Authentik · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for authentik Providers API
132 actions
132 updates
phrasing
extends
openapi/authentik-providers-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Authentik's API. It is a proposal applied on top of the contract, not a document Authentik publishes.
What the actions change
x-apievangelist-phrasing
Targets 132 · first 16 shown; the file carries all of them
$.info
$.paths['/providers/all/'].get
$.paths['/providers/all/{id}/'].get
$.paths['/providers/all/{id}/'].delete
$.paths['/providers/all/{id}/used_by/'].get
$.paths['/providers/all/types/'].get
$.paths['/providers/google_workspace/'].get
$.paths['/providers/google_workspace/'].post
$.paths['/providers/google_workspace/{id}/'].get
$.paths['/providers/google_workspace/{id}/'].put
$.paths['/providers/google_workspace/{id}/'].delete
$.paths['/providers/google_workspace/{id}/'].patch
$.paths['/providers/google_workspace/{id}/sync/object/'].post
$.paths['/providers/google_workspace/{id}/sync/status/'].get
$.paths['/providers/google_workspace/{id}/used_by/'].get
$.paths['/providers/google_workspace_groups/'].get
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for authentik Providers API
version: 1.0.0
extends: openapi/authentik-providers-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 131
- target: $.paths['/providers/all/'].get
update:
x-apievangelist-phrasing:
intent: List all providers of every type
effect: read
questions:
- Which providers of any type are configured in my authentik instance?
- Can I see only backchannel providers, or exclude them from the full provider list?
- Are there providers not yet attached to any application?
instructions:
- text: List every provider across all protocol types.
- text: Search all providers for {search}.
slots:
search: query.search
- text: Show all providers with backchannel set to {backchannel}.
slots:
backchannel: query.backchannel
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/all/{id}/'].get
update:
x-apievangelist-phrasing:
intent: Get any provider by ID
effect: read
questions:
- What type of provider is a given provider ID, whatever its protocol?
- Can I look up a provider generically without knowing if it is OAuth2, SAML or LDAP?
instructions:
- text: Get provider {id} from the generic all-providers endpoint.
slots:
id: path.id
- text: Show the basic details of provider {id} regardless of its type.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/all/{id}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete a provider of any type
effect: destructive
questions:
- Can I delete a provider without knowing which protocol type it is?
- What happens when I remove a provider through the generic provider endpoint?
instructions:
- text: Delete provider {id} via the all-providers endpoint.
slots:
id: path.id
- text: Remove provider {id}, whatever its type.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/all/{id}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what depends on a provider
effect: read
questions:
- What objects reference a provider before I delete it, whatever its type?
- Is any application still using this provider from the generic list?
instructions:
- text: List everything that uses provider {id} via the generic provider endpoint.
slots:
id: path.id
- text: Show the dependents of provider {id} before I remove it.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/all/types/'].get
update:
x-apievangelist-phrasing:
intent: List creatable provider types
effect: read
questions:
- What kinds of providers can I create in authentik?
- Which provider protocols are available to add, like OAuth2, SAML or proxy?
instructions:
- text: List all the provider types I can create.
- text: Show me the available provider type options.
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/google_workspace/'].get
update:
x-apievangelist-phrasing:
intent: List Google Workspace providers
effect: read
questions:
- Which Google Workspace sync providers have I set up?
- Can I filter Google Workspace providers by the delegated admin subject?
instructions:
- text: List my Google Workspace providers.
- text: Find Google Workspace providers delegated to {delegated_subject}.
slots:
delegated_subject: query.delegated_subject
- text: Show Google Workspace providers named {name}.
slots:
name: query.name
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/google_workspace/'].post
update:
x-apievangelist-phrasing:
intent: Create a Google Workspace provider
effect: write
questions:
- How do I sync authentik users and groups into Google Workspace?
- What credentials and delegated subject does a new Google Workspace provider need?
