Palo Alto Networks · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Incident Security Service Posture Management IDP API

12 actions 12 updates phrasing extends openapi/palo-alto-networks-idp-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 12

$.info
$.paths['/sspm/identity/v1/idps'].get
$.paths['/sspm/identity/v1/idps'].post
$.paths['/sspm/identity/v1/idps/{idpId}/accounts/logout'].get
$.paths['/sspm/identity/v1/idps/{idpId}/accounts/logout'].post
$.paths['/sspm/identity/v1/idps/{idpId}/feature_state'].get
$.paths['/sspm/identity/v1/idps/{idpId}/idp_accounts/count'].get
$.paths['/sspm/identity/v1/idps/{idpId}/idp_accounts/csv_report'].post
$.paths['/sspm/identity/v1/idps/{idpId}/mfa_activity'].get
$.paths['/sspm/identity/v1/idps/{idpId}/mfa_activity/count'].get
$.paths['/sspm/identity/v1/idps/{idpId}/mfa_activity/count_by_app_type'].get
$.paths['/sspm/identity/v1/idps/{idpId}/mfa_activity/csv_report'].post

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Incident Security Service Posture Management IDP API
  version: 1.0.0
extends: openapi/palo-alto-networks-idp-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 11
- target: $.paths['/sspm/identity/v1/idps'].get
  update:
    x-apievangelist-phrasing:
      intent: List the tenant's identity providers
      effect: read
      questions:
      - Which identity providers are connected to my SaaS security posture tenant?
      - Can I see only the designated identity providers?
      instructions:
      - text: List all identity providers configured for tenant {x-ps-tenant}.
        slots:
          x-ps-tenant: header.x-ps-tenant
      - text: Show only identity providers where designated is {designated}.
        slots:
          designated: query.designated
      method: generated
      generated: '2026-09-26'
- target: $.paths['/sspm/identity/v1/idps'].post
  update:
    x-apievangelist-phrasing:
      intent: Register a new identity provider
      effect: write
      questions:
      - How do I add an identity provider to my SSPM tenant?
      - Can a new identity provider be marked as designated when I add it?
      instructions:
      - text: Add identity provider {idpId} of type {idpType}.
        slots:
          idpId: query.idpId
          idpType: query.idpType
      - text: Register a {idpType} identity provider and mark it designated={designated}.
        slots:
          idpType: query.idpType
          designated: query.designated
      method: generated
      generated: '2026-09-26'
- target: $.paths['/sspm/identity/v1/idps/{idpId}/accounts/logout'].get
  update:
    x-apievangelist-phrasing:
      intent: Check the status of a forced account logout
      effect: read
      questions:
      - Did the forced logout of accounts on my identity provider finish?
      - What is the outcome of a specific logout batch I triggered earlier?
      instructions:
      - text: Check logout status for identity provider {idpId}, batch {batch_id}.
        slots:
          idpId: path.idpId
          batch_id: query.batch_id
      - text: Show the result of the account logout run on identity provider {idpId}.
        slots:
          idpId: path.idpId
      method: generated
      generated: '2026-09-26'
- target: $.paths['/sspm/identity/v1/idps/{idpId}/accounts/logout'].post
  update:
    x-apievangelist-phrasing:
      intent: Force-log out users from an identity provider
      effect: destructive
      questions:
      - How can I terminate sessions for compromised users in my identity provider?
      - Can I sign out a specific list of users from one identity provider at once?
      instructions:
      - text: Log out users {users} from identity provider {idpId}.
        slots:
          users: requestBody.users
          idpId: path.idpId
      - text: Force session termination for the listed accounts on identity provider {idpId}.
        slots:
          idpId: path.idpId
      method: generated
      generated: '2026-09-26'
- target: $.paths['/sspm/identity/v1/idps/{idpId}/feature_state'].get
  update:
    x-apievangelist-phrasing:
      intent: Check an identity provider feature's scan state
      effect: read
      questions:
      - When was a feature on my identity provider last scanned, and is it healthy?
      - What is the current state of a given feature for one identity provider?
      instructions:
      - text: Get the state and last scan time of feature {feature} on identity provider {idpId}.
        slots:
          feature: query.feature
          idpId: path.idpId
      - text: Show feature health for identity provider {idpId}.
        slots:
          idpId: path.idpId
      method: generated
      generated: '2026-09-26'
