Cloudera · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Cloudera Service Iam API
80 actions
80 updates
phrasing
extends
openapi/cloudera-iam-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Cloudera's API. It is a proposal applied on top of the contract, not a document Cloudera publishes.
What the actions change
x-apievangelist-phrasing
Targets 80 · first 16 shown; the file carries all of them
$.info
$.paths['/iam/getUser'].post
$.paths['/iam/listUsers'].post
$.paths['/iam/createUser'].post
$.paths['/iam/updateUser'].post
$.paths['/iam/deleteUser'].post
$.paths['/iam/createUserAccessKey'].post
$.paths['/iam/createMachineUserAccessKey'].post
$.paths['/iam/deleteAccessKey'].post
$.paths['/iam/updateAccessKey'].post
$.paths['/iam/getAccessKey'].post
$.paths['/iam/listAccessKeys'].post
$.paths['/iam/listRoles'].post
$.paths['/iam/listResourceRoles'].post
$.paths['/iam/setAccountMessages'].post
$.paths['/iam/getAccountMessages'].post
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Cloudera Service Iam API
version: 1.0.0
extends: openapi/cloudera-iam-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-10-01'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 79
- target: $.paths['/iam/getUser'].post
update:
x-apievangelist-phrasing:
intent: Look up a CDP user's details
effect: read
questions:
- How can I see the details of one user in my CDP account?
- Which CDP user does my current access key belong to?
instructions:
- text: Show me the CDP user profile for {userId}.
slots:
userId: requestBody.userId
- text: Tell me which CDP user my access key is authenticated as.
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/listUsers'].post
update:
x-apievangelist-phrasing:
intent: List users in the CDP account
effect: read
questions:
- Can I get a list of every human user in my Cloudera CDP account?
- Is the CDP user listing paginated with a page size?
instructions:
- text: List all users in my CDP account.
- text: List the CDP users {userIds}, {pageSize} per page.
slots:
userIds: requestBody.userIds
pageSize: requestBody.pageSize
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/createUser'].post
update:
x-apievangelist-phrasing:
intent: Create a CDP user
effect: write
questions:
- How do I add a new person as a user in CDP with their email and identity provider ID?
- Can I put a new CDP user into groups at the moment I create them?
instructions:
- text: Create a CDP user with email {email} and identity provider user ID {identityProviderUserId}.
slots:
email: requestBody.email
identityProviderUserId: requestBody.identityProviderUserId
- text: Create CDP user {firstName} {lastName} ({email}, IdP ID {identityProviderUserId}) and add them to groups {groups}.
slots:
firstName: requestBody.firstName
lastName: requestBody.lastName
email: requestBody.email
identityProviderUserId: requestBody.identityProviderUserId
groups: requestBody.groups
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/updateUser'].post
update:
x-apievangelist-phrasing:
intent: Activate or deactivate a CDP user
effect: write
questions:
- Can I deactivate a CDP user without deleting them?
- What happens if I send a user update with no fields changed?
instructions:
- text: Deactivate CDP user {user} by setting active to {active}.
slots:
user: requestBody.user
active: requestBody.active
- text: Reactivate the CDP user {user}.
slots:
user: requestBody.user
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/deleteUser'].post
update:
x-apievangelist-phrasing:
intent: Delete a CDP user and their access
effect: destructive
questions:
- What gets removed when I delete a human user from CDP?
- Does deleting a CDP user also remove their access keys and group memberships?
instructions:
- text: Delete CDP user {userId} along with their access keys and role assignments.
slots:
userId: requestBody.userId
- text: Permanently remove the person {userId} from my CDP account.
slots:
userId: requestBody.userId
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/createUserAccessKey'].post
update:
x-apievangelist-phrasing:
intent: Create an API access key for a user
effect: write
questions:
- How do I generate a CDP API access key for a human user?
- Can I choose the key type when creating an access key for a user?
instructions:
- text: Create a new API access key for user {user}.
slots:
user: requestBody.user
- text: Generate a {type} access key for CDP user {user}.
slots:
type: requestBody.type
user: requestBody.user
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/createMachineUserAccessKey'].post
update:
x-apievangelist-phrasing:
intent: Create an access key for a machine user
effect: write
questions:
- How do I give a CDP machine user an API key for automation?
