Authentik · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for authentik Stages API

211 actions 211 updates phrasing extends openapi/authentik-stages-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Authentik's API. It is a proposal applied on top of the contract, not a document Authentik publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 211 · first 16 shown; the file carries all of them

$.info
$.paths['/stages/account_lockdown/'].get
$.paths['/stages/account_lockdown/'].post
$.paths['/stages/account_lockdown/{stage_uuid}/'].get
$.paths['/stages/account_lockdown/{stage_uuid}/'].put
$.paths['/stages/account_lockdown/{stage_uuid}/'].delete
$.paths['/stages/account_lockdown/{stage_uuid}/'].patch
$.paths['/stages/account_lockdown/{stage_uuid}/used_by/'].get
$.paths['/stages/all/'].get
$.paths['/stages/all/{stage_uuid}/'].get
$.paths['/stages/all/{stage_uuid}/'].delete
$.paths['/stages/all/{stage_uuid}/used_by/'].get
$.paths['/stages/all/types/'].get
$.paths['/stages/all/user_settings/'].get
$.paths['/stages/authenticator/duo/'].get
$.paths['/stages/authenticator/duo/'].post

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for authentik Stages API
  version: 1.0.0
extends: openapi/authentik-stages-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 210
- target: $.paths['/stages/account_lockdown/'].get
  update:
    x-apievangelist-phrasing:
      intent: List account lockdown stages
      effect: read
      questions:
      - Which account lockdown stages are configured in my authentik instance?
      - Can I find the lockdown stages that revoke a user's tokens?
      instructions:
      - text: List all account lockdown stages.
      - text: Find account lockdown stages that deactivate the user, matching {name}.
        slots:
          name: query.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/account_lockdown/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an account lockdown stage
      effect: write
      questions:
      - How do I add a stage that locks down a compromised account?
      - Can a new lockdown stage delete sessions and set an unusable password at once?
      instructions:
      - text: Create an account lockdown stage named {name}.
        slots:
          name: requestBody.name
      - text: 'Set up a new lockdown stage {name} that revokes all tokens: {revoke_tokens}.'
        slots:
          name: requestBody.name
          revoke_tokens: requestBody.revoke_tokens
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/account_lockdown/{stage_uuid}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an account lockdown stage
      effect: read
      questions:
      - What does a specific account lockdown stage do to the user when it runs?
      - Is the self-service completion flow set on this lockdown stage?
      instructions:
      - text: Show account lockdown stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      - text: Fetch the lockdown settings of stage {stage_uuid} so I can see if it deactivates users.
        slots:
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/account_lockdown/{stage_uuid}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace an account lockdown stage's settings
      effect: write
      questions:
      - Can I overwrite every setting on an existing account lockdown stage in one request?
      - What must I resend when fully replacing a lockdown stage's configuration?
      instructions:
      - text: Replace the whole configuration of lockdown stage {stage_uuid}, naming it {name}.
        slots:
          stage_uuid: path.stage_uuid
          name: requestBody.name
      - text: Fully rewrite lockdown stage {stage_uuid} as {name} with delete sessions set to {delete_sessions}.
        slots:
          stage_uuid: path.stage_uuid
          name: requestBody.name
          delete_sessions: requestBody.delete_sessions
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/account_lockdown/{stage_uuid}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an account lockdown stage
      effect: destructive
      questions:
      - How can I remove an account lockdown stage I no longer need?
      - Is deleting a lockdown stage permanent?
      instructions:
      - text: Delete account lockdown stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      - text: Remove the lockdown stage {stage_uuid} from authentik.
        slots:
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/account_lockdown/{stage_uuid}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Change one setting on an account lockdown stage
      effect: write
      questions:
      - Can I turn on token revocation for an existing lockdown stage without touching its other settings?
      - Is it possible to just change where users land after a self-service lockdown?
      instructions:
      - text: On lockdown stage {stage_uuid}, only set deactivate user to {deactivate_user}.
        slots:
          stage_uuid: path.stage_uuid
          deactivate_user: requestBody.deactivate_user
      - text: Point lockdown stage {stage_uuid} at completion flow {self_service_completion_flow}, leaving the rest as is.
        slots:
          stage_uuid: path.stage_uuid
          self_service_completion_flow: requestBody.self_service_completion_flow
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/account_lockdown/{stage_uuid}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses an account lockdown stage
      effect: read
      questions:
      - Which flows depend on a given account lockdown stage?
