Elastic Stack · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Elk Stack Security API

101 actions 101 updates phrasing extends openapi/elk-stack-security-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Elastic Stack's API. It is a proposal applied on top of the contract, not a document Elastic Stack publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 101 · first 16 shown; the file carries all of them

$.info
$.paths['/_encryption/_reset'].post
$.paths['/_security/profile/_activate'].post
$.paths['/_security/_authenticate'].get
$.paths['/_security/role'].get
$.paths['/_security/role'].post
$.paths['/_security/role'].delete
$.paths['/_security/api_key/_bulk_update'].post
$.paths['/_security/user/{username}/_password'].put
$.paths['/_security/user/{username}/_password'].post
$.paths['/_security/user/_password'].put
$.paths['/_security/user/_password'].post
$.paths['/_security/api_key/{ids}/_clear_cache'].post
$.paths['/_security/privilege/{application}/_clear_cache'].post
$.paths['/_security/realm/{realms}/_clear_cache'].post
$.paths['/_security/role/{name}/_clear_cache'].post

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Elk Stack Security API
  version: 1.0.0
extends: openapi/elk-stack-security-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 100
- target: $.paths['/_encryption/_reset'].post
  update:
    x-apievangelist-phrasing:
      intent: Reset the project encryption key
      effect: destructive
      questions:
      - How do I recover when the project encryption key can no longer be read from disk?
      - What data is lost if I destroy and regenerate the project encryption key?
      instructions:
      - text: Reset the project encryption key, confirming data loss with {accept_data_loss}.
        slots:
          accept_data_loss: query.accept_data_loss
      - text: Destroy the current PEK and generate a new one; accept_data_loss is {accept_data_loss}.
        slots:
          accept_data_loss: query.accept_data_loss
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/profile/_activate'].post
  update:
    x-apievangelist-phrasing:
      intent: Activate a user profile for another user
      effect: write
      questions:
      - How does Kibana create or refresh a user profile on behalf of a user who just logged in?
      - Can a profile be activated with a username and password instead of an access token?
      instructions:
      - text: Activate the user profile for {username} using grant type {grant_type}.
        slots:
          username: requestBody.username
          grant_type: requestBody.grant_type
      - text: Activate a profile from access token {access_token} with grant type {grant_type}.
        slots:
          access_token: requestBody.access_token
          grant_type: requestBody.grant_type
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/_authenticate'].get
  update:
    x-apievangelist-phrasing:
      intent: See who I'm authenticated as
      effect: read
      questions:
      - Which user and roles is my current Elasticsearch credential authenticated as?
      - How can I verify that my credentials work and see the realm they come from?
      instructions:
      - text: Tell me who I'm currently authenticated as.
      - text: Show the authenticated user, roles and realm for my current credentials.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/role'].get
  update:
    x-apievangelist-phrasing:
      intent: List all native realm roles
      effect: read
      questions:
      - Which roles are defined in the native realm?
      - Can I list every role, including the implicit ones?
      instructions:
      - text: List all roles in the native realm.
      - text: Get every role, with include_implicit set to {include_implicit}.
        slots:
          include_implicit: query.include_implicit
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/role'].post
  update:
    x-apievangelist-phrasing:
      intent: Create or update many roles at once
      effect: write
      questions:
      - How do I create several native realm roles in a single request?
      - Can I bulk-update the privileges of multiple roles together?
      instructions:
      - text: Bulk create or update the roles {roles}.
        slots:
          roles: requestBody.roles
      - text: 'Upsert these role definitions in one batch: {roles}.'
        slots:
          roles: requestBody.roles
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/role'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete many roles at once
      effect: destructive
      questions:
      - How do I delete several native realm roles in one call?
      - Can I bulk-remove roles by listing their names?
      instructions:
      - text: Bulk delete the roles {names}.
        slots:
          names: requestBody.names
      - text: 'Remove these roles from the native realm together: {names}.'
        slots:
          names: requestBody.names
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/api_key/_bulk_update'].post
  update:
    x-apievangelist-phrasing:
      intent: Update multiple API keys at once
      effect: write
      questions:
      - How do I apply the same metadata or expiration to many API keys in one request?
