How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Palo Alto Networks Discovery and Exposure Management API

Discovery and Exposure Management(CDEM) APIs help you in identifying unmanaged or exposed assets that must be secured. You can use the APIs in this section to fetch the details that are displayed in the Discovery and Exposure Management(CDEM) dashboard. For more information about Discovery and Exposure Management(CDEM) dashboard, see [Discovery and Exposure Management(CDEM) dashboard](https://docs.prismacloud.io/en/enterprise-edition/content-collections/dashboards/dashboards-discovery-exposure-management)

Palo Alto Networks Discovery and Exposure Management API is one of 741 APIs that Palo Alto Networks publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Discovery and Exposure Management. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 26 operations across 26 paths, and defines 57 schemas. It is described by OpenAPI 3.2.0, at version v0.

Requests are made against 15 base URLs: https://api.prismacloud.io, https://api2.prismacloud.io, https://api3.prismacloud.io, https://api4.prismacloud.io, https://api.anz.prismacloud.io, https://api.eu.prismacloud.io, https://api2.eu.prismacloud.io, https://api.gov.prismacloud.io, https://api.prismacloud.cn, https://api.ca.prismacloud.io, https://api.sg.prismacloud.io, https://api.uk.prismacloud.io, https://api.ind.prismacloud.io, https://api.jp.prismacloud.io, https://api.fr.prismacloud.io.

26 operations 26 paths 57 schemas 16 GET10 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
v0
Base URL
https://{firewall}/api/
Authentication
API Key
Resource Areas
1

Authentication & Security 1

Palo Alto Networks Discovery and Exposure Management API declares 1 security scheme for authenticating requests. An API key is passed in the header as x-redlock-auth (x-redlock-auth).

  • x-redlock-auth — The x-redlock-auth value is a JSON Web Token (JWT).

Paths & Operations 26

Across 26 paths, the API surfaces 26 operations — 16 GET, 10 POST. Each is listed below with its method, path, parameters, and response codes.

Discovery and Exposure Management 26

Discovery and Exposure Management(CDEM) APIs help you in identifying unmanaged or exposed assets that must be secured. You can use the APIs in this section to fetch the details th…

POST
/asm/api/v1/convert-cloud-account
Onboard Cloud Accounts
onboard-Cloud-Accounts body → 200404
POST
/asm/api/v1/asset
Get Assets List
asset-inventory-for-l3 body → 200404
POST
/asm/api/v1/asset/{asset_id}/finding
Get Findings of an Asset
get-asset-findings 2 params body → 200404
POST
/asm/api/v1/asset/{asset_id}/finding/filters
Get Asset Findings Filter
get-finding-filters 1 param body → 200404
POST
/asm/api/v1/asset/snooze
Snooze Unmanaged Assets
asset-snooze body → 200404
POST
/asm/api/v1/asset/reopen
Unsnooze Unmanaged Assets
asset-unsnooze body → 200404
POST
/asm/api/v1/asset/email
Email Asset Details
send-asset-detail-email-from-sidecar body → 404200
POST
/asm/api/v1/asset/download
Download Unmanaged Assets
asset-download body → 200404
POST
/asm/api/v1/asset/aggregation-by-resource-type
Get Aggregated Asset Count by Asset Type
get-asset-count-by-asset-type-for-l2 body → 200404
POST
/asm/api/v1/asset/aggregation-by-cloud-type
Get Aggregated Asset Count by Cloud Type
get-assets-aggregated-by-provider-for-l1 body → 404200
GET
/asm/api/v1/service
Get Services
list-services 2 params → 200404
GET
/asm/api/v1/service/{serviceId}
Get Service Details
fetch-asm-service-details 3 params → 404200
GET
/asm/api/v1/industry-benchmarks
Get Industry Benchmark Data
get-industry-benchmarks → 200404
GET
/asm/api/v1/dashboard/convertible-accounts
Get Convertible Accounts
get-convertible-cloud-accounts 3 params → 200404
GET
/asm/api/v1/dashboard/asset
Get Convertible Assets
list-assets 5 params → 404200
GET
/asm/api/v1/dashboard/asset/trend
Get Asset Trend
fetch-assets-by-manage-type-and-remediation 1 param → 200404
GET
/asm/api/v1/dashboard/asset/top-risk
Get Asset Top Risks
get-top-risks → 200404
GET
/asm/api/v1/dashboard/asset/internet-exposure-risk
Get Internet Exposure Risk Distribution
fetch-internet-exposure-asm-assets → 200404
GET
/asm/api/v1/dashboard/asset/geolocation
Get Assets Count Across Location
fetch-asset-by-geo-location → 200404
GET
/asm/api/v1/dashboard/asset/count
Get Convertible Assets Count
get-asset-counts → 200404
GET
/asm/api/v1/asset/{asset_id}/vulnerability
Get Vulnerabilities in an Asset by ID
asset-vulnerability 5 params → 200400
GET
/asm/api/v1/asset/{assetId}/flowlog-relationships
Get Flow Logs of Unmanaged Assets
fetch-flowlog-relationships 2 params → 200404
GET
/asm/api/v1/asset/{asmAssetId}/service
Get List of Service for an Asset
fetch-asm-services-linked-to-asset 3 params → 200404
GET
/asm/api/v1/asset/vulnerability
Get Impacted Distros for a Vulnerability
vulnerability 1 param → 200
GET
/asm/api/v1/asset/snoozed-regex
Get Snooze Regex Pattern
list-snoozed-pattern → 200
GET
/asm/api/v1/asset/filters
Get Asset Filters
get-asset-filters → 200404

