Authentik · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for authentik Stages API
211 actions
211 updates
phrasing
extends
openapi/authentik-stages-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Authentik's API. It is a proposal applied on top of the contract, not a document Authentik publishes.
What the actions change
x-apievangelist-phrasing
Targets 211 · first 16 shown; the file carries all of them
$.info
$.paths['/stages/account_lockdown/'].get
$.paths['/stages/account_lockdown/'].post
$.paths['/stages/account_lockdown/{stage_uuid}/'].get
$.paths['/stages/account_lockdown/{stage_uuid}/'].put
$.paths['/stages/account_lockdown/{stage_uuid}/'].delete
$.paths['/stages/account_lockdown/{stage_uuid}/'].patch
$.paths['/stages/account_lockdown/{stage_uuid}/used_by/'].get
$.paths['/stages/all/'].get
$.paths['/stages/all/{stage_uuid}/'].get
$.paths['/stages/all/{stage_uuid}/'].delete
$.paths['/stages/all/{stage_uuid}/used_by/'].get
$.paths['/stages/all/types/'].get
$.paths['/stages/all/user_settings/'].get
$.paths['/stages/authenticator/duo/'].get
$.paths['/stages/authenticator/duo/'].post
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for authentik Stages API
version: 1.0.0
extends: openapi/authentik-stages-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 210
- target: $.paths['/stages/account_lockdown/'].get
update:
x-apievangelist-phrasing:
intent: List account lockdown stages
effect: read
questions:
- Which account lockdown stages are configured in my authentik instance?
- Can I find the lockdown stages that revoke a user's tokens?
instructions:
- text: List all account lockdown stages.
- text: Find account lockdown stages that deactivate the user, matching {name}.
slots:
name: query.name
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/account_lockdown/'].post
update:
x-apievangelist-phrasing:
intent: Create an account lockdown stage
effect: write
questions:
- How do I add a stage that locks down a compromised account?
- Can a new lockdown stage delete sessions and set an unusable password at once?
instructions:
- text: Create an account lockdown stage named {name}.
slots:
name: requestBody.name
- text: 'Set up a new lockdown stage {name} that revokes all tokens: {revoke_tokens}.'
slots:
name: requestBody.name
revoke_tokens: requestBody.revoke_tokens
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/account_lockdown/{stage_uuid}/'].get
update:
x-apievangelist-phrasing:
intent: Get an account lockdown stage
effect: read
questions:
- What does a specific account lockdown stage do to the user when it runs?
- Is the self-service completion flow set on this lockdown stage?
instructions:
- text: Show account lockdown stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
- text: Fetch the lockdown settings of stage {stage_uuid} so I can see if it deactivates users.
slots:
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/account_lockdown/{stage_uuid}/'].put
update:
x-apievangelist-phrasing:
intent: Replace an account lockdown stage's settings
effect: write
questions:
- Can I overwrite every setting on an existing account lockdown stage in one request?
- What must I resend when fully replacing a lockdown stage's configuration?
instructions:
- text: Replace the whole configuration of lockdown stage {stage_uuid}, naming it {name}.
slots:
stage_uuid: path.stage_uuid
name: requestBody.name
- text: Fully rewrite lockdown stage {stage_uuid} as {name} with delete sessions set to {delete_sessions}.
slots:
stage_uuid: path.stage_uuid
name: requestBody.name
delete_sessions: requestBody.delete_sessions
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/account_lockdown/{stage_uuid}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete an account lockdown stage
effect: destructive
questions:
- How can I remove an account lockdown stage I no longer need?
- Is deleting a lockdown stage permanent?
instructions:
- text: Delete account lockdown stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
- text: Remove the lockdown stage {stage_uuid} from authentik.
slots:
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/account_lockdown/{stage_uuid}/'].patch
update:
x-apievangelist-phrasing:
intent: Change one setting on an account lockdown stage
effect: write
questions:
- Can I turn on token revocation for an existing lockdown stage without touching its other settings?
- Is it possible to just change where users land after a self-service lockdown?
instructions:
- text: On lockdown stage {stage_uuid}, only set deactivate user to {deactivate_user}.
slots:
stage_uuid: path.stage_uuid
deactivate_user: requestBody.deactivate_user
- text: Point lockdown stage {stage_uuid} at completion flow {self_service_completion_flow}, leaving the rest as is.
slots:
stage_uuid: path.stage_uuid
self_service_completion_flow: requestBody.self_service_completion_flow
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/account_lockdown/{stage_uuid}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses an account lockdown stage
effect: read
questions:
- Which flows depend on a given account lockdown stage?
