Authentik · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for authentik Requests API
30 actions
30 updates
phrasing
extends
openapi/authentik-requests-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Authentik's API. It is a proposal applied on top of the contract, not a document Authentik publishes.
What the actions change
x-apievangelist-phrasing
Targets 30 · first 16 shown; the file carries all of them
$.info
$.paths['/requests/grant-requests/'].get
$.paths['/requests/grant-requests/'].post
$.paths['/requests/grant-requests/{uuid}/'].get
$.paths['/requests/grant-requests/{uuid}/'].delete
$.paths['/requests/grant-requests/{uuid}/fulfill/'].patch
$.paths['/requests/grant-requests/{uuid}/revoke/'].delete
$.paths['/requests/grant-requests/agent/'].post
$.paths['/requests/grant-requests/pending_review/'].get
$.paths['/requests/rule-bindings/'].get
$.paths['/requests/rule-bindings/'].post
$.paths['/requests/rule-bindings/{uuid}/'].get
$.paths['/requests/rule-bindings/{uuid}/'].put
$.paths['/requests/rule-bindings/{uuid}/'].delete
$.paths['/requests/rule-bindings/{uuid}/'].patch
$.paths['/requests/rule-bindings/{uuid}/used_by/'].get
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for authentik Requests API
version: 1.0.0
extends: openapi/authentik-requests-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 29
- target: $.paths['/requests/grant-requests/'].get
update:
x-apievangelist-phrasing:
intent: List access grant requests
effect: read
questions:
- Which access grant requests have been filed, and what status are they in?
- Can I see only the grant requests created by one user?
- What grant requests belong to agents owned by a given person?
instructions:
- text: List all grant requests.
- text: Show grant requests with status {status}.
slots:
status: query.status
- text: List grant requests created by {created_by}.
slots:
created_by: query.created_by
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/grant-requests/'].post
update:
x-apievangelist-phrasing:
intent: Request access to resources
effect: write
questions:
- How do I ask for temporary access to something I don't have yet?
- Can I request access that expires on a set date?
instructions:
- text: Request access to {pbms}.
slots:
pbms: requestBody.pbms
- text: Open a grant request for {pbms} expiring at {expiry}.
slots:
pbms: requestBody.pbms
expiry: requestBody.expiry
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/grant-requests/{uuid}/'].get
update:
x-apievangelist-phrasing:
intent: Get one grant request
effect: read
questions:
- What is the current status of a particular access request?
- Where can I view a single grant request by its ID?
instructions:
- text: Show grant request {uuid}.
slots:
uuid: path.uuid
- text: Check the status of access request {uuid}.
slots:
uuid: path.uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/grant-requests/{uuid}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete a grant request
effect: destructive
questions:
- Can I withdraw and delete an access request I filed by mistake?
- Is there a way to remove a grant request record entirely?
instructions:
- text: Delete grant request {uuid}.
slots:
uuid: path.uuid
- text: Withdraw access request {uuid} and remove it.
slots:
uuid: path.uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/grant-requests/{uuid}/fulfill/'].patch
update:
x-apievangelist-phrasing:
intent: Approve or deny a grant request
effect: write
questions:
- How do I approve a pending access request as a reviewer?
- Can I reject a grant request by setting its status?
instructions:
- text: Set grant request {uuid} to status {status}.
slots:
uuid: path.uuid
status: requestBody.status
- text: Fulfill access request {uuid} with decision data {data}.
slots:
uuid: path.uuid
data: requestBody.data
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/grant-requests/{uuid}/revoke/'].delete
update:
x-apievangelist-phrasing:
intent: Revoke an active access grant
effect: destructive
questions:
- How can I end someone's temporary access before it expires?
- Who is allowed to cut off an approved grant immediately?
instructions:
- text: Revoke the active grant {uuid} now.
slots:
uuid: path.uuid
- text: End approved access from grant request {uuid} immediately.
slots:
uuid: path.uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/grant-requests/agent/'].post
update:
x-apievangelist-phrasing:
intent: Delegate owner access to an agent
effect: write
questions:
- Can an AI agent ask its owner for time-boxed access without running a browser flow?
- What access is an agent allowed to request from the person who owns it?
instructions:
- text: Have my agent request delegated access to {pbms} from its owner.
slots:
pbms: requestBody.pbms
- text: File an agent grant request for {pbms} and give me the fulfill link.
slots:
pbms: requestBody.pbms
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/grant-requests/pending_review/'].get
update:
x-apievangelist-phrasing:
intent: List grant requests awaiting my review
effect: read
questions:
- Which access requests am I eligible to approve right now?
- Is anything waiting on my review in the approval queue?
instructions:
- text: Show grant requests pending my review.
- text: List requests I can review that were filed by {created_by}.
slots:
created_by: query.created_by
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rule-bindings/'].get
update:
x-apievangelist-phrasing:
intent: List request rule bindings
effect: read
questions:
- Which targets have an access-request rule bound to them?