- Which key types can I pick when creating a machine user's access key?
instructions:
- text: Create an access key for machine user {machineUserName}.
slots:
machineUserName: requestBody.machineUserName
- text: Generate a {type} access key for the service account {machineUserName}.
slots:
type: requestBody.type
machineUserName: requestBody.machineUserName
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/deleteAccessKey'].post
update:
x-apievangelist-phrasing:
intent: Delete an API access key
effect: destructive
questions:
- How do I permanently delete a CDP access key that leaked?
- Is deleting an access key different from just disabling it?
instructions:
- text: Delete access key {accessKeyId}.
slots:
accessKeyId: requestBody.accessKeyId
- text: Permanently remove the CDP API key {accessKeyId}.
slots:
accessKeyId: requestBody.accessKeyId
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/updateAccessKey'].post
update:
x-apievangelist-phrasing:
intent: Enable or disable an access key
effect: write
questions:
- Can I temporarily disable a CDP access key instead of deleting it?
- How do I turn an inactive access key back on?
instructions:
- text: Set the status of access key {accessKeyId} to {status}.
slots:
accessKeyId: requestBody.accessKeyId
status: requestBody.status
- text: Disable access key {accessKeyId} for now.
slots:
accessKeyId: requestBody.accessKeyId
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/getAccessKey'].post
update:
x-apievangelist-phrasing:
intent: Look up an access key's details
effect: read
questions:
- Which actor owns a given CDP access key and is it active?
- Can I see details of the access key I'm calling the API with?
instructions:
- text: Show details for access key {accessKeyId}.
slots:
accessKeyId: requestBody.accessKeyId
- text: Describe the access key I'm currently using.
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/listAccessKeys'].post
update:
x-apievangelist-phrasing:
intent: List access keys in the account
effect: read
questions:
- What API access keys exist across my CDP account?
- Can I page through access keys a few at a time?
instructions:
- text: List all CDP access keys.
- text: List access keys {accessKeyIds}.
slots:
accessKeyIds: requestBody.accessKeyIds
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/listRoles'].post
update:
x-apievangelist-phrasing:
intent: List the account-level roles available
effect: read
questions:
- What account-wide roles can I grant in CDP?
- Which policies do CDP roles carry?
instructions:
- text: List every account role available in CDP.
- text: Show the roles named {roleNames}.
slots:
roleNames: requestBody.roleNames
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/listResourceRoles'].post
update:
x-apievangelist-phrasing:
intent: List available resource roles
effect: read
questions:
- Which resource roles exist for granting rights over specific CDP resources?
- Can I look up a resource role's CRN by name?
instructions:
- text: List all resource roles available in CDP.
- text: Show the resource roles {resourceRoleNames}.
slots:
resourceRoleNames: requestBody.resourceRoleNames
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/setAccountMessages'].post
update:
x-apievangelist-phrasing:
intent: Set the account's contact-your-admin message
effect: write
questions:
- Can I customize the 'contact your administrator' message users see in CDP?
- Where do I set the help text shown to users who lack access?
instructions:
- text: Set the contact-your-administrator message to {contactYourAdministratorMessage}.
slots:
contactYourAdministratorMessage: requestBody.contactYourAdministratorMessage
- text: Update the account message users see when they need admin help to {contactYourAdministratorMessage}.
slots:
contactYourAdministratorMessage: requestBody.contactYourAdministratorMessage
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/getAccountMessages'].post
update:
x-apievangelist-phrasing:
intent: Get the account's custom messages
effect: read
questions:
- What admin contact message is currently configured for my CDP account?
- Can I read back the custom account messages users see?
instructions:
- text: Show the current account messages.
- text: Get the contact-your-administrator text set on my CDP account.
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/assignUserRole'].post
update:
x-apievangelist-phrasing:
intent: Grant an account role to a user
effect: write
questions:
- How do I give a human user an account-level role like PowerUser?