- What would break if I removed this lockdown stage?
instructions:
- text: Show everything that references lockdown stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
- text: List the objects bound to account lockdown stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/all/'].get
update:
x-apievangelist-phrasing:
intent: List every stage of any type
effect: read
questions:
- What stages exist across all types in my authentik install?
- Can I search every stage by name regardless of its kind?
instructions:
- text: List all stages of every type.
- text: Search all stages, whatever their type, for the name {name}.
slots:
name: query.name
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/all/{stage_uuid}/'].get
update:
x-apievangelist-phrasing:
intent: Get any stage by its ID
effect: read
questions:
- How do I look up a stage when I only have its UUID and not its type?
- What kind of stage is a given stage ID?
instructions:
- text: Look up stage {stage_uuid} without knowing its type.
slots:
stage_uuid: path.stage_uuid
- text: Tell me what type of stage {stage_uuid} is.
slots:
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/all/{stage_uuid}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete a stage of any type
effect: destructive
questions:
- Can I delete a stage by ID without going through its type-specific endpoint?
- Is there one endpoint that removes any kind of stage?
instructions:
- text: Delete stage {stage_uuid}, whatever type it is.
slots:
stage_uuid: path.stage_uuid
- text: Remove the generic stage {stage_uuid} from the stage list.
slots:
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/all/{stage_uuid}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses a stage of any type
effect: read
questions:
- Which objects reference a stage when I don't know what type it is?
- Is a given stage ID still bound to any flow?
instructions:
- text: Show what uses stage {stage_uuid}, regardless of type.
slots:
stage_uuid: path.stage_uuid
- text: Check whether generic stage {stage_uuid} is referenced anywhere.
slots:
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/all/types/'].get
update:
x-apievangelist-phrasing:
intent: List the stage types that can be created
effect: read
questions:
- What kinds of stages can I create in authentik?
- Which stage types are available to add to a flow?
instructions:
- text: List all creatable stage types.
- text: Show me every stage type I'm allowed to create.
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/all/user_settings/'].get
update:
x-apievangelist-phrasing:
intent: List stages a user can configure themselves
effect: read
questions:
- Which stages can the current user set up from their own settings page?
- What self-service stages are exposed to users?
instructions:
- text: List the stages the current user can configure.
- text: Show the user-configurable settings stages.
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/duo/'].get
update:
x-apievangelist-phrasing:
intent: List Duo authenticator stages
effect: read
questions:
- Which Duo MFA setup stages are configured?
- Can I find Duo stages by their API hostname?
instructions:
- text: List all Duo authenticator stages.
- text: Find Duo stages that use API hostname {api_hostname}.
slots:
api_hostname: query.api_hostname
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/duo/'].post
update:
x-apievangelist-phrasing:
intent: Create a Duo authenticator stage
effect: write
questions:
- How do I connect Duo push MFA to authentik as a setup stage?
- What Duo credentials do I need to create a Duo stage?
instructions:
- text: Create Duo stage {name} with client ID {client_id}, secret {client_secret} and host {api_hostname}.
slots:
name: requestBody.name
client_id: requestBody.client_id
client_secret: requestBody.client_secret
api_hostname: requestBody.api_hostname
- text: Add a Duo authenticator stage {name} with admin integration key {admin_integration_key}, host {api_hostname}, client {client_id} and secret {client_secret}.
slots:
name: requestBody.name
admin_integration_key: requestBody.admin_integration_key
api_hostname: requestBody.api_hostname
client_id: requestBody.client_id
client_secret: requestBody.client_secret
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/duo/{stage_uuid}/'].get
update:
x-apievangelist-phrasing:
intent: Get a Duo authenticator stage
effect: read
questions:
- What Duo hostname and client ID is a given Duo stage using?
- Does this Duo stage have a configure flow set?
instructions:
- text: Show Duo stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
- text: Fetch the Duo connection details for stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/duo/{stage_uuid}/'].put
update:
x-apievangelist-phrasing:
intent: Replace a Duo authenticator stage's settings
effect: write
questions:
- Can I overwrite all of a Duo stage's credentials and settings at once?
- What fields are required when fully replacing a Duo stage?
instructions:
- text: 'Replace Duo stage {stage_uuid} entirely: name {name}, client {client_id}, secret {client_secret}, host {api_hostname}.'
slots:
stage_uuid: path.stage_uuid
name: requestBody.name
client_id: requestBody.client_id
client_secret: requestBody.client_secret
api_hostname: requestBody.api_hostname
- text: Rewrite the full config of Duo stage {stage_uuid} as {name} on host {api_hostname} using client {client_id} and secret {client_secret}.
slots:
stage_uuid: path.stage_uuid
name: requestBody.name
api_hostname: requestBody.api_hostname
client_id: requestBody.client_id
client_secret: requestBody.client_secret
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/duo/{stage_uuid}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete a Duo authenticator stage
effect: destructive
questions:
- How can I remove a Duo MFA stage?
