Authentik · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for authentik Authenticators API

84 actions 84 updates phrasing extends openapi/authentik-authenticators-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Authentik's API. It is a proposal applied on top of the contract, not a document Authentik publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 84 · first 16 shown; the file carries all of them

$.info
$.paths['/authenticators/admin/all/'].get
$.paths['/authenticators/admin/duo/'].get
$.paths['/authenticators/admin/duo/'].post
$.paths['/authenticators/admin/duo/{id}/'].get
$.paths['/authenticators/admin/duo/{id}/'].put
$.paths['/authenticators/admin/duo/{id}/'].delete
$.paths['/authenticators/admin/duo/{id}/'].patch
$.paths['/authenticators/admin/email/'].get
$.paths['/authenticators/admin/email/'].post
$.paths['/authenticators/admin/email/{id}/'].get
$.paths['/authenticators/admin/email/{id}/'].put
$.paths['/authenticators/admin/email/{id}/'].delete
$.paths['/authenticators/admin/email/{id}/'].patch
$.paths['/authenticators/admin/endpoint/'].get
$.paths['/authenticators/admin/endpoint/'].post

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for authentik Authenticators API
  version: 1.0.0
extends: openapi/authentik-authenticators-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 83
- target: $.paths['/authenticators/admin/all/'].get
  update:
    x-apievangelist-phrasing:
      intent: List every MFA device a user has (admin)
      effect: read
      questions:
      - As an admin, how can I see all of a given user's MFA devices across every type?
      - Can I pull one combined list of a user's authenticators instead of checking each device type?
      instructions:
      - text: As admin, list all authenticator devices belonging to user {user}.
        slots:
          user: query.user
      - text: Show every enrolled MFA device, of any type, for user {user}.
        slots:
          user: query.user
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/duo/'].get
  update:
    x-apievangelist-phrasing:
      intent: List all users' Duo devices (admin)
      effect: read
      questions:
      - Which Duo devices are enrolled across all users in authentik?
      - As an administrator, can I search every user's Duo devices by name?
      instructions:
      - text: As admin, list every Duo device in the instance.
      - text: Search all users' Duo devices for {search}.
        slots:
          search: query.search
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/duo/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a Duo device record (admin)
      effect: write
      questions:
      - Can an admin register a Duo device record directly through the API?
      - How do I add a Duo authenticator entry on behalf of a user?
      instructions:
      - text: As admin, create a Duo device named {name}.
        slots:
          name: requestBody.name
      - text: Add a new admin-managed Duo authenticator called {name}.
        slots:
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/duo/{id}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get any user's Duo device (admin)
      effect: read
      questions:
      - As an admin, how do I inspect a specific user's Duo device?
      - Can administrators look up any Duo device by its ID, not just their own?
      instructions:
      - text: As admin, show Duo device {id}.
        slots:
          id: path.id
      - text: Get the admin view of Duo authenticator {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/duo/{id}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace any user's Duo device (admin)
      effect: write
      questions:
      - As an admin, how do I fully overwrite another user's Duo device record?
      - Can an admin resubmit a Duo device with a new name via a full replace?
      instructions:
      - text: As admin, replace Duo device {id} with the name {name}.
        slots:
          id: path.id
          name: requestBody.name
      - text: Overwrite the whole admin record of Duo device {id}, naming it {name}.
        slots:
          id: path.id
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/duo/{id}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Remove any user's Duo device (admin)
      effect: destructive
      questions:
      - How can an admin remove a user's lost Duo device?
      - Can administrators delete a Duo enrollment for someone else?
      instructions:
      - text: As admin, delete Duo device {id}.
        slots:
          id: path.id
      - text: Remove another user's Duo enrollment {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/duo/{id}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Rename any user's Duo device (admin)
      effect: write
      questions:
      - As an admin, can I rename a user's Duo device without resending the whole record?
      - How does an administrator patch just the label on someone's Duo device?
      instructions:
      - text: As admin, rename Duo device {id} to {name}.
        slots:
          id: path.id
          name: requestBody.name
      - text: Patch only the name of another user's Duo device {id} to {name}.
        slots:
          id: path.id
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/email/'].get
  update:
    x-apievangelist-phrasing:
      intent: List all users' email authenticators (admin)
      effect: read
      questions:
      - Which email-based MFA devices exist across all users?
