Authentik · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for authentik Endpoints API

71 actions 71 updates phrasing extends openapi/authentik-endpoints-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Authentik's API. It is a proposal applied on top of the contract, not a document Authentik publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 71 · first 16 shown; the file carries all of them

$.info
$.paths['/endpoints/agents/connectors/'].get
$.paths['/endpoints/agents/connectors/'].post
$.paths['/endpoints/agents/connectors/{connector_uuid}/'].get
$.paths['/endpoints/agents/connectors/{connector_uuid}/'].put
$.paths['/endpoints/agents/connectors/{connector_uuid}/'].delete
$.paths['/endpoints/agents/connectors/{connector_uuid}/'].patch
$.paths['/endpoints/agents/connectors/{connector_uuid}/mdm_config/'].post
$.paths['/endpoints/agents/connectors/{connector_uuid}/used_by/'].get
$.paths['/endpoints/agents/connectors/agent_config/'].get
$.paths['/endpoints/agents/connectors/auth_fed/'].post
$.paths['/endpoints/agents/connectors/auth_ia/'].post
$.paths['/endpoints/agents/connectors/check_in/'].post
$.paths['/endpoints/agents/connectors/enroll/'].post
$.paths['/endpoints/agents/enrollment_tokens/'].get
$.paths['/endpoints/agents/enrollment_tokens/'].post

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for authentik Endpoints API
  version: 1.0.0
extends: openapi/authentik-endpoints-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 70
- target: $.paths['/endpoints/agents/connectors/'].get
  update:
    x-apievangelist-phrasing:
      intent: List authentik Agent connectors
      effect: read
      questions:
      - Which authentik Agent connectors are set up for my devices?
      - Can I see only the Agent connectors that are currently enabled?
      instructions:
      - text: List all authentik Agent connectors.
      - text: Show Agent connectors named {name}.
        slots:
          name: query.name
      - text: List Agent connectors where enabled is {enabled}.
        slots:
          enabled: query.enabled
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/connectors/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an authentik Agent connector
      effect: write
      questions:
      - How do I set up a new connector for the authentik Agent on endpoints?
      - Can a new Agent connector set how long device auth sessions last?
      instructions:
      - text: Create an Agent connector named {name}.
        slots:
          name: requestBody.name
      - text: Add a new Agent connector {name} with a refresh interval of {refresh_interval}.
        slots:
          name: requestBody.name
          refresh_interval: requestBody.refresh_interval
      - text: Create Agent connector {name} using authorization flow {authorization_flow}.
        slots:
          name: requestBody.name
          authorization_flow: requestBody.authorization_flow
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/connectors/{connector_uuid}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an authentik Agent connector
      effect: read
      questions:
      - What settings does a particular Agent connector have?
      - Is the NSS UID offset configured on this Agent connector?
      instructions:
      - text: Show Agent connector {connector_uuid}.
        slots:
          connector_uuid: path.connector_uuid
      - text: Fetch the snapshot expiry and session settings of Agent connector {connector_uuid}.
        slots:
          connector_uuid: path.connector_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/connectors/{connector_uuid}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace an Agent connector's settings
      effect: write
      questions:
      - Can I overwrite the full configuration of an Agent connector in one call?
      - What do I have to resend when fully replacing an Agent connector?
      instructions:
      - text: Replace every setting of Agent connector {connector_uuid}, naming it {name}.
        slots:
          connector_uuid: path.connector_uuid
          name: requestBody.name
      - text: Fully rewrite Agent connector {connector_uuid} as {name} with auth session duration {auth_session_duration}.
        slots:
          connector_uuid: path.connector_uuid
          name: requestBody.name
          auth_session_duration: requestBody.auth_session_duration
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/connectors/{connector_uuid}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an authentik Agent connector
      effect: destructive
      questions:
      - How do I remove an Agent connector I no longer use?
      - Is deleting an Agent connector permanent?
      instructions:
      - text: Delete Agent connector {connector_uuid}.
        slots:
          connector_uuid: path.connector_uuid
      - text: Remove the authentik Agent connector {connector_uuid}.
        slots:
          connector_uuid: path.connector_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/connectors/{connector_uuid}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Change some settings on an Agent connector
      effect: write
      questions:
      - Can I just disable an Agent connector without touching its other settings?
