Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Palo Alto Networks Mobile Agent API
27 actions
27 updates
phrasing
extends
openapi/palo-alto-networks-mobileagent-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 27 · first 16 shown; the file carries all of them
$.info
$.paths['/sse/config/v1/mobile-agent/agent-profiles'].get
$.paths['/sse/config/v1/mobile-agent/agent-profiles'].put
$.paths['/sse/config/v1/mobile-agent/agent-profiles'].post
$.paths['/sse/config/v1/mobile-agent/agent-profiles'].delete
$.paths['/sse/config/v1/mobile-agent/agent-versions'].get
$.paths['/sse/config/v1/mobile-agent/authentication-settings'].get
$.paths['/sse/config/v1/mobile-agent/authentication-settings'].put
$.paths['/sse/config/v1/mobile-agent/authentication-settings'].post
$.paths['/sse/config/v1/mobile-agent/authentication-settings'].delete
$.paths['/sse/config/v1/mobile-agent/enable'].get
$.paths['/sse/config/v1/mobile-agent/enable'].post
$.paths['/sse/config/v1/mobile-agent/global-settings'].get
$.paths['/sse/config/v1/mobile-agent/global-settings'].put
$.paths['/sse/config/v1/mobile-agent/infrastructure-settings'].get
$.paths['/sse/config/v1/mobile-agent/infrastructure-settings'].put
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Palo Alto Networks Mobile Agent API
version: 1.0.0
extends: openapi/palo-alto-networks-mobileagent-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 26
- target: $.paths['/sse/config/v1/mobile-agent/agent-profiles'].get
update:
x-apievangelist-phrasing:
intent: List GlobalProtect agent profiles
effect: read
questions:
- Which GlobalProtect agent profiles are configured for my mobile users?
- Can I page through the GlobalProtect app profiles in one Prisma Access folder?
instructions:
- text: List the GlobalProtect agent profiles in folder {folder}.
slots:
folder: query.folder
- text: Show the first {limit} GlobalProtect agent profiles in {folder}.
slots:
limit: query.limit
folder: query.folder
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/agent-profiles'].put
update:
x-apievangelist-phrasing:
intent: Change a GlobalProtect agent profile
effect: write
questions:
- Can I change the gateways an existing GlobalProtect agent profile connects to?
- How do I turn on HIP collection in a GlobalProtect agent profile I already have?
instructions:
- text: Update GlobalProtect agent profile {name} in folder {folder} to use gateways {gateways}.
slots:
name: query.name
folder: query.folder
gateways: requestBody.gateways
- text: Change the operating systems targeted by agent profile {name} in {folder} to {os}.
slots:
name: query.name
folder: query.folder
os: requestBody.os
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/agent-profiles'].post
update:
x-apievangelist-phrasing:
intent: Create a GlobalProtect agent profile
effect: write
questions:
- How do I create a new GlobalProtect agent profile for a group of mobile users?
- Can a new GlobalProtect app profile apply only to certain operating systems?
instructions:
- text: Create a GlobalProtect agent profile named {name} in folder {folder}.
slots:
name: requestBody.name
folder: query.folder
- text: Add a new agent profile {name} in {folder} for users {source_user}.
slots:
name: requestBody.name
folder: query.folder
source_user: requestBody.source_user
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/agent-profiles'].delete
update:
x-apievangelist-phrasing:
intent: Delete a GlobalProtect agent profile
effect: destructive
questions:
- Can I remove a GlobalProtect agent profile my mobile users no longer need?
- What do I need to specify to delete a GlobalProtect app profile?
instructions:
- text: Delete GlobalProtect agent profile {name} from folder {folder}.
slots:
name: query.name
folder: query.folder
- text: Remove the {name} GlobalProtect app profile in {folder}.
slots:
name: query.name
folder: query.folder
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/agent-versions'].get
update:
x-apievangelist-phrasing:
intent: List available GlobalProtect agent versions
effect: read
questions:
- Which GlobalProtect app versions can I deploy to my mobile users?