      - As an admin, can I search everyone's email authenticators by name?
      instructions:
      - text: As admin, list every email authenticator device.
      - text: Find email authenticators across all users named {name}.
        slots:
          name: query.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/email/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an email authenticator record (admin)
      effect: write
      questions:
      - Can an admin create an email MFA device through the API?
      - How do I add an email authenticator entry as an administrator?
      instructions:
      - text: As admin, create an email authenticator named {name}.
        slots:
          name: requestBody.name
      - text: Add an admin-managed email MFA device called {name}.
        slots:
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/email/{id}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get any user's email authenticator (admin)
      effect: read
      questions:
      - As an admin, how do I view a particular user's email authenticator?
      - Can an administrator open any email MFA device by ID?
      instructions:
      - text: As admin, show email authenticator {id}.
        slots:
          id: path.id
      - text: Get the admin view of email MFA device {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/email/{id}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace any user's email authenticator (admin)
      effect: write
      questions:
      - As an admin, how do I fully replace someone's email authenticator record?
      - Can administrators overwrite an email MFA device in a single PUT?
      instructions:
      - text: As admin, replace email authenticator {id} with the name {name}.
        slots:
          id: path.id
          name: requestBody.name
      - text: Overwrite the whole admin record of email device {id}, naming it {name}.
        slots:
          id: path.id
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/email/{id}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Remove any user's email authenticator (admin)
      effect: destructive
      questions:
      - How does an admin delete a user's email-based MFA device?
      - Can I remove another person's email authenticator as an administrator?
      instructions:
      - text: As admin, delete email authenticator {id}.
        slots:
          id: path.id
      - text: Remove another user's email MFA device {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/email/{id}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Rename any user's email authenticator (admin)
      effect: write
      questions:
      - As an admin, can I change only the name of a user's email authenticator?
      - How does an administrator patch the label on someone's email MFA device?
      instructions:
      - text: As admin, rename email authenticator {id} to {name}.
        slots:
          id: path.id
          name: requestBody.name
      - text: Patch only the name of another user's email device {id} to {name}.
        slots:
          id: path.id
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/endpoint/'].get
  update:
    x-apievangelist-phrasing:
      intent: List all endpoint devices (admin)
      effect: read
      questions:
      - Which endpoint authenticator devices are registered across all users?
      - As an admin, can I search endpoint devices by name?
      instructions:
      - text: As admin, list every endpoint authenticator device.
      - text: Search all endpoint devices for {search}.
        slots:
          search: query.search
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/endpoint/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an endpoint device record (admin)
      effect: write
      questions:
      - Can an admin register an endpoint authenticator device through the API?
      - How do I add a managed endpoint device as an administrator?
      instructions:
      - text: As admin, create an endpoint device named {name}.
        slots:
          name: requestBody.name
      - text: Register endpoint authenticator {name} with primary key {pk}.
        slots:
          name: requestBody.name
          pk: requestBody.pk
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/endpoint/{uuid}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get any endpoint device (admin)
      effect: read
      questions:
      - As an admin, how do I look up an endpoint authenticator device by UUID?
      - Can administrators view any user's endpoint device?
      instructions:
      - text: As admin, show endpoint device {uuid}.
        slots:
          uuid: path.uuid
      - text: Get the admin view of endpoint authenticator {uuid}.
        slots:
          uuid: path.uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/endpoint/{uuid}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace an endpoint device (admin)
      effect: write
      questions:
      - As an admin, how do I fully overwrite an endpoint device record?
      - Can an administrator replace an endpoint authenticator in one PUT request?
      instructions:
      - text: As admin, replace endpoint device {uuid} with the name {name}.
        slots:
          uuid: path.uuid
          name: requestBody.name
      - text: 'Overwrite the whole record of endpoint device {uuid}: name {name}, pk {pk}.'
        slots:
          uuid: path.uuid
          name: requestBody.name
          pk: requestBody.pk
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/endpoint/{uuid}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Remove an endpoint device (admin)
      effect: destructive
      questions:
      - How does an admin remove an endpoint authenticator device?
      - Can I delete a decommissioned endpoint device as an administrator?
      instructions:
      - text: As admin, delete endpoint device {uuid}.
        slots:
          uuid: path.uuid
      - text: Remove the decommissioned endpoint authenticator {uuid}.
        slots:
          uuid: path.uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/endpoint/{uuid}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Rename an endpoint device (admin)
      effect: write
      questions:
      - As an admin, can I rename an endpoint device without resending everything?
