# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Security Services Decryption Rules API version: 1.0.0 extends: openapi/palo-alto-networks-decryption-rules-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 12 - target: $.paths['/decryption-rules'].get update: x-apievangelist-phrasing: intent: List decryption rules effect: read questions: - Which SSL decryption rules are in my pre or post rulebase? - Can I list decryption rules for just one folder or snippet? instructions: - text: List {position} decryption rules in folder {folder}. slots: position: query.position folder: query.folder - text: Find the {position} decryption rule named {name}. slots: position: query.position name: query.name method: generated generated: '2026-09-26' - target: $.paths['/decryption-rules'].post update: x-apievangelist-phrasing: intent: Create a decryption rule effect: write questions: - How do I add a rule to decrypt traffic between two zones? - What fields are required when creating a decryption rule? instructions: - text: Create a {position} decryption rule {name} with action {action} from zone {from} to zone {to}. slots: position: query.position name: requestBody.name action: requestBody.action from: requestBody.from to: requestBody.to - text: Add decryption rule {name} for sources {source} to destinations {destination} in URL category {category}. slots: name: requestBody.name source: requestBody.source destination: requestBody.destination category: requestBody.category method: generated generated: '2026-09-26' - target: $.paths['/decryption-rules/{id}'].get update: x-apievangelist-phrasing: intent: Get a decryption rule effect: read questions: - What does a specific decryption rule match and do? - Can I fetch one decryption rule by its ID? instructions: - text: Show decryption rule {id}. slots: id: path.id - text: Get the settings of decryption rule {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/decryption-rules/{id}'].put update: x-apievangelist-phrasing: intent: Update a decryption rule effect: write questions: - Can I change the action or zones on an existing decryption rule? - Is there a way to disable a decryption rule without deleting it? instructions: - text: Change decryption rule {id} action to {action}. slots: id: path.id action: requestBody.action - text: Set disabled={disabled} on decryption rule {id}. slots: disabled: requestBody.disabled id: path.id method: generated generated: '2026-09-26' - target: $.paths['/decryption-rules/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a decryption rule effect: destructive questions: - How do I remove a decryption rule? - Does deleting a decryption rule take it out of the rulebase immediately? instructions: - text: Delete decryption rule {id}. slots: id: path.id - text: Remove the obsolete decryption rule {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/decryption-rules/{id}:move'].post update: x-apievangelist-phrasing: intent: Reorder a decryption rule effect: write questions: - Can I move a decryption rule above or below another rule? - How do I change the evaluation order of decryption rules? instructions: - text: Move decryption rule {id} to {destination} in the {rulebase} rulebase. slots: id: path.id destination: requestBody.destination rulebase: requestBody.rulebase - text: Place decryption rule {id} {destination} rule {destination_rule} in {rulebase}. slots: id: path.id destination: requestBody.destination destination_rule: requestBody.destination_rule rulebase: requestBody.rulebase method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/decryption-rules'].get update: x-apievangelist-phrasing: intent: List decryption rules effect: read questions: - Which SSL decryption rules are configured in a Prisma Access folder? - Can I list only the pre-rulebase decryption rules? instructions: - text: List {position} decryption rules in folder {folder} through the SSE config v1 path. slots: position: query.position folder: query.folder - text: Find decryption rules named {name} in folder {folder} at position {position}. slots: name: query.name folder: query.folder position: query.position method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/decryption-rules'].post update: x-apievangelist-phrasing: intent: Create a decryption rule effect: write questions: - How do I add a rule that decrypts traffic for certain URL categories? - Can I create a no-decrypt rule for specific users and destinations? instructions: - text: Create decryption rule {name} with action {action} for categories {category} in folder {folder} at {position}. slots: name: requestBody.name action: requestBody.action category: requestBody.category folder: query.folder position: query.position - text: Add a {action} decryption rule {name} from users {source_user} to {destination} in {folder} ({position}). slots: action: requestBody.action name: requestBody.name source_user: requestBody.source_user destination: requestBody.destination folder: query.folder position: query.position method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/decryption-rules/{id}'].get update: x-apievangelist-phrasing: intent: Get a decryption rule effect: read questions: - What does a specific decryption rule match and what action does it take? - Can I look up one decryption rule by its ID? instructions: - text: Get decryption rule {id}. slots: id: path.id - text: Show the sources, destinations and action of decryption rule {id}. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/decryption-rules/{id}'].put update: x-apievangelist-phrasing: intent: Edit a decryption rule effect: write questions: - Can I change the action or categories on an existing decryption rule? - How do I disable a decryption rule without deleting it? instructions: - text: Edit decryption rule {id} ({name}) via the SSE config v1 path, setting its action to {action}. slots: id: path.id name: requestBody.name action: requestBody.action - text: Update decryption rule {id} to cover categories {category} for users {source_user}. slots: id: path.id category: requestBody.category source_user: requestBody.source_user method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/decryption-rules/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a decryption rule effect: destructive questions: - How do I remove a decryption rule from my policy? - Is a deleted decryption rule gone for good? instructions: - text: Delete decryption rule {id} using the SSE config v1 endpoint. slots: id: path.id - text: Remove the decryption rule with ID {id}. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/decryption-rules/{id}:move'].post update: x-apievangelist-phrasing: intent: Reorder a decryption rule effect: write questions: - Can I move a decryption rule to the top of the rulebase? - How do I place one decryption rule before another? instructions: - text: Move decryption rule {id} to the {destination} of the {rulebase} rulebase in folder {folder}. slots: id: path.id destination: requestBody.destination rulebase: requestBody.rulebase folder: query.folder - text: Place decryption rule {id} {destination} rule {destination_rule} in {rulebase} for folder {folder}. slots: id: path.id destination: requestBody.destination destination_rule: requestBody.destination_rule rulebase: requestBody.rulebase folder: query.folder method: generated generated: '2026-10-01'