destructive questions: - How do I delete an authentication profile I no longer use? - What happens if I remove an authentication profile? instructions: - text: Delete SSE config authentication profile {id}. slots: id: path.id - text: Remove authentication profile {id} using the SSE v1 API. slots: id: path.id method: generated generated: '2026-10-01'