Elastic Stack · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Elastic Cloud Enterprise Authentication API
19 actions
19 updates
phrasing
extends
openapi/elk-stack-authentication-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Elastic Stack's API. It is a proposal applied on top of the contract, not a document Elastic Stack publishes.
What the actions change
x-apievangelist-phrasing
Targets 19 · first 16 shown; the file carries all of them
$.info
$.paths['/users/auth'].get
$.paths['/users/auth/_login'].post
$.paths['/users/auth/_logout'].post
$.paths['/users/auth/_refresh'].post
$.paths['/users/auth/keys'].get
$.paths['/users/auth/keys'].post
$.paths['/users/auth/keys'].delete
$.paths['/users/auth/keys/_all'].get
$.paths['/users/auth/keys/_all'].delete
$.paths['/users/auth/keys/{api_key_id}'].get
$.paths['/users/auth/keys/{api_key_id}'].delete
$.paths['/users/auth/methods'].get
$.paths['/users/auth/saml/_callback'].post
$.paths['/users/auth/saml/_init'].get
$.paths['/users/{user_id}/auth/keys'].get
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Elastic Cloud Enterprise Authentication API
version: 1.0.0
extends: openapi/elk-stack-authentication-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 18
- target: $.paths['/users/auth'].get
update:
x-apievangelist-phrasing:
intent: Get my authentication info
effect: read
questions:
- Am I currently holding elevated permissions in Elastic Cloud Enterprise?
- Can I see whether my user has a TOTP device set up?
instructions:
- text: Show my current authentication information.
- text: Tell me whether my session has elevated permissions.
method: generated
generated: '2026-09-26'
- target: $.paths['/users/auth/_login'].post
update:
x-apievangelist-phrasing:
intent: Log in with a username and password
effect: write
questions:
- How do I sign in to ECE with a username and password?
- What does a login request need to return a session token?
instructions:
- text: Log in as {username} with password {password}.
slots:
username: requestBody.username
password: requestBody.password
- text: Authenticate user {username} using {password} and login state {login_state}.
slots:
username: requestBody.username
password: requestBody.password
login_state: requestBody.login_state
method: generated
generated: '2026-09-26'
- target: $.paths['/users/auth/_logout'].post
update:
x-apievangelist-phrasing:
intent: Log out of the current session
effect: destructive
questions:
- How do I end my current ECE session?
- Does logging out destroy the session token?
instructions:
- text: Log me out.
- text: Destroy my current session.
method: generated
generated: '2026-09-26'
- target: $.paths['/users/auth/_refresh'].post
update:
x-apievangelist-phrasing:
intent: Refresh my authentication token
effect: write
questions:
- Can I get a new auth token before the current one expires?
- What call issues a fresh authentication token?
instructions:
- text: Refresh my authentication token.
- text: Issue me a new session token.
method: generated
generated: '2026-09-26'
- target: $.paths['/users/auth/keys'].get
update:
x-apievangelist-phrasing:
intent: List API keys I can see
effect: read
questions:
- Which API keys exist that I am allowed to view?
- Can I page through the API key list?
instructions:
- text: List my API keys.
- text: Show the next page of API keys from {next_page}.
slots:
next_page: query.next_page
method: generated
generated: '2026-09-26'
- target: $.paths['/users/auth/keys'].post
update:
x-apievangelist-phrasing:
intent: Create an API key
effect: write
questions:
- How do I create a new API key for automation?
- Can a new API key have an expiration and role assignments?
instructions:
- text: Create an API key described as {description}.
slots:
description: requestBody.description
- text: Create an API key {description} that expires in {expiration}.
slots:
description: requestBody.description
expiration: requestBody.expiration
method: generated
generated: '2026-09-26'
- target: $.paths['/users/auth/keys'].delete
update:
x-apievangelist-phrasing:
intent: Delete several of my API keys
effect: destructive
questions:
- Can I revoke a batch of API keys in one call?
- What deletes or invalidates a list of my API keys?
instructions:
- text: Delete the API keys {keys}.
slots:
keys: requestBody.keys
- text: 'Invalidate these API keys at once: {keys}.'
slots:
keys: requestBody.keys
method: generated
generated: '2026-09-26'
- target: $.paths['/users/auth/keys/_all'].get
update:
x-apievangelist-phrasing:
intent: List API keys of all users (deprecated)
effect: read
questions:
- Can an admin see the API keys belonging to every user?
- Is the all-users API key listing still supported?
instructions:
- text: List API keys for all users with the deprecated endpoint.
- text: Show every user's API key metadata.
method: generated
generated: '2026-09-26'
- target: $.paths['/users/auth/keys/_all'].delete
update:
x-apievangelist-phrasing:
intent: Delete API keys across multiple users
effect: destructive
questions:
- Can I revoke API keys belonging to several different users in one request?
