Authentik · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for authentik Core API

79 actions 79 updates phrasing extends openapi/authentik-core-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Authentik's API. It is a proposal applied on top of the contract, not a document Authentik publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 79 · first 16 shown; the file carries all of them

$.info
$.paths['/core/application_entitlements/'].get
$.paths['/core/application_entitlements/'].post
$.paths['/core/application_entitlements/{pbm_uuid}/'].get
$.paths['/core/application_entitlements/{pbm_uuid}/'].put
$.paths['/core/application_entitlements/{pbm_uuid}/'].delete
$.paths['/core/application_entitlements/{pbm_uuid}/'].patch
$.paths['/core/application_entitlements/{pbm_uuid}/used_by/'].get
$.paths['/core/application_entitlements/requestable/'].get
$.paths['/core/applications/'].get
$.paths['/core/applications/'].post
$.paths['/core/applications/{slug}/'].get
$.paths['/core/applications/{slug}/'].put
$.paths['/core/applications/{slug}/'].delete
$.paths['/core/applications/{slug}/'].patch
$.paths['/core/applications/{slug}/check_access/'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for authentik Core API
  version: 1.0.0
extends: openapi/authentik-core-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 78
- target: $.paths['/core/application_entitlements/'].get
  update:
    x-apievangelist-phrasing:
      intent: List application entitlements
      effect: read
      questions:
      - Which entitlements are defined for my applications in authentik?
      - Can I filter entitlements to a single application?
      instructions:
      - text: List all application entitlements.
      - text: Show entitlements defined for application {app}.
        slots:
          app: query.app
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/application_entitlements/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an application entitlement
      effect: write
      questions:
      - How do I define a new entitlement that users of an application can be granted?
      - Can I attach custom attributes to a new entitlement?
      instructions:
      - text: Create entitlement {name} for application {app}.
        slots:
          name: requestBody.name
          app: requestBody.app
      - text: Add a new entitlement {name} on app {app} with attributes {attributes}.
        slots:
          name: requestBody.name
          app: requestBody.app
          attributes: requestBody.attributes
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/application_entitlements/{pbm_uuid}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an application entitlement
      effect: read
      questions:
      - What attributes does a specific entitlement carry?
      - Which application does a given entitlement belong to?
      instructions:
      - text: Get entitlement {pbm_uuid}.
        slots:
          pbm_uuid: path.pbm_uuid
      - text: Show the name, app and attributes of entitlement {pbm_uuid}.
        slots:
          pbm_uuid: path.pbm_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/application_entitlements/{pbm_uuid}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace an application entitlement
      effect: write
      questions:
      - Can I fully overwrite an existing entitlement's name and application?
      - What must I resend to replace an entitlement completely?
      instructions:
      - text: Replace entitlement {pbm_uuid} with name {name} on app {app}.
        slots:
          pbm_uuid: path.pbm_uuid
          name: requestBody.name
          app: requestBody.app
      - text: Overwrite entitlement {pbm_uuid} so it is {name} for application {app}.
        slots:
          pbm_uuid: path.pbm_uuid
          name: requestBody.name
          app: requestBody.app
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/application_entitlements/{pbm_uuid}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an application entitlement
      effect: destructive
      questions:
      - Can I remove an entitlement that is no longer needed?
      - What permanently deletes an application entitlement?
      instructions:
      - text: Delete entitlement {pbm_uuid}.
        slots:
          pbm_uuid: path.pbm_uuid
      - text: Remove application entitlement {pbm_uuid} permanently.
        slots:
          pbm_uuid: path.pbm_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/application_entitlements/{pbm_uuid}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Edit fields on an entitlement
      effect: write
      questions:
      - Can I rename an entitlement without resending its application?