      - Is it possible to change only the challenge idle timeout on an Agent connector?
      instructions:
      - text: On Agent connector {connector_uuid}, only set enabled to {enabled}.
        slots:
          connector_uuid: path.connector_uuid
          enabled: requestBody.enabled
      - text: Change just the challenge idle timeout of Agent connector {connector_uuid} to {challenge_idle_timeout}.
        slots:
          connector_uuid: path.connector_uuid
          challenge_idle_timeout: requestBody.challenge_idle_timeout
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/connectors/{connector_uuid}/mdm_config/'].post
  update:
    x-apievangelist-phrasing:
      intent: Generate MDM config to deploy the Agent
      effect: read
      questions:
      - How do I get a configuration profile to push the authentik Agent through my MDM?
      - Which platform and enrollment token does the MDM deployment config need?
      instructions:
      - text: Generate MDM configuration for connector {connector_uuid} on platform {platform} with enrollment token {enrollment_token}.
        slots:
          connector_uuid: path.connector_uuid
          platform: requestBody.platform
          enrollment_token: requestBody.enrollment_token
      - text: Build the MDM deployment profile for Agent connector {connector_uuid} targeting {platform}.
        slots:
          connector_uuid: path.connector_uuid
          platform: requestBody.platform
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/connectors/{connector_uuid}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses an Agent connector
      effect: read
      questions:
      - What objects depend on this Agent connector?
      - Would removing an Agent connector break anything else?
      instructions:
      - text: Show everything that references Agent connector {connector_uuid}.
        slots:
          connector_uuid: path.connector_uuid
      - text: List objects using Agent connector {connector_uuid}.
        slots:
          connector_uuid: path.connector_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/connectors/agent_config/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the running Agent's configuration
      effect: read
      questions:
      - Where does the installed authentik Agent fetch its own configuration from?
      - Can the Agent on a device read the config its connector assigns it?
      instructions:
      - text: Fetch the Agent configuration for this device.
      - text: Get the config the authentik Agent should run with.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/connectors/auth_fed/'].post
  update:
    x-apievangelist-phrasing:
      intent: Authenticate a device via federated JWT
      effect: write
      questions:
      - How does an enrolled device sign in to authentik using a federated token?
      - Can a device exchange a JWT from a federation provider for an Agent session?
      instructions:
      - text: Run federated authentication for device {device}.
        slots:
          device: query.device
      - text: Authenticate device {device} through JWT federation.
        slots:
          device: query.device
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/connectors/auth_ia/'].post
  update:
    x-apievangelist-phrasing:
      intent: Start interactive Agent authentication
      effect: write
      questions:
      - How does the Agent start an interactive login for a user on a device?
      - Can I pass a login hint when the Agent begins interactive auth?
      instructions:
      - text: Begin interactive Agent authentication.
      - text: Start interactive authentication with login hint {login_hint}.
        slots:
          login_hint: query.login_hint
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/connectors/check_in/'].post
  update:
    x-apievangelist-phrasing:
      intent: Report a device check-in from the Agent
      effect: write
      questions:
      - How does the Agent report a device's OS, disks and installed software to authentik?
      - What inventory can a device send when it checks in?
      instructions:
      - text: Send a device check-in with operating system {os} and vendor {vendor}.
        slots:
          os: requestBody.os
          vendor: requestBody.vendor
      - text: Check in this device reporting hardware {hardware} and software {software}.
        slots:
          hardware: requestBody.hardware
          software: requestBody.software
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/connectors/enroll/'].post
  update:
    x-apievangelist-phrasing:
      intent: Enroll a device with the Agent
      effect: write
      questions:
      - How do I enroll a new laptop into authentik endpoint management?
