Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Palo Alto Networks SASE IAM Service Service Accounts API
14 actions
14 updates
phrasing
extends
openapi/palo-alto-networks-service-accounts-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 14
$.info
$.paths['/service-accounts'].get
$.paths['/service-accounts'].post
$.paths['/service-accounts/{id}'].get
$.paths['/service-accounts/{id}'].put
$.paths['/service-accounts/{id}'].delete
$.paths['/service-accounts/{id}/keys'].post
$.paths['/service-accounts/{id}/keys/{key_id}'].delete
$.paths['/iam/v1/service_accounts'].get
$.paths['/iam/v1/service_accounts'].post
$.paths['/iam/v1/service_accounts/{id}'].get
$.paths['/iam/v1/service_accounts/{id}'].put
$.paths['/iam/v1/service_accounts/{id}'].delete
$.paths['/iam/v1/service_accounts/{id}/operations/reset'].post
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Palo Alto Networks SASE IAM Service Service Accounts API
version: 1.0.0
extends: openapi/palo-alto-networks-service-accounts-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-10-01'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 13
- target: $.paths['/service-accounts'].get
update:
x-apievangelist-phrasing:
intent: List service accounts
effect: read
questions:
- Which service accounts exist for API automation in my tenant?
- Can I list service accounts for one Tenant Service Group only?
instructions:
- text: List all service accounts.
- text: List service accounts in TSG {tsg_id}.
slots:
tsg_id: query.tsg_id
method: generated
generated: '2026-09-26'
- target: $.paths['/service-accounts'].post
update:
x-apievangelist-phrasing:
intent: Create a service account
effect: write
questions:
- How do I create a machine identity for API automation?
- Which Tenant Service Group does a new service account have to belong to?
instructions:
- text: Create service account {name} in TSG {tsg_id}.
slots:
name: requestBody.name
tsg_id: requestBody.tsg_id
- text: Add service account {name} to TSG {tsg_id} described as {description}.
slots:
name: requestBody.name
tsg_id: requestBody.tsg_id
description: requestBody.description
method: generated
generated: '2026-09-26'
- target: $.paths['/service-accounts/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get a service account
effect: read
questions:
- What are the full details of one service account?
- Can I look up a service account by its ID?
instructions:
- text: Get service account {id}.
slots:
id: path.id
- text: Show details of service account {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/service-accounts/{id}'].put
update:
x-apievangelist-phrasing:
intent: Rename or re-describe a service account
effect: write
questions:
- Can I change a service account's display name?
- Is it possible to update the description of an existing service account?
instructions:
- text: Set the display name of service account {id} to {display_name}.
slots:
id: path.id
display_name: requestBody.display_name
- text: Update the description of service account {id} to {description}.
slots:
id: path.id
description: requestBody.description
method: generated
generated: '2026-09-26'
- target: $.paths['/service-accounts/{id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a service account
effect: destructive
questions:
- What happens to active API sessions when I delete a service account?
- How do I remove a service account and all its credentials?
instructions:
- text: Delete service account {id}.
slots:
id: path.id
- text: Remove service account {id} and revoke all its credentials.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/service-accounts/{id}/keys'].post
update:
x-apievangelist-phrasing:
intent: Generate client credentials for a service account
effect: write
questions:
- How do I get a client ID and secret for a service account?
- Can I make service account credentials expire after a set number of days?
instructions:
- text: Generate new credentials for service account {id}.
slots:
id: path.id
- text: Create a client secret for service account {id} that expires in {expires_in_days} days.
slots:
id: path.id
expires_in_days: requestBody.expires_in_days
method: generated
generated: '2026-09-26'
- target: $.paths['/service-accounts/{id}/keys/{key_id}'].delete
update:
x-apievangelist-phrasing:
intent: Revoke a service account key
effect: destructive
questions:
- Can I revoke one leaked key without deleting the whole service account?
- What happens to sessions using a key I revoke?
instructions:
- text: Revoke key {key_id} on service account {id}.
slots:
key_id: path.key_id
id: path.id
- text: Invalidate credential {key_id} for service account {id}.
slots:
key_id: path.key_id
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/iam/v1/service_accounts'].get
update:
x-apievangelist-phrasing:
intent: List service accounts
effect: read
questions:
- Which service accounts exist in my Prisma SASE tenant?
- Can I see every IAM service account at once?
instructions:
- text: List every service account through the IAM v1 endpoint.
- text: Show me every IAM service account in the tenant.
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/v1/service_accounts'].post
update:
x-apievangelist-phrasing:
intent: Create a service account
effect: write
questions:
- How do I create a service account for an automation script?
- Can I set a contact email on a new service account?
instructions:
- text: Create a service account named {name} with contact email {contact_email}.
slots:
name: requestBody.name
contact_email: requestBody.contact_email
- text: Add service account {name} described as {description}.
slots:
name: requestBody.name
description: requestBody.description
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/v1/service_accounts/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get a service account
effect: read
questions:
- What are the details of one particular service account?
- Can I read one service account through the IAM v1 API?
instructions:
- text: Fetch IAM v1 service account {id}.
slots:
id: path.id
- text: Show the details of service account {id}.
slots:
id: path.id
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/v1/service_accounts/{id}'].put
update:
x-apievangelist-phrasing:
intent: Update a service account
effect: write
questions:
- Can I change the contact email on an existing service account?
- What fields of a service account can I edit?
instructions:
- text: Set the contact email of service account {id} to {contact_email}.
slots:
id: path.id
contact_email: requestBody.contact_email
- text: Change the IAM v1 description of service account {id} to {description}.
slots:
id: path.id
description: requestBody.description
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/v1/service_accounts/{id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a service account
effect: destructive
questions:
- How do I remove a service account that's no longer needed?
- Can I delete a service account by ID?
instructions:
- text: Delete IAM v1 service account {id}.
slots:
id: path.id
- text: Remove service account {id} from the tenant.
slots:
id: path.id
method: generated
generated: '2026-10-01'
- target: $.paths['/iam/v1/service_accounts/{id}/operations/reset'].post
update:
x-apievangelist-phrasing:
intent: Reset a service account
effect: destructive
questions:
- What does resetting a service account do?
- Can I reset a compromised service account?
instructions:
- text: Reset service account {id}.
slots:
id: path.id
- text: Run the reset operation on service account {id}.
slots:
id: path.id
method: generated
generated: '2026-10-01'