Authentik · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for authentik Oauth2 API

13 actions 13 updates phrasing extends openapi/authentik-oauth2-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Authentik's API. It is a proposal applied on top of the contract, not a document Authentik publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 13

$.info
$.paths['/oauth2/access_tokens/'].get
$.paths['/oauth2/access_tokens/{id}/'].get
$.paths['/oauth2/access_tokens/{id}/'].delete
$.paths['/oauth2/access_tokens/{id}/used_by/'].get
$.paths['/oauth2/authorization_codes/'].get
$.paths['/oauth2/authorization_codes/{id}/'].get
$.paths['/oauth2/authorization_codes/{id}/'].delete
$.paths['/oauth2/authorization_codes/{id}/used_by/'].get
$.paths['/oauth2/refresh_tokens/'].get
$.paths['/oauth2/refresh_tokens/{id}/'].get
$.paths['/oauth2/refresh_tokens/{id}/'].delete
$.paths['/oauth2/refresh_tokens/{id}/used_by/'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for authentik Oauth2 API
  version: 1.0.0
extends: openapi/authentik-oauth2-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 12
- target: $.paths['/oauth2/access_tokens/'].get
  update:
    x-apievangelist-phrasing:
      intent: List issued OAuth2 access tokens
      effect: read
      questions:
      - Which OAuth2 access tokens has authentik issued to a given user?
      - Can I see the access tokens handed out by one specific OAuth2 provider?
      instructions:
      - text: List all OAuth2 access tokens.
      - text: Show OAuth2 access tokens issued to user {user}.
        slots:
          user: query.user
      - text: List access tokens issued by OAuth2 provider {provider}.
        slots:
          provider: query.provider
      method: generated
      generated: '2026-09-26'
- target: $.paths['/oauth2/access_tokens/{id}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get one OAuth2 access token
      effect: read
      questions:
      - Which user and provider does a particular access token belong to?
      - Where can I inspect a single issued OAuth2 access token by its ID?
      instructions:
      - text: Show the details of access token {id}.
        slots:
          id: path.id
      - text: Look up OAuth2 access token {id} and tell me who it belongs to.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/oauth2/access_tokens/{id}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Revoke an OAuth2 access token
      effect: destructive
      questions:
      - How do I kill an access token that was leaked?
      - Can I delete a single OAuth2 access token without touching the user's refresh token?
      instructions:
      - text: Delete access token {id}.
        slots:
          id: path.id
      - text: Revoke OAuth2 access token {id} right away.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/oauth2/access_tokens/{id}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what references an access token
      effect: read
      questions:
      - Is anything in authentik still referencing this access token?
      - Which objects would be affected if I removed a given OAuth2 access token?
      instructions:
      - text: List objects that use access token {id}.
        slots:
          id: path.id
      - text: Check what depends on OAuth2 access token {id} before I delete it.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/oauth2/authorization_codes/'].get
  update:
    x-apievangelist-phrasing:
      intent: List OAuth2 authorization codes
      effect: read
      questions:
      - Which authorization codes are outstanding for a user?
      - Can I filter pending OAuth2 authorization codes by provider?
      instructions:
      - text: List all OAuth2 authorization codes.
      - text: Show authorization codes issued to user {user}.
        slots:
          user: query.user
      - text: List authorization codes for OAuth2 provider {provider}.
        slots:
          provider: query.provider
      method: generated
      generated: '2026-09-26'
- target: $.paths['/oauth2/authorization_codes/{id}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get one OAuth2 authorization code
      effect: read
      questions:
      - Which user and client is a specific authorization code tied to?
      - Where can I view one OAuth2 authorization code by its ID?
      instructions:
      - text: Show authorization code {id}.
        slots:
          id: path.id
      - text: Get the details of OAuth2 authorization code {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/oauth2/authorization_codes/{id}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an OAuth2 authorization code
      effect: destructive
      questions:
      - Can I invalidate an authorization code before a client exchanges it?
      - What is the way to delete an unused OAuth2 authorization code?
      instructions:
      - text: Delete authorization code {id}.
        slots:
          id: path.id
      - text: Invalidate OAuth2 authorization code {id} so it can't be redeemed.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/oauth2/authorization_codes/{id}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what references an authorization code
      effect: read
      questions:
      - Which objects still point at a given authorization code?
      - Is an OAuth2 authorization code referenced by anything else in authentik?
      instructions:
      - text: List objects that use authorization code {id}.
        slots:
          id: path.id
      - text: Show what depends on OAuth2 authorization code {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/oauth2/refresh_tokens/'].get
  update:
    x-apievangelist-phrasing:
      intent: List OAuth2 refresh tokens
      effect: read
      questions:
      - Which long-lived refresh tokens does a user currently hold?
      - Can I list the refresh tokens issued by one OAuth2 provider?
      instructions:
      - text: List all OAuth2 refresh tokens.
      - text: Show refresh tokens belonging to user {user}.
        slots:
          user: query.user
      - text: List refresh tokens issued by OAuth2 provider {provider}.
        slots:
          provider: query.provider
      method: generated
      generated: '2026-09-26'
- target: $.paths['/oauth2/refresh_tokens/{id}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get one OAuth2 refresh token
      effect: read
      questions:
      - Which provider issued a particular refresh token, and to whom?
      - Where do I view a single OAuth2 refresh token by its ID?
      instructions:
      - text: Show refresh token {id}.
        slots:
          id: path.id
      - text: Get the details of OAuth2 refresh token {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/oauth2/refresh_tokens/{id}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Revoke an OAuth2 refresh token
      effect: destructive
      questions:
      - How do I stop a client from minting new access tokens with a refresh token?
      - Can I delete one user's OAuth2 refresh token to force them to sign in again?
      instructions:
      - text: Delete refresh token {id}.
        slots:
          id: path.id
      - text: Revoke OAuth2 refresh token {id} now.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/oauth2/refresh_tokens/{id}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what references a refresh token
      effect: read
      questions:
      - Which objects are linked to a specific refresh token?
      - Does anything else in authentik depend on this OAuth2 refresh token?
      instructions:
      - text: List objects that use refresh token {id}.
        slots:
          id: path.id
      - text: Check what depends on OAuth2 refresh token {id} before revoking it.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'