Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Prisma Cloud Access Keys API Overview Cloud Accounts API
36 actions
36 updates
phrasing
extends
openapi/palo-alto-networks-cloud-accounts-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 36 · first 16 shown; the file carries all of them
$.info
$.paths['/cloud'].get
$.paths['/cloud/name'].get
$.paths['/cloud/name'].post
$.paths['/cloud/{cloud_type}/{id}/project'].get
$.paths['/cloud/type'].get
$.paths['/cloud/{id}/owners'].get
$.paths['/cloud/{cloud_type}'].post
$.paths['/cloud/oci/terraform'].post
$.paths['/cloud/{cloud_type}/{id}'].get
$.paths['/cloud/{cloud_type}/{id}'].put
$.paths['/cloud/{cloud_type}/{id}'].delete
$.paths['/cloud/{cloud_type}/{id}'].patch
$.paths['/account/{accountId}/config/status'].get
$.paths['/cloud/status/{cloud_type}'].post
$.paths['/cloud/{id}/status/{enabled}'].patch
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Prisma Cloud Access Keys API Overview Cloud Accounts API
version: 1.0.0
extends: openapi/palo-alto-networks-cloud-accounts-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-10-01'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 35
- target: $.paths['/cloud'].get
update:
x-apievangelist-phrasing:
intent: List all onboarded cloud accounts
effect: read
questions:
- Which cloud accounts are onboarded to Prisma Cloud right now?
- Can I list my cloud accounts without the account group details attached?
instructions:
- text: List every cloud account onboarded to Prisma Cloud.
- text: 'Show all onboarded cloud accounts, excluding account group details: {exclude}.'
slots:
exclude: query.excludeAccountGroupDetails
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud/name'].get
update:
x-apievangelist-phrasing:
intent: Get cloud account IDs and names
effect: read
questions:
- What are the IDs and names of my active cloud accounts?
- Can I get just account names for one cloud type using a simple GET lookup?
instructions:
- text: Get the IDs and names of only active cloud accounts.
- text: Look up account names and IDs for cloud type {cloudType} via the GET name list.
slots:
cloudType: query.cloudType
- text: Get account names for account groups {accountGroupIds}.
slots:
accountGroupIds: query.accountGroupIds
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud/name'].post
update:
x-apievangelist-phrasing:
intent: Look up cloud account names with a filter body
effect: read
questions:
- Can I filter cloud account names by a time range and a filter key in a POST body?
- Is there a way to get cloud account names grouped by a field for specific account IDs?
instructions:
- text: Post a cloud account name lookup for time range {timeRange}.
slots:
timeRange: requestBody.timeRange
- text: Fetch account names for account IDs {accountIds} within {timeRange}, grouped by {groupBy}.
slots:
accountIds: requestBody.accountIds
timeRange: requestBody.timeRange
groupBy: requestBody.groupBy
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud/{cloud_type}/{id}/project'].get
update:
x-apievangelist-phrasing:
intent: List member accounts under a cloud organization
effect: read
questions:
- Which child accounts or projects sit under my onboarded cloud organization?
- Can I see all the member accounts onboarded as children of one org account?
instructions:
- text: List the child accounts of {cloud_type} organization {id}.
slots:
cloud_type: path.cloud_type
id: path.id
- text: Show the projects onboarded under org account {id} on {cloud_type} without group details.
slots:
id: path.id
cloud_type: path.cloud_type
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud/type'].get
update:
x-apievangelist-phrasing:
intent: List supported cloud types
effect: read
questions:
- What cloud types does Prisma Cloud support?
- Which cloud types do I personally have access to?
instructions:
- text: List all cloud types.
- text: Show only the cloud types I can access.
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud/{id}/owners'].get
update:
x-apievangelist-phrasing:
intent: List owner emails for a cloud account
effect: read
questions:
- Who owns this cloud account?
- Where can I find the owner email addresses for an onboarded account?
instructions:
- text: Get the owner email addresses for cloud account {id}.
slots:
id: path.id
- text: Tell me who owns account {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud/{cloud_type}'].post
update:
x-apievangelist-phrasing:
intent: Onboard a cloud account by cloud type
effect: write
questions:
- How do I onboard a new Azure, GCP or Alibaba account into Prisma Cloud?
- Can I skip the account status checks to speed up onboarding a cloud account?
instructions:
- text: Onboard a new {cloud_type} cloud account.
slots:
cloud_type: path.cloud_type
- text: Add a {cloud_type} account and skip status checks.
slots:
cloud_type: path.cloud_type
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud/oci/terraform'].post
update:
x-apievangelist-phrasing:
intent: Generate an OCI onboarding Terraform script
effect: write
questions:
- How do I get a Terraform template to onboard my Oracle Cloud tenancy?