      - How do I patch just the label of an endpoint authenticator as an administrator?
      instructions:
      - text: As admin, rename endpoint device {uuid} to {name}.
        slots:
          uuid: path.uuid
          name: requestBody.name
      - text: Patch only the name of endpoint authenticator {uuid} to {name}.
        slots:
          uuid: path.uuid
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/sms/'].get
  update:
    x-apievangelist-phrasing:
      intent: List all users' SMS devices (admin)
      effect: read
      questions:
      - Which SMS-based MFA devices are enrolled across all users?
      - As an admin, can I search everyone's SMS authenticators by name?
      instructions:
      - text: As admin, list every SMS authenticator device.
      - text: Find SMS devices across all users named {name}.
        slots:
          name: query.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/sms/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an SMS device record (admin)
      effect: write
      questions:
      - Can an admin create an SMS MFA device through the API?
      - How do I add an SMS authenticator entry as an administrator?
      instructions:
      - text: As admin, create an SMS device named {name}.
        slots:
          name: requestBody.name
      - text: Add an admin-managed text-message authenticator called {name}.
        slots:
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/sms/{id}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get any user's SMS device (admin)
      effect: read
      questions:
      - As an admin, how do I view a specific user's SMS authenticator?
      - Can administrators open any SMS MFA device by ID?
      instructions:
      - text: As admin, show SMS device {id}.
        slots:
          id: path.id
      - text: Get the admin view of text-message authenticator {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/sms/{id}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace any user's SMS device (admin)
      effect: write
      questions:
      - As an admin, how do I fully replace someone's SMS device record?
      - Can administrators overwrite an SMS authenticator in a single PUT?
      instructions:
      - text: As admin, replace SMS device {id} with the name {name}.
        slots:
          id: path.id
          name: requestBody.name
      - text: Overwrite the whole admin record of SMS authenticator {id}, naming it {name}.
        slots:
          id: path.id
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/sms/{id}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Remove any user's SMS device (admin)
      effect: destructive
      questions:
      - How does an admin remove a user's SMS MFA device after a phone number change?
      - Can I delete another person's SMS authenticator as an administrator?
      instructions:
      - text: As admin, delete SMS device {id}.
        slots:
          id: path.id
      - text: Remove another user's text-message authenticator {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/sms/{id}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Rename any user's SMS device (admin)
      effect: write
      questions:
      - As an admin, can I change only the name of a user's SMS device?
      - How does an administrator patch the label on someone's SMS authenticator?
      instructions:
      - text: As admin, rename SMS device {id} to {name}.
        slots:
          id: path.id
          name: requestBody.name
      - text: Patch only the name of another user's SMS authenticator {id} to {name}.
        slots:
          id: path.id
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/static/'].get
  update:
    x-apievangelist-phrasing:
      intent: List all users' static token devices (admin)
      effect: read
      questions:
      - Which static recovery-code devices exist across all users?
      - As an admin, can I search everyone's static token authenticators?
      instructions:
      - text: As admin, list every static token device.
      - text: Search all users' static recovery-code devices for {search}.
        slots:
          search: query.search
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/static/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a static token device (admin)
      effect: write
      questions:
      - Can an admin create a static recovery-code device through the API?
      - How do I add a static token authenticator as an administrator?
      instructions:
      - text: As admin, create a static token device named {name}.
        slots:
          name: requestBody.name
      - text: Add an admin-managed recovery-code authenticator called {name}.
        slots:
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/static/{id}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get any user's static token device (admin)
      effect: read
      questions:
      - As an admin, how do I inspect a user's static recovery-code device?
      - Can administrators open any static token authenticator by ID?
      instructions:
      - text: As admin, show static token device {id}.
        slots:
          id: path.id
      - text: Get the admin view of recovery-code authenticator {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/static/{id}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace any user's static token device (admin)
      effect: write
      questions:
      - As an admin, how do I fully replace someone's static token device record?
      - Can administrators overwrite a recovery-code device in a single PUT?
      instructions:
      - text: As admin, replace static token device {id} with the name {name}.
        slots:
          id: path.id
          name: requestBody.name
      - text: Overwrite the whole admin record of recovery-code device {id}, naming it {name}.
        slots:
          id: path.id
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/static/{id}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Remove any user's static token device (admin)
      effect: destructive
      questions:
      - How does an admin revoke a user's static recovery codes?
