Palo Alto Networks · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Palo Alto Networks Cloud Accounts (AWS) API

12 actions 12 updates phrasing extends openapi/palo-alto-networks-cloud-accounts-aws-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 12

$.info
$.paths['/cas/v1/aws_account'].post
$.paths['/cas/v1/aws_account/{account_id}/ancestors'].post
$.paths['/cas/v1/aws_account/{id}'].put
$.paths['/cas/v1/aws_account/{parent_id}/children'].post
$.paths['/cas/v1/cloud_account/status/aws'].post
$.paths['/cloud-accounts-manager/v1/cloudAccounts/awsAccounts/{account_id}/ancestors'].post
$.paths['/cloud-accounts-manager/v1/cloudAccounts/awsAccounts/{parent_id}/children'].post
$.paths['/cas/v1/aws_template/presigned_url'].post
$.paths['/cas/v1/aws_template'].post
$.paths['/config/v3/account/awsorg/{id}'].get
$.paths['/config/v3/account/awsorg/{id}/status'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Palo Alto Networks Cloud Accounts (AWS) API
  version: 1.0.0
extends: openapi/palo-alto-networks-cloud-accounts-aws-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 11
- target: $.paths['/cas/v1/aws_account'].post
  update:
    x-apievangelist-phrasing:
      intent: Onboard an AWS cloud account
      effect: write
      questions:
      - How do I onboard an AWS account into Prisma Cloud using an IAM role ARN?
      - Can I onboard a whole AWS organization rather than a single account?
      - Is there a way to skip status checks to speed up adding an AWS account?
      instructions:
      - text: Onboard AWS account {accountId} as {name} using role {roleArn}, account type {accountType}.
        slots:
          accountId: requestBody.accountId
          name: requestBody.name
          roleArn: requestBody.roleArn
          accountType: requestBody.accountType
      - text: Add AWS {accountType} account {accountId} named {name} with role {roleArn} into account groups {groupIds}.
        slots:
          accountType: requestBody.accountType
          accountId: requestBody.accountId
          name: requestBody.name
          roleArn: requestBody.roleArn
          groupIds: requestBody.groupIds
      method: generated
      generated: '2026-09-26'
- target: $.paths['/cas/v1/aws_account/{account_id}/ancestors'].post
  update:
    x-apievangelist-phrasing:
      intent: List ancestors of AWS member accounts and OUs
      effect: read
      questions:
      - Which parent OUs sit above certain member accounts in my onboarded AWS organization?
      - Can I map a list of AWS account and OU IDs to their ancestor chain?
      instructions:
      - text: List the ancestors of resources {resourceIds} in AWS org account {account_id}, with AWS account {accountId}, role {roleArn}, type {accountType}.
        slots:
          resourceIds: requestBody.resourceIds
          account_id: path.account_id
          accountId: requestBody.accountId
          roleArn: requestBody.roleArn
          accountType: requestBody.accountType
      - text: Find parent OUs for {resourceIds} under cloud account {account_id} (AWS ID {accountId}, role {roleArn}, {accountType}).
        slots:
          resourceIds: requestBody.resourceIds
          account_id: path.account_id
          accountId: requestBody.accountId
          roleArn: requestBody.roleArn
          accountType: requestBody.accountType
      method: generated
      generated: '2026-09-26'
- target: $.paths['/cas/v1/aws_account/{id}'].put
  update:
    x-apievangelist-phrasing:
      intent: Update an onboarded AWS cloud account
      effect: write
      questions:
      - How do I change the role ARN or features on an AWS account already in Prisma Cloud?
      - Can I move an onboarded AWS account into different account groups?
      instructions:
      - text: 'Update AWS cloud account {id}: AWS ID {accountId}, name {name}, role {roleArn}, type {accountType}.'
        slots:
          id: path.id
          accountId: requestBody.accountId
          name: requestBody.name
          roleArn: requestBody.roleArn
          accountType: requestBody.accountType
      - text: Reassign onboarded AWS account {id} ({accountId}, {name}, role {roleArn}, {accountType}) to groups {groupIds}.
        slots:
          id: path.id
          accountId: requestBody.accountId
          name: requestBody.name
          roleArn: requestBody.roleArn
          accountType: requestBody.accountType
          groupIds: requestBody.groupIds
      method: generated
      generated: '2026-09-26'
- target: $.paths['/cas/v1/aws_account/{parent_id}/children'].post
  update:
    x-apievangelist-phrasing:
      intent: List child OUs and accounts under an AWS parent
      effect: read
      questions:
      - What accounts and OUs live directly under a given organizational unit in my AWS organization?
