Auth0 · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Auth0 Management Guardian API
37 actions
37 updates
phrasing
extends
openapi/auth0-guardian-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Auth0's API. It is a proposal applied on top of the contract, not a document Auth0 publishes.
What the actions change
x-apievangelist-phrasing
Targets 37 · first 16 shown; the file carries all of them
$.info
$.paths['/guardian/enrollments/ticket'].post
$.paths['/guardian/enrollments/{id}'].get
$.paths['/guardian/enrollments/{id}'].delete
$.paths['/guardian/factors'].get
$.paths['/guardian/factors/duo/settings'].get
$.paths['/guardian/factors/duo/settings'].put
$.paths['/guardian/factors/duo/settings'].patch
$.paths['/guardian/factors/phone/message-types'].get
$.paths['/guardian/factors/phone/message-types'].put
$.paths['/guardian/factors/phone/providers/twilio'].get
$.paths['/guardian/factors/phone/providers/twilio'].put
$.paths['/guardian/factors/phone/selected-provider'].get
$.paths['/guardian/factors/phone/selected-provider'].put
$.paths['/guardian/factors/phone/templates'].get
$.paths['/guardian/factors/phone/templates'].put
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Auth0 Management Guardian API
version: 1.0.0
extends: openapi/auth0-guardian-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-10-01'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 36
- target: $.paths['/guardian/enrollments/ticket'].post
update:
x-apievangelist-phrasing:
intent: Create an MFA enrollment ticket for a user
effect: write
questions:
- How do I send a user a link to enroll in multi-factor authentication?
- Can an MFA enrollment ticket be emailed to the user automatically in their own language?
- Is it possible to let a user enroll more than one MFA factor from a single ticket?
instructions:
- text: Create an MFA enrollment ticket for user {user_id}.
slots:
user_id: requestBody.user_id
- text: Generate an MFA enrollment ticket for {user_id} and email it to {email}.
slots:
user_id: requestBody.user_id
email: requestBody.email
- text: Create an enrollment ticket for {user_id} that sets up the {factor} factor.
slots:
user_id: requestBody.user_id
factor: requestBody.factor
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/enrollments/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get one MFA enrollment's status and type
effect: read
questions:
- What status and factor type does a specific MFA enrollment have?
- Can I look up a single multi-factor enrollment by its ID to see if it is confirmed?
instructions:
- text: Show me the details of MFA enrollment {id}.
slots:
id: path.id
- text: Check whether MFA enrollment {id} is confirmed.
slots:
id: path.id
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/enrollments/{id}'].delete
update:
x-apievangelist-phrasing:
intent: Remove an MFA enrollment so the user can re-enroll
effect: destructive
questions:
- How do I reset a user's MFA so they can enroll a new device?
- What happens to a user when I delete one of their MFA enrollments?
instructions:
- text: Delete MFA enrollment {id} so the user can enroll again.
slots:
id: path.id
- text: Remove the lost-phone MFA enrollment {id} from the user's account.
slots:
id: path.id
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors'].get
update:
x-apievangelist-phrasing:
intent: List the tenant's MFA factors
effect: read
questions:
- Which multi-factor authentication factors are available in my Auth0 tenant?
- Can I see at a glance which MFA factors are turned on or off?
instructions:
- text: List every MFA factor in my tenant with its enabled state.
- text: Show me which MFA factors are currently enabled.
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/duo/settings'].get
update:
x-apievangelist-phrasing:
intent: Get the DUO MFA configuration
effect: read
questions:
- What DUO integration key and API host is my MFA currently set up with?
- Where can I check the current DUO factor configuration?
instructions:
- text: Show me the current DUO MFA configuration.
- text: Fetch the DUO account settings used for multi-factor authentication.
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/duo/settings'].put
update:
x-apievangelist-phrasing:
intent: Set the full DUO MFA configuration
effect: write
questions:
- How do I connect my DUO account to multi-factor authentication from scratch?
