Palo Alto Networks · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for TLS Protect Cloud API for Strata Cloud Manager Built-In…

9 actions 9 updates phrasing extends openapi/palo-alto-networks-built-in-accounts-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 9

$.info
$.paths['/v1/serviceaccounts'].get
$.paths['/v1/serviceaccounts'].post
$.paths['/v1/serviceaccounts/{id}'].get
$.paths['/v1/serviceaccounts/{id}'].delete
$.paths['/v1/serviceaccounts/{id}'].patch
$.paths['/v1/serviceaccounts/scopes'].get
$.paths['/v1/serviceaccounts/{id}/ocitoken'].put
$.paths['/v1/serviceaccounts/{id}/credentials'].put

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for TLS Protect Cloud API for Strata Cloud Manager Built-In…
  version: 1.0.0
extends: openapi/palo-alto-networks-built-in-accounts-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 8
- target: $.paths['/v1/serviceaccounts'].get
  update:
    x-apievangelist-phrasing:
      intent: List service accounts
      effect: read
      questions:
      - Which service accounts do I have access to?
      - Can I see every machine-to-machine service account in my tenant?
      instructions:
      - text: List all the service accounts I can access.
      - text: Show every service account used for machine-to-machine auth.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/v1/serviceaccounts'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a service account
      effect: write
      questions:
      - How do I create a service account for machine-to-machine authentication?
      - Does an RSA key service account need a public key when I create it?
      instructions:
      - text: Create a new service account for machine-to-machine authentication.
      - text: Set up a service account that authenticates with an RSA public key.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/v1/serviceaccounts/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a service account
      effect: read
      questions:
      - What are the settings on one particular service account?
      - Can I look up a service account by its ID?
      instructions:
      - text: Get service account {id}.
        slots:
          id: path.id
      - text: Show the details of service account {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/v1/serviceaccounts/{id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a service account
      effect: destructive
      questions:
      - Does deleting a service account also invalidate its credentials?
      - How do I remove a service account I no longer use?
      instructions:
      - text: Delete service account {id}.
        slots:
          id: path.id
      - text: Remove service account {id} and invalidate its credentials.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/v1/serviceaccounts/{id}'].patch
  update:
    x-apievangelist-phrasing:
      intent: Enable or disable a service account
      effect: write
      questions:
      - Can I disable a service account without deleting it?
      - Which fields can I patch on an existing service account?
      instructions:
      - text: Set service account {id} enabled to {enabled}.
        slots:
          id: path.id
          enabled: requestBody.enabled
      - text: Disable service account {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/v1/serviceaccounts/scopes'].get
  update:
    x-apievangelist-phrasing:
      intent: List available service account scopes
      effect: read
      questions:
      - What scopes can I grant to a service account?
      - Which service account scopes are available to me?
      instructions:
      - text: List the scopes available for service accounts.
      - text: Show me every permission scope a service account can be given.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/v1/serviceaccounts/{id}/ocitoken'].put
  update:
    x-apievangelist-phrasing:
      intent: Regenerate a service account's OCI registry token
      effect: destructive
      questions:
      - Can I rotate the OCI registry token for a service account?
      - What happens to the old OCI registry token when I regenerate it?
      instructions:
      - text: Regenerate the OCI registry token for service account {id}.
        slots:
          id: path.id
      - text: Issue a fresh OCI registry token for service account {id}, replacing the current one.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/v1/serviceaccounts/{id}/credentials'].put
  update:
    x-apievangelist-phrasing:
      intent: Extend a service account's credential lifetime
      effect: write
      questions:
      - Can I extend how long a service account's credentials stay valid?
      - How do I refresh the credentials on a service account before they expire?
      instructions:
      - text: Extend the credential lifetime of service account {id} to {lifetime}.
        slots:
          id: path.id
          lifetime: requestBody.extendCredentialLifetime
      - text: Update credentials for service account {id} with extension {lifetime}.
        slots:
          id: path.id
          lifetime: requestBody.extendCredentialLifetime
      method: generated
      generated: '2026-09-26'