- Can I run a new Google Workspace provider in dry-run mode first?
instructions:
- text: Create Google Workspace provider {name} as {delegated_subject} with credentials {credentials}, group domain {default_group_email_domain}.
slots:
name: requestBody.name
delegated_subject: requestBody.delegated_subject
credentials: requestBody.credentials
default_group_email_domain: requestBody.default_group_email_domain
- text: Set up Google sync {name}, dry run {dry_run}, impersonating {delegated_subject}, key {credentials}, domain {default_group_email_domain}.
slots:
name: requestBody.name
dry_run: requestBody.dry_run
delegated_subject: requestBody.delegated_subject
credentials: requestBody.credentials
default_group_email_domain: requestBody.default_group_email_domain
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/google_workspace/{id}/'].get
update:
x-apievangelist-phrasing:
intent: Get a Google Workspace provider
effect: read
questions:
- What settings does a specific Google Workspace provider use for user deletion?
- Which OAuth scopes is my Google Workspace provider configured with?
instructions:
- text: Get Google Workspace provider {id}.
slots:
id: path.id
- text: Show the configuration of Google Workspace provider {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/google_workspace/{id}/'].put
update:
x-apievangelist-phrasing:
intent: Replace a Google Workspace provider's config
effect: write
questions:
- Can I fully replace the configuration of an existing Google Workspace provider?
- How do I swap the service account credentials on a Google Workspace provider?
instructions:
- text: Replace Google Workspace provider {id} with name {name}, subject {delegated_subject}, credentials {credentials}, domain {default_group_email_domain}.
slots:
id: path.id
name: requestBody.name
delegated_subject: requestBody.delegated_subject
credentials: requestBody.credentials
default_group_email_domain: requestBody.default_group_email_domain
- text: 'Overwrite Google Workspace provider {id}: {name}, key {credentials}, subject {delegated_subject}, domain {default_group_email_domain}.'
slots:
id: path.id
name: requestBody.name
credentials: requestBody.credentials
delegated_subject: requestBody.delegated_subject
default_group_email_domain: requestBody.default_group_email_domain
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/google_workspace/{id}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete a Google Workspace provider
effect: destructive
questions:
- Can I remove a Google Workspace sync provider I no longer need?
- Does deleting a Google Workspace provider stop syncing to Google?
instructions:
- text: Delete Google Workspace provider {id}.
slots:
id: path.id
- text: Remove the Google Workspace sync provider {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/google_workspace/{id}/'].patch
update:
x-apievangelist-phrasing:
intent: Update some Google Workspace provider settings
effect: write
questions:
- Can I turn off dry-run on a Google Workspace provider without resending everything?
- How do I change only the group filter on my Google Workspace provider?
instructions:
- text: Set dry run to {dry_run} on Google Workspace provider {id}.
slots:
id: path.id
dry_run: requestBody.dry_run
- text: Change the user delete action on Google Workspace provider {id} to {user_delete_action}.
slots:
id: path.id
user_delete_action: requestBody.user_delete_action
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/google_workspace/{id}/sync/object/'].post
update:
x-apievangelist-phrasing:
intent: Re-sync one user or group to Google Workspace
effect: write
questions:
- Can I push a single user to Google Workspace without running a full sync?
- Is it possible to force one group to re-sync to Google even while in dry run?
instructions:
- text: Sync {sync_object_model} {sync_object_id} to Google Workspace provider {id}.
slots:
id: path.id
sync_object_model: requestBody.sync_object_model
sync_object_id: requestBody.sync_object_id
- text: Re-sync object {sync_object_id} of type {sync_object_model} through Google Workspace provider {id}, overriding dry run {override_dry_run}.
slots:
id: path.id
sync_object_id: requestBody.sync_object_id
sync_object_model: requestBody.sync_object_model
override_dry_run: requestBody.override_dry_run
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/google_workspace/{id}/sync/status/'].get
update:
x-apievangelist-phrasing:
intent: Check a Google Workspace provider's sync status
effect: read
questions:
- Is my Google Workspace sync currently running or did it finish?