- Can I replace the whole DUO configuration with new integration and secret keys at once?
instructions:
- text: Set the DUO configuration with integration key {ikey}, secret key {skey} and API host {host}.
slots:
ikey: requestBody.ikey
skey: requestBody.skey
host: requestBody.host
- text: Replace the entire DUO MFA setup using API host {host}.
slots:
host: requestBody.host
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/duo/settings'].patch
update:
x-apievangelist-phrasing:
intent: Change individual DUO MFA settings
effect: write
questions:
- Can I change just the DUO API hostname without re-entering the other keys?
- How would I rotate only the DUO secret key on an existing setup?
instructions:
- text: Update only the DUO secret key to {skey}.
slots:
skey: requestBody.skey
- text: Patch the existing DUO setup to point at API host {host}.
slots:
host: requestBody.host
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/phone/message-types'].get
update:
x-apievangelist-phrasing:
intent: List enabled phone MFA delivery methods
effect: read
questions:
- Are SMS codes, voice calls or both enabled for phone MFA?
- Which phone message types can users receive MFA codes through right now?
instructions:
- text: Show me which phone MFA message types are enabled.
- text: Check whether voice is enabled alongside SMS for phone MFA.
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/phone/message-types'].put
update:
x-apievangelist-phrasing:
intent: Choose SMS and/or voice for phone MFA
effect: write
questions:
- How do I let users get their MFA code by voice call as well as text message?
- Can I switch phone MFA to SMS only?
instructions:
- text: Set the phone MFA message types to {message_types}.
slots:
message_types: requestBody.message_types
- text: Enable both SMS and voice for phone MFA by setting message types to {message_types}.
slots:
message_types: requestBody.message_types
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/phone/providers/twilio'].get
update:
x-apievangelist-phrasing:
intent: Get the Twilio phone MFA provider configuration
effect: read
questions:
- Which Twilio sender number and messaging service is my phone MFA using?
- Where do I view the Twilio settings for phone-based multi-factor authentication?
instructions:
- text: Show me the Twilio configuration for phone MFA.
- text: Fetch the Twilio account SID and from-number configured for phone factors.
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/phone/providers/twilio'].put
update:
x-apievangelist-phrasing:
intent: Update the Twilio phone MFA provider configuration
effect: write
questions:
- How do I change the Twilio number that sends phone MFA codes?
- Can I switch phone MFA to use a Twilio messaging service SID instead of a from-number?
instructions:
- text: Set the Twilio phone provider to send from {from} using account SID {sid}.
slots:
from: requestBody.from
sid: requestBody.sid
- text: Configure phone MFA Twilio with messaging service {messaging_service_sid} and auth token {auth_token}.
slots:
messaging_service_sid: requestBody.messaging_service_sid
auth_token: requestBody.auth_token
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/phone/selected-provider'].get
update:
x-apievangelist-phrasing:
intent: See which phone provider delivers MFA codes
effect: read
questions:
- Which provider is currently selected for sending phone MFA messages?
- Is my tenant using Twilio or the built-in phone provider for MFA?
instructions:
- text: Show me the selected phone provider for MFA.
- text: Tell me which phone messaging provider multi-factor authentication currently uses.
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/phone/selected-provider'].put
update:
x-apievangelist-phrasing:
intent: Choose the phone provider for MFA messages
effect: write
questions:
- How do I switch the provider that sends phone MFA codes?
- Can phone MFA be moved to Twilio as the selected provider?
instructions:
- text: Set the phone MFA provider to {provider}.
slots:
provider: requestBody.provider
- text: Switch phone-based multi-factor messaging over to {provider}.
slots:
provider: requestBody.provider
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/phone/templates'].get
update:
x-apievangelist-phrasing:
intent: Get phone MFA enrollment and verification messages
effect: read
questions:
- What text do users receive by phone when they enroll in or verify MFA?
- Where can I read the current phone enrollment and verification message templates?
instructions:
- text: Show me the phone MFA enrollment and verification templates.