- Is deleting a Duo authenticator stage reversible?
instructions:
- text: Delete Duo stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
- text: Remove the Duo authenticator stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/duo/{stage_uuid}/'].patch
update:
x-apievangelist-phrasing:
intent: Change one setting on a Duo stage
effect: write
questions:
- Can I rotate just the Duo client secret on an existing stage?
- Is it possible to change only the friendly name users see for Duo?
instructions:
- text: Update only the client secret of Duo stage {stage_uuid} to {client_secret}.
slots:
stage_uuid: path.stage_uuid
client_secret: requestBody.client_secret
- text: Set the friendly name of Duo stage {stage_uuid} to {friendly_name}.
slots:
stage_uuid: path.stage_uuid
friendly_name: requestBody.friendly_name
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/duo/{stage_uuid}/enrollment_status/'].post
update:
x-apievangelist-phrasing:
intent: Check a user's Duo enrollment status
effect: read
questions:
- Has the user in the current session finished enrolling in Duo?
- Can I check Duo enrollment progress during a flow?
instructions:
- text: Check the Duo enrollment status for the current session on stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
- text: See if the current user has completed Duo enrollment via stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/duo/{stage_uuid}/import_device_manual/'].post
update:
x-apievangelist-phrasing:
intent: Import one Duo device for a user
effect: write
questions:
- Can I link a specific Duo user's device to an authentik username by hand?
- What do I need to manually import a single Duo device?
instructions:
- text: Import Duo user {duo_user_id}'s device for username {username} via stage {stage_uuid}.
slots:
duo_user_id: requestBody.duo_user_id
username: requestBody.username
stage_uuid: path.stage_uuid
- text: Manually map Duo ID {duo_user_id} to authentik user {username} on Duo stage {stage_uuid}.
slots:
duo_user_id: requestBody.duo_user_id
username: requestBody.username
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/duo/{stage_uuid}/import_devices_automatic/'].post
update:
x-apievangelist-phrasing:
intent: Bulk import Duo devices automatically
effect: write
questions:
- How do I pull all existing Duo devices into authentik automatically?
- Can authentik sync every Duo enrollment in one go?
instructions:
- text: Automatically import all Duo devices through stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
- text: Run the automatic Duo device import for stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/duo/{stage_uuid}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses a Duo stage
effect: read
questions:
- Which flows reference a particular Duo stage?
- Is my Duo MFA stage bound to anything before I delete it?
instructions:
- text: Show what uses Duo stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
- text: List objects referencing the Duo authenticator stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/email/'].get
update:
x-apievangelist-phrasing:
intent: List email authenticator stages
effect: read
questions:
- Which email one-time-code MFA stages are set up?
- Can I find email authenticator stages that use a particular SMTP host?
instructions:
- text: List all email authenticator stages.
- text: Find email OTP stages sending from {from_address}.
slots:
from_address: query.from_address
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/email/'].post
update:
x-apievangelist-phrasing:
intent: Create an email authenticator stage
effect: write
questions:
- How do I let users enroll email as a second factor?
- Can a new email MFA stage use the global email settings instead of its own SMTP server?
instructions:
- text: Create an email authenticator stage named {name}.
slots:
name: requestBody.name
- text: Add email MFA stage {name} with subject {subject} and code expiry {token_expiry}.
slots:
name: requestBody.name
subject: requestBody.subject
token_expiry: requestBody.token_expiry
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/email/{stage_uuid}/'].get
update:
x-apievangelist-phrasing:
intent: Get an email authenticator stage
effect: read
questions:
- What SMTP settings is a given email MFA stage using?
- How long are codes valid on this email authenticator stage?
instructions:
- text: Show email authenticator stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
- text: Fetch the SMTP and code settings of email MFA stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/email/{stage_uuid}/'].put
update:
x-apievangelist-phrasing:
intent: Replace an email authenticator stage's settings
effect: write
questions:
- Can I overwrite the entire configuration of an email MFA stage?