- When did the last Google Workspace provider sync complete?
instructions:
- text: Check the sync status of Google Workspace provider {id}.
slots:
id: path.id
- text: Show whether Google Workspace provider {id} is syncing right now.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/google_workspace/{id}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses a Google Workspace provider
effect: read
questions:
- What objects depend on my Google Workspace provider?
- Is any application still bound to this Google Workspace sync provider?
instructions:
- text: List the objects that use Google Workspace provider {id}.
slots:
id: path.id
- text: Show dependents of Google Workspace provider {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/google_workspace_groups/'].get
update:
x-apievangelist-phrasing:
intent: List groups synced to Google Workspace
effect: read
questions:
- Which authentik groups have been mapped to Google Workspace groups?
- Can I find the Google group linked to a specific authentik group name?
instructions:
- text: List Google Workspace group mappings.
- text: Show Google Workspace group links for authentik group {group_name}.
slots:
group_name: query.group__name
- text: List groups synced by Google Workspace provider {provider_id}.
slots:
provider_id: query.provider__id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/google_workspace_groups/'].post
update:
x-apievangelist-phrasing:
intent: Link a group to a Google Workspace group
effect: write
questions:
- How do I manually tie an authentik group to an existing Google group ID?
- Can I record a Google Workspace group mapping by hand?
instructions:
- text: Link authentik group {group} to Google group {google_id} on provider {provider}.
slots:
group: requestBody.group
google_id: requestBody.google_id
provider: requestBody.provider
- text: 'Create a Google Workspace group mapping: Google ID {google_id}, group {group}, provider {provider}.'
slots:
google_id: requestBody.google_id
group: requestBody.group
provider: requestBody.provider
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/google_workspace_groups/{id}/'].get
update:
x-apievangelist-phrasing:
intent: Get a Google Workspace group mapping
effect: read
questions:
- Which Google group ID does a particular group mapping point to?
- What authentik group is behind this Google Workspace group link?
instructions:
- text: Get Google Workspace group mapping {id}.
slots:
id: path.id
- text: Show the Google group link {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/google_workspace_groups/{id}/'].delete
update:
x-apievangelist-phrasing:
intent: Remove a Google Workspace group mapping
effect: destructive
questions:
- Can I unlink an authentik group from its Google Workspace group?
- What happens if I delete a Google group mapping record?
instructions:
- text: Delete Google Workspace group mapping {id}.
slots:
id: path.id
- text: Unlink the Google group mapping {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/google_workspace_groups/{id}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses a Google Workspace group mapping
effect: read
questions:
- Does anything reference this Google Workspace group mapping?
- What depends on a synced Google group link before I remove it?
instructions:
- text: List objects using Google Workspace group mapping {id}.
slots:
id: path.id
- text: Show dependents of the Google group link {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/google_workspace_users/'].get
update:
x-apievangelist-phrasing:
intent: List users synced to Google Workspace
effect: read
questions:
- Which authentik users have been provisioned into Google Workspace?
- Can I check whether a given username is linked to a Google account?
instructions:
- text: List Google Workspace user mappings.
- text: Find the Google Workspace user link for username {username}.
slots:
username: query.user__username
- text: List users synced by Google Workspace provider {provider_id}.
slots:
provider_id: query.provider__id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/google_workspace_users/'].post
update:
x-apievangelist-phrasing:
intent: Link a user to a Google Workspace account
effect: write
questions:
- How do I manually map an authentik user to an existing Google user ID?
- Can I add a Google Workspace user link without running sync?
instructions:
- text: Link user {user} to Google user {google_id} on provider {provider}.
slots:
user: requestBody.user
google_id: requestBody.google_id
provider: requestBody.provider
- text: Create a Google Workspace user mapping for Google ID {google_id}, user {user}, provider {provider}.
slots:
google_id: requestBody.google_id
user: requestBody.user
provider: requestBody.provider
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/google_workspace_users/{id}/'].get
update:
x-apievangelist-phrasing:
intent: Get a Google Workspace user mapping
effect: read
questions:
- Which Google account is a specific user mapping tied to?
