Palo Alto Networks · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Palo Alto Networks Applications API

49 actions 49 updates phrasing extends openapi/palo-alto-networks-applications-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 49 · first 16 shown; the file carries all of them

$.info
$.paths['/seb-api/v1/applications'].get
$.paths['/seb-api/v1/applications/{id}'].get
$.paths['/seb-api/v1/applications/{id}'].delete
$.paths['/seb-api/v1/applications/type/{type}'].get
$.paths['/seb-api/v1/applications/type/{type}'].post
$.paths['/seb-api/v1/applications/type/{type}/{id}'].get
$.paths['/seb-api/v1/applications/type/{type}/{id}'].delete
$.paths['/seb-api/v1/applications/type/{type}/{id}'].patch
$.paths['/seb-api/v1/applications/categories'].get
$.paths['/seb-api/v1/applications/bulk-create/{type}'].post
$.paths['/seb-api/v1/applications/bulk-delete'].post
$.paths['/sse/config/v1/applications'].get
$.paths['/sse/config/v1/applications'].post
$.paths['/sse/config/v1/applications/{id}'].get
$.paths['/sse/config/v1/applications/{id}'].put

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Palo Alto Networks Applications API
  version: 1.0.0
extends: openapi/palo-alto-networks-applications-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-10-01'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 48
- target: $.paths['/seb-api/v1/applications'].get
  update:
    x-apievangelist-phrasing:
      intent: List all secure browser applications
      effect: read
      questions:
      - Can I see every application defined in the Secure Enterprise Browser console across all types?
      - Is it possible to search secure browser applications by name or URL and page through them?
      instructions:
      - text: List all secure browser applications whose URL contains {url}.
        slots:
          url: query.url
      - text: Show secure browser applications of every type named like {name}, sorted by {sort}.
        slots:
          name: query.name
          sort: query.sort
      method: generated
      generated: '2026-09-26'
- target: $.paths['/seb-api/v1/applications/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a secure browser application by ID
      effect: read
      questions:
      - What is configured on a single secure browser application when I only know its ID?
      - Can I view the draft rather than the active version of a secure browser application?
      instructions:
      - text: Fetch secure browser application {id} without specifying its type.
        slots:
          id: path.id
      - text: Get the {configurationVersion} configuration of secure browser application {id}.
        slots:
          configurationVersion: query.configurationVersion
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/seb-api/v1/applications/{id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a secure browser application by ID
      effect: destructive
      questions:
      - Can I permanently remove one secure browser application using just its ID?
      - Is deleting a secure browser application by ID reversible?
      instructions:
      - text: Permanently delete secure browser application {id} by its ID alone.
        slots:
          id: path.id
      - text: Remove the secure browser app with ID {id}, no type needed.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/seb-api/v1/applications/type/{type}'].get
  update:
    x-apievangelist-phrasing:
      intent: List secure browser applications of one type
      effect: read
      questions:
      - Which secure browser applications exist of a particular type, like private or non-web apps?
      - Can I filter the applications of a single type by name?
      instructions:
      - text: List all secure browser applications of type {type}.
        slots:
          type: path.type
      - text: Find {type} applications in the secure browser named {name}.
        slots:
          type: path.type
          name: query.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/seb-api/v1/applications/type/{type}'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a secure browser application
      effect: write
      questions:
      - How do I add a single new custom application to the Secure Enterprise Browser console?
      - Is there a limit on how many URLs custom, private and non-web apps can hold combined?
      instructions:
      - text: Create one new secure browser application of type {type}.
        slots:
          type: path.type
      - text: Add a single {type} app to the secure browser management console.
        slots:
          type: path.type
      method: generated
      generated: '2026-09-26'
- target: $.paths['/seb-api/v1/applications/type/{type}/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a secure browser application within a type
      effect: read
      questions:
      - Can I fetch a secure browser application by ID scoped to its type?
      - What does the active configuration of a specific private app look like?
      instructions:
      - text: Get the {type} secure browser application {id}.
        slots:
          type: path.type
          id: path.id
      - text: Show the {configurationVersion} version of {type} app {id}.
        slots:
          configurationVersion: query.configurationVersion
          type: path.type
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/seb-api/v1/applications/type/{type}/{id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a secure browser application of a type
      effect: destructive
      questions:
      - Can I remove a secure browser app when I know both its type and ID?