- What happens if the user already has that role?
instructions:
- text: Assign role {role} to user {user}.
slots:
role: requestBody.role
user: requestBody.user
- text: Grant {user} the account role {role}.
slots:
user: requestBody.user
role: requestBody.role
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/unassignUserRole'].post
update:
x-apievangelist-phrasing:
intent: Remove an account role from a user
effect: destructive
questions:
- How can I take an account role away from a human user?
- Will unassigning fail if the user doesn't have the role?
instructions:
- text: Unassign role {role} from user {user}.
slots:
role: requestBody.role
user: requestBody.user
- text: Revoke the account role {role} held by {user}.
slots:
role: requestBody.role
user: requestBody.user
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/assignUserResourceRole'].post
update:
x-apievangelist-phrasing:
intent: Grant a user a role on a specific resource
effect: write
questions:
- How do I give a user rights over a single environment rather than the whole account?
- What CRNs do I need to grant a resource role to a person?
instructions:
- text: Assign resource role {resourceRoleCrn} on {resourceCrn} to user {user}.
slots:
resourceRoleCrn: requestBody.resourceRoleCrn
resourceCrn: requestBody.resourceCrn
user: requestBody.user
- text: Give user {user} the {resourceRoleCrn} resource role over resource {resourceCrn}.
slots:
user: requestBody.user
resourceRoleCrn: requestBody.resourceRoleCrn
resourceCrn: requestBody.resourceCrn
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/unassignUserResourceRole'].post
update:
x-apievangelist-phrasing:
intent: Remove a user's role on a specific resource
effect: destructive
questions:
- How do I revoke a person's access to one specific CDP resource?
- Does removing a user's resource role fail if it wasn't assigned?
instructions:
- text: Unassign resource role {resourceRoleCrn} on {resourceCrn} from user {user}.
slots:
resourceRoleCrn: requestBody.resourceRoleCrn
resourceCrn: requestBody.resourceCrn
user: requestBody.user
- text: Revoke user {user}'s {resourceRoleCrn} rights over {resourceCrn}.
slots:
user: requestBody.user
resourceRoleCrn: requestBody.resourceRoleCrn
resourceCrn: requestBody.resourceCrn
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/listUserAssignedRoles'].post
update:
x-apievangelist-phrasing:
intent: List a user's account roles
effect: read
questions:
- What account roles does a particular human user hold?
- Which account roles do I have myself?
instructions:
- text: List the account roles assigned to user {user}.
slots:
user: requestBody.user
- text: Show my own assigned account roles.
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/listUserAssignedResourceRoles'].post
update:
x-apievangelist-phrasing:
intent: List a user's resource role assignments
effect: read
questions:
- Which resources does a user have resource roles on?
- Can I audit a person's per-resource permissions?
instructions:
- text: List the resource roles assigned to user {user}.
slots:
user: requestBody.user
- text: Show my own resource role assignments.
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/assignMachineUserRole'].post
update:
x-apievangelist-phrasing:
intent: Grant an account role to a machine user
effect: write
questions:
- How do I give a service account (machine user) an account-level role?
- Will it error if the machine user already has the role?
instructions:
- text: Assign role {role} to machine user {machineUserName}.
slots:
role: requestBody.role
machineUserName: requestBody.machineUserName
- text: Grant the service account {machineUserName} the account role {role}.
slots:
machineUserName: requestBody.machineUserName
role: requestBody.role
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/unassignMachineUserRole'].post
update:
x-apievangelist-phrasing:
intent: Remove an account role from a machine user
effect: destructive
questions:
- Can I strip an account role from a machine user?
- What if the machine user doesn't actually hold the role I'm removing?
instructions:
- text: Unassign role {role} from machine user {machineUserName}.
slots:
role: requestBody.role
machineUserName: requestBody.machineUserName
- text: Revoke account role {role} from the service account {machineUserName}.
slots:
role: requestBody.role
machineUserName: requestBody.machineUserName
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/assignMachineUserResourceRole'].post
update:
x-apievangelist-phrasing:
intent: Grant a machine user a role on a resource
effect: write
questions:
- How do I scope a machine user's permissions to a single CDP resource?
