Authentik · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for authentik Rbac API
23 actions
23 updates
phrasing
extends
openapi/authentik-rbac-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Authentik's API. It is a proposal applied on top of the contract, not a document Authentik publishes.
What the actions change
x-apievangelist-phrasing
Targets 23 · first 16 shown; the file carries all of them
$.info
$.paths['/rbac/initial_permissions/'].get
$.paths['/rbac/initial_permissions/'].post
$.paths['/rbac/initial_permissions/{id}/'].get
$.paths['/rbac/initial_permissions/{id}/'].put
$.paths['/rbac/initial_permissions/{id}/'].delete
$.paths['/rbac/initial_permissions/{id}/'].patch
$.paths['/rbac/initial_permissions/{id}/used_by/'].get
$.paths['/rbac/permissions/'].get
$.paths['/rbac/permissions/{id}/'].get
$.paths['/rbac/permissions/assigned_by_roles/'].get
$.paths['/rbac/permissions/assigned_by_roles/{uuid}/assign/'].post
$.paths['/rbac/permissions/assigned_by_roles/{uuid}/unassign/'].patch
$.paths['/rbac/permissions/roles/'].get
$.paths['/rbac/roles/'].get
$.paths['/rbac/roles/'].post
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for authentik Rbac API
version: 1.0.0
extends: openapi/authentik-rbac-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 22
- target: $.paths['/rbac/initial_permissions/'].get
update:
x-apievangelist-phrasing:
intent: List initial permission sets
effect: read
questions:
- Which initial permission sets are configured for newly created objects?
- Can I search initial permissions by name?
instructions:
- text: List all initial permission sets.
- text: Find initial permission sets named {name}.
slots:
name: query.name
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/initial_permissions/'].post
update:
x-apievangelist-phrasing:
intent: Create an initial permission set
effect: write
questions:
- How do I grant a role permissions automatically on objects a user creates?
- What does a new initial permissions entry need besides a role?
instructions:
- text: Create initial permissions {name} for role {role}.
slots:
name: requestBody.name
role: requestBody.role
- text: Set up initial permissions {name} giving role {role} the permissions {permissions}.
slots:
name: requestBody.name
role: requestBody.role
permissions: requestBody.permissions
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/initial_permissions/{id}/'].get
update:
x-apievangelist-phrasing:
intent: Get one initial permission set
effect: read
questions:
- What role and permissions does a specific initial permissions entry grant?
- How do I look up one initial permission set by ID?
instructions:
- text: Show initial permission set {id}.
slots:
id: path.id
- text: Get the role and permissions of initial permissions entry {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/initial_permissions/{id}/'].put
update:
x-apievangelist-phrasing:
intent: Replace an initial permission set
effect: write
questions:
- How do I fully overwrite an existing initial permissions entry?
- Can I reassign an initial permission set to a different role in one full update?
instructions:
- text: Replace initial permission set {id} with name {name} and role {role}.
slots:
id: path.id
name: requestBody.name
role: requestBody.role
- text: 'Overwrite initial permissions {id}: name {name}, role {role}, permissions {permissions}.'
slots:
id: path.id
name: requestBody.name
role: requestBody.role
permissions: requestBody.permissions
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/initial_permissions/{id}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete an initial permission set
effect: destructive
questions:
- How do I stop auto-granting permissions on new objects by removing an initial permission set?
- Can I delete an initial permissions entry?
instructions:
- text: Delete initial permission set {id}.
slots:
id: path.id
- text: Remove the initial permissions entry {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/initial_permissions/{id}/'].patch
update:
x-apievangelist-phrasing:
intent: Patch fields of an initial permission set
effect: write
questions:
- Can I change only the permissions list on an initial permission set?
- Is there a way to rename an initial permissions entry without resending everything?
instructions:
- text: Patch initial permission set {id} to grant only {permissions}.
slots:
id: path.id
permissions: requestBody.permissions
- text: Rename initial permissions entry {id} to {name}.
slots:
id: path.id
name: requestBody.name
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/initial_permissions/{id}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses an initial permission set
effect: read
questions:
- Which objects reference a given initial permissions entry?
- What depends on this initial permission set before I remove it?
instructions:
- text: List objects that use initial permission set {id}.
slots:
id: path.id
- text: Show dependents of initial permissions entry {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/permissions/'].get
update:
x-apievangelist-phrasing:
intent: List available permissions
effect: read
questions:
- Which permissions exist in authentik that I can grant to roles?
- Can I filter the permission catalog by app label or model?
- What permissions does a particular role currently have?
instructions:
- text: List all available permissions.
- text: Show permissions for app {app_label} and model {model}.
slots:
app_label: query.content_type__app_label
model: query.content_type__model
- text: Find the permission with codename {codename}.
slots:
codename: query.codename
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/permissions/{id}/'].get
update:
x-apievangelist-phrasing:
intent: Get one permission definition
effect: read
questions:
- What does a single permission with a given ID cover?
- How do I look up one permission's codename and model?
instructions:
- text: Show permission {id}.
slots:
id: path.id
- text: Get the codename and model of permission {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/permissions/assigned_by_roles/'].get
update:
x-apievangelist-phrasing:
intent: List roles holding permissions on an object
effect: read
questions:
- Which roles have permissions on a specific object?