      - Is it possible to change only an entitlement's attributes?
      instructions:
      - text: Rename entitlement {pbm_uuid} to {name}.
        slots:
          pbm_uuid: path.pbm_uuid
          name: requestBody.name
      - text: Set only the attributes of entitlement {pbm_uuid} to {attributes}.
        slots:
          pbm_uuid: path.pbm_uuid
          attributes: requestBody.attributes
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/application_entitlements/{pbm_uuid}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses an entitlement
      effect: read
      questions:
      - Which objects depend on a given entitlement before I delete it?
      - Is an entitlement still referenced by any policy binding?
      instructions:
      - text: List everything that uses entitlement {pbm_uuid}.
        slots:
          pbm_uuid: path.pbm_uuid
      - text: Show objects referencing entitlement {pbm_uuid}.
        slots:
          pbm_uuid: path.pbm_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/application_entitlements/requestable/'].get
  update:
    x-apievangelist-phrasing:
      intent: List entitlements I can request
      effect: read
      questions:
      - Which entitlements am I allowed to request access to?
      - Can I see requestable entitlements for just one application?
      instructions:
      - text: List the entitlements the current user can request.
      - text: Show requestable entitlements for application {app}.
        slots:
          app: query.app
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/applications/'].get
  update:
    x-apievangelist-phrasing:
      intent: List applications
      effect: read
      questions:
      - What applications are configured in my authentik instance?
      - Can I list only applications that have a launch URL, or those a particular user can access?
      instructions:
      - text: List applications in group {group}.
        slots:
          group: query.group
      - text: Show the applications user {for_user} has access to.
        slots:
          for_user: query.for_user
      - text: Search applications for {search}.
        slots:
          search: query.search
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/applications/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an application
      effect: write
      questions:
      - How do I register a new application in authentik?
      - Can I link a provider and a launch URL when creating an application?
      instructions:
      - text: Create application {name} with slug {slug}.
        slots:
          name: requestBody.name
          slug: requestBody.slug
      - text: Create application {name} ({slug}) using provider {provider} and launch URL {meta_launch_url}.
        slots:
          name: requestBody.name
          slug: requestBody.slug
          provider: requestBody.provider
          meta_launch_url: requestBody.meta_launch_url
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/applications/{slug}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an application
      effect: read
      questions:
      - Which provider is attached to a given application?
      - What launch URL and publisher does an application show?
      instructions:
      - text: Get application {slug}.
        slots:
          slug: path.slug
      - text: Show the provider and metadata for application {slug}.
        slots:
          slug: path.slug
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/applications/{slug}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace an application
      effect: write
      questions:
      - Can I overwrite an application's whole configuration in one call?
      - What happens to unset fields when I replace an application entirely?
      instructions:
      - text: Replace application {slug} with name {name} and new slug {new_slug}.
        slots:
          slug: path.slug
          name: requestBody.name
          new_slug: requestBody.slug
      - text: Overwrite application {slug} as {name}, bound to provider {provider}.
        slots:
          slug: path.slug
          name: requestBody.name
          provider: requestBody.provider
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/applications/{slug}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an application
      effect: destructive
      questions:
      - Can I remove an application from authentik for good?
      - What deletes an application I retired?
      instructions:
      - text: Delete application {slug}.
        slots:
          slug: path.slug
      - text: Remove application {slug} permanently.
        slots:
          slug: path.slug
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/applications/{slug}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Edit fields on an application
      effect: write
      questions:
      - Can I hide an application from the user library without changing anything else?
      - Is it possible to change just an application's icon or description?
      instructions:
      - text: Set meta-hide to {meta_hide} on application {slug}.
        slots:
          meta_hide: requestBody.meta_hide
          slug: path.slug
      - text: Change only the launch URL of application {slug} to {meta_launch_url}.
        slots:
          slug: path.slug
          meta_launch_url: requestBody.meta_launch_url
      - text: Update the description of application {slug} to {meta_description}.
        slots:
          slug: path.slug
          meta_description: requestBody.meta_description
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/applications/{slug}/check_access/'].get
  update:
    x-apievangelist-phrasing:
      intent: Check access to an application
      effect: read
      questions:
      - Does a specific user pass the policies to open an application?