- What agent versions does Prisma Access currently offer for GlobalProtect?
instructions:
- text: List the GlobalProtect agent versions that are available.
- text: Show me which GlobalProtect client versions I can choose from.
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/authentication-settings'].get
update:
x-apievangelist-phrasing:
intent: List GlobalProtect authentication settings
effect: read
questions:
- What authentication settings are configured for GlobalProtect users?
- Which authentication profile does GlobalProtect use for each operating system?
instructions:
- text: List the GlobalProtect authentication settings in folder {folder}.
slots:
folder: query.folder
- text: Show {limit} GlobalProtect authentication settings from {folder}.
slots:
limit: query.limit
folder: query.folder
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/authentication-settings'].put
update:
x-apievangelist-phrasing:
intent: Edit a GlobalProtect authentication setting
effect: write
questions:
- Can I switch the authentication profile on an existing GlobalProtect authentication setting?
- How do I require a client certificate or user credential on an authentication setting I already have?
instructions:
- text: Edit GlobalProtect authentication setting {name} in {folder} to use authentication profile {authentication_profile}.
slots:
name: query.name
folder: query.folder
authentication_profile: requestBody.authentication_profile
- text: Change the OS for authentication setting {name} in {folder} to {os}.
slots:
name: query.name
folder: query.folder
os: requestBody.os
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/authentication-settings'].post
update:
x-apievangelist-phrasing:
intent: Create a GlobalProtect authentication setting
effect: write
questions:
- How do I add a new authentication setting for GlobalProtect users on a specific OS?
- Can a new GlobalProtect authentication setting require both credentials and a client certificate?
instructions:
- text: Create a GlobalProtect authentication setting in {folder} for {os} using profile {authentication_profile}.
slots:
folder: query.folder
os: requestBody.os
authentication_profile: requestBody.authentication_profile
- text: Add an authentication setting in {folder} for {os} with credential-or-cert requirement {user_credential_or_client_cert_required}.
slots:
folder: query.folder
os: requestBody.os
user_credential_or_client_cert_required: requestBody.user_credential_or_client_cert_required
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/authentication-settings'].delete
update:
x-apievangelist-phrasing:
intent: Delete a GlobalProtect authentication setting
effect: destructive
questions:
- Can I remove a GlobalProtect authentication setting I no longer use?
- What happens if I delete a GlobalProtect authentication setting from a folder?
instructions:
- text: Delete GlobalProtect authentication setting {name} from folder {folder}.
slots:
name: query.name
folder: query.folder
- text: Remove the {name} GlobalProtect auth setting in {folder}.
slots:
name: query.name
folder: query.folder
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/enable'].get
update:
x-apievangelist-phrasing:
intent: Check whether GlobalProtect is enabled
effect: read
questions:
- Is the mobile agent (GlobalProtect) turned on for my Prisma Access configuration?
- How can I tell if mobile users are enabled in my tenant?
instructions:
- text: Check whether the GlobalProtect mobile agent is enabled.
- text: Tell me if mobile agent support is switched on for my configuration.
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/enable'].post
update:
x-apievangelist-phrasing:
intent: Enable the GlobalProtect mobile agent
effect: write
questions:
- How do I turn on GlobalProtect for mobile users in Prisma Access?
- What call switches the mobile agent on for my configuration?
instructions:
- text: Enable the GlobalProtect mobile agent for my configuration.
- text: Turn on mobile user support with GlobalProtect.
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/global-settings'].get
update:
x-apievangelist-phrasing:
intent: Show GlobalProtect global settings
effect: read
questions:
- Which agent version and manual gateway are set in my GlobalProtect global settings?
- Where can I see the tenant-wide GlobalProtect settings?
instructions:
- text: Show the global settings configured for GlobalProtect.
- text: Get the current GlobalProtect global agent version setting.
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/global-settings'].put
update:
x-apievangelist-phrasing:
intent: Edit GlobalProtect global settings
effect: write
questions:
- Can I pin all mobile users to a specific GlobalProtect agent version?