      - Which details does a device need to provide to enroll?
      instructions:
      - text: Enroll device {device_name} with serial number {device_serial}.
        slots:
          device_name: requestBody.device_name
          device_serial: requestBody.device_serial
      - text: Register the machine with serial {device_serial} as {device_name}.
        slots:
          device_serial: requestBody.device_serial
          device_name: requestBody.device_name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/enrollment_tokens/'].get
  update:
    x-apievangelist-phrasing:
      intent: List device enrollment tokens
      effect: read
      questions:
      - What enrollment tokens exist for enrolling devices?
      - Can I see only the enrollment tokens tied to one connector?
      instructions:
      - text: List all device enrollment tokens.
      - text: Show enrollment tokens for connector {connector}.
        slots:
          connector: query.connector
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/enrollment_tokens/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a device enrollment token
      effect: write
      questions:
      - How do I make a token that devices use to enroll with the Agent?
      - Can an enrollment token expire and drop devices into a device group?
      instructions:
      - text: Create enrollment token {name} for connector {connector}.
        slots:
          name: requestBody.name
          connector: requestBody.connector
      - text: Make an enrollment token {name} on connector {connector} that expires at {expires}.
        slots:
          name: requestBody.name
          connector: requestBody.connector
          expires: requestBody.expires
      - text: Create token {name} for connector {connector} placing devices in group {device_group}.
        slots:
          name: requestBody.name
          connector: requestBody.connector
          device_group: requestBody.device_group
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/enrollment_tokens/{token_uuid}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a device enrollment token
      effect: read
      questions:
      - What connector and expiry does a given enrollment token have?
      - Which device group will an enrollment token assign?
      instructions:
      - text: Show enrollment token {token_uuid}.
        slots:
          token_uuid: path.token_uuid
      - text: Fetch the details of enrollment token {token_uuid}.
        slots:
          token_uuid: path.token_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/enrollment_tokens/{token_uuid}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace an enrollment token's settings
      effect: write
      questions:
      - Can I overwrite all fields of an enrollment token at once?
      - What must I resend when fully replacing an enrollment token?
      instructions:
      - text: Replace enrollment token {token_uuid} with name {name} on connector {connector}.
        slots:
          token_uuid: path.token_uuid
          name: requestBody.name
          connector: requestBody.connector
      - text: Fully rewrite enrollment token {token_uuid} as {name} for connector {connector}, expiring {expires}.
        slots:
          token_uuid: path.token_uuid
          name: requestBody.name
          connector: requestBody.connector
          expires: requestBody.expires
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/enrollment_tokens/{token_uuid}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a device enrollment token
      effect: destructive
      questions:
      - How do I revoke an enrollment token so no more devices can use it?
      - Is deleting an enrollment token irreversible?
      instructions:
      - text: Delete enrollment token {token_uuid}.
        slots:
          token_uuid: path.token_uuid
      - text: Remove device enrollment token {token_uuid}.
        slots:
          token_uuid: path.token_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/enrollment_tokens/{token_uuid}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Change part of an enrollment token
      effect: write
      questions:
      - Can I just extend an enrollment token's expiry without changing anything else?
      - Is it possible to only move an enrollment token to another device group?
      instructions:
      - text: Only set the expiry of enrollment token {token_uuid} to {expires}.
        slots:
          token_uuid: path.token_uuid
          expires: requestBody.expires
      - text: Change just the device group of enrollment token {token_uuid} to {device_group}.
        slots:
          token_uuid: path.token_uuid
          device_group: requestBody.device_group
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/enrollment_tokens/{token_uuid}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses an enrollment token
      effect: read
      questions:
      - Which objects reference a particular enrollment token?
      - What would be affected if I removed this enrollment token?
      instructions:
      - text: Show what depends on enrollment token {token_uuid}.
        slots:
          token_uuid: path.token_uuid
      - text: List objects referencing enrollment token {token_uuid}.
        slots:
          token_uuid: path.token_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/enrollment_tokens/{token_uuid}/view_key/'].get
  update:
    x-apievangelist-phrasing:
      intent: Reveal an enrollment token's key
      effect: read
      questions:
      - How do I see the actual secret key of an enrollment token?