- Which CRNs are required to give a service account a resource role?
instructions:
- text: Grant machine account {machineUserName} resource-scoped role {resourceRoleCrn} over {resourceCrn}.
slots:
resourceRoleCrn: requestBody.resourceRoleCrn
resourceCrn: requestBody.resourceCrn
machineUserName: requestBody.machineUserName
- text: Let service account {machineUserName} act as {resourceRoleCrn} over {resourceCrn}.
slots:
machineUserName: requestBody.machineUserName
resourceRoleCrn: requestBody.resourceRoleCrn
resourceCrn: requestBody.resourceCrn
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/unassignMachineUserResourceRole'].post
update:
x-apievangelist-phrasing:
intent: Remove a machine user's role on a resource
effect: destructive
questions:
- How do I revoke a machine user's rights on one specific resource?
- Does removing a service account's resource role fail when it isn't assigned?
instructions:
- text: Strip resource-scoped role {resourceRoleCrn} on {resourceCrn} from machine account {machineUserName}.
slots:
resourceRoleCrn: requestBody.resourceRoleCrn
resourceCrn: requestBody.resourceCrn
machineUserName: requestBody.machineUserName
- text: Revoke service account {machineUserName}'s {resourceRoleCrn} rights on {resourceCrn}.
slots:
machineUserName: requestBody.machineUserName
resourceRoleCrn: requestBody.resourceRoleCrn
resourceCrn: requestBody.resourceCrn
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/listMachineUserAssignedRoles'].post
update:
x-apievangelist-phrasing:
intent: List a machine user's account roles
effect: read
questions:
- What account roles has a given machine user been granted?
- Can I audit the account-level roles of a service account?
instructions:
- text: Enumerate the account-wide roles carried by machine account {machineUserName}.
slots:
machineUserName: requestBody.machineUserName
- text: Show which account roles the service account {machineUserName} holds.
slots:
machineUserName: requestBody.machineUserName
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/listMachineUserAssignedResourceRoles'].post
update:
x-apievangelist-phrasing:
intent: List a machine user's resource roles
effect: read
questions:
- Which resources does a machine user hold resource roles on?
- Can I review a service account's per-resource permissions?
instructions:
- text: Audit resource-scoped grants for machine account {machineUserName}.
slots:
machineUserName: requestBody.machineUserName
- text: Show the per-resource grants for service account {machineUserName}.
slots:
machineUserName: requestBody.machineUserName
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/listResourceAssignees'].post
update:
x-apievangelist-phrasing:
intent: List who has roles on a resource
effect: read
questions:
- Who has access to a particular CDP environment or resource, and with which role?
- Can I list every assignee of a resource along with their resource roles?
instructions:
- text: List everyone assigned resource roles on {resourceCrn}.
slots:
resourceCrn: requestBody.resourceCrn
- text: Show the assignees and their roles for resource {resourceCrn}, {pageSize} at a time.
slots:
resourceCrn: requestBody.resourceCrn
pageSize: requestBody.pageSize
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/createMachineUser'].post
update:
x-apievangelist-phrasing:
intent: Create a machine user for API access
effect: write
questions:
- How do I create a service account in CDP for automation scripts?
- Can a machine user log in to the CDP console?
instructions:
- text: Create a machine user named {machineUserName}.
slots:
machineUserName: requestBody.machineUserName
- text: Set up a new CDP service account called {machineUserName} for my pipelines.
slots:
machineUserName: requestBody.machineUserName
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/listMachineUsers'].post
update:
x-apievangelist-phrasing:
intent: List machine users in the account
effect: read
questions:
- What service accounts (machine users) exist in my CDP account?
- Can I look up specific machine users by name?
instructions:
- text: List all machine users in my account.
- text: Show the machine users {machineUserNames}.
slots:
machineUserNames: requestBody.machineUserNames
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/deleteMachineUser'].post
update:
x-apievangelist-phrasing:
intent: Delete a machine user
effect: destructive
questions:
- What gets cleaned up when I delete a CDP machine user?
