# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Identity Services Authentication Rules API version: 1.0.0 extends: openapi/palo-alto-networks-authentication-rules-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 11 - target: $.paths['/authentication-rules'].get update: x-apievangelist-phrasing: intent: List authentication rules effect: read questions: - Which authentication rules are in my pre or post rulebase? - Can I find an authentication rule by name within a folder? instructions: - text: List the authentication rules at position {position}. slots: position: query.position - text: Find authentication rules named {name} in folder {folder} at position {position}. slots: name: query.name folder: query.folder position: query.position method: generated generated: '2026-09-26' - target: $.paths['/authentication-rules'].post update: x-apievangelist-phrasing: intent: Create an authentication rule effect: write questions: - How do I require users to authenticate before reaching a service? - Can I set a timeout on a new authentication rule? instructions: - text: Create authentication rule {name} at position {position} from zone {from} to zone {to}. slots: name: requestBody.name position: query.position from: requestBody.from to: requestBody.to - text: Add an authentication rule {name} for sources {source} to destinations {destination} on service {service} at {position}. slots: name: requestBody.name source: requestBody.source destination: requestBody.destination service: requestBody.service position: query.position method: generated generated: '2026-09-26' - target: $.paths['/authentication-rules/{id}'].get update: x-apievangelist-phrasing: intent: Get an authentication rule effect: read questions: - What sources, destinations and enforcement does a specific authentication rule use? - Can I read one authentication rule by its ID? instructions: - text: Get authentication rule {id}. slots: id: path.id - text: Show the details of authentication rule {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/authentication-rules/{id}'].put update: x-apievangelist-phrasing: intent: Update an authentication rule effect: write questions: - How do I change the destinations covered by an existing authentication rule? - Can I disable an authentication rule without deleting it? instructions: - text: Update authentication rule {id} to cover destinations {destination}. slots: id: path.id destination: requestBody.destination - text: Set the disabled flag on authentication rule {id} to {disabled}. slots: id: path.id disabled: requestBody.disabled method: generated generated: '2026-09-26' - target: $.paths['/authentication-rules/{id}'].delete update: x-apievangelist-phrasing: intent: Delete an authentication rule effect: destructive questions: - How do I remove an authentication rule I no longer need? - Is deleting an authentication rule permanent? instructions: - text: Delete authentication rule {id}. slots: id: path.id - text: Remove authentication rule {id} from the rulebase. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/authentication-rules/{id}:move'].post update: x-apievangelist-phrasing: intent: Reorder an authentication rule effect: write questions: - How do I move an authentication rule to the top of the rulebase? - Can I place one authentication rule directly before another? instructions: - text: Move authentication rule {id} to {destination} of the {rulebase} rulebase. slots: id: path.id destination: requestBody.destination rulebase: requestBody.rulebase - text: Place authentication rule {id} {destination} rule {destination_rule} in the {rulebase} rulebase. slots: id: path.id destination: requestBody.destination destination_rule: requestBody.destination_rule rulebase: requestBody.rulebase method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/authentication-rules'].get update: x-apievangelist-phrasing: intent: List authentication rules effect: read questions: - Which authentication policy rules are set in a folder? - Can I find an authentication rule by name in the post rulebase? instructions: - text: List {position} authentication rules in folder {folder}. slots: position: query.position folder: query.folder - text: Find authentication rule {name} in folder {folder} at {position}. slots: name: query.name folder: query.folder position: query.position method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/authentication-rules'].post update: x-apievangelist-phrasing: intent: Create an authentication rule effect: write questions: - Can I require users to authenticate before reaching certain destinations? - Can I create an authentication rule in a folder with a custom timeout? instructions: - text: Create authentication rule {name} with enforcement {authentication_enforcement} in folder {folder} at {position}. slots: name: requestBody.name authentication_enforcement: requestBody.authentication_enforcement folder: query.folder position: query.position - text: Add an auth rule {name} for users {source_user} to {destination} with timeout {timeout} in {folder} ({position}). slots: name: requestBody.name source_user: requestBody.source_user destination: requestBody.destination timeout: requestBody.timeout folder: query.folder position: query.position method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/authentication-rules/{id}'].put update: x-apievangelist-phrasing: intent: Edit an authentication rule effect: write questions: - Can I change the enforcement profile on an existing authentication rule? - How do I disable an authentication rule temporarily? instructions: - text: Update authentication rule {id} to use enforcement {authentication_enforcement}. slots: id: path.id authentication_enforcement: requestBody.authentication_enforcement - text: Set disabled to {disabled} on authentication rule {id}. slots: disabled: requestBody.disabled id: path.id method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/authentication-rules/{id}'].delete update: x-apievangelist-phrasing: intent: Delete an authentication rule effect: destructive questions: - What's the way to remove an authentication rule from policy? - Can I delete an authentication rule by ID? instructions: - text: Delete authentication rule {id} using the SSE config v1 endpoint. slots: id: path.id - text: Remove the authentication policy rule {id}. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/authentication-rules/{id}:move'].post update: x-apievangelist-phrasing: intent: Reorder an authentication rule effect: write questions: - Can I move an authentication rule to the bottom of its rulebase? - How do I put an authentication rule after a specific other rule? instructions: - text: Move authentication rule {id} to the {destination} of {rulebase} in folder {folder}. slots: id: path.id destination: requestBody.destination rulebase: requestBody.rulebase folder: query.folder - text: Place auth rule {id} {destination} rule {destination_rule} in the {rulebase} rulebase of {folder}. slots: id: path.id destination: requestBody.destination destination_rule: requestBody.destination_rule rulebase: requestBody.rulebase folder: query.folder method: generated generated: '2026-10-01'