- What happens to unspecified fields when I fully replace an email authenticator stage?
instructions:
- text: Replace email authenticator stage {stage_uuid} entirely, naming it {name}.
slots:
stage_uuid: path.stage_uuid
name: requestBody.name
- text: Fully rewrite email MFA stage {stage_uuid} as {name} using SMTP host {host} and port {port}.
slots:
stage_uuid: path.stage_uuid
name: requestBody.name
host: requestBody.host
port: requestBody.port
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/email/{stage_uuid}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete an email authenticator stage
effect: destructive
questions:
- How can I get rid of an email MFA stage?
- Will deleting an email authenticator stage affect flows that use it?
instructions:
- text: Delete email authenticator stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
- text: Remove email OTP stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/email/{stage_uuid}/'].patch
update:
x-apievangelist-phrasing:
intent: Change one setting on an email authenticator stage
effect: write
questions:
- Can I change only the email subject line for one-time codes?
- Is it possible to switch an email MFA stage to the global email settings without resending everything?
instructions:
- text: Change just the subject of email MFA stage {stage_uuid} to {subject}.
slots:
stage_uuid: path.stage_uuid
subject: requestBody.subject
- text: Set use global settings to {use_global_settings} on email authenticator stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
use_global_settings: requestBody.use_global_settings
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/email/{stage_uuid}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses an email authenticator stage
effect: read
questions:
- Which flows rely on a specific email MFA stage?
- Is this email authenticator stage still in use anywhere?
instructions:
- text: Show what uses email authenticator stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
- text: List references to email OTP stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/endpoint_gdtc/'].get
update:
x-apievangelist-phrasing:
intent: List Google Device Trust endpoint stages
effect: read
questions:
- Which Google Device Trust connector stages are configured?
- Can I filter endpoint GDTC stages by their configure flow?
instructions:
- text: List all endpoint GDTC authenticator stages.
- text: Find Google Device Trust stages named {name}.
slots:
name: query.name
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/endpoint_gdtc/'].post
update:
x-apievangelist-phrasing:
intent: Create a Google Device Trust endpoint stage
effect: write
questions:
- How do I add a Google Device Trust check to a login flow?
- What credentials does a new endpoint GDTC stage require?
instructions:
- text: Create endpoint GDTC stage {name} with service account credentials {credentials}.
slots:
name: requestBody.name
credentials: requestBody.credentials
- text: Add a Google Device Trust stage {name} shown to users as {friendly_name}, using credentials {credentials}.
slots:
name: requestBody.name
friendly_name: requestBody.friendly_name
credentials: requestBody.credentials
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/endpoint_gdtc/{stage_uuid}/'].get
update:
x-apievangelist-phrasing:
intent: Get a Google Device Trust endpoint stage
effect: read
questions:
- What is configured on a specific Google Device Trust stage?
- Which configure flow does this endpoint GDTC stage point to?
instructions:
- text: Show endpoint GDTC stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
- text: Fetch the details of Google Device Trust stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/endpoint_gdtc/{stage_uuid}/'].put
update:
x-apievangelist-phrasing:
intent: Replace a Google Device Trust stage's settings
effect: write
questions:
- Can I overwrite a Google Device Trust stage's name and credentials together?
- Does fully replacing an endpoint GDTC stage require resending the credentials?
instructions:
- text: Replace endpoint GDTC stage {stage_uuid} with name {name} and credentials {credentials}.
slots:
stage_uuid: path.stage_uuid
name: requestBody.name
credentials: requestBody.credentials
- text: Fully rewrite Google Device Trust stage {stage_uuid}, calling it {name}, with credentials {credentials}.
slots:
stage_uuid: path.stage_uuid
name: requestBody.name
credentials: requestBody.credentials
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/endpoint_gdtc/{stage_uuid}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete a Google Device Trust endpoint stage
effect: destructive
questions:
- How can I remove a Google Device Trust stage?
- Is an endpoint GDTC stage gone for good once deleted?
instructions:
- text: Delete endpoint GDTC stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
- text: Remove Google Device Trust stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/endpoint_gdtc/{stage_uuid}/'].patch
update:
x-apievangelist-phrasing:
intent: Change one setting on a Google Device Trust stage
effect: write
questions:
- Can I swap only the service account credentials on a Google Device Trust stage?
- Is it possible to rename an endpoint GDTC stage without touching its credentials?
instructions:
- text: Update just the credentials of endpoint GDTC stage {stage_uuid} to {credentials}.
slots:
stage_uuid: path.stage_uuid
credentials: requestBody.credentials
- text: Rename Google Device Trust stage {stage_uuid} to {name}.
slots:
stage_uuid: path.stage_uuid
name: requestBody.name
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/endpoint_gdtc/{stage_uuid}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses a Google Device Trust stage
effect: read
questions:
- Which flows reference my Google Device Trust stage?