      - What would break if I removed this lockdown stage?
      instructions:
      - text: Show everything that references lockdown stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      - text: List the objects bound to account lockdown stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/all/'].get
  update:
    x-apievangelist-phrasing:
      intent: List every stage of any type
      effect: read
      questions:
      - What stages exist across all types in my authentik install?
      - Can I search every stage by name regardless of its kind?
      instructions:
      - text: List all stages of every type.
      - text: Search all stages, whatever their type, for the name {name}.
        slots:
          name: query.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/all/{stage_uuid}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get any stage by its ID
      effect: read
      questions:
      - How do I look up a stage when I only have its UUID and not its type?
      - What kind of stage is a given stage ID?
      instructions:
      - text: Look up stage {stage_uuid} without knowing its type.
        slots:
          stage_uuid: path.stage_uuid
      - text: Tell me what type of stage {stage_uuid} is.
        slots:
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/all/{stage_uuid}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a stage of any type
      effect: destructive
      questions:
      - Can I delete a stage by ID without going through its type-specific endpoint?
      - Is there one endpoint that removes any kind of stage?
      instructions:
      - text: Delete stage {stage_uuid}, whatever type it is.
        slots:
          stage_uuid: path.stage_uuid
      - text: Remove the generic stage {stage_uuid} from the stage list.
        slots:
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/all/{stage_uuid}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses a stage of any type
      effect: read
      questions:
      - Which objects reference a stage when I don't know what type it is?
      - Is a given stage ID still bound to any flow?
      instructions:
      - text: Show what uses stage {stage_uuid}, regardless of type.
        slots:
          stage_uuid: path.stage_uuid
      - text: Check whether generic stage {stage_uuid} is referenced anywhere.
        slots:
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/all/types/'].get
  update:
    x-apievangelist-phrasing:
      intent: List the stage types that can be created
      effect: read
      questions:
      - What kinds of stages can I create in authentik?
      - Which stage types are available to add to a flow?
      instructions:
      - text: List all creatable stage types.
      - text: Show me every stage type I'm allowed to create.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/all/user_settings/'].get
  update:
    x-apievangelist-phrasing:
      intent: List stages a user can configure themselves
      effect: read
      questions:
      - Which stages can the current user set up from their own settings page?
      - What self-service stages are exposed to users?
      instructions:
      - text: List the stages the current user can configure.
      - text: Show the user-configurable settings stages.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/duo/'].get
  update:
    x-apievangelist-phrasing:
      intent: List Duo authenticator stages
      effect: read
      questions:
      - Which Duo MFA setup stages are configured?
      - Can I find Duo stages by their API hostname?
      instructions:
      - text: List all Duo authenticator stages.
      - text: Find Duo stages that use API hostname {api_hostname}.
        slots:
          api_hostname: query.api_hostname
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/duo/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a Duo authenticator stage
      effect: write
      questions:
      - How do I connect Duo push MFA to authentik as a setup stage?
      - What Duo credentials do I need to create a Duo stage?
      instructions:
      - text: Create Duo stage {name} with client ID {client_id}, secret {client_secret} and host {api_hostname}.
        slots:
          name: requestBody.name
          client_id: requestBody.client_id
          client_secret: requestBody.client_secret
          api_hostname: requestBody.api_hostname
      - text: Add a Duo authenticator stage {name} with admin integration key {admin_integration_key}, host {api_hostname}, client {client_id} and secret {client_secret}.
        slots:
          name: requestBody.name
          admin_integration_key: requestBody.admin_integration_key
          api_hostname: requestBody.api_hostname
          client_id: requestBody.client_id
          client_secret: requestBody.client_secret
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/duo/{stage_uuid}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a Duo authenticator stage
      effect: read
      questions:
      - What Duo hostname and client ID is a given Duo stage using?
      - Does this Duo stage have a configure flow set?
      instructions:
      - text: Show Duo stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      - text: Fetch the Duo connection details for stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/duo/{stage_uuid}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace a Duo authenticator stage's settings
      effect: write
      questions:
      - Can I overwrite all of a Duo stage's credentials and settings at once?
      - What fields are required when fully replacing a Duo stage?
      instructions:
      - text: 'Replace Duo stage {stage_uuid} entirely: name {name}, client {client_id}, secret {client_secret}, host {api_hostname}.'
        slots:
          stage_uuid: path.stage_uuid
          name: requestBody.name
          client_id: requestBody.client_id
          client_secret: requestBody.client_secret
          api_hostname: requestBody.api_hostname
      - text: Rewrite the full config of Duo stage {stage_uuid} as {name} on host {api_hostname} using client {client_id} and secret {client_secret}.
        slots:
          stage_uuid: path.stage_uuid
          name: requestBody.name
          api_hostname: requestBody.api_hostname
          client_id: requestBody.client_id
          client_secret: requestBody.client_secret
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/duo/{stage_uuid}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a Duo authenticator stage
      effect: destructive
      questions:
      - How can I remove a Duo MFA stage?
