Cloudflare · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Cloudflare Zones API

509 actions 509 updates phrasing extends openapi/cloudflare-zones-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Cloudflare's API. It is a proposal applied on top of the contract, not a document Cloudflare publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 509 · first 16 shown; the file carries all of them

$.info
$.paths['/zones'].get
$.paths['/zones'].post
$.paths['/zones/{identifier}/access/apps'].get
$.paths['/zones/{identifier}/access/apps'].post
$.paths['/zones/{identifier}/access/apps/{app_id}'].get
$.paths['/zones/{identifier}/access/apps/{app_id}'].put
$.paths['/zones/{identifier}/access/apps/{app_id}'].delete
$.paths['/zones/{identifier}/access/apps/{app_id}/revoke_tokens'].post
$.paths['/zones/{identifier}/access/apps/{app_id}/user_policy_checks'].get
$.paths['/zones/{identifier}/access/apps/{uuid}/ca'].get
$.paths['/zones/{identifier}/access/apps/{uuid}/ca'].post
$.paths['/zones/{identifier}/access/apps/{uuid}/ca'].delete
$.paths['/zones/{identifier}/access/apps/{uuid}/policies'].get
$.paths['/zones/{identifier}/access/apps/{uuid}/policies'].post
$.paths['/zones/{identifier}/access/apps/{uuid1}/policies/{uuid}'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Cloudflare Zones API
  version: 1.0.0
extends: openapi/cloudflare-zones-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 508
- target: $.paths['/zones'].get
  update:
    x-apievangelist-phrasing:
      intent: List and filter my zones
      effect: read
      questions:
      - How do I see every domain I have added to Cloudflare?
      - Can I filter my zones by status, like only the ones still pending?
      - Which zones belong to a particular account?
      instructions:
      - text: List all my zones.
      - text: Show my zones named {name}.
        slots:
          name: query.name
      - text: List zones with status {status} for account {account_id}.
        slots:
          status: query.status
          account_id: query.account.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones'].post
  update:
    x-apievangelist-phrasing:
      intent: Add a new domain as a zone
      effect: write
      questions:
      - How do I add a new domain to my account so it can be proxied?
      - Can I create a partial (CNAME setup) zone instead of a full one?
      instructions:
      - text: Add {name} as a new zone under account {account}.
        slots:
          name: requestBody.name
          account: requestBody.account
      - text: Create a {type} zone for domain {name} in account {account}.
        slots:
          type: requestBody.type
          name: requestBody.name
          account: requestBody.account
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/apps'].get
  update:
    x-apievangelist-phrasing:
      intent: List Access applications in a zone
      effect: read
      questions:
      - What Access applications are protecting this zone?
      - Can I see all the self-hosted apps Access guards on one domain?
      instructions:
      - text: List the Access applications on zone {identifier}.
        slots:
          identifier: path.identifier
      - text: Show every Access app configured for zone {identifier}.
        slots:
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/apps'].post
  update:
    x-apievangelist-phrasing:
      intent: Add an Access application to a zone
      effect: write
      questions:
      - How do I put a new application behind Access on my zone?
      - Can I register a bookmark application in zone-level Access?
      instructions:
      - text: Add a new Access application to zone {identifier}.
        slots:
          identifier: path.identifier
      - text: Register a bookmark app with Access on zone {identifier}.
        slots:
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/apps/{app_id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get one Access application's details
      effect: read
      questions:
      - Where can I see the configuration of a single Access app on my zone?
      - What domain and session settings does this Access application use?
      instructions:
      - text: Show Access application {app_id} on zone {identifier}.
        slots:
          app_id: path.app_id
          identifier: path.identifier
      - text: Fetch the settings of app {app_id} in zone {identifier}.
        slots:
          app_id: path.app_id
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/apps/{app_id}'].put
  update:
    x-apievangelist-phrasing:
      intent: Update an Access application
      effect: write
      questions:
      - How do I change the configuration of an existing Access application?
      - Can I edit a bookmark app I already added to zone-level Access?
      instructions:
      - text: Update Access application {app_id} on zone {identifier}.
        slots:
          app_id: path.app_id
          identifier: path.identifier
      - text: Change the settings of existing app {app_id} in zone {identifier}.
        slots:
          app_id: path.app_id
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/apps/{app_id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an Access application
      effect: destructive
      questions:
      - How do I stop protecting an app with Access and remove it from my zone?
