Strivacity · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Admin Portal Account API
28 actions
28 updates
phrasing
extends
openapi/strivacity-account-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Strivacity's API. It is a proposal applied on top of the contract, not a document Strivacity publishes.
What the actions change
x-apievangelist-phrasing
Targets 28 · first 16 shown; the file carries all of them
$.info
$.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts'].get
$.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts'].post
$.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}'].get
$.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}'].delete
$.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/authenticators'].post
$.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/authenticators/{authenticatorId}'].delete
$.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/disable'].post
$.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/enable'].post
$.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/groups'].post
$.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/identities/identifier'].post
$.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/impersonation'].post
$.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/liftPasscodeLock'].post
$.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/liftPasswordLock'].post
$.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/lock'].post
$.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/notificationPreferences'].put
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Admin Portal Account API
version: 1.0.0
extends: openapi/strivacity-account-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-10-01'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 27
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts'].get
update:
x-apievangelist-phrasing:
intent: List accounts in an identity store
effect: read
questions:
- Which accounts in my identity store have never logged in?
- Can I filter customer accounts by email, organization or role?
- How do I find accounts created or disabled within a date range?
instructions:
- text: List all accounts in identity store {store}.
slots:
store: path.identityStoreName
- text: Find accounts in {store} whose email is {email}.
slots:
store: path.identityStoreName
email: query.emailNativeClaim
- text: Show accounts in {store} that have never logged in.
slots:
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts'].post
update:
x-apievangelist-phrasing:
intent: Create a customer account
effect: write
questions:
- How do I create a new user account in a Strivacity identity store?
- Can I migrate a user with a password hash from a legacy store?
- Is it possible to create an account without sending email verification?
instructions:
- text: Create an account in {store} with email {email} and language {language}.
slots:
store: path.identityStoreName
email: requestBody.email
language: requestBody.language
- text: Create an account for phone {phone} in identity store {store}, language {language}.
slots:
store: path.identityStoreName
phone: requestBody.phone
language: requestBody.language
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}'].get
update:
x-apievangelist-phrasing:
intent: Get an account's details
effect: read
questions:
- What details are stored on a single customer account?
- Can I look up one account by its ID?
instructions:
- text: Get account {account} from identity store {store}.
slots:
account: path.accountId
store: path.identityStoreName
- text: Show me the profile of account {account} in {store}.
slots:
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}'].delete
update:
x-apievangelist-phrasing:
intent: Delete an account
effect: destructive
questions:
- How do I permanently delete a user account?
- Can I remove a customer account from an identity store?
instructions:
- text: Delete account {account} from identity store {store}.
slots:
account: path.accountId
store: path.identityStoreName
- text: Permanently remove user {account} in {store}.
slots:
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/authenticators'].post
update:
x-apievangelist-phrasing:
intent: Add an email or phone authenticator
effect: write
questions:
- How do I add a phone number as an MFA authenticator for a user?
- Can I register an email authenticator on someone's account?
- Which authenticator types can an admin add to an account?
instructions:
- text: Add a {type} authenticator with target {target} to account {account} in {store}.
slots:
type: requestBody.type
target: requestBody.target
account: path.accountId
store: path.identityStoreName
- text: Register phone authenticator {target} for user {account} in {store}.
slots:
target: requestBody.target
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/authenticators/{authenticatorId}'].delete
update:
x-apievangelist-phrasing:
intent: Remove an authenticator from an account
effect: destructive
questions:
- How do I remove an MFA authenticator from a user's account?
- Can an admin delete a lost phone authenticator for a customer?
instructions:
- text: Delete authenticator {authenticator} from account {account} in {store}.
slots:
authenticator: path.authenticatorId
account: path.accountId
store: path.identityStoreName
- text: Remove the authenticator {authenticator} that user {account} no longer has, in {store}.
slots:
authenticator: path.authenticatorId
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/disable'].post
update:
x-apievangelist-phrasing:
intent: Disable an account
effect: destructive
questions:
- How do I disable a user so they can no longer sign in?
- Can I suspend an account without deleting it?
instructions:
- text: Disable account {account} in identity store {store}.
slots:
account: path.accountId
store: path.identityStoreName
- text: Suspend user {account} in {store} without deleting them.
slots:
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/enable'].post
update:
x-apievangelist-phrasing:
intent: Re-enable a disabled account
effect: write
questions:
- How do I re-enable an account that was disabled?