      - Can I delete another person's static token device as an administrator?
      instructions:
      - text: As admin, delete static token device {id}.
        slots:
          id: path.id
      - text: Remove another user's recovery-code authenticator {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/static/{id}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Rename any user's static token device (admin)
      effect: write
      questions:
      - As an admin, can I change only the name of a user's static token device?
      - How does an administrator patch the label on someone's recovery-code device?
      instructions:
      - text: As admin, rename static token device {id} to {name}.
        slots:
          id: path.id
          name: requestBody.name
      - text: Patch only the name of another user's recovery-code device {id} to {name}.
        slots:
          id: path.id
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/totp/'].get
  update:
    x-apievangelist-phrasing:
      intent: List all users' TOTP devices (admin)
      effect: read
      questions:
      - Which authenticator-app (TOTP) devices are enrolled across all users?
      - As an admin, can I search everyone's TOTP devices by name?
      instructions:
      - text: As admin, list every TOTP device.
      - text: Find TOTP authenticator apps across all users named {name}.
        slots:
          name: query.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/totp/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a TOTP device record (admin)
      effect: write
      questions:
      - Can an admin create a TOTP authenticator-app device through the API?
      - How do I add a time-based one-time password device as an administrator?
      instructions:
      - text: As admin, create a TOTP device named {name}.
        slots:
          name: requestBody.name
      - text: Add an admin-managed authenticator-app device called {name}.
        slots:
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/totp/{id}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get any user's TOTP device (admin)
      effect: read
      questions:
      - As an admin, how do I view a specific user's TOTP device?
      - Can administrators open any authenticator-app device by ID?
      instructions:
      - text: As admin, show TOTP device {id}.
        slots:
          id: path.id
      - text: Get the admin view of authenticator-app device {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/totp/{id}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace any user's TOTP device (admin)
      effect: write
      questions:
      - What's the admin call to resend a user's entire TOTP authenticator-app record?
      - Can administrators overwrite an authenticator-app device in a single PUT?
      instructions:
      - text: As admin, replace TOTP device {id} with the name {name}.
        slots:
          id: path.id
          name: requestBody.name
      - text: Overwrite the whole admin record of authenticator-app device {id}, naming it {name}.
        slots:
          id: path.id
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/totp/{id}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Remove any user's TOTP device (admin)
      effect: destructive
      questions:
      - How does an admin reset MFA for a user who lost the phone with their authenticator app?
      - Can I delete another person's TOTP device as an administrator?
      instructions:
      - text: As admin, delete TOTP device {id}.
        slots:
          id: path.id
      - text: Remove another user's authenticator-app device {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/totp/{id}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Rename any user's TOTP device (admin)
      effect: write
      questions:
      - Is there a way for an admin to relabel one user's TOTP authenticator app without a full replace?
      - How does an administrator patch the label on someone's authenticator-app device?
      instructions:
      - text: As admin, rename TOTP device {id} to {name}.
        slots:
          id: path.id
          name: requestBody.name
      - text: Patch only the name of another user's authenticator-app device {id} to {name}.
        slots:
          id: path.id
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/webauthn/'].get
  update:
    x-apievangelist-phrasing:
      intent: List all users' WebAuthn devices (admin)
      effect: read
      questions:
      - Which security keys and passkeys are registered across all users?
      - As an admin, can I search everyone's WebAuthn devices by name?
      instructions:
      - text: As admin, list every WebAuthn device.
      - text: Search all users' passkeys and security keys for {search}.
        slots:
          search: query.search
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/webauthn/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a WebAuthn device record (admin)
      effect: write
      questions:
      - Can an admin create a WebAuthn device record through the API?
      - How do I add a security key entry as an administrator?
      instructions:
      - text: As admin, create a WebAuthn device named {name}.
        slots:
          name: requestBody.name
      - text: Add an admin-managed security key record called {name}.
        slots:
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/webauthn/{id}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get any user's WebAuthn device (admin)
      effect: read
      questions:
      - As an admin, how do I inspect a specific user's passkey or security key?
