Authentik · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for authentik Crypto API
11 actions
11 updates
phrasing
extends
openapi/authentik-crypto-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Authentik's API. It is a proposal applied on top of the contract, not a document Authentik publishes.
What the actions change
x-apievangelist-phrasing
Targets 11
$.info
$.paths['/crypto/certificatekeypairs/'].get
$.paths['/crypto/certificatekeypairs/'].post
$.paths['/crypto/certificatekeypairs/{kp_uuid}/'].get
$.paths['/crypto/certificatekeypairs/{kp_uuid}/'].put
$.paths['/crypto/certificatekeypairs/{kp_uuid}/'].delete
$.paths['/crypto/certificatekeypairs/{kp_uuid}/'].patch
$.paths['/crypto/certificatekeypairs/{kp_uuid}/used_by/'].get
$.paths['/crypto/certificatekeypairs/{kp_uuid}/view_certificate/'].get
$.paths['/crypto/certificatekeypairs/{kp_uuid}/view_private_key/'].get
$.paths['/crypto/certificatekeypairs/generate/'].post
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for authentik Crypto API
version: 1.0.0
extends: openapi/authentik-crypto-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 10
- target: $.paths['/crypto/certificatekeypairs/'].get
update:
x-apievangelist-phrasing:
intent: List certificate-key pairs
effect: read
questions:
- Which certificates and key pairs are stored in my authentik instance?
- Can I list only the certificate-key pairs that include a private key?
- Is there a way to filter certificates by key type or whether authentik manages them?
instructions:
- text: List all certificate-key pairs.
- text: 'Show only certificate-key pairs that have a private key: {has_key}.'
slots:
has_key: query.has_key
- text: Find certificate-key pairs of key type {key_type} named {name}.
slots:
key_type: query.key_type
name: query.name
method: generated
generated: '2026-09-26'
- target: $.paths['/crypto/certificatekeypairs/'].post
update:
x-apievangelist-phrasing:
intent: Import a certificate-key pair
effect: write
questions:
- How do I upload an existing PEM certificate so authentik can use it?
- Can I import a certificate without its private key?
instructions:
- text: Import certificate {certificate_data} as a new keypair called {name}.
slots:
certificate_data: requestBody.certificate_data
name: requestBody.name
- text: Upload PEM certificate {certificate_data} with private key {key_data} under the name {name}.
slots:
certificate_data: requestBody.certificate_data
key_data: requestBody.key_data
name: requestBody.name
method: generated
generated: '2026-09-26'
- target: $.paths['/crypto/certificatekeypairs/{kp_uuid}/'].get
update:
x-apievangelist-phrasing:
intent: Get a certificate-key pair
effect: read
questions:
- What are the details of one certificate-key pair, like its fingerprint and expiry?
- Can I look up a single stored certificate by its UUID?
instructions:
- text: Show the details of certificate-key pair {kp_uuid}.
slots:
kp_uuid: path.kp_uuid
- text: Get the metadata for keypair {kp_uuid}.
slots:
kp_uuid: path.kp_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/crypto/certificatekeypairs/{kp_uuid}/'].put
update:
x-apievangelist-phrasing:
intent: Replace a certificate-key pair
effect: write
questions:
- How do I swap in a renewed certificate on an existing keypair?
- Can I fully replace the name and PEM data of a stored certificate in one call?
instructions:
- text: Replace keypair {kp_uuid} with name {name} and certificate {certificate_data}.
slots:
kp_uuid: path.kp_uuid
name: requestBody.name
certificate_data: requestBody.certificate_data
- text: Overwrite keypair {kp_uuid} entirely with certificate {certificate_data}, key {key_data} and name {name}.
slots:
kp_uuid: path.kp_uuid
certificate_data: requestBody.certificate_data
key_data: requestBody.key_data
name: requestBody.name
method: generated
generated: '2026-09-26'
- target: $.paths['/crypto/certificatekeypairs/{kp_uuid}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete a certificate-key pair
effect: destructive
questions:
- How do I remove a certificate I no longer need from authentik?
- What happens when I delete a keypair that something still uses?
instructions:
- text: Delete certificate-key pair {kp_uuid}.
slots:
kp_uuid: path.kp_uuid
- text: Remove the stored certificate {kp_uuid} permanently.
slots:
kp_uuid: path.kp_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/crypto/certificatekeypairs/{kp_uuid}/'].patch
update:
x-apievangelist-phrasing:
intent: Edit fields on a certificate-key pair
effect: write
questions:
- Can I just rename a certificate-key pair without re-uploading it?
- How do I add a private key to a certificate that was imported without one?
instructions:
- text: Rename keypair {kp_uuid} to {name}.
slots:
kp_uuid: path.kp_uuid
name: requestBody.name
- text: Attach private key {key_data} to the existing keypair {kp_uuid}.
slots:
key_data: requestBody.key_data
kp_uuid: path.kp_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/crypto/certificatekeypairs/{kp_uuid}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses a certificate-key pair
effect: read
questions:
- Which providers or sources depend on this certificate before I rotate it?
- Is a certificate still referenced by anything in authentik?
instructions:
- text: List every object that uses certificate {kp_uuid}.
slots:
kp_uuid: path.kp_uuid
- text: Check what depends on keypair {kp_uuid} before I delete it.
slots:
kp_uuid: path.kp_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/crypto/certificatekeypairs/{kp_uuid}/view_certificate/'].get
update:
x-apievangelist-phrasing:
intent: View or download a certificate
effect: read
questions:
- How do I get the PEM text of a certificate stored in authentik?
- Can I download a certificate as a file, and is that access logged?
instructions:
- text: Show the certificate PEM for keypair {kp_uuid}.
slots:
kp_uuid: path.kp_uuid
- text: 'Download the public certificate of {kp_uuid} as a file: {download}.'
slots:
kp_uuid: path.kp_uuid
download: query.download
method: generated
generated: '2026-09-26'
- target: $.paths['/crypto/certificatekeypairs/{kp_uuid}/view_private_key/'].get
update:
x-apievangelist-phrasing:
intent: View or download a private key
effect: read
questions:
- How can I export the private key that belongs to a stored keypair?
- Does authentik record an audit event when someone views a private key?
instructions:
- text: Reveal the private key for keypair {kp_uuid}.
slots:
kp_uuid: path.kp_uuid
- text: 'Download the private key of {kp_uuid} as a file: {download}.'
slots:
kp_uuid: path.kp_uuid
download: query.download
method: generated
generated: '2026-09-26'
- target: $.paths['/crypto/certificatekeypairs/generate/'].post
update:
x-apievangelist-phrasing:
intent: Generate a self-signed certificate
effect: write
questions:
- Can authentik create a self-signed certificate for me?
- How long can a generated certificate be valid, and can I add subject alternative names?
- Which key algorithm can I choose when generating a new keypair?
instructions:
- text: Generate a self-signed certificate for {common_name} valid for {validity_days} days.
slots:
common_name: requestBody.common_name
validity_days: requestBody.validity_days
- text: Create a new self-signed keypair for {common_name} with SANs {subject_alt_name}, {validity_days} days, algorithm {alg}.
slots:
common_name: requestBody.common_name
subject_alt_name: requestBody.subject_alt_name
validity_days: requestBody.validity_days
alg: requestBody.alg
method: generated
generated: '2026-09-26'