      - Can I change the role descriptors on several API keys together?
      instructions:
      - text: Set expiration {expiration} on API keys {ids}.
        slots:
          expiration: requestBody.expiration
          ids: requestBody.ids
      - text: Bulk update API keys {ids} with metadata {metadata}.
        slots:
          ids: requestBody.ids
          metadata: requestBody.metadata
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/user/{username}/_password'].put
  update:
    x-apievangelist-phrasing:
      intent: Change a user's password (PUT)
      effect: write
      questions:
      - How do I reset the password of a specific native realm user?
      - Can I set a user's password from a precomputed hash instead of plain text?
      instructions:
      - text: Change the password for user {username} to {password}.
        slots:
          username: path.username
          password: requestBody.password
      - text: Set password hash {password_hash} on user {username}.
        slots:
          username: path.username
          password_hash: requestBody.password_hash
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/user/{username}/_password'].post
  update:
    x-apievangelist-phrasing:
      intent: Change a named user's password via POST
      effect: write
      questions:
      - Is there a POST form of the endpoint for changing a named user's password?
      - Can a built-in user like kibana_system get a new password through a POST call?
      instructions:
      - text: With POST, give user {username} the new password {password}.
        slots:
          username: path.username
          password: requestBody.password
      - text: POST a new hashed credential {password_hash} for built-in user {username}.
        slots:
          username: path.username
          password_hash: requestBody.password_hash
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/user/_password'].put
  update:
    x-apievangelist-phrasing:
      intent: Change my own password (PUT)
      effect: write
      questions:
      - How do I change the password of the user I'm currently logged in as?
      - Can I update my own password without naming my username in the path?
      instructions:
      - text: Change my own password to {password}.
        slots:
          password: requestBody.password
      - text: Replace my current credential with hash {password_hash}.
        slots:
          password_hash: requestBody.password_hash
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/user/_password'].post
  update:
    x-apievangelist-phrasing:
      intent: Change my own password via POST
      effect: write
      questions:
      - Is there a POST version of changing the password for the logged-in user?
      - Can I refresh the index immediately after changing my own password with a POST request?
      instructions:
      - text: Using POST, update the password of the current user to {password}.
        slots:
          password: requestBody.password
      - text: POST my new password {password} and set refresh to {refresh}.
        slots:
          password: requestBody.password
          refresh: query.refresh
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/api_key/{ids}/_clear_cache'].post
  update:
    x-apievangelist-phrasing:
      intent: Clear cached API keys
      effect: write
      questions:
      - How do I evict specific API keys from the API key cache?
      - Can I flush every cached API key at once?
      instructions:
      - text: Clear the API key cache for keys {ids}.
        slots:
          ids: path.ids
      - text: Evict API key IDs {ids} from the cache.
        slots:
          ids: path.ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/privilege/{application}/_clear_cache'].post
  update:
    x-apievangelist-phrasing:
      intent: Clear cached application privileges
      effect: write
      questions:
      - How do I evict an application's privileges from the privilege cache?
      - Why do my application privilege changes not show up until the cache is cleared?
      instructions:
      - text: Clear the privilege cache for application {application}.
        slots:
          application: path.application
      - text: Evict cached privileges of app {application}.
        slots:
          application: path.application
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/realm/{realms}/_clear_cache'].post
  update:
    x-apievangelist-phrasing:
      intent: Clear the user cache for realms
      effect: write
      questions:
      - How do I force a realm to re-authenticate users by clearing its user cache?
      - Can I evict only specific users from a realm's cache?
      instructions:
      - text: Clear the user cache for realm {realms}.
        slots:
          realms: path.realms
      - text: Evict users {usernames} from the cache of realm {realms}.
        slots:
          realms: path.realms
          usernames: query.usernames
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/role/{name}/_clear_cache'].post
  update:
    x-apievangelist-phrasing:
      intent: Clear cached roles
      effect: write
      questions:
      - How do I evict a role from the native role cache after editing it?