      - What happens when I delete an application from zone-level Access?
      instructions:
      - text: Delete Access application {app_id} from zone {identifier}.
        slots:
          app_id: path.app_id
          identifier: path.identifier
      - text: Remove app {app_id} from Access on zone {identifier}.
        slots:
          app_id: path.app_id
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/apps/{app_id}/revoke_tokens'].post
  update:
    x-apievangelist-phrasing:
      intent: Revoke all tokens issued for an app
      effect: destructive
      questions:
      - How do I force everyone to log in again to one Access application?
      - Can I invalidate every token that was issued for a single app?
      instructions:
      - text: Revoke all tokens issued for Access app {app_id} on zone {identifier}.
        slots:
          app_id: path.app_id
          identifier: path.identifier
      - text: Log everyone out of application {app_id} in zone {identifier}.
        slots:
          app_id: path.app_id
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/apps/{app_id}/user_policy_checks'].get
  update:
    x-apievangelist-phrasing:
      intent: Test whether users can reach an app
      effect: read
      questions:
      - How can I check if a specific user would be allowed into an Access app?
      - Is there a way to test my Access policies before rolling them out?
      instructions:
      - text: Test the Access policies of app {app_id} on zone {identifier}.
        slots:
          app_id: path.app_id
          identifier: path.identifier
      - text: Check which users pass the policy checks for app {app_id} in zone {identifier}.
        slots:
          app_id: path.app_id
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/apps/{uuid}/ca'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an app's short-lived certificate CA
      effect: read
      questions:
      - Where do I find the public key of the short-lived certificate CA for an SSH app?
      - Does this Access application already have a short-lived certificate CA?
      instructions:
      - text: Get the short-lived certificate CA for app {uuid} on zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      - text: Show the CA public key for Access app {uuid} in zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/apps/{uuid}/ca'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a short-lived certificate CA for an app
      effect: write
      questions:
      - How do I generate a short-lived certificate CA so users get ephemeral certs?
      - Can I create a new CA and public key for one Access application?
      instructions:
      - text: Create a short-lived certificate CA for app {uuid} on zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      - text: Generate a new CA and public key for Access app {uuid} in zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/apps/{uuid}/ca'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an app's short-lived certificate CA
      effect: destructive
      questions:
      - How do I remove the short-lived certificate CA from an application?
      - What breaks if I delete the CA used for short-lived certificates?
      instructions:
      - text: Delete the short-lived certificate CA of app {uuid} on zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      - text: Remove the ephemeral cert CA from Access app {uuid} in zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/apps/{uuid}/policies'].get
  update:
    x-apievangelist-phrasing:
      intent: List Access policies for an application
      effect: read
      questions:
      - Which Access policies are attached to this application?
      - Can I see the allow and block rules configured for one app?
      instructions:
      - text: List the Access policies for app {uuid} on zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      - text: Show every policy on Access application {uuid} in zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/apps/{uuid}/policies'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an Access policy for an application
      effect: write
      questions:
      - How do I add a rule that decides who can reach an Access app?
      - Can a new policy require approval or a purpose justification before access?
      instructions:
      - text: Create an Access policy named {name} with decision {decision} on app {uuid} in zone {identifier}.
        slots:
          name: requestBody.name
          decision: requestBody.decision
          uuid: path.uuid
          identifier: path.identifier
      - text: Add policy {name} to app {uuid} on zone {identifier} including {include}.
        slots:
          name: requestBody.name
          uuid: path.uuid
          identifier: path.identifier
          include: requestBody.include
      - text: Create a {decision} policy {name} for app {uuid} in zone {identifier} that requires approval {approval_required}.
        slots:
          decision: requestBody.decision
          name: requestBody.name
          uuid: path.uuid
          identifier: path.identifier
          approval_required: requestBody.approval_required
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/apps/{uuid1}/policies/{uuid}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get one Access policy
      effect: read
      questions:
      - How can I view the include, exclude and require rules of a single policy?
      - What decision does a particular Access policy make?
      instructions:
      - text: Show Access policy {uuid} of app {uuid1} on zone {identifier}.
        slots:
          uuid: path.uuid
          uuid1: path.uuid1
          identifier: path.identifier
      - text: Fetch policy {uuid} for application {uuid1} in zone {identifier}.
        slots:
          uuid: path.uuid
          uuid1: path.uuid1
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/apps/{uuid1}/policies/{uuid}'].put
  update:
    x-apievangelist-phrasing:
      intent: Update an Access policy
      effect: write
      questions:
      - How do I change who an existing Access policy lets in?
