Auth0 · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Auth0 Management Keys API
15 actions
15 updates
phrasing
extends
openapi/auth0-keys-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Auth0's API. It is a proposal applied on top of the contract, not a document Auth0 publishes.
What the actions change
x-apievangelist-phrasing
Targets 15
$.info
$.paths['/keys/custom-signing'].get
$.paths['/keys/custom-signing'].put
$.paths['/keys/custom-signing'].delete
$.paths['/keys/encryption'].get
$.paths['/keys/encryption'].post
$.paths['/keys/encryption/rekey'].post
$.paths['/keys/encryption/{kid}'].get
$.paths['/keys/encryption/{kid}'].post
$.paths['/keys/encryption/{kid}'].delete
$.paths['/keys/encryption/{kid}/wrapping-key'].post
$.paths['/keys/signing'].get
$.paths['/keys/signing/rotate'].post
$.paths['/keys/signing/{kid}'].get
$.paths['/keys/signing/{kid}/revoke'].put
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Auth0 Management Keys API
version: 1.0.0
extends: openapi/auth0-keys-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-10-01'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 14
- target: $.paths['/keys/custom-signing'].get
update:
x-apievangelist-phrasing:
intent: Get the custom signing keys JWKS
effect: read
questions:
- What custom signing keys have I uploaded to my tenant?
- Can I see the full JWKS of my bring-your-own signing keys?
instructions:
- text: Show me my custom signing keys JWKS.
- text: Fetch the public keys I uploaded for custom token signing.
method: generated
generated: '2026-10-01'
- target: $.paths['/keys/custom-signing'].put
update:
x-apievangelist-phrasing:
intent: Create or replace the custom signing keys JWKS
effect: write
questions:
- How do I upload my own public keys for custom token signing?
- Does setting custom signing keys replace the whole existing set?
instructions:
- text: Replace my custom signing keys with {keys}.
slots:
keys: requestBody.keys
- text: 'Upload this JWKS key set as my custom signing keys: {keys}.'
slots:
keys: requestBody.keys
method: generated
generated: '2026-10-01'
- target: $.paths['/keys/custom-signing'].delete
update:
x-apievangelist-phrasing:
intent: Delete all custom signing keys
effect: destructive
questions:
- How do I remove every custom signing key I uploaded?
- Can I clear out my bring-your-own signing key set entirely?
instructions:
- text: Delete my custom signing keys.
- text: Remove the whole custom signing JWKS from the tenant.
method: generated
generated: '2026-10-01'
- target: $.paths['/keys/encryption'].get
update:
x-apievangelist-phrasing:
intent: List the tenant's encryption keys
effect: read
questions:
- Which encryption keys does my tenant currently hold?
- Can I get a total count of encryption keys when listing them?
instructions:
- text: List all encryption keys in my tenant.
- text: Show page {page} of encryption keys with totals included.
slots:
page: query.page
method: generated
generated: '2026-10-01'
- target: $.paths['/keys/encryption'].post
update:
x-apievangelist-phrasing:
intent: Create a pre-activated encryption key
effect: write
questions:
- How do I start bringing my own encryption key to my tenant?
- What key type do I need to specify when creating a new encryption key?
instructions:
- text: Create a new encryption key of type {type}.
slots:
type: requestBody.type
- text: Set up a pre-activated {type} encryption key without key material.
slots:
type: requestBody.type
method: generated
generated: '2026-10-01'
- target: $.paths['/keys/encryption/rekey'].post
update:
x-apievangelist-phrasing:
intent: Rekey the encryption key hierarchy
effect: write
questions:
- How do I rotate the whole encryption key hierarchy?
- Is there a single call to rekey my tenant's encryption keys?
instructions:
- text: Rekey my tenant's encryption key hierarchy.
- text: Run a rekey operation on all encryption keys.
method: generated
generated: '2026-10-01'
- target: $.paths['/keys/encryption/{kid}'].get
update:
x-apievangelist-phrasing:
intent: Get one encryption key by key ID
effect: read
questions:
- What is the state and type of a specific encryption key?
- Can I look up an encryption key by its kid?
instructions:
- text: Show me encryption key {kid}.
slots:
kid: path.kid
- text: Check the state of encryption key {kid}.
slots:
kid: path.kid
method: generated
generated: '2026-10-01'
- target: $.paths['/keys/encryption/{kid}'].post
update:
x-apievangelist-phrasing:
intent: Import wrapped key material and activate a key
effect: write
questions:
- How do I import my own wrapped encryption key material?
- What activates a pre-created encryption key?
instructions:
- text: Import wrapped key {wrapped_key} into encryption key {kid}.
slots:
wrapped_key: requestBody.wrapped_key
kid: path.kid
- text: Activate encryption key {kid} with my wrapped key material {wrapped_key}.
slots:
kid: path.kid
wrapped_key: requestBody.wrapped_key
method: generated
generated: '2026-10-01'
- target: $.paths['/keys/encryption/{kid}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a customer-provided encryption key
effect: destructive
questions:
- How do I go back to native encryption after bringing my own key?
- What happens when I delete a custom encryption key?
instructions:
- text: Delete encryption key {kid}.
slots:
kid: path.kid
- text: Remove my custom key {kid} and revert to the native encryption key.
slots:
kid: path.kid
method: generated
generated: '2026-10-01'
- target: $.paths['/keys/encryption/{kid}/wrapping-key'].post
update:
x-apievangelist-phrasing:
intent: Create a public wrapping key for key import
effect: write
questions:
- Where do I get a public key to wrap my encryption key material before import?
- Is a wrapping key needed before importing my own encryption key?
instructions:
- text: Create a public wrapping key for encryption key {kid}.
slots:
kid: path.kid
- text: Generate the wrapping key I need to wrap material for {kid}.
slots:
kid: path.kid
method: generated
generated: '2026-10-01'
- target: $.paths['/keys/signing'].get
update:
x-apievangelist-phrasing:
intent: List application signing keys
effect: read
questions:
- Which application signing keys are current, next and previous in my tenant?
- Can I see all the keys used to sign tokens for my applications?
instructions:
- text: List all application signing keys.
- text: Show me the current and next token signing keys.
method: generated
generated: '2026-10-01'
- target: $.paths['/keys/signing/rotate'].post
update:
x-apievangelist-phrasing:
intent: Rotate the application signing key
effect: write
questions:
- How do I rotate the key that signs my tenant's tokens?
- Can I promote the next signing key to current in one step?
instructions:
- text: Rotate my application signing key.
- text: Roll the tenant's token signing key now.
method: generated
generated: '2026-10-01'
- target: $.paths['/keys/signing/{kid}'].get
update:
x-apievangelist-phrasing:
intent: Get one application signing key by key ID
effect: read
questions:
- What is the certificate and status of a specific signing key?
- Can I fetch a signing key by its kid to check if it's revoked?
instructions:
- text: Show me signing key {kid}.
slots:
kid: path.kid
- text: Check whether signing key {kid} has been revoked.
slots:
kid: path.kid
method: generated
generated: '2026-10-01'
- target: $.paths['/keys/signing/{kid}/revoke'].put
update:
x-apievangelist-phrasing:
intent: Revoke an application signing key
effect: destructive
questions:
- How do I revoke a signing key I think was compromised?
- Can a previous signing key be revoked by its key ID?
instructions:
- text: Revoke signing key {kid}.
slots:
kid: path.kid
- text: Invalidate the compromised application signing key {kid}.
slots:
kid: path.kid
method: generated
generated: '2026-10-01'