Authentik · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for authentik Rac API
14 actions
14 updates
phrasing
extends
openapi/authentik-rac-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Authentik's API. It is a proposal applied on top of the contract, not a document Authentik publishes.
What the actions change
x-apievangelist-phrasing
Targets 14
$.info
$.paths['/rac/connection_tokens/'].get
$.paths['/rac/connection_tokens/{connection_token_uuid}/'].get
$.paths['/rac/connection_tokens/{connection_token_uuid}/'].put
$.paths['/rac/connection_tokens/{connection_token_uuid}/'].delete
$.paths['/rac/connection_tokens/{connection_token_uuid}/'].patch
$.paths['/rac/connection_tokens/{connection_token_uuid}/used_by/'].get
$.paths['/rac/endpoints/'].get
$.paths['/rac/endpoints/'].post
$.paths['/rac/endpoints/{pbm_uuid}/'].get
$.paths['/rac/endpoints/{pbm_uuid}/'].put
$.paths['/rac/endpoints/{pbm_uuid}/'].delete
$.paths['/rac/endpoints/{pbm_uuid}/'].patch
$.paths['/rac/endpoints/{pbm_uuid}/used_by/'].get
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for authentik Rac API
version: 1.0.0
extends: openapi/authentik-rac-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 13
- target: $.paths['/rac/connection_tokens/'].get
update:
x-apievangelist-phrasing:
intent: List remote access connection tokens
effect: read
questions:
- Which remote access connection tokens are active?
- Can I see the RAC connection tokens for one user's sessions?
instructions:
- text: List all RAC connection tokens.
- text: Show connection tokens for remote access endpoint {endpoint}.
slots:
endpoint: query.endpoint
- text: List connection tokens belonging to user {session__user}.
slots:
session__user: query.session__user
method: generated
generated: '2026-09-26'
- target: $.paths['/rac/connection_tokens/{connection_token_uuid}/'].get
update:
x-apievangelist-phrasing:
intent: Get a remote access connection token
effect: read
questions:
- Which endpoint and provider does a connection token point to?
- Can I look up one RAC connection token?
instructions:
- text: Show RAC connection token {connection_token_uuid}.
slots:
connection_token_uuid: path.connection_token_uuid
- text: Fetch the details of connection token {connection_token_uuid}.
slots:
connection_token_uuid: path.connection_token_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/rac/connection_tokens/{connection_token_uuid}/'].put
update:
x-apievangelist-phrasing:
intent: Replace a remote access connection token
effect: write
questions:
- Can I overwrite both the provider and endpoint on a connection token?
- What must I resend to fully replace a RAC connection token?
instructions:
- text: Replace connection token {connection_token_uuid} with provider {provider} and endpoint {endpoint}.
slots:
connection_token_uuid: path.connection_token_uuid
provider: requestBody.provider
endpoint: requestBody.endpoint
- text: Fully rewrite RAC token {connection_token_uuid} to use endpoint {endpoint} via provider {provider}.
slots:
connection_token_uuid: path.connection_token_uuid
endpoint: requestBody.endpoint
provider: requestBody.provider
method: generated
generated: '2026-09-26'
- target: $.paths['/rac/connection_tokens/{connection_token_uuid}/'].delete
update:
x-apievangelist-phrasing:
intent: Revoke a remote access connection token
effect: destructive
questions:
- How do I kill a remote access connection token?
- Is deleting a RAC connection token permanent?
instructions:
- text: Delete RAC connection token {connection_token_uuid}.
slots:
connection_token_uuid: path.connection_token_uuid
- text: Revoke remote access token {connection_token_uuid}.
slots:
connection_token_uuid: path.connection_token_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/rac/connection_tokens/{connection_token_uuid}/'].patch
update:
x-apievangelist-phrasing:
intent: Change part of a connection token
effect: write
questions:
- Can I just point a connection token at a different endpoint?
- Is it possible to only change the provider on a RAC token?
instructions:
- text: Only change the endpoint of connection token {connection_token_uuid} to {endpoint}.
slots:
connection_token_uuid: path.connection_token_uuid
endpoint: requestBody.endpoint
- text: Set just the provider of RAC token {connection_token_uuid} to {provider}.
slots:
connection_token_uuid: path.connection_token_uuid
provider: requestBody.provider
method: generated
generated: '2026-09-26'
- target: $.paths['/rac/connection_tokens/{connection_token_uuid}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses a connection token
effect: read
questions:
- What references a particular RAC connection token?
- Does anything depend on this connection token?
instructions:
- text: Show what references connection token {connection_token_uuid}.
slots:
connection_token_uuid: path.connection_token_uuid
- text: List objects using RAC token {connection_token_uuid}.
slots:
connection_token_uuid: path.connection_token_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/rac/endpoints/'].get
update:
x-apievangelist-phrasing:
intent: List accessible remote access endpoints
effect: read
questions:
- Which remote desktop or SSH endpoints can I connect to?