      - What happens when I delete a non-web application from the secure browser?
      instructions:
      - text: Delete the {type} secure browser application {id}.
        slots:
          type: path.type
          id: path.id
      - text: Remove {type} app {id} from the secure browser console.
        slots:
          type: path.type
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/seb-api/v1/applications/type/{type}/{id}'].patch
  update:
    x-apievangelist-phrasing:
      intent: Partially update a secure browser application
      effect: write
      questions:
      - Can I change a few attributes of a secure browser application and leave the rest untouched?
      - Does editing a secure browser app's URLs count toward the 15,000-URL tenant limit?
      instructions:
      - text: Patch the {type} secure browser application {id} with only the changed attributes.
        slots:
          type: path.type
          id: path.id
      - text: Update secure browser app {id} of type {type}.
        slots:
          id: path.id
          type: path.type
      method: generated
      generated: '2026-09-26'
- target: $.paths['/seb-api/v1/applications/categories'].get
  update:
    x-apievangelist-phrasing:
      intent: List secure browser application categories
      effect: read
      questions:
      - What application categories are available in the Secure Enterprise Browser?
      - Which categories can I assign to a secure browser app?
      instructions:
      - text: List the secure browser application categories.
      - text: Show me every category available for browser applications.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/seb-api/v1/applications/bulk-create/{type}'].post
  update:
    x-apievangelist-phrasing:
      intent: Bulk create secure browser applications
      effect: write
      questions:
      - Can I add many secure browser applications of one type in a single request?
      - Is there a faster way to load dozens of private apps into the secure browser at once?
      instructions:
      - text: Bulk create several {type} applications in the secure browser.
        slots:
          type: path.type
      - text: Import a batch of {type} apps into the secure browser console in one call.
        slots:
          type: path.type
      method: generated
      generated: '2026-09-26'
- target: $.paths['/seb-api/v1/applications/bulk-delete'].post
  update:
    x-apievangelist-phrasing:
      intent: Bulk delete secure browser applications
      effect: destructive
      questions:
      - Can I delete many secure browser applications at once in a single atomic operation?
      - If one ID in a bulk delete fails, are the other apps still removed?
      instructions:
      - text: Bulk delete the secure browser applications {appIds}.
        slots:
          appIds: requestBody.appIds
      - text: 'Permanently remove all of these browser app IDs at once: {appIds}.'
        slots:
          appIds: requestBody.appIds
      method: generated
      generated: '2026-09-26'
- target: $.paths['/sse/config/v1/applications'].get
  update:
    x-apievangelist-phrasing:
      intent: List Prisma Access application objects in a folder
      effect: read
      questions:
      - Which custom application objects are defined in a Prisma Access config folder?
      - Can I page through Prisma Access application objects with limit and offset?
      instructions:
      - text: List Prisma Access application objects in folder {folder}.
        slots:
          folder: query.folder
      - text: Find the Prisma Access application named {name} in folder {folder}.
        slots:
          name: query.name
          folder: query.folder
      method: generated
      generated: '2026-09-26'
- target: $.paths['/sse/config/v1/applications'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a Prisma Access application object
      effect: write
      questions:
      - How do I define a custom App-ID application in a Prisma Access folder with its risk and category?
      - Can I mark a new Prisma Access application as evasive or used by malware?
      instructions:
      - text: Create Prisma Access application {name} in folder {folder} with category {category}, subcategory {subcategory}, technology {technology} and risk {risk}.
        slots:
          name: requestBody.name
          folder: query.folder
          category: requestBody.category
          subcategory: requestBody.subcategory
          technology: requestBody.technology
          risk: requestBody.risk
      - text: Add a custom app {name} to Prisma Access folder {folder} with a TCP timeout of {tcp_timeout} seconds.
        slots:
          name: requestBody.name
          folder: query.folder
          tcp_timeout: requestBody.tcp_timeout
      method: generated
      generated: '2026-09-26'
- target: $.paths['/sse/config/v1/applications/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a Prisma Access application object
      effect: read
      questions:
      - What risk level and characteristics does a given Prisma Access application object have?
