Authentik · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for authentik Policies API
77 actions
77 updates
phrasing
extends
openapi/authentik-policies-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Authentik's API. It is a proposal applied on top of the contract, not a document Authentik publishes.
What the actions change
x-apievangelist-phrasing
Targets 77 · first 16 shown; the file carries all of them
$.info
$.paths['/policies/all/'].get
$.paths['/policies/all/{policy_uuid}/'].get
$.paths['/policies/all/{policy_uuid}/'].delete
$.paths['/policies/all/{policy_uuid}/test/'].post
$.paths['/policies/all/{policy_uuid}/used_by/'].get
$.paths['/policies/all/cache_clear/'].post
$.paths['/policies/all/cache_info/'].get
$.paths['/policies/all/types/'].get
$.paths['/policies/bindings/'].get
$.paths['/policies/bindings/'].post
$.paths['/policies/bindings/{policy_binding_uuid}/'].get
$.paths['/policies/bindings/{policy_binding_uuid}/'].put
$.paths['/policies/bindings/{policy_binding_uuid}/'].delete
$.paths['/policies/bindings/{policy_binding_uuid}/'].patch
$.paths['/policies/bindings/{policy_binding_uuid}/used_by/'].get
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for authentik Policies API
version: 1.0.0
extends: openapi/authentik-policies-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 76
- target: $.paths['/policies/all/'].get
update:
x-apievangelist-phrasing:
intent: List policies of every type
effect: read
questions:
- Which policies of any type exist in my authentik instance?
- Can I find policies that are not bound to anything yet?
- Which policies are not used by any prompt stage?
instructions:
- text: List all policies across every policy type.
- text: Show policies of any type where unbound is {bindings__isnull}.
slots:
bindings__isnull: query.bindings__isnull
- text: Search all policy types for {search}.
slots:
search: query.search
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/all/{policy_uuid}/'].get
update:
x-apievangelist-phrasing:
intent: Get any policy by UUID
effect: read
questions:
- What is a policy when I only know its UUID and not its type?
- Can I look up a policy generically regardless of its kind?
instructions:
- text: Show policy {policy_uuid} whatever its type.
slots:
policy_uuid: path.policy_uuid
- text: Look up the generic policy record {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/all/{policy_uuid}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete a policy of any type
effect: destructive
questions:
- Can I delete a policy by UUID without knowing which type it is?
- Is there one endpoint that removes any kind of policy?
instructions:
- text: Delete policy {policy_uuid} regardless of its type.
slots:
policy_uuid: path.policy_uuid
- text: Remove the generic policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/all/{policy_uuid}/test/'].post
update:
x-apievangelist-phrasing:
intent: Test a policy against a user
effect: read
questions:
- How do I check whether a policy would pass or fail for a particular user?
- Can I dry-run a policy with extra context before binding it?
instructions:
- text: Test policy {policy_uuid} against user {user}.
slots:
policy_uuid: path.policy_uuid
user: requestBody.user
- text: Evaluate policy {policy_uuid} for user {user} with context {context}.
slots:
policy_uuid: path.policy_uuid
user: requestBody.user
context: requestBody.context
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/all/{policy_uuid}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses a policy of any type
effect: read
questions:
- Which flows, stages or apps reference a policy I only know by UUID?
- What would break if I deleted this policy, whatever its type?
instructions:
- text: List objects that use policy {policy_uuid} of any type.
slots:
policy_uuid: path.policy_uuid
- text: Show generic dependents of policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/all/cache_clear/'].post
update:
x-apievangelist-phrasing:
intent: Clear the policy cache
effect: destructive
questions:
- How do I flush cached policy results so changes take effect immediately?
- Can I reset authentik's policy evaluation cache?
instructions:
- text: Clear the policy cache.
- text: Flush all cached policy results.
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/all/cache_info/'].get
update:
x-apievangelist-phrasing:
intent: Show policy cache statistics
effect: read
questions:
- How many policy results are currently cached?
- What does the policy cache hold right now?
instructions:
- text: Show info about cached policies.
- text: Report how many policy results are in the cache.
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/all/types/'].get
update:
x-apievangelist-phrasing:
intent: List creatable policy types
effect: read
questions:
- What kinds of policies can I create in authentik?
- Which policy types are available to add?
instructions:
- text: List all creatable policy types.
- text: Show the policy types I can create.
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/bindings/'].get
update:
x-apievangelist-phrasing:
intent: List policy bindings
effect: read
questions:
- Which policies, users or groups are bound to a given flow or application?