      - Why is someone being denied access to an app?
      instructions:
      - text: Check whether user {for_user} can access application {slug}.
        slots:
          for_user: query.for_user
          slug: path.slug
      - text: Test my own access to application {slug}.
        slots:
          slug: path.slug
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/applications/{slug}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses an application
      effect: read
      questions:
      - Which objects reference an application before I delete it?
      - Is an application still used by any brand or binding?
      instructions:
      - text: List everything that uses application {slug}.
        slots:
          slug: path.slug
      - text: Show objects that depend on application {slug}.
        slots:
          slug: path.slug
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/applications/requestable/'].get
  update:
    x-apievangelist-phrasing:
      intent: List applications I can request
      effect: read
      questions:
      - Which applications can I ask to be given access to?
      - Can I search requestable applications by name?
      instructions:
      - text: List the applications the current user can request access to.
      - text: Find requestable applications named {name}.
        slots:
          name: query.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/authenticated_sessions/'].get
  update:
    x-apievangelist-phrasing:
      intent: List signed-in sessions
      effect: read
      questions:
      - Who is currently logged in to authentik, and from where?
      - Can I find sessions by a user's username or last IP address?
      instructions:
      - text: List active sessions for user {username}.
        slots:
          username: query.user__username
      - text: Show sessions last seen from IP {ip}.
        slots:
          ip: query.session__last_ip
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/authenticated_sessions/{uuid}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a signed-in session
      effect: read
      questions:
      - What device and IP is a specific session coming from?
      - Can I inspect one authenticated session by its id?
      instructions:
      - text: Get session {uuid}.
        slots:
          uuid: path.uuid
      - text: Show the user agent and last IP of session {uuid}.
        slots:
          uuid: path.uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/authenticated_sessions/{uuid}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Revoke a session
      effect: destructive
      questions:
      - Can I log out one specific session remotely?
      - What ends a single suspicious login session?
      instructions:
      - text: Revoke session {uuid}.
        slots:
          uuid: path.uuid
      - text: Sign out the single session {uuid}.
        slots:
          uuid: path.uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/authenticated_sessions/{uuid}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses a session
      effect: read
      questions:
      - Which objects reference a given authenticated session?
      - Does anything depend on a session before I revoke it?
      instructions:
      - text: List objects that use session {uuid}.
        slots:
          uuid: path.uuid
      - text: Show what references authenticated session {uuid}.
        slots:
          uuid: path.uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/authenticated_sessions/bulk_delete/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Revoke all sessions for several users
      effect: destructive
      questions:
      - Can I force-logout several users at once?
      - Is there a way to kill every session belonging to a list of users?
      instructions:
      - text: Revoke all sessions for users {user_pks}.
        slots:
          user_pks: query.user_pks
      - text: Log out every session of the users with ids {user_pks}.
        slots:
          user_pks: query.user_pks
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/brands/'].get
  update:
    x-apievangelist-phrasing:
      intent: List brands
      effect: read
      questions:
      - Which brands are configured, and which domain does each serve?
      - Can I find the default brand or brands using a given authentication flow?
      instructions:
      - text: List all brands.
      - text: Find the brand for domain {domain}.
        slots:
          domain: query.domain
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/brands/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a brand
      effect: write
      questions:
      - How do I add a new brand for another domain with its own logo and title?
      - Can I assign custom flows and a web certificate when creating a brand?
      instructions:
      - text: Create a brand for domain {domain}.
        slots:
          domain: requestBody.domain
      - text: Create a brand on {domain} titled {branding_title} with logo {branding_logo}.
        slots:
          domain: requestBody.domain
          branding_title: requestBody.branding_title
          branding_logo: requestBody.branding_logo
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/brands/{brand_uuid}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a brand
      effect: read
      questions:
      - Which flows and certificate does a particular brand use?