      - Can I look up one Prisma Access App-ID object by its identifier?
      instructions:
      - text: Get Prisma Access application object {id}.
        slots:
          id: path.id
      - text: Show the category and risk of Prisma Access app {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/sse/config/v1/applications/{id}'].put
  update:
    x-apievangelist-phrasing:
      intent: Edit a Prisma Access application object
      effect: write
      questions:
      - Can I change the risk rating of an existing Prisma Access application object?
      - Is it possible to adjust session timeouts on a custom Prisma Access app?
      instructions:
      - text: Edit Prisma Access application {id} and set its risk to {risk}.
        slots:
          id: path.id
          risk: requestBody.risk
      - text: Change the UDP timeout of Prisma Access app {id} to {udp_timeout} seconds.
        slots:
          id: path.id
          udp_timeout: requestBody.udp_timeout
      method: generated
      generated: '2026-09-26'
- target: $.paths['/sse/config/v1/applications/{id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a Prisma Access application object
      effect: destructive
      questions:
      - Can I remove a custom application object from Prisma Access configuration?
      - What gets deleted when I drop a Prisma Access App-ID object?
      instructions:
      - text: Delete Prisma Access application object {id}.
        slots:
          id: path.id
      - text: Remove the custom Prisma Access app {id} from the config.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/mt/monitor/adem/v1/applications'].get
  update:
    x-apievangelist-phrasing:
      intent: List applications monitored by Autonomous DEM
      effect: read
      questions:
      - Which applications is Autonomous DEM probing with synthetic tests?
      - What synthetic tests are configured for a monitored application?
      instructions:
      - text: List the applications configured for monitoring in Autonomous DEM.
      - text: Show the ADEM synthetic tests for monitored application {app_id}.
        slots:
          app_id: query.app_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/appid/api/v1/download/app'].post
  update:
    x-apievangelist-phrasing:
      intent: Download the application inventory as CSV
      effect: read
      questions:
      - Can I export the complete Prisma Cloud application inventory to a CSV file?
      - Is it possible to download only apps with a certain business criticality from the inventory?
      instructions:
      - text: Download the application inventory CSV filtered to business owner {businessOwner}.
        slots:
          businessOwner: requestBody.businessOwner
      - text: Export the inventory of {environment} applications as a CSV.
        slots:
          environment: requestBody.environment
      method: generated
      generated: '2026-09-26'
- target: $.paths['/appid/api/v1/app/criteria'].get
  update:
    x-apievangelist-phrasing:
      intent: Download all application discovery criteria
      effect: read
      questions:
      - What discovery criteria group my assets into applications?
      - Can I include deleted discovery criteria when listing them?
      instructions:
      - text: Download all application discovery criteria, predefined and custom.
      - text: List discovery criteria with deleted ones included set to {fetch_deleted}.
        slots:
          fetch_deleted: query.fetch_deleted
      method: generated
      generated: '2026-09-26'
- target: $.paths['/appid/api/v1/app/criteria'].post
  update:
    x-apievangelist-phrasing:
      intent: Create custom application discovery criteria
      effect: write
      questions:
      - How do I define a custom filter that groups scanned assets into a new application?
      - Can creating discovery criteria also create the application definition?
      instructions:
      - text: Create discovery criteria {name} for application {app} with metadata {metadata}.
        slots:
          name: requestBody.name
          app: requestBody.app
          metadata: requestBody.metadata
      - text: Add custom discovery criteria {name} for {app} and set create_definition to {create_definition}.
        slots:
          name: requestBody.name
          app: requestBody.app
          create_definition: query.create_definition
      method: generated
      generated: '2026-09-26'
- target: $.paths['/appid/api/v1/app/criteria/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an application's discovery criteria
      effect: read
      questions:
      - Which discovery criteria were used to find a particular application?
      - Can I see the asset filter behind one app in the application inventory?
      instructions:
      - text: Get the discovery criteria for application {id}.
        slots:
          id: path.id
      - text: Show how application {id} was discovered.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/appid/api/v1/app/criteria/{id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete application discovery criteria
      effect: destructive
      questions:
      - Can I remove a custom discovery criteria that I no longer need?