- Does deleting a service account remove its access keys and group memberships?
instructions:
- text: Delete machine user {machineUserName}.
slots:
machineUserName: requestBody.machineUserName
- text: Remove the service account {machineUserName} and all its access keys.
slots:
machineUserName: requestBody.machineUserName
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/createSamlProvider'].post
update:
x-apievangelist-phrasing:
intent: Register a SAML identity provider
effect: write
questions:
- How do I connect my SAML identity provider to CDP for single sign-on?
- Can I enable SCIM provisioning when adding a SAML provider?
instructions:
- text: Create SAML provider {samlProviderName} with metadata {samlMetadataDocument}.
slots:
samlProviderName: requestBody.samlProviderName
samlMetadataDocument: requestBody.samlMetadataDocument
- text: Add SAML provider {samlProviderName} with SCIM set to {enableScim} and group sync on login {syncGroupsOnLogin}.
slots:
samlProviderName: requestBody.samlProviderName
enableScim: requestBody.enableScim
syncGroupsOnLogin: requestBody.syncGroupsOnLogin
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/deleteSamlProvider'].post
update:
x-apievangelist-phrasing:
intent: Delete a SAML identity provider
effect: destructive
questions:
- How do I remove a SAML identity provider from my CDP account?
- Can I disconnect an old SSO provider I no longer use?
instructions:
- text: Delete SAML provider {samlProviderName}.
slots:
samlProviderName: requestBody.samlProviderName
- text: Remove the {samlProviderName} SSO connection from CDP.
slots:
samlProviderName: requestBody.samlProviderName
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/listSamlProviders'].post
update:
x-apievangelist-phrasing:
intent: List SAML identity providers
effect: read
questions:
- Which SAML identity providers are configured in my CDP account?
- Can I page through SAML providers by name?
instructions:
- text: List all SAML providers in my account.
- text: List SAML providers named {samlProviderNames}.
slots:
samlProviderNames: requestBody.samlProviderNames
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/describeSamlProvider'].post
update:
x-apievangelist-phrasing:
intent: Show one SAML provider's configuration
effect: read
questions:
- What settings does a specific SAML provider have, like SCIM or group sync?
- Can I view the full configuration of one SSO provider?
instructions:
- text: Describe SAML provider {samlProviderName}.
slots:
samlProviderName: requestBody.samlProviderName
- text: Show the configuration of the {samlProviderName} SSO connection.
slots:
samlProviderName: requestBody.samlProviderName
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/updateSamlProvider'].post
update:
x-apievangelist-phrasing:
intent: Update a SAML provider's settings
effect: write
questions:
- How do I upload new SAML metadata for an existing identity provider?
- Can I switch on SCIM for a SAML provider that's already set up?
instructions:
- text: Update SAML provider {samlProviderName} with new metadata {samlMetadataDocument}.
slots:
samlProviderName: requestBody.samlProviderName
samlMetadataDocument: requestBody.samlMetadataDocument
- text: Turn workload usernames from email to {generateWorkloadUsernameByEmail} on existing SAML provider {samlProviderName}.
slots:
generateWorkloadUsernameByEmail: requestBody.generateWorkloadUsernameByEmail
samlProviderName: requestBody.samlProviderName
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/enableClouderaSSOLogin'].post
update:
x-apievangelist-phrasing:
intent: Enable Cloudera SSO login for the account
effect: write
questions:
- How do I allow all users to log in with Cloudera SSO?
- Is turning on Cloudera SSO safe if it's already enabled?
instructions:
- text: Enable Cloudera SSO interactive login for my account.
- text: Turn Cloudera SSO login back on for everyone.
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/disableClouderaSSOLogin'].post
update:
x-apievangelist-phrasing:
intent: Disable Cloudera SSO login for non-admins
effect: write
questions:
- Can I force users to log in through my own identity provider instead of Cloudera SSO?
- Who can still use Cloudera SSO after it's disabled?
instructions:
- text: Disable Cloudera SSO login for my account.
- text: Restrict Cloudera SSO so only account administrators can use it.
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/getAccount'].post
update:
x-apievangelist-phrasing:
intent: Get CDP account information
effect: read
questions:
- What account-level settings does my CDP tenant have?
- Can I retrieve information about my CDP account itself?
instructions:
- text: Show my CDP account information.
