Authentik · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for authentik Oauth2 API
13 actions
13 updates
phrasing
extends
openapi/authentik-oauth2-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Authentik's API. It is a proposal applied on top of the contract, not a document Authentik publishes.
What the actions change
x-apievangelist-phrasing
Targets 13
$.info
$.paths['/oauth2/access_tokens/'].get
$.paths['/oauth2/access_tokens/{id}/'].get
$.paths['/oauth2/access_tokens/{id}/'].delete
$.paths['/oauth2/access_tokens/{id}/used_by/'].get
$.paths['/oauth2/authorization_codes/'].get
$.paths['/oauth2/authorization_codes/{id}/'].get
$.paths['/oauth2/authorization_codes/{id}/'].delete
$.paths['/oauth2/authorization_codes/{id}/used_by/'].get
$.paths['/oauth2/refresh_tokens/'].get
$.paths['/oauth2/refresh_tokens/{id}/'].get
$.paths['/oauth2/refresh_tokens/{id}/'].delete
$.paths['/oauth2/refresh_tokens/{id}/used_by/'].get
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for authentik Oauth2 API
version: 1.0.0
extends: openapi/authentik-oauth2-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 12
- target: $.paths['/oauth2/access_tokens/'].get
update:
x-apievangelist-phrasing:
intent: List issued OAuth2 access tokens
effect: read
questions:
- Which OAuth2 access tokens has authentik issued to a given user?
- Can I see the access tokens handed out by one specific OAuth2 provider?
instructions:
- text: List all OAuth2 access tokens.
- text: Show OAuth2 access tokens issued to user {user}.
slots:
user: query.user
- text: List access tokens issued by OAuth2 provider {provider}.
slots:
provider: query.provider
method: generated
generated: '2026-09-26'
- target: $.paths['/oauth2/access_tokens/{id}/'].get
update:
x-apievangelist-phrasing:
intent: Get one OAuth2 access token
effect: read
questions:
- Which user and provider does a particular access token belong to?
- Where can I inspect a single issued OAuth2 access token by its ID?
instructions:
- text: Show the details of access token {id}.
slots:
id: path.id
- text: Look up OAuth2 access token {id} and tell me who it belongs to.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/oauth2/access_tokens/{id}/'].delete
update:
x-apievangelist-phrasing:
intent: Revoke an OAuth2 access token
effect: destructive
questions:
- How do I kill an access token that was leaked?
- Can I delete a single OAuth2 access token without touching the user's refresh token?
instructions:
- text: Delete access token {id}.
slots:
id: path.id
- text: Revoke OAuth2 access token {id} right away.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/oauth2/access_tokens/{id}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what references an access token
effect: read
questions:
- Is anything in authentik still referencing this access token?
- Which objects would be affected if I removed a given OAuth2 access token?
instructions:
- text: List objects that use access token {id}.
slots:
id: path.id
- text: Check what depends on OAuth2 access token {id} before I delete it.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/oauth2/authorization_codes/'].get
update:
x-apievangelist-phrasing:
intent: List OAuth2 authorization codes
effect: read
questions:
- Which authorization codes are outstanding for a user?
- Can I filter pending OAuth2 authorization codes by provider?
instructions:
- text: List all OAuth2 authorization codes.
- text: Show authorization codes issued to user {user}.
slots:
user: query.user
- text: List authorization codes for OAuth2 provider {provider}.
slots:
provider: query.provider
method: generated
generated: '2026-09-26'
- target: $.paths['/oauth2/authorization_codes/{id}/'].get
update:
x-apievangelist-phrasing:
intent: Get one OAuth2 authorization code
effect: read
questions:
- Which user and client is a specific authorization code tied to?
- Where can I view one OAuth2 authorization code by its ID?
instructions:
- text: Show authorization code {id}.
slots:
id: path.id
- text: Get the details of OAuth2 authorization code {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/oauth2/authorization_codes/{id}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete an OAuth2 authorization code
effect: destructive
questions:
- Can I invalidate an authorization code before a client exchanges it?
- What is the way to delete an unused OAuth2 authorization code?
instructions:
- text: Delete authorization code {id}.
slots:
id: path.id
- text: Invalidate OAuth2 authorization code {id} so it can't be redeemed.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/oauth2/authorization_codes/{id}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what references an authorization code
effect: read
questions:
- Which objects still point at a given authorization code?
- Is an OAuth2 authorization code referenced by anything else in authentik?
instructions:
- text: List objects that use authorization code {id}.
slots:
id: path.id
- text: Show what depends on OAuth2 authorization code {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/oauth2/refresh_tokens/'].get
update:
x-apievangelist-phrasing:
intent: List OAuth2 refresh tokens
effect: read
questions:
- Which long-lived refresh tokens does a user currently hold?
- Can I list the refresh tokens issued by one OAuth2 provider?
instructions:
- text: List all OAuth2 refresh tokens.
- text: Show refresh tokens belonging to user {user}.
slots:
user: query.user
- text: List refresh tokens issued by OAuth2 provider {provider}.
slots:
provider: query.provider
method: generated
generated: '2026-09-26'
- target: $.paths['/oauth2/refresh_tokens/{id}/'].get
update:
x-apievangelist-phrasing:
intent: Get one OAuth2 refresh token
effect: read
questions:
- Which provider issued a particular refresh token, and to whom?
- Where do I view a single OAuth2 refresh token by its ID?
instructions:
- text: Show refresh token {id}.
slots:
id: path.id
- text: Get the details of OAuth2 refresh token {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/oauth2/refresh_tokens/{id}/'].delete
update:
x-apievangelist-phrasing:
intent: Revoke an OAuth2 refresh token
effect: destructive
questions:
- How do I stop a client from minting new access tokens with a refresh token?
- Can I delete one user's OAuth2 refresh token to force them to sign in again?
instructions:
- text: Delete refresh token {id}.
slots:
id: path.id
- text: Revoke OAuth2 refresh token {id} now.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/oauth2/refresh_tokens/{id}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what references a refresh token
effect: read
questions:
- Which objects are linked to a specific refresh token?
- Does anything else in authentik depend on this OAuth2 refresh token?
instructions:
- text: List objects that use refresh token {id}.
slots:
id: path.id
- text: Check what depends on OAuth2 refresh token {id} before revoking it.
slots:
id: path.id
method: generated
generated: '2026-09-26'