      - Can I clear the role cache for just one role?
      instructions:
      - text: Clear the role cache for role {name}.
        slots:
          name: path.name
      - text: Evict cached role {name} from the native role cache.
        slots:
          name: path.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/service/{namespace}/{service}/credential/token/{name}/_clear_cache'].post
  update:
    x-apievangelist-phrasing:
      intent: Clear service account token caches
      effect: write
      questions:
      - How do I evict a service account token from the token caches?
      - Can I clear cached credentials for one specific service account token?
      instructions:
      - text: Clear the cache for service token {name} of service {namespace}/{service}.
        slots:
          namespace: path.namespace
          service: path.service
          name: path.name
      - text: Evict cached token {name} for {namespace}/{service}.
        slots:
          namespace: path.namespace
          service: path.service
          name: path.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/api_key/clone'].put
  update:
    x-apievangelist-phrasing:
      intent: Clone an API key (PUT)
      effect: write
      questions:
      - How do I copy an existing API key so it gets a new ID but the same role descriptors?
      - Can a cloned API key have its own name and expiration?
      instructions:
      - text: Clone API key {api_key} under the name {name}.
        slots:
          api_key: requestBody.api_key
          name: requestBody.name
      - text: Duplicate key {api_key} with expiration {expiration}.
        slots:
          api_key: requestBody.api_key
          expiration: requestBody.expiration
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/api_key/clone'].post
  update:
    x-apievangelist-phrasing:
      intent: Clone an API key via POST
      effect: write
      questions:
      - Is there a POST endpoint to make a copy of an API key with a fresh ID?
      - Does a copied key inherit the source key's permissions?
      instructions:
      - text: Via POST, create a copy of API key {api_key} called {name}.
        slots:
          api_key: requestBody.api_key
          name: requestBody.name
      - text: POST a clone of {api_key} carrying metadata {metadata}.
        slots:
          api_key: requestBody.api_key
          metadata: requestBody.metadata
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/api_key'].get
  update:
    x-apievangelist-phrasing:
      intent: Get API key information
      effect: read
      questions:
      - What API keys exist for a given user or realm?
      - Can I list only the API keys that are still active?
      - Which API keys do I own?
      instructions:
      - text: Get information for API key {id}.
        slots:
          id: query.id
      - text: Show the API keys owned by user {username}.
        slots:
          username: query.username
      - text: 'Look up API keys named {name}, active only: {active_only}.'
        slots:
          name: query.name
          active_only: query.active_only
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/api_key'].put
  update:
    x-apievangelist-phrasing:
      intent: Create an API key (PUT)
      effect: write
      questions:
      - How do I create an API key so a script can call Elasticsearch without basic auth?
      - Can I restrict a new API key to specific role descriptors?
      instructions:
      - text: Create an API key named {name} that expires in {expiration}.
        slots:
          name: requestBody.name
          expiration: requestBody.expiration
      - text: Create API key {name} limited to role descriptors {role_descriptors}.
        slots:
          name: requestBody.name
          role_descriptors: requestBody.role_descriptors
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/api_key'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an API key via POST
      effect: write
      questions:
      - Is there a POST request for generating a new Elasticsearch API key?
      - Does a newly generated API key never expire unless I set an expiration?
      instructions:
      - text: Using POST, generate an API key called {name}.
        slots:
          name: requestBody.name
      - text: POST a new key {name} with metadata {metadata}.
        slots:
          name: requestBody.name
          metadata: requestBody.metadata
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/api_key'].delete
  update:
    x-apievangelist-phrasing:
      intent: Invalidate API keys
      effect: destructive
      questions:
      - How do I revoke API keys so they stop authenticating?
      - Can I invalidate all API keys belonging to one user?
