Authentik · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for authentik Providers API

132 actions 132 updates phrasing extends openapi/authentik-providers-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Authentik's API. It is a proposal applied on top of the contract, not a document Authentik publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 132 · first 16 shown; the file carries all of them

$.info
$.paths['/providers/all/'].get
$.paths['/providers/all/{id}/'].get
$.paths['/providers/all/{id}/'].delete
$.paths['/providers/all/{id}/used_by/'].get
$.paths['/providers/all/types/'].get
$.paths['/providers/google_workspace/'].get
$.paths['/providers/google_workspace/'].post
$.paths['/providers/google_workspace/{id}/'].get
$.paths['/providers/google_workspace/{id}/'].put
$.paths['/providers/google_workspace/{id}/'].delete
$.paths['/providers/google_workspace/{id}/'].patch
$.paths['/providers/google_workspace/{id}/sync/object/'].post
$.paths['/providers/google_workspace/{id}/sync/status/'].get
$.paths['/providers/google_workspace/{id}/used_by/'].get
$.paths['/providers/google_workspace_groups/'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for authentik Providers API
  version: 1.0.0
extends: openapi/authentik-providers-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 131
- target: $.paths['/providers/all/'].get
  update:
    x-apievangelist-phrasing:
      intent: List all providers of every type
      effect: read
      questions:
      - Which providers of any type are configured in my authentik instance?
      - Can I see only backchannel providers, or exclude them from the full provider list?
      - Are there providers not yet attached to any application?
      instructions:
      - text: List every provider across all protocol types.
      - text: Search all providers for {search}.
        slots:
          search: query.search
      - text: Show all providers with backchannel set to {backchannel}.
        slots:
          backchannel: query.backchannel
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/all/{id}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get any provider by ID
      effect: read
      questions:
      - What type of provider is a given provider ID, whatever its protocol?
      - Can I look up a provider generically without knowing if it is OAuth2, SAML or LDAP?
      instructions:
      - text: Get provider {id} from the generic all-providers endpoint.
        slots:
          id: path.id
      - text: Show the basic details of provider {id} regardless of its type.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/all/{id}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a provider of any type
      effect: destructive
      questions:
      - Can I delete a provider without knowing which protocol type it is?
      - What happens when I remove a provider through the generic provider endpoint?
      instructions:
      - text: Delete provider {id} via the all-providers endpoint.
        slots:
          id: path.id
      - text: Remove provider {id}, whatever its type.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/all/{id}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what depends on a provider
      effect: read
      questions:
      - What objects reference a provider before I delete it, whatever its type?
      - Is any application still using this provider from the generic list?
      instructions:
      - text: List everything that uses provider {id} via the generic provider endpoint.
        slots:
          id: path.id
      - text: Show the dependents of provider {id} before I remove it.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/all/types/'].get
  update:
    x-apievangelist-phrasing:
      intent: List creatable provider types
      effect: read
      questions:
      - What kinds of providers can I create in authentik?
      - Which provider protocols are available to add, like OAuth2, SAML or proxy?
      instructions:
      - text: List all the provider types I can create.
      - text: Show me the available provider type options.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/google_workspace/'].get
  update:
    x-apievangelist-phrasing:
      intent: List Google Workspace providers
      effect: read
      questions:
      - Which Google Workspace sync providers have I set up?
      - Can I filter Google Workspace providers by the delegated admin subject?
      instructions:
      - text: List my Google Workspace providers.
      - text: Find Google Workspace providers delegated to {delegated_subject}.
        slots:
          delegated_subject: query.delegated_subject
      - text: Show Google Workspace providers named {name}.
        slots:
          name: query.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/google_workspace/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a Google Workspace provider
      effect: write
      questions:
      - How do I sync authentik users and groups into Google Workspace?
      - What credentials and delegated subject does a new Google Workspace provider need?