      - What permission do I need to delete discovery criteria?
      instructions:
      - text: Delete discovery criteria {id}.
        slots:
          id: path.id
      - text: Remove the application discovery rule with criteria ID {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/appid/api/v1/app/criteria/{id}'].patch
  update:
    x-apievangelist-phrasing:
      intent: Update application discovery criteria
      effect: write
      questions:
      - Can I rename or change the filter of an existing discovery criteria?
      - Is it possible to point existing discovery criteria at a different application?
      instructions:
      - text: Update discovery criteria {id} to name {name}, application {app} and metadata {metadata}.
        slots:
          id: path.id
          name: requestBody.name
          app: requestBody.app
          metadata: requestBody.metadata
      - text: Change the metadata filter on discovery criteria {id} to {metadata}.
        slots:
          id: path.id
          metadata: requestBody.metadata
      method: generated
      generated: '2026-09-26'
- target: $.paths['/appid/api/v1/download/app/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Download an application's details as CSV
      effect: read
      questions:
      - Can I export the alerts, vulnerabilities or assets of one application to CSV?
      - Which file types can I choose when downloading an application's details?
      instructions:
      - text: Download the {file_type} details CSV for application {id}.
        slots:
          file_type: query.file_type
          id: path.id
      - text: Export application {id} details as a {file_type} file.
        slots:
          id: path.id
          file_type: query.file_type
      method: generated
      generated: '2026-09-26'
- target: $.paths['/appid/api/v1/download/app/config/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Download an Application Bill of Materials
      effect: read
      questions:
      - How do I get the Application Bill of Materials for an app?
      - Can I download an ABOM listing an application's assets and vulnerabilities as CSV?
      instructions:
      - text: Download the ABOM for application {id}.
        slots:
          id: path.id
      - text: Get the application bill of materials CSV for app {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/appid/api/v2/app'].post
  update:
    x-apievangelist-phrasing:
      intent: List discovered applications in the inventory
      effect: read
      questions:
      - Which applications has Prisma Cloud discovered in my Application Inventory?
      - Can I filter discovered applications by owner or business criticality?
      - How many applications does the inventory list return at most?
      instructions:
      - text: List discovered applications owned by {owner}.
        slots:
          owner: requestBody.owner
      - text: Show inventory applications in environment {environment} with criticality {businessCriticality}.
        slots:
          environment: requestBody.environment
          businessCriticality: requestBody.businessCriticality
      method: generated
      generated: '2026-09-26'
- target: $.paths['/appid/api/v2/app/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a discovered application's details
      effect: read
      questions:
      - What details does the inventory hold for one discovered application?
      - Can I look up an Application Inventory entry by its ID?
      instructions:
      - text: Get inventory details for discovered application {id}.
        slots:
          id: path.id
      - text: Show the owner and environment of inventory app {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/appid/api/v2/app/{id}/assets'].post
  update:
    x-apievangelist-phrasing:
      intent: List assets that belong to an application
      effect: read
      questions:
      - Which cloud assets are associated with a discovered application?
      - Can I filter and page through the assets of one application?
      instructions:
      - text: List the assets associated with application {id}.
        slots:
          id: path.id
      - text: Get the next page of assets for application {id} using token {nextPageToken}.
        slots:
          id: path.id
          nextPageToken: requestBody.nextPageToken
      method: generated
      generated: '2026-09-26'
- target: $.paths['/appid/api/v2/app/{id}/vulnerabilities'].post
  update:
    x-apievangelist-phrasing:
      intent: List vulnerabilities in an application
      effect: read
      questions:
      - What vulnerabilities affect a discovered application?
      - Can I filter an application's vulnerabilities before paging through them?
      instructions:
      - text: List the vulnerabilities found in application {id}.
        slots:
          id: path.id
      - text: Show vulnerabilities for application {id} matching {filters}.
        slots:
          id: path.id
          filters: requestBody.filters
      method: generated
      generated: '2026-09-26'
- target: $.paths['/appid/api/v2/app/{id}/alerts'].post
  update:
    x-apievangelist-phrasing:
      intent: List alerts for an application
      effect: read
      questions:
      - Which security alerts are open against a discovered application?
