Harness · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Harness Oidc Access Token API

5 actions 5 updates phrasing extends openapi/harness-oidc-access-token-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Harness's API. It is a proposal applied on top of the contract, not a document Harness publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 5

$.info
$.paths['/ng/api/oidc/access-token/aws/webidentity-session-access'].post
$.paths['/ng/api/oidc/access-token/gcp/service-account-access'].post
$.paths['/ng/api/oidc/access-token/azure'].post
$.paths['/ng/api/oidc/access-token/gcp/workload-access'].post

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Harness Oidc Access Token API
  version: 1.0.0
extends: openapi/harness-oidc-access-token-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 4
- target: $.paths['/ng/api/oidc/access-token/aws/webidentity-session-access'].post
  update:
    x-apievangelist-phrasing:
      intent: Exchange an OIDC token for AWS IAM role credentials
      effect: write
      questions:
      - Can I get temporary AWS credentials for an IAM role using an OIDC token?
      - What does it take to assume an AWS role with web identity from a pipeline?
      instructions:
      - text: Get AWS credentials for IAM role {role_arn} using OIDC token {token}.
        slots:
          role_arn: requestBody.iamRoleArn
          token: requestBody.oidcIdToken
      - text: Assume AWS role {role_arn} through web identity federation.
        slots:
          role_arn: requestBody.iamRoleArn
      method: generated
      generated: '2026-09-26'
- target: $.paths['/ng/api/oidc/access-token/gcp/service-account-access'].post
  update:
    x-apievangelist-phrasing:
      intent: Get a GCP service account token via OIDC
      effect: write
      questions:
      - Can I impersonate a GCP service account using an OIDC ID token?
      - How is a Google Cloud service account access token generated without keys?
      instructions:
      - text: Generate a GCP service account access token from OIDC token {token} with request {request}.
        slots:
          token: requestBody.oidcIdToken
          request: requestBody.gcpOidcTokenRequestDTO
      - text: Get a keyless GCP service account token for request {request} using ID token {token}.
        slots:
          request: requestBody.gcpOidcTokenRequestDTO
          token: requestBody.oidcIdToken
      method: generated
      generated: '2026-09-26'
- target: $.paths['/ng/api/oidc/access-token/azure'].post
  update:
    x-apievangelist-phrasing:
      intent: Exchange an OIDC token for Azure credentials
      effect: write
      questions:
      - Can I get Azure credentials from an OIDC token without a client secret?
      - What tenant and client IDs are needed for Azure workload identity federation?
      instructions:
      - text: Exchange an OIDC token for Azure credentials in tenant {tenant_id} for app {client_id} with request {request}.
        slots:
          tenant_id: requestBody.tenantId
          client_id: requestBody.clientId
          request: requestBody.azureOidcTokenRequestDTO
      - text: Get an Azure access token for resource {resource}, tenant {tenant_id}, client {client_id}, request {request}.
        slots:
          resource: requestBody.resource
          tenant_id: requestBody.tenantId
          client_id: requestBody.clientId
          request: requestBody.azureOidcTokenRequestDTO
      method: generated
      generated: '2026-09-26'
- target: $.paths['/ng/api/oidc/access-token/gcp/workload-access'].post
  update:
    x-apievangelist-phrasing:
      intent: Get a GCP workload identity access token
      effect: write
      questions:
      - Can I get a GCP workload identity federation token from an OIDC ID token?
      - Which call returns a federated workload access token for Google Cloud?
      instructions:
      - text: Generate a GCP workload identity token from OIDC token {token} with request {request}.
        slots:
          token: requestBody.oidcIdToken
          request: requestBody.gcpOidcTokenRequestDTO
      - text: Exchange ID token {token} for a federated workload access token using {request}.
        slots:
          token: requestBody.oidcIdToken
          request: requestBody.gcpOidcTokenRequestDTO
      method: generated
      generated: '2026-09-26'