# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Authentication and RBAC API's SSO API version: 1.0.0 extends: openapi/palo-alto-networks-sso-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 8 - target: $.paths['/authn/v1/saml/config'].get update: x-apievangelist-phrasing: intent: Get the tenant SAML configuration effect: read questions: - How is SAML single sign-on currently set up for my Prisma Cloud tenant? - Which identity provider and audience URI does our SAML setup use? instructions: - text: Show the tenant's SAML configuration. - text: Get our current SAML SSO settings. method: generated generated: '2026-09-26' - target: $.paths['/authn/v1/saml/config'].put update: x-apievangelist-phrasing: intent: Update the tenant SAML configuration effect: write questions: - Can I rotate the IdP certificate on an existing SAML setup? - How do I turn on SAML auto-provisioning of users for an existing configuration? instructions: - text: Update the existing SAML config to use certificate {certificate}. slots: certificate: requestBody.certificate - text: Change the SAML logout redirect URL to {logoutRedirectUrl}. slots: logoutRedirectUrl: requestBody.logoutRedirectUrl - text: Set SAML auto-provisioning on the existing config to {autoProvisionEnabled}. slots: autoProvisionEnabled: requestBody.autoProvisionEnabled method: generated generated: '2026-09-26' - target: $.paths['/authn/v1/saml/config'].post update: x-apievangelist-phrasing: intent: Create the tenant SAML configuration effect: write questions: - How do I set up SAML SSO for the first time on my tenant? - What do I need from my identity provider to create a SAML configuration? instructions: - text: Create a SAML configuration for identity provider {identityProvider} with certificate {certificate}. slots: identityProvider: requestBody.identityProvider certificate: requestBody.certificate - text: Set up new SAML SSO with audience URI {audienceUri}. slots: audienceUri: requestBody.audienceUri method: generated generated: '2026-09-26' - target: $.paths['/authn/api/v1/oauth2/config'].get update: x-apievangelist-phrasing: intent: Get the tenant OIDC configuration effect: read questions: - What OpenID Connect settings does my tenant use for sign-in? - Which issuer and client ID is our OIDC login configured with? instructions: - text: Show the tenant's OIDC configuration. - text: Get our OAuth2 settings used for OpenID Connect. method: generated generated: '2026-09-26' - target: $.paths['/authn/api/v1/oauth2/config'].put update: x-apievangelist-phrasing: intent: Replace the tenant OIDC configuration effect: write questions: - How do I overwrite every setting of our OIDC configuration at once? - Can I replace the full OpenID Connect config with a new issuer and endpoints? instructions: - text: Replace the OIDC config with client {clientId}, issuer {issuer}, auth URI {idpAuthUri} and token URI {tokenUri}. slots: clientId: requestBody.clientId issuer: requestBody.issuer idpAuthUri: requestBody.idpAuthUri tokenUri: requestBody.tokenUri - text: Overwrite all OIDC settings, requesting scopes {scopes}. slots: scopes: requestBody.scopes method: generated generated: '2026-09-26' - target: $.paths['/authn/api/v1/oauth2/config'].post update: x-apievangelist-phrasing: intent: Create the tenant OIDC configuration effect: write questions: - How do I set up OpenID Connect sign-in for my tenant for the first time? - Can I enable PKCE when I first configure OIDC? instructions: - text: Create an OIDC configuration for client {clientId} with issuer {issuer}. slots: clientId: requestBody.clientId issuer: requestBody.issuer - text: Set up new OpenID Connect login using token URI {tokenUri} and auth URI {idpAuthUri}. slots: tokenUri: requestBody.tokenUri idpAuthUri: requestBody.idpAuthUri method: generated generated: '2026-09-26' - target: $.paths['/authn/api/v1/oauth2/config'].patch update: x-apievangelist-phrasing: intent: Partially update the tenant OIDC configuration effect: write questions: - Can I change just one OIDC setting without resending the whole configuration? - How do I switch on just-in-time provisioning in our existing OIDC setup? instructions: - text: Patch only the OIDC client secret to {clientSecret}. slots: clientSecret: requestBody.clientSecret - text: Change just the OIDC JIT provisioning flag to {isJitEnabled}. slots: isJitEnabled: requestBody.isJitEnabled method: generated generated: '2026-09-26' - target: $.paths['/authn/api/v1/oauth2/login'].get update: x-apievangelist-phrasing: intent: Get the OIDC login URL effect: read questions: - Where do users go to sign in to my tenant with OpenID Connect? - What's the OIDC login link for a specific user? instructions: - text: Get the OIDC login URL for my tenant. - text: Get the OIDC login URL for user {user_name}. slots: user_name: query.user_name method: generated generated: '2026-09-26'