      - Can I see the alert details for one app in the inventory?
      instructions:
      - text: List the alerts for application {id}.
        slots:
          id: path.id
      - text: Show alerts on application {id} matching {filters}.
        slots:
          id: path.id
          filters: requestBody.filters
      method: generated
      generated: '2026-09-26'
- target: $.paths['/appid/api/v2/app/summary'].get
  update:
    x-apievangelist-phrasing:
      intent: Get application inventory statistics
      effect: read
      questions:
      - How many applications have been discovered in my environment overall?
      - What are the total vulnerability counts across all discovered applications?
      instructions:
      - text: Get the application summary statistics for my environment.
      - text: Show how many apps and vulnerabilities the inventory has in total.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/appid/api/v2/app/{id}/grouped-counts'].post
  update:
    x-apievangelist-phrasing:
      intent: Get an application's risk counts
      effect: read
      questions:
      - What is the grouped risk count for a single application?
      - Can I get risk counts for one app narrowed by filters?
      instructions:
      - text: Get the risk counts for application {id}.
        slots:
          id: path.id
      - text: Show grouped risk counts for application {id} using filters {filters}.
        slots:
          id: path.id
          filters: requestBody.filters
      method: generated
      generated: '2026-09-26'
- target: $.paths['/appid/api/v2/tags'].get
  update:
    x-apievangelist-phrasing:
      intent: List tags used for application discovery
      effect: read
      questions:
      - Which tags are used to scan and discover applications?
      - What asset tags drive application discovery in Prisma Cloud?
      instructions:
      - text: List the tags used to discover applications.
      - text: Show me every discovery tag for the application inventory.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/appid/search/api/v1/app'].post
  update:
    x-apievangelist-phrasing:
      intent: Search applications with an RQL query
      effect: read
      questions:
      - Can I find discovered applications by writing an RQL query against the application inventory?
      - Which applications match a saved RQL search over a given time range?
      - Is there a way to run an application search query in Prisma Cloud and get each match's details?
      instructions:
      - text: Run the RQL application search {query}.
        slots:
          query: query.query
      - text: Search applications with RQL {query} over time range {timeRange}.
        slots:
          query: query.query
          timeRange: query.timeRange
      method: generated
      generated: '2026-10-01'
- target: $.paths['/appid/search/api/v1/app/risk'].post
  update:
    x-apievangelist-phrasing:
      intent: Get an application's vulnerabilities and alerts by query
      effect: read
      questions:
      - What vulnerabilities and alerts are tied to the assets behind one application, found through the search API?
      - Can I pull an application's combined risk findings, vulnerabilities plus alerts, in a single search call?
      instructions:
      - text: Search the vulnerabilities and alerts on the assets of application {applicationId}.
        slots:
          applicationId: requestBody.applicationId
      - text: Return combined vulnerability and alert findings for application {applicationId} matching {query}.
        slots:
          applicationId: requestBody.applicationId
          query: requestBody.query
      method: generated
      generated: '2026-10-01'
- target: $.paths['/appid/search/api/v1/app/service'].post
  update:
    x-apievangelist-phrasing:
      intent: Count assets, vulnerabilities and alerts per service
      effect: read
      questions:
      - How many assets, vulnerabilities and alerts does each service inside an application have?
      - Can I break an application's risk down service by service?
      instructions:
      - text: Show per-service counts of assets, vulnerabilities and alerts for application {applicationId}.
        slots:
          applicationId: requestBody.applicationId
      - text: Break down risk by service for application {applicationId} using search {query}.
        slots:
          applicationId: requestBody.applicationId
          query: requestBody.query
      method: generated
      generated: '2026-10-01'
- target: $.paths['/appid/app/service/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an application's assets and services
      effect: read
      questions:
      - Which assets and services make up a given application, along with the alerts on those assets?
      - Can I see the service map of one application from its ID?
      instructions:
      - text: List the assets and services that belong to application {id}.
        slots:
          id: path.id
      - text: Show the services of application {id} with the alerts raised on their assets.
        slots:
          id: path.id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/api/applications'].get
  update:
    x-apievangelist-phrasing:
      intent: List SaaS apps connected to SaaS Security
      effect: read
      questions:
      - Which SaaS applications are connected to my SaaS Security tenant?
      - How many active incidents and scanned assets does each connected SaaS app have?
      instructions:
      - text: List the SaaS applications connected to SaaS Security.