      - Is viewing an enrollment token's key logged?
      instructions:
      - text: Reveal the key for enrollment token {token_uuid}.
        slots:
          token_uuid: path.token_uuid
      - text: Show me the secret value of enrollment token {token_uuid}.
        slots:
          token_uuid: path.token_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/psso/ise/'].get
  update:
    x-apievangelist-phrasing:
      intent: List Platform SSO Secure Enclave keys
      effect: read
      questions:
      - Which Apple Secure Enclave keys are registered for Platform SSO?
      - Can I filter Platform SSO enclave keys by user?
      instructions:
      - text: List all Platform SSO Secure Enclave key registrations.
      - text: Show Secure Enclave keys registered for user {user}.
        slots:
          user: query.user
      - text: Find the Secure Enclave registration with key ID {apple_enclave_key_id}.
        slots:
          apple_enclave_key_id: query.apple_enclave_key_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/psso/ise/'].post
  update:
    x-apievangelist-phrasing:
      intent: Register a Secure Enclave key for a user
      effect: write
      questions:
      - How do I register an Apple Secure Enclave key for a user's Platform SSO?
      - What does a new Platform SSO enclave key record need?
      instructions:
      - text: Register Secure Enclave key {apple_secure_enclave_key} with ID {apple_enclave_key_id} for user {user} on a {device_type}.
        slots:
          apple_secure_enclave_key: requestBody.apple_secure_enclave_key
          apple_enclave_key_id: requestBody.apple_enclave_key_id
          user: requestBody.user
          device_type: requestBody.device_type
      - text: Save a {device_type} Secure Enclave key {apple_secure_enclave_key} (ID {apple_enclave_key_id}) so {user} can use Platform SSO.
        slots:
          device_type: requestBody.device_type
          apple_secure_enclave_key: requestBody.apple_secure_enclave_key
          apple_enclave_key_id: requestBody.apple_enclave_key_id
          user: requestBody.user
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/psso/ise/{uuid}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a Secure Enclave key registration
      effect: read
      questions:
      - Which user and device type does a Secure Enclave key record belong to?
      - Can I look up one Platform SSO enclave key registration?
      instructions:
      - text: Show Secure Enclave key registration {uuid}.
        slots:
          uuid: path.uuid
      - text: Fetch the Platform SSO enclave key record {uuid}.
        slots:
          uuid: path.uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/psso/ise/{uuid}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace a Secure Enclave key registration
      effect: write
      questions:
      - Can I overwrite every field of a Platform SSO enclave key record?
      - What is required to fully replace a Secure Enclave key registration?
      instructions:
      - text: Replace enclave key record {uuid} with key {apple_secure_enclave_key}, ID {apple_enclave_key_id}, user {user}, device type {device_type}.
        slots:
          uuid: path.uuid
          apple_secure_enclave_key: requestBody.apple_secure_enclave_key
          apple_enclave_key_id: requestBody.apple_enclave_key_id
          user: requestBody.user
          device_type: requestBody.device_type
      - text: 'Overwrite all of enclave registration {uuid}: user {user}, key {apple_secure_enclave_key}, key ID {apple_enclave_key_id}, type {device_type}.'
        slots:
          uuid: path.uuid
          user: requestBody.user
          apple_secure_enclave_key: requestBody.apple_secure_enclave_key
          apple_enclave_key_id: requestBody.apple_enclave_key_id
          device_type: requestBody.device_type
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/psso/ise/{uuid}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a Secure Enclave key registration
      effect: destructive
      questions:
      - How do I remove a user's Platform SSO Secure Enclave key?
      - Is removing an enclave key registration permanent?
      instructions:
      - text: Delete Secure Enclave key registration {uuid}.
        slots:
          uuid: path.uuid
      - text: Remove the Platform SSO enclave key {uuid}.
        slots:
          uuid: path.uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/psso/ise/{uuid}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Change part of a Secure Enclave key record
      effect: write
      questions:
      - Can I just reassign a Secure Enclave key record to another user?
      - Is it possible to only change the device type on an enclave key registration?
      instructions:
      - text: Only change the user of enclave key record {uuid} to {user}.
        slots:
          uuid: path.uuid
          user: requestBody.user
      - text: Set just the device type of Secure Enclave registration {uuid} to {device_type}.
        slots:
          uuid: path.uuid
          device_type: requestBody.device_type
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/psso/ise/{uuid}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses a Secure Enclave key record
      effect: read
      questions:
      - What objects reference a given Platform SSO enclave key?