      - Are invalidated API keys still visible afterwards?
      instructions:
      - text: Invalidate API keys {ids}.
        slots:
          ids: requestBody.ids
      - text: Revoke every API key owned by user {username}.
        slots:
          username: requestBody.username
      - text: Invalidate the API key named {name}.
        slots:
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/cross_cluster/api_key'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a cross-cluster API key
      effect: write
      questions:
      - How do I create an API key for API key based remote cluster access?
      - Can a cross-cluster key grant both search and replication access?
      instructions:
      - text: Create cross-cluster API key {name} with access {access}.
        slots:
          name: requestBody.name
          access: requestBody.access
      - text: Create a remote cluster key {name} granting {access} that expires in {expiration}.
        slots:
          name: requestBody.name
          access: requestBody.access
          expiration: requestBody.expiration
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/service/{namespace}/{service}/credential/token/{name}'].put
  update:
    x-apievangelist-phrasing:
      intent: Create a named service account token (PUT)
      effect: write
      questions:
      - How do I create a named token for a service account like elastic/fleet-server?
      - Can a service account token be used instead of basic authentication?
      instructions:
      - text: Create service token {name} for service account {namespace}/{service}.
        slots:
          namespace: path.namespace
          service: path.service
          name: path.name
      - text: Issue token {name} to {namespace}/{service} with refresh {refresh}.
        slots:
          namespace: path.namespace
          service: path.service
          name: path.name
          refresh: query.refresh
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/service/{namespace}/{service}/credential/token/{name}'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a named service account token via POST
      effect: write
      questions:
      - Is there a POST call for issuing a named service account token?
      - Can I POST to mint a credential with my chosen token name for a service?
      instructions:
      - text: Using POST, mint token {name} for service {namespace}/{service}.
        slots:
          namespace: path.namespace
          service: path.service
          name: path.name
      - text: POST a new credential called {name} under {namespace}/{service}.
        slots:
          namespace: path.namespace
          service: path.service
          name: path.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/service/{namespace}/{service}/credential/token/{name}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a service account token
      effect: destructive
      questions:
      - How do I revoke a service account token that was leaked?
      - Can I delete one named token for a service account?
      instructions:
      - text: Delete service token {name} from {namespace}/{service}.
        slots:
          namespace: path.namespace
          service: path.service
          name: path.name
      - text: Revoke the {name} token of service account {namespace}/{service}.
        slots:
          namespace: path.namespace
          service: path.service
          name: path.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/service/{namespace}/{service}/credential/token'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an auto-named service account token
      effect: write
      questions:
      - Can Elasticsearch generate a service account token with an automatically assigned name?
      - How do I get a token for a service account without choosing a token name?
      instructions:
      - text: Create an auto-named token for service account {namespace}/{service}.
        slots:
          namespace: path.namespace
          service: path.service
      - text: Generate a token with a system-assigned name for {namespace}/{service}.
        slots:
          namespace: path.namespace
          service: path.service
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/delegate_pki'].post
  update:
    x-apievangelist-phrasing:
      intent: Exchange a PKI certificate chain for a token
      effect: write
      questions:
      - How do I exchange a client X.509 certificate chain for an Elasticsearch access token?
      - Can a proxy that terminates TLS delegate PKI authentication to Elasticsearch?
      instructions:
      - text: Delegate PKI authentication for certificate chain {x509_certificate_chain}.
        slots:
          x509_certificate_chain: requestBody.x509_certificate_chain
      - text: Get an access token from X.509 chain {x509_certificate_chain}.
        slots:
          x509_certificate_chain: requestBody.x509_certificate_chain
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/privilege/{application}/{name}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get one application privilege
      effect: read
      questions:
      - What actions does a specific named privilege of my application grant?
      - Can I look up a single application privilege by application and name?
      instructions:
      - text: Get privilege {name} of application {application}.
        slots:
          application: path.application
          name: path.name
      - text: Show the actions granted by {application} privilege {name}.
        slots:
          application: path.application
          name: path.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/privilege/{application}/{name}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete application privileges
      effect: destructive
      questions:
      - How do I remove an application privilege I no longer use?