- target: $.paths['/sspm/identity/v1/idps/{idpId}/idp_accounts/count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count accounts on an identity provider
      effect: read
      questions:
      - How many user accounts are linked to my identity provider?
      - Can I count just the orphaned or privileged accounts in an identity provider?
      instructions:
      - text: Count the accounts on identity provider {idpId}.
        slots:
          idpId: path.idpId
      - text: Count accounts on identity provider {idpId} matching filter {filter}.
        slots:
          idpId: path.idpId
          filter: query.filter
      method: generated
      generated: '2026-09-26'
- target: $.paths['/sspm/identity/v1/idps/{idpId}/idp_accounts/csv_report'].post
  update:
    x-apievangelist-phrasing:
      intent: Generate a CSV report of identity provider accounts
      effect: write
      questions:
      - Can I export the user accounts in my identity provider to CSV for an access review?
      - Who receives the identity provider account report once it is generated?
      instructions:
      - text: Generate an account CSV for identity provider {idpId} and send it to {userFullName} at {userEmail} for service {service}.
        slots:
          idpId: path.idpId
          userFullName: requestBody.userFullName
          userEmail: requestBody.userEmail
          service: requestBody.service
      - text: Build a CSV of accounts on identity provider {idpId} sorted by {sortBy}.
        slots:
          idpId: path.idpId
          sortBy: query.sortBy
      method: generated
      generated: '2026-09-26'
- target: $.paths['/sspm/identity/v1/idps/{idpId}/mfa_activity'].get
  update:
    x-apievangelist-phrasing:
      intent: View MFA activity logs for an identity provider
      effect: read
      questions:
      - What multi-factor authentication events has my identity provider recorded, with user and IP?
      - Can I page through MFA logs sorted by time?
      instructions:
      - text: Show MFA activity for identity provider {idpId}.
        slots:
          idpId: path.idpId
      - text: List MFA events on identity provider {idpId} matching {filter}, page {page}.
        slots:
          idpId: path.idpId
          filter: query.filter
          page: query.page
      method: generated
      generated: '2026-09-26'
- target: $.paths['/sspm/identity/v1/idps/{idpId}/mfa_activity/count'].get
  update:
    x-apievangelist-phrasing:
      intent: Count MFA events on an identity provider
      effect: read
      questions:
      - How many multi-factor authentication events happened on my identity provider?
      - What is the total MFA volume matching a filter?
      instructions:
      - text: Count MFA events for identity provider {idpId}.
        slots:
          idpId: path.idpId
      - text: Give me the number of MFA events on identity provider {idpId} that match {filter}.
        slots:
          idpId: path.idpId
          filter: query.filter
      method: generated
      generated: '2026-09-26'
- target: $.paths['/sspm/identity/v1/idps/{idpId}/mfa_activity/count_by_app_type'].get
  update:
    x-apievangelist-phrasing:
      intent: Break down MFA activity by application type
      effect: read
      questions:
      - Which application types generate the most MFA prompts on my identity provider?
      - Is there a per-app-type breakdown of multi-factor authentication activity?
      instructions:
      - text: Break down MFA activity by app type for identity provider {idpId}.
        slots:
          idpId: path.idpId
      - text: Group MFA counts by application type on identity provider {idpId} using filter {filter}.
        slots:
          idpId: path.idpId
          filter: query.filter
      method: generated
      generated: '2026-09-26'
- target: $.paths['/sspm/identity/v1/idps/{idpId}/mfa_activity/csv_report'].post
  update:
    x-apievangelist-phrasing:
      intent: Generate a CSV report of MFA activity
      effect: write
      questions:
      - Can I export multi-factor authentication activity to a CSV for auditors?
      - What details do I have to supply to request an MFA activity report?
      instructions:
      - text: Generate an MFA activity CSV for identity provider {idpId}, addressed to {userFullName} at {userEmail} for service {service}.
        slots:
          idpId: path.idpId
          userFullName: requestBody.userFullName
          userEmail: requestBody.userEmail
          service: requestBody.service
      - text: Export MFA events on identity provider {idpId} matching {filter} to CSV.
        slots:
          idpId: path.idpId
          filter: query.filter
      method: generated
      generated: '2026-09-26'