- Can the OCI onboarding script also generate keys, and how long do they last?
instructions:
- text: Generate the OCI Terraform zip for tenancy {accountId} with user {userName}, group {groupName} and policy {policyName}.
slots:
accountId: requestBody.accountId
userName: requestBody.userName
groupName: requestBody.groupName
policyName: requestBody.policyName
- text: Create an OCI onboarding script with generated keys for tenancy {accountId}.
slots:
accountId: requestBody.accountId
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud/{cloud_type}/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get details of one cloud account
effect: read
questions:
- What top-level details does Prisma Cloud hold for a specific cloud account?
- Can I see which account groups a given cloud account belongs to?
instructions:
- text: Get info for {cloud_type} account {id}.
slots:
cloud_type: path.cloud_type
id: path.id
- text: Show {cloud_type} account {id} including its account group info.
slots:
cloud_type: path.cloud_type
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud/{cloud_type}/{id}'].put
update:
x-apievangelist-phrasing:
intent: Update a cloud account by cloud type
effect: write
questions:
- How do I change the onboarding settings of an existing non-AWS cloud account?
- Can I update a cloud account's configuration without waiting for status checks?
instructions:
- text: Update the configuration of {cloud_type} account {id}.
slots:
cloud_type: path.cloud_type
id: path.id
- text: Save changes to {cloud_type} account {id} and skip status checks.
slots:
cloud_type: path.cloud_type
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud/{cloud_type}/{id}'].delete
update:
x-apievangelist-phrasing:
intent: Remove an onboarded cloud account
effect: destructive
questions:
- How do I offboard a cloud account from Prisma Cloud?
- What happens if I delete a cloud account that's been onboarded?
instructions:
- text: Delete {cloud_type} account {id}.
slots:
cloud_type: path.cloud_type
id: path.id
- text: Offboard cloud account {id} of type {cloud_type}.
slots:
id: path.id
cloud_type: path.cloud_type
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud/{cloud_type}/{id}'].patch
update:
x-apievangelist-phrasing:
intent: Update a cloud account’s settings
effect: write
questions:
- Can I change the account groups on an onboarded cloud account or switch it off?
- Is it possible to update child account status along with the parent account?
instructions:
- text: Move {cloud_type} account {id} into account groups {groupIds}.
slots:
cloud_type: path.cloud_type
id: path.id
groupIds: requestBody.groupIds
- text: Set enabled to {enabled} on {cloud_type} account {id} and apply it to child accounts with {updateChildrenStatus}.
slots:
enabled: requestBody.enabled
cloud_type: path.cloud_type
id: path.id
updateChildrenStatus: requestBody.updateChildrenStatus
method: generated
generated: '2026-10-01'
- target: $.paths['/account/{accountId}/config/status'].get
update:
x-apievangelist-phrasing:
intent: Show services with warnings for an account
effect: read
questions:
- Which Prisma Cloud services are showing warnings or errors for my account?
- Why is my cloud account in an error state?
instructions:
- text: List the services with warning or error status for account {accountId}.
slots:
accountId: path.accountId
- text: Show the config status details of cloud account {accountId}.
slots:
accountId: path.accountId
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud/status/{cloud_type}'].post
update:
x-apievangelist-phrasing:
intent: Dry-run onboarding checks for a cloud type
effect: read
questions:
- Can I validate my onboarding parameters before actually adding an account?
- How do I run a trial onboarding for an Azure or GCP account?
instructions:
- text: Run an onboarding trial for a {cloud_type} account.
slots:
cloud_type: path.cloud_type
- text: Validate my {cloud_type} account parameters before onboarding.
slots:
cloud_type: path.cloud_type
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud/{id}/status/{enabled}'].patch
update:
x-apievangelist-phrasing:
intent: Enable or disable a cloud account
effect: write
questions:
- What's the quickest way to turn monitoring off for one cloud account?
- Can I re-enable an account and its children just by setting a status flag?
instructions:
- text: Set the status of cloud account {id} to {enabled}.
slots:
id: path.id
enabled: path.enabled
- text: Disable account {id} by setting enabled to {enabled} and apply to children.
slots:
id: path.id
enabled: path.enabled
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud/{cloud_type}/accounts/{account_id}/hierarchy'].get
update:
x-apievangelist-phrasing:
intent: Get the saved GCP resource hierarchy
effect: read
questions:
- Where can I see the GCP folder and project hierarchy I saved earlier?
