Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Prisma Cloud Access Keys API Overview User Profile API
15 actions
15 updates
phrasing
extends
openapi/palo-alto-networks-user-profile-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 15
$.info
$.paths['/user/me'].get
$.paths['/user/me'].put
$.paths['/v3/user'].get
$.paths['/v3/user'].post
$.paths['/v2/user'].get
$.paths['/v2/user'].post
$.paths['/v2/user/{id}'].get
$.paths['/v2/user/{id}'].put
$.paths['/user/{id}'].delete
$.paths['/user/{id}/status/{enabled}'].patch
$.paths['/user/name'].get
$.paths['/user/domain'].get
$.paths['/user/saml/bypass'].get
$.paths['/user/saml/bypass'].put
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Prisma Cloud Access Keys API Overview User Profile API
version: 1.0.0
extends: openapi/palo-alto-networks-user-profile-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 14
- target: $.paths['/user/me'].get
update:
x-apievangelist-phrasing:
intent: View my own user profile
effect: read
questions:
- What does my own Prisma Cloud profile say about me, like my roles and time zone?
- Where can I check the personal details on the account I'm signed in with?
instructions:
- text: Show me my own user profile.
- text: Look up the profile of the account I'm logged in as.
method: generated
generated: '2026-09-26'
- target: $.paths['/user/me'].put
update:
x-apievangelist-phrasing:
intent: Update my own user profile
effect: write
questions:
- Can I change my own name or time zone without an admin?
- How do I switch my default role on my own profile?
instructions:
- text: Change my own profile's time zone to {timeZone}.
slots:
timeZone: requestBody.timeZone
- text: Update my name on my profile to {firstName} {lastName}.
slots:
firstName: requestBody.firstName
lastName: requestBody.lastName
- text: Set my own default role to {defaultRoleId}.
slots:
defaultRoleId: requestBody.defaultRoleId
method: generated
generated: '2026-09-26'
- target: $.paths['/v3/user'].get
update:
x-apievangelist-phrasing:
intent: List users and service accounts
effect: read
questions:
- Which users and service accounts exist in my tenant?
- Can I see service accounts alongside human users in one list?
instructions:
- text: List every user and service account in my tenant.
- text: Show all service accounts and users using the v3 user list.
method: generated
generated: '2026-09-26'
- target: $.paths['/v3/user'].post
update:
x-apievangelist-phrasing:
intent: Add a user or service account
effect: write
questions:
- How do I create a service account for automation instead of a person?
- Can I give a new account an access key expiration when I add it?
instructions:
- text: Add a service account named {username} with role {defaultRoleId}.
slots:
username: requestBody.username
defaultRoleId: requestBody.defaultRoleId
- text: Create a user account of type {type} for {email}.
slots:
type: requestBody.type
email: requestBody.email
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/user'].get
update:
x-apievangelist-phrasing:
intent: List users with their roles (v2)
effect: read
questions:
- Which users belong to my tenant and what roles does each hold?
- Is there an older list of users that shows multiple roles per person?
instructions:
- text: List all tenant users with their assigned roles using the v2 endpoint.
- text: Show every user and their multiple roles from the v2 user list.
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/user'].post
update:
x-apievangelist-phrasing:
intent: Add an administrative user (v2)
effect: write
questions:
- How do I add a new admin who needs more than one role?
- What's required to create an administrative user through the v2 endpoint?
instructions:
- text: Add admin {email} named {firstName} {lastName} with roles {roleIds} via v2.
slots:
email: requestBody.email
firstName: requestBody.firstName
lastName: requestBody.lastName
roleIds: requestBody.roleIds
- text: Create a v2 administrative user {email} in time zone {timeZone}.
slots:
email: requestBody.email
timeZone: requestBody.timeZone
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/user/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get a user's profile by email
effect: read
questions:
- What roles and settings does a specific user have?
- Can I look up one admin's profile by their email?
instructions:
- text: Get the user profile for {email}.
slots:
email: path.id
- text: Show the roles assigned to user {email}.
slots:
email: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/user/{id}'].put
update:
x-apievangelist-phrasing:
intent: Update another user's profile (v2)
effect: write
questions:
- Can I change another admin's roles or time zone?
- How do I rename a user in the tenant?
instructions:
- text: Update user {email}'s roles to {roleIds}.
slots:
email: path.id
roleIds: requestBody.roleIds
- text: Change the time zone of user {email} to {timeZone}.
slots:
email: path.id
timeZone: requestBody.timeZone
method: generated
generated: '2026-09-26'
- target: $.paths['/user/{id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a user or service account
effect: destructive
questions:
- How do I permanently remove someone's account from the tenant?
- Can I delete a service account I no longer use?
instructions:
- text: Delete user profile {id}.
slots:
id: path.id
- text: Remove the service account {id} from my tenant.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/user/{id}/status/{enabled}'].patch
update:
x-apievangelist-phrasing:
intent: Enable or disable a user
effect: write
questions:
- Can I lock a user out temporarily without deleting them?
- How do I re-enable an account that was disabled?
instructions:
- text: Disable user {id} by setting status {enabled}.
slots:
id: path.id
enabled: path.enabled
- text: Set the enabled status of user {id} to {enabled}.
slots:
id: path.id
enabled: path.enabled
method: generated
generated: '2026-09-26'
- target: $.paths['/user/name'].get
update:
x-apievangelist-phrasing:
intent: List all user emails
effect: read
questions:
- What email addresses do my active users sign in with?
- Is there a quick list of just the emails of non-deleted users?
instructions:
- text: List the emails of all active users.
- text: Give me every user email in the system.
method: generated
generated: '2026-09-26'
- target: $.paths['/user/domain'].get
update:
x-apievangelist-phrasing:
intent: List allowed email domains
effect: read
questions:
- Which email domains are on the allow list for new users?
- What domains can user accounts be created under?
instructions:
- text: List the allow-listed email domains.
- text: Show which email domains my tenant permits.
method: generated
generated: '2026-09-26'
- target: $.paths['/user/saml/bypass'].get
update:
x-apievangelist-phrasing:
intent: List users allowed to bypass SSO
effect: read
questions:
- Who can still sign in with a password even though SSO is on?
- Which users are allowed to log in through both SAML and username and password?
instructions:
- text: List the users who can bypass SSO.
- text: Show me the SSO bypass allow list.
method: generated
generated: '2026-09-26'
- target: $.paths['/user/saml/bypass'].put
update:
x-apievangelist-phrasing:
intent: Set which users can bypass SSO
effect: write
questions:
- How do I let a break-glass admin log in with a password when SAML is enforced?
- Can I change the list of people allowed to skip single sign-on?
instructions:
- text: Replace the SSO bypass list so the given emails can log in with SAML or a password.
- text: Update the users allowed to bypass single sign-on.
method: generated
generated: '2026-09-26'