How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Palo Alto Networks Defenders API

{'$ref': 'desc/defenders/defenders.md'}

Palo Alto Networks Defenders API is one of 741 APIs that Palo Alto Networks publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Defenders. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 42 operations across 42 paths, and defines 41 schemas. It is described by OpenAPI 3.2.0, at version 1.0.

Requests are made against a single base URL, PATH_TO_CONSOLE.

42 operations 42 paths 41 schemas 2 DELETE14 GET26 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0
Base URL
https://{firewall}/api/
Resource Areas
1

Paths & Operations 42

Across 42 paths, the API surfaces 42 operations — 2 DELETE, 14 GET, 26 POST. Each is listed below with its method, path, parameters, and response codes.

Defenders 42

Defenders. 21 operations in this definition.

GET
/api/v34.03/defenders
Get Deployed Defenders
get-defenders 18 params → 200default
POST
/api/v34.03/defenders/aci.yaml
A CI Container Group Y A M L
post-defenders-aci.yaml 4 params → 200default
POST
/api/v34.03/defenders/app-embedded
Generate a Docker File for App-embedded Defender
post-defenders-app-embedded body → 200default
POST
/api/v34.03/defenders/cloud-run.yaml
Cloud Run Service Y A M L
post-defenders-cloud-run.yaml 4 params → 200default
POST
/api/v34.03/defenders/daemonset.yaml
Generate Daemonset Deployment YAML File
post-defenders-daemonset.yaml body → 200default
GET
/api/v34.03/defenders/download
Download Deployed Defenders
get-defenders-download 18 params → 200default
POST
/api/v34.03/defenders/eks-fargate.yaml
Generate K8s Controller Manifest
post-defenders-eks-fargate.yaml 4 params → 200default
POST
/api/v34.03/defenders/fargate.json
Generate a Protected JSON Fargate Task Definition
post-defenders-fargate.json 10 params body → 200default
POST
/api/v34.03/defenders/fargate.yaml
Generate a Protected YAML Fargate Task Definition
post-defenders-fargate.yaml 10 params → 200default
POST
/api/v34.03/defenders/helm/twistlock-defender-helm.tar.gz
Generate a Helm Deployment Chart for Defender
post-defenders-helm-twistlock-defender-helm.tar.gz body → 200default
GET
/api/v34.03/defenders/image-name
Get Docker Image Name for Defender
get-defenders-image-name → 200default
GET
/api/v34.03/defenders/install-bundle
Get Certificate Bundle for Defender
get-defenders-install-bundle 10 params → 200default
GET
/api/v34.03/defenders/names
Get Defender Names
get-defenders-names 18 params → 200default
POST
/api/v34.03/defenders/serverless/bundle
Generate Serverless Bundle for Defender
post-defenders-serverless-bundle body → 200default
GET
/api/v34.03/defenders/summary
Get Defenders Summary
get-defenders-summary → 200default
GET
/api/v34.03/defenders/tas-cloud-controller-address
Defenders Tas Cloud Controller Address
get-defenders-tas-cloud-controller-address 18 params → 200default
POST
/api/v34.03/defenders/upgrade
Upgrade Connected Single Linux Defenders
post-defenders-upgrade 18 params → 200default
DELETE
/api/v34.03/defenders/{id}
Delete a Defender
delete-defenders-id 1 param → 200default
POST
/api/v34.03/defenders/{id}/features
Update Defender Configuration
post-defenders-id-features 1 param body → 200default
POST
/api/v34.03/defenders/{id}/restart
Restart a Defender
post-defenders-id-restart 1 param → 200default
POST
/api/v34.03/defenders/{id}/upgrade
Upgrade a Defender
post-defenders-id-upgrade 1 param → 200default
GET
/api/v34.04/defenders
Get Deployed Defenders
get-defenders 18 params → 200default
POST
/api/v34.04/defenders/aci.yaml
A CI Container Group Y A M L
post-defenders-aci.yaml 4 params → 200default
POST
/api/v34.04/defenders/app-embedded
Generate a Docker File for App-embedded Defender
post-defenders-app-embedded body → 200default
POST
/api/v34.04/defenders/cloud-run.yaml
Cloud Run Service Y A M L
post-defenders-cloud-run.yaml 4 params → 200default
POST
/api/v34.04/defenders/daemonset.yaml
Generate Daemonset Deployment YAML File
post-defenders-daemonset.yaml body → 200default
GET
/api/v34.04/defenders/download
Download Deployed Defenders
get-defenders-download 18 params → 200default
POST
/api/v34.04/defenders/eks-fargate.yaml
Generate K8s Controller Manifest
post-defenders-eks-fargate.yaml 4 params → 200default
POST
/api/v34.04/defenders/fargate.json
Generate a Protected JSON Fargate Task Definition
post-defenders-fargate.json 10 params body → 200default
POST
/api/v34.04/defenders/fargate.yaml
Generate a Protected YAML Fargate Task Definition
post-defenders-fargate.yaml 10 params → 200default
POST
/api/v34.04/defenders/helm/twistlock-defender-helm.tar.gz
Generate a Helm Deployment Chart for Defender
post-defenders-helm-twistlock-defender-helm.tar.gz body → 200default
GET
/api/v34.04/defenders/image-name
Get Docker Image Name for Defender
get-defenders-image-name → 200default
GET
/api/v34.04/defenders/install-bundle
Get Certificate Bundle for Defender
get-defenders-install-bundle 10 params → 200default
GET
/api/v34.04/defenders/names
Get Defender Names
get-defenders-names 18 params → 200default
POST
/api/v34.04/defenders/serverless/bundle
Generate Serverless Bundle for Defender
post-defenders-serverless-bundle body → 200default
GET
/api/v34.04/defenders/summary
Get Defenders Summary
get-defenders-summary → 200default
GET
/api/v34.04/defenders/tas-cloud-controller-address
Defenders Tas Cloud Controller Address
get-defenders-tas-cloud-controller-address 18 params → 200default
POST
/api/v34.04/defenders/upgrade
Upgrade Connected Single Linux Defenders
post-defenders-upgrade 18 params → 200default
DELETE
/api/v34.04/defenders/{id}
Delete a Defender
delete-defenders-id 1 param → 200default
POST
/api/v34.04/defenders/{id}/features
Update Defender Configuration
post-defenders-id-features 1 param body → 200default
POST
/api/v34.04/defenders/{id}/restart
Restart a Defender
post-defenders-id-restart 1 param → 200default
POST
/api/v34.04/defenders/{id}/upgrade
Upgrade a Defender
post-defenders-id-upgrade 1 param → 200default