      - Can I run a new Google Workspace provider in dry-run mode first?
      instructions:
      - text: Create Google Workspace provider {name} as {delegated_subject} with credentials {credentials}, group domain {default_group_email_domain}.
        slots:
          name: requestBody.name
          delegated_subject: requestBody.delegated_subject
          credentials: requestBody.credentials
          default_group_email_domain: requestBody.default_group_email_domain
      - text: Set up Google sync {name}, dry run {dry_run}, impersonating {delegated_subject}, key {credentials}, domain {default_group_email_domain}.
        slots:
          name: requestBody.name
          dry_run: requestBody.dry_run
          delegated_subject: requestBody.delegated_subject
          credentials: requestBody.credentials
          default_group_email_domain: requestBody.default_group_email_domain
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/google_workspace/{id}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a Google Workspace provider
      effect: read
      questions:
      - What settings does a specific Google Workspace provider use for user deletion?
      - Which OAuth scopes is my Google Workspace provider configured with?
      instructions:
      - text: Get Google Workspace provider {id}.
        slots:
          id: path.id
      - text: Show the configuration of Google Workspace provider {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/google_workspace/{id}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace a Google Workspace provider's config
      effect: write
      questions:
      - Can I fully replace the configuration of an existing Google Workspace provider?
      - How do I swap the service account credentials on a Google Workspace provider?
      instructions:
      - text: Replace Google Workspace provider {id} with name {name}, subject {delegated_subject}, credentials {credentials}, domain {default_group_email_domain}.
        slots:
          id: path.id
          name: requestBody.name
          delegated_subject: requestBody.delegated_subject
          credentials: requestBody.credentials
          default_group_email_domain: requestBody.default_group_email_domain
      - text: 'Overwrite Google Workspace provider {id}: {name}, key {credentials}, subject {delegated_subject}, domain {default_group_email_domain}.'
        slots:
          id: path.id
          name: requestBody.name
          credentials: requestBody.credentials
          delegated_subject: requestBody.delegated_subject
          default_group_email_domain: requestBody.default_group_email_domain
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/google_workspace/{id}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a Google Workspace provider
      effect: destructive
      questions:
      - Can I remove a Google Workspace sync provider I no longer need?
      - Does deleting a Google Workspace provider stop syncing to Google?
      instructions:
      - text: Delete Google Workspace provider {id}.
        slots:
          id: path.id
      - text: Remove the Google Workspace sync provider {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/google_workspace/{id}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Update some Google Workspace provider settings
      effect: write
      questions:
      - Can I turn off dry-run on a Google Workspace provider without resending everything?
      - How do I change only the group filter on my Google Workspace provider?
      instructions:
      - text: Set dry run to {dry_run} on Google Workspace provider {id}.
        slots:
          id: path.id
          dry_run: requestBody.dry_run
      - text: Change the user delete action on Google Workspace provider {id} to {user_delete_action}.
        slots:
          id: path.id
          user_delete_action: requestBody.user_delete_action
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/google_workspace/{id}/sync/object/'].post
  update:
    x-apievangelist-phrasing:
      intent: Re-sync one user or group to Google Workspace
      effect: write
      questions:
      - Can I push a single user to Google Workspace without running a full sync?
      - Is it possible to force one group to re-sync to Google even while in dry run?
      instructions:
      - text: Sync {sync_object_model} {sync_object_id} to Google Workspace provider {id}.
        slots:
          id: path.id
          sync_object_model: requestBody.sync_object_model
          sync_object_id: requestBody.sync_object_id
      - text: Re-sync object {sync_object_id} of type {sync_object_model} through Google Workspace provider {id}, overriding dry run {override_dry_run}.
        slots:
          id: path.id
          sync_object_id: requestBody.sync_object_id
          sync_object_model: requestBody.sync_object_model
          override_dry_run: requestBody.override_dry_run
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/google_workspace/{id}/sync/status/'].get
  update:
    x-apievangelist-phrasing:
      intent: Check a Google Workspace provider's sync status
      effect: read
      questions:
      - Is my Google Workspace sync currently running or did it finish?