Schemas 57

The contract defines 57 schemas that model the data the API accepts and returns. The most detailed are SideCarAssetEmailDetails (18 properties), AssetInventory (11 properties), AssetInventoryRequest (10 properties), Node (10 properties). Each schema is shown below with its type and property counts.

AssetCountView
object
2 properties
Certificate
object
List of certificates
5 properties
Ip
object
List of IPs
4 properties
SnoozedRegexResponse
object
1 property
Data
object
2 properties
InferredCveMetaData
object
9 properties
CloudDistribution
object
1 property
FindingRequest
object
4 properties
ResourceTypeAggregation
object
8 properties
AsmSideCarServiceDetails
object
4 properties
ImpactedDistro
object
3 properties
BenchmarkingResponse
object
1 property
SideCarAssetEmailDetails
object
18 properties
GeoLocation
object
List of assets grouped by geolocation
4 properties
CloudTypeAggregation
object
8 properties
AssetSideCarAsmServices
object
2 properties
AssetInventory
object
11 properties
AsmAssetsTopRisks
object
1 property
Service
object
List of services
3 properties
AssetInventoryResponse
object
3 properties
CloudAccountsList
object
1 property
FindingFilter
object
2 properties
RelativeTimeRangeConfig
object
Snooze time range config
2 properties
VulnerabilityResponse
object
4 properties
AccountDetails
object
List of convertible accounts
6 properties
Risk
object
List of risks
4 properties
AssetTrend
object
4 properties
AssetsByGeoLocation
object
1 property
AssetUnsnoozeRequest
object
2 properties
IssuesMetadata
object
List of issues metadata
2 properties
AssetFilterResponse
object
6 properties
AssetInventoryRequest
object
10 properties
FindingResponse
object
2 properties
Finding
object
5 properties
AsmAssetFlowLogRelationshipsResponse
object
1 property
ConvertibleCloudAccounts
object
3 properties
AccountConversionResponse
object
5 properties
AssetSnoozeRequest
object
5 properties
RelativeTimeDuration
object
2 properties
Assets
object
Remediated assets
2 properties
AccountConversionResponseList
object
1 property
InferredCveResponse
object
3 properties
AsmAssetsInfo
object
2 properties
Connection
object
List of connections
3 properties
Asset
object
List of assets
9 properties
CloudAccountDetails
object
3 properties
Node
object
List of nodes
10 properties
AsmDashboardListAssetsResponse
object
2 properties
ErrorResponse
object
4 properties
AsmServicesList
object
3 properties
AssetL2View
object
1 property
AsmInternetExposureRisk
object
5 properties
DistroDetails
object
4 properties
CloudTypeCount
object
2 properties
AssetsRatio
object
Unmanaged assets ratio
2 properties
Overview
object
9 properties
AsmDashboardAssetCounts
object
1 property

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

palo-alto-networks-discovery-and-exposure-management-api-openapi.yml Raw ↑

Other APIs Palo Alto Networks publishes across the network.

PAN-OS XML API
PAN-OS OpenConfig API
Panorama API
AutoFocus API (Deprecated)
Prisma SASE Service Status API
Cross-Platform Service Status API
SASE Authentication Service API
Expedition API (Deprecated)
VM-Series Licensing API
Palo Alto Networks 5G Deregistered Trend API
Palo Alto Networks 5G Network Interconnects and Bandwidth API
Palo Alto Networks 5G Registered Trend API
Where this information came from

This is an independent, third-party profile of Palo Alto Networks Discovery and Exposure Management API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.