      - What logo and title is set on a brand?
      instructions:
      - text: Get brand {brand_uuid}.
        slots:
          brand_uuid: path.brand_uuid
      - text: Show the branding and flows of brand {brand_uuid}.
        slots:
          brand_uuid: path.brand_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/brands/{brand_uuid}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace a brand
      effect: write
      questions:
      - Can I overwrite a brand's entire configuration at once?
      - What happens to flows I leave out when replacing a brand?
      instructions:
      - text: Replace brand {brand_uuid} with domain {domain}.
        slots:
          brand_uuid: path.brand_uuid
          domain: requestBody.domain
      - text: Overwrite brand {brand_uuid} on {domain} with title {branding_title}.
        slots:
          brand_uuid: path.brand_uuid
          domain: requestBody.domain
          branding_title: requestBody.branding_title
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/brands/{brand_uuid}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a brand
      effect: destructive
      questions:
      - Can I remove a brand I no longer serve?
      - What deletes a brand permanently?
      instructions:
      - text: Delete brand {brand_uuid}.
        slots:
          brand_uuid: path.brand_uuid
      - text: Remove brand {brand_uuid} for good.
        slots:
          brand_uuid: path.brand_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/brands/{brand_uuid}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Edit fields on a brand
      effect: write
      questions:
      - Can I change just a brand's favicon or custom CSS?
      - Is it possible to swap only the recovery flow on a brand?
      instructions:
      - text: Set the custom CSS of brand {brand_uuid} to {branding_custom_css}.
        slots:
          brand_uuid: path.brand_uuid
          branding_custom_css: requestBody.branding_custom_css
      - text: Change only the recovery flow on brand {brand_uuid} to {flow_recovery}.
        slots:
          brand_uuid: path.brand_uuid
          flow_recovery: requestBody.flow_recovery
      - text: Update the favicon of brand {brand_uuid} to {branding_favicon}.
        slots:
          brand_uuid: path.brand_uuid
          branding_favicon: requestBody.branding_favicon
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/brands/{brand_uuid}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses a brand
      effect: read
      questions:
      - Which objects reference a brand before I delete it?
      - Is a brand still in use anywhere?
      instructions:
      - text: List everything that uses brand {brand_uuid}.
        slots:
          brand_uuid: path.brand_uuid
      - text: Show objects depending on brand {brand_uuid}.
        slots:
          brand_uuid: path.brand_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/brands/current/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the brand for the current request
      effect: read
      questions:
      - Which brand is being served for the domain I'm on right now?
      - What title and logo apply to the current request?
      instructions:
      - text: Get the current brand.
      - text: Show the brand that applies to this request's domain.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/groups/'].get
  update:
    x-apievangelist-phrasing:
      intent: List groups
      effect: read
      questions:
      - What groups exist in authentik, and who belongs to them?
      - Can I find the groups a particular username is a member of?
      instructions:
      - text: List groups that include member {username}.
        slots:
          username: query.members_by_username
      - text: Search groups for {search}, including their users.
        slots:
          search: query.search
      - text: Show superuser groups only, is-superuser = {is_superuser}.
        slots:
          is_superuser: query.is_superuser
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/groups/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a group
      effect: write
      questions:
      - How do I create a new group and put users in it?
      - Can a new group inherit from parent groups or get roles assigned?
      instructions:
      - text: Create group {name}.
        slots:
          name: requestBody.name
      - text: Create group {name} with members {users} under parents {parents}.
        slots:
          name: requestBody.name
          users: requestBody.users
          parents: requestBody.parents
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/groups/{group_uuid}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a group
      effect: read
      questions:
      - Who are the members of a specific group?