- How do I set a manual gateway in the GlobalProtect global settings?
instructions:
- text: Set the GlobalProtect global agent version to {agent_version}.
slots:
agent_version: requestBody.agent_version
- text: Update the GlobalProtect global manual gateway to {manual_gateway}.
slots:
manual_gateway: requestBody.manual_gateway
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/infrastructure-settings'].get
update:
x-apievangelist-phrasing:
intent: Show GlobalProtect infrastructure settings
effect: read
questions:
- What portal hostname, DNS servers and IP pools are set for GlobalProtect in a folder?
- Where do I see the SSE infrastructure settings for mobile users in one folder?
instructions:
- text: Show the GlobalProtect infrastructure settings in folder {folder}.
slots:
folder: query.folder
- text: List the SSE mobile agent portal and IP pool settings for {folder}.
slots:
folder: query.folder
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/infrastructure-settings'].put
update:
x-apievangelist-phrasing:
intent: Edit GlobalProtect infrastructure settings
effect: write
questions:
- Can I change the DNS servers on my existing GlobalProtect infrastructure settings?
- How do I update the portal hostname for GlobalProtect mobile users?
instructions:
- text: Edit infrastructure settings {name} in {folder} to use portal hostname {portal_hostname}.
slots:
name: requestBody.name
folder: query.folder
portal_hostname: requestBody.portal_hostname
- text: Replace the IP pools in GlobalProtect infrastructure settings {name} in {folder} with {ip_pools}.
slots:
name: requestBody.name
folder: query.folder
ip_pools: requestBody.ip_pools
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/infrastructure-settings'].post
update:
x-apievangelist-phrasing:
intent: Create GlobalProtect infrastructure settings
effect: write
questions:
- What do I need to create GlobalProtect infrastructure settings through the SSE config API?
- Can I enable IPv6 or WINS when setting up GlobalProtect infrastructure for the first time?
instructions:
- text: Create GlobalProtect infrastructure settings {name} in {folder} with portal {portal_hostname}, DNS {dns_servers} and IP pools {ip_pools}.
slots:
name: requestBody.name
folder: query.folder
portal_hostname: requestBody.portal_hostname
dns_servers: requestBody.dns_servers
ip_pools: requestBody.ip_pools
- text: Set up new SSE mobile infrastructure settings {name} in folder {folder}.
slots:
name: requestBody.name
folder: query.folder
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/infrastructure-settings'].delete
update:
x-apievangelist-phrasing:
intent: Delete GlobalProtect infrastructure settings
effect: destructive
questions:
- Can I remove a set of GlobalProtect infrastructure settings from a folder?
- What identifies the infrastructure settings I want to delete?
instructions:
- text: Delete GlobalProtect infrastructure settings {name} from folder {folder}.
slots:
name: query.name
folder: query.folder
- text: Remove the SSE mobile infrastructure settings called {name} in {folder}.
slots:
name: query.name
folder: query.folder
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/locations'].get
update:
x-apievangelist-phrasing:
intent: List Prisma Access locations for GlobalProtect
effect: read
questions:
- Which Prisma Access locations are my GlobalProtect users able to connect to?
- What regions are configured for mobile users in a folder?
instructions:
- text: List the Prisma Access locations configured for GlobalProtect in {folder}.
slots:
folder: query.folder
- text: Show which mobile user regions are set in folder {folder}.
slots:
folder: query.folder
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/locations'].put
update:
x-apievangelist-phrasing:
intent: Edit Prisma Access locations for GlobalProtect
effect: write
questions:
- How do I add or remove Prisma Access locations for my mobile users?
- Can I change which regions GlobalProtect users connect through?
instructions:
- text: Set the GlobalProtect Prisma Access locations in {folder} to region {region}.
slots:
folder: query.folder
region: requestBody.region
- text: Update the mobile user locations in folder {folder}.
slots:
folder: query.folder
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/tunnel-profiles'].get
update:
x-apievangelist-phrasing:
intent: List GlobalProtect tunnel profiles
effect: read
questions:
- Which GlobalProtect tunnel profiles are defined for my mobile users?