      - When did the last Google Workspace provider sync complete?
      instructions:
      - text: Check the sync status of Google Workspace provider {id}.
        slots:
          id: path.id
      - text: Show whether Google Workspace provider {id} is syncing right now.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/google_workspace/{id}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses a Google Workspace provider
      effect: read
      questions:
      - What objects depend on my Google Workspace provider?
      - Is any application still bound to this Google Workspace sync provider?
      instructions:
      - text: List the objects that use Google Workspace provider {id}.
        slots:
          id: path.id
      - text: Show dependents of Google Workspace provider {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/google_workspace_groups/'].get
  update:
    x-apievangelist-phrasing:
      intent: List groups synced to Google Workspace
      effect: read
      questions:
      - Which authentik groups have been mapped to Google Workspace groups?
      - Can I find the Google group linked to a specific authentik group name?
      instructions:
      - text: List Google Workspace group mappings.
      - text: Show Google Workspace group links for authentik group {group_name}.
        slots:
          group_name: query.group__name
      - text: List groups synced by Google Workspace provider {provider_id}.
        slots:
          provider_id: query.provider__id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/google_workspace_groups/'].post
  update:
    x-apievangelist-phrasing:
      intent: Link a group to a Google Workspace group
      effect: write
      questions:
      - How do I manually tie an authentik group to an existing Google group ID?
      - Can I record a Google Workspace group mapping by hand?
      instructions:
      - text: Link authentik group {group} to Google group {google_id} on provider {provider}.
        slots:
          group: requestBody.group
          google_id: requestBody.google_id
          provider: requestBody.provider
      - text: 'Create a Google Workspace group mapping: Google ID {google_id}, group {group}, provider {provider}.'
        slots:
          google_id: requestBody.google_id
          group: requestBody.group
          provider: requestBody.provider
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/google_workspace_groups/{id}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a Google Workspace group mapping
      effect: read
      questions:
      - Which Google group ID does a particular group mapping point to?
      - What authentik group is behind this Google Workspace group link?
      instructions:
      - text: Get Google Workspace group mapping {id}.
        slots:
          id: path.id
      - text: Show the Google group link {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/google_workspace_groups/{id}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Remove a Google Workspace group mapping
      effect: destructive
      questions:
      - Can I unlink an authentik group from its Google Workspace group?
      - What happens if I delete a Google group mapping record?
      instructions:
      - text: Delete Google Workspace group mapping {id}.
        slots:
          id: path.id
      - text: Unlink the Google group mapping {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/google_workspace_groups/{id}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses a Google Workspace group mapping
      effect: read
      questions:
      - Does anything reference this Google Workspace group mapping?
      - What depends on a synced Google group link before I remove it?
      instructions:
      - text: List objects using Google Workspace group mapping {id}.
        slots:
          id: path.id
      - text: Show dependents of the Google group link {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/google_workspace_users/'].get
  update:
    x-apievangelist-phrasing:
      intent: List users synced to Google Workspace
      effect: read
      questions:
      - Which authentik users have been provisioned into Google Workspace?
      - Can I check whether a given username is linked to a Google account?
      instructions:
      - text: List Google Workspace user mappings.
      - text: Find the Google Workspace user link for username {username}.
        slots:
          username: query.user__username
      - text: List users synced by Google Workspace provider {provider_id}.
        slots:
          provider_id: query.provider__id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/google_workspace_users/'].post
  update:
    x-apievangelist-phrasing:
      intent: Link a user to a Google Workspace account
      effect: write
      questions:
      - How do I manually map an authentik user to an existing Google user ID?