- What resource hierarchy was stored for my GCP org account?
instructions:
- text: Get the saved resource hierarchy for GCP account {account_id} of type {cloud_type}.
slots:
account_id: path.account_id
cloud_type: path.cloud_type
- text: Show the previously saved hierarchy of {cloud_type} account {account_id}.
slots:
cloud_type: path.cloud_type
account_id: path.account_id
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud/gcp/parent/{parent_id}/children'].post
update:
x-apievangelist-phrasing:
intent: List GCP folders and projects under a parent
effect: read
questions:
- How can I see both folders and projects beneath a GCP organization?
- Can I page through GCP projects and folders under a parent separately?
instructions:
- text: List the folders and projects under GCP parent {parent_id} of type {parentType}.
slots:
parent_id: path.parent_id
parentType: query.parentType
- text: Get all children of GCP {parentType} {parent_id} using my service account key {credentials}.
slots:
parentType: query.parentType
parent_id: path.parent_id
credentials: requestBody.credentials
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud/{cloud_type}/parent/{parent_id}/folders'].post
update:
x-apievangelist-phrasing:
intent: List GCP child folders of a parent
effect: read
questions:
- Which GCP folders sit directly under my organization or folder?
- Can I list only the folders, not projects, under a GCP parent?
instructions:
- text: List only the child folders of GCP {parentType} {parent_id} for {cloud_type}.
slots:
parentType: query.parentType
parent_id: path.parent_id
cloud_type: path.cloud_type
- text: Page through GCP folders under {parent_id} with page size {pageSize}; parent type {parentType}, cloud {cloud_type}.
slots:
parent_id: path.parent_id
pageSize: query.pageSize
parentType: query.parentType
cloud_type: path.cloud_type
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud/{cloud_type}/parent/{parent_id}/projects'].post
update:
x-apievangelist-phrasing:
intent: List GCP child projects of a parent
effect: read
questions:
- What GCP projects live under a given folder?
- Can I list only the projects, skipping folders, beneath a GCP org?
instructions:
- text: List the child projects of GCP {parentType} {parent_id} for {cloud_type}.
slots:
parentType: query.parentType
parent_id: path.parent_id
cloud_type: path.cloud_type
- text: Page GCP projects under {parent_id} with page size {pageSize}; parent type {parentType}, cloud {cloud_type}.
slots:
parent_id: path.parent_id
pageSize: query.pageSize
parentType: query.parentType
cloud_type: path.cloud_type
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud/{cloud_type}/accounts/{account_id}/ancestors'].post
update:
x-apievangelist-phrasing:
intent: Find ancestors of GCP projects and folders
effect: read
questions:
- Which parent folders and org does a given GCP project roll up to?
- Can I map several GCP projects to their ancestor chain at once?
instructions:
- text: Get the GCP ancestors of resources {resourceIds} in {cloud_type} account {account_id}.
slots:
resourceIds: requestBody.resourceIds
cloud_type: path.cloud_type
account_id: path.account_id
- text: Show the ancestor chain for GCP projects in account {account_id} of type {cloud_type}.
slots:
account_id: path.account_id
cloud_type: path.cloud_type
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud-accounts-manager/v1/cloudAccounts/azureAccounts/{parent_id}/children'].post
update:
x-apievangelist-phrasing:
intent: List Azure subscriptions and groups under a parent
effect: read
questions:
- What subscriptions and management groups are under my Azure tenant?
- Can I browse the children of an Azure management group?
instructions:
- text: List Azure subscriptions and management groups under parent {parent_id}.
slots:
parent_id: path.parent_id
- text: Show the children of Azure management group {parent_id}.
slots:
parent_id: path.parent_id
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud-accounts-manager/v1/cloudAccounts/azureAccounts/{account_id}/ancestors'].post
update:
x-apievangelist-phrasing:
intent: Find ancestors of Azure subscriptions
effect: read
questions:
- Which management groups does an Azure subscription roll up to?
- Can I get the ancestor path for several Azure subscriptions at once?
instructions:
- text: Get the Azure ancestors of {resourceIds} in tenant account {account_id}.
slots:
resourceIds: requestBody.resourceIds
account_id: path.account_id
- text: Show the management group ancestry for Azure tenant {account_id}.
slots:
account_id: path.account_id
method: generated
generated: '2026-09-26'
- target: $.paths['/dlp/api/v1/config/awsorg/status'].post
update:
x-apievangelist-phrasing:
intent: Check AWS org data security prerequisites
effect: read
questions:
- Does my AWS Organization meet the prerequisites for data security scanning?