- What does a single Google Workspace user link record contain?
instructions:
- text: Get Google Workspace user mapping {id}.
slots:
id: path.id
- text: Show the Google user link {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/google_workspace_users/{id}/'].delete
update:
x-apievangelist-phrasing:
intent: Remove a Google Workspace user mapping
effect: destructive
questions:
- Can I unlink a user from their Google Workspace account record?
- Is it possible to delete a stale Google user mapping?
instructions:
- text: Delete Google Workspace user mapping {id}.
slots:
id: path.id
- text: Unlink the Google user mapping {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/google_workspace_users/{id}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses a Google Workspace user mapping
effect: read
questions:
- Does anything reference this Google Workspace user mapping?
- What depends on a synced Google user link?
instructions:
- text: List objects using Google Workspace user mapping {id}.
slots:
id: path.id
- text: Show dependents of the Google user link {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/ldap/'].get
update:
x-apievangelist-phrasing:
intent: List LDAP providers
effect: read
questions:
- Which LDAP outpost providers do I have configured?
- Can I find LDAP providers by their base DN or TLS server name?
instructions:
- text: List my LDAP providers.
- text: Find LDAP providers with base DN {base_dn}.
slots:
base_dn: query.base_dn__iexact
- text: Show LDAP providers using authorization flow {flow_slug}.
slots:
flow_slug: query.authorization_flow__slug__iexact
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/ldap/'].post
update:
x-apievangelist-phrasing:
intent: Create an LDAP provider
effect: write
questions:
- How do I expose authentik users over LDAP for a legacy app?
- Can a new LDAP provider support MFA during bind?
instructions:
- text: Create an LDAP provider {name} with authorization flow {authorization_flow} and invalidation flow {invalidation_flow}.
slots:
name: requestBody.name
authorization_flow: requestBody.authorization_flow
invalidation_flow: requestBody.invalidation_flow
- text: Set up LDAP provider {name} with base DN {base_dn}, bind flow {authorization_flow}, invalidation flow {invalidation_flow}.
slots:
name: requestBody.name
base_dn: requestBody.base_dn
authorization_flow: requestBody.authorization_flow
invalidation_flow: requestBody.invalidation_flow
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/ldap/{id}/'].get
update:
x-apievangelist-phrasing:
intent: Get an LDAP provider
effect: read
questions:
- What base DN and bind mode does a specific LDAP provider use?
- Which certificate is my LDAP provider serving for LDAPS?
instructions:
- text: Get LDAP provider {id}.
slots:
id: path.id
- text: Show the settings of LDAP provider {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/ldap/{id}/'].put
update:
x-apievangelist-phrasing:
intent: Replace an LDAP provider's config
effect: write
questions:
- Can I overwrite every setting of an LDAP provider in one request?
- How do I fully reconfigure an existing LDAP provider?
instructions:
- text: Replace LDAP provider {id} with name {name}, authorization flow {authorization_flow}, invalidation flow {invalidation_flow}.
slots:
id: path.id
name: requestBody.name
authorization_flow: requestBody.authorization_flow
invalidation_flow: requestBody.invalidation_flow
- text: 'Overwrite LDAP provider {id}: name {name}, base DN {base_dn}, flows {authorization_flow} and {invalidation_flow}.'
slots:
id: path.id
name: requestBody.name
base_dn: requestBody.base_dn
authorization_flow: requestBody.authorization_flow
invalidation_flow: requestBody.invalidation_flow
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/ldap/{id}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete an LDAP provider
effect: destructive
questions:
- Can I remove an LDAP provider I'm no longer using?