      - Can I delete a single privilege from an application?
      instructions:
      - text: Delete privilege {name} from application {application}.
        slots:
          application: path.application
          name: path.name
      - text: Remove application privilege {application}/{name}.
        slots:
          application: path.application
          name: path.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/role/{name}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a specific role
      effect: read
      questions:
      - What cluster and index privileges does a particular role grant?
      - Can I look up one role by name in the native realm?
      instructions:
      - text: Show the role {name}.
        slots:
          name: path.name
      - text: Get the privileges defined in role {name}.
        slots:
          name: path.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/role/{name}'].put
  update:
    x-apievangelist-phrasing:
      intent: Create or update a role (PUT)
      effect: write
      questions:
      - How do I create a role that grants read access to certain indices?
      - Can a role include remote cluster index privileges?
      instructions:
      - text: Create role {name} with index privileges {indices}.
        slots:
          name: path.name
          indices: requestBody.indices
      - text: Update role {name} to grant cluster privileges {cluster}.
        slots:
          name: path.name
          cluster: requestBody.cluster
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/role/{name}'].post
  update:
    x-apievangelist-phrasing:
      intent: Create or update a role via POST
      effect: write
      questions:
      - Is there a POST request for defining a single native realm role?
      - Can I give a role a description and run_as permissions?
      instructions:
      - text: Via POST, define role {name} with description {description}.
        slots:
          name: path.name
          description: requestBody.description
      - text: POST role {name} allowing run_as for {run_as}.
        slots:
          name: path.name
          run_as: requestBody.run_as
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/role/{name}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a role
      effect: destructive
      questions:
      - How do I remove a single role from the native realm?
      - What happens to users assigned a role after I delete it?
      instructions:
      - text: Delete role {name}.
        slots:
          name: path.name
      - text: Remove the native realm role {name}.
        slots:
          name: path.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/role_mapping/{name}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a role mapping
      effect: read
      questions:
      - Which roles does a specific role mapping assign, and to which users?
      - Can I look up one role mapping by name?
      instructions:
      - text: Show role mapping {name}.
        slots:
          name: path.name
      - text: Get the rules and roles of mapping {name}.
        slots:
          name: path.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/role_mapping/{name}'].put
  update:
    x-apievangelist-phrasing:
      intent: Create or update a role mapping (PUT)
      effect: write
      questions:
      - How do I map LDAP or SAML users to Elasticsearch roles?
      - Can a role mapping assign roles through templates instead of fixed names?
      instructions:
      - text: Create role mapping {name} assigning roles {roles} to users matching {rules}.
        slots:
          name: path.name
          roles: requestBody.roles
          rules: requestBody.rules
      - text: Update mapping {name} and set enabled to {enabled}.
        slots:
          name: path.name
          enabled: requestBody.enabled
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/role_mapping/{name}'].post
  update:
    x-apievangelist-phrasing:
      intent: Create or update a role mapping via POST
      effect: write
      questions:
      - Is there a POST endpoint for defining which roles a group of users receives?
      - Can I POST a mapping that uses role templates?
      instructions:
      - text: Via POST, create role mapping {name} with role templates {role_templates}.
        slots:
          name: path.name
          role_templates: requestBody.role_templates
      - text: POST mapping {name} granting {roles}.
        slots:
          name: path.name
          roles: requestBody.roles
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/role_mapping/{name}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a role mapping
      effect: destructive
      questions:
      - How do I remove a role mapping so users stop receiving its roles?
      - Can I delete one role mapping by name?
      instructions:
      - text: Delete role mapping {name}.
        slots:
          name: path.name
      - text: Remove the mapping {name} that assigns roles to users.
        slots:
          name: path.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/user/{username}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a specific user
      effect: read
      questions:
      - What roles and details does a particular native realm user have?