      - Is deleting a Duo authenticator stage reversible?
      instructions:
      - text: Delete Duo stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      - text: Remove the Duo authenticator stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/duo/{stage_uuid}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Change one setting on a Duo stage
      effect: write
      questions:
      - Can I rotate just the Duo client secret on an existing stage?
      - Is it possible to change only the friendly name users see for Duo?
      instructions:
      - text: Update only the client secret of Duo stage {stage_uuid} to {client_secret}.
        slots:
          stage_uuid: path.stage_uuid
          client_secret: requestBody.client_secret
      - text: Set the friendly name of Duo stage {stage_uuid} to {friendly_name}.
        slots:
          stage_uuid: path.stage_uuid
          friendly_name: requestBody.friendly_name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/duo/{stage_uuid}/enrollment_status/'].post
  update:
    x-apievangelist-phrasing:
      intent: Check a user's Duo enrollment status
      effect: read
      questions:
      - Has the user in the current session finished enrolling in Duo?
      - Can I check Duo enrollment progress during a flow?
      instructions:
      - text: Check the Duo enrollment status for the current session on stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      - text: See if the current user has completed Duo enrollment via stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/duo/{stage_uuid}/import_device_manual/'].post
  update:
    x-apievangelist-phrasing:
      intent: Import one Duo device for a user
      effect: write
      questions:
      - Can I link a specific Duo user's device to an authentik username by hand?
      - What do I need to manually import a single Duo device?
      instructions:
      - text: Import Duo user {duo_user_id}'s device for username {username} via stage {stage_uuid}.
        slots:
          duo_user_id: requestBody.duo_user_id
          username: requestBody.username
          stage_uuid: path.stage_uuid
      - text: Manually map Duo ID {duo_user_id} to authentik user {username} on Duo stage {stage_uuid}.
        slots:
          duo_user_id: requestBody.duo_user_id
          username: requestBody.username
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/duo/{stage_uuid}/import_devices_automatic/'].post
  update:
    x-apievangelist-phrasing:
      intent: Bulk import Duo devices automatically
      effect: write
      questions:
      - How do I pull all existing Duo devices into authentik automatically?
      - Can authentik sync every Duo enrollment in one go?
      instructions:
      - text: Automatically import all Duo devices through stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      - text: Run the automatic Duo device import for stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/duo/{stage_uuid}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses a Duo stage
      effect: read
      questions:
      - Which flows reference a particular Duo stage?
      - Is my Duo MFA stage bound to anything before I delete it?
      instructions:
      - text: Show what uses Duo stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      - text: List objects referencing the Duo authenticator stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/email/'].get
  update:
    x-apievangelist-phrasing:
      intent: List email authenticator stages
      effect: read
      questions:
      - Which email one-time-code MFA stages are set up?
      - Can I find email authenticator stages that use a particular SMTP host?
      instructions:
      - text: List all email authenticator stages.
      - text: Find email OTP stages sending from {from_address}.
        slots:
          from_address: query.from_address
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/email/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an email authenticator stage
      effect: write
      questions:
      - How do I let users enroll email as a second factor?
      - Can a new email MFA stage use the global email settings instead of its own SMTP server?
      instructions:
      - text: Create an email authenticator stage named {name}.
        slots:
          name: requestBody.name
      - text: Add email MFA stage {name} with subject {subject} and code expiry {token_expiry}.
        slots:
          name: requestBody.name
          subject: requestBody.subject
          token_expiry: requestBody.token_expiry
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/email/{stage_uuid}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an email authenticator stage
      effect: read
      questions:
      - What SMTP settings is a given email MFA stage using?
      - How long are codes valid on this email authenticator stage?
      instructions:
      - text: Show email authenticator stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      - text: Fetch the SMTP and code settings of email MFA stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/email/{stage_uuid}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace an email authenticator stage's settings
      effect: write
      questions:
      - Can I overwrite the entire configuration of an email MFA stage?