- Can I see the split tunneling setup across my tunnel profiles?
instructions:
- text: List the GlobalProtect tunnel profiles in folder {folder}.
slots:
folder: query.folder
- text: Show {limit} tunnel profiles from {folder} starting at offset {offset}.
slots:
limit: query.limit
folder: query.folder
offset: query.offset
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/tunnel-profiles'].put
update:
x-apievangelist-phrasing:
intent: Update a GlobalProtect tunnel profile
effect: write
questions:
- How do I change split tunneling on an existing GlobalProtect tunnel profile?
- Can I block direct access to the local network in a tunnel profile I already have?
instructions:
- text: Update tunnel profile {name} in {folder} with split tunneling {split_tunneling}.
slots:
name: query.name
folder: query.folder
split_tunneling: requestBody.split_tunneling
- text: Turn off direct local network access on tunnel profile {name} in {folder}.
slots:
name: query.name
folder: query.folder
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/tunnel-profiles'].post
update:
x-apievangelist-phrasing:
intent: Create a GlobalProtect tunnel profile
effect: write
questions:
- How do I create a new GlobalProtect tunnel profile with split tunneling?
- Can a new tunnel profile apply only to certain source users or addresses?
instructions:
- text: Create a GlobalProtect tunnel profile named {name} in folder {folder}.
slots:
name: requestBody.name
folder: query.folder
- text: Add tunnel profile {name} in {folder} for source addresses {source_address}.
slots:
name: requestBody.name
folder: query.folder
source_address: requestBody.source_address
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/tunnel-profiles'].delete
update:
x-apievangelist-phrasing:
intent: Delete a GlobalProtect tunnel profile
effect: destructive
questions:
- Can I remove a GlobalProtect tunnel profile that nobody uses anymore?
- What do I pass to delete a tunnel profile from a folder?
instructions:
- text: Delete GlobalProtect tunnel profile {name} from folder {folder}.
slots:
name: query.name
folder: query.folder
- text: Remove the {name} tunnel profile from {folder}.
slots:
name: query.name
folder: query.folder
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/mobile-agent/user-authentication:move'].post
update:
x-apievangelist-phrasing:
intent: Reorder GlobalProtect authentication settings
effect: write
questions:
- How do I change the evaluation order of my GlobalProtect authentication settings?
- Can I move one authentication setting before another?
instructions:
- text: Move authentication setting {name} in {folder} to {where} {destination}.
slots:
name: query.name
folder: query.folder
where: requestBody.where
destination: requestBody.destination
- text: Put authentication setting {name} in folder {folder} at the top of the list.
slots:
name: query.name
folder: query.folder
method: generated
generated: '2026-09-26'
- target: $.paths['/mobile-agent/infrastructure-settings'].get
update:
x-apievangelist-phrasing:
intent: Get mobile agent infrastructure settings (candidate)
effect: read
questions:
- Where can I read the mobile user infrastructure settings that define Prisma Access regions and DNS suffix?
- What IP pool and DNS suffix does the mobile agent candidate configuration use?
instructions:
- text: Get the mobile agent infrastructure settings, including DNS suffix and regions, for folder {folder}.
slots:
folder: query.folder
- text: Show the candidate mobile user infrastructure settings.
method: generated
generated: '2026-09-26'
- target: $.paths['/mobile-agent/infrastructure-settings'].post
update:
x-apievangelist-phrasing:
intent: Stage mobile agent infrastructure in candidate config
effect: write
questions:
- Can I set the DNS suffix and regions for mobile users in the candidate configuration?
- Do mobile infrastructure changes take effect before I push the configuration?
instructions:
- text: Write mobile agent infrastructure settings {name} to the candidate config with IP pool {ip_pool} and DNS suffix {dns_suffix}.
slots:
name: requestBody.name
ip_pool: requestBody.ip_pool
dns_suffix: requestBody.dns_suffix
- text: Stage mobile user regions {regions} in the candidate infrastructure settings.
slots:
regions: requestBody.regions
method: generated
generated: '2026-09-26'