      - Can I add a Google Workspace user link without running sync?
      instructions:
      - text: Link user {user} to Google user {google_id} on provider {provider}.
        slots:
          user: requestBody.user
          google_id: requestBody.google_id
          provider: requestBody.provider
      - text: Create a Google Workspace user mapping for Google ID {google_id}, user {user}, provider {provider}.
        slots:
          google_id: requestBody.google_id
          user: requestBody.user
          provider: requestBody.provider
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/google_workspace_users/{id}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a Google Workspace user mapping
      effect: read
      questions:
      - Which Google account is a specific user mapping tied to?
      - What does a single Google Workspace user link record contain?
      instructions:
      - text: Get Google Workspace user mapping {id}.
        slots:
          id: path.id
      - text: Show the Google user link {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/google_workspace_users/{id}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Remove a Google Workspace user mapping
      effect: destructive
      questions:
      - Can I unlink a user from their Google Workspace account record?
      - Is it possible to delete a stale Google user mapping?
      instructions:
      - text: Delete Google Workspace user mapping {id}.
        slots:
          id: path.id
      - text: Unlink the Google user mapping {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/google_workspace_users/{id}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses a Google Workspace user mapping
      effect: read
      questions:
      - Does anything reference this Google Workspace user mapping?
      - What depends on a synced Google user link?
      instructions:
      - text: List objects using Google Workspace user mapping {id}.
        slots:
          id: path.id
      - text: Show dependents of the Google user link {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/ldap/'].get
  update:
    x-apievangelist-phrasing:
      intent: List LDAP providers
      effect: read
      questions:
      - Which LDAP outpost providers do I have configured?
      - Can I find LDAP providers by their base DN or TLS server name?
      instructions:
      - text: List my LDAP providers.
      - text: Find LDAP providers with base DN {base_dn}.
        slots:
          base_dn: query.base_dn__iexact
      - text: Show LDAP providers using authorization flow {flow_slug}.
        slots:
          flow_slug: query.authorization_flow__slug__iexact
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/ldap/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an LDAP provider
      effect: write
      questions:
      - How do I expose authentik users over LDAP for a legacy app?
      - Can a new LDAP provider support MFA during bind?
      instructions:
      - text: Create an LDAP provider {name} with authorization flow {authorization_flow} and invalidation flow {invalidation_flow}.
        slots:
          name: requestBody.name
          authorization_flow: requestBody.authorization_flow
          invalidation_flow: requestBody.invalidation_flow
      - text: Set up LDAP provider {name} with base DN {base_dn}, bind flow {authorization_flow}, invalidation flow {invalidation_flow}.
        slots:
          name: requestBody.name
          base_dn: requestBody.base_dn
          authorization_flow: requestBody.authorization_flow
          invalidation_flow: requestBody.invalidation_flow
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/ldap/{id}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an LDAP provider
      effect: read
      questions:
      - What base DN and bind mode does a specific LDAP provider use?
      - Which certificate is my LDAP provider serving for LDAPS?
      instructions:
      - text: Get LDAP provider {id}.
        slots:
          id: path.id
      - text: Show the settings of LDAP provider {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/ldap/{id}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace an LDAP provider's config
      effect: write
      questions:
      - Can I overwrite every setting of an LDAP provider in one request?
      - How do I fully reconfigure an existing LDAP provider?
      instructions:
      - text: Replace LDAP provider {id} with name {name}, authorization flow {authorization_flow}, invalidation flow {invalidation_flow}.
        slots:
          id: path.id
          name: requestBody.name
          authorization_flow: requestBody.authorization_flow
          invalidation_flow: requestBody.invalidation_flow
      - text: 'Overwrite LDAP provider {id}: name {name}, base DN {base_dn}, flows {authorization_flow} and {invalidation_flow}.'
        slots:
          id: path.id
          name: requestBody.name
          base_dn: requestBody.base_dn
          authorization_flow: requestBody.authorization_flow
          invalidation_flow: requestBody.invalidation_flow
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/ldap/{id}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an LDAP provider
      effect: destructive
      questions:
      - Can I remove an LDAP provider I'm no longer using?