- text: Fetch the message text sent by phone for MFA verification codes.
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/phone/templates'].put
update:
x-apievangelist-phrasing:
intent: Customize phone MFA enrollment and verification messages
effect: write
questions:
- Can I rewrite the text message users get when verifying MFA by phone?
- How do I brand the phone enrollment message for multi-factor authentication?
instructions:
- text: Set the phone enrollment message to {enrollment_message} and the verification message to {verification_message}.
slots:
enrollment_message: requestBody.enrollment_message
verification_message: requestBody.verification_message
- text: Update the phone factor templates with verification text {verification_message} and enrollment text {enrollment_message}.
slots:
verification_message: requestBody.verification_message
enrollment_message: requestBody.enrollment_message
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/push-notification/providers/apns'].get
update:
x-apievangelist-phrasing:
intent: Get the APNs push MFA configuration
effect: read
questions:
- Which iOS bundle ID is set for push notification MFA through APNs?
- Is my APNs push configuration in sandbox or production mode?
instructions:
- text: Show me the APNs push notification configuration for MFA.
- text: Check whether the APNs MFA provider is set to sandbox.
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/push-notification/providers/apns'].put
update:
x-apievangelist-phrasing:
intent: Overwrite the APNs push MFA configuration
effect: write
questions:
- How do I set up APNs from scratch for push-based MFA on iOS?
- Can I replace the whole APNs configuration with a new p12 certificate and bundle ID?
instructions:
- text: Replace the APNs configuration with bundle ID {bundle_id} and certificate {p12}.
slots:
bundle_id: requestBody.bundle_id
p12: requestBody.p12
- text: Overwrite all APNs push settings using bundle {bundle_id} in sandbox mode {sandbox}.
slots:
bundle_id: requestBody.bundle_id
sandbox: requestBody.sandbox
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/push-notification/providers/apns'].patch
update:
x-apievangelist-phrasing:
intent: Change individual APNs push MFA settings
effect: write
questions:
- Can I flip APNs from sandbox to production without re-uploading the certificate?
- How do I swap just the APNs p12 certificate when it expires?
instructions:
- text: Update only the APNs sandbox flag to {sandbox}.
slots:
sandbox: requestBody.sandbox
- text: Patch the existing APNs setup with renewed certificate {p12}.
slots:
p12: requestBody.p12
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/push-notification/providers/fcm'].put
update:
x-apievangelist-phrasing:
intent: Overwrite the legacy FCM push MFA configuration
effect: write
questions:
- How do I set the legacy FCM server key for Android push MFA from scratch?
- Can I replace the whole legacy FCM configuration in one call?
instructions:
- text: Replace the legacy FCM push configuration with server key {server_key}.
slots:
server_key: requestBody.server_key
- text: Overwrite all FCM (legacy) settings for MFA push using key {server_key}.
slots:
server_key: requestBody.server_key
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/push-notification/providers/fcm'].patch
update:
x-apievangelist-phrasing:
intent: Update the legacy FCM server key for push MFA
effect: write
questions:
- Can I rotate just the legacy FCM server key on my existing push MFA setup?
- Is there a partial update for the older FCM provider configuration?
instructions:
- text: Patch the legacy FCM provider with new server key {server_key}.
slots:
server_key: requestBody.server_key
- text: Rotate the legacy FCM server key to {server_key} without resetting other settings.
slots:
server_key: requestBody.server_key
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/push-notification/providers/fcmv1'].put
update:
x-apievangelist-phrasing:
intent: Overwrite the FCM v1 push MFA configuration
effect: write
questions:
- How do I configure FCM HTTP v1 service account credentials for Android push MFA?