- Can a superuser see the full list of RAC endpoints, not just their own?
instructions:
- text: List the remote access endpoints I can reach.
- text: Show RAC endpoints for provider {provider}.
slots:
provider: query.provider
- text: 'List every RAC endpoint as a superuser, full list: {superuser_full_list}.'
slots:
superuser_full_list: query.superuser_full_list
method: generated
generated: '2026-09-26'
- target: $.paths['/rac/endpoints/'].post
update:
x-apievangelist-phrasing:
intent: Create a remote access endpoint
effect: write
questions:
- How do I add an RDP, SSH or VNC host for remote access?
- Can I cap how many connections a new endpoint allows?
instructions:
- text: Create RAC endpoint {name} on provider {provider} for {protocol} host {host} with auth mode {auth_mode}.
slots:
name: requestBody.name
provider: requestBody.provider
protocol: requestBody.protocol
host: requestBody.host
auth_mode: requestBody.auth_mode
- text: Add remote host {host} as endpoint {name} ({protocol}) under provider {provider}, auth {auth_mode}, max {maximum_connections} connections.
slots:
host: requestBody.host
name: requestBody.name
protocol: requestBody.protocol
provider: requestBody.provider
auth_mode: requestBody.auth_mode
maximum_connections: requestBody.maximum_connections
method: generated
generated: '2026-09-26'
- target: $.paths['/rac/endpoints/{pbm_uuid}/'].get
update:
x-apievangelist-phrasing:
intent: Get a remote access endpoint
effect: read
questions:
- What host and protocol does a given RAC endpoint use?
- How many simultaneous connections does this endpoint allow?
instructions:
- text: Show remote access endpoint {pbm_uuid}.
slots:
pbm_uuid: path.pbm_uuid
- text: Fetch the settings of RAC endpoint {pbm_uuid}.
slots:
pbm_uuid: path.pbm_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/rac/endpoints/{pbm_uuid}/'].put
update:
x-apievangelist-phrasing:
intent: Replace a remote access endpoint
effect: write
questions:
- Can I overwrite every setting of a remote access endpoint at once?
- What fields must be resent to fully replace a RAC endpoint?
instructions:
- text: 'Replace endpoint {pbm_uuid}: name {name}, provider {provider}, protocol {protocol}, host {host}, auth mode {auth_mode}.'
slots:
pbm_uuid: path.pbm_uuid
name: requestBody.name
provider: requestBody.provider
protocol: requestBody.protocol
host: requestBody.host
auth_mode: requestBody.auth_mode
- text: Fully rewrite RAC endpoint {pbm_uuid} as {name} to {host} over {protocol}, provider {provider}, auth {auth_mode}.
slots:
pbm_uuid: path.pbm_uuid
name: requestBody.name
host: requestBody.host
protocol: requestBody.protocol
provider: requestBody.provider
auth_mode: requestBody.auth_mode
method: generated
generated: '2026-09-26'
- target: $.paths['/rac/endpoints/{pbm_uuid}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete a remote access endpoint
effect: destructive
questions:
- How do I remove a host from remote access?
- Is deleting a RAC endpoint reversible?
instructions:
- text: Delete RAC endpoint {pbm_uuid}.
slots:
pbm_uuid: path.pbm_uuid
- text: Remove remote access endpoint {pbm_uuid}.
slots:
pbm_uuid: path.pbm_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/rac/endpoints/{pbm_uuid}/'].patch
update:
x-apievangelist-phrasing:
intent: Change part of a remote access endpoint
effect: write
questions:
- Can I just change the host of a remote access endpoint?
- Is it possible to only raise the connection limit on an endpoint?
instructions:
- text: Only change the host of RAC endpoint {pbm_uuid} to {host}.
slots:
pbm_uuid: path.pbm_uuid
host: requestBody.host
- text: Set just the maximum connections of endpoint {pbm_uuid} to {maximum_connections}.
slots:
pbm_uuid: path.pbm_uuid
maximum_connections: requestBody.maximum_connections
method: generated
generated: '2026-09-26'
- target: $.paths['/rac/endpoints/{pbm_uuid}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses a remote access endpoint
effect: read
questions:
- Which objects reference a given RAC endpoint?
- What depends on this remote access endpoint?
instructions:
- text: Show what references RAC endpoint {pbm_uuid}.
slots:
pbm_uuid: path.pbm_uuid
- text: List objects using remote access endpoint {pbm_uuid}.
slots:
pbm_uuid: path.pbm_uuid
method: generated
generated: '2026-09-26'