# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for TLS Protect Cloud API for Strata Cloud Manager Credential… version: 1.0.0 extends: openapi/palo-alto-networks-credential-management-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 14 - target: $.paths['/v1/credentialmanagerconfigurations'].get update: x-apievangelist-phrasing: intent: List Credential Manager Service configurations effect: read questions: - Which Credential Manager Service configurations are set up for my company? - Can I list only the credential manager configs of a certain CMS type? instructions: - text: List all our Credential Manager Service configurations. - text: Show the credential manager configurations of type {cmsTypes}. slots: cmsTypes: query.cmsTypes method: generated generated: '2026-09-26' - target: $.paths['/v1/credentialmanagerconfigurations'].put update: x-apievangelist-phrasing: intent: Update a Credential Manager Service configuration effect: write questions: - How do I change the settings of an existing credential manager configuration? - Can I share a credential manager configuration with every tenant? instructions: - text: Rename credential manager configuration {id} to {name}. slots: id: requestBody.id name: requestBody.name - text: Route credential manager configuration {id} through VSatellites {vSatelliteIds}. slots: id: requestBody.id vSatelliteIds: requestBody.vSatelliteIds method: generated generated: '2026-09-26' - target: $.paths['/v1/credentialmanagerconfigurations'].post update: x-apievangelist-phrasing: intent: Add Credential Manager Service configurations effect: write questions: - How do I connect a privileged access management vault as a new Credential Manager Service? - Can my company have more than one credential manager configuration of the same type? instructions: - text: 'Add these Credential Manager Service configurations: {cmsConfigurations}.' slots: cmsConfigurations: requestBody.cmsConfigurations - text: Register a new credential manager connection using {cmsConfigurations}. slots: cmsConfigurations: requestBody.cmsConfigurations method: generated generated: '2026-09-26' - target: $.paths['/v1/credentialmanagerconfigurations/{id}'].get update: x-apievangelist-phrasing: intent: Get one Credential Manager Service configuration effect: read questions: - What are the details of a single credential manager configuration by its ID? - Which VSatellites does a particular credential manager configuration use? instructions: - text: Show credential manager configuration {id}. slots: id: path.id - text: Look up the Credential Manager Service config with ID {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/v1/credentialmanagerconfigurations/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a Credential Manager Service configuration effect: destructive questions: - How do I remove a credential manager configuration we no longer use? - Can I delete a Credential Manager Service configuration by its ID? instructions: - text: Delete credential manager configuration {id}. slots: id: path.id - text: Remove the Credential Manager Service config {id} from our company. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/v1/credentialmanagerconfigurations/test'].post update: x-apievangelist-phrasing: intent: Test a credential manager connection before saving effect: read questions: - Can I test connectivity to a privileged access vault with unsaved configuration details? - How do I check a PAM connection works through selected VSatellites before adding it? instructions: - text: Test a {cmsType} credential manager connection with details {cmsDetails} using web socket client {wsClientId}. slots: cmsType: requestBody.cmsType cmsDetails: requestBody.cmsDetails wsClientId: requestBody.wsClientId - text: Try connecting to the PAM through VSatellites {vSatelliteIds} with client {wsClientId}. slots: vSatelliteIds: requestBody.vSatelliteIds wsClientId: requestBody.wsClientId method: generated generated: '2026-09-26' - target: $.paths['/v1/credentialmanagerconfigurations/{id}/test'].post update: x-apievangelist-phrasing: intent: Test a saved credential manager configuration effect: read questions: - Is my saved credential manager configuration still able to reach the vault? - How do I re-test the connection of an existing Credential Manager Service config by ID? instructions: - text: Test the connection of saved credential manager configuration {id}. slots: id: path.id - text: Verify that stored CMS config {id} can still reach its privileged access system. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/v1/credentials'].get update: x-apievangelist-phrasing: intent: List shared credentials effect: read questions: - What shared credentials does my company have stored? - Can I filter shared credentials by team or authentication type? instructions: - text: List all shared credentials for my company. - text: Show shared credentials for team {teamIds} with auth type {authTypes}. slots: teamIds: query.teamIds authTypes: query.authTypes method: generated generated: '2026-09-26' - target: $.paths['/v1/credentials'].put update: x-apievangelist-phrasing: intent: Update a shared credential effect: write questions: - How do I change the values or teams of an existing shared credential? - Can I move a shared credential to a different credential manager configuration? instructions: - text: Update shared credential {id} with new details {credentialDetails}. slots: id: requestBody.id credentialDetails: requestBody.credentialDetails - text: Give teams {teamsIds} access to shared credential {id}. slots: id: requestBody.id teamsIds: requestBody.teamsIds method: generated generated: '2026-09-26' - target: $.paths['/v1/credentials'].post update: x-apievangelist-phrasing: intent: Add new shared credentials effect: write questions: - How do I store a new shared credential for my team to use? - Do shared credential names have to be unique? instructions: - text: 'Add these shared credentials: {credentials}.' slots: credentials: requestBody.credentials - text: Create new shared credentials from {credentials}. slots: credentials: requestBody.credentials method: generated generated: '2026-09-26' - target: $.paths['/v1/credentials'].delete update: x-apievangelist-phrasing: intent: Delete several shared credentials at once effect: destructive questions: - Can I bulk delete a list of shared credentials in one call? - How do I remove multiple stored credentials by their IDs together? instructions: - text: Delete the shared credentials with IDs {ids}. slots: ids: query.ids - text: Bulk remove shared credentials {ids}. slots: ids: query.ids method: generated generated: '2026-09-26' - target: $.paths['/v1/credentials/{id}'].get update: x-apievangelist-phrasing: intent: Get a shared credential by ID effect: read questions: - What is stored in a particular shared credential? - Can I fetch one shared credential with its full details? instructions: - text: Show shared credential {id}. slots: id: path.id - text: Get shared credential {id} including details {details}. slots: id: path.id details: query.details method: generated generated: '2026-09-26' - target: $.paths['/v1/credentials/{id}'].delete update: x-apievangelist-phrasing: intent: Delete one shared credential effect: destructive questions: - How do I delete a single shared credential by its ID? - What happens when I remove one stored credential from the company? instructions: - text: Delete shared credential {id}. slots: id: path.id - text: Remove the single shared credential with ID {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/v1/credentials/test'].post update: x-apievangelist-phrasing: intent: Test access to a shared credential effect: read questions: - Can I check that a shared credential actually works before relying on it? - If I pass both a credential ID and new values to the test, which one wins? instructions: - text: Test access to shared credential {id} through client {wsClientId}. slots: id: requestBody.id wsClientId: requestBody.wsClientId - text: Check whether {authType} credential values {credentialDetails} work, using client {wsClientId}. slots: authType: requestBody.authType credentialDetails: requestBody.credentialDetails wsClientId: requestBody.wsClientId method: generated generated: '2026-09-26'