Elastic Stack · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Elastic Cloud Enterprise Platform Configuration Security API
23 actions
23 updates
phrasing
extends
openapi/elk-stack-platformconfigurationsecurity-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Elastic Stack's API. It is a proposal applied on top of the contract, not a document Elastic Stack publishes.
What the actions change
x-apievangelist-phrasing
Targets 23 · first 16 shown; the file carries all of them
$.info
$.paths['/platform/configuration/security/deployment'].get
$.paths['/platform/configuration/security/deployment'].put
$.paths['/platform/configuration/security/deployment'].post
$.paths['/platform/configuration/security/enrollment-tokens'].get
$.paths['/platform/configuration/security/enrollment-tokens'].post
$.paths['/platform/configuration/security/enrollment-tokens/{token}'].delete
$.paths['/platform/configuration/security/realms'].get
$.paths['/platform/configuration/security/realms/_reorder'].post
$.paths['/platform/configuration/security/realms/active-directory'].post
$.paths['/platform/configuration/security/realms/active-directory/{realm_id}'].get
$.paths['/platform/configuration/security/realms/active-directory/{realm_id}'].put
$.paths['/platform/configuration/security/realms/active-directory/{realm_id}'].delete
$.paths['/platform/configuration/security/realms/ldap'].post
$.paths['/platform/configuration/security/realms/ldap/{realm_id}'].get
$.paths['/platform/configuration/security/realms/ldap/{realm_id}'].put
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Elastic Cloud Enterprise Platform Configuration Security API
version: 1.0.0
extends: openapi/elk-stack-platformconfigurationsecurity-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 22
- target: $.paths['/platform/configuration/security/deployment'].get
update:
x-apievangelist-phrasing:
intent: View the platform security deployment
effect: read
questions:
- What does the current security deployment for my Elastic Cloud Enterprise platform look like?
- Is a security deployment already set up on this installation?
instructions:
- text: Show the current security deployment.
- text: Get the platform's security deployment configuration.
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/deployment'].put
update:
x-apievangelist-phrasing:
intent: Update the platform security deployment
effect: write
questions:
- Can I change the version or topology of the existing security deployment?
- How do I resize the security deployment that backs platform authentication?
instructions:
- text: Update the security deployment to version {version}.
slots:
version: requestBody.version
- text: Change the existing security deployment topology to {topology}.
slots:
topology: requestBody.topology
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/deployment'].post
update:
x-apievangelist-phrasing:
intent: Create the platform security deployment
effect: write
questions:
- How do I set up a security deployment for the first time on my platform?
- What name and version can I give a new security deployment?
instructions:
- text: Create a security deployment named {name}.
slots:
name: requestBody.name
- text: Set up a new security deployment {name} on version {version}.
slots:
name: requestBody.name
version: requestBody.version
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/enrollment-tokens'].get
update:
x-apievangelist-phrasing:
intent: List active enrollment tokens
effect: read
questions:
- Which enrollment tokens are currently active for adding hosts to the platform?
- Can I review all outstanding runner enrollment tokens?
instructions:
- text: List all active enrollment tokens.
- text: Show outstanding enrollment tokens for new hosts.
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/enrollment-tokens'].post
update:
x-apievangelist-phrasing:
intent: Create an enrollment token
effect: write
questions:
- How do I generate a token so a new host can join my installation with certain roles?
- Can an enrollment token expire after a set number of seconds, or be persistent?
instructions:
- text: Create an enrollment token with persistent set to {persistent}.
slots:
persistent: requestBody.persistent
- text: Generate an enrollment token for roles {roles} valid for {validity_in_seconds} seconds, persistent {persistent}.
slots:
roles: requestBody.roles
validity_in_seconds: requestBody.validity_in_seconds
persistent: requestBody.persistent
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/enrollment-tokens/{token}'].delete
update:
x-apievangelist-phrasing:
intent: Revoke an enrollment token
effect: destructive
questions:
- How can I revoke an enrollment token that leaked?
- Does deleting an enrollment token stop it from being used immediately?
instructions:
- text: Revoke enrollment token {token}.
slots:
token: path.token
- text: Delete the enrollment token {token} so no more hosts can use it.
slots:
token: path.token
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/realms'].get
update:
x-apievangelist-phrasing:
intent: List security realm configurations
effect: read
questions:
- Which authentication realms, like LDAP, SAML or Active Directory, are configured?
- In what order are my security realms evaluated?
instructions:
- text: List every configured security realm.
- text: Show all realm configurations across LDAP, SAML and Active Directory.
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/realms/_reorder'].post
update:
x-apievangelist-phrasing:
intent: Reorder security realms
effect: write
questions:
- Can I change which authentication realm is tried first?