      - Can I see a group's parents, children and inherited roles?
      instructions:
      - text: Get group {group_uuid}.
        slots:
          group_uuid: path.group_uuid
      - text: Show group {group_uuid} with its users and inherited roles.
        slots:
          group_uuid: path.group_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/groups/{group_uuid}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace a group
      effect: write
      questions:
      - Can I overwrite a group's whole definition, member list included?
      - What must I send to fully replace a group?
      instructions:
      - text: Replace group {group_uuid} with name {name}.
        slots:
          group_uuid: path.group_uuid
          name: requestBody.name
      - text: Overwrite group {group_uuid} as {name} with exactly members {users}.
        slots:
          group_uuid: path.group_uuid
          name: requestBody.name
          users: requestBody.users
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/groups/{group_uuid}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a group
      effect: destructive
      questions:
      - Can I remove a group entirely?
      - What deletes a group I no longer need?
      instructions:
      - text: Delete group {group_uuid}.
        slots:
          group_uuid: path.group_uuid
      - text: Remove group {group_uuid} permanently.
        slots:
          group_uuid: path.group_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/groups/{group_uuid}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Edit fields on a group
      effect: write
      questions:
      - Can I rename a group without touching its members?
      - Is it possible to grant a group superuser status on its own?
      instructions:
      - text: Rename group {group_uuid} to {name}.
        slots:
          group_uuid: path.group_uuid
          name: requestBody.name
      - text: Set is-superuser to {is_superuser} on group {group_uuid}.
        slots:
          is_superuser: requestBody.is_superuser
          group_uuid: path.group_uuid
      - text: Change only the roles of group {group_uuid} to {roles}.
        slots:
          group_uuid: path.group_uuid
          roles: requestBody.roles
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/groups/{group_uuid}/add_user/'].post
  update:
    x-apievangelist-phrasing:
      intent: Add a user to a group
      effect: write
      questions:
      - How do I add one person to an existing group?
      - Can I add a single member without rewriting the group's user list?
      instructions:
      - text: Add user {pk} to group {group_uuid}.
        slots:
          pk: requestBody.pk
          group_uuid: path.group_uuid
      - text: Put user id {pk} into group {group_uuid}.
        slots:
          pk: requestBody.pk
          group_uuid: path.group_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/groups/{group_uuid}/remove_user/'].post
  update:
    x-apievangelist-phrasing:
      intent: Remove a user from a group
      effect: write
      questions:
      - Can I take one member out of a group?
      - What removes a single user from a group without deleting the user?
      instructions:
      - text: Remove user {pk} from group {group_uuid}.
        slots:
          pk: requestBody.pk
          group_uuid: path.group_uuid
      - text: Drop user id {pk} out of group {group_uuid}.
        slots:
          pk: requestBody.pk
          group_uuid: path.group_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/groups/{group_uuid}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses a group
      effect: read
      questions:
      - Which policies or bindings reference a group?
      - Is a group still used anywhere before I delete it?
      instructions:
      - text: List everything that uses group {group_uuid}.
        slots:
          group_uuid: path.group_uuid
      - text: Show objects that depend on group {group_uuid}.
        slots:
          group_uuid: path.group_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/object_attributes/'].get
  update:
    x-apievangelist-phrasing:
      intent: List custom object attributes
      effect: read
      questions:
      - Which custom attribute definitions exist for users or other models?
      - Can I list only enabled attribute definitions for a given model?
      instructions:
      - text: List custom attribute definitions for model {model}.
        slots:
          model: query.object_type__model
      - text: Show object attributes with enabled = {enabled}.
        slots:
          enabled: query.enabled
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/object_attributes/'].post
  update:
    x-apievangelist-phrasing:
      intent: Define a custom object attribute
      effect: write
      questions:
      - How do I add a custom field definition to a model such as users?