- What does Prisma Cloud check before I can set up data security for an AWS org?
instructions:
- text: Check data security preconditions for AWS org {accountId} with role {roleArn}, external ID {externalId} and SNS topic {snsTopicArn}.
slots:
accountId: requestBody.accountId
roleArn: requestBody.roleArn
externalId: requestBody.externalId
snsTopicArn: requestBody.snsTopicArn
- text: Verify AWS org {accountId} is ready for a data security config.
slots:
accountId: requestBody.accountId
method: generated
generated: '2026-09-26'
- target: $.paths['/dlp/api/config/v2'].put
update:
x-apievangelist-phrasing:
intent: Update data security config for an AWS org
effect: write
questions:
- How do I change the scan option on an existing AWS org data security config?
- Can I rotate the member role name used by an AWS org data security scan?
instructions:
- text: Update the AWS org data security config for {accountId} to scan option {scanOption}.
slots:
accountId: requestBody.accountId
scanOption: requestBody.scanOption
- text: Change the existing data security scan of AWS org {accountId} to use member role {memberRoleName}.
slots:
accountId: requestBody.accountId
memberRoleName: requestBody.memberRoleName
method: generated
generated: '2026-09-26'
- target: $.paths['/dlp/api/config/v2'].post
update:
x-apievangelist-phrasing:
intent: Create a data security config for an AWS org
effect: write
questions:
- How do I turn on data security scanning for my whole AWS Organization?
- What do I need, like role ARNs and an SNS topic, to create an AWS org data security config?
instructions:
- text: Create a data security config for AWS org {accountId} with master role {masterRoleArn} and SNS topic {snsTopicArn}.
slots:
accountId: requestBody.accountId
masterRoleArn: requestBody.masterRoleArn
snsTopicArn: requestBody.snsTopicArn
- text: Start data security scanning on AWS org {accountId} with scan option {scanOption}.
slots:
accountId: requestBody.accountId
scanOption: requestBody.scanOption
method: generated
generated: '2026-09-26'
- target: $.paths['/dlp/api/config/v2/{accountId}'].get
update:
x-apievangelist-phrasing:
intent: Get the data security config of an AWS org
effect: read
questions:
- What data security scan settings are configured for my AWS org?
- Is data security already configured for this AWS Organization?
instructions:
- text: Get the data security config for AWS org {accountId}.
slots:
accountId: path.accountId
- text: Show the scan settings on AWS org account {accountId}.
slots:
accountId: path.accountId
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud-accounts-manager/v1/cloudAccounts/awsAccounts/{parent_id}/children'].post
update:
x-apievangelist-phrasing:
intent: List AWS OU children (legacy endpoint)
effect: read
questions:
- Is there still a legacy endpoint to list accounts and OUs under an AWS organizational unit?
- Can I page AWS child accounts under an OU using the older cloud accounts manager path?
instructions:
- text: Using the legacy endpoint, list the accounts and OUs under AWS OU {parent_id}.
slots:
parent_id: path.parent_id
- text: 'Legacy lookup: fetch {accountFetchCount} child accounts of AWS OU {parent_id}.'
slots:
accountFetchCount: query.accountFetchCount
parent_id: path.parent_id
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud-accounts-manager/v1/cloudAccounts/awsAccounts/{account_id}/ancestors'].post
update:
x-apievangelist-phrasing:
intent: Find AWS account ancestors (legacy endpoint)
effect: read
questions:
- Does the older cloud accounts manager API still return ancestors for AWS member accounts?
- Where's the legacy call that maps AWS OUs to their parents?
instructions:
- text: Using the legacy endpoint, get ancestors of members in AWS account {account_id}.
slots:
account_id: path.account_id
- text: 'Legacy lookup: show the OU ancestry for AWS org account {account_id}.'
slots:
account_id: path.account_id
method: generated
generated: '2026-09-26'
- target: $.paths['/cas/v1/aws_account'].post
update:
x-apievangelist-phrasing:
intent: Onboard an AWS account
effect: write
questions:
- How do I onboard an AWS account or organization using a role ARN?
- Can I choose which features to enable when adding an AWS account?
instructions:
- text: Onboard AWS account {accountId} named {name} with role {roleArn} as type {accountType}.
slots:
accountId: requestBody.accountId
name: requestBody.name
roleArn: requestBody.roleArn
accountType: requestBody.accountType
- text: Add AWS organization {accountId} as {name} using role {roleArn} into account group {defaultAccountGroupId}; type {accountType}.
slots:
accountId: requestBody.accountId
name: requestBody.name
roleArn: requestBody.roleArn
defaultAccountGroupId: requestBody.defaultAccountGroupId
accountType: requestBody.accountType
method: generated
generated: '2026-09-26'
- target: $.paths['/cas/v1/aws_account/{id}'].put
update:
x-apievangelist-phrasing:
intent: Update an onboarded AWS account
effect: write
questions:
- How do I change the role ARN or features of an AWS account already onboarded?