- Can I replace the full FCMv1 configuration with a new service account JSON?
instructions:
- text: Replace the FCMv1 push configuration with credentials {server_credentials}.
slots:
server_credentials: requestBody.server_credentials
- text: Overwrite all FCM v1 settings for push MFA using service account {server_credentials}.
slots:
server_credentials: requestBody.server_credentials
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/push-notification/providers/fcmv1'].patch
update:
x-apievangelist-phrasing:
intent: Update the FCM v1 push MFA credentials
effect: write
questions:
- Can I rotate just the FCMv1 service account credentials on an existing push setup?
- Is there a partial update for the FCM v1 provider used by Guardian push?
instructions:
- text: Patch the FCMv1 provider with new credentials {server_credentials}.
slots:
server_credentials: requestBody.server_credentials
- text: Rotate the FCM v1 service account to {server_credentials} without resetting other settings.
slots:
server_credentials: requestBody.server_credentials
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/push-notification/providers/sns'].get
update:
x-apievangelist-phrasing:
intent: Get the AWS SNS push MFA configuration
effect: read
questions:
- Which AWS region and platform application ARNs is push MFA using via SNS?
- Where can I view my AWS SNS push notification settings for MFA?
instructions:
- text: Show me the AWS SNS push notification configuration for MFA.
- text: Fetch the SNS APNs and GCM platform application ARNs used for push MFA.
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/push-notification/providers/sns'].put
update:
x-apievangelist-phrasing:
intent: Configure AWS SNS for push MFA from scratch
effect: write
questions:
- How do I route push MFA notifications through my own AWS SNS account?
- Can I replace the whole SNS push configuration with new AWS keys and region?
instructions:
- text: Configure SNS push MFA in region {aws_region} with access key {aws_access_key_id} and secret {aws_secret_access_key}.
slots:
aws_region: requestBody.aws_region
aws_access_key_id: requestBody.aws_access_key_id
aws_secret_access_key: requestBody.aws_secret_access_key
- text: Replace the SNS setup with APNs platform ARN {sns_apns_platform_application_arn}.
slots:
sns_apns_platform_application_arn: requestBody.sns_apns_platform_application_arn
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/push-notification/providers/sns'].patch
update:
x-apievangelist-phrasing:
intent: Change individual AWS SNS push MFA settings
effect: write
questions:
- Can I update only the GCM platform ARN in my existing SNS push setup?
- How would I rotate just the AWS secret key used for SNS push MFA?
instructions:
- text: Patch the SNS push setup with GCM platform ARN {sns_gcm_platform_application_arn}.
slots:
sns_gcm_platform_application_arn: requestBody.sns_gcm_platform_application_arn
- text: Update only the SNS AWS secret key to {aws_secret_access_key}.
slots:
aws_secret_access_key: requestBody.aws_secret_access_key
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/push-notification/selected-provider'].get
update:
x-apievangelist-phrasing:
intent: See which push notification provider MFA uses
effect: read
questions:
- Is push MFA currently delivered through Guardian, SNS or direct APNs/FCM?
- Which push notification provider is selected for my tenant?
instructions:
- text: Show me the selected push notification provider for MFA.
- text: Tell me which provider sends Guardian push notifications.
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/push-notification/selected-provider'].put
update:
x-apievangelist-phrasing:
intent: Choose the push notification provider for MFA
effect: write
questions:
- How do I switch push MFA to deliver through AWS SNS?
- Can I change the selected push notification provider for Guardian?
instructions:
- text: Set the push notification provider for MFA to {provider}.
slots:
provider: requestBody.provider
- text: Switch Guardian push delivery over to {provider}.
slots:
provider: requestBody.provider
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/sms/providers/twilio'].get
update:
x-apievangelist-phrasing:
intent: Get Twilio SMS MFA settings (deprecated endpoint)
effect: read
questions:
- What does the older SMS-only Twilio configuration endpoint return?
- Can I still read Twilio settings through the deprecated SMS factor path?
instructions:
- text: Fetch the Twilio configuration from the deprecated SMS factor endpoint.
- text: Show me the legacy SMS-factor Twilio settings.