- Can I filter rule bindings by the rule they use?
instructions:
- text: List all request rule bindings.
- text: Show bindings for request rule {rule}.
slots:
rule: query.rule
- text: List rule bindings on target {target}.
slots:
target: query.target
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rule-bindings/'].post
update:
x-apievangelist-phrasing:
intent: Bind a request rule to a target
effect: write
questions:
- How do I make an application requestable under a given approval rule?
- Can I cap how long granted access lasts when binding a rule?
instructions:
- text: Bind request rule {rule} to target {target}.
slots:
rule: requestBody.rule
target: requestBody.target
- text: Attach rule {rule} to {target} with a maximum grant duration of {expiry_granted_max}.
slots:
rule: requestBody.rule
target: requestBody.target
expiry_granted_max: requestBody.expiry_granted_max
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rule-bindings/{uuid}/'].get
update:
x-apievangelist-phrasing:
intent: Get a request rule binding
effect: read
questions:
- What rule, target and expiry limits does one binding define?
- Where can I view a single request rule binding?
instructions:
- text: Show request rule binding {uuid}.
slots:
uuid: path.uuid
- text: Get the expiry settings of rule binding {uuid}.
slots:
uuid: path.uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rule-bindings/{uuid}/'].put
update:
x-apievangelist-phrasing:
intent: Replace a request rule binding
effect: write
questions:
- Can I overwrite both the rule and the target on an existing binding?
- What does fully replacing a request rule binding require?
instructions:
- text: Replace rule binding {uuid} to bind rule {rule} to {target}.
slots:
uuid: path.uuid
rule: requestBody.rule
target: requestBody.target
- text: Redefine binding {uuid} as rule {rule} on {target} with pending expiry {expiry_pending}.
slots:
uuid: path.uuid
rule: requestBody.rule
target: requestBody.target
expiry_pending: requestBody.expiry_pending
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rule-bindings/{uuid}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete a request rule binding
effect: destructive
questions:
- How do I stop a target from being requestable under a rule?
- Can I remove one request rule binding?
instructions:
- text: Delete request rule binding {uuid}.
slots:
uuid: path.uuid
- text: Unbind the request rule in binding {uuid}.
slots:
uuid: path.uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rule-bindings/{uuid}/'].patch
update:
x-apievangelist-phrasing:
intent: Change some rule binding settings
effect: write
questions:
- Can I shorten only how long pending requests stay open on a binding?
- Is it possible to switch just the policy engine mode of a rule binding?
instructions:
- text: Set pending-request expiry on rule binding {uuid} to {expiry_pending}.
slots:
uuid: path.uuid
expiry_pending: requestBody.expiry_pending
- text: Change the policy engine mode of binding {uuid} to {policy_engine_mode}.
slots:
uuid: path.uuid
policy_engine_mode: requestBody.policy_engine_mode
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rule-bindings/{uuid}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses a request rule binding
effect: read
questions:
- Which objects depend on a given request rule binding?
- Is anything still attached to this rule binding?
instructions:
- text: List objects that use rule binding {uuid}.
slots:
uuid: path.uuid
- text: Show what references request rule binding {uuid}.
slots:
uuid: path.uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rule-child-bindings/'].get
update:
x-apievangelist-phrasing:
intent: List child bindings of request rules
effect: read
questions:
- Which child bindings hang off a given request rule binding?
- Can I filter child bindings by their target?
instructions:
- text: List all request rule child bindings.
- text: Show child bindings under binding {binding}.
slots:
binding: query.binding
- text: List child bindings pointing at target {target}.
slots:
target: query.target
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rule-child-bindings/'].post
update:
x-apievangelist-phrasing:
intent: Add a child binding to a rule binding
effect: write
questions:
- How do I extend an existing request rule binding to an additional target?
- Can I nest a target under a rule binding as a child?
instructions:
- text: Create a child binding of {binding} for target {target}.
slots:
binding: requestBody.binding
target: requestBody.target
- text: Nest target {target} under rule binding {binding}.
slots:
target: requestBody.target
binding: requestBody.binding
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rule-child-bindings/{uuid}/'].get
update:
x-apievangelist-phrasing:
intent: Get a rule child binding
effect: read
questions:
- Which parent binding and target does a child binding link?
- Where can I view one request rule child binding?
instructions:
- text: Show rule child binding {uuid}.
slots:
uuid: path.uuid
- text: Get the parent and target of child binding {uuid}.
slots:
uuid: path.uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rule-child-bindings/{uuid}/'].put
update:
x-apievangelist-phrasing:
intent: Replace a rule child binding
effect: write
questions:
- Can I overwrite both the parent binding and target of a child binding?