- Can I rename an existing AWS cloud account?
instructions:
- text: Update AWS cloud account {id} with new role {roleArn}; AWS ID {accountId}, name {name}, type {accountType}.
slots:
id: path.id
roleArn: requestBody.roleArn
accountId: requestBody.accountId
name: requestBody.name
accountType: requestBody.accountType
- text: Rename AWS cloud account {id} to {name}.
slots:
id: path.id
name: requestBody.name
method: generated
generated: '2026-09-26'
- target: $.paths['/cas/v1/cloud_account/status/aws'].post
update:
x-apievangelist-phrasing:
intent: Check an AWS account onboarding status
effect: read
questions:
- Will my AWS role ARN and settings pass Prisma Cloud's account checks?
- What status messages come back for an AWS account before or after onboarding?
instructions:
- text: Check the AWS status messages for account {accountId} with role {roleArn}; name {name}, type {accountType}.
slots:
accountId: requestBody.accountId
roleArn: requestBody.roleArn
name: requestBody.name
accountType: requestBody.accountType
- text: Validate AWS account {accountId} permissions.
slots:
accountId: requestBody.accountId
method: generated
generated: '2026-09-26'
- target: $.paths['/cas/v1/aws_account/{parent_id}/children'].post
update:
x-apievangelist-phrasing:
intent: List AWS accounts and OUs under an OU
effect: read
questions:
- Which AWS accounts and organizational units are under a given OU?
- Can I browse my AWS org tree one OU at a time?
instructions:
- text: List the AWS accounts and OUs under OU {parent_id} for org {accountId} with role {roleArn}, type {accountType}.
slots:
parent_id: path.parent_id
accountId: requestBody.accountId
roleArn: requestBody.roleArn
accountType: requestBody.accountType
- text: Show the child OUs of AWS OU {parent_id}.
slots:
parent_id: path.parent_id
method: generated
generated: '2026-09-26'
- target: $.paths['/cas/v1/aws_account/{account_id}/ancestors'].post
update:
x-apievangelist-phrasing:
intent: Find ancestors of AWS accounts and OUs
effect: read
questions:
- Which OUs does an AWS member account sit under?
- Can I get the parent chain for several AWS accounts in one request?
instructions:
- text: Get the ancestors of AWS resources {resourceIds} in org account {account_id}.
slots:
resourceIds: requestBody.resourceIds
account_id: path.account_id
- text: Map AWS accounts {resourceIds} to their OU ancestry using role {roleArn} for {accountId}, type {accountType}.
slots:
resourceIds: requestBody.resourceIds
roleArn: requestBody.roleArn
accountId: requestBody.accountId
accountType: requestBody.accountType
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud/{cloudType}'].post
update:
x-apievangelist-phrasing:
intent: Onboard a named cloud account with account groups
effect: write
questions:
- What do I need to supply, like the provider account ID and a display name, to start monitoring an AWS or OCI account?
- Can I attach account groups to a cloud account at the moment I onboard it?
- Is it possible to onboard a cloud account with monitoring switched off at first?
instructions:
- text: Onboard {cloudType} account {accountId} under the display name {name}.
slots:
cloudType: path.cloudType
accountId: requestBody.accountId
name: requestBody.name
- text: Start monitoring {cloudType} account {accountId} as {name} and put it in account groups {groupIds}.
slots:
cloudType: path.cloudType
accountId: requestBody.accountId
name: requestBody.name
groupIds: requestBody.groupIds
method: generated
generated: '2026-10-01'
- target: $.paths['/cloud/{cloudType}/{id}'].delete
update:
x-apievangelist-phrasing:
intent: Stop monitoring a cloud account, keeping its alerts
effect: destructive
questions:
- How can I stop Prisma Cloud monitoring an account but keep its old alerts for historical analysis?
- Are alerts and data kept after a cloud account is removed from monitoring?
instructions:
- text: Remove {cloudType} account {id} from monitoring but keep its alert history.
slots:
cloudType: path.cloudType
id: path.id
- text: Stop monitoring cloud account {id} ({cloudType}) and retain its historical data.
slots:
id: path.id
cloudType: path.cloudType
method: generated
generated: '2026-10-01'