Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Palo Alto Networks Cloud Accounts (AWS) API
12 actions
12 updates
phrasing
extends
openapi/palo-alto-networks-cloud-accounts-aws-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 12
$.info
$.paths['/cas/v1/aws_account'].post
$.paths['/cas/v1/aws_account/{account_id}/ancestors'].post
$.paths['/cas/v1/aws_account/{id}'].put
$.paths['/cas/v1/aws_account/{parent_id}/children'].post
$.paths['/cas/v1/cloud_account/status/aws'].post
$.paths['/cloud-accounts-manager/v1/cloudAccounts/awsAccounts/{account_id}/ancestors'].post
$.paths['/cloud-accounts-manager/v1/cloudAccounts/awsAccounts/{parent_id}/children'].post
$.paths['/cas/v1/aws_template/presigned_url'].post
$.paths['/cas/v1/aws_template'].post
$.paths['/config/v3/account/awsorg/{id}'].get
$.paths['/config/v3/account/awsorg/{id}/status'].get
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Palo Alto Networks Cloud Accounts (AWS) API
version: 1.0.0
extends: openapi/palo-alto-networks-cloud-accounts-aws-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 11
- target: $.paths['/cas/v1/aws_account'].post
update:
x-apievangelist-phrasing:
intent: Onboard an AWS cloud account
effect: write
questions:
- How do I onboard an AWS account into Prisma Cloud using an IAM role ARN?
- Can I onboard a whole AWS organization rather than a single account?
- Is there a way to skip status checks to speed up adding an AWS account?
instructions:
- text: Onboard AWS account {accountId} as {name} using role {roleArn}, account type {accountType}.
slots:
accountId: requestBody.accountId
name: requestBody.name
roleArn: requestBody.roleArn
accountType: requestBody.accountType
- text: Add AWS {accountType} account {accountId} named {name} with role {roleArn} into account groups {groupIds}.
slots:
accountType: requestBody.accountType
accountId: requestBody.accountId
name: requestBody.name
roleArn: requestBody.roleArn
groupIds: requestBody.groupIds
method: generated
generated: '2026-09-26'
- target: $.paths['/cas/v1/aws_account/{account_id}/ancestors'].post
update:
x-apievangelist-phrasing:
intent: List ancestors of AWS member accounts and OUs
effect: read
questions:
- Which parent OUs sit above certain member accounts in my onboarded AWS organization?
- Can I map a list of AWS account and OU IDs to their ancestor chain?
instructions:
- text: List the ancestors of resources {resourceIds} in AWS org account {account_id}, with AWS account {accountId}, role {roleArn}, type {accountType}.
slots:
resourceIds: requestBody.resourceIds
account_id: path.account_id
accountId: requestBody.accountId
roleArn: requestBody.roleArn
accountType: requestBody.accountType
- text: Find parent OUs for {resourceIds} under cloud account {account_id} (AWS ID {accountId}, role {roleArn}, {accountType}).
slots:
resourceIds: requestBody.resourceIds
account_id: path.account_id
accountId: requestBody.accountId
roleArn: requestBody.roleArn
accountType: requestBody.accountType
method: generated
generated: '2026-09-26'
- target: $.paths['/cas/v1/aws_account/{id}'].put
update:
x-apievangelist-phrasing:
intent: Update an onboarded AWS cloud account
effect: write
questions:
- How do I change the role ARN or features on an AWS account already in Prisma Cloud?
- Can I move an onboarded AWS account into different account groups?
instructions:
- text: 'Update AWS cloud account {id}: AWS ID {accountId}, name {name}, role {roleArn}, type {accountType}.'
slots:
id: path.id
accountId: requestBody.accountId
name: requestBody.name
roleArn: requestBody.roleArn
accountType: requestBody.accountType
- text: Reassign onboarded AWS account {id} ({accountId}, {name}, role {roleArn}, {accountType}) to groups {groupIds}.
slots:
id: path.id
accountId: requestBody.accountId
name: requestBody.name
roleArn: requestBody.roleArn
accountType: requestBody.accountType
groupIds: requestBody.groupIds
method: generated
generated: '2026-09-26'
- target: $.paths['/cas/v1/aws_account/{parent_id}/children'].post
update:
x-apievangelist-phrasing:
intent: List child OUs and accounts under an AWS parent
effect: read
questions:
- What accounts and OUs live directly under a given organizational unit in my AWS organization?