      - Can I page through child accounts and child OUs separately?
      instructions:
      - text: List children of AWS OU {parent_id} for account {accountId} with role {roleArn} and type {accountType}.
        slots:
          parent_id: path.parent_id
          accountId: requestBody.accountId
          roleArn: requestBody.roleArn
          accountType: requestBody.accountType
      - text: Get {accountFetchCount} child accounts under OU {parent_id} (AWS {accountId}, role {roleArn}, {accountType}).
        slots:
          accountFetchCount: query.accountFetchCount
          parent_id: path.parent_id
          accountId: requestBody.accountId
          roleArn: requestBody.roleArn
          accountType: requestBody.accountType
      method: generated
      generated: '2026-09-26'
- target: $.paths['/cas/v1/cloud_account/status/aws'].post
  update:
    x-apievangelist-phrasing:
      intent: Check the status of an AWS cloud account
      effect: read
      questions:
      - Why is my AWS account showing errors in Prisma Cloud — what do its status messages say?
      - Can I validate an AWS account's role and permissions before onboarding it?
      instructions:
      - text: Check status of AWS account {accountId} named {name} with role {roleArn}, type {accountType}.
        slots:
          accountId: requestBody.accountId
          name: requestBody.name
          roleArn: requestBody.roleArn
          accountType: requestBody.accountType
      - text: Show status messages for AWS {accountType} account {accountId} ({name}) using role {roleArn}.
        slots:
          accountType: requestBody.accountType
          accountId: requestBody.accountId
          name: requestBody.name
          roleArn: requestBody.roleArn
      method: generated
      generated: '2026-09-26'
- target: $.paths['/cloud-accounts-manager/v1/cloudAccounts/awsAccounts/{account_id}/ancestors'].post
  update:
    x-apievangelist-phrasing:
      intent: List AWS ancestors via the legacy endpoint
      effect: read
      questions:
      - Is there an older cloud-accounts-manager endpoint for finding the ancestors of AWS member accounts?
      - Can I get ancestors for an AWS account with the legacy call that needs only the account ID?
      instructions:
      - text: Using the legacy cloud accounts manager, list ancestors for AWS account {account_id}.
        slots:
          account_id: path.account_id
      - text: Call the legacy AWS ancestors endpoint for cloud account {account_id}.
        slots:
          account_id: path.account_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/cloud-accounts-manager/v1/cloudAccounts/awsAccounts/{parent_id}/children'].post
  update:
    x-apievangelist-phrasing:
      intent: List AWS OU children via the legacy endpoint
      effect: read
      questions:
      - Is there a legacy call to list child accounts and OUs under an AWS parent without sending credentials in the body?
      - Can the older children endpoint page OUs with its own token?
      instructions:
      - text: Using the legacy cloud accounts manager, list children of OU {parent_id}.
        slots:
          parent_id: path.parent_id
      - text: Get {ouFetchCount} child OUs of {parent_id} from the legacy children endpoint.
        slots:
          ouFetchCount: query.ouFetchCount
          parent_id: path.parent_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/cas/v1/aws_template/presigned_url'].post
  update:
    x-apievangelist-phrasing:
      intent: Generate an AWS CloudFormation quick-create link
      effect: write
      questions:
      - How do I get a CloudFormation quick-create link with a presigned template URL for onboarding AWS?
      - Can the generated stack link include permissions only for the features I select?
      instructions:
      - text: Generate a CloudFormation quick-create stack link for AWS account {accountId} of type {accountType}.
        slots:
          accountId: requestBody.accountId
          accountType: requestBody.accountType
      - text: Create a presigned CFT stack link for {accountType} account {accountId} with features {features}.
        slots:
          accountType: requestBody.accountType
          accountId: requestBody.accountId
          features: requestBody.features
      method: generated
      generated: '2026-09-26'
- target: $.paths['/cas/v1/aws_template'].post
  update:
    x-apievangelist-phrasing:
      intent: Download the AWS onboarding CFT template
      effect: write
      questions:
      - Where can I download the CloudFormation template file that creates the Prisma Cloud IAM role?
      - Does the downloadable CFT include the generated external ID?
      instructions:
      - text: Download the CFT template file for AWS account {accountId}, type {accountType}.
        slots:
          accountId: requestBody.accountId
          accountType: requestBody.accountType
      - text: Generate a {cftType} CFT template body for {accountType} account {accountId}.
        slots:
          cftType: requestBody.cftType
          accountType: requestBody.accountType
          accountId: requestBody.accountId
      method: generated
      generated: '2026-09-26'
- target: $.paths['/config/v3/account/awsorg/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get AWS Org master account details for PCDS
      effect: read
      questions:
      - What attributes define my AWS organization master account for data security flows?
      - Can I fetch the PCDS configuration of an AWS Org account?
      instructions:
      - text: Fetch the AWS Org master account details for {id}.
        slots:
          id: path.id
      - text: Show the PCDS config of AWS organization account {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/config/v3/account/awsorg/{id}/status'].get
  update:
    x-apievangelist-phrasing:
      intent: Check PCDS permissions on an AWS Org account
      effect: read
      questions:
      - Is my AWS Org account missing any permissions needed for data security scanning?
      - Can I run a permissions check on a PCDS AWS organization account?
      instructions:
      - text: Run the PCDS permissions check on AWS Org account {id}.
        slots:
          id: path.id
      - text: List missing permissions for AWS organization account {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'