Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Network Deployment Service Connections API
13 actions
13 updates
phrasing
extends
openapi/palo-alto-networks-service-connections-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 13
$.info
$.paths['/service-connections'].get
$.paths['/service-connections'].post
$.paths['/service-connections/{id}'].get
$.paths['/service-connections/{id}'].put
$.paths['/service-connections/{id}'].delete
$.paths['/sse/config/v1/bgp-routing'].get
$.paths['/sse/config/v1/bgp-routing'].put
$.paths['/sse/config/v1/service-connections'].get
$.paths['/sse/config/v1/service-connections'].post
$.paths['/sse/config/v1/service-connections/{id}'].get
$.paths['/sse/config/v1/service-connections/{id}'].put
$.paths['/sse/config/v1/service-connections/{id}'].delete
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Network Deployment Service Connections API
version: 1.0.0
extends: openapi/palo-alto-networks-service-connections-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-10-01'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 12
- target: $.paths['/service-connections'].get
update:
x-apievangelist-phrasing:
intent: List service connections
effect: read
questions:
- Which Prisma Access service connections are set up?
- Can I find a service connection by name?
instructions:
- text: List the service connections in folder {folder}.
slots:
folder: query.folder
- text: Find service connection {name} in folder {folder}.
slots:
name: query.name
folder: query.folder
method: generated
generated: '2026-09-26'
- target: $.paths['/service-connections'].post
update:
x-apievangelist-phrasing:
intent: Stage a new service connection
effect: write
questions:
- Is a new service connection live right away, or does it need a push?
- Can I attach a NAT pool and QoS settings when I stage a service connection in the candidate config?
instructions:
- text: Stage service connection {name} in region {region} with IPSec tunnel {ipsec_tunnel}.
slots:
name: requestBody.name
region: requestBody.region
ipsec_tunnel: requestBody.ipsec_tunnel
- text: Add a candidate service connection {name} in {region} over tunnel {ipsec_tunnel} with NAT pool {nat_pool} and QoS {qos}.
slots:
name: requestBody.name
region: requestBody.region
ipsec_tunnel: requestBody.ipsec_tunnel
nat_pool: requestBody.nat_pool
qos: requestBody.qos
method: generated
generated: '2026-10-01'
- target: $.paths['/service-connections/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get a service connection
effect: read
questions:
- What tunnel and region does a given service connection use?
- Can I fetch one service connection by ID?
instructions:
- text: Get service connection {id}.
slots:
id: path.id
- text: Show the tunnel and BGP settings of service connection {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/service-connections/{id}'].put
update:
x-apievangelist-phrasing:
intent: Update a service connection in the candidate config
effect: write
questions:
- Can I enable QoS on a service connection that already exists?
- Do edits to a service connection apply before I push the candidate configuration?
instructions:
- text: Update the QoS settings of existing service connection {id} to {qos}.
slots:
id: path.id
qos: requestBody.qos
- text: Change service connection {id} to region {region} in the candidate config.
slots:
id: path.id
region: requestBody.region
method: generated
generated: '2026-10-01'
- target: $.paths['/service-connections/{id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a service connection
effect: destructive
questions:
- How do I remove a service connection?
- Is deleting a service connection permanent?
instructions:
- text: Delete service connection {id}.
slots:
id: path.id
- text: Remove the service connection {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/bgp-routing'].get
update:
x-apievangelist-phrasing:
intent: View Prisma Access BGP routing settings
effect: read
questions:
- What BGP routing preference is set for my Prisma Access service connections?
- Can I check whether backbone routing is enabled in a folder?
instructions:
- text: Show the BGP routing settings for folder {folder} at position {position}.
slots:
folder: query.folder
position: query.position
- text: Retrieve BGP routing named {name} in folder {folder} at position {position}.
slots:
name: query.name
folder: query.folder
position: query.position
method: generated
generated: '2026-10-01'
- target: $.paths['/sse/config/v1/bgp-routing'].put
update:
x-apievangelist-phrasing:
intent: Change Prisma Access BGP routing settings
effect: write
questions:
- How do I switch the routing preference between default and hot-potato?
- Can I stop Prisma Access from withdrawing static routes?
instructions:
- text: Set the BGP routing preference to {routing_preference}.
slots:
routing_preference: requestBody.routing_preference
- text: Update BGP routing so accept route over service connection is {accept_route_over_SC}.
slots:
accept_route_over_SC: requestBody.accept_route_over_SC
method: generated
generated: '2026-10-01'
- target: $.paths['/sse/config/v1/service-connections'].get
update:
x-apievangelist-phrasing:
intent: List service connections in an SSE folder
effect: read
questions:
- Which service connections are configured in a given SSE config folder?
- Can I page through service connections with limit and offset on the sse/config/v1 path?
instructions:
- text: List service connections in SSE folder {folder}.
slots:
folder: query.folder
- text: Find the service connection named {name} in SSE folder {folder}.
slots:
name: query.name
folder: query.folder
method: generated
generated: '2026-10-01'
- target: $.paths['/sse/config/v1/service-connections'].post
update:
x-apievangelist-phrasing:
intent: Create a service connection (SSE config v1)
effect: write
questions:
- What does a new service connection need, like region and IPsec tunnel, on the SSE v1 API?
- Can I attach a BGP peer and backup service connection when creating one?
instructions:
- text: Create SSE service connection {name} in region {region} over IPsec tunnel {ipsec_tunnel} in folder {folder}.
slots:
name: requestBody.name
region: requestBody.region
ipsec_tunnel: requestBody.ipsec_tunnel
folder: query.folder
- text: Add SSE service connection {name} with subnets {subnets} and BGP peer {bgp_peer} in folder {folder}.
slots:
name: requestBody.name
subnets: requestBody.subnets
bgp_peer: requestBody.bgp_peer
folder: query.folder
method: generated
generated: '2026-10-01'
- target: $.paths['/sse/config/v1/service-connections/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get a service connection by ID (SSE config v1)
effect: read
questions:
- What IPsec tunnel and region does one SSE service connection use?
- Can I read one service connection's full config from the sse/config/v1 endpoint?
instructions:
- text: Show SSE service connection {id}.
slots:
id: path.id
- text: Get the sse/config/v1 details of service connection {id}.
slots:
id: path.id
method: generated
generated: '2026-10-01'
- target: $.paths['/sse/config/v1/service-connections/{id}'].put
update:
x-apievangelist-phrasing:
intent: Edit a service connection (SSE config v1)
effect: write
questions:
- Can I change the subnets behind an existing SSE service connection?
- How do I move a service connection to a secondary IPsec tunnel on the SSE v1 API?
instructions:
- text: Edit SSE service connection {id} to use subnets {subnets}.
slots:
id: path.id
subnets: requestBody.subnets
- text: Set secondary IPsec tunnel {secondary_ipsec_tunnel} on SSE service connection {id}.
slots:
secondary_ipsec_tunnel: requestBody.secondary_ipsec_tunnel
id: path.id
method: generated
generated: '2026-10-01'
- target: $.paths['/sse/config/v1/service-connections/{id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a service connection (SSE config v1)
effect: destructive
questions:
- How do I remove a service connection through the SSE config v1 API?
- Does deleting an SSE service connection cut access to the data center behind it?
instructions:
- text: Delete SSE service connection {id}.
slots:
id: path.id
- text: Remove service connection {id} using the sse/config/v1 path.
slots:
id: path.id
method: generated
generated: '2026-10-01'