      - What happens to unspecified fields when I fully replace an email authenticator stage?
      instructions:
      - text: Replace email authenticator stage {stage_uuid} entirely, naming it {name}.
        slots:
          stage_uuid: path.stage_uuid
          name: requestBody.name
      - text: Fully rewrite email MFA stage {stage_uuid} as {name} using SMTP host {host} and port {port}.
        slots:
          stage_uuid: path.stage_uuid
          name: requestBody.name
          host: requestBody.host
          port: requestBody.port
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/email/{stage_uuid}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an email authenticator stage
      effect: destructive
      questions:
      - How can I get rid of an email MFA stage?
      - Will deleting an email authenticator stage affect flows that use it?
      instructions:
      - text: Delete email authenticator stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      - text: Remove email OTP stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/email/{stage_uuid}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Change one setting on an email authenticator stage
      effect: write
      questions:
      - Can I change only the email subject line for one-time codes?
      - Is it possible to switch an email MFA stage to the global email settings without resending everything?
      instructions:
      - text: Change just the subject of email MFA stage {stage_uuid} to {subject}.
        slots:
          stage_uuid: path.stage_uuid
          subject: requestBody.subject
      - text: Set use global settings to {use_global_settings} on email authenticator stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
          use_global_settings: requestBody.use_global_settings
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/email/{stage_uuid}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses an email authenticator stage
      effect: read
      questions:
      - Which flows rely on a specific email MFA stage?
      - Is this email authenticator stage still in use anywhere?
      instructions:
      - text: Show what uses email authenticator stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      - text: List references to email OTP stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/endpoint_gdtc/'].get
  update:
    x-apievangelist-phrasing:
      intent: List Google Device Trust endpoint stages
      effect: read
      questions:
      - Which Google Device Trust connector stages are configured?
      - Can I filter endpoint GDTC stages by their configure flow?
      instructions:
      - text: List all endpoint GDTC authenticator stages.
      - text: Find Google Device Trust stages named {name}.
        slots:
          name: query.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/endpoint_gdtc/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a Google Device Trust endpoint stage
      effect: write
      questions:
      - How do I add a Google Device Trust check to a login flow?
      - What credentials does a new endpoint GDTC stage require?
      instructions:
      - text: Create endpoint GDTC stage {name} with service account credentials {credentials}.
        slots:
          name: requestBody.name
          credentials: requestBody.credentials
      - text: Add a Google Device Trust stage {name} shown to users as {friendly_name}, using credentials {credentials}.
        slots:
          name: requestBody.name
          friendly_name: requestBody.friendly_name
          credentials: requestBody.credentials
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/endpoint_gdtc/{stage_uuid}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a Google Device Trust endpoint stage
      effect: read
      questions:
      - What is configured on a specific Google Device Trust stage?
      - Which configure flow does this endpoint GDTC stage point to?
      instructions:
      - text: Show endpoint GDTC stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      - text: Fetch the details of Google Device Trust stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/endpoint_gdtc/{stage_uuid}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace a Google Device Trust stage's settings
      effect: write
      questions:
      - Can I overwrite a Google Device Trust stage's name and credentials together?
      - Does fully replacing an endpoint GDTC stage require resending the credentials?
      instructions:
      - text: Replace endpoint GDTC stage {stage_uuid} with name {name} and credentials {credentials}.
        slots:
          stage_uuid: path.stage_uuid
          name: requestBody.name
          credentials: requestBody.credentials
      - text: Fully rewrite Google Device Trust stage {stage_uuid}, calling it {name}, with credentials {credentials}.
        slots:
          stage_uuid: path.stage_uuid
          name: requestBody.name
          credentials: requestBody.credentials
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/endpoint_gdtc/{stage_uuid}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a Google Device Trust endpoint stage
      effect: destructive
      questions:
      - How can I remove a Google Device Trust stage?
      - Is an endpoint GDTC stage gone for good once deleted?
      instructions:
      - text: Delete endpoint GDTC stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      - text: Remove Google Device Trust stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/endpoint_gdtc/{stage_uuid}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Change one setting on a Google Device Trust stage
      effect: write
      questions:
      - Can I swap only the service account credentials on a Google Device Trust stage?
      - Is it possible to rename an endpoint GDTC stage without touching its credentials?
      instructions:
      - text: Update just the credentials of endpoint GDTC stage {stage_uuid} to {credentials}.
        slots:
          stage_uuid: path.stage_uuid
          credentials: requestBody.credentials
      - text: Rename Google Device Trust stage {stage_uuid} to {name}.
        slots:
          stage_uuid: path.stage_uuid
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/endpoint_gdtc/{stage_uuid}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses a Google Device Trust stage
      effect: read
      questions:
      - Which flows reference my Google Device Trust stage?