- Is an endpoint GDTC stage still bound to anything?
instructions:
- text: Show what uses endpoint GDTC stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
- text: List references to Google Device Trust stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/sms/'].get
update:
x-apievangelist-phrasing:
intent: List SMS authenticator stages
effect: read
questions:
- Which SMS MFA stages are configured?
- Can I find SMS stages that only verify phone numbers during enrollment?
instructions:
- text: List all SMS authenticator stages.
- text: Find SMS stages sending from number {from_number}.
slots:
from_number: query.from_number
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/sms/'].post
update:
x-apievangelist-phrasing:
intent: Create an SMS authenticator stage
effect: write
questions:
- How do I let users enroll a phone number for text message codes?
- What provider details does a new SMS MFA stage need?
instructions:
- text: Create SMS stage {name} using provider {provider}, sender {from_number}, account SID {account_sid} and auth token {auth}.
slots:
name: requestBody.name
provider: requestBody.provider
from_number: requestBody.from_number
account_sid: requestBody.account_sid
auth: requestBody.auth
- text: Add verify-only SMS stage {name} ({verify_only}) via {provider} from {from_number}, SID {account_sid}, token {auth}.
slots:
name: requestBody.name
verify_only: requestBody.verify_only
provider: requestBody.provider
from_number: requestBody.from_number
account_sid: requestBody.account_sid
auth: requestBody.auth
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/sms/{stage_uuid}/'].get
update:
x-apievangelist-phrasing:
intent: Get an SMS authenticator stage
effect: read
questions:
- Which SMS provider and sender number does a given SMS stage use?
- Is this SMS MFA stage set to verify only?
instructions:
- text: Show SMS authenticator stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
- text: Fetch the provider settings of SMS stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/sms/{stage_uuid}/'].put
update:
x-apievangelist-phrasing:
intent: Replace an SMS authenticator stage's settings
effect: write
questions:
- Can I overwrite every setting on an SMS MFA stage at once?
- Which fields are mandatory when fully replacing an SMS stage?
instructions:
- text: 'Replace SMS stage {stage_uuid}: name {name}, provider {provider}, sender {from_number}, SID {account_sid}, token {auth}.'
slots:
stage_uuid: path.stage_uuid
name: requestBody.name
provider: requestBody.provider
from_number: requestBody.from_number
account_sid: requestBody.account_sid
auth: requestBody.auth
- text: Fully rewrite SMS MFA stage {stage_uuid} as {name} on {provider}, number {from_number}, account {account_sid}, auth {auth}.
slots:
stage_uuid: path.stage_uuid
name: requestBody.name
provider: requestBody.provider
from_number: requestBody.from_number
account_sid: requestBody.account_sid
auth: requestBody.auth
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/sms/{stage_uuid}/'].delete
update:
x-apievangelist-phrasing:
intent: Delete an SMS authenticator stage
effect: destructive
questions:
- How can I remove an SMS MFA stage?
- Can a deleted SMS authenticator stage be restored?
instructions:
- text: Delete SMS authenticator stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
- text: Remove text message MFA stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/sms/{stage_uuid}/'].patch
update:
x-apievangelist-phrasing:
intent: Change one setting on an SMS stage
effect: write
questions:
- Can I change only the sender phone number on an SMS stage?
- Is it possible to rotate just the SMS provider auth token?
instructions:
- text: Change the sender number of SMS stage {stage_uuid} to {from_number}.
slots:
stage_uuid: path.stage_uuid
from_number: requestBody.from_number
- text: Rotate only the auth token on SMS stage {stage_uuid} to {auth}.
slots:
stage_uuid: path.stage_uuid
auth: requestBody.auth
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/sms/{stage_uuid}/used_by/'].get
update:
x-apievangelist-phrasing:
intent: See what uses an SMS stage
effect: read
questions:
- Which flows use a specific SMS MFA stage?
- Is my SMS authenticator stage referenced anywhere?
instructions:
- text: Show what uses SMS stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
- text: List objects bound to SMS authenticator stage {stage_uuid}.
slots:
stage_uuid: path.stage_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/stages/authenticator/static/'].get
update:
x-apievangelist-phrasing:
intent: List static recovery code stages
effect: read
questions:
- Which backup code stages are configured?
- Can I find static token stages by how many codes they generate?
instructions:
- text: List all static authenticator stages.
- text: Find recovery code stages that issue {token_count} codes.
slots:
token_count: query.token_count
method: generated
generated: '2026-09-26'
# --- truncated at 32 KB (141 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/authentik/refs/heads/main/overlays/authentik-stages-api-phrasing-overlay.yaml