Schemas 41

The contract defines 41 schemas that model the data the API accepts and returns. The most detailed are defender.Defender (31 properties), common.DaemonSetOptions (30 properties), defender.Status (16 properties), common.CloudMetadata (15 properties). Each schema is shown below with its type and property counts.

-_types.DefenderSummary
array
shared.ServerlessBundleRequest
object
ServerlessBundleRequest represents the arguments to serverless bundle request
3 properties
common.CloudMetadata
object
CloudMetadata is the metadata for a cloud provider managed asset (e.g., as part of AWS/GCP/Azure/OCI)
15 properties
common.DaemonSetOptions
object
DaemonSetOptions are options for creating the daemonset install script for defenders
30 properties
common.ContainerRuntime
string
ContainerRuntime represents the supported container runtime types
defender.Status
object
Status is the generic status state per defender or global
16 properties
waas.UnprotectedProcess
object
UnprotectedProcess holds unprotected processes alongside the port
3 properties
appembedded.FargateTask
object
FargateTask represents the generic fargate task AWS template
common.ACIMetadata
object
1 property
defender.ScanStatus
object
ScanStatus represents the status of current scan
6 properties
defender.Category
string
Category represents the defender target category
common.CloudRunMetadata
object
2 properties
common.GCPCloudMetadata
object
1 property
common.CloudProvider
string
CloudProvider specifies the cloud provider name
common.ExternalLabel
object
ExternalLabel holds an external label with a source and timestamp
5 properties
common.Toleration
object
Toleration holds options for pod toleration ref: https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/ code ref: k8s.io/api/core/v1/typ…
5 properties
string
string
common.Secret
object
Secret Stores the plain and encrypted version of a value. The plain version is not stored in a database
2 properties
-_uint8
array
defender.Features
object
Features is the defender features that can be updated
2 properties
defender.FeatureStatus
object
FeatureStatus holds data about defender features
3 properties
-_defender.Defender
array
shared.LambdaRuntimeType
string
LambdaRuntimeType represents the runtime type of the serverless function The constants used are taken from: https://docs.aws.amazon.com/lambda/latest/dg/APICre…
types.DefenderSummary
object
DefenderSummary is a summary for a type of defender
4 properties
defender.ProxyListenerType
string
ProxyListenerType is the proxy listener type of defenders
common.DefenderProxyOpt
object
DefenderProxyOpt holds options for defender proxy configuration It embeds ProxySettings but override it's Password field with a simple string This is needed in…
5 properties
waas.ProtectionStatus
object
ProtectionStatus describes the status of the WAAS protection
6 properties
common.ExternalLabelSourceType
string
ExternalLabelSourceType indicates the source of the labels
defender.Type
string
Type is the type to be given at startup
common.ClusterType
string
ClusterType is the cluster type
-_string
array
uint8
integer
waas.OutOfBandMode
string
OutOfBandMode holds the app firewall out-of-band mode
shared.DefenderInstallBundle
object
DefenderInstallBundle represents the install bundle for the defender
2 properties
defender.SystemInfo
object
SystemInfo is the OS information of the host
5 properties
defender.UpgradeStatus
object
UpgradeStatus represents the status of current twistlock defender upgrade
4 properties
int
integer
common.ProxySettings
object
ProxySettings are the http proxy settings
5 properties
common.AzureMetadata
object
2 properties
defender.Defender
object
Defender is an update about an agent starting
31 properties
shared.AppEmbeddedEmbedRequest
object
AppEmbeddedEmbedRequest represents the arguments required for a AppEmbedded defender embed request
5 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

palo-alto-networks-defenders-api-openapi.yml Raw ↑

Other APIs Palo Alto Networks publishes across the network.

PAN-OS XML API
PAN-OS OpenConfig API
Panorama API
AutoFocus API (Deprecated)
Prisma SASE Service Status API
Cross-Platform Service Status API
SASE Authentication Service API
Expedition API (Deprecated)
VM-Series Licensing API
Palo Alto Networks 5G Deregistered Trend API
Palo Alto Networks 5G Network Interconnects and Bandwidth API
Palo Alto Networks 5G Registered Trend API
Where this information came from

This is an independent, third-party profile of Palo Alto Networks Defenders API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.