      - Does anything depend on this Secure Enclave key registration?
      instructions:
      - text: Show what references Secure Enclave registration {uuid}.
        slots:
          uuid: path.uuid
      - text: List objects using enclave key record {uuid}.
        slots:
          uuid: path.uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/psso/register/device/'].post
  update:
    x-apievangelist-phrasing:
      intent: Register a device for Platform SSO
      effect: write
      questions:
      - How does a Mac register its signing and encryption keys for Platform SSO?
      - Which device keys are needed to register for Platform SSO?
      instructions:
      - text: Register this device for Platform SSO with signing key {device_signing_key} ({sign_key_id}) and encryption key {device_encryption_key} ({enc_key_id}).
        slots:
          device_signing_key: requestBody.device_signing_key
          sign_key_id: requestBody.sign_key_id
          device_encryption_key: requestBody.device_encryption_key
          enc_key_id: requestBody.enc_key_id
      - text: 'Enroll this Mac in Platform SSO: key IDs {sign_key_id} and {enc_key_id}, keys {device_signing_key} and {device_encryption_key}.'
        slots:
          sign_key_id: requestBody.sign_key_id
          enc_key_id: requestBody.enc_key_id
          device_signing_key: requestBody.device_signing_key
          device_encryption_key: requestBody.device_encryption_key
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/agents/psso/register/user/'].post
  update:
    x-apievangelist-phrasing:
      intent: Register a user for Platform SSO
      effect: write
      questions:
      - How does a user register their Secure Enclave key for Platform SSO sign-in?
      - What must a user send to complete Platform SSO user registration?
      instructions:
      - text: Register the Platform SSO user with auth {user_auth}, enclave key {user_secure_enclave_key} and key ID {enclave_key_id}.
        slots:
          user_auth: requestBody.user_auth
          user_secure_enclave_key: requestBody.user_secure_enclave_key
          enclave_key_id: requestBody.enclave_key_id
      - text: Complete Platform SSO user registration using enclave key ID {enclave_key_id}, key {user_secure_enclave_key} and credentials {user_auth}.
        slots:
          enclave_key_id: requestBody.enclave_key_id
          user_secure_enclave_key: requestBody.user_secure_enclave_key
          user_auth: requestBody.user_auth
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/connectors/'].get
  update:
    x-apievangelist-phrasing:
      intent: List all endpoint connectors of any type
      effect: read
      questions:
      - What endpoint connectors of every kind are configured?
      - Can I search across all device connectors regardless of type?
      instructions:
      - text: List every endpoint connector, whatever its type.
      - text: Search all endpoint connectors for {search}.
        slots:
          search: query.search
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/connectors/{connector_uuid}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get any endpoint connector by ID
      effect: read
      questions:
      - How can I look up an endpoint connector when I don't know its type?
      - What type is a given endpoint connector?
      instructions:
      - text: Show endpoint connector {connector_uuid} regardless of type.
        slots:
          connector_uuid: path.connector_uuid
      - text: Look up generic endpoint connector {connector_uuid}.
        slots:
          connector_uuid: path.connector_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/connectors/{connector_uuid}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete any endpoint connector
      effect: destructive
      questions:
      - Can I delete an endpoint connector without knowing whether it's Fleet, Chrome or Agent?
      - Is deleting a generic endpoint connector permanent?
      instructions:
      - text: Delete endpoint connector {connector_uuid} of whatever type.
        slots:
          connector_uuid: path.connector_uuid
      - text: Remove generic endpoint connector {connector_uuid}.
        slots:
          connector_uuid: path.connector_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/connectors/{connector_uuid}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses any endpoint connector
      effect: read
      questions:
      - What depends on an endpoint connector of any type?
