# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks SASE IAM Service Service Accounts API version: 1.0.0 extends: openapi/palo-alto-networks-service-accounts-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 13 - target: $.paths['/service-accounts'].get update: x-apievangelist-phrasing: intent: List service accounts effect: read questions: - Which service accounts exist for API automation in my tenant? - Can I list service accounts for one Tenant Service Group only? instructions: - text: List all service accounts. - text: List service accounts in TSG {tsg_id}. slots: tsg_id: query.tsg_id method: generated generated: '2026-09-26' - target: $.paths['/service-accounts'].post update: x-apievangelist-phrasing: intent: Create a service account effect: write questions: - How do I create a machine identity for API automation? - Which Tenant Service Group does a new service account have to belong to? instructions: - text: Create service account {name} in TSG {tsg_id}. slots: name: requestBody.name tsg_id: requestBody.tsg_id - text: Add service account {name} to TSG {tsg_id} described as {description}. slots: name: requestBody.name tsg_id: requestBody.tsg_id description: requestBody.description method: generated generated: '2026-09-26' - target: $.paths['/service-accounts/{id}'].get update: x-apievangelist-phrasing: intent: Get a service account effect: read questions: - What are the full details of one service account? - Can I look up a service account by its ID? instructions: - text: Get service account {id}. slots: id: path.id - text: Show details of service account {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/service-accounts/{id}'].put update: x-apievangelist-phrasing: intent: Rename or re-describe a service account effect: write questions: - Can I change a service account's display name? - Is it possible to update the description of an existing service account? instructions: - text: Set the display name of service account {id} to {display_name}. slots: id: path.id display_name: requestBody.display_name - text: Update the description of service account {id} to {description}. slots: id: path.id description: requestBody.description method: generated generated: '2026-09-26' - target: $.paths['/service-accounts/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a service account effect: destructive questions: - What happens to active API sessions when I delete a service account? - How do I remove a service account and all its credentials? instructions: - text: Delete service account {id}. slots: id: path.id - text: Remove service account {id} and revoke all its credentials. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/service-accounts/{id}/keys'].post update: x-apievangelist-phrasing: intent: Generate client credentials for a service account effect: write questions: - How do I get a client ID and secret for a service account? - Can I make service account credentials expire after a set number of days? instructions: - text: Generate new credentials for service account {id}. slots: id: path.id - text: Create a client secret for service account {id} that expires in {expires_in_days} days. slots: id: path.id expires_in_days: requestBody.expires_in_days method: generated generated: '2026-09-26' - target: $.paths['/service-accounts/{id}/keys/{key_id}'].delete update: x-apievangelist-phrasing: intent: Revoke a service account key effect: destructive questions: - Can I revoke one leaked key without deleting the whole service account? - What happens to sessions using a key I revoke? instructions: - text: Revoke key {key_id} on service account {id}. slots: key_id: path.key_id id: path.id - text: Invalidate credential {key_id} for service account {id}. slots: key_id: path.key_id id: path.id method: generated generated: '2026-09-26' - target: $.paths['/iam/v1/service_accounts'].get update: x-apievangelist-phrasing: intent: List service accounts effect: read questions: - Which service accounts exist in my Prisma SASE tenant? - Can I see every IAM service account at once? instructions: - text: List every service account through the IAM v1 endpoint. - text: Show me every IAM service account in the tenant. method: generated generated: '2026-10-01' - target: $.paths['/iam/v1/service_accounts'].post update: x-apievangelist-phrasing: intent: Create a service account effect: write questions: - How do I create a service account for an automation script? - Can I set a contact email on a new service account? instructions: - text: Create a service account named {name} with contact email {contact_email}. slots: name: requestBody.name contact_email: requestBody.contact_email - text: Add service account {name} described as {description}. slots: name: requestBody.name description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/iam/v1/service_accounts/{id}'].get update: x-apievangelist-phrasing: intent: Get a service account effect: read questions: - What are the details of one particular service account? - Can I read one service account through the IAM v1 API? instructions: - text: Fetch IAM v1 service account {id}. slots: id: path.id - text: Show the details of service account {id}. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/iam/v1/service_accounts/{id}'].put update: x-apievangelist-phrasing: intent: Update a service account effect: write questions: - Can I change the contact email on an existing service account? - What fields of a service account can I edit? instructions: - text: Set the contact email of service account {id} to {contact_email}. slots: id: path.id contact_email: requestBody.contact_email - text: Change the IAM v1 description of service account {id} to {description}. slots: id: path.id description: requestBody.description method: generated generated: '2026-10-01' - target: $.paths['/iam/v1/service_accounts/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a service account effect: destructive questions: - How do I remove a service account that's no longer needed? - Can I delete a service account by ID? instructions: - text: Delete IAM v1 service account {id}. slots: id: path.id - text: Remove service account {id} from the tenant. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/iam/v1/service_accounts/{id}/operations/reset'].post update: x-apievangelist-phrasing: intent: Reset a service account effect: destructive questions: - What does resetting a service account do? - Can I reset a compromised service account? instructions: - text: Reset service account {id}. slots: id: path.id - text: Run the reset operation on service account {id}. slots: id: path.id method: generated generated: '2026-10-01'