- Can I list only disabled policy bindings?
- What bindings reference a particular policy?
instructions:
- text: List all policy bindings.
- text: Show bindings attached to target {target}.
slots:
target: query.target
- text: Find bindings for policy {policy} where enabled is {enabled}.
slots:
policy: query.policy
enabled: query.enabled
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/bindings/'].post
update:
x-apievangelist-phrasing:
intent: Bind a policy, user or group to a target
effect: write
questions:
- How do I attach a policy to a flow or application?
- Can I bind a group directly to a target instead of a policy?
- Is it possible to negate a binding or set a timeout on it?
instructions:
- text: Bind policy {policy} to target {target} at order {order}.
slots:
policy: requestBody.policy
target: requestBody.target
order: requestBody.order
- text: Bind group {group} to target {target} with order {order}.
slots:
group: requestBody.group
target: requestBody.target
order: requestBody.order
- text: Create a negated binding of policy {policy} on {target} at order {order}, negate {negate}.
slots:
policy: requestBody.policy
target: requestBody.target
order: requestBody.order
negate: requestBody.negate
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/bindings/{policy_binding_uuid}/'].get
update:
x-apievangelist-phrasing:
intent: Get one policy binding
effect: read
questions:
- What does a specific policy binding link together?
- How do I see the order and timeout of one binding?
instructions:
- text: Show policy binding {policy_binding_uuid}.
slots:
policy_binding_uuid: path.policy_binding_uuid
- text: Get the settings of binding {policy_binding_uuid}.
slots:
policy_binding_uuid: path.policy_binding_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/bindings/{policy_binding_uuid}/'].put
update:
x-apievangelist-phrasing:
intent: Replace a policy binding
effect: write
questions:
- Can I fully redefine an existing binding with a new target and order?
- Is there a full-replace call for a policy binding?
instructions:
- text: Replace binding {policy_binding_uuid} with target {target} and order {order}.
slots:
policy_binding_uuid: path.policy_binding_uuid
target: requestBody.target
order: requestBody.order
- text: 'Overwrite binding {policy_binding_uuid}: policy {policy}, target {target}, order {order}.'
slots:
policy_binding_uuid: path.policy_binding_uuid
policy: requestBody.policy
target: requestBody.target
order: requestBody.order
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/bindings/{policy_binding_uuid}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete a policy binding
effect: destructive
questions:
- How do I unbind a policy from a flow or application?
- Can I delete a binding without deleting the policy itself?
instructions:
- text: Delete policy binding {policy_binding_uuid}.
slots:
policy_binding_uuid: path.policy_binding_uuid
- text: Unbind by removing binding {policy_binding_uuid}.
slots:
policy_binding_uuid: path.policy_binding_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/bindings/{policy_binding_uuid}/'].patch
update:
x-apievangelist-phrasing:
intent: Change individual fields of a binding
effect: write
questions:
- Can I just disable a policy binding without redefining it?
- Is it possible to change only a binding's order or timeout?
instructions:
- text: Set enabled to {enabled} on binding {policy_binding_uuid}.
slots:
policy_binding_uuid: path.policy_binding_uuid
enabled: requestBody.enabled
- text: Move binding {policy_binding_uuid} to order {order}.
slots:
policy_binding_uuid: path.policy_binding_uuid
order: requestBody.order
- text: Change the timeout of binding {policy_binding_uuid} to {timeout} seconds.
slots:
policy_binding_uuid: path.policy_binding_uuid
timeout: requestBody.timeout
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/bindings/{policy_binding_uuid}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses a policy binding
effect: read
questions:
- Which objects reference a particular policy binding?
- What depends on this binding before I remove it?
instructions:
- text: List objects that use binding {policy_binding_uuid}.
slots:
policy_binding_uuid: path.policy_binding_uuid
- text: Show dependents of policy binding {policy_binding_uuid}.
slots:
policy_binding_uuid: path.policy_binding_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/dummy/'].get
update:
x-apievangelist-phrasing:
intent: List dummy test policies
effect: read
questions:
- Which dummy policies have I set up for testing flows?
- Can I filter dummy policies by the result they return?
instructions:
- text: List all dummy policies.
- text: Show dummy policies that return result {result}.
slots:
result: query.result
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/dummy/'].post
update:
x-apievangelist-phrasing:
intent: Create a dummy test policy
effect: write
questions:
- How do I create a placeholder policy that always passes or fails for testing?