- How is the evaluation order of security realms set?
instructions:
- text: Reorder the security realms to {realms}.
slots:
realms: requestBody.realms
- text: Set realm evaluation order as {realms}.
slots:
realms: requestBody.realms
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/realms/active-directory'].post
update:
x-apievangelist-phrasing:
intent: Add an Active Directory realm
effect: write
questions:
- How do I let users sign in to the platform with Active Directory?
- Can an Active Directory realm bind anonymously instead of with a bind DN?
instructions:
- text: Create Active Directory realm {id} named {name} for domain {domain_name} at {urls}, bind anonymously {bind_anonymously}.
slots:
id: requestBody.id
name: requestBody.name
domain_name: requestBody.domain_name
urls: requestBody.urls
bind_anonymously: requestBody.bind_anonymously
- text: Add an AD realm {id} called {name} on domain {domain_name}, servers {urls}, anonymous bind {bind_anonymously}, bind DN {bind_dn}.
slots:
id: requestBody.id
name: requestBody.name
domain_name: requestBody.domain_name
urls: requestBody.urls
bind_anonymously: requestBody.bind_anonymously
bind_dn: requestBody.bind_dn
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/realms/active-directory/{realm_id}'].get
update:
x-apievangelist-phrasing:
intent: Get an Active Directory realm
effect: read
questions:
- What domain and server URLs does one Active Directory realm use?
- Can I view the role mappings on an Active Directory realm?
instructions:
- text: Show Active Directory realm {realm_id}.
slots:
realm_id: path.realm_id
- text: Get the AD configuration for realm {realm_id}.
slots:
realm_id: path.realm_id
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/realms/active-directory/{realm_id}'].put
update:
x-apievangelist-phrasing:
intent: Update an Active Directory realm
effect: write
questions:
- How do I change the domain controllers an existing Active Directory realm points at?
- Can I disable an Active Directory realm without deleting it?
instructions:
- text: 'Update AD realm {realm_id}: id {id}, name {name}, domain {domain_name}, URLs {urls}, anonymous bind {bind_anonymously}.'
slots:
realm_id: path.realm_id
id: requestBody.id
name: requestBody.name
domain_name: requestBody.domain_name
urls: requestBody.urls
bind_anonymously: requestBody.bind_anonymously
- text: Set enabled {enabled} on Active Directory realm {realm_id} ({id}, {name}, {domain_name}, {urls}, bind anonymously {bind_anonymously}).
slots:
realm_id: path.realm_id
enabled: requestBody.enabled
id: requestBody.id
name: requestBody.name
domain_name: requestBody.domain_name
urls: requestBody.urls
bind_anonymously: requestBody.bind_anonymously
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/realms/active-directory/{realm_id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete an Active Directory realm
effect: destructive
questions:
- Can I remove an Active Directory login realm from the platform?
- Do I need a version number to safely delete an AD realm?
instructions:
- text: Delete Active Directory realm {realm_id}.
slots:
realm_id: path.realm_id
- text: Remove AD realm {realm_id} at version {version}.
slots:
realm_id: path.realm_id
version: query.version
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/realms/ldap'].post
update:
x-apievangelist-phrasing:
intent: Add an LDAP realm
effect: write
questions:
- How do I connect platform login to our LDAP directory?
- Can an LDAP realm use user DN templates instead of searching for users?
instructions:
- text: Create LDAP realm {id} named {name} at {urls}, bind type {bind_type}, anonymous bind {bind_anonymously}.
slots:
id: requestBody.id
name: requestBody.name
urls: requestBody.urls
bind_type: requestBody.bind_type
bind_anonymously: requestBody.bind_anonymously
- text: Add LDAP realm {id} ({name}) on {urls} with bind type {bind_type}, anonymous {bind_anonymously}, DN templates {user_dn_templates}.
slots:
id: requestBody.id
name: requestBody.name
urls: requestBody.urls
bind_type: requestBody.bind_type
bind_anonymously: requestBody.bind_anonymously
user_dn_templates: requestBody.user_dn_templates
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/realms/ldap/{realm_id}'].get
update:
x-apievangelist-phrasing:
intent: Get an LDAP realm
effect: read
questions:
- What LDAP servers and group search settings does a given realm use?
- Can I inspect a single LDAP realm's configuration?
instructions:
- text: Show LDAP realm {realm_id}.
slots:
realm_id: path.realm_id
- text: Get the LDAP configuration of realm {realm_id}.
slots:
realm_id: path.realm_id
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/realms/ldap/{realm_id}'].put
update:
x-apievangelist-phrasing:
intent: Update an LDAP realm
effect: write
questions:
- How do I change the bind credentials or servers of an existing LDAP realm?
