Snyk · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Snyk Oauth2 API

4 actions 4 updates phrasing extends openapi/snyk-oauth2-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Snyk's API. It is a proposal applied on top of the contract, not a document Snyk publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 4

$.info
$.paths['/oauth2/authorize'].get
$.paths['/token'].post
$.paths['/revoke'].post

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Snyk Oauth2 API
  version: 1.0.0
extends: openapi/snyk-oauth2-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-10-01'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 3
- target: $.paths['/oauth2/authorize'].get
  update:
    x-apievangelist-phrasing:
      intent: Start the OAuth authorization code flow
      effect: read
      questions:
      - How do I send a user to authorize my app against their Snyk organizations?
      - Which code challenge method does the authorize step accept for PKCE?
      - Can I pass a state value to match the authorization callback to my request?
      instructions:
      - text: Build the authorize URL for client {client_id} redirecting to {redirect_uri} with code challenge {code_challenge}.
        slots:
          client_id: query.client_id
          redirect_uri: query.redirect_uri
          code_challenge: query.code_challenge
      - text: Start the authorization code flow with response type {response_type}, challenge method {code_challenge_method} and state {state}.
        slots:
          response_type: query.response_type
          code_challenge_method: query.code_challenge_method
          state: query.state
      method: generated
      generated: '2026-10-01'
- target: $.paths['/token'].post
  update:
    x-apievangelist-phrasing:
      intent: Exchange an authorization code for an access token
      effect: write
      questions:
      - What do I do with the authorization code once the user is redirected back to my app?
      - How do I get an access token after a user authorizes my client application?
      instructions:
      - text: Exchange the authorization code I just received for an access token.
      - text: Request a new access token for my OAuth client application.
      method: generated
      generated: '2026-10-01'
- target: $.paths['/revoke'].post
  update:
    x-apievangelist-phrasing:
      intent: Revoke a leaked refresh token
      effect: destructive
      questions:
      - How can I invalidate a refresh token that was accidentally leaked?
      - Can I stop a refresh token from ever being reused?
      instructions:
      - text: Revoke refresh token {token} for client {client_id} using secret {client_secret}.
        slots:
          token: requestBody.token
          client_id: requestBody.client_id
          client_secret: requestBody.client_secret
      - text: Kill the leaked refresh token {token} so it can no longer be used.
        slots:
          token: requestBody.token
      method: generated
      generated: '2026-10-01'