      - Can administrators open any WebAuthn device by ID?
      instructions:
      - text: As admin, show WebAuthn device {id}.
        slots:
          id: path.id
      - text: Get the admin view of security key {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/webauthn/{id}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace any user's WebAuthn device (admin)
      effect: write
      questions:
      - What's the admin call to resend a user's entire WebAuthn passkey record?
      - Can administrators overwrite a security key record in a single PUT?
      instructions:
      - text: As admin, replace WebAuthn device {id} with the name {name}.
        slots:
          id: path.id
          name: requestBody.name
      - text: Overwrite the whole admin record of security key {id}, naming it {name}.
        slots:
          id: path.id
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/webauthn/{id}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Remove any user's WebAuthn device (admin)
      effect: destructive
      questions:
      - How does an admin revoke a user's lost security key?
      - Can I delete another person's passkey as an administrator?
      instructions:
      - text: As admin, delete WebAuthn device {id}.
        slots:
          id: path.id
      - text: Remove another user's security key {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/admin/webauthn/{id}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Rename any user's WebAuthn device (admin)
      effect: write
      questions:
      - Is there a way for an admin to relabel one user's WebAuthn passkey without a full replace?
      - How does an administrator patch the label on someone's security key?
      instructions:
      - text: As admin, rename WebAuthn device {id} to {name}.
        slots:
          id: path.id
          name: requestBody.name
      - text: Patch only the name of another user's security key {id} to {name}.
        slots:
          id: path.id
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/all/'].get
  update:
    x-apievangelist-phrasing:
      intent: List all of my MFA devices
      effect: read
      questions:
      - What MFA devices do I have enrolled on my own account?
      - Can I see all my authenticators of every type in one list?
      instructions:
      - text: List all my enrolled authenticator devices.
      - text: Show every MFA method on my account, whatever the type.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/duo/'].get
  update:
    x-apievangelist-phrasing:
      intent: List my Duo devices
      effect: read
      questions:
      - Which Duo devices are set up on my own account?
      - Can I search my Duo devices by name?
      instructions:
      - text: List my Duo devices.
      - text: Find my own Duo device named {name}.
        slots:
          name: query.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/duo/{id}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get one of my Duo devices
      effect: read
      questions:
      - How do I see the details of a Duo device on my account?
      - Can I look up my own Duo enrollment by ID?
      instructions:
      - text: Show my Duo device {id}.
        slots:
          id: path.id
      - text: Get details of my own Duo enrollment {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/duo/{id}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace one of my Duo devices
      effect: write
      questions:
      - How do I resubmit my Duo device record with a new name?
      - Can I fully replace my own Duo device entry with a PUT?
      instructions:
      - text: Replace my Duo device {id} with the name {name}.
        slots:
          id: path.id
          name: requestBody.name
      - text: Overwrite my own Duo device record {id}, setting its name to {name}.
        slots:
          id: path.id
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/duo/{id}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Remove one of my Duo devices
      effect: destructive
      questions:
      - How do I unenroll a Duo device from my account?
      - Can I delete my own old Duo device?
      instructions:
      - text: Delete my Duo device {id}.
        slots:
          id: path.id
      - text: Unenroll my own Duo device {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/duo/{id}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Rename one of my Duo devices
      effect: write
      questions:
      - Can I give my Duo device a friendlier name?
      - How do I change only the label on my own Duo device?
      instructions:
      - text: Rename my Duo device {id} to {name}.
        slots:
          id: path.id
          name: requestBody.name
      - text: Change just the name of my own Duo device {id} to {name}.
        slots:
          id: path.id
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/duo/{id}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what references my Duo device
      effect: read
      questions:
      - What objects in authentik reference my Duo device?
      - Is anything still using a Duo device before I remove it?
      instructions:
      - text: List everything that uses Duo device {id}.
        slots:
          id: path.id
      - text: Check what depends on my Duo device {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/authenticators/email/'].get
  update:
    x-apievangelist-phrasing:
      intent: List my email authenticators
      effect: read
      questions:
      - Which email MFA devices are set up on my own account?
      - Can I search my email authenticators by name?
      instructions:
      - text: List my email authenticators.
      - text: Find my own email MFA device named {name}.
        slots:
          name: query.name
      method: generated
      generated: '2026-09-26'


# --- truncated at 32 KB (50 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/authentik/refs/heads/main/overlays/authentik-authenticators-api-phrasing-overlay.yaml