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/sms/providers/twilio'].put
update:
x-apievangelist-phrasing:
intent: Update Twilio SMS MFA settings (deprecated endpoint)
effect: write
questions:
- Does the deprecated SMS Twilio endpoint still accept a new from-number?
- What fields does the older SMS-only Twilio update take?
instructions:
- text: Using the deprecated SMS endpoint, set the Twilio from-number to {from}.
slots:
from: requestBody.from
- text: Update the legacy SMS Twilio config with SID {sid} and auth token {auth_token}.
slots:
sid: requestBody.sid
auth_token: requestBody.auth_token
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/sms/selected-provider'].get
update:
x-apievangelist-phrasing:
intent: Get the SMS MFA provider (deprecated endpoint)
effect: read
questions:
- Which provider does the old SMS selected-provider endpoint report?
- Can I still check the SMS provider via the deprecated SMS path?
instructions:
- text: Read the selected SMS provider from the deprecated SMS endpoint.
- text: Show me the legacy SMS-factor provider selection.
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/sms/selected-provider'].put
update:
x-apievangelist-phrasing:
intent: Set the SMS MFA provider (deprecated endpoint)
effect: write
questions:
- Does the deprecated SMS selected-provider endpoint still let me pick a provider?
- What value does the legacy SMS provider update expect?
instructions:
- text: Using the deprecated SMS endpoint, set the SMS provider to {provider}.
slots:
provider: requestBody.provider
- text: Switch the legacy SMS-factor provider to {provider}.
slots:
provider: requestBody.provider
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/sms/templates'].get
update:
x-apievangelist-phrasing:
intent: Get SMS MFA message templates (deprecated endpoint)
effect: read
questions:
- What do the old SMS-only enrollment and verification templates say?
- Can I still read SMS templates through the deprecated SMS factor path?
instructions:
- text: Fetch the SMS enrollment and verification templates from the deprecated endpoint.
- text: Show me the legacy SMS-factor message templates.
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/sms/templates'].put
update:
x-apievangelist-phrasing:
intent: Update SMS MFA message templates (deprecated endpoint)
effect: write
questions:
- Does the deprecated SMS templates endpoint still let me change the message text?
- Which two messages must I send to the legacy SMS template update?
instructions:
- text: Using the deprecated SMS endpoint, set enrollment text {enrollment_message} and verification text {verification_message}.
slots:
enrollment_message: requestBody.enrollment_message
verification_message: requestBody.verification_message
- text: Update the legacy SMS templates so verification reads {verification_message} and enrollment reads {enrollment_message}.
slots:
verification_message: requestBody.verification_message
enrollment_message: requestBody.enrollment_message
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/factors/{name}'].put
update:
x-apievangelist-phrasing:
intent: Turn an MFA factor on or off
effect: write
questions:
- How do I enable one-time password MFA for my tenant?
- Can I disable a single MFA factor like email without touching the others?
instructions:
- text: Enable the {name} MFA factor by setting enabled to {enabled}.
slots:
name: path.name
enabled: requestBody.enabled
- text: Turn off the {name} factor (enabled {enabled}).
slots:
name: path.name
enabled: requestBody.enabled
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/policies'].get
update:
x-apievangelist-phrasing:
intent: Get the tenant's MFA policies
effect: read
questions:
- Is MFA required on every login or only when confidence is low?
- What multi-factor authentication policy is my tenant enforcing today?
instructions:
- text: Show me the MFA policies configured for my tenant.
- text: Tell me whether all-applications MFA is enforced.
method: generated
generated: '2026-10-01'
- target: $.paths['/guardian/policies'].put
update:
x-apievangelist-phrasing:
intent: Set the tenant's MFA policies
effect: write
questions:
- How do I require MFA for every application in my tenant?
- Can I switch to confidence-score based MFA instead of always prompting?
instructions:
- text: Set the MFA policy to require multi-factor on all applications.
- text: Replace the tenant MFA policies with the confidence-score policy.
method: generated
generated: '2026-10-01'