- Who has been granted access to one model instance through roles?
instructions:
- text: Show which roles hold permissions on model {model}.
slots:
model: query.model
- text: List role permissions on {model} object {object_pk}.
slots:
model: query.model
object_pk: query.object_pk
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/permissions/assigned_by_roles/{uuid}/assign/'].post
update:
x-apievangelist-phrasing:
intent: Grant permissions to a role
effect: write
questions:
- How do I give a role permissions globally across authentik?
- Can I grant a role permissions on just one specific object?
instructions:
- text: Grant role {uuid} the permissions {permissions} globally.
slots:
uuid: path.uuid
permissions: requestBody.permissions
- text: Assign {permissions} to role {uuid} only on {model} object {object_pk}.
slots:
uuid: path.uuid
permissions: requestBody.permissions
model: requestBody.model
object_pk: requestBody.object_pk
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/permissions/assigned_by_roles/{uuid}/unassign/'].patch
update:
x-apievangelist-phrasing:
intent: Revoke permissions from a role
effect: destructive
questions:
- How do I take permissions away from a role?
- Can I revoke a role's permissions on one object while keeping its global ones?
instructions:
- text: Revoke {permissions} from role {uuid}.
slots:
uuid: path.uuid
permissions: requestBody.permissions
- text: Unassign {permissions} from role {uuid} for {model} object {object_pk}.
slots:
uuid: path.uuid
permissions: requestBody.permissions
model: requestBody.model
object_pk: requestBody.object_pk
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/permissions/roles/'].get
update:
x-apievangelist-phrasing:
intent: List a role's object permissions
effect: read
questions:
- What object-level permissions has a given role been assigned?
- Can I see every per-object grant a role holds?
instructions:
- text: Show the object permissions assigned to role {uuid}.
slots:
uuid: query.uuid
- text: List per-object grants for role {uuid} matching {search}.
slots:
uuid: query.uuid
search: query.search
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/roles/'].get
update:
x-apievangelist-phrasing:
intent: List roles
effect: read
questions:
- What roles are defined in authentik?
- Which roles does a given user have, including inherited ones?
- Can I list only the managed roles?
instructions:
- text: List all roles.
- text: 'Show roles for user {users}, including inherited: {inherited}.'
slots:
users: query.users
inherited: query.inherited
- text: Find roles assigned to group {groups}.
slots:
groups: query.groups
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/roles/'].post
update:
x-apievangelist-phrasing:
intent: Create a role
effect: write
questions:
- How do I create a new role for grouping permissions?
- What is needed to add a role in authentik?
instructions:
- text: Create a role named {name}.
slots:
name: requestBody.name
- text: Add a new RBAC role called {name}.
slots:
name: requestBody.name
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/roles/{uuid}/'].get
update:
x-apievangelist-phrasing:
intent: Get one role
effect: read
questions:
- What are the details of a specific role?
- How do I look up a role by its UUID?
instructions:
- text: Show role {uuid}.
slots:
uuid: path.uuid
- text: Get the details of RBAC role {uuid}.
slots:
uuid: path.uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/roles/{uuid}/'].put
update:
x-apievangelist-phrasing:
intent: Replace a role
effect: write
questions:
- How do I do a full update of a role's definition?
- Can I overwrite a role record with a PUT?
instructions:
- text: Replace role {uuid} with name {name}.
slots:
uuid: path.uuid
name: requestBody.name
- text: Fully update RBAC role {uuid}, setting its name to {name}.
slots:
uuid: path.uuid
name: requestBody.name
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/roles/{uuid}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete a role
effect: destructive
questions:
- How do I delete a role I no longer need?
- Can I remove an RBAC role permanently?
instructions:
- text: Delete role {uuid}.
slots:
uuid: path.uuid
- text: Permanently remove RBAC role {uuid}.
slots:
uuid: path.uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/roles/{uuid}/'].patch
update:
x-apievangelist-phrasing:
intent: Rename a role
effect: write
questions:
- Can I just rename a role without a full update?
- Is there a patch call to change a role's name?
instructions:
- text: Rename role {uuid} to {name}.
slots:
uuid: path.uuid
name: requestBody.name
- text: Patch RBAC role {uuid} so it is called {name}.
slots:
uuid: path.uuid
name: requestBody.name
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/roles/{uuid}/add_user/'].post
update:
x-apievangelist-phrasing:
intent: Add a user to a role
effect: write
questions:
- How do I put a user into a role?
- Can I assign a role directly to one user?
instructions:
- text: Add user {pk} to role {uuid}.
slots:
pk: requestBody.pk
uuid: path.uuid
- text: Give user {pk} the role {uuid}.
slots:
pk: requestBody.pk
uuid: path.uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/roles/{uuid}/remove_user/'].post
update:
x-apievangelist-phrasing:
intent: Remove a user from a role
effect: destructive
questions:
- How do I take a user out of a role?
- Can I revoke a role from one specific user?
instructions:
- text: Remove user {pk} from role {uuid}.
slots:
pk: requestBody.pk
uuid: path.uuid
- text: Revoke role {uuid} from user {pk}.
slots:
pk: requestBody.pk
uuid: path.uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/rbac/roles/{uuid}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses a role
effect: read
questions:
- Which objects reference a given role?
- What depends on this role before I delete it?
instructions:
- text: List everything that uses role {uuid}.
slots:
uuid: path.uuid
- text: Show dependents of RBAC role {uuid}.
slots:
uuid: path.uuid
method: generated
generated: '2026-09-26'