- Can I update the group attribute an LDAP realm maps roles from?
instructions:
- text: 'Update LDAP realm {realm_id}: id {id}, name {name}, URLs {urls}, bind type {bind_type}, anonymous {bind_anonymously}.'
slots:
realm_id: path.realm_id
id: requestBody.id
name: requestBody.name
urls: requestBody.urls
bind_type: requestBody.bind_type
bind_anonymously: requestBody.bind_anonymously
- text: Change group attribute to {user_group_attribute} on LDAP realm {realm_id} ({id}, {name}, {urls}, {bind_type}, anon {bind_anonymously}).
slots:
realm_id: path.realm_id
user_group_attribute: requestBody.user_group_attribute
id: requestBody.id
name: requestBody.name
urls: requestBody.urls
bind_type: requestBody.bind_type
bind_anonymously: requestBody.bind_anonymously
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/realms/ldap/{realm_id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete an LDAP realm
effect: destructive
questions:
- Can I remove an LDAP realm we no longer use for sign-in?
- Is a version check supported when deleting an LDAP realm?
instructions:
- text: Delete LDAP realm {realm_id}.
slots:
realm_id: path.realm_id
- text: Remove LDAP realm {realm_id} at version {version}.
slots:
realm_id: path.realm_id
version: query.version
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/realms/saml'].post
update:
x-apievangelist-phrasing:
intent: Add a SAML realm
effect: write
questions:
- How do I enable single sign-on to the platform through a SAML identity provider?
- Can a SAML realm force re-authentication or sign its SAML messages?
instructions:
- text: Create SAML realm {id} named {name} with IdP {idp}, SP {sp} and attributes {attributes}.
slots:
id: requestBody.id
name: requestBody.name
idp: requestBody.idp
sp: requestBody.sp
attributes: requestBody.attributes
- text: Add SAML SSO realm {id} ({name}) using IdP {idp}, service provider {sp}, attribute mapping {attributes}, force_authn {force_authn}.
slots:
id: requestBody.id
name: requestBody.name
idp: requestBody.idp
sp: requestBody.sp
attributes: requestBody.attributes
force_authn: requestBody.force_authn
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/realms/saml/{realm_id}'].get
update:
x-apievangelist-phrasing:
intent: Get a SAML realm
effect: read
questions:
- What identity provider and attribute mappings does a given SAML realm use?
- Can I check a single SAML realm's settings?
instructions:
- text: Show SAML realm {realm_id}.
slots:
realm_id: path.realm_id
- text: Get the SAML configuration for realm {realm_id}.
slots:
realm_id: path.realm_id
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/realms/saml/{realm_id}'].put
update:
x-apievangelist-phrasing:
intent: Update a SAML realm
effect: write
questions:
- How do I update the identity provider metadata on an existing SAML realm?
- Can I change role mappings on a SAML realm I already configured?
instructions:
- text: 'Update SAML realm {realm_id}: id {id}, name {name}, IdP {idp}, SP {sp}, attributes {attributes}.'
slots:
realm_id: path.realm_id
id: requestBody.id
name: requestBody.name
idp: requestBody.idp
sp: requestBody.sp
attributes: requestBody.attributes
- text: Set role mappings {role_mappings} on SAML realm {realm_id} ({id}, {name}, {idp}, {sp}, {attributes}).
slots:
realm_id: path.realm_id
role_mappings: requestBody.role_mappings
id: requestBody.id
name: requestBody.name
idp: requestBody.idp
sp: requestBody.sp
attributes: requestBody.attributes
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/realms/saml/{realm_id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a SAML realm
effect: destructive
questions:
- Can I remove a SAML single sign-on realm from the platform?
- What version do I pass when deleting a SAML realm?
instructions:
- text: Delete SAML realm {realm_id}.
slots:
realm_id: path.realm_id
- text: Remove SAML realm {realm_id} at version {version}.
slots:
realm_id: path.realm_id
version: query.version
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/tls/{service_name}'].get
update:
x-apievangelist-phrasing:
intent: Get a service's TLS certificate chain
effect: read
questions:
- Which TLS certificate is the platform's proxy or admin console serving?
- Can I check the certificate chain installed for a platform service?
instructions:
- text: Show the TLS certificate for service {service_name}.
slots:
service_name: path.service_name
- text: Get the certificate chain in use by {service_name}.
slots:
service_name: path.service_name
method: generated
generated: '2026-09-26'
- target: $.paths['/platform/configuration/security/tls/{service_name}'].post
update:
x-apievangelist-phrasing:
intent: Set a service's TLS certificate chain
effect: write
questions:
- How do I install a new TLS certificate for a platform service?
- Can I replace an expiring certificate chain on the proxy?
instructions:
- text: Upload a new TLS certificate chain for service {service_name}.
slots:
service_name: path.service_name
- text: Replace the certificate on {service_name} with this chain.
slots:
service_name: path.service_name
method: generated
generated: '2026-09-26'