      - Can I see a user's profile UID along with their account?
      instructions:
      - text: Show user {username}.
        slots:
          username: path.username
      - text: 'Get user {username} including profile uid: {with_profile_uid}.'
        slots:
          username: path.username
          with_profile_uid: query.with_profile_uid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/user/{username}'].put
  update:
    x-apievangelist-phrasing:
      intent: Create or update a user (PUT)
      effect: write
      questions:
      - How do I add a new user to the native realm with a password and roles?
      - Can I update a user's roles without changing their password?
      instructions:
      - text: Create user {username} with password {password} and roles {roles}.
        slots:
          username: path.username
          password: requestBody.password
          roles: requestBody.roles
      - text: Update user {username}'s email to {email}.
        slots:
          username: path.username
          email: requestBody.email
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/user/{username}'].post
  update:
    x-apievangelist-phrasing:
      intent: Create or update a user via POST
      effect: write
      questions:
      - Is there a POST request for adding a native realm user?
      - Can I set a user's full name and metadata when creating them?
      instructions:
      - text: Via POST, add user {username} with full name {full_name}.
        slots:
          username: path.username
          full_name: requestBody.full_name
      - text: POST user {username} assigned the roles {roles}.
        slots:
          username: path.username
          roles: requestBody.roles
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/user/{username}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a user
      effect: destructive
      questions:
      - How do I delete a user from the native realm?
      - Can a deleted native user be restored afterwards?
      instructions:
      - text: Delete user {username}.
        slots:
          username: path.username
      - text: Remove native realm user {username} permanently.
        slots:
          username: path.username
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/user/{username}/_disable'].put
  update:
    x-apievangelist-phrasing:
      intent: Disable a user (PUT)
      effect: write
      questions:
      - How do I block a native user from logging in without deleting them?
      - Can I disable a built-in user account?
      instructions:
      - text: Disable user {username}.
        slots:
          username: path.username
      - text: Prevent {username} from authenticating by disabling the account.
        slots:
          username: path.username
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/user/{username}/_disable'].post
  update:
    x-apievangelist-phrasing:
      intent: Disable a user via POST
      effect: write
      questions:
      - Is there a POST call for turning off a native realm account?
      - Can I POST to deactivate an account and refresh right away?
      instructions:
      - text: Using POST, deactivate account {username}.
        slots:
          username: path.username
      - text: POST a disable for {username} with refresh {refresh}.
        slots:
          username: path.username
          refresh: query.refresh
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/profile/{uid}/_disable'].put
  update:
    x-apievangelist-phrasing:
      intent: Disable a user profile (PUT)
      effect: write
      questions:
      - How do I hide a user profile from user profile searches?
      - Can I disable a profile by its UID?
      instructions:
      - text: Disable user profile {uid}.
        slots:
          uid: path.uid
      - text: Hide profile {uid} from profile suggestions.
        slots:
          uid: path.uid
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/profile/{uid}/_disable'].post
  update:
    x-apievangelist-phrasing:
      intent: Disable a user profile via POST
      effect: write
      questions:
      - Is there a POST request to make a profile invisible in searches?
      - Can I POST to deactivate a Kibana user profile?
      instructions:
      - text: Using POST, deactivate profile {uid}.
        slots:
          uid: path.uid
      - text: POST a disable for Kibana profile {uid} with refresh {refresh}.
        slots:
          uid: path.uid
          refresh: query.refresh
      method: generated
      generated: '2026-09-26'
- target: $.paths['/_security/user/{username}/_enable'].put
  update:
    x-apievangelist-phrasing:
      intent: Enable a user (PUT)
      effect: write
      questions:
      - How do I re-enable a native user account that was disabled?
      - Can I let a disabled built-in user log in again?
      instructions:
      - text: Enable user {username}.
        slots:
          username: path.username
      - text: Restore login access for disabled account {username}.
        slots:
          username: path.username
      method: generated
      generated: '2026-09-26'


# --- truncated at 32 KB (65 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/elk-stack/refs/heads/main/overlays/elk-stack-security-api-phrasing-overlay.yaml