      - text: Show connection status for each connected SaaS app.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/v2/applications'].get
  update:
    x-apievangelist-phrasing:
      intent: List ZTNA-protected applications
      effect: read
      questions:
      - Which private applications are protected by ZTNA?
      - What connector group provides access to each ZTNA application?
      instructions:
      - text: List all ZTNA-protected applications.
      - text: Show the private resources exposed through ZTNA and their connector groups.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/v2/applications'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a ZTNA application
      effect: write
      questions:
      - How do I publish a private application through ZTNA with a connector group?
      - Can I enable ZTNA access to a new app immediately on creation?
      instructions:
      - text: Create ZTNA application {name} for {fqdn} using connector group {group_id}.
        slots:
          name: requestBody.name
          fqdn: requestBody.fqdn
          group_id: requestBody.group_id
      - text: Protect {fqdn} with ZTNA as {name} via group {group_id}, exposing ports {ports}.
        slots:
          fqdn: requestBody.fqdn
          name: requestBody.name
          group_id: requestBody.group_id
          ports: requestBody.ports
      method: generated
      generated: '2026-09-26'
- target: $.paths['/v2/applications/{app_id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a ZTNA application
      effect: read
      questions:
      - Which FQDN and ports does a specific ZTNA application expose?
      - Is ZTNA access enabled for a particular application?
      instructions:
      - text: Get ZTNA application {app_id}.
        slots:
          app_id: path.app_id
      - text: Show the ports and protocols of ZTNA app {app_id}.
        slots:
          app_id: path.app_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/v2/applications/{app_id}'].put
  update:
    x-apievangelist-phrasing:
      intent: Update a ZTNA application
      effect: write
      questions:
      - Can I move a ZTNA application to a different connector group?
      - Is it possible to change the FQDN a ZTNA application points to?
      instructions:
      - text: Update ZTNA application {app_id} to use connector group {group_id}.
        slots:
          app_id: path.app_id
          group_id: requestBody.group_id
      - text: Point ZTNA app {app_id} named {name} at {fqdn}.
        slots:
          app_id: path.app_id
          name: requestBody.name
          fqdn: requestBody.fqdn
      method: generated
      generated: '2026-09-26'
- target: $.paths['/v2/applications/{app_id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a ZTNA application
      effect: destructive
      questions:
      - Can I stop protecting a private app with ZTNA by deleting its definition?
      - What happens to user access when a ZTNA application is removed?
      instructions:
      - text: Delete ZTNA application {app_id}.
        slots:
          app_id: path.app_id
      - text: Remove the ZTNA definition for app {app_id}.
        slots:
          app_id: path.app_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/applications'].get
  update:
    x-apievangelist-phrasing:
      intent: List Strata Cloud Manager application objects
      effect: read
      questions:
      - Which application objects are defined in a Strata Cloud Manager folder, snippet or device?
      - Can I list config application objects scoped to a snippet?
      instructions:
      - text: List Strata Cloud Manager applications in snippet {snippet}.
        slots:
          snippet: query.snippet
      - text: Show SCM application objects defined on device {device}.
        slots:
          device: query.device
      method: generated
      generated: '2026-09-26'
- target: $.paths['/applications'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a Strata Cloud Manager application
      effect: write
      questions:
      - How can I add a custom application object to Strata Cloud Manager configuration?
      - Which fields are required for a new SCM application, like category and risk?
      instructions:
      - text: Create Strata Cloud Manager application {name} with category {category} and risk {risk}.
        slots:
          name: requestBody.name
          category: requestBody.category
          risk: requestBody.risk
      - text: Add SCM app {name} in category {category}, risk {risk}, with parent app {parent_app}.
        slots:
          name: requestBody.name
          category: requestBody.category
          risk: requestBody.risk
          parent_app: requestBody.parent_app
      method: generated
      generated: '2026-09-26'
- target: $.paths['/applications/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a Strata Cloud Manager application
      effect: read
      questions:
      - What does an existing Strata Cloud Manager application object contain?
      - Can I fetch an SCM application object by its UUID?
      instructions:
      - text: Get Strata Cloud Manager application {id}.
        slots:
          id: path.id
      - text: Show the SCM application object with UUID {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'


# --- truncated at 32 KB (33 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/overlays/palo-alto-networks-applications-api-phrasing-overlay.yaml