Microsoft Entra ID (formerly Azure AD) · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Identity.SignIns Oauth2 Permission Grants.o Auth2…

7 actions 7 updates phrasing extends openapi/azure-ad-oauth2permissiongrants-oauth2permissiongrant-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Microsoft Entra ID (formerly Azure AD)'s API. It is a proposal applied on top of the contract, not a document Microsoft Entra ID (formerly Azure AD) publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 7

$.info
$.paths['/oauth2PermissionGrants'].get
$.paths['/oauth2PermissionGrants'].post
$.paths['/oauth2PermissionGrants/{oAuth2PermissionGrant-id}'].get
$.paths['/oauth2PermissionGrants/{oAuth2PermissionGrant-id}'].delete
$.paths['/oauth2PermissionGrants/{oAuth2PermissionGrant-id}'].patch
$.paths['/oauth2PermissionGrants/$count'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Identity.SignIns Oauth2 Permission Grants.o Auth2…
  version: 1.0.0
extends: openapi/azure-ad-oauth2permissiongrants-oauth2permissiongrant-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-10-01'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 6
- target: $.paths['/oauth2PermissionGrants'].get
  update:
    x-apievangelist-phrasing:
      intent: List delegated permission grants
      effect: read
      questions:
      - Which client apps have been granted delegated permissions to call APIs for signed-in users?
      - How do I audit every OAuth2 consent grant in my tenant?
      - Can I filter delegated grants down to a single client app?
      instructions:
      - text: List all delegated permission grants in the tenant.
      - text: List delegated permission grants matching {filter}.
        slots:
          filter: query.$filter
      method: generated
      generated: '2026-10-01'
- target: $.paths['/oauth2PermissionGrants'].post
  update:
    x-apievangelist-phrasing:
      intent: Grant delegated permissions to a client app
      effect: write
      questions:
      - How do I programmatically consent to delegated scopes for an app on behalf of all users?
      - Can I grant a client service principal access to an API for just one user?
      instructions:
      - text: Grant client {client_id} the delegated scopes {scope} on resource {resource_id} for all principals.
        slots:
          client_id: requestBody.clientId
          scope: requestBody.scope
          resource_id: requestBody.resourceId
      - text: Create a delegated grant with consent type {consent_type} letting client {client_id} access {resource_id} as user {principal_id} with scopes {scope}.
        slots:
          consent_type: requestBody.consentType
          client_id: requestBody.clientId
          resource_id: requestBody.resourceId
          principal_id: requestBody.principalId
          scope: requestBody.scope
      method: generated
      generated: '2026-10-01'
- target: $.paths['/oauth2PermissionGrants/{oAuth2PermissionGrant-id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get one delegated permission grant
      effect: read
      questions:
      - What scopes does a specific delegated permission grant cover?
      - How do I check whether a particular consent grant is for all principals or one user?
      instructions:
      - text: Show delegated permission grant {grant_id}.
        slots:
          grant_id: path.oAuth2PermissionGrant-id
      - text: Tell me the client, resource and scopes on grant {grant_id}.
        slots:
          grant_id: path.oAuth2PermissionGrant-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/oauth2PermissionGrants/{oAuth2PermissionGrant-id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Revoke a delegated permission grant
      effect: destructive
      questions:
      - How do I revoke consent an app was given to act on users' behalf?
      - Do existing access tokens stop working immediately when I remove a delegated grant?
      instructions:
      - text: Revoke delegated permission grant {grant_id}.
        slots:
          grant_id: path.oAuth2PermissionGrant-id
      - text: Delete consent grant {grant_id} so no new tokens are issued for its scopes.
        slots:
          grant_id: path.oAuth2PermissionGrant-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/oauth2PermissionGrants/{oAuth2PermissionGrant-id}'].patch
  update:
    x-apievangelist-phrasing:
      intent: Change the scopes on a delegated grant
      effect: write
      questions:
      - Can I add or remove scopes on a consent grant that already exists?
      - How do I narrow an existing delegated grant to fewer permissions?
      instructions:
      - text: Set the scopes on existing grant {grant_id} to {scope}.
        slots:
          grant_id: path.oAuth2PermissionGrant-id
          scope: requestBody.scope
      - text: Remove every scope except User.Read from delegated grant {grant_id}.
        slots:
          grant_id: path.oAuth2PermissionGrant-id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/oauth2PermissionGrants/$count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count delegated permission grants
      effect: read
      questions:
      - How many delegated permission grants exist across my tenant?
      - What's the count of consent grants that match a filter such as a consent type?
      instructions:
      - text: Count the delegated permission grants.
      - text: Count delegated grants where {filter}.
        slots:
          filter: query.$filter
      method: generated
      generated: '2026-10-01'