      - Can I change the precedence of a policy I already created?
      instructions:
      - text: Update Access policy {uuid} on app {uuid1} in zone {identifier} to decision {decision}.
        slots:
          uuid: path.uuid
          uuid1: path.uuid1
          identifier: path.identifier
          decision: requestBody.decision
      - text: Rename policy {uuid} of app {uuid1} on zone {identifier} to {name} and include {include}.
        slots:
          uuid: path.uuid
          uuid1: path.uuid1
          identifier: path.identifier
          name: requestBody.name
          include: requestBody.include
      - text: Set the precedence of policy {uuid} for app {uuid1} in zone {identifier} to {precedence}.
        slots:
          uuid: path.uuid
          uuid1: path.uuid1
          identifier: path.identifier
          precedence: requestBody.precedence
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/apps/{uuid1}/policies/{uuid}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an Access policy
      effect: destructive
      questions:
      - How do I remove a policy from an Access application?
      - Will deleting an Access policy change who can reach the app?
      instructions:
      - text: Delete Access policy {uuid} from app {uuid1} on zone {identifier}.
        slots:
          uuid: path.uuid
          uuid1: path.uuid1
          identifier: path.identifier
      - text: Remove policy {uuid} of application {uuid1} in zone {identifier}.
        slots:
          uuid: path.uuid
          uuid1: path.uuid1
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/apps/ca'].get
  update:
    x-apievangelist-phrasing:
      intent: List short-lived certificate CAs in a zone
      effect: read
      questions:
      - Which of my Access apps in this zone have short-lived certificate CAs?
      - Can I get all the CA public keys at once for SSH short-lived certs?
      instructions:
      - text: List all short-lived certificate CAs on zone {identifier}.
        slots:
          identifier: path.identifier
      - text: Show every ephemeral cert CA and public key in zone {identifier}.
        slots:
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/certificates'].get
  update:
    x-apievangelist-phrasing:
      intent: List Access mTLS root certificates
      effect: read
      questions:
      - What mTLS root certificates has Access got for my zone?
      - Can I see every client-auth root CA uploaded to zone-level Access?
      instructions:
      - text: List the Access mTLS certificates on zone {identifier}.
        slots:
          identifier: path.identifier
      - text: Show all mTLS root certs Access uses in zone {identifier}.
        slots:
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/certificates'].post
  update:
    x-apievangelist-phrasing:
      intent: Add an mTLS root certificate to Access
      effect: write
      questions:
      - How do I upload a root CA so Access can authenticate devices with mTLS?
      - Can I link a new mTLS certificate to specific hostnames when adding it?
      instructions:
      - text: Add mTLS root certificate {name} with PEM {certificate} to Access on zone {identifier}.
        slots:
          name: requestBody.name
          certificate: requestBody.certificate
          identifier: path.identifier
      - text: Upload root cert {name} to zone {identifier} for hostnames {associated_hostnames} using {certificate}.
        slots:
          name: requestBody.name
          identifier: path.identifier
          associated_hostnames: requestBody.associated_hostnames
          certificate: requestBody.certificate
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/certificates/{uuid}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get one Access mTLS certificate
      effect: read
      questions:
      - How can I look up a single mTLS root certificate in Access?
      - Which hostnames is this mTLS certificate associated with?
      instructions:
      - text: Show Access mTLS certificate {uuid} on zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      - text: Fetch mTLS root cert {uuid} in zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/certificates/{uuid}'].put
  update:
    x-apievangelist-phrasing:
      intent: Update an Access mTLS certificate
      effect: write
      questions:
      - How do I change which hostnames an Access mTLS certificate applies to?
      - Can I rename an mTLS root certificate I already uploaded?
      instructions:
      - text: Associate mTLS certificate {uuid} on zone {identifier} with hostnames {associated_hostnames}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
          associated_hostnames: requestBody.associated_hostnames
      - text: Rename mTLS cert {uuid} in zone {identifier} to {name} for hostnames {associated_hostnames}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
          name: requestBody.name
          associated_hostnames: requestBody.associated_hostnames
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/certificates/{uuid}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an Access mTLS certificate
      effect: destructive
      questions:
      - How do I remove an mTLS root certificate from Access?
      - What happens to devices using a root cert once I delete it from Access?
      instructions:
      - text: Delete Access mTLS certificate {uuid} from zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      - text: Remove mTLS root cert {uuid} in zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/certificates/settings'].get
  update:
    x-apievangelist-phrasing:
      intent: List mTLS hostname settings
      effect: read
      questions:
      - Which hostnames in my zone have mTLS client certificate forwarding turned on?