- Will deleting an LDAP provider break binds from my legacy apps?
instructions:
- text: Delete LDAP provider {id}.
slots:
id: path.id
- text: Remove the LDAP provider {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/ldap/{id}/'].patch
update:
x-apievangelist-phrasing:
intent: Update some LDAP provider settings
effect: write
questions:
- Can I change just the base DN of my LDAP provider?
- How do I enable MFA support on an existing LDAP provider?
instructions:
- text: Set the base DN of LDAP provider {id} to {base_dn}.
slots:
id: path.id
base_dn: requestBody.base_dn
- text: Turn MFA support {mfa_support} on LDAP provider {id}.
slots:
id: path.id
mfa_support: requestBody.mfa_support
- text: Change the search mode of LDAP provider {id} to {search_mode}.
slots:
id: path.id
search_mode: requestBody.search_mode
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/ldap/{id}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses an LDAP provider
effect: read
questions:
- Which applications or outposts depend on my LDAP provider?
- Is an LDAP provider still referenced anywhere?
instructions:
- text: List objects that use LDAP provider {id}.
slots:
id: path.id
- text: Show dependents of LDAP provider {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra/'].get
update:
x-apievangelist-phrasing:
intent: List Microsoft Entra providers
effect: read
questions:
- Which Microsoft Entra ID sync providers are configured?
- Can I list Entra providers that exclude service account users?
instructions:
- text: List my Microsoft Entra providers.
- text: Find Microsoft Entra providers named {name}.
slots:
name: query.name
- text: Show Entra providers filtering on group {filter_group}.
slots:
filter_group: query.filter_group
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra/'].post
update:
x-apievangelist-phrasing:
intent: Create a Microsoft Entra provider
effect: write
questions:
- How do I provision authentik users and groups into Microsoft Entra ID?
- What app registration details does a Microsoft Entra provider require?
instructions:
- text: Create a Microsoft Entra provider {name} for tenant {tenant_id} with client ID {client_id} and secret {client_secret}.
slots:
name: requestBody.name
tenant_id: requestBody.tenant_id
client_id: requestBody.client_id
client_secret: requestBody.client_secret
- text: Set up Entra sync {name} in dry-run {dry_run} using tenant {tenant_id}, client {client_id}, secret {client_secret}.
slots:
name: requestBody.name
dry_run: requestBody.dry_run
tenant_id: requestBody.tenant_id
client_id: requestBody.client_id
client_secret: requestBody.client_secret
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra/{id}/'].get
update:
x-apievangelist-phrasing:
intent: Get a Microsoft Entra provider
effect: read
questions:
- Which Entra tenant is a specific provider syncing to?
- What group delete action does my Microsoft Entra provider use?
instructions:
- text: Get Microsoft Entra provider {id}.
slots:
id: path.id
- text: Show the configuration of Entra provider {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra/{id}/'].put
update:
x-apievangelist-phrasing:
intent: Replace a Microsoft Entra provider's config
effect: write
questions:
- Can I fully replace an Entra provider's tenant, client and secret at once?
- How do I overwrite all settings of a Microsoft Entra sync provider?
instructions:
- text: Replace Entra provider {id} with name {name}, tenant {tenant_id}, client {client_id}, secret {client_secret}.
slots:
id: path.id
name: requestBody.name
tenant_id: requestBody.tenant_id
client_id: requestBody.client_id
client_secret: requestBody.client_secret
- text: 'Overwrite Microsoft Entra provider {id} config: {name}, tenant {tenant_id}, app {client_id}, secret {client_secret}.'
slots:
id: path.id
name: requestBody.name
tenant_id: requestBody.tenant_id
client_id: requestBody.client_id
client_secret: requestBody.client_secret
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra/{id}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete a Microsoft Entra provider
effect: destructive
questions:
- Can I delete a Microsoft Entra sync provider?
