Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Incident Security Service Posture Management IDP API
12 actions
12 updates
phrasing
extends
openapi/palo-alto-networks-idp-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 12
$.info
$.paths['/sspm/identity/v1/idps'].get
$.paths['/sspm/identity/v1/idps'].post
$.paths['/sspm/identity/v1/idps/{idpId}/accounts/logout'].get
$.paths['/sspm/identity/v1/idps/{idpId}/accounts/logout'].post
$.paths['/sspm/identity/v1/idps/{idpId}/feature_state'].get
$.paths['/sspm/identity/v1/idps/{idpId}/idp_accounts/count'].get
$.paths['/sspm/identity/v1/idps/{idpId}/idp_accounts/csv_report'].post
$.paths['/sspm/identity/v1/idps/{idpId}/mfa_activity'].get
$.paths['/sspm/identity/v1/idps/{idpId}/mfa_activity/count'].get
$.paths['/sspm/identity/v1/idps/{idpId}/mfa_activity/count_by_app_type'].get
$.paths['/sspm/identity/v1/idps/{idpId}/mfa_activity/csv_report'].post
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Incident Security Service Posture Management IDP API
version: 1.0.0
extends: openapi/palo-alto-networks-idp-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 11
- target: $.paths['/sspm/identity/v1/idps'].get
update:
x-apievangelist-phrasing:
intent: List the tenant's identity providers
effect: read
questions:
- Which identity providers are connected to my SaaS security posture tenant?
- Can I see only the designated identity providers?
instructions:
- text: List all identity providers configured for tenant {x-ps-tenant}.
slots:
x-ps-tenant: header.x-ps-tenant
- text: Show only identity providers where designated is {designated}.
slots:
designated: query.designated
method: generated
generated: '2026-09-26'
- target: $.paths['/sspm/identity/v1/idps'].post
update:
x-apievangelist-phrasing:
intent: Register a new identity provider
effect: write
questions:
- How do I add an identity provider to my SSPM tenant?
- Can a new identity provider be marked as designated when I add it?
instructions:
- text: Add identity provider {idpId} of type {idpType}.
slots:
idpId: query.idpId
idpType: query.idpType
- text: Register a {idpType} identity provider and mark it designated={designated}.
slots:
idpType: query.idpType
designated: query.designated
method: generated
generated: '2026-09-26'
- target: $.paths['/sspm/identity/v1/idps/{idpId}/accounts/logout'].get
update:
x-apievangelist-phrasing:
intent: Check the status of a forced account logout
effect: read
questions:
- Did the forced logout of accounts on my identity provider finish?
- What is the outcome of a specific logout batch I triggered earlier?
instructions:
- text: Check logout status for identity provider {idpId}, batch {batch_id}.
slots:
idpId: path.idpId
batch_id: query.batch_id
- text: Show the result of the account logout run on identity provider {idpId}.
slots:
idpId: path.idpId
method: generated
generated: '2026-09-26'
- target: $.paths['/sspm/identity/v1/idps/{idpId}/accounts/logout'].post
update:
x-apievangelist-phrasing:
intent: Force-log out users from an identity provider
effect: destructive
questions:
- How can I terminate sessions for compromised users in my identity provider?
- Can I sign out a specific list of users from one identity provider at once?
instructions:
- text: Log out users {users} from identity provider {idpId}.
slots:
users: requestBody.users
idpId: path.idpId
- text: Force session termination for the listed accounts on identity provider {idpId}.
slots:
idpId: path.idpId
method: generated
generated: '2026-09-26'
- target: $.paths['/sspm/identity/v1/idps/{idpId}/feature_state'].get
update:
x-apievangelist-phrasing:
intent: Check an identity provider feature's scan state
effect: read
questions:
- When was a feature on my identity provider last scanned, and is it healthy?