- Can a suspended user be reactivated?
instructions:
- text: Enable account {account} in identity store {store}.
slots:
account: path.accountId
store: path.identityStoreName
- text: Reactivate the disabled user {account} in {store}.
slots:
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/groups'].post
update:
x-apievangelist-phrasing:
intent: Assign groups to an account
effect: write
questions:
- How do I put a user into one or more groups at once?
- What permissions do I need to assign groups to an account?
instructions:
- text: Assign groups to account {account} in identity store {store}.
slots:
account: path.accountId
store: path.identityStoreName
- text: Add user {account} in {store} to the groups I list.
slots:
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/identities/identifier'].post
update:
x-apievangelist-phrasing:
intent: Change an account's login identifier
effect: write
questions:
- How do I change the email or username a user logs in with?
- Can I update an account identifier without triggering verification?
instructions:
- text: Change the {type} identifier of account {account} in {store} to {identifier}.
slots:
type: requestBody.type
account: path.accountId
store: path.identityStoreName
identifier: requestBody.identifier
- text: Update the login identifier for user {account} in {store}.
slots:
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/impersonation'].post
update:
x-apievangelist-phrasing:
intent: Impersonate an account for support
effect: write
questions:
- How can a support agent impersonate a customer to troubleshoot?
- Does an impersonation request need a reason and a client?
instructions:
- text: Generate an impersonation link for account {account} in {store} via client {client} because {reason}.
slots:
account: path.accountId
store: path.identityStoreName
client: requestBody.clientId
reason: requestBody.reason
- text: Let me log in as user {account} in {store} for support, reason {reason}.
slots:
account: path.accountId
store: path.identityStoreName
reason: requestBody.reason
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/liftPasscodeLock'].post
update:
x-apievangelist-phrasing:
intent: Unlock an account locked by passcode attempts
effect: write
questions:
- How do I unlock a user who failed too many one-time passcode attempts?
- Can an admin clear a passcode lock on an account?
instructions:
- text: Lift the passcode lock on account {account} in {store}.
slots:
account: path.accountId
store: path.identityStoreName
- text: Unlock user {account} in {store} after too many OTP failures.
slots:
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/liftPasswordLock'].post
update:
x-apievangelist-phrasing:
intent: Unlock an account locked by password attempts
effect: write
questions:
- How do I unlock a user who is locked out after wrong passwords?
- Can I lift a password lockout for a customer?
instructions:
- text: Lift the password lock on account {account} in {store}.
slots:
account: path.accountId
store: path.identityStoreName
- text: Unlock user {account} in {store} after too many wrong passwords.
slots:
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/lock'].post
update:
x-apievangelist-phrasing:
intent: Lock an account
effect: write
questions:
- How do I put a lock on a suspicious user account?
- Which lock types can an admin set on an account?
instructions:
- text: Set a {type} lock on account {account} in {store}.
slots:
type: requestBody.type
account: path.accountId
store: path.identityStoreName
- text: Lock user {account} in identity store {store}.
slots:
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/notificationPreferences'].put
update:
x-apievangelist-phrasing:
intent: Update an account's notification preferences
effect: write
questions:
- How do I stop a user from getting password reset success emails?
- Which notifications can be switched on or off for one account?
instructions:
- text: Update notification preferences for account {account} in {store}.
slots:
account: path.accountId
store: path.identityStoreName
- text: Turn off account lockout notifications for user {account} in {store}.
slots:
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/organization'].put
update:
x-apievangelist-phrasing:
intent: Move an account to another organization
effect: write
questions:
- How do I move a user to a different organization?
- Can I change which organization an account belongs to?
instructions:
- text: Move account {account} in {store} to organization {organization}.
slots:
account: path.accountId
store: path.identityStoreName
organization: requestBody.id
- text: Change the organization of user {account} in {store}.
slots:
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/password/change'].post
update:
x-apievangelist-phrasing:
intent: Set a new password for an account
effect: write
questions:
- How do I set a new password directly on a user's account?
- Can an admin change a password and bypass the password policy?
instructions:
- text: Change the password of account {account} in {store} to {password}.
slots:
account: path.accountId
store: path.identityStoreName
password: requestBody.newPassword
- text: Set a new password hash for user {account} in {store}.
slots:
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/password/reset'].post
update:
x-apievangelist-phrasing:
intent: Send a password reset email to a user
effect: write
questions:
- How do I trigger a password reset email for a customer?
