Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Identity Services SCEP Profiles API
11 actions
11 updates
phrasing
extends
openapi/palo-alto-networks-scep-profiles-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 11
$.info
$.paths['/scep-profiles'].get
$.paths['/scep-profiles'].post
$.paths['/scep-profiles/{id}'].get
$.paths['/scep-profiles/{id}'].put
$.paths['/scep-profiles/{id}'].delete
$.paths['/sse/config/v1/scep-profiles'].get
$.paths['/sse/config/v1/scep-profiles'].post
$.paths['/sse/config/v1/scep-profiles/{id}'].get
$.paths['/sse/config/v1/scep-profiles/{id}'].put
$.paths['/sse/config/v1/scep-profiles/{id}'].delete
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Identity Services SCEP Profiles API
version: 1.0.0
extends: openapi/palo-alto-networks-scep-profiles-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-10-01'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 10
- target: $.paths['/scep-profiles'].get
update:
x-apievangelist-phrasing:
intent: List SCEP profiles
effect: read
questions:
- Which SCEP certificate enrollment profiles are configured?
- Can I find a SCEP profile by name in a folder?
instructions:
- text: List SCEP profiles in folder {folder}.
slots:
folder: query.folder
- text: Find the SCEP profile named {name}.
slots:
name: query.name
method: generated
generated: '2026-09-26'
- target: $.paths['/scep-profiles'].post
update:
x-apievangelist-phrasing:
intent: Create a SCEP profile
effect: write
questions:
- How do I set up SCEP so the firewall can enroll certificates from my CA?
- Can I choose the key algorithm and digest for a new SCEP profile?
instructions:
- text: Create SCEP profile {name} enrolling from {scep_url} with CA identity {ca_identity_name} and subject {subject}.
slots:
name: requestBody.name
scep_url: requestBody.scep_url
ca_identity_name: requestBody.ca_identity_name
subject: requestBody.subject
- text: Add SCEP profile {name} using key algorithm {algorithm}, digest {digest} and challenge {scep_challenge}.
slots:
name: requestBody.name
algorithm: requestBody.algorithm
digest: requestBody.digest
scep_challenge: requestBody.scep_challenge
method: generated
generated: '2026-09-26'
- target: $.paths['/scep-profiles/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get a SCEP profile
effect: read
questions:
- What SCEP server URL and CA identity does one profile use?
- Can I retrieve a SCEP profile by its id?
instructions:
- text: Show SCEP profile {id}.
slots:
id: path.id
- text: Get the enrollment settings of SCEP profile {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/scep-profiles/{id}'].put
update:
x-apievangelist-phrasing:
intent: Update a SCEP profile
effect: write
questions:
- How do I change the SCEP server URL on an existing profile?
- Can I rotate the challenge password of a SCEP profile already configured?
instructions:
- text: Rotate the challenge on existing SCEP profile {id} to {scep_challenge}.
slots:
id: path.id
scep_challenge: requestBody.scep_challenge
- text: Point existing SCEP profile {id} at new server URL {scep_url}.
slots:
id: path.id
scep_url: requestBody.scep_url
method: generated
generated: '2026-09-26'
- target: $.paths['/scep-profiles/{id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a SCEP profile
effect: destructive
questions:
- How do I remove a SCEP profile?
- Can I delete a SCEP enrollment profile I no longer use?
instructions:
- text: Delete SCEP profile {id}.
slots:
id: path.id
- text: Remove the SCEP enrollment profile {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/scep-profiles'].get
update:
x-apievangelist-phrasing:
intent: List SCEP profiles
effect: read
questions:
- Which SCEP profiles are set up for certificate enrollment?
- Can I list SCEP profiles in a single folder?
instructions:
- text: List SCEP profiles in folder {folder} through the SSE config v1 endpoint.
slots:
folder: query.folder
- text: Find SCEP profile {name} in {folder}.
slots:
name: query.name
folder: query.folder
method: generated
generated: '2026-10-01'
- target: $.paths['/sse/config/v1/scep-profiles'].post
update:
x-apievangelist-phrasing:
intent: Create a SCEP profile
effect: write
questions:
- How do I create a SCEP profile to enroll certificates from our CA?
- What CA identity and digest does a new SCEP profile need?
instructions:
- text: Create a {type} SCEP profile {name} for CA {ca_identity_name} with digest {digest}.
slots:
type: query.type
name: requestBody.name
ca_identity_name: requestBody.ca_identity_name
digest: requestBody.digest
- text: Add a {type} SCEP profile {name} for {ca_identity_name} using digest {digest} and challenge {scep_challenge}.
slots:
type: query.type
name: requestBody.name
ca_identity_name: requestBody.ca_identity_name
digest: requestBody.digest
scep_challenge: requestBody.scep_challenge
method: generated
generated: '2026-10-01'
- target: $.paths['/sse/config/v1/scep-profiles/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get a SCEP profile
effect: read
questions:
- What CA and challenge settings does one SCEP profile use?
- Can I fetch a SCEP profile by ID?
instructions:
- text: Get SCEP profile {id}.
slots:
id: path.id
- text: Show the CA settings of SCEP profile {id}.
slots:
id: path.id
method: generated
generated: '2026-10-01'
- target: $.paths['/sse/config/v1/scep-profiles/{id}'].put
update:
x-apievangelist-phrasing:
intent: Edit a SCEP profile
effect: write
questions:
- Can I change the digest algorithm on an existing SCEP profile?
- How do I update the SCEP challenge on a profile?
instructions:
- text: Edit SCEP profile {id} ({name}) to use CA {ca_identity_name} and digest {digest}.
slots:
id: path.id
name: requestBody.name
ca_identity_name: requestBody.ca_identity_name
digest: requestBody.digest
- text: Change the SCEP challenge on profile {id} ({name}, CA {ca_identity_name}, digest {digest}) to {scep_challenge}.
slots:
id: path.id
name: requestBody.name
ca_identity_name: requestBody.ca_identity_name
digest: requestBody.digest
scep_challenge: requestBody.scep_challenge
method: generated
generated: '2026-10-01'
- target: $.paths['/sse/config/v1/scep-profiles/{id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a SCEP profile
effect: destructive
questions:
- Can I remove a SCEP profile that's no longer used?
- What ID do I pass to delete a SCEP profile?
instructions:
- text: Delete SCEP profile {id} through the SSE config v1 endpoint.
slots:
id: path.id
- text: Remove SCEP profile {id}.
slots:
id: path.id
method: generated
generated: '2026-10-01'