      - Can a custom attribute be required, unique or validated with a regex?
      instructions:
      - text: Create attribute {key} labelled {label} of type {type} on {object_type}.
        slots:
          key: requestBody.key
          label: requestBody.label
          type: requestBody.type
          object_type: requestBody.object_type
      - text: Define required attribute {key} ({label}, {type}) on {object_type} with regex {regex}.
        slots:
          key: requestBody.key
          label: requestBody.label
          type: requestBody.type
          object_type: requestBody.object_type
          regex: requestBody.regex
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/object_attributes/{attribute_id}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a custom attribute definition
      effect: read
      questions:
      - What type and validation rules does a custom attribute have?
      - Is a particular attribute definition required or unique?
      instructions:
      - text: Get attribute definition {attribute_id}.
        slots:
          attribute_id: path.attribute_id
      - text: Show the key, type and regex of attribute {attribute_id}.
        slots:
          attribute_id: path.attribute_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/object_attributes/{attribute_id}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace a custom attribute definition
      effect: write
      questions:
      - Can I fully redefine an existing custom attribute?
      - What fields must be resent to replace an attribute definition?
      instructions:
      - text: Replace attribute {attribute_id} with key {key}, label {label}, type {type} on {object_type}.
        slots:
          attribute_id: path.attribute_id
          key: requestBody.key
          label: requestBody.label
          type: requestBody.type
          object_type: requestBody.object_type
      - text: Overwrite attribute definition {attribute_id} as {key} of type {type} for {object_type}, labelled {label}.
        slots:
          attribute_id: path.attribute_id
          key: requestBody.key
          type: requestBody.type
          object_type: requestBody.object_type
          label: requestBody.label
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/object_attributes/{attribute_id}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a custom attribute definition
      effect: destructive
      questions:
      - Can I remove a custom attribute definition I no longer want?
      - What deletes an object attribute definition?
      instructions:
      - text: Delete attribute definition {attribute_id}.
        slots:
          attribute_id: path.attribute_id
      - text: Remove custom attribute {attribute_id}.
        slots:
          attribute_id: path.attribute_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/object_attributes/{attribute_id}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Edit a custom attribute definition
      effect: write
      questions:
      - Can I disable a custom attribute without deleting it?
      - Is it possible to change only an attribute's label?
      instructions:
      - text: Set enabled to {enabled} on attribute {attribute_id}.
        slots:
          enabled: requestBody.enabled
          attribute_id: path.attribute_id
      - text: Change the label of attribute {attribute_id} to {label}.
        slots:
          attribute_id: path.attribute_id
          label: requestBody.label
      - text: 'Make attribute {attribute_id} required: {is_required}.'
        slots:
          attribute_id: path.attribute_id
          is_required: requestBody.is_required
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/tokens/'].get
  update:
    x-apievangelist-phrasing:
      intent: List tokens
      effect: read
      questions:
      - What API and app-password tokens exist in authentik?
      - Can I list only the tokens belonging to one username or with a given intent?
      instructions:
      - text: List tokens owned by {username}.
        slots:
          username: query.user__username
      - text: Show tokens with intent {intent}.
        slots:
          intent: query.intent
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/tokens/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a token
      effect: write
      questions:
      - How do I create an API token for a user?
      - Can I make a token that expires on a specific date?
      instructions:
      - text: Create token {identifier} with intent {intent}.
        slots:
          identifier: requestBody.identifier
          intent: requestBody.intent
      - text: Create token {identifier} for user {user} expiring at {expires}.
        slots:
          identifier: requestBody.identifier
          user: requestBody.user
          expires: requestBody.expires
      method: generated
      generated: '2026-09-26'
- target: $.paths['/core/tokens/{identifier}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a token's details
      effect: read
      questions:
      - When does a specific token expire and who owns it?
      - Can I see a token's metadata without revealing its secret?
      instructions:
      - text: Get token {identifier}.
        slots:
          identifier: path.identifier
      - text: Show the owner, intent and expiry of token {identifier}.
        slots:
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'


# --- truncated at 32 KB (49 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/authentik/refs/heads/main/overlays/authentik-core-api-phrasing-overlay.yaml