- Can a dummy policy wait a random time before returning?
instructions:
- text: Create a dummy policy {name} that returns {result}.
slots:
name: requestBody.name
result: requestBody.result
- text: Create dummy policy {name} waiting between {wait_min} and {wait_max} seconds.
slots:
name: requestBody.name
wait_min: requestBody.wait_min
wait_max: requestBody.wait_max
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/dummy/{policy_uuid}/'].get
update:
x-apievangelist-phrasing:
intent: Get one dummy policy
effect: read
questions:
- What result and wait times does a specific dummy policy use?
- Can I view one dummy policy's settings by UUID?
instructions:
- text: Show dummy policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
- text: Get the result and wait range of dummy policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/dummy/{policy_uuid}/'].put
update:
x-apievangelist-phrasing:
intent: Replace a dummy policy
effect: write
questions:
- Can I fully overwrite a dummy policy's configuration?
- Is there a full-update call for dummy test policies?
instructions:
- text: Replace dummy policy {policy_uuid} with name {name} and result {result}.
slots:
policy_uuid: path.policy_uuid
name: requestBody.name
result: requestBody.result
- text: Fully update dummy policy {policy_uuid}, naming it {name}.
slots:
policy_uuid: path.policy_uuid
name: requestBody.name
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/dummy/{policy_uuid}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete a dummy policy
effect: destructive
questions:
- How do I remove a dummy test policy once testing is done?
- Can I delete a dummy policy by UUID?
instructions:
- text: Delete dummy policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
- text: Remove the dummy test policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/dummy/{policy_uuid}/'].patch
update:
x-apievangelist-phrasing:
intent: Change fields of a dummy policy
effect: write
questions:
- Can I flip only the result of a dummy policy?
- Is it possible to adjust just the wait range on a dummy policy?
instructions:
- text: Change dummy policy {policy_uuid} to return {result}.
slots:
policy_uuid: path.policy_uuid
result: requestBody.result
- text: Set dummy policy {policy_uuid} maximum wait to {wait_max} seconds.
slots:
policy_uuid: path.policy_uuid
wait_max: requestBody.wait_max
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/dummy/{policy_uuid}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses a dummy policy
effect: read
questions:
- Which bindings or objects still reference a dummy policy?
- What depends on this dummy test policy?
instructions:
- text: List objects that use dummy policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
- text: Show dependents of dummy test policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/event_matcher/'].get
update:
x-apievangelist-phrasing:
intent: List event matcher policies
effect: read
questions:
- Which event matcher policies are configured for notifications?
- Can I find event matcher policies that match a given action or client IP?
instructions:
- text: List all event matcher policies.
- text: Show event matcher policies for action {action}.
slots:
action: query.action
- text: Find event matcher policies matching client IP {client_ip}.
slots:
client_ip: query.client_ip
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/event_matcher/'].post
update:
x-apievangelist-phrasing:
intent: Create an event matcher policy
effect: write
questions:
- How do I create a policy that matches specific events for alerts?
- Can an event matcher policy match on app, model and client IP together?
instructions:
- text: Create event matcher policy {name} for action {action}.
slots:
name: requestBody.name
action: requestBody.action
- text: Create event matcher {name} matching app {app}, model {model} and client IP {client_ip}.
slots:
name: requestBody.name
app: requestBody.app
model: requestBody.model
client_ip: requestBody.client_ip
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/event_matcher/{policy_uuid}/'].get
update:
x-apievangelist-phrasing:
intent: Get one event matcher policy
effect: read
questions:
- What events does a specific event matcher policy match?
- Can I view one event matcher policy's criteria?
instructions:
- text: Show event matcher policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
- text: Get the match criteria of event matcher {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/event_matcher/{policy_uuid}/'].put
update:
x-apievangelist-phrasing:
intent: Replace an event matcher policy
effect: write
questions:
- Can I fully redefine an event matcher policy's criteria?
- Is there a full-replace call for event matcher policies?
instructions:
- text: Replace event matcher {policy_uuid} with name {name} and action {action}.
slots:
policy_uuid: path.policy_uuid
name: requestBody.name
action: requestBody.action
- text: Fully update event matcher policy {policy_uuid}, named {name}, for app {app}.
slots:
policy_uuid: path.policy_uuid
name: requestBody.name
app: requestBody.app
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/event_matcher/{policy_uuid}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete an event matcher policy
effect: destructive
questions:
- How do I remove an event matcher policy I no longer alert on?
- Can I delete an event matcher policy by UUID?
instructions:
- text: Delete event matcher policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
- text: Remove the event matcher {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/event_matcher/{policy_uuid}/'].patch
update:
x-apievangelist-phrasing:
intent: Change fields of an event matcher policy
effect: write
questions:
- Can I change only the client IP an event matcher policy matches?