- Can an admin start a password reset on behalf of a user?
instructions:
- text: Send a password reset email to account {account} in {store} via application {app}.
slots:
account: path.accountId
store: path.identityStoreName
app: header.X-Notification-By-Application
- text: Request a password reset for user {account} in {store}.
slots:
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/personal'].put
update:
x-apievangelist-phrasing:
intent: Update an account's profile attributes
effect: write
questions:
- How do I update profile attributes like name or address on an account?
- Does updating account metadata overwrite attributes I don't send?
instructions:
- text: Update the profile attributes of account {account} in {store}.
slots:
account: path.accountId
store: path.identityStoreName
- text: Change the stored metadata for user {account} in identity store {store}.
slots:
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/provisions'].get
update:
x-apievangelist-phrasing:
intent: List an account's provisioning statuses
effect: read
questions:
- Has this user been provisioned to my downstream systems yet?
- Where can I see outbound provisioning status for one account?
instructions:
- text: List provisioning statuses for account {account} in {store}.
slots:
account: path.accountId
store: path.identityStoreName
- text: Show which provision targets user {account} in {store} synced to.
slots:
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/provisions/{outboundProvisionId}/sync'].post
update:
x-apievangelist-phrasing:
intent: Prioritize an account's provisioning sync
effect: write
questions:
- How do I push one user to a provisioning target right away?
- Can I make an outbound provision sync an account with higher priority?
instructions:
- text: Prioritize syncing account {account} in {store} to provision target {target}.
slots:
account: path.accountId
store: path.identityStoreName
target: path.outboundProvisionId
- text: Resync user {account} in {store} to outbound provision {target} now.
slots:
account: path.accountId
store: path.identityStoreName
target: path.outboundProvisionId
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/roles'].get
update:
x-apievangelist-phrasing:
intent: List an account's organization roles
effect: read
questions:
- What organization roles does this user currently hold?
- Can I see every role assignment for one account?
instructions:
- text: List role assignments for account {account} in {store}.
slots:
account: path.accountId
store: path.identityStoreName
- text: Show the organization roles held by user {account} in {store}.
slots:
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/roles'].post
update:
x-apievangelist-phrasing:
intent: Assign organization roles to an account
effect: write
questions:
- How do I give a user admin roles within an organization?
- Can I assign several roles to an account in one call?
instructions:
- text: Assign roles {roles} in organization {organization} to account {account} in {store}.
slots:
roles: requestBody.roles
organization: requestBody.organization
account: path.accountId
store: path.identityStoreName
- text: Grant user {account} in {store} the roles {roles} for organization {organization}.
slots:
account: path.accountId
store: path.identityStoreName
roles: requestBody.roles
organization: requestBody.organization
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/roles/{roleId}'].delete
update:
x-apievangelist-phrasing:
intent: Remove an organization role from an account
effect: destructive
questions:
- How do I revoke a role a user has in an organization?
- Can I take one organization role away from an account?
instructions:
- text: Remove role {role} in organization {organization} from account {account} in {store}.
slots:
role: path.roleId
organization: query.organization
account: path.accountId
store: path.identityStoreName
- text: Revoke role {role} for user {account} in {store} within organization {organization}.
slots:
role: path.roleId
account: path.accountId
store: path.identityStoreName
organization: query.organization
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/sessions'].get
update:
x-apievangelist-phrasing:
intent: List an account's active sessions
effect: read
questions:
- Which devices and browsers is this user currently signed in on?
- Can I see a customer's active login sessions?
instructions:
- text: List sessions for account {account} in {store}.
slots:
account: path.accountId
store: path.identityStoreName
- text: Show where user {account} in {store} is logged in.
slots:
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/sessions'].delete
update:
x-apievangelist-phrasing:
intent: Log an account out everywhere
effect: destructive
questions:
- How do I sign a user out of every browser at once?
- Does clearing sessions perform a back-channel logout?
instructions:
- text: Clear all sessions for account {account} in {store}.
slots:
account: path.accountId
store: path.identityStoreName
- text: Log user {account} in {store} out of every device.
slots:
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'
- target: $.paths['/admin/api/v1/identityStores/{identityStoreName}/accounts/{accountId}/sessions/{sessionId}'].delete
update:
x-apievangelist-phrasing:
intent: End one session for an account
effect: destructive
questions:
- How do I end just one of a user's sessions?
- Can I revoke a single device session without logging out the rest?
instructions:
- text: Delete session {session} for account {account} in {store}.
slots:
session: path.sessionId
account: path.accountId
store: path.identityStoreName
- text: End only session {session} of user {account} in {store}.
slots:
session: path.sessionId
account: path.accountId
store: path.identityStoreName
method: generated
generated: '2026-10-01'