      - Can I see the per-hostname mTLS settings Access applies?
      instructions:
      - text: List the mTLS hostname settings for zone {identifier}.
        slots:
          identifier: path.identifier
      - text: Show how mTLS is configured per hostname in zone {identifier}.
        slots:
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/certificates/settings'].put
  update:
    x-apievangelist-phrasing:
      intent: Update mTLS hostname settings
      effect: write
      questions:
      - How do I change mTLS behavior for individual hostnames in a zone?
      - Can I turn on China network or client cert forwarding per hostname?
      instructions:
      - text: Replace the mTLS hostname settings on zone {identifier} with {settings}.
        slots:
          identifier: path.identifier
          settings: requestBody.settings
      - text: Update per-hostname mTLS settings in zone {identifier} to {settings}.
        slots:
          identifier: path.identifier
          settings: requestBody.settings
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/groups'].get
  update:
    x-apievangelist-phrasing:
      intent: List Access groups in a zone
      effect: read
      questions:
      - What Access groups have been defined for my zone?
      - Can I see the reusable user groups that zone-level Access policies reference?
      instructions:
      - text: List the Access groups on zone {identifier}.
        slots:
          identifier: path.identifier
      - text: Show every Access group in zone {identifier}.
        slots:
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/groups'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an Access group
      effect: write
      questions:
      - How do I make a reusable group of users for Access policies?
      - Can a new Access group exclude some people while including others?
      instructions:
      - text: Create Access group {name} on zone {identifier} including {include}.
        slots:
          name: requestBody.name
          identifier: path.identifier
          include: requestBody.include
      - text: Make group {name} in zone {identifier} that includes {include} and excludes {exclude}.
        slots:
          name: requestBody.name
          identifier: path.identifier
          include: requestBody.include
          exclude: requestBody.exclude
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/groups/{uuid}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get one Access group
      effect: read
      questions:
      - How can I see who belongs to one Access group?
      - What include and require rules define a particular Access group?
      instructions:
      - text: Show Access group {uuid} on zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      - text: Fetch the rules of group {uuid} in zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/groups/{uuid}'].put
  update:
    x-apievangelist-phrasing:
      intent: Update an Access group
      effect: write
      questions:
      - How do I change the membership rules of an existing Access group?
      - Can I add a require rule to a group I already made?
      instructions:
      - text: Update Access group {uuid} on zone {identifier} to include {include}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
          include: requestBody.include
      - text: Rename group {uuid} in zone {identifier} to {name} with include rules {include}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
          name: requestBody.name
          include: requestBody.include
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/groups/{uuid}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an Access group
      effect: destructive
      questions:
      - How do I get rid of an Access group I no longer use?
      - Does deleting an Access group affect the policies that reference it?
      instructions:
      - text: Delete Access group {uuid} from zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      - text: Remove group {uuid} in zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/identity_providers'].get
  update:
    x-apievangelist-phrasing:
      intent: List Access identity providers
      effect: read
      questions:
      - Which login methods are set up for Access on my zone?
      - Can I see every identity provider configured for zone-level Access?
      instructions:
      - text: List the identity providers for Access on zone {identifier}.
        slots:
          identifier: path.identifier
      - text: Show all login methods configured in zone {identifier}.
        slots:
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/identity_providers'].post
  update:
    x-apievangelist-phrasing:
      intent: Add an identity provider to Access
      effect: write
      questions:
      - How do I connect a new SSO login method to Access for a zone?
      - Can I add a one-time PIN or SAML login to zone-level Access?
      instructions:
      - text: Add a new identity provider to Access on zone {identifier}.
        slots:
          identifier: path.identifier
      - text: Connect an SSO login method to zone {identifier}.
        slots:
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/identity_providers/{uuid}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get one Access identity provider
      effect: read
      questions:
      - How can I view the configuration of a single login method?
      - What settings does this identity provider use in Access?
      instructions:
      - text: Show identity provider {uuid} on zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      - text: Fetch the config of login method {uuid} in zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/identity_providers/{uuid}'].put
  update:
    x-apievangelist-phrasing:
      intent: Update an Access identity provider
      effect: write
      questions:
      - How do I change the settings of a login method already in Access?
