# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Prisma Cloud Access Keys API Overview IP Allow List API version: 1.0.0 extends: openapi/palo-alto-networks-ip-allowlist-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 14 - target: $.paths['/allow_list/network'].get update: x-apievangelist-phrasing: intent: List trusted public networks effect: read questions: - Which public networks are on my trusted IP allow list? - What trusted networks has my tenant defined for alerting? instructions: - text: List all trusted public networks. - text: Show my allow list networks. method: generated generated: '2026-10-01' - target: $.paths['/allow_list/network'].post update: x-apievangelist-phrasing: intent: Add a trusted public network effect: write questions: - How do I add a new trusted network to the IP allow list? - Does a newly created trusted network start with any CIDR blocks? instructions: - text: Create a trusted network named {name}. slots: name: requestBody.name - text: Add public network {name} to the allow list. slots: name: requestBody.name method: generated generated: '2026-10-01' - target: $.paths['/allow_list/network/{networkUuid}'].get update: x-apievangelist-phrasing: intent: Get a trusted network effect: read questions: - What CIDRs are in a specific trusted network? - Can I look up one allow list network by its ID? instructions: - text: Get trusted network {networkUuid}. slots: networkUuid: path.networkUuid - text: Show the details of allow list network {networkUuid}. slots: networkUuid: path.networkUuid method: generated generated: '2026-10-01' - target: $.paths['/allow_list/network/{networkUuid}'].put update: x-apievangelist-phrasing: intent: Rename a trusted network effect: write questions: - Can I rename a trusted network without recreating it? - Is it possible to change the label on an existing allow list network? instructions: - text: Rename trusted network {networkUuid} to {name}. slots: networkUuid: path.networkUuid name: requestBody.name - text: Change the name of network {networkUuid} to {name}. slots: networkUuid: path.networkUuid name: requestBody.name method: generated generated: '2026-10-01' - target: $.paths['/allow_list/network/{networkUuid}/cidr'].post update: x-apievangelist-phrasing: intent: Add a CIDR block to a trusted network effect: write questions: - How do I add an IP range to one of my trusted networks? - Can a new CIDR block overlap ranges in my other trusted networks? instructions: - text: Add CIDR {cidr} to trusted network {networkUuid}. slots: cidr: requestBody.cidr networkUuid: path.networkUuid - text: Add range {cidr} with description {description} to network {networkUuid}. slots: cidr: requestBody.cidr description: requestBody.description networkUuid: path.networkUuid method: generated generated: '2026-10-01' - target: $.paths['/allow_list/network/{networkUuid}/cidr/{cidrUuid}'].put update: x-apievangelist-phrasing: intent: Update a CIDR block in a trusted network effect: write questions: - Can I change an existing CIDR range in a trusted network? - What happens to the description if I send it blank when editing a CIDR block? instructions: - text: Change CIDR {cidrUuid} in network {networkUuid} to {cidr}. slots: cidrUuid: path.cidrUuid networkUuid: path.networkUuid cidr: requestBody.cidr - text: Update the description of CIDR block {cidrUuid} in network {networkUuid} to {description}, keeping range {cidr}. slots: cidrUuid: path.cidrUuid networkUuid: path.networkUuid description: requestBody.description cidr: requestBody.cidr method: generated generated: '2026-10-01' - target: $.paths['/allow_list/network/{networkUuid}/cidr/{cidrUuid}'].delete update: x-apievangelist-phrasing: intent: Remove a CIDR block from a trusted network effect: destructive questions: - How do I drop an IP range from a trusted network? - Can I delete one CIDR block without removing the whole network? instructions: - text: Delete CIDR {cidrUuid} from network {networkUuid}. slots: cidrUuid: path.cidrUuid networkUuid: path.networkUuid - text: Remove range {cidrUuid} from trusted network {networkUuid}. slots: cidrUuid: path.cidrUuid networkUuid: path.networkUuid method: generated generated: '2026-10-01' - target: $.paths['/ip_allow_list_login'].get update: x-apievangelist-phrasing: intent: List login IP allow lists effect: read questions: - Which IP ranges are allowed to log in to my Prisma Cloud tenant? - What named login allow lists do we have? instructions: - text: List all login IP allow lists. - text: Show every CIDR allowed for tenant login. method: generated generated: '2026-10-01' - target: $.paths['/ip_allow_list_login'].post update: x-apievangelist-phrasing: intent: Add a login IP allow list effect: write questions: - How many CIDRs can I put in a single login allow list? - Can I restrict console login to our office IP ranges? instructions: - text: Create login allow list {name} with CIDRs {cidr}. slots: name: requestBody.name cidr: requestBody.cidr - text: Allow login from {cidr} under a new list called {name}. slots: cidr: requestBody.cidr name: requestBody.name method: generated generated: '2026-10-01' - target: $.paths['/ip_allow_list_login/{id}'].get update: x-apievangelist-phrasing: intent: Get a login IP allow list effect: read questions: - What CIDRs are in one particular login allow list? - Can I look up a single login IP allow list by ID? instructions: - text: Get login IP allow list {id}. slots: id: path.id - text: Show the CIDRs in login allow list {id}. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/ip_allow_list_login/{id}'].put update: x-apievangelist-phrasing: intent: Update a login IP allow list effect: write questions: - Can I replace the CIDRs in an existing login allow list? - Is it possible to rename a login IP allow list? instructions: - text: Set login allow list {id} to CIDRs {cidr}, keeping name {name}. slots: id: path.id cidr: requestBody.cidr name: requestBody.name - text: Rename login allow list {id} to {name} with CIDRs {cidr}. slots: id: path.id name: requestBody.name cidr: requestBody.cidr method: generated generated: '2026-10-01' - target: $.paths['/ip_allow_list_login/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a login IP allow list effect: destructive questions: - Why can't I delete my last login allow list entry? - How do I remove a named login IP allow list? instructions: - text: Delete login IP allow list {id}. slots: id: path.id - text: Remove login allow list {id} from the tenant. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/ip_allow_list_login/status'].get update: x-apievangelist-phrasing: intent: Check if login IP allow listing is on effect: read questions: - Is the login IP allow list currently enforced on my tenant? - Are logins restricted by IP right now? instructions: - text: Check whether the login IP allow list is enabled. - text: Tell me if login IP restriction is on. method: generated generated: '2026-10-01' - target: $.paths['/ip_allow_list_login/status'].patch update: x-apievangelist-phrasing: intent: Turn login IP allow listing on or off effect: write questions: - Can I switch on login IP restriction for the whole tenant? - What's the call to temporarily disable the login allow list? instructions: - text: Enable the login IP allow list. - text: Disable login IP allow list enforcement. method: generated generated: '2026-10-01'