Palo Alto Networks Defenders API is one of 741 APIs that Palo Alto Networks publishes on the APIs.io network, described by a machine-readable OpenAPI specification.
Tagged areas include Defenders. The published artifact set on APIs.io includes an OpenAPI specification.
This API exposes
42 operations
across 42 paths,
and defines 41 schemas.
It is described by OpenAPI 3.2.0, at version 1.0.
Requests are made against a single base URL, PATH_TO_CONSOLE.
42 operations42 paths41 schemas2 DELETE14 GET26 POST
Metadata
The identity and technical contract details declared by the specification.
Specification
OpenAPI 3.2.0
API Version
1.0
Base URL
https://{firewall}/api/
Resource Areas
1
Paths & Operations 42
Across 42 paths, the API surfaces 42 operations — 2 DELETE, 14 GET, 26 POST. Each is listed below with its method, path, parameters, and response codes.
The contract defines 41 schemas that model the data the API accepts and returns. The most detailed are defender.Defender (31 properties), common.DaemonSetOptions (30 properties), defender.Status (16 properties), common.CloudMetadata (15 properties). Each schema is shown below with its type and property counts.
-_types.DefenderSummary
array
shared.ServerlessBundleRequest
object
ServerlessBundleRequest represents the arguments to serverless bundle request
3 properties
common.CloudMetadata
object
CloudMetadata is the metadata for a cloud provider managed asset (e.g., as part of AWS/GCP/Azure/OCI)
15 properties
common.DaemonSetOptions
object
DaemonSetOptions are options for creating the daemonset install script for defenders
30 properties
common.ContainerRuntime
string
ContainerRuntime represents the supported container runtime types
defender.Status
object
Status is the generic status state per defender or global
16 properties
waas.UnprotectedProcess
object
UnprotectedProcess holds unprotected processes alongside the port
3 properties
appembedded.FargateTask
object
FargateTask represents the generic fargate task AWS template
common.ACIMetadata
object
1 property
defender.ScanStatus
object
ScanStatus represents the status of current scan
6 properties
defender.Category
string
Category represents the defender target category
common.CloudRunMetadata
object
2 properties
common.GCPCloudMetadata
object
1 property
common.CloudProvider
string
CloudProvider specifies the cloud provider name
common.ExternalLabel
object
ExternalLabel holds an external label with a source and timestamp
5 properties
common.Toleration
object
Toleration holds options for pod toleration ref: https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/ code ref: k8s.io/api/core/v1/typ…
5 properties
string
string
common.Secret
object
Secret Stores the plain and encrypted version of a value. The plain version is not stored in a database
2 properties
-_uint8
array
defender.Features
object
Features is the defender features that can be updated
2 properties
defender.FeatureStatus
object
FeatureStatus holds data about defender features
3 properties
-_defender.Defender
array
shared.LambdaRuntimeType
string
LambdaRuntimeType represents the runtime type of the serverless function The constants used are taken from: https://docs.aws.amazon.com/lambda/latest/dg/APICre…
types.DefenderSummary
object
DefenderSummary is a summary for a type of defender
4 properties
defender.ProxyListenerType
string
ProxyListenerType is the proxy listener type of defenders
common.DefenderProxyOpt
object
DefenderProxyOpt holds options for defender proxy configuration It embeds ProxySettings but override it's Password field with a simple string This is needed in…
5 properties
waas.ProtectionStatus
object
ProtectionStatus describes the status of the WAAS protection
6 properties
common.ExternalLabelSourceType
string
ExternalLabelSourceType indicates the source of the labels
defender.Type
string
Type is the type to be given at startup
common.ClusterType
string
ClusterType is the cluster type
-_string
array
uint8
integer
waas.OutOfBandMode
string
OutOfBandMode holds the app firewall out-of-band mode
shared.DefenderInstallBundle
object
DefenderInstallBundle represents the install bundle for the defender
2 properties
defender.SystemInfo
object
SystemInfo is the OS information of the host
5 properties
defender.UpgradeStatus
object
UpgradeStatus represents the status of current twistlock defender upgrade
4 properties
int
integer
common.ProxySettings
object
ProxySettings are the http proxy settings
5 properties
common.AzureMetadata
object
2 properties
defender.Defender
object
Defender is an update about an agent starting
31 properties
shared.AppEmbeddedEmbedRequest
object
AppEmbeddedEmbedRequest represents the arguments required for a AppEmbedded defender embed request
5 properties
Specification
The full machine-readable OpenAPI contract behind this narrative.
Every API here is available over the API and to AI agents over MCP. APIs is not yet its own endpoint on the v1 API. Reach this content through network search and the tag graph, or the MCP server below.
Installs https://mcp.apievangelist.com/mcp in Claude, Cursor, VS Code and the rest — one button, every client.
MCP tools for apis
4 tools reach this content
search_api_evangelistSearch every content type across the network at once.
find_relatedThe shared-tag relevance graph — what else covers this.
get_tagEverything one tag labels, across all content types.
guide_topicPRO — a curated bundle for a topic: area, guidance, rules, papers, stories, services.
A second provider on the same verified email joins the account you already have.
Your account
ⓘWhere this information came from
This is an independent, third-party profile of Palo Alto Networks Defenders API, published by
API Evangelist. We do not operate, host, resell, or
support these APIs, and we are not affiliated with or endorsed by the company unless stated above.
Everything here is built from publicly available information — the company's own site,
developer portal, documentation, public repositories, and the specifications it publishes for public use.
Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's
public API artifacts, scored against a published rubric. They are not certifications,
endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and
you do not need to justify the request. A removed company is recorded as unrated, never scored
zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy → On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.