      - Before removing a generic connector, what references it?
      instructions:
      - text: Show what uses generic endpoint connector {connector_uuid}.
        slots:
          connector_uuid: path.connector_uuid
      - text: List dependents of endpoint connector {connector_uuid} across all connector types.
        slots:
          connector_uuid: path.connector_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/connectors/types/'].get
  update:
    x-apievangelist-phrasing:
      intent: List creatable endpoint connector types
      effect: read
      questions:
      - What kinds of endpoint connectors can I create?
      - Which device connector types does this authentik version support?
      instructions:
      - text: List the endpoint connector types I can create.
      - text: Show all available connector types for device management.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/device_access_groups/'].get
  update:
    x-apievangelist-phrasing:
      intent: List device access groups
      effect: read
      questions:
      - Which device access groups have been defined?
      - Can I find a device access group by name?
      instructions:
      - text: List all device access groups.
      - text: Show device access groups named {name}.
        slots:
          name: query.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/device_access_groups/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a device access group
      effect: write
      questions:
      - How do I create a group to control access for a set of devices?
      - Can a new device access group carry custom attributes?
      instructions:
      - text: Create a device access group named {name}.
        slots:
          name: requestBody.name
      - text: Add device access group {name} with attributes {attributes}.
        slots:
          name: requestBody.name
          attributes: requestBody.attributes
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/device_access_groups/{pbm_uuid}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a device access group
      effect: read
      questions:
      - What attributes are set on a specific device access group?
      - Can I view one device access group's details?
      instructions:
      - text: Show device access group {pbm_uuid}.
        slots:
          pbm_uuid: path.pbm_uuid
      - text: Fetch the attributes of device access group {pbm_uuid}.
        slots:
          pbm_uuid: path.pbm_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/device_access_groups/{pbm_uuid}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace a device access group
      effect: write
      questions:
      - Can I overwrite a device access group's name and attributes together?
      - What does a full replacement of a device access group require?
      instructions:
      - text: Replace device access group {pbm_uuid} with name {name}.
        slots:
          pbm_uuid: path.pbm_uuid
          name: requestBody.name
      - text: Fully rewrite device access group {pbm_uuid} as {name} with attributes {attributes}.
        slots:
          pbm_uuid: path.pbm_uuid
          name: requestBody.name
          attributes: requestBody.attributes
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/device_access_groups/{pbm_uuid}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a device access group
      effect: destructive
      questions:
      - How do I remove a device access group?
      - Is deleting a device access group reversible?
      instructions:
      - text: Delete device access group {pbm_uuid}.
        slots:
          pbm_uuid: path.pbm_uuid
      - text: Remove the device access group {pbm_uuid}.
        slots:
          pbm_uuid: path.pbm_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/device_access_groups/{pbm_uuid}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Change part of a device access group
      effect: write
      questions:
      - Can I just rename a device access group?
      - Is it possible to only update the attributes of a device access group?
      instructions:
      - text: Only rename device access group {pbm_uuid} to {name}.
        slots:
          pbm_uuid: path.pbm_uuid
          name: requestBody.name
      - text: Change just the attributes of device access group {pbm_uuid} to {attributes}.
        slots:
          pbm_uuid: path.pbm_uuid
          attributes: requestBody.attributes
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/device_access_groups/{pbm_uuid}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses a device access group
      effect: read
      questions:
      - Which devices or objects reference a device access group?
      - What would break if I deleted this device access group?
      instructions:
      - text: Show what references device access group {pbm_uuid}.
        slots:
          pbm_uuid: path.pbm_uuid
      - text: List objects using device access group {pbm_uuid}.
        slots:
          pbm_uuid: path.pbm_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/endpoints/device_bindings/'].get
  update:
    x-apievangelist-phrasing:
      intent: List device policy bindings
      effect: read
      questions:
      - Which policies, users or groups are bound to device access targets?
      - Can I list only the enabled device bindings for one target?
      instructions:
      - text: List all device policy bindings.
      - text: Show device bindings for target {target}.
        slots:
          target: query.target
      - text: List device bindings that use policy {policy}.
        slots:
          policy: query.policy
      method: generated
      generated: '2026-09-26'


# --- truncated at 32 KB (50 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/authentik/refs/heads/main/overlays/authentik-endpoints-api-phrasing-overlay.yaml