- What happens to Entra syncing when I remove its provider?
instructions:
- text: Delete Microsoft Entra provider {id}.
slots:
id: path.id
- text: Remove the Entra sync provider {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra/{id}/'].patch
update:
x-apievangelist-phrasing:
intent: Update some Microsoft Entra provider settings
effect: write
questions:
- Can I rotate only the client secret on my Entra provider?
- How do I switch a Microsoft Entra provider out of dry-run mode?
instructions:
- text: Update the client secret of Entra provider {id} to {client_secret}.
slots:
id: path.id
client_secret: requestBody.client_secret
- text: Set dry run to {dry_run} on Microsoft Entra provider {id}.
slots:
id: path.id
dry_run: requestBody.dry_run
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra/{id}/sync/object/'].post
update:
x-apievangelist-phrasing:
intent: Re-sync one user or group to Microsoft Entra
effect: write
questions:
- Can I push just one user to Entra ID without a full sync?
- Is there a way to re-sync a single group to Microsoft Entra on demand?
instructions:
- text: Sync {sync_object_model} {sync_object_id} to Microsoft Entra provider {id}.
slots:
id: path.id
sync_object_model: requestBody.sync_object_model
sync_object_id: requestBody.sync_object_id
- text: Re-sync object {sync_object_id} ({sync_object_model}) through Entra provider {id} with dry-run override {override_dry_run}.
slots:
id: path.id
sync_object_id: requestBody.sync_object_id
sync_object_model: requestBody.sync_object_model
override_dry_run: requestBody.override_dry_run
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra/{id}/sync/status/'].get
update:
x-apievangelist-phrasing:
intent: Check a Microsoft Entra provider's sync status
effect: read
questions:
- Is my Microsoft Entra sync still running?
- When did the Entra provider last finish syncing?
instructions:
- text: Check the sync status of Microsoft Entra provider {id}.
slots:
id: path.id
- text: Show whether Entra provider {id} is currently syncing.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra/{id}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses a Microsoft Entra provider
effect: read
questions:
- What objects reference my Microsoft Entra provider?
- Is an Entra sync provider still attached to any application?
instructions:
- text: List objects that use Microsoft Entra provider {id}.
slots:
id: path.id
- text: Show dependents of Entra provider {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra_groups/'].get
update:
x-apievangelist-phrasing:
intent: List groups synced to Microsoft Entra
effect: read
questions:
- Which authentik groups are linked to Entra ID groups?
- Can I look up the Entra group mapped to a given group UUID?
instructions:
- text: List Microsoft Entra group mappings.
- text: Show Entra group links for authentik group {group_name}.
slots:
group_name: query.group__name
- text: List groups synced by Entra provider {provider_id}.
slots:
provider_id: query.provider__id
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra_groups/'].post
update:
x-apievangelist-phrasing:
intent: Link a group to a Microsoft Entra group
effect: write
questions:
- How do I manually map an authentik group to an existing Entra group object ID?
- Can I create an Entra group link by hand?
instructions:
- text: Link group {group} to Entra group {microsoft_id} on provider {provider}.
slots:
group: requestBody.group
microsoft_id: requestBody.microsoft_id
provider: requestBody.provider
- text: 'Create a Microsoft Entra group mapping: Microsoft ID {microsoft_id}, group {group}, provider {provider}.'
slots:
microsoft_id: requestBody.microsoft_id
group: requestBody.group
provider: requestBody.provider
method: generated
generated: '2026-09-26'
- target: $.paths['/providers/microsoft_entra_groups/{id}/'].get
update:
x-apievangelist-phrasing:
intent: Get a Microsoft Entra group mapping
effect: read
questions:
- Which Entra group object does this mapping record point to?
- What authentik group sits behind a given Entra group link?
instructions:
- text: Get Microsoft Entra group mapping {id}.
slots:
id: path.id
- text: Show the Entra group link {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
# --- truncated at 32 KB (93 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/authentik/refs/heads/main/overlays/authentik-providers-api-phrasing-overlay.yaml