- text: Get the details of the current CDP account.
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/createGroup'].post
update:
x-apievangelist-phrasing:
intent: Create a user group
effect: write
questions:
- How do I create a group in CDP to manage roles for many users at once?
- Can a group's membership sync from the identity provider on login?
instructions:
- text: Create a group called {groupName}.
slots:
groupName: requestBody.groupName
- text: Create group {groupName} with sync-membership-on-login set to {syncMembershipOnUserLogin}.
slots:
groupName: requestBody.groupName
syncMembershipOnUserLogin: requestBody.syncMembershipOnUserLogin
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/deleteGroup'].post
update:
x-apievangelist-phrasing:
intent: Delete a user group
effect: destructive
questions:
- How do I delete a CDP group I no longer need?
- Can I remove an obsolete group from my account?
instructions:
- text: Delete group {groupName}.
slots:
groupName: requestBody.groupName
- text: Remove the {groupName} group from CDP.
slots:
groupName: requestBody.groupName
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/listGroups'].post
update:
x-apievangelist-phrasing:
intent: List groups in the account
effect: read
questions:
- What groups exist in my CDP account?
- Can I look up a few specific groups by name?
instructions:
- text: List all groups in my CDP account.
- text: Show the groups {groupNames}.
slots:
groupNames: requestBody.groupNames
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/updateGroup'].post
update:
x-apievangelist-phrasing:
intent: Change a group's membership sync setting
effect: write
questions:
- Can I change whether an existing group syncs its members when users log in?
- Is there a way to edit a group's settings after creating it?
instructions:
- text: Set sync-membership-on-login to {syncMembershipOnUserLogin} for existing group {groupName}.
slots:
syncMembershipOnUserLogin: requestBody.syncMembershipOnUserLogin
groupName: requestBody.groupName
- text: Update group {groupName} so login no longer syncs membership.
slots:
groupName: requestBody.groupName
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/addUserToGroup'].post
update:
x-apievangelist-phrasing:
intent: Add a user to a group
effect: write
questions:
- How do I put a human user into a CDP group?
- Does adding someone to a group give them the group's roles?
instructions:
- text: Add user {userId} to group {groupName}.
slots:
userId: requestBody.userId
groupName: requestBody.groupName
- text: Make {userId} a member of the {groupName} group.
slots:
userId: requestBody.userId
groupName: requestBody.groupName
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/addMachineUserToGroup'].post
update:
x-apievangelist-phrasing:
intent: Add a machine user to a group
effect: write
questions:
- Can a service account be a member of a CDP group?
- How do I give a machine user a group's permissions?
instructions:
- text: Add machine user {machineUserName} to group {groupName}.
slots:
machineUserName: requestBody.machineUserName
groupName: requestBody.groupName
- text: Put the service account {machineUserName} into {groupName}.
slots:
machineUserName: requestBody.machineUserName
groupName: requestBody.groupName
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/removeUserFromGroup'].post
update:
x-apievangelist-phrasing:
intent: Remove a user from a group
effect: destructive
questions:
- How do I take a person out of a CDP group?
- Will removing a user from a group drop the roles they got through it?
instructions:
- text: Remove user {userId} from group {groupName}.
slots:
userId: requestBody.userId
groupName: requestBody.groupName
- text: Take {userId} out of the {groupName} group.
slots:
userId: requestBody.userId
groupName: requestBody.groupName
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/removeMachineUserFromGroup'].post
update:
x-apievangelist-phrasing:
intent: Remove a machine user from a group
effect: destructive
questions:
- Can I pull a service account out of a group?
- How do I stop a machine user inheriting a group's roles?
instructions:
- text: Remove machine user {machineUserName} from group {groupName}.
slots:
machineUserName: requestBody.machineUserName
groupName: requestBody.groupName
- text: Take the service account {machineUserName} out of {groupName}.
slots:
machineUserName: requestBody.machineUserName
groupName: requestBody.groupName
method: generated
generated: '2026-10-01'
# --- truncated at 32 KB (54 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cloudera/refs/heads/main/overlays/cloudera-iam-api-phrasing-overlay.yaml