- What is the current state of a given feature for one identity provider?
instructions:
- text: Get the state and last scan time of feature {feature} on identity provider {idpId}.
slots:
feature: query.feature
idpId: path.idpId
- text: Show feature health for identity provider {idpId}.
slots:
idpId: path.idpId
method: generated
generated: '2026-09-26'
- target: $.paths['/sspm/identity/v1/idps/{idpId}/idp_accounts/count'].get
update:
x-apievangelist-phrasing:
intent: Count accounts on an identity provider
effect: read
questions:
- How many user accounts are linked to my identity provider?
- Can I count just the orphaned or privileged accounts in an identity provider?
instructions:
- text: Count the accounts on identity provider {idpId}.
slots:
idpId: path.idpId
- text: Count accounts on identity provider {idpId} matching filter {filter}.
slots:
idpId: path.idpId
filter: query.filter
method: generated
generated: '2026-09-26'
- target: $.paths['/sspm/identity/v1/idps/{idpId}/idp_accounts/csv_report'].post
update:
x-apievangelist-phrasing:
intent: Generate a CSV report of identity provider accounts
effect: write
questions:
- Can I export the user accounts in my identity provider to CSV for an access review?
- Who receives the identity provider account report once it is generated?
instructions:
- text: Generate an account CSV for identity provider {idpId} and send it to {userFullName} at {userEmail} for service {service}.
slots:
idpId: path.idpId
userFullName: requestBody.userFullName
userEmail: requestBody.userEmail
service: requestBody.service
- text: Build a CSV of accounts on identity provider {idpId} sorted by {sortBy}.
slots:
idpId: path.idpId
sortBy: query.sortBy
method: generated
generated: '2026-09-26'
- target: $.paths['/sspm/identity/v1/idps/{idpId}/mfa_activity'].get
update:
x-apievangelist-phrasing:
intent: View MFA activity logs for an identity provider
effect: read
questions:
- What multi-factor authentication events has my identity provider recorded, with user and IP?
- Can I page through MFA logs sorted by time?
instructions:
- text: Show MFA activity for identity provider {idpId}.
slots:
idpId: path.idpId
- text: List MFA events on identity provider {idpId} matching {filter}, page {page}.
slots:
idpId: path.idpId
filter: query.filter
page: query.page
method: generated
generated: '2026-09-26'
- target: $.paths['/sspm/identity/v1/idps/{idpId}/mfa_activity/count'].get
update:
x-apievangelist-phrasing:
intent: Count MFA events on an identity provider
effect: read
questions:
- How many multi-factor authentication events happened on my identity provider?
- What is the total MFA volume matching a filter?
instructions:
- text: Count MFA events for identity provider {idpId}.
slots:
idpId: path.idpId
- text: Give me the number of MFA events on identity provider {idpId} that match {filter}.
slots:
idpId: path.idpId
filter: query.filter
method: generated
generated: '2026-09-26'
- target: $.paths['/sspm/identity/v1/idps/{idpId}/mfa_activity/count_by_app_type'].get
update:
x-apievangelist-phrasing:
intent: Break down MFA activity by application type
effect: read
questions:
- Which application types generate the most MFA prompts on my identity provider?
- Is there a per-app-type breakdown of multi-factor authentication activity?
instructions:
- text: Break down MFA activity by app type for identity provider {idpId}.
slots:
idpId: path.idpId
- text: Group MFA counts by application type on identity provider {idpId} using filter {filter}.
slots:
idpId: path.idpId
filter: query.filter
method: generated
generated: '2026-09-26'
- target: $.paths['/sspm/identity/v1/idps/{idpId}/mfa_activity/csv_report'].post
update:
x-apievangelist-phrasing:
intent: Generate a CSV report of MFA activity
effect: write
questions:
- Can I export multi-factor authentication activity to a CSV for auditors?
- What details do I have to supply to request an MFA activity report?
instructions:
- text: Generate an MFA activity CSV for identity provider {idpId}, addressed to {userFullName} at {userEmail} for service {service}.
slots:
idpId: path.idpId
userFullName: requestBody.userFullName
userEmail: requestBody.userEmail
service: requestBody.service
- text: Export MFA events on identity provider {idpId} matching {filter} to CSV.
slots:
idpId: path.idpId
filter: query.filter
method: generated
generated: '2026-09-26'