- Is it possible to update just the query of an event matcher?
instructions:
- text: Change event matcher {policy_uuid} to match client IP {client_ip}.
slots:
policy_uuid: path.policy_uuid
client_ip: requestBody.client_ip
- text: Set the query on event matcher policy {policy_uuid} to {query}.
slots:
policy_uuid: path.policy_uuid
query: requestBody.query
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/event_matcher/{policy_uuid}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses an event matcher policy
effect: read
questions:
- Which notification rules or bindings reference an event matcher policy?
- What depends on this event matcher?
instructions:
- text: List objects that use event matcher policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
- text: Show dependents of event matcher {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/expression/'].get
update:
x-apievangelist-phrasing:
intent: List expression policies
effect: read
questions:
- Which Python expression policies exist in authentik?
- Can I search expression policies by the code they contain?
instructions:
- text: List all expression policies.
- text: Find expression policies whose expression contains {expression}.
slots:
expression: query.expression
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/expression/'].post
update:
x-apievangelist-phrasing:
intent: Create an expression policy
effect: write
questions:
- How do I write a custom Python policy for access decisions?
- Can I turn on execution logging for a new expression policy?
instructions:
- text: Create expression policy {name} with code {expression}.
slots:
name: requestBody.name
expression: requestBody.expression
- text: Add expression policy {name} running {expression} with execution logging {execution_logging}.
slots:
name: requestBody.name
expression: requestBody.expression
execution_logging: requestBody.execution_logging
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/expression/{policy_uuid}/'].get
update:
x-apievangelist-phrasing:
intent: Get one expression policy
effect: read
questions:
- What Python code does a specific expression policy run?
- Can I view one expression policy by UUID?
instructions:
- text: Show expression policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
- text: Get the Python code of expression policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/expression/{policy_uuid}/'].put
update:
x-apievangelist-phrasing:
intent: Replace an expression policy
effect: write
questions:
- Can I fully overwrite an expression policy's name and code?
- Is there a full-replace call for expression policies?
instructions:
- text: Replace expression policy {policy_uuid} with name {name} and code {expression}.
slots:
policy_uuid: path.policy_uuid
name: requestBody.name
expression: requestBody.expression
- text: Fully update expression policy {policy_uuid} to {name} running {expression}.
slots:
policy_uuid: path.policy_uuid
name: requestBody.name
expression: requestBody.expression
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/expression/{policy_uuid}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete an expression policy
effect: destructive
questions:
- How do I remove a custom Python expression policy?
- Can I delete an expression policy by UUID?
instructions:
- text: Delete expression policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
- text: Remove the Python expression policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/expression/{policy_uuid}/'].patch
update:
x-apievangelist-phrasing:
intent: Edit an expression policy's code
effect: write
questions:
- Can I change just the Python code of an expression policy?
- Is it possible to toggle execution logging on an existing expression policy?
instructions:
- text: Change the code of expression policy {policy_uuid} to {expression}.
slots:
policy_uuid: path.policy_uuid
expression: requestBody.expression
- text: Set execution logging to {execution_logging} on expression policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
execution_logging: requestBody.execution_logging
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/expression/{policy_uuid}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses an expression policy
effect: read
questions:
- Which flows or bindings reference a given expression policy?
- What depends on this Python expression policy?
instructions:
- text: List objects that use expression policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
- text: Show dependents of Python expression policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/geoip/'].get
update:
x-apievangelist-phrasing:
intent: List GeoIP policies
effect: read
questions:
- Which GeoIP policies restrict logins by location?
- Can I search GeoIP policies by name?
instructions:
- text: List all GeoIP policies.
- text: Find GeoIP policies named {name}.
slots:
name: query.name
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/geoip/'].post
update:
x-apievangelist-phrasing:
intent: Create a GeoIP policy
effect: write
questions:
- How do I restrict sign-ins to certain countries?
- Can a GeoIP policy block impossible travel between logins?
- Is it possible to allow only specific ASNs?
instructions:
- text: Create GeoIP policy {name} allowing countries {countries}.
slots:
name: requestBody.name
countries: requestBody.countries
- text: Create GeoIP policy {name} for countries {countries} with impossible travel check {check_impossible_travel}.
slots:
name: requestBody.name
countries: requestBody.countries
check_impossible_travel: requestBody.check_impossible_travel
- text: Create GeoIP policy {name} for countries {countries} and ASNs {asns}.
slots:
name: requestBody.name
countries: requestBody.countries
asns: requestBody.asns
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/geoip/{policy_uuid}/'].get
update:
x-apievangelist-phrasing:
intent: Get one GeoIP policy
effect: read
questions:
- Which countries and ASNs does a specific GeoIP policy cover?