      - Can I rotate the client secret on an existing identity provider?
      instructions:
      - text: Update identity provider {uuid} on zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      - text: Change the configuration of login method {uuid} in zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/identity_providers/{uuid}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an Access identity provider
      effect: destructive
      questions:
      - How do I remove a login method from Access?
      - What happens to users who sign in with an identity provider I delete?
      instructions:
      - text: Delete identity provider {uuid} from zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      - text: Remove login method {uuid} from Access in zone {identifier}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/organizations'].get
  update:
    x-apievangelist-phrasing:
      intent: Get my Zero Trust organization config
      effect: read
      questions:
      - What is the auth domain of my Zero Trust organization?
      - Where can I see the login page design and seat expiry for my organization?
      instructions:
      - text: Show the Zero Trust organization settings for zone {identifier}.
        slots:
          identifier: path.identifier
      - text: Get my Zero Trust org config via zone {identifier}.
        slots:
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/organizations'].put
  update:
    x-apievangelist-phrasing:
      intent: Update my Zero Trust organization
      effect: write
      questions:
      - How do I change the login page design for my Zero Trust organization?
      - Can I make the dashboard read-only for my organization's Zero Trust settings?
      instructions:
      - text: Rename the Zero Trust organization on zone {identifier} to {name}.
        slots:
          identifier: path.identifier
          name: requestBody.name
      - text: Set the auth domain of my organization on zone {identifier} to {auth_domain}.
        slots:
          identifier: path.identifier
          auth_domain: requestBody.auth_domain
      - text: Expire inactive user seats after {user_seat_expiration_inactive_time} for zone {identifier}.
        slots:
          user_seat_expiration_inactive_time: requestBody.user_seat_expiration_inactive_time
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/organizations'].post
  update:
    x-apievangelist-phrasing:
      intent: Set up a Zero Trust organization
      effect: write
      questions:
      - How do I set up a Zero Trust organization for the first time?
      - What auth domain do I need to create my organization?
      instructions:
      - text: Create Zero Trust organization {name} with auth domain {auth_domain} on zone {identifier}.
        slots:
          name: requestBody.name
          auth_domain: requestBody.auth_domain
          identifier: path.identifier
      - text: Set up my organization on zone {identifier} named {name} at {auth_domain}.
        slots:
          identifier: path.identifier
          name: requestBody.name
          auth_domain: requestBody.auth_domain
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/organizations/revoke_user'].post
  update:
    x-apievangelist-phrasing:
      intent: Revoke all Access tokens for a user
      effect: destructive
      questions:
      - How do I cut off one person's access to every application at once?
      - Can I sign out a departing employee from all Access apps?
      instructions:
      - text: Revoke all Access tokens for {email} on zone {identifier}.
        slots:
          email: requestBody.email
          identifier: path.identifier
      - text: Kick user {email} out of every app in zone {identifier}.
        slots:
          email: requestBody.email
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/service_tokens'].get
  update:
    x-apievangelist-phrasing:
      intent: List Access service tokens
      effect: read
      questions:
      - Which service tokens exist for machine access to my zone?
      - Can I see all the non-human credentials Access has issued?
      instructions:
      - text: List the service tokens on zone {identifier}.
        slots:
          identifier: path.identifier
      - text: Show every Access service token in zone {identifier}.
        slots:
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/service_tokens'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an Access service token
      effect: write
      questions:
      - How do I give a script or bot credentials to get past Access?
      - When can I see the client secret of a new service token?
      instructions:
      - text: Create service token {name} on zone {identifier}.
        slots:
          name: requestBody.name
          identifier: path.identifier
      - text: Generate a service token {name} valid for {duration} in zone {identifier}.
        slots:
          name: requestBody.name
          duration: requestBody.duration
          identifier: path.identifier
      method: generated
      generated: '2026-09-26'
- target: $.paths['/zones/{identifier}/access/service_tokens/{uuid}'].put
  update:
    x-apievangelist-phrasing:
      intent: Update an Access service token
      effect: write
      questions:
      - How do I rename or change the lifetime of an existing service token?
      - Can I extend how long a service token lasts?
      instructions:
      - text: Rename service token {uuid} on zone {identifier} to {name}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
          name: requestBody.name
      - text: Set the duration of service token {uuid} in zone {identifier} to {duration}.
        slots:
          uuid: path.uuid
          identifier: path.identifier
          duration: requestBody.duration
      method: generated
      generated: '2026-09-26'


# --- truncated at 32 KB (351 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cloudflare/refs/heads/main/overlays/cloudflare-zones-api-phrasing-overlay.yaml