      - Will deleting an LDAP provider break binds from my legacy apps?
      instructions:
      - text: Delete LDAP provider {id}.
        slots:
          id: path.id
      - text: Remove the LDAP provider {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/ldap/{id}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Update some LDAP provider settings
      effect: write
      questions:
      - Can I change just the base DN of my LDAP provider?
      - How do I enable MFA support on an existing LDAP provider?
      instructions:
      - text: Set the base DN of LDAP provider {id} to {base_dn}.
        slots:
          id: path.id
          base_dn: requestBody.base_dn
      - text: Turn MFA support {mfa_support} on LDAP provider {id}.
        slots:
          id: path.id
          mfa_support: requestBody.mfa_support
      - text: Change the search mode of LDAP provider {id} to {search_mode}.
        slots:
          id: path.id
          search_mode: requestBody.search_mode
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/ldap/{id}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses an LDAP provider
      effect: read
      questions:
      - Which applications or outposts depend on my LDAP provider?
      - Is an LDAP provider still referenced anywhere?
      instructions:
      - text: List objects that use LDAP provider {id}.
        slots:
          id: path.id
      - text: Show dependents of LDAP provider {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra/'].get
  update:
    x-apievangelist-phrasing:
      intent: List Microsoft Entra providers
      effect: read
      questions:
      - Which Microsoft Entra ID sync providers are configured?
      - Can I list Entra providers that exclude service account users?
      instructions:
      - text: List my Microsoft Entra providers.
      - text: Find Microsoft Entra providers named {name}.
        slots:
          name: query.name
      - text: Show Entra providers filtering on group {filter_group}.
        slots:
          filter_group: query.filter_group
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a Microsoft Entra provider
      effect: write
      questions:
      - How do I provision authentik users and groups into Microsoft Entra ID?
      - What app registration details does a Microsoft Entra provider require?
      instructions:
      - text: Create a Microsoft Entra provider {name} for tenant {tenant_id} with client ID {client_id} and secret {client_secret}.
        slots:
          name: requestBody.name
          tenant_id: requestBody.tenant_id
          client_id: requestBody.client_id
          client_secret: requestBody.client_secret
      - text: Set up Entra sync {name} in dry-run {dry_run} using tenant {tenant_id}, client {client_id}, secret {client_secret}.
        slots:
          name: requestBody.name
          dry_run: requestBody.dry_run
          tenant_id: requestBody.tenant_id
          client_id: requestBody.client_id
          client_secret: requestBody.client_secret
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra/{id}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a Microsoft Entra provider
      effect: read
      questions:
      - Which Entra tenant is a specific provider syncing to?
      - What group delete action does my Microsoft Entra provider use?
      instructions:
      - text: Get Microsoft Entra provider {id}.
        slots:
          id: path.id
      - text: Show the configuration of Entra provider {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra/{id}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace a Microsoft Entra provider's config
      effect: write
      questions:
      - Can I fully replace an Entra provider's tenant, client and secret at once?
      - How do I overwrite all settings of a Microsoft Entra sync provider?
      instructions:
      - text: Replace Entra provider {id} with name {name}, tenant {tenant_id}, client {client_id}, secret {client_secret}.
        slots:
          id: path.id
          name: requestBody.name
          tenant_id: requestBody.tenant_id
          client_id: requestBody.client_id
          client_secret: requestBody.client_secret
      - text: 'Overwrite Microsoft Entra provider {id} config: {name}, tenant {tenant_id}, app {client_id}, secret {client_secret}.'
        slots:
          id: path.id
          name: requestBody.name
          tenant_id: requestBody.tenant_id
          client_id: requestBody.client_id
          client_secret: requestBody.client_secret
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra/{id}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a Microsoft Entra provider
      effect: destructive
      questions:
      - Can I delete a Microsoft Entra sync provider?
      - What happens to Entra syncing when I remove its provider?
      instructions:
      - text: Delete Microsoft Entra provider {id}.
        slots:
          id: path.id
      - text: Remove the Entra sync provider {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra/{id}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Update some Microsoft Entra provider settings
      effect: write
      questions:
      - Can I rotate only the client secret on my Entra provider?
