GitLab · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for GitLab OAuth 2.0 Tokens API

4 actions 4 updates phrasing extends openapi/gitlab-tokens-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for GitLab's API. It is a proposal applied on top of the contract, not a document GitLab publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 4

$.info
$.paths['/oauth/token'].post
$.paths['/oauth/revoke'].post
$.paths['/oauth/token/info'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for GitLab OAuth 2.0 Tokens API
  version: 1.0.0
extends: openapi/gitlab-tokens-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 3
- target: $.paths['/oauth/token'].post
  update:
    x-apievangelist-phrasing:
      intent: Exchange a code or refresh token for an access token
      effect: write
      questions:
      - How do I turn an OAuth authorization code into an access token?
      - Can I refresh an expired OAuth access token without asking the user again?
      - How long do OAuth access tokens last?
      instructions:
      - text: Exchange code {code} for an access token for client {client_id} using grant {grant_type}.
        slots:
          code: requestBody.code
          client_id: requestBody.client_id
          grant_type: requestBody.grant_type
      - text: Get a new access token for client {client_id} from refresh token {refresh_token} with grant {grant_type}.
        slots:
          client_id: requestBody.client_id
          refresh_token: requestBody.refresh_token
          grant_type: requestBody.grant_type
      - text: Poll for a token with device code {device_code} for client {client_id}, grant {grant_type}.
        slots:
          device_code: requestBody.device_code
          client_id: requestBody.client_id
          grant_type: requestBody.grant_type
      method: generated
      generated: '2026-09-26'
- target: $.paths['/oauth/revoke'].post
  update:
    x-apievangelist-phrasing:
      intent: Revoke an OAuth access or refresh token
      effect: destructive
      questions:
      - How do I invalidate an OAuth token when a user logs out?
      - Can I revoke a refresh token so it can't mint new access tokens?
      instructions:
      - text: Revoke token {token} for client {client_id} with secret {client_secret}.
        slots:
          token: requestBody.token
          client_id: requestBody.client_id
          client_secret: requestBody.client_secret
      - text: Kill OAuth token {token} issued to app {client_id} using secret {client_secret}.
        slots:
          token: requestBody.token
          client_id: requestBody.client_id
          client_secret: requestBody.client_secret
      method: generated
      generated: '2026-09-26'
- target: $.paths['/oauth/token/info'].get
  update:
    x-apievangelist-phrasing:
      intent: Inspect the current OAuth token
      effect: read
      questions:
      - What scopes does my current OAuth token have?
      - When does the access token I'm using expire?
      instructions:
      - text: Show the scopes and expiry of my current OAuth token.
      - text: Check whether my access token is still active.
      method: generated
      generated: '2026-09-26'