      - Is an endpoint GDTC stage still bound to anything?
      instructions:
      - text: Show what uses endpoint GDTC stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      - text: List references to Google Device Trust stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/sms/'].get
  update:
    x-apievangelist-phrasing:
      intent: List SMS authenticator stages
      effect: read
      questions:
      - Which SMS MFA stages are configured?
      - Can I find SMS stages that only verify phone numbers during enrollment?
      instructions:
      - text: List all SMS authenticator stages.
      - text: Find SMS stages sending from number {from_number}.
        slots:
          from_number: query.from_number
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/sms/'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an SMS authenticator stage
      effect: write
      questions:
      - How do I let users enroll a phone number for text message codes?
      - What provider details does a new SMS MFA stage need?
      instructions:
      - text: Create SMS stage {name} using provider {provider}, sender {from_number}, account SID {account_sid} and auth token {auth}.
        slots:
          name: requestBody.name
          provider: requestBody.provider
          from_number: requestBody.from_number
          account_sid: requestBody.account_sid
          auth: requestBody.auth
      - text: Add verify-only SMS stage {name} ({verify_only}) via {provider} from {from_number}, SID {account_sid}, token {auth}.
        slots:
          name: requestBody.name
          verify_only: requestBody.verify_only
          provider: requestBody.provider
          from_number: requestBody.from_number
          account_sid: requestBody.account_sid
          auth: requestBody.auth
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/sms/{stage_uuid}/'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an SMS authenticator stage
      effect: read
      questions:
      - Which SMS provider and sender number does a given SMS stage use?
      - Is this SMS MFA stage set to verify only?
      instructions:
      - text: Show SMS authenticator stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      - text: Fetch the provider settings of SMS stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/sms/{stage_uuid}/'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace an SMS authenticator stage's settings
      effect: write
      questions:
      - Can I overwrite every setting on an SMS MFA stage at once?
      - Which fields are mandatory when fully replacing an SMS stage?
      instructions:
      - text: 'Replace SMS stage {stage_uuid}: name {name}, provider {provider}, sender {from_number}, SID {account_sid}, token {auth}.'
        slots:
          stage_uuid: path.stage_uuid
          name: requestBody.name
          provider: requestBody.provider
          from_number: requestBody.from_number
          account_sid: requestBody.account_sid
          auth: requestBody.auth
      - text: Fully rewrite SMS MFA stage {stage_uuid} as {name} on {provider}, number {from_number}, account {account_sid}, auth {auth}.
        slots:
          stage_uuid: path.stage_uuid
          name: requestBody.name
          provider: requestBody.provider
          from_number: requestBody.from_number
          account_sid: requestBody.account_sid
          auth: requestBody.auth
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/sms/{stage_uuid}/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an SMS authenticator stage
      effect: destructive
      questions:
      - How can I remove an SMS MFA stage?
      - Can a deleted SMS authenticator stage be restored?
      instructions:
      - text: Delete SMS authenticator stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      - text: Remove text message MFA stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/sms/{stage_uuid}/'].patch
  update:
    x-apievangelist-phrasing:
      intent: Change one setting on an SMS stage
      effect: write
      questions:
      - Can I change only the sender phone number on an SMS stage?
      - Is it possible to rotate just the SMS provider auth token?
      instructions:
      - text: Change the sender number of SMS stage {stage_uuid} to {from_number}.
        slots:
          stage_uuid: path.stage_uuid
          from_number: requestBody.from_number
      - text: Rotate only the auth token on SMS stage {stage_uuid} to {auth}.
        slots:
          stage_uuid: path.stage_uuid
          auth: requestBody.auth
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/sms/{stage_uuid}/used_by/'].get
  update:
    x-apievangelist-phrasing:
      intent: See what uses an SMS stage
      effect: read
      questions:
      - Which flows use a specific SMS MFA stage?
      - Is my SMS authenticator stage referenced anywhere?
      instructions:
      - text: Show what uses SMS stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      - text: List objects bound to SMS authenticator stage {stage_uuid}.
        slots:
          stage_uuid: path.stage_uuid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/stages/authenticator/static/'].get
  update:
    x-apievangelist-phrasing:
      intent: List static recovery code stages
      effect: read
      questions:
      - Which backup code stages are configured?
      - Can I find static token stages by how many codes they generate?
      instructions:
      - text: List all static authenticator stages.
      - text: Find recovery code stages that issue {token_count} codes.
        slots:
          token_count: query.token_count
      method: generated
      generated: '2026-09-26'


# --- truncated at 32 KB (141 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/authentik/refs/heads/main/overlays/authentik-stages-api-phrasing-overlay.yaml