- Can I view one GeoIP policy's travel distance settings?
instructions:
- text: Show GeoIP policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
- text: Get the countries and distance settings of GeoIP policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/geoip/{policy_uuid}/'].put
update:
x-apievangelist-phrasing:
intent: Replace a GeoIP policy
effect: write
questions:
- Can I fully redefine a GeoIP policy's name and countries?
- Is there a full-replace call for GeoIP policies?
instructions:
- text: Replace GeoIP policy {policy_uuid} with name {name} and countries {countries}.
slots:
policy_uuid: path.policy_uuid
name: requestBody.name
countries: requestBody.countries
- text: 'Fully update GeoIP policy {policy_uuid}: {name}, countries {countries}, ASNs {asns}.'
slots:
policy_uuid: path.policy_uuid
name: requestBody.name
countries: requestBody.countries
asns: requestBody.asns
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/geoip/{policy_uuid}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete a GeoIP policy
effect: destructive
questions:
- How do I remove a location-based GeoIP restriction?
- Can I delete a GeoIP policy by UUID?
instructions:
- text: Delete GeoIP policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
- text: Remove the location restriction GeoIP policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/geoip/{policy_uuid}/'].patch
update:
x-apievangelist-phrasing:
intent: Change fields of a GeoIP policy
effect: write
questions:
- Can I add countries to a GeoIP policy without redefining the rest?
- Is it possible to change only the maximum travel distance on a GeoIP policy?
instructions:
- text: Set the allowed countries of GeoIP policy {policy_uuid} to {countries}.
slots:
policy_uuid: path.policy_uuid
countries: requestBody.countries
- text: Change GeoIP policy {policy_uuid} max history distance to {history_max_distance_km} km.
slots:
policy_uuid: path.policy_uuid
history_max_distance_km: requestBody.history_max_distance_km
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/geoip/{policy_uuid}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses a GeoIP policy
effect: read
questions:
- Which flows or bindings reference a GeoIP policy?
- What depends on this location policy?
instructions:
- text: List objects that use GeoIP policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
- text: Show dependents of location policy {policy_uuid}.
slots:
policy_uuid: path.policy_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/geoip_iso3166/'].get
update:
x-apievangelist-phrasing:
intent: List ISO 3166 country codes
effect: read
questions:
- Which country codes can I use in a GeoIP policy?
- What is the list of ISO-3166-1 countries authentik recognizes?
instructions:
- text: List all ISO-3166-1 countries.
- text: Show the country codes available for GeoIP rules.
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/password/'].get
update:
x-apievangelist-phrasing:
intent: List password strength policies
effect: read
questions:
- Which password complexity policies are configured?
- Can I find password policies that check against Have I Been Pwned?
- Which password policies require a minimum length above a given value?
instructions:
- text: List all password strength policies.
- text: Show password policies with HIBP check {check_have_i_been_pwned}.
slots:
check_have_i_been_pwned: query.check_have_i_been_pwned
- text: Find password policies with minimum length {length_min}.
slots:
length_min: query.length_min
method: generated
generated: '2026-09-26'
- target: $.paths['/policies/password/'].post
update:
x-apievangelist-phrasing:
intent: Create a password strength policy
effect: write
questions:
- How do I enforce a minimum password length and required symbols?
- Can a password policy reject passwords found in breach databases?
- Is a zxcvbn strength score threshold supported?
instructions:
- text: Create password policy {name} with minimum length {length_min}.
slots:
name: requestBody.name
length_min: requestBody.length_min
- text: Create password policy {name} requiring {amount_digits} digits and {amount_symbols} symbols.
slots:
name: requestBody.name
amount_digits: requestBody.amount_digits
amount_symbols: requestBody.amount_symbols
- text: Create password policy {name} with zxcvbn check {check_zxcvbn} and threshold {zxcvbn_score_threshold}.
slots:
name: requestBody.name
check_zxcvbn: requestBody.check_zxcvbn
zxcvbn_score_threshold: requestBody.zxcvbn_score_threshold
method: generated
generated: '2026-09-26'
# --- truncated at 32 KB (52 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/authentik/refs/heads/main/overlays/authentik-policies-api-phrasing-overlay.yaml