- Can I page through child accounts and child OUs separately?
instructions:
- text: List children of AWS OU {parent_id} for account {accountId} with role {roleArn} and type {accountType}.
slots:
parent_id: path.parent_id
accountId: requestBody.accountId
roleArn: requestBody.roleArn
accountType: requestBody.accountType
- text: Get {accountFetchCount} child accounts under OU {parent_id} (AWS {accountId}, role {roleArn}, {accountType}).
slots:
accountFetchCount: query.accountFetchCount
parent_id: path.parent_id
accountId: requestBody.accountId
roleArn: requestBody.roleArn
accountType: requestBody.accountType
method: generated
generated: '2026-09-26'
- target: $.paths['/cas/v1/cloud_account/status/aws'].post
update:
x-apievangelist-phrasing:
intent: Check the status of an AWS cloud account
effect: read
questions:
- Why is my AWS account showing errors in Prisma Cloud — what do its status messages say?
- Can I validate an AWS account's role and permissions before onboarding it?
instructions:
- text: Check status of AWS account {accountId} named {name} with role {roleArn}, type {accountType}.
slots:
accountId: requestBody.accountId
name: requestBody.name
roleArn: requestBody.roleArn
accountType: requestBody.accountType
- text: Show status messages for AWS {accountType} account {accountId} ({name}) using role {roleArn}.
slots:
accountType: requestBody.accountType
accountId: requestBody.accountId
name: requestBody.name
roleArn: requestBody.roleArn
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud-accounts-manager/v1/cloudAccounts/awsAccounts/{account_id}/ancestors'].post
update:
x-apievangelist-phrasing:
intent: List AWS ancestors via the legacy endpoint
effect: read
questions:
- Is there an older cloud-accounts-manager endpoint for finding the ancestors of AWS member accounts?
- Can I get ancestors for an AWS account with the legacy call that needs only the account ID?
instructions:
- text: Using the legacy cloud accounts manager, list ancestors for AWS account {account_id}.
slots:
account_id: path.account_id
- text: Call the legacy AWS ancestors endpoint for cloud account {account_id}.
slots:
account_id: path.account_id
method: generated
generated: '2026-09-26'
- target: $.paths['/cloud-accounts-manager/v1/cloudAccounts/awsAccounts/{parent_id}/children'].post
update:
x-apievangelist-phrasing:
intent: List AWS OU children via the legacy endpoint
effect: read
questions:
- Is there a legacy call to list child accounts and OUs under an AWS parent without sending credentials in the body?
- Can the older children endpoint page OUs with its own token?
instructions:
- text: Using the legacy cloud accounts manager, list children of OU {parent_id}.
slots:
parent_id: path.parent_id
- text: Get {ouFetchCount} child OUs of {parent_id} from the legacy children endpoint.
slots:
ouFetchCount: query.ouFetchCount
parent_id: path.parent_id
method: generated
generated: '2026-09-26'
- target: $.paths['/cas/v1/aws_template/presigned_url'].post
update:
x-apievangelist-phrasing:
intent: Generate an AWS CloudFormation quick-create link
effect: write
questions:
- How do I get a CloudFormation quick-create link with a presigned template URL for onboarding AWS?
- Can the generated stack link include permissions only for the features I select?
instructions:
- text: Generate a CloudFormation quick-create stack link for AWS account {accountId} of type {accountType}.
slots:
accountId: requestBody.accountId
accountType: requestBody.accountType
- text: Create a presigned CFT stack link for {accountType} account {accountId} with features {features}.
slots:
accountType: requestBody.accountType
accountId: requestBody.accountId
features: requestBody.features
method: generated
generated: '2026-09-26'
- target: $.paths['/cas/v1/aws_template'].post
update:
x-apievangelist-phrasing:
intent: Download the AWS onboarding CFT template
effect: write
questions:
- Where can I download the CloudFormation template file that creates the Prisma Cloud IAM role?
- Does the downloadable CFT include the generated external ID?
instructions:
- text: Download the CFT template file for AWS account {accountId}, type {accountType}.
slots:
accountId: requestBody.accountId
accountType: requestBody.accountType
- text: Generate a {cftType} CFT template body for {accountType} account {accountId}.
slots:
cftType: requestBody.cftType
accountType: requestBody.accountType
accountId: requestBody.accountId
method: generated
generated: '2026-09-26'
- target: $.paths['/config/v3/account/awsorg/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get AWS Org master account details for PCDS
effect: read
questions:
- What attributes define my AWS organization master account for data security flows?
- Can I fetch the PCDS configuration of an AWS Org account?
instructions:
- text: Fetch the AWS Org master account details for {id}.
slots:
id: path.id
- text: Show the PCDS config of AWS organization account {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/config/v3/account/awsorg/{id}/status'].get
update:
x-apievangelist-phrasing:
intent: Check PCDS permissions on an AWS Org account
effect: read
questions:
- Is my AWS Org account missing any permissions needed for data security scanning?
- Can I run a permissions check on a PCDS AWS organization account?
instructions:
- text: Run the PCDS permissions check on AWS Org account {id}.
slots:
id: path.id
- text: List missing permissions for AWS organization account {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'