- How does an admin invalidate other users' keys in bulk?
instructions:
- text: 'Delete these API keys across users: {user_api_keys}.'
slots:
user_api_keys: requestBody.user_api_keys
- text: Invalidate the multi-user key set {user_api_keys}.
slots:
user_api_keys: requestBody.user_api_keys
method: generated
generated: '2026-09-26'
- target: $.paths['/users/auth/keys/{api_key_id}'].get
update:
x-apievangelist-phrasing:
intent: Get one of my API keys
effect: read
questions:
- What is the metadata for a particular API key?
- Can I check when a specific key was created?
instructions:
- text: Get API key {api_key_id}.
slots:
api_key_id: path.api_key_id
- text: Show the metadata for my key {api_key_id}.
slots:
api_key_id: path.api_key_id
method: generated
generated: '2026-09-26'
- target: $.paths['/users/auth/keys/{api_key_id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete one of my API keys
effect: destructive
questions:
- How do I revoke a single API key that leaked?
- Can I invalidate just one of my keys?
instructions:
- text: Delete API key {api_key_id}.
slots:
api_key_id: path.api_key_id
- text: Revoke my key {api_key_id} now.
slots:
api_key_id: path.api_key_id
method: generated
generated: '2026-09-26'
- target: $.paths['/users/auth/methods'].get
update:
x-apievangelist-phrasing:
intent: List available authentication methods
effect: read
questions:
- Which sign-in methods are enabled, like password or SAML?
- What authentication options does this installation offer?
instructions:
- text: List the available authentication methods.
- text: Show which login options are enabled.
method: generated
generated: '2026-09-26'
- target: $.paths['/users/auth/saml/_callback'].post
update:
x-apievangelist-phrasing:
intent: Complete SAML sign-in from the identity provider
effect: write
questions:
- What handles the SAML response coming back from my identity provider?
- Is RelayState needed when completing SAML login?
instructions:
- text: Complete SAML login with response {SAMLResponse}.
slots:
SAMLResponse: requestBody.SAMLResponse
- text: Post SAML response {SAMLResponse} with relay state {RelayState}.
slots:
SAMLResponse: requestBody.SAMLResponse
RelayState: requestBody.RelayState
method: generated
generated: '2026-09-26'
- target: $.paths['/users/auth/saml/_init'].get
update:
x-apievangelist-phrasing:
intent: Start SAML single sign-on
effect: read
questions:
- How do I kick off SAML single sign-on to my identity provider?
- Can I choose which SAML realm to redirect to?
instructions:
- text: Start SAML sign-on.
- text: Begin SAML SSO against realm {realm} with state {state}.
slots:
realm: query.realm
state: query.state
method: generated
generated: '2026-09-26'
- target: $.paths['/users/{user_id}/auth/keys'].get
update:
x-apievangelist-phrasing:
intent: List a user's API keys
effect: read
questions:
- Which API keys has a particular user created?
- Can an admin audit the keys one user owns?
instructions:
- text: List the API keys created by user {user_id}.
slots:
user_id: path.user_id
- text: Audit every key belonging to {user_id}.
slots:
user_id: path.user_id
method: generated
generated: '2026-09-26'
- target: $.paths['/users/{user_id}/auth/keys'].delete
update:
x-apievangelist-phrasing:
intent: Delete all API keys of a user
effect: destructive
questions:
- How do I revoke every API key for a user who left?
- Can I wipe all of one user's keys in a single call?
instructions:
- text: Delete all API keys for user {user_id}.
slots:
user_id: path.user_id
- text: Invalidate every key owned by {user_id}.
slots:
user_id: path.user_id
method: generated
generated: '2026-09-26'
- target: $.paths['/users/{user_id}/auth/keys/{api_key_id}'].get
update:
x-apievangelist-phrasing:
intent: Get one API key of a user
effect: read
questions:
- Can I view a single API key that belongs to another user?
- What metadata does one user's specific key have?
instructions:
- text: Get API key {api_key_id} of user {user_id}.
slots:
api_key_id: path.api_key_id
user_id: path.user_id
- text: Show metadata for user {user_id}'s key {api_key_id}.
slots:
user_id: path.user_id
api_key_id: path.api_key_id
method: generated
generated: '2026-09-26'
- target: $.paths['/users/{user_id}/auth/keys/{api_key_id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete one API key of a user
effect: destructive
questions:
- How does an admin revoke one specific key belonging to another user?
- Can I invalidate a single key without touching the user's others?
instructions:
- text: Delete API key {api_key_id} of user {user_id}.
slots:
api_key_id: path.api_key_id
user_id: path.user_id
- text: Revoke user {user_id}'s key {api_key_id}.
slots:
user_id: path.user_id
api_key_id: path.api_key_id
method: generated
generated: '2026-09-26'