- What must I send to fully replace a child binding?
instructions:
- text: Replace child binding {uuid} with parent {binding} and target {target}.
slots:
uuid: path.uuid
binding: requestBody.binding
target: requestBody.target
- text: Redefine child binding {uuid} to link {binding} to {target}.
slots:
uuid: path.uuid
binding: requestBody.binding
target: requestBody.target
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rule-child-bindings/{uuid}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete a rule child binding
effect: destructive
questions:
- How can I detach a nested target from a request rule binding?
- Can I delete a single child binding?
instructions:
- text: Delete rule child binding {uuid}.
slots:
uuid: path.uuid
- text: Remove nested target binding {uuid}.
slots:
uuid: path.uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rule-child-bindings/{uuid}/'].patch
update:
x-apievangelist-phrasing:
intent: Change a child binding's target or parent
effect: write
questions:
- Can I move a child binding to a different target without resending its parent?
- Is it possible to reparent only a child binding?
instructions:
- text: Point child binding {uuid} at target {target}.
slots:
uuid: path.uuid
target: requestBody.target
- text: Move child binding {uuid} under parent binding {binding}.
slots:
uuid: path.uuid
binding: requestBody.binding
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rule-child-bindings/{uuid}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses a rule child binding
effect: read
questions:
- Which objects reference a given child binding?
- Does anything still depend on this nested rule binding?
instructions:
- text: List objects that use child binding {uuid}.
slots:
uuid: path.uuid
- text: Show what references rule child binding {uuid}.
slots:
uuid: path.uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rules/'].get
update:
x-apievangelist-phrasing:
intent: List access request rules
effect: read
questions:
- Which approval rules govern access requests in authentik?
- Can I find the request rules that use a particular request flow?
instructions:
- text: List all access request rules.
- text: Find request rules named {name}.
slots:
name: query.name
- text: Show request rules using flow {request_flow__slug}.
slots:
request_flow__slug: query.request_flow__slug
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rules/'].post
update:
x-apievangelist-phrasing:
intent: Create an access request rule
effect: write
questions:
- How do I require a minimum number of reviewers before access is granted?
- Can a new request rule notify reviewers through my existing transports?
instructions:
- text: Create request rule {name} needing {min_reviewers} reviewers.
slots:
name: requestBody.name
min_reviewers: requestBody.min_reviewers
- text: Add rule {name} using request flow {request_flow} and notifying via {notification_transports}.
slots:
name: requestBody.name
request_flow: requestBody.request_flow
notification_transports: requestBody.notification_transports
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rules/{uuid}/'].get
update:
x-apievangelist-phrasing:
intent: Get an access request rule
effect: read
questions:
- How many reviewers and which flow does a specific request rule use?
- Where can I view one access request rule?
instructions:
- text: Show request rule {uuid}.
slots:
uuid: path.uuid
- text: Get the reviewer settings of approval rule {uuid}.
slots:
uuid: path.uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rules/{uuid}/'].put
update:
x-apievangelist-phrasing:
intent: Replace an access request rule
effect: write
questions:
- Can I overwrite an approval rule's full configuration in one call?
- What is needed to completely replace a request rule?
instructions:
- text: Replace request rule {uuid} with name {name}.
slots:
uuid: path.uuid
name: requestBody.name
- text: Redefine rule {uuid} as {name} requiring {min_reviewers} reviewers.
slots:
uuid: path.uuid
name: requestBody.name
min_reviewers: requestBody.min_reviewers
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rules/{uuid}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete an access request rule
effect: destructive
questions:
- How do I remove an approval rule nobody uses anymore?
- Can I delete a single access request rule?
instructions:
- text: Delete request rule {uuid}.
slots:
uuid: path.uuid
- text: Remove approval rule {uuid}.
slots:
uuid: path.uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rules/{uuid}/'].patch
update:
x-apievangelist-phrasing:
intent: Change some request rule settings
effect: write
questions:
- Can I raise only the minimum reviewer count on an existing rule?
- Is it possible to count required reviewers per group instead of overall?
instructions:
- text: Set the minimum reviewers on rule {uuid} to {min_reviewers}.
slots:
uuid: path.uuid
min_reviewers: requestBody.min_reviewers
- text: 'Make reviewer counts per group on rule {uuid}: {min_reviewers_is_per_group}.'
slots:
uuid: path.uuid
min_reviewers_is_per_group: requestBody.min_reviewers_is_per_group
- text: Change the notification mode of rule {uuid} to {notification_mode}.
slots:
uuid: path.uuid
notification_mode: requestBody.notification_mode
method: generated
generated: '2026-09-26'
- target: $.paths['/requests/rules/{uuid}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses an access request rule
effect: read
questions:
- Which bindings rely on a given approval rule?
- Is anything still attached to this request rule?
instructions:
- text: List objects that use request rule {uuid}.
slots:
uuid: path.uuid
- text: Show what references approval rule {uuid}.
slots:
uuid: path.uuid
method: generated
generated: '2026-09-26'