      - How do I switch a Microsoft Entra provider out of dry-run mode?
      instructions:
      - text: Update the client secret of Entra provider {id} to {client_secret}.
        slots:
          id: path.id
          client_secret: requestBody.client_secret
      - text: Set dry run to {dry_run} on Microsoft Entra provider {id}.
        slots:
          id: path.id
          dry_run: requestBody.dry_run
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra/{id}/sync/object/'].post
  update:
    x-apievangelist-phrasing:
      intent: Re-sync one user or group to Microsoft Entra
      effect: write
      questions:
      - Can I push just one user to Entra ID without a full sync?
      - Is there a way to re-sync a single group to Microsoft Entra on demand?
      instructions:
      - text: Sync {sync_object_model} {sync_object_id} to Microsoft Entra provider {id}.
        slots:
          id: path.id
          sync_object_model: requestBody.sync_object_model
          sync_object_id: requestBody.sync_object_id
      - text: Re-sync object {sync_object_id} ({sync_object_model}) through Entra provider {id} with dry-run override {override_dry_run}.
        slots:
          id: path.id
          sync_object_id: requestBody.sync_object_id
          sync_object_model: requestBody.sync_object_model
          override_dry_run: requestBody.override_dry_run
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra/{id}/sync/status/'].get
  update:
    x-apievangelist-phrasing:
      intent: Check a Microsoft Entra provider's sync status
      effect: read
      questions:
      - Is my Microsoft Entra sync still running?
      - When did the Entra provider last finish syncing?
      instructions:
      - text: Check the sync status of Microsoft Entra provider {id}.
        slots:
          id: path.id
      - text: Show whether Entra provider {id} is currently syncing.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra/{id}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses a Microsoft Entra provider
      effect: read
      questions:
      - What objects reference my Microsoft Entra provider?
      - Is an Entra sync provider still attached to any application?
      instructions:
      - text: List objects that use Microsoft Entra provider {id}.
        slots:
          id: path.id
      - text: Show dependents of Entra provider {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra_groups/'].get
  update:
    x-apievangelist-phrasing:
      intent: List groups synced to Microsoft Entra
      effect: read
      questions:
      - Which authentik groups are linked to Entra ID groups?
      - Can I look up the Entra group mapped to a given group UUID?
      instructions:
      - text: List Microsoft Entra group mappings.
      - text: Show Entra group links for authentik group {group_name}.
        slots:
          group_name: query.group__name
      - text: List groups synced by Entra provider {provider_id}.
        slots:
          provider_id: query.provider__id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra_groups/'].post
  update:
    x-apievangelist-phrasing:
      intent: Link a group to a Microsoft Entra group
      effect: write
      questions:
      - How do I manually map an authentik group to an existing Entra group object ID?
      - Can I create an Entra group link by hand?
      instructions:
      - text: Link group {group} to Entra group {microsoft_id} on provider {provider}.
        slots:
          group: requestBody.group
          microsoft_id: requestBody.microsoft_id
          provider: requestBody.provider
      - text: 'Create a Microsoft Entra group mapping: Microsoft ID {microsoft_id}, group {group}, provider {provider}.'
        slots:
          microsoft_id: requestBody.microsoft_id
          group: requestBody.group
          provider: requestBody.provider
      method: generated
      generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra_groups/{id}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a Microsoft Entra group mapping
      effect: read
      questions:
      - Which Entra group object does this mapping record point to?
      - What authentik group sits behind a given Entra group link?
      instructions:
      - text: Get Microsoft Entra group mapping {id}.
        slots:
          id: path.id
      - text: Show the Entra group link {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'


# --- truncated at 32 KB (93 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/authentik